Authentication sharing in a firewall cluster
42 claims: 17 independent, 25 dependent
- 1ファイアウォールクラスターを動作させる方法であって、 3つ以上のノードを有する前記ファイアウォールクラスターの うち、ファイアウォールタスクを実行する 第1のノードにおいて接続 要求 を受信することと、 前記接続要求を処理して接続を確立することと、 前記 確立された 接続に関連付けられたユーザーデータを特定することと、 前記ユーザーデータを、前記ファイアウォールクラスター内の少なくとも1つの別のノードと共有することと、 前記第1のノードを再度割り当てることと を含み、 前記第1のノードを再度割り当てることは、 前記第1のノードを、前記ファイアウォールタスクを実行することから侵入保護タスクを実行することに変更することと、 前記第1のノードから前記少なくとも1つの別のノードへ、前記確立された接続をリダイレクトすることと、 前記第1のノードを再度割り当てて、前記侵入保護タスクを実行することと を含み、 前記第1のノードを再度割り当てることは、前記侵入保護タスクを実行するように構成された第2のノードの故障に応じて行われる 、ファイアウォールクラスターを動作させる方法。
- 2前記接続 要求 を受信した後であって、前記ユーザーデータを共有する前に、受信した前記接続 要求 に関する接続情報を前記ファイアウォールクラスター内の 前記 少なくとも1つの別のノードと共有することを更に含む、請求項1に記載のファイアウォールクラスターを動作させる方法。
- 3前記ユーザーデータは、 前記接続要求にそれぞれ関連付けられた ユーザーの識別情報及 びI Pアドレスを含む、請求項1又は2に記載のファイアウォールクラスターを動作させる方法。
- 4前記ユーザーデータを共有することは、前記ユーザーデータを、前記ファイアウォールクラスター内の 複数の 別のノードにブロードキャストすることを含む、請求項1~3のいずれか1項に記載のファイアウォールクラスターを動作させる方法。
- 5前記ユーザーデータを共有することは、前記ユーザーデータをマスターノードに送信することを含む、請求項1~4のいずれか1項に記載のファイアウォールクラスターを動作させる方法。
- 6前記マスターノードが、前記ユーザーデータを前記ファイアウォールクラスター内の他のノードにブロードキャストすることを更に含む、請求項5に記載のファイアウォールクラスターを動作させる方法。
- 7前記 確立された 接続に関連付けられ た 共有された前記ユーザーデータを用いて、前記第1のノードの故障時に別のノードにおいて 対応する後続の確立された 接続をフィルタリングすることを更に含む、請求項1~6のいずれか1項に記載のファイアウォールクラスターを動作させる方法。
- 8前記 確立された 接続に関連付けられ た 共有された前記ユーザーデータを用いて、別のノードにおいて 対応する後続の確立された 接続をフィルタリングし、前記ファイアウォールクラスターにおける負荷分散を提供することを更に含む、請求項1~7のいずれか1項に記載のファイアウォールクラスターを動作させる方法。
- 9ユーザーデータを特定することは、前記確立された接続を形成する前の前記接続要求の処理中に実行される、請求項1に記載のファイアウォールクラスターを動作させる方法。
- 10ファイアウォールクラスターであって、 3つ以上の全てのノードのうち、第1のノードおよび第2のノードを備え、 前記第1のノードは、 前記第1のノードが ファイアウォール タスクを実行している間に、 接続 要求 を受信し、 前記接続要求を処理して第1の接続を確立し、 前記 第1の 接続に関連付けられたユーザーデータを特定し、 前記ユーザーデータを、前記ファイアウォールクラスター内の少なくとも 前記第2 のノードと共有 し 、 前記ファイアウォールタスクを実行することを停止するための命令を受信し、 前記第1の接続のための前記ファイアウォールタスクを実行することを停止し、 侵入保護タスクを実行することを開始するように構成され、 前記第2のノードは、 前記第1の接続に対応する後続の接続を確立し、 共有された前記ユーザーデータを利用して、前記後続の接続のための前記ファイアウォールタスクを実行するように構成され、 前記命令は、前記侵入保護タスクを実行するように構成された第3のノードの故障に応じて受信される、 ファイアウォールクラスター。
- 11前記第1のノードは更に、前記接続 要求 を受信した後であって 、ユ ーザーデータを共有する前に、受信した前記接続 要求 に関する接続情報を前記ファイアウォールクラスター内の 前記第2 のノードと共有するように 構成される 、請求項 10 に記載のファイアウォールクラスター。
- 12ユ ーザーデータは、 前記接続要求にそれぞれ関連付けられた ユーザーの識別情報及 びI Pアドレスを含む、請求項 10 又は 11 に記載のファイアウォールクラスター。
