会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 21. 发明申请
    • Granting privileges and sharing resources in a telecommunications system
    • 在电信系统中授予权限和共享资源
    • US20070073880A1
    • 2007-03-29
    • US11239494
    • 2005-09-29
    • Anjur KrishnakumarP. KrishnanVenkatesh Krishnaswamy
    • Anjur KrishnakumarP. KrishnanVenkatesh Krishnaswamy
    • G06F15/173
    • H04L63/0807H04L63/102
    • A method and an apparatus are disclosed that provide a privilege-granting technique for enabling a service-providing domain to grant a privilege to a requesting user in a service-requesting domain. A request handler in the service-providing domain, which comprises one or more service-associated resources, receives a user request to use a service and requests a token from a privilege-granting server, in accordance with the illustrative embodiment of the present invention. Upon receiving the token that specifies a granted privilege from the privilege-granting server, the request handler extends the privilege to the requesting user. Alternatively, the request handler can request a plurality of tokens in advance from the privilege-granting server; after receiving the tokens, the request handler extends a privilege to each requesting user as the handler receives requests to use one or more services.
    • 公开了一种方法和装置,其提供授权授权技术,用于使服务提供域能够向服务请求域中的请求用户授予特权。 根据本发明的说明性实施例,服务提供域中的包括一个或多个服务相关资源的请求处理程序接收使用服务的用户请求并从特权授予服务器请求令牌。 在从授权授权服务器接收到指定授权特权的令牌之后,请求处理程序将权限扩展到请求用户。 或者,请求处理程序可以从特权授予服务器预先请求多个令牌; 在接收到令牌之后,请求处理程序在处理程序接收到使用一个或多个服务的请求时,将权限扩展到每个请求用户。
    • 22. 发明申请
    • Rapid fault detection and recovery for internet protocol telephony
    • 互联网协议电话快速故障检测和恢复
    • US20050281204A1
    • 2005-12-22
    • US10953024
    • 2004-09-29
    • Mark KarolP. KrishnanJuan Li
    • Mark KarolP. KrishnanJuan Li
    • H04L12/26H04L12/56H04L12/66H04L29/14
    • H04L43/50H04L43/10H04L65/80H04L69/40
    • Techniques for performing rapid fault detection and recovery in communication networks are disclosed. For example, in one aspect of the invention, a technique for detecting one or more conditions in a communication network comprises the following steps/operations. One or more keep-alive packets are transmitted from a source node in the communication network to a destination node in the communication network over two or more paths between the source node and the destination node, wherein the two or more paths are at least partially disjoint. Upon receipt of the one or more keep-alive packets at the destination node via the two or more paths, at least one quality measure is computed at the destination node for each of the two or more paths, the at least one quality measure being indicative of one or more conditions in the communication network. While not limited thereto, the invention is particularly well-suited to Internet Protocol (IP) telephony networks, particularly those that provide Voice over IP (VoIP) applications.
    • 公开了在通信网络中执行快速故障检测和恢复的技术。 例如,在本发明的一个方面,用于检测通信网络中的一个或多个条件的技术包括以下步骤/操作。 一个或多个保持活动分组从通信网络中的源节点通过源节点和目的地节点之间的两个或多个路径发送到通信网络中的目的地节点,其中两个或更多个路径至少部分地不相交 。 经由两个或多个路径在目的地节点处接收到一个或多个保持活动分组时,在目的地节点处针对两个或更多个路径中的每一个计算至少一个质量度量,所述至少一个质量度量指示 通信网络中的一个或多个条件。 虽然不限于此,本发明特别适用于因特网协议(IP)电话网络,特别是那些提供IP语音(VoIP)应用的电话网络。
    • 24. 发明申请
    • Method and apparatus for content based authentication for network access
    • 用于网络访问的基于内容的身份验证的方法和装置
    • US20050111466A1
    • 2005-05-26
    • US10721721
    • 2003-11-25
    • Martin KappesP. Krishnan
    • Martin KappesP. Krishnan
    • H04L29/06H04L12/28G06F15/173H04M3/16
    • H04L63/08H04L63/0876H04W12/06
    • A method and apparatus are provided for authenticating the contents of a device requesting access to a first network, such as an enterprise network. If a device has connected to at least one other network then the content of the device is evaluated prior to obtaining access. The scope of the content evaluation may be based, for example, on properties of the other network or on one or more defined content authentication rules. If a device attempts to access a network, the content of the device is evaluated and the device may be restricted to accessing only one or more restoration services if the content fails to satisfy one or more predefined criteria, such as a content item that is out of date or a determination that the device connected to one or more external networks. The restoration service(s) can update a content item that is out of date, reinstall one or more programs or return configuration settings to default values.
