DISTRIBUTED GROUP KEY MANAGEMENT SCHEME FOR SECURE MANY-TO-MANY COMMUNICATION
    2.
    发明申请
    DISTRIBUTED GROUP KEY MANAGEMENT SCHEME FOR SECURE MANY-TO-MANY COMMUNICATION 审中-公开
    分布式群组密钥管理方案,用于安全多人通信

    公开(公告)号:WO0103365A8

    公开(公告)日:2001-07-12

    申请号:PCT/US0018583

    申请日:2000-07-06

    Abstract: A group key management system (20) and method for providing secure many-to-many communication is presented. The system (20) employs a binary distribution tree structure (26). The binary tree (26) includes a first internal node having a first branch and a second branch depending therefrom. Each of the branches includes a first member (22, 22a) assigned to a corresponding leaf node. The first member (22, 22a) has a unique binary ID (24) that is associated with the corresponding leaf node to which the first member (22, 22a) is assigned. A first secret key (28) of the first member (22, 22a) is operable for encrypting data to be sent to other members (22, 22a). The first member (22, 22a) is associated with a key association group (33) that is comprised of other members (22, 22a). The other members (22, 22a) have blinded keys (30). A blinded key (30) derived from the first secret key (28) of the first member (22, 22a) is transmitted to the key association group (33). Wherein, the first member (22, 22a) uses the blinded keys (30) received from the key association group (33) and the first secret key (28) to calculate an unblinded key of the first internal node. The unblinded key is used for encrypting data that is communicated between members (22, 22a) located on branches depending from the first internal node.

    Abstract translation: 提出了组密钥管理系统(20)和用于提供安全的多对多通信的方法。 系统(20)采用二进制分布树结构(26)。 二叉树(26)包括具有第一分支和从其依赖的第二分支的第一内部节点。 每个分支包括分配给相应叶节点的第一成员(22,22a)。 第一成员(22,22a)具有与第一成员(22,22a)被分配到的对应叶节点相关联的唯一二进制ID(24)。 第一成员(22,22a)的第一秘密密钥(28)可用于加密要发送给其他成员(22,22a)的数据。 第一成员(22,22a)与由其他成员(22,22a)组成的关键关联组(33)相关联。 其他部件(22,22a)具有不透光的键(30)。 从第一成员(22,22a)的第一秘密密钥(28)导出的盲密钥(30)被发送到密钥关联组(33)。 其中,第一成员(22,22a)使用从密钥关联组(33)接收到的盲密钥(30)和第一密钥(28)来计算第一内部节点的非盲密钥。 非盲的密钥用于加密在位于根据第一内部节点的分支上的成员(22,22a)之间传送的数据。

    METHOD AND APPARATUS FOR TRANSPARENT CLOUD COMPUTING WITH A VIRTUALIZED NETWORK INFRASTRUCTURE
    3.
    发明申请
    METHOD AND APPARATUS FOR TRANSPARENT CLOUD COMPUTING WITH A VIRTUALIZED NETWORK INFRASTRUCTURE 审中-公开
    具有虚拟化网络基础设施的透明云计算方法和设备

    公开(公告)号:WO2011049742A3

    公开(公告)日:2011-07-07

    申请号:PCT/US2010051570

    申请日:2010-10-06

    Abstract: A capability is provided for providing transparent cloud computing with a virtualized network infrastructure. A method for enabling use of a resource of a data center as an extension of a customer network includes receiving, at a forwarding element (FE), a packet intended for a virtual machine hosted at an edge domain of the data center, determining a VLAN ID of the VLAN for the customer network in the edge domain, updating the packet to include the VLAN ID of the VLAN for the customer network in the edge domain, and propagating the updated packet from the FE toward virtual machine. The edge domain supports a plurality of VLANs for a respective plurality of customer networks. The packet includes an identifier of the customer network and a MAC address of the virtual machine. The VLAN ID of the VLAN for the customer network in the edge domain is determined using the identifier of the customer network and the MAC address of the virtual machine. The FE may be associated with the edge domain at which the virtual machine is hosted, an edge domain of the data center that is different than the edge domain at which the virtual machine is hosted, or the customer network. Depending on the location of the FE at which the packet is received, additional processing may be provided as needed.