- 13前記ユーザーデータを共有することは、前記ユーザーデータを、前記ファイアウォールクラスター内 の別 のノードにブロードキャストすることを含む、請求項 10 ~ 12 のいずれか1項に記載のファイアウォールクラスター。
- 14マスターノードを更に備え、 前記ユーザーデータを共有することは、前記ユーザーデータを前記マスターノードに送信することを含む、請求項 10 ~ 13 のいずれか1項に記載のファイアウォールクラスター。
- 15前記マスターノードは更に、前記ユーザーデータを前記ファイアウォールクラスター内の他のノードにブロードキャストするように 構成される 、請求項 14 に記載のファイアウォールクラスター。
- 16前記第2のノードは、 前記 第1の 接続に関連付けられ た 共有された前記ユーザーデータを用いて、前記第1のノードの故障時 に前 記 後続の 接続をフィルタリングするように 構成される 、請求項 10 ~ 15 のいずれか1項に記載のファイアウォールクラスター。
- 17前記第2のノードは、 前記 第1の 接続に関連付けられ た 共有された前記ユーザーデータを用いて 、 前記 後続の 接続をフィルタリングし、前記ファイアウォールクラスターにおける負荷分散を提供するように 構成される 、請求項 10 ~ 16 のいずれか1項に記載のファイアウォールクラスター。
- 18コンピュータに、 3つ以上のノードを有するファイアウォールクラスターのうち、ファイアウォールタスクを実行する第1のノードにおいて接続要求を受信する手順と、 前記接続要求を処理して接続を確立する手順と、 前記確立された接続に関連付けられたユーザーデータを特定する手順と、 前記ユーザーデータを、前記ファイアウォールクラスター内の少なくとも1つの別のノードと共有する手順と、 前記第1のノードを再度割り当てることを特定させ、再度割り当てることは、前記第1のノードを、前記ファイアウォールタスクを実行することから侵入保護タスクを実行することに変更する手順と 前記第1のノードから前記少なくとも1つの別のノードに前記確立された接続をリダイレクトする手順と、 前記第1のノードを再度割り当てて、前記侵入保護タスクを実行する手順と を実行させ、 前記第1のノードの再割り当ては、前記侵入保護タスクを実行するように構成された第2のノードの故障に応じて行われる、プログラム。
- 19コンピュータに、 3つ以上のノードを有するファイアウォールクラスターのうち、ファイアウォールタスクを実行する第1のノードで受信された接続要求を処理して接続を確立する手順と、 前記確立された接続を処理するべくバックアップノードにより利用され、前記確立された接続に関連付けられた状態情報を、前記ファイアウォールクラスター内の少なくとも1つの別のノードと共有する手順と、 侵入保護タスクを実行するように構成された第2のノードの故障に応じて、侵入保護タスクを実行すべく前記第1のノードを再度割り当てる手順と を実行させるプログラム。
- 20前記コンピュータに、 前記接続要求を受信した後であって、前記状態情報を共有する前に、受信した前記接続要求に関する接続情報を、前記ファイアウォールクラスター内の少なくとも1つの別のノードと共有する手順を更に実行させる、請求項19に記載のプログラム。
- 21前記状態情報は、前記接続要求にそれぞれ関連付けられたユーザーの識別情報およびIPアドレスを含む、請求項19に記載のプログラム。
- 22前記状態情報を共有する手順は、前記ファイアウォールクラスター内の複数の別のノードに前記状態情報をブロードキャストする手順を含む、請求項19~21のいずれか1項に記載のプログラム。
- 23前記状態情報を共有する手順は、前記バックアップノードに前記状態情報を送信する手順を含む、請求項19~21のいずれか1項に記載のプログラム。
- 24前記コンピュータに、 前記バックアップノードから前記ファイアウォールクラスター内の別のノードに前記状態情報をブロードキャストする手順を更に実行させる、請求項23に記載のプログラム。
- 25前記コンピュータに、 前記確立された接続に関連付けられた共有された前記状態情報を用いて、前記第1のノードの故障時に別のノードにおいて、対応する後続の確立された接続をフィルタリングする手順を更に実行させる、請求項19~21のいずれか1項に記載のプログラム。
- 26前記コンピュータに、 前記確立された接続に関連付けられた共有された前記状態情報を用いて、別のノードにおいて、対応する後続の確立された接続をフィルタリングし、前記ファイアウォールクラスター内の負荷分散を提供する手順を更に実行させる、請求項19~21のいずれか1項に記載のプログラム。
- 27前記接続要求を処理する手順は、前記確立された接続を形成する前に、共有された前記状態情報を決定する手順を含む、請求項19~21のいずれか1項に記載のプログラム。
