Abstract:
A system for the maintenance and creation of security tunnels between IoT devices and IoT cloud servers, comprising the steps of receiving one or more packets from one or more IoT devices in a smart router, routing the one or more packets to an agent within the router, the agent performing one or more services on the one or more packets, routing the one or more packets to a WAN port of the router, and sending the one or more packets by a cloud secure tunnel to one or more IoT cloud servers. The system may have secure tunnels that are formed between the IoT devices using a unique password for each IoT device. The additional step of selectively stopping communication between the IoT devices and the router, wherein when the communication of one IoT device to the router is compromised, the remaining tunnels with unique passwords are integral.
Abstract:
A method to prevent internet protocol address spoofing for execution by an Auto Configuration Server and the Auto Configuration Server are claimed. Such an Auto Configuration Server is coupled via at least one Load Balancer in a broadband network to at least one device, comprising at least one gateway device, in at least one home network. The Auto configuration Server remotely manages the devices by using the CPE WAN Management Protocol CWMP on top of the Hypertext Transfer Protocol http. The method comprises the steps of receiving from the device a CWMP Inform message and - a step of determining by a determiner from the message according to the CWMP data model parameter a public IP address of the gateway device; and - a step of retrieving by a retriever from a X-Forwarded For field in a http header field at the http level of the Inform message a Forwarded IP address; and - a step of comparing by a comparator the public IP address with the Forwarded IP address and deciding whether spoofing is present. The step of retrieving is further executed by predetermining a number (n) of the at least one load balancers, according to a network topology in the broadband network, through which the CWMP messages passes in order to reach the Auto Configuration Server; and by selecting the Forwarded IP address from the X-Forwarded For field in function of the n-most last IP address.
Abstract:
A gateway, a diagnosing method of gateway and a computer program product capable of enhancing security of the gateway with cheap and simple measure. The diagnosing method (200) of gateway comprises: identifying an abnormal behavior of the gateway (S210); and notifying the identified abnormal behavior to at least one terminal device (S220). A potential attack to a gateway may be detected as an abnormal behavior and sent to user of the gateway, such that the user of the gateway may be aware of the potential attack and administrate the configuration of the gateway, thus enhanced security may be achieved on the gateway.
Abstract:
Network management infrastructure operable to be connected to at least one remote home network comprising at least one terminal (T21, T22) connected to a gateway (BRG2), wherein said infrastructure comprises a processor configured to connect a physical network interface (PNIB) of the infrastructure to the home network.
Abstract:
The method for operating a distribution point unit comprising a selection switch (17) and a monitor and control logic (15) for providing a first and a second service, comprises the steps of: receiving a switching signal powering the monitor and control logic (68), and switching the selection switch from the first service to the second service by the monitor and control logic (70), after receiving the switching signal. The selection switch has a default state, in which the first service is provided. The first service is in particular an xDSL and/or a PSTN service, and the second service is a G.fast service.
Abstract:
A distribution point unit using discrete multi-tone technology, said distribution point unit being configured for connection to a wired shared medium associated with an available spectrum, said wired shared medium connecting said distribution point unit with a plurality of users, said distribution point unit comprising an assigning unit configured for assigning a first portion of the available spectrum to a first user of said plurality of users and a second portion of the available spectrum to a second user of said plurality of users; a sending and receiving unit configured for encoding and decoding digital data, using discrete multi-tone technology, and configured for sending and receiving encoded digital data over the assigned first portion to/from the first user and over the assigned second portion to/from the second user.
Abstract:
Embodiments include a method for downloading data (e.g., audio files, video files, etc.) to a router. In some embodiments, the method includes receiving, via a web server residing in the router, information identifying data to be downloaded over a network from a remote device. The method can also include initiating operations for downloading the data from the remote device. The method can also include receiving, in the router, data packets from the network, where some of the data packets include portions of the data. The method can also include identifying those data packets that include data portions, and extracting the data portions. The method can also include combining the data portions to form a data file, and storing the data file in the router.
Abstract:
In one embodiment, methods are described for recovering lost customer premises equipment (CPE) information on a cable modem termination system (CMTS) in the presence of only Dynamic Host Control Protocol Version 6 (DHCPv6) CONFIRM. A CMTS purges routing information for an Internet Protocol Version 6 (IPv6) node, such as a CPE router, in response to detecting an interface reset for the IPv6 node. IPv6 addresses and prefixes information for the IPv6 node is gleaned from a DHCPv6 CONFIRM message received from the IPv6 node. By sending portions of the IPv6 addresses and prefixes information within a DHCPv6 LEASEQUERY message, a DHCPv6 CONFIRM message with an embedded DHCPv6 LEASEQUERY message, or a DHCPv6 CONFIRM message with an Interface-ID option, a reply message can be received that contains the purged routing information for the IPv6 node.
Abstract:
A system, method and device provide passive operation mode and noise management. The system, in one embodiment, includes power loss bypass and upstream noise management. Cable television (CATV) networks supply high frequency "downstream" signals from a main signal distribution facility, known as a "headend," through the CATV network infrastructure, to the homes and offices of subscribers.