    Abstract translation: 提供的功能是提供透明的云计算与虚拟化网络基础架构。 一种使得能够使用数据中心的资源作为客户网络的扩展的方法包括:在转发元件(FE)处接收旨在被托管在数据中心的边缘域处的虚拟机的分组;确定VLAN 在边缘域中用于客户网络的VLAN的ID,更新分组以将用于客户网络的VLAN的VLAN ID包括在边缘域中,并且将更新的分组从FE传播到虚拟机。 边缘域支持用于相应多个客户网络的多个VLAN。 该分组包括客户网络的标识符和虚拟机的MAC地址。 使用客户网络的标识符和虚拟机的MAC地址来确定边缘域中客户网络的VLAN的VLAN ID。 FE可以与托管虚拟机的边缘域,不同于托管虚拟机的边缘域的数据中心的边缘域或客户网络相关联。 根据接收分组的FE的位置,可以根据需要提供额外的处理。

    DUAL ENCRYPTION PROTOCOL FOR SCALABLE SECURE GROUP COMMUNICATION
    5.
    发明申请
    DUAL ENCRYPTION PROTOCOL FOR SCALABLE SECURE GROUP COMMUNICATION 审中-公开
    用于可扩展安全组通信的双重加密协议

    公开(公告)号:WO0103364A8

    公开(公告)日:2001-05-17

    申请号:PCT/US0018529

    申请日:2000-07-06

    Abstract: A logical tree structure (10) and method for managing membership in a multicast group provides scalability and security from internal attacks. The structure defines key groups (20) and subgroups (24, 22), with each subgroup having a subgroup manager (12, 14, 18). Dual encryption allows the sender (12) of the multicast data to manage distribution of a first set of encryption keys whereas the individual subgroup managers (12, 14, 18) manage the distribution of a second set of encryption keys. The two key sets allow the sender (12) to delegate much of the group management responsibilities without compromising security because a key from each set is required to access the multicast data. Security is further maintained via a method in which subgroup managers (12, 14, 18) can be either members (18) or participants (14). Access to both keys is provided to members (18) whereas access to only one key is provided to participants (14). Nodes can be added without generating a new encryption key at the top level which provides improved scalability.

    Abstract translation: 用于管理多播组中的成员资格的逻辑树结构(10)和方法提供了来自内部攻击的可伸缩性和安全性。 该结构定义了密钥组(20)和子组(24,22),每个子组具有子组管理器(12,14,18)。 双重加密允许多播数据的发送者(12)管理第一组加密密钥的分发,而各个子组管理者(12,14,18)管理第二组加密密钥的分发。 这两个密钥集允许发送者(12)在不损害安全性的情况下委派大部分组管理责任,因为每个组的密钥都需要访问多播数据。 通过小组经理(12,14,18)可以是成员(18)或参与者(14)的方法进一步保证安全。 向成员(18)提供对两个密钥的访问,而仅向参与者(14)提供对一个密钥的访问。 可以添加节点而不会在顶层生成新的加密密钥,从而提高可伸缩性。

    ADVERTISEMENT SCHEDULING IN A PACKET-BASED MEDIA-DELIVERY SYSTEM
    6.
    发明申请
    ADVERTISEMENT SCHEDULING IN A PACKET-BASED MEDIA-DELIVERY SYSTEM 审中-公开
    基于分组媒体传送系统的广告调度

    公开(公告)号:WO2010117605A2

    公开(公告)日:2010-10-14

    申请号:PCT/US2010028106

    申请日:2010-03-22

    Abstract: In one embodiment, a scheme for the display of targeted and personalized advertisements in a packet-based media-delivery system, such as an Internet Protocol Television (IPTV) service. An Internet keyword-based advertisement-bidding model is used to place the most-appropriate IPTV advertisements for viewers depending on their interests as determined through the users' Internet activities, while maximizing advertising revenue for the IPTV service provider. One method for scheduling an advertisement for rendering in one or more time slots in packet-based media programming comprises: (a) obtaining at least one keyword from one or more Internet sessions corresponding to at least one user; (b) receiving a plurality of bid amounts corresponding to a plurality of available advertisements for the one or more time slots; and (c) scheduling, based on the at least one keyword and at least one of the bid amounts, the advertisement to be rendered to the at least one user in the one or more time slots.