- 28複数のノードのクラスターを動作させる方法であって、 3つ以上のノードを有する前記複数のノードのクラスターのうち、ファイアウォールタスクを実行する第1のノードで接続要求を受信する段階と、 前記接続要求を処理して接続を確立する段階と、 前記確立された接続に関連付けられた状態情報を、前記複数のノードのクラスターのうち少なくとも1つの別のノードと共有する段階と、 侵入保護タスクを実行するように構成された第2のノードの故障に応じて、侵入保護タスクを実行するように前記第1のノードを再度割り当てる段階と を備え、 共有された前記状態情報は、前記確立された接続を処理するバックアップノードによる使用のためのものである、方法。
- 29前記接続要求を受信した後であって、前記状態情報を共有する前に、受信した前記接続要求に関する接続情報を、前記複数のノードのクラスター内の少なくとも別のノードと共有する段階を更に備える、請求項28に記載の方法。
- 30前記状態情報は、前記接続要求にそれぞれ関連付けられたユーザーの識別情報およびIPアドレスを含む、請求項28に記載の方法。
- 31前記状態情報を共有する段階は、前記クラスター内の複数の別のノードに前記状態情報をブロードキャストする段階を含む、請求項28~30のいずれか1項に記載の方法。
- 32前記状態情報を共有する段階は、前記バックアップノードに前記状態情報を送信する段階を含む、請求項28~30のいずれか1項に記載の方法。
- 33前記状態情報を共有する段階は、前記バックアップノードから前記クラスター内の別のノードに前記状態情報をブロードキャストする段階を更に含む、請求項32に記載の方法。
- 34前記確立された接続に関連付けられた共有された前記状態情報を用いて、別のノードにおいて、対応する後続の確立された接続をフィルタリングすることにより前記クラスターを負荷分散する段階を更に備える、請求項28~30のいずれか1項に記載の方法。
- 35前記接続要求を処理する段階は、前記接続を確立する前に、前記状態情報を決定する段階を含む、請求項28~30のいずれか1項に記載の方法。
- 36結合された第1のノード、第2のノードおよび第3のノードを備え、 前記第1のノードは、ファイアウォールタスクを実行するように構成され、前記第3のノードは、侵入保護タスクを実行するように構成され、 前記第1のノードは、更に、 接続要求を受信し、 前記接続要求を処理して接続を確立し、 共有された状態情報を用いて前記確立された接続を処理するために、前記確立された接続に関連付けられた前記状態情報を前記第2のノードと共有し、 前記第1のノードを再度割り当てて、前記第3のノードの故障に応じて侵入保護タスクを実行するように構成される、ファイアウォールクラスター。
- 37前記第1のノードは、前記接続要求を受信した後であって、前記状態情報を共有する前に、受信した前記接続要求に関する接続情報を、前記ファイアウォールクラスター内の少なくとも1つの別のノードと共有するように更に構成される、請求項36に記載のファイアウォールクラスター。
- 38前記第1のノードは、前記ファイアウォールクラスター内の複数の別のノードに前記状態情報をブロードキャストすることにより、前記状態情報を共有するように構成される、請求項36に記載のファイアウォールクラスター。
- 39前記第2のノードは、前記ファイアウォールクラスター内の複数の別のノードに前記状態情報をブロードキャストするように構成される、請求項36~38のいずれか1項に記載のファイアウォールクラスター。
- 40共有された前記状態情報を用いて、別のノードにおいて、後続の確立された接続をフィルタリングすることにより、前記ファイアウォールクラスター内の負荷分散を提供するように構成される負荷分散装置を更に備える、請求項36~38のいずれか1項に記載のファイアウォールクラスター。
- 41前記第1のノードは、前記確立された接続を形成する前に、共有された前記状態情報を決定するように更に構成される、請求項36~38のいずれか1項に記載のファイアウォールクラスター。
- 42前記第2のノードは、前記第1のノードの故障時に別のノードにおいて、後続の確立された接続をフィルタリングするように更に構成される、請求項36~38のいずれか1項に記載のファイアウォールクラスター。
Independent claims42
32 paragraphs, as filed
0001The present invention relates to firewall operation in a comprehensive manner, and more specifically, in one embodiment, the present invention relates to authentication sharing in a firewall cluster.
