会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • Method and apparatus providing distributed authorization management of communication sessions
    • 提供通信会话的分布式授权管理的方法和装置
    • US07028073B1
    • 2006-04-11
    • US10051834
    • 2002-01-16
    • Sonny BuiDavid CatesPauline ChenTerry KerstetterJohn KnightKavita Shekhar PatilThomas Anthony Roden
    • Sonny BuiDavid CatesPauline ChenTerry KerstetterJohn KnightKavita Shekhar PatilThomas Anthony Roden
    • G06F15/16
    • H04L63/10H04L67/14H04L67/22H04L69/329
    • A mechanism for authorizing a data communication session between a client and a first server is disclosed. When a request is received to establish a session with a particular entity that is associated with the client, it is determined whether authorization of the session can be performed locally at a second server. If it is determined that authorization of the session can be performed locally at the second server then, the first server is informed that the session may be established between the client and the first server for the particular entity. A third server that is associated with the particular entity is identified and once the first server is informed that the session may be established, the third server is informed that the session has been authorized to be established for the particular entity. However, if authorization of the session cannot be performed locally at the second server then, the third server is requested to authorize the session between the client and the first server. Thereafter, based on the response that is received from the third server, the first server is informed as to whether the session may be authorized.
    • 公开了一种用于授权客户端和第一服务器之间的数据通信会话的机制。 当接收到与与客户端相关联的特定实体建立会话的请求时,确定是否可以在第二服务器本地执行会话的授权。 如果确定可以在第二服务器本地执行会话的授权,则通知第一服务器可以在客户端和特定实体的第一服务器之间建立会话。 识别与特定实体相关联的第三服务器,并且一旦通知第一服务器可以建立会话,则通知第三服务器该会话已被授权为该特定实体建立。 然而,如果会话的授权不能在第二服务器本地执行,则请求第三服务器授权客户端和第一服务器之间的会话。 此后,基于从第三服务器接收到的响应,通知第一服务器是否该会话被授权。
    • 2. 发明授权
    • Mechanism for authorizing a data communication session between a client and a server
    • 授权客户端和服务器之间的数据通信会话的机制
    • US06412007B1
    • 2002-06-25
    • US09231926
    • 1999-01-14
    • Sonny BuiDavid CatesPauline ChenTerry KerstetterJohn KnightKavita Shekhar PatilThomas Anthony Roden
    • Sonny BuiDavid CatesPauline ChenTerry KerstetterJohn KnightKavita Shekhar PatilThomas Anthony Roden
    • G06F1516
    • H04L63/10H04L67/14H04L67/22H04L69/329
    • A mechanism for authorizing a data communication session between a client and a first server is disclosed. When a request is received to establish a session with a particular entity that is associated with the client, it is determined whether authorization of the session can be performed locally at a second server. If it is determined that authorization of the session can be performed locally at the second server then, the first server is informed that the session may be established between the client and the first server for the particular entity. A third server that is associated with the particular entity is identified and once the first server is informed that the session may be established, the third server is informed that the session has been authorized to be established for the particular entity. However, if authorization of the session cannot be performed locally at the second server then, the third server is requested to authorize the session between the client and the first server. Thereafter, based on the response that is received from the third server, the first server is informed as to whether the session may be authorized.
    • 公开了一种用于授权客户端和第一服务器之间的数据通信会话的机制。 当接收到与与客户端相关联的特定实体建立会话的请求时,确定是否可以在第二服务器本地执行会话的授权。 如果确定可以在第二服务器本地执行会话的授权,则通知第一服务器可以在客户端和特定实体的第一服务器之间建立会话。 识别与特定实体相关联的第三服务器,并且一旦通知第一服务器可以建立会话,则通知第三服务器该会话已被授权为该特定实体建立。 然而,如果会话的授权不能在第二服务器本地执行,则请求第三服务器授权客户端和第一服务器之间的会话。 此后,基于从第三服务器接收到的响应,通知第一服务器是否该会话被授权。
    • 4. 发明授权
    • Distributed database system with authoritative node
    • 具有权威节点的分布式数据库系统
    • US06571287B1
    • 2003-05-27
    • US10166623
    • 2002-06-10
    • John KnightThomas Anthony RodenDarrell Myers Shively, IIPauline ChenKavita Shekhar PatilSonny Bui
    • John KnightThomas Anthony RodenDarrell Myers Shively, IIPauline ChenKavita Shekhar PatilSonny Bui
    • G06F1100
    • H04L63/10
    • An authorizing apparatus for use with a client that connects to a first server in a network includes a second server that authorizes session requests of the client for the first server. Resource allocation data is available to the second server and indicates whether a session may be established between the client and the first server. The second server has information that associates an entity that is associated with one or more clients, and information that associates the second server to a third server that is authoritative for the second server and the associated clients. When a request to establish a session between the client and the first server is received, the second server determines, based on one of the records that is associated with the client, whether the session may be established when the client is associated with the entity. If not, the second server requests a global authorization server to determine whether a session is allowable. As a result, session management is resolved locally when possible, and over-subscription of clients to servers is prevented.