    • 提供了一种用于认证请求接入诸如企业网络的第一网络的设备的内容的方法和装置。 如果设备已经连接到至少一个其他网络,则在获得访问之前对设备的内容进行评估。 内容评估的范围可以例如基于另一网络的属性或基于一个或多个定义的内容认证规则。 如果设备尝试访问网络,则评估设备的内容,并且如果内容不能满足一个或多个预定义的标准(例如,出口的内容项目),则设备可能被限制为仅访问一个或多个恢复服务 或确定设备连接到一个或多个外部网络。 恢复服务可以更新过期的内容项目,重新安装一个或多个程序或将配置设置返回到默认值。
    • 25. 发明授权
    • Adaptive re-ordering of data packet filter rules
    • 数据包过滤规则的自适应重排序
    • US06606710B2
    • 2003-08-12
    • US10179460
    • 2002-06-24
    • P. KrishnanDanny RazBinay Sugla
    • P. KrishnanDanny RazBinay Sugla
    • G06F1130
    • H04L63/0227H04L63/0263
    • A packet data filter which stores ordered rules and sequentially applies the rules to received data packets to determine the disposition of the data packet. The packet filter maintains a match count in memory which indicates the number of times each rule matched an incoming data packet. Periodically, at the initiation of a user, or based on operating parameters of the filter, the rules are automatically re-ordered based on the match count. As a result of the re-ordering, rules with higher match counts are moved earlier in the sequential evaluation order and rules with lower match counts are moved later in the sequential evaluation order. As such, rules which are more likely to match incoming data packets are evaluated earlier, thus avoiding the evaluation of later rules. In order to prevent a re-ordering which would change the overall security policy of the packet filter, pairs of rules are compared to determine if they conflict (i.e., the swapping of the two rules would result in a change in the overall security policy). During re-ordering, the swapping of conflicting rules is prevented.
    • 分组数据过滤器,其存储有序规则,并且将规则顺序地应用于接收的数据分组,以确定数据分组的配置。 分组过滤器在内存中保持匹配计数,其指示每个规则与输入数据分组匹配的次数。 定期地,在用户开始时,或者基于过滤器的操作参数,基于匹配计数自动重新排序规则。 作为重新排序的结果,具有较高匹配计数的规则在顺序评估顺序中被更早地移动,并且具有较低匹配计数的规则将在顺序评估顺序中稍后移动。 因此,较早地评估更有可能匹配传入数据分组的规则,从而避免对稍后规则的评估。 为了防止重新排序,这将改变分组过滤器的整体安全策略,将比较对规则来确定它们是否冲突(即,两个规则的交换将导致总体安全策略的改变) 。 在重新订购期间,阻止了冲突规则的交换。
    • 27. 发明授权
    • Method and apparatus for content based authentication for network access
    • 用于网络访问的基于内容的身份验证的方法和装置
    • US07752320B2
    • 2010-07-06
    • US10721721
    • 2003-11-25
    • Martin KappesP. Krishnan
    • Martin KappesP. Krishnan
    • G06F15/16
    • H04L63/08H04L63/0876H04W12/06
    • A method and apparatus are provided for authenticating the contents of a device requesting access to a first network, such as an enterprise network. If a device has connected to at least one other network then the content of the device is evaluated prior to obtaining access. The scope of the content evaluation may be based, for example, on properties of the other network or on one or more defined content authentication rules. If a device attempts to access a network, the content of the device is evaluated and the device may be restricted to accessing only one or more restoration services if the content fails to satisfy one or more predefined criteria, such as a content item that is out of date or a determination that the device connected to one or more external networks. The restoration service(s) can update a content item that is out of date, reinstall one or more programs or return configuration settings to default values.
    • 提供了一种用于认证请求接入诸如企业网络的第一网络的设备的内容的方法和装置。 如果设备已经连接到至少一个其他网络,则在获得访问之前对设备的内容进行评估。 内容评估的范围可以例如基于另一网络的属性或基于一个或多个定义的内容认证规则。 如果设备尝试访问网络,则评估设备的内容,并且如果内容不能满足一个或多个预定义的标准(例如,出口的内容项目),则设备可能被限制为仅访问一个或多个恢复服务 或确定设备连接到一个或多个外部网络。 恢复服务可以更新过期的内容项目,重新安装一个或多个程序或将配置设置返回到默认值。
    • 29. 发明申请
    • Evaluating quality of service in an IP network with cooperating relays
    • 用合作继电器评估IP网络中的服务质量
    • US20070081460A1
    • 2007-04-12
    • US11329933
    • 2006-01-11
    • Bengi Karacali-AkyamacMark KarolAnjur KrishnakumarP. KrishnanJean Meloche
    • Bengi Karacali-AkyamacMark KarolAnjur KrishnakumarP. KrishnanJean Meloche
    • H04L12/26
    • H04L45/26H04L41/5038H04L43/12H04L45/00H04L47/11H04L47/24
    • A technique is disclosed that evaluates a network path between (i) a first node in a first subnetwork of endpoint nodes, such as IP phones, and (ii) a second node in a second subnetwork. A “ricochet” node in the network path evaluates the path by probing one or both subnetworks, where the ricochet node acts as relay for traffic packets being transmitted between the two subnetworks. A given relay has only to probe a single, representative node within a subnetwork at any given time in order to obtain performance data that is representative of the subnetwork overall. By probing the representative node, the relay is able to acquire an assessment of network conditions that is valid for the path between the relay and any endpoint in the subnetwork. As a result, the disclosed technique reduces the probing overhead when many endpoint nodes on a given subnetwork are simultaneously active and experiencing adverse network conditions.
    • 公开了一种技术,其评估(i)端点节点的第一子网络中的第一节点(例如IP电话)和(ii)第二子网络中的第二节点之间的网络路径。 网络路径中的“弹射”节点通过探测一个或两个子网络来评估路径,其中弹性节点用作在两个子网络之间传输的业务分组的中继。 给定的中继只能在任何给定的时间探测子网内的单个代表性节点,以获得代表子网的性能数据。 通过探测代表节点,中继器能够获取对于继电器和子网中的任何端点之间的路径有效的网络条件的评估。 因此,所公开的技术减少了给定子网上的许多端点节点同时处于活动状态并且经历不利的网络条件时的探测开销。