0002[Cross-reference of related applications] This application claims the priority of US Patent Application No. l3 / 227,848 filed on September 8, 2011. This US patent application forms part of this specification by reference.
0003[Restricted copyright waiver] Part of the disclosure of this patent document includes material for which copyright protection has been requested. The copyright owner has no objection to the facsimile reproduction of a patent document or patent disclosure by anyone, as can be seen in the files or records of the United States Patent Office and the Trademark Office, but with respect to any other right. Reserve all rights.
0004The main reason computers are useful tools is that they can communicate with other computer systems and retrieve information over computer networks. A network typically includes a group of interconnected computers linked by wiring, fiber optics, radio, or other means of data transmission that give the computer the ability to transfer information between computers. The Internet is perhaps the most well-known computer network, with millions of people browsing web pages, sending emails, performing other computer-to-computer communications, and so on. Allows access to one million other computers.
0005However, because the Internet is so large and the interests of Internet users are so diverse that malicious or unsolicited users (pranksters) can risk other users with other users' computers. It is not uncommon to try to communicate. For example, a hacker may log in to a corporate computer and attempt to steal, delete, or modify information. Computer viruses or Trojan horse programs may be delivered to other computers or unknowingly downloaded or executed by a large number of computer users. In addition, computer users within an organization such as a company may occasionally attempt to perform unauthorized network communications, such as running a file sharing program or sending company secrets from within the company's network to the Internet. ..
0006For these and other reasons, many businesses, organizations, and even home users use network firewalls or similar devices between their local network and the Internet. A firewall is typically a computerized network device that inspects the network traffic that passes through it, allowing the desired network traffic to pass through a set of rules.
0007The firewall observes communication packets such as TCP / IP packets or other network protocol packets, and inspects the source network address and destination network address, which port is used, and characteristics such as connection status or history. By performing the filtering function. Some firewalls also inspect packets to and from a particular application, and proxy devices by processing and forwarding selected network requests between protected users and external networked computers. Some work as.
0008Firewalls typically control the flow of network information by monitoring connections between various ports, sockets and protocols, such as by inspecting network traffic within the firewall. Selectively filter or pass data and log network activity using sockets, ports, applications and other informed rules. Firewall rules are typically configured to identify a particular type of network traffic. These types are types of traffic that should be prohibited or to which certain other restrictions apply, while blocking traffic on ports that are known to be used by file-sharing programs. Scans for viruses of any traffic received over traditional FTP ports, blocking certain applications or users from performing some tasks while others perform such tasks. And to block traffic based on known attack patterns such as iterative queries on different ports from a common IP address.
0009However, the ability of firewalls to manage such connections when distributed across multiple computer systems is limited in that knowledge of the connection is usually only stored in the system that handles the connection. Therefore, improved firewall distribution in the cluster is desired.
0010Various exemplary embodiments of the invention include a firewall cluster system with a first node, which first node receives and associates a connection in a firewall cluster with three or more nodes. It is possible to identify the user data and share this user data with at least another node in the firewall cluster. Another node can use the application state data to continue processing connections or provide load balancing in the event of a first node failure or the like.