    • 用于与网络中的第一服务器连接的客户端使用的授权装置包括授权客户端针对第一服务器的会话请求的第二服务器。 资源分配数据可用于第二服务器,并且指示是否可以在客户端和第一服务器之间建立会话。 第二服务器具有将与一个或多个客户端相关联的实体关联的信息以及将第二服务器与对于第二服务器和关联的客户端具有权威性的第三服务器相关联的信息。 当接收到在客户机和第一服务器之间建立会话的请求时,第二服务器基于与客户端相关联的记录之一来确定当客户端与实体相关联时是否可以建立会话。 如果没有,则第二服务器请求全局授权服务器来确定会话是否被允许。 因此,会话管理在可能的情况下在本地解决,并且客户端对服务器的超额订购被阻止。
    • 6. 发明授权
    • Automatic hardware failure detection and recovery for distributed max sessions server
    • 分布式最大会话服务器的自动硬件故障检测和恢复
    • US07272649B1
    • 2007-09-18
    • US09410511
    • 1999-09-30
    • Darrell Myers Shively, IIJohn KnightKavita Shekhar PatilPauline Chen BoydSonny BuiThomas Anthony Roden
    • Darrell Myers Shively, IIJohn KnightKavita Shekhar PatilPauline Chen BoydSonny BuiThomas Anthony Roden
    • G06F15/173
    • G06F11/0751G06F11/0709H04L43/16H04L63/0892H04L67/14H04L69/40
    • A Max Sessions Server (MSS) automatically detects hardware and communications failures. Upon detection, counters are adjusted accordingly to maintain an accurate count of users or groups of users on a system. A database of unique identifiers for each connection is maintained, where the unique identifier is a concatenation of a Network Access Server (NAS) and the connection's incoming NAS node number. If a user requests permission to log into the system, the MSS first checks the database to determine if the unique identifier is already logged in. If so, then a hardware or communications failure has occurred and the MSS must make the appropriate adjustments to the database and counter. Additionally, the MSS or an authentication, authorization and accounting (AAA) server will periodically check to determine if an NAS has ceased communicating over a particular length of time and relay any failures to the MSS. If the NAS has experienced a hardware or communications failure, then the MSS must make the appropriate adjustments to the database and counters for all sessions logged in from the failed NAS. Finally, the MSS may broadcast the failure to all MSSs associated with the NAS on the system.
    • 最大会话服务器(MSS)自动检测硬件和通信故障。 检测后,相应地调整计数器,以便在系统上维持用户或用户组的准确计数。 维护每个连接的唯一标识符的数据库,其中唯一标识符是网络访问服务器(NAS)和连接的传入NAS节点号码的级联。 如果用户请求登录系统的权限,则MSS首先检查数据库以确定唯一标识符是否已经登录。如果是,则发生硬件或通信故障,并且MSS必须对数据库进行适当的调整 和柜台。 此外,MSS或认证,授权和计费(AAA)服务器将定期检查以确定NAS是否已停止在特定时间长度的通信,并将任何故障中继到MSS。 如果NAS遇到硬件或通信故障,则MSS必须对从NAS发起的所有会话进行数据库和计数器的适当调整。 最后,MSS可以将故障广播到与系统上的NAS相关联的所有MSS。
    • 7. 发明授权
    • Distributed database system with authoritative node
    • 具有权威节点的分布式数据库系统
    • US06442608B1
    • 2002-08-27
    • US09231929
    • 1999-01-14
    • John KnightThomas Anthony RodenDarrell Myers Shively, IIPauline ChenKavita Shekhar PatilSonny Bui
    • John KnightThomas Anthony RodenDarrell Myers Shively, IIPauline ChenKavita Shekhar PatilSonny Bui
    • G06F15173
    • H04L63/10
    • An authorizing apparatus for use with a client that connects to a first server in a network is described. The authorizing apparatus includes a second server that authorizes session requests of the client for the first server. A plurality of records of resource allocation data is coupled with the second server. Each record indicates whether a session may be established between the client and the first server. Coupled to the second server is information that associates an entity that includes and is associated with one or more clients, and information that associates the second server to a third server that is authoritative for the second server and the associated clients. Means are provided for receiving a request to establish a session between the client and the first server and for determining, at the second server, based on one of the records that is associated with the client, whether the session may be established when the client is associated with the entity. Also provided are means for informing the first server that the session is authorized only when the second server determines from the one of the records that the session may be established. Although the first, second and third servers have been described as separate servers the functions performed by two or more of the servers may actually be combined in a single server unit.