    Abstract translation: 在一个实施例中,用于在基于分组的媒体传送系统(诸如因特网协议电视(IPTV))服务中显示目标和个性化广告的方案。 基于互联网关键词的广告投标模型用于根据用户的互联网活动确定的兴趣为观众放置最适合的IPTV广告,同时最大化IPTV服务提供商的广告收入。 一种用于在基于分组的媒体编程中的一个或多个时隙中调度用于呈现广告的方法包括:(a)从与至少一个用户对应的一个或多个因特网会话中获得至少一个关键字; (b)接收与所述一个或多个时隙的多个可用广告相对应的多个出价金额; 以及(c)基于所述至少一个关键字和所述投标金额中的至少一个,在所述一个或多个时隙中对所述至少一个用户呈现的广告进行调度。

    METHOD AND APPARATUS FOR UTILIZING NETWORK SERVICES IN A MANNER SUBSTANTIALLY TRANSPARENT TO SERVICE ENDPOINTS
    8.
    发明申请
    METHOD AND APPARATUS FOR UTILIZING NETWORK SERVICES IN A MANNER SUBSTANTIALLY TRANSPARENT TO SERVICE ENDPOINTS 审中-公开
    使用网络服务的方法和设备在大量透明的服务端点

    公开(公告)号:WO2007001846A1

    公开(公告)日:2007-01-04

    申请号:PCT/US2006/023079

    申请日:2006-06-13

    CPC classification number: H04L65/1043 H04L65/1016

    Abstract: The invention includes a method and apparatus for regenerative signaling. Specifically, the method includes receiving at least one base protocol message formatted in accordance with at least one base protocol, obtaining service information associated with at least one network service, and generating, in response to the at least one base protocol message, at least one companion protocol message formatted in accordance with at least one companion protocol. The at least one base protocol message is associated with at least one service endpoint. The service information associated with at least one network service is obtained using the at least one base protocol message. The at least one companion protocol message is generated using at least a portion of the service information. The at least one companion protocol message is operable for controlling the at least one network service in a manner substantially transparent to the at least one service endpoint.

    Abstract translation: 本发明包括用于再生信令的方法和装置。 具体地说,该方法包括接收根据至少一个基本协议格式化的至少一个基本协议消息,获得与至少一个网络服务相关联的服务信息,以及响应于该至少一个基本协议消息,生成至少一个 根据至少一个协同协议格式化的协同协议消息。 所述至少一个基本协议消息与至少一个服务端点相关联。 使用至少一个基本协议消息获得与至少一个网络服务相关联的服务信息。 使用服务信息的至少一部分来生成至少一个协同协议消息。 所述至少一个协同协议消息可操作用于以对所述至少一个服务端点基本透明的方式来控制所述至少一个网络服务。

    PRIVACY-PRESERVING ADVERTISEMENT TARGETING USING RANDOMIZED PROFILE PERTURBATION
    9.
    发明申请
    PRIVACY-PRESERVING ADVERTISEMENT TARGETING USING RANDOMIZED PROFILE PERTURBATION 审中-公开
    隐私保护使用随机配置文件的广告策略

    公开(公告)号:WO2013036421A1

    公开(公告)日:2013-03-14

    申请号:PCT/US2012/052952

    申请日:2012-08-30

    CPC classification number: G06Q30/02

    Abstract: A distribution and scheduling system for advertisements that targets ads to users and maximizes service-provider revenue without having full knowledge of user-profile information. Each user device stores a user profile and is pre-loaded with a set of ads that could possibly be shown during a timeslot. Each user device selects and displays an ad based on the user profile but does not identify the selected ad to the service provider. Instead, the user devices provide perturbed user-profile information in the form of Boolean vectors, which the service provider uses in conjunction with a guaranteed-approximation online algorithm to estimate the number of users that saw a particular ad. Thus, the service provider can charge advertisers for the number of times their ads are viewed, without knowing the users' profiles or which ads were viewed by individual users, and users can view the targeted ads while maintaining privacy from the service provider.

    Abstract translation: 用于向用户展示广告的广告的分发和调度系统,并且在不了解用户简档信息的情况下最大化服务提供商收入。 每个用户设备存储用户简档,并且预先加载可能在时隙期间显示的一组广告。 每个用户设备根据用户配置文件选择并显示广告,但不将所选广告标识给服务提供商。 相反,用户设备以布尔向量的形式提供扰动的用户简档信息,服务提供商结合保证近似在线算法来估计看到特定广告的用户数量。 因此,服务提供商可以在不知道用户的个人资料或哪些广告被个人用户查看的情况下向广告客户收取广告的次数,并且用户可以在维护来自服务提供商的隐私的同时查看有针对性的广告。

Patent Agency Ranking