会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明申请
    • Method of providing an encrypted multipoint VPN service
    • 提供加密多点VPN服务的方法
    • US20070115990A1
    • 2007-05-24
    • US11284951
    • 2005-11-22
    • Rajiv AsatiMohamed KhalidHaseeb NiaziVijay Bollapragada
    • Rajiv AsatiMohamed KhalidHaseeb NiaziVijay Bollapragada
    • H04L12/56H04J3/24
    • H04L45/00H04L63/0272H04L63/164
    • A method, apparatus and computer program product for providing an encrypted multipoint Virtual Private Network (VPN) service is presented. A first packet of a plurality of packets is received at an ingress provider edge (PE) the plurality of packets destined for a remote server in communication with said egress PE router. A lookup for a destination prefix of a first packet is preformed, and a determination made that a next-hop for the first packet is reachable through a mGRE tunnel. A resolution request is sent to a hub to acquire a routable IP address. The packets sent to the hub are encapsulated, and encrypting until a resolution reply is received and until security associations (SAs) have been exchanged. Then a VPN is established between the ingress and egress PEs and is used for all subsequent packets.
    • 提出了一种用于提供加密的多点虚拟专用网(VPN)服务的方法,装置和计算机程序产品。 多个分组的第一分组在入口提供商边缘(PE)处接收去往与所述出口PE路由器通信的远程服务器的多个分组。 执行对第一分组的目的地前缀的查找,并且确定通过mGRE隧道可以达到第一分组的下一跳。 将解析请求发送到集线器以获取可路由的IP地址。 发送到集线器的数据包被封装,并进行加密,直到收到解决回复,直到交换安全关联(SA)为止。 然后在入口和出口PE之间建立VPN,并用于所有后续数据包。
    • 4. 发明授权
    • Method of providing an encrypted multipoint VPN service
    • 提供加密多点VPN服务的方法
    • US07590123B2
    • 2009-09-15
    • US11284951
    • 2005-11-22
    • Rajiv AsatiMohamed KhalidHaseeb NiaziVijay Bollapragada
    • Rajiv AsatiMohamed KhalidHaseeb NiaziVijay Bollapragada
    • H04J3/16H04J3/22H04L12/28H04L12/56
    • H04L45/00H04L63/0272H04L63/164
    • A method, apparatus and computer program product for providing an encrypted multipoint Virtual Private Network (VPN) service is presented. A first packet of a plurality of packets is received at an ingress provider edge (PE) the plurality of packets destined for a remote server in communication with said egress PE router. A lookup for a destination prefix of a first packet is preformed, and a determination made that a next-hop for the first packet is reachable through a mGRE tunnel. A resolution request is sent to a hub to acquire a routable IP address. The packets sent to the hub are encapsulated, and encrypting until a resolution reply is received and until security associations (SAs) have been exchanged. Then a VPN is established between the ingress and egress PEs and is used for all subsequent packets.
    • 提出了一种用于提供加密的多点虚拟专用网(VPN)服务的方法,装置和计算机程序产品。 多个分组的第一分组在入口提供商边缘(PE)处接收去往与所述出口PE路由器通信的远程服务器的多个分组。 执行对第一分组的目的地前缀的查找,并且确定通过mGRE隧道可以达到第一分组的下一跳。 将解析请求发送到集线器以获取可路由的IP地址。 发送到集线器的数据包被封装,并进行加密,直到收到解决回复,直到交换安全关联(SA)为止。 然后在入口和出口PE之间建立VPN,并用于所有后续数据包。
    • 5. 发明申请
    • Methods and apparatus for tunnel stitching in a network
    • 网络中隧道拼接的方法和装置
    • US20070248091A1
    • 2007-10-25
    • US11409586
    • 2006-04-24
    • Mohamed KhalidRajiv AsatiVijay BollapragadaSunil Cherukuri
    • Mohamed KhalidRajiv AsatiVijay BollapragadaSunil Cherukuri
    • H04L12/56
    • H04L63/0272H04L63/029H04L63/061
    • An edge router (disposed between a packet-switched network and a label-switching network) is configured to receive an IKE message originating from a client on the Internet (e.g., packet-switched network) attempting to set up a tunnel. Upon receipt of the IKE message, the edge router utilizes a unique identifier in the IKE message to identify a virtual private network in the label-switching network. In lieu of terminating an IPSec tunnel at the edge router and performing a respective key exchange with the client, the edge router identifies a corresponding forwarding table associated with the virtual private network (identified by the unique identifier in the IKE message) and, based on the corresponding forwarding table, forwards the IKE message to a destination reachable via the label-switching network. The destination (e.g., a key server in a corresponding VPN) communicates with the client through the edge router to set up the tunnel.
    • 边缘路由器(布置在分组交换网络和标签交换网络之间)被配置为接收来自尝试建立隧道的因特网上的客户端(例如,分组交换网络)的IKE消息。 在接收到IKE消息时,边缘路由器利用IKE消息中的唯一标识符来标识标签交换网络中的虚拟专用网络。 边缘路由器代替在边缘路由器上终止IPSec隧道并与客户端进行相应的密钥交换,从而识别与虚拟专用网络相关联的对应转发表(由IKE消息中的唯一标识符标识),并且基于 相应的转发表,将IKE消息转发到可通过标签交换网络到达的目的地。 目的地(例如,对应的VPN中的密钥服务器)通过边缘路由器与客户端进行通信,以建立隧道。