    • 描述了一种与连接到网络中的第一服务器的客户端一起使用的授权装置。 授权装置包括授权客户端针对第一服务器的会话请求的第二服务器。 资源分配数据的多个记录与第二服务器耦合。 每个记录指示是否可以在客户端和第一个服务器之间建立会话。 耦合到第二服务器的是将包括并与一个或多个客户端相关联的实体关联的信息,以及将第二服务器与对于第二服务器和相关联的客户端具有权威性的第三服务器相关联的信息。 提供了用于接收在客户端和第一服务器之间建立会话的请求的装置,并且用于在第二服务器处,基于与客户端相关联的记录中的一个来确定该会话是否可以在客户端是 与实体相关联。 还提供了用于通知第一服务器仅当第二服务器从记录中的一个确定会话可被建立时才允许该会话被授权的装置。 虽然第一,第二和第三服务器已经被描述为单独的服务器,但是由两台或多台服务器执行的功能实际上可以组合在单个服务器单元中。
    • 9. 发明授权
    • Disconnect policy for distributed computing systems
    • 断开分布式计算系统的策略
    • US06412077B1
    • 2002-06-25
    • US09231920
    • 1999-01-14
    • Thomas Anthony RodenJohn KnightDavid Cates
    • Thomas Anthony RodenJohn KnightDavid Cates
    • G06F1100
    • H04L67/141H04L63/102H04L67/14H04L67/32
    • A mechanism for performing a disconnect policy involving authorizing a data communication session between a client and a first server is disclosed. The mechanism provides a failover scheme in which local servers record the number of active sessions that they have authorized for a particular user entity. Each user entity is assigned an authoritative server. The authoritative servers maintain global session information for each user entity in which they are assigned. When a local server cannot authorize a session for a particular user entity the local server communicates with the authoritative server to determine whether a session should be established for the user entity. If communication is lost between a local server and an authoritative server, the local server assumes that no other servers have authorized active sessions for the particular user entity. In a similar manner, the authoritative server assumes that the local server has not authorized any active sessions for the particular entity. Thus, both the local server and the authoritative server may independently authorize sessions for the user entity. When communication is re-established between the local server and the authoritative server, the servers exchange information to recreate the current state. If it is determined that too many active sessions have been established for user entity, further authorization requests from the user entity are denied until the number of active sessions is reduced below an acceptable level. This, failover scheme removes the need for redundant servers and instead distributes the burden of redundancy to the local servers where communication problems are far less likely to occur.
    • 公开了一种用于执行涉及授权客户端与第一服务器之间的数据通信会话的断开策略的机制。 该机制提供了一种故障转移方案,其中本地服务器记录他们为特定用户实体授权的活动会话数。 每个用户实体都被分配一个权威服务器。 授权服务器为其分配的每个用户实体维护全局会话信息。 当本地服务器无法为特定用户实体授权会话时,本地服务器与权威服务器进行通信,以确定是否应为用户实体建立会话。 如果本地服务器和授权服务器之间的通信丢失,本地服务器假定没有其他服务器授权特定用户实体的活动会话。 以类似的方式,授权服务器假定本地服务器尚未授权特定实体的任何活动会话。 因此,本地服务器和权威服务器可以独立地授权用户实体的会话。当本地服务器和权威服务器之间重新建立通信时,服务器交换信息以重新创建当前状态。 如果确定为用户实体建立了太多的活动会话,则拒绝来自用户实体的进一步的授权请求,直到活动会话的数量减少到可接受的水平以下。 这种故障切换方案不再需要冗余服务器,而是将冗余负担分配给本地服务器,因为这些服务器的通信问题不太可能发生。
    • 10. 发明授权
    • Method and apparatus for identifying a data communications session
    • 用于识别数据通信会话的方法和装置
    • US06742126B1
    • 2004-05-25
    • US09414386
    • 1999-10-07
    • Joseph F. MannMingqi DengThomas Anthony Roden
    • Joseph F. MannMingqi DengThomas Anthony Roden
    • G06F1130
    • H04L63/08H04L63/102
    • A method and apparatus for using a session identifier to identify a specific data communications session between an apparatus and an external apparatus is disclosed. When a data communications session is initiated between the apparatus and an external apparatus, the external apparatus sends authenticating information to the apparatus. The apparatus uses the authenticating information to determine the identity and the privileges of the external apparatus for the particular session. A unique session identifier is created by the apparatus, and the session identifier is associated with the external apparatus's identity and privileges. The session identifier is passed between the apparatus and the external apparatus with each subsequent data communication in the session until the session is terminated. The apparatus uses the session identifier received with the data communications to identify the external apparatus and its privileges and allocate resources accordingly. The session identifier is encoded using a six bit code, thereby making it compatible with the Internet e-mail protocol and while also optimizing data compression. The encoded session identifier may be transmitted by appending it to a URL like a query string.
    • 公开了一种使用会话标识符来识别设备和外部设备之间的特定数据通信会话的方法和装置。 当在设备和外部设备之间启动数据通信会话时,外部设备向设备发送认证信息。 该设备使用认证信息来确定特定会话的外部设备的身份和特权。 该设备创建唯一的会话标识符,并且会话标识符与外部设备的身份和特权相关联。 会话标识符在设备和外部设备之间通过会话中的每个后续数据通信直到会话终止。 该装置使用与数据通信接收的会话标识符来识别外部设备及其特权并相应地分配资源。 会话标识符使用六位代码进行编码,从而使其与Internet电子邮件协议兼容,同时优化数据压缩。 可以通过将编码的会话标识符附加到诸如查询字符串的URL来发送。