会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 4. 发明授权
    • Method and apparatus for application-independent end-to-end security in shared-link access networks
    • 共享链路接入网络中与应用无关的端到端安全性的方法和装置
    • US06963982B1
    • 2005-11-08
    • US09698978
    • 2000-10-27
    • Jose′ C. BrustoloniJuan Alberto Garay
    • Jose′ C. BrustoloniJuan Alberto Garay
    • H04L9/00H04L29/06H04L29/12
    • H04L29/12009H04L29/12377H04L29/12462H04L29/125H04L29/12556H04L61/2517H04L61/255H04L61/2564H04L61/2585H04L63/029H04L63/164
    • Clients that are connected on a private network and which are assigned a private IP address that is not routable on the Internet can connect to the Internet through a router/server that includes a network address translator (NAT). For outgoing packets, the NAT translates the client's private source IP address and generalized port number (GPN) to the NAT's global IP address and GPN. For incoming packets sent to the NAT's global IP address and GPN, the NAT translates the global destination IP address and GPN to the client's private IP address and GPN. For protocols which cannot be directly supported by the NAT, such as those in the IPSec security protocol suite, the NAT is extended by creating in the NAT's translation table an entry that associates, for a specific unsupported protocol, a client's private IP address and GPN, the NAT's global IP address and GPN, and a foreign address on the Internet, that is valid until a specified or default expiration time. Outgoing packets from the client to that foreign address and incoming packets from that foreign address to the NAT's global IP address and GPN are translated according to the entry until the entry expires. In associations with these translations to outgoing and incoming packets, the client implements any Application Layer Gateway (ALG) that would otherwise be implemented at the NAT. Further, at the client, outgoing packets are modified before being transmitted so as to pre-compensate for the effects of the translations. Incoming packets at the client from the NAT are similarly modified so as to post-compensate for the effects of the translations. For the IPSec protocol, these modification include adjusting the checksum in the TCP or UDP header to account for IP address and TCP or UDP port number translations.
    • 连接在专用网络上且被分配了Internet上不可路由的私有IP地址的客户端可以通过包含网络地址转换器(NAT)的路由器/服务器连接到Internet。 对于出站数据包,NAT将客户端的私有IP地址和广义端口号(GPN)转换为NAT的全局IP地址和GPN。 对于发送到NAT的全局IP地址和GPN的传入数据包,NAT将全局目标IP地址和GPN转换为客户端的私有IP地址和GPN。 对于NAT不能直接支持的协议(如IPSec安全协议套件中的协议),通过在NAT的转换表中创建一个条目来扩展NAT,对于特定的不支持的协议,客户端的私有IP地址和GPN ,NAT的全球IP地址和GPN以及互联网上的外部地址,直到指定或默认的到期时间才有效。 从客户端到该外部地址的传出数据包以及从该外部地址到NAT的全局IP地址和GPN的传入数据包将根据条目进行转换,直到条目到期为止。 在将这些转换与传出和传入的数据包相关联时,客户端将实现否则将在NAT处实现的任何应用层网关(ALG)。 此外,在客户端,传出的数据包被修改,然后被传输,以便预先补偿翻译的效果。 来自NAT的客户端的传入数据包也进行了类似的修改,以补偿翻译的效果。 对于IPSec协议,这些修改包括调整TCP或UDP报头中的校验和,以考虑IP地址和TCP或UDP端口号转换。
    • 5. 发明授权
    • Method and apparatus for extending network address translation for unsupported protocols
    • 用于扩展不支持协议的网络地址转换的方法和装置
    • US06886103B1
    • 2005-04-26
    • US09698973
    • 2000-10-27
    • Jose C. BrustoloniJuan Alberto Garay
    • Jose C. BrustoloniJuan Alberto Garay
    • H04L9/00H04L29/06H04L29/12
    • H04L29/12009H04L29/12377H04L29/12462H04L29/125H04L29/12556H04L29/12924H04L61/2517H04L61/255H04L61/2564H04L61/2585H04L61/6063H04L63/0428H04L63/164
    • Clients that are connected on a private network and which are assigned a private IP address that is not routable on the Internet can connect to the Internet through a router/server that includes a network address translator (NAT). For outgoing packets, the NAT translates the client's private source IP address and generalized port number (GPN) to the NAT's global IP address and GPN. For incoming packets sent to the NAT's global IP address and GPN, the NAT translates the global destination IP address and GPN to the client's private IP address and GPN. For protocols which cannot be directly supported by the NAT, such as those in the IPSec security protocol suite, the NAT is extended by creating in the NAT's translation table an entry that associates, for a specific unsupported protocol, a client's private IP address and GPN, the NAT's global IP address and GPN, and a foreign address on the Internet, that is valid until a specified or default expiration time. Outgoing packets from the client to that foreign address and incoming packets from that foreign address to the NAT's global IP address and GPN are translated according to the entry until the entry expires. In associations with these translations to outgoing and incoming packets, the client implements any Application Layer Gateway (ALG) that would otherwise be implemented at the NAT. Further, at the client, outgoing packets are modified before being transmitted so as to pre-compensate for the effects of the translations. Incoming packets at the client from the NAT are similarly modified so as to post-compensate for the effects of the translations. For the IPSec protocol, these modification include adjusting the checksum in the TCP or UDP header to account for IP address and TCP or UDP port number translations.
    • 连接在专用网络上且被分配了Internet上不可路由的私有IP地址的客户端可以通过包含网络地址转换器(NAT)的路由器/服务器连接到Internet。 对于出站数据包,NAT将客户端的私有IP地址和广义端口号(GPN)转换为NAT的全局IP地址和GPN。 对于发送到NAT的全局IP地址和GPN的传入数据包,NAT将全局目标IP地址和GPN转换为客户端的私有IP地址和GPN。 对于NAT不能直接支持的协议(如IPSec安全协议套件中的协议),通过在NAT的转换表中创建一个条目来扩展NAT,对于特定的不支持的协议,客户端的私有IP地址和GPN ,NAT的全球IP地址和GPN以及互联网上的外部地址,直到指定或默认的到期时间才有效。 从客户端到该外部地址的传出数据包以及从该外部地址到NAT的全局IP地址和GPN的传入数据包将根据条目进行转换,直到条目到期为止。 在将这些转换与传出和传入的数据包相关联时,客户端将实现否则将在NAT处实现的任何应用层网关(ALG)。 此外,在客户端,传出的数据包被修改,然后被传输,以便预先补偿翻译的效果。 来自NAT的客户端的传入数据包也进行了类似的修改,以补偿翻译的效果。 对于IPSec协议,这些修改包括调整TCP或UDP报头中的校验和,以考虑IP地址和TCP或UDP端口号转换。