0011<figref num="1">FIG. 5 illustrates an exemplary network, including a firewall, that can be used to implement some embodiments of the present invention.</figref>
0012<figref num="2">FIG. 5 illustrates an exemplary network that includes a firewall cluster that includes a plurality of firewall nodes, which can be used to implement some embodiments of the present invention.</figref>
0013<figref num="3">FIG. 5 is a flow chart illustrating the use of shared user passport information within a firewall cluster according to an exemplary embodiment of the present invention.</figref>
0014In the following detailed description of exemplary embodiments of the invention, specific examples are referenced for illustration and description. These examples are described in sufficient detail to allow one of ordinary skill in the art to practice the invention and serve to demonstrate how the invention can be applied to various purposes or embodiments. Fulfill. There are other embodiments of the invention, which are within the scope of the invention and make logical, mechanical, electrical and other modifications without departing from the subject matter or scope of the invention. be able to. However, the features and limitations of the various embodiments of the invention described herein are essential to the exemplary embodiments in which they are incorporated and do not limit the invention as a whole. No reference to the elements, behaviors and uses of the invention as a whole limits the invention as a whole and serves only to define these exemplary embodiments. Therefore, the following detailed description does not limit the scope of the present invention, and the scope of the present invention is defined only by the appended claims.
0015FIG. 1 shows a normal computer network environment with a public network such as the Internet in 101, a private network 102, and a computer network device shown in 103 that can operate to provide firewall and intrusion protection features. There is. In this particular example, the computer network device 103 is positioned between the Internet and the private network to coordinate the traffic flow between the private and public networks.
0016The network device 103, in various embodiments, functions as a firewall device, an intrusion protection device, or both. A firewall device or module within a network device provides various network flow control functions such as investigating network packets and dropping or rejecting network packets that meet a set of firewall filtering rules. As explained above, firewalls typically observe communication packets such as TCP / IP packets or other network protocol packets, source network address and destination network address, which port is used, and the state of the connection. Alternatively, the filtering function is executed by inspecting characteristics such as history. Some firewalls also inspect packets to determine which application has established a connection, and handle selected network requests between protected users and external networked computers. And some act as proxy devices by transferring. Firewalls often use "signatures" or other characteristics of unwanted traffic to detect and block unwanted traffic that is considered harmful or otherwise.
0017Firewalls typically use a set of rules to filter traffic so that what is done with respect to any particular element of network data depends on how the set of rules is applied to that particular data. To. For example, a rule that blocks all traffic to port 6346 blocks incoming traffic directed to that port on a server in the protected network, but blocks other data destined for different port numbers on the same server. do not. Similarly, rules that block traffic originating from file-sharing programs such as Shareaza use patterns in traffic to block Shareaza traffic on port 6346, but allow other traffic on port 6346.
0018However, in an environment where the firewall is implemented as a distributed system across multiple computers or nodes, such as large systems or complex systems, the ability of multiple nodes to share a connection is limited to socket information, application information, etc. regarding the connection. It is limited to the information of each node related to the connection such as user information. Therefore, some embodiments of the present invention share state information such as users or other such connection data with other systems in the cluster firewall, and multiple nodes in the firewall cluster handle the same connection. It provides a mechanism that makes it possible to do so. This allows load balancing by shifting connectivity between systems, managing node failures in a cluster by transferring that node's connectivity to another machine, and performing other such functions. Capabilities are given to the cluster.
0019In one such example, a firewall or intrusion protection system is implemented as a cluster or connected group of nodes that share processing traffic flowing through the firewall. FIG. 2 shows a network with a distributed firewall that can be used to implement some embodiments of the present invention. Here, the network such as the Internet 201 is connected to the internal network 202 by the firewall 203. Firewall 203 includes an inbound traffic module 204 and an outbound traffic module 205 capable of performing functions such as load balancing and other firewall management functions. Firewall or intrusion protection rules apply at firewall node 206, which are connected to each other by a network connection as shown.
0020Here, each of the five nodes shown is an instance of a firewall or associated software that can act to apply rules to the traffic that selectively allow or block traffic flowing between the Internet 201 and the internal network 202. It has a separate computer system to run. In an alternative embodiment, some nodes such as node 1, node 2 and node 3 run firewall applications, while other nodes such as 4 and 5 run intrusion prevention system (IPS) applications. Nodes 204 and 205 are responsible for performing functions such as load balancing of traffic routed to firewall node 206, and together efficiently ensure that these nodes provide higher throughput capabilities than a single node. Ensure that it can function.
0021Some firewall embodiments perform complex connection identification functions that go beyond simply applying ports, IPs and other such rules to data streams. For example, some firewall examples identify users by using user authentication to the firewall, or by using indirect authentication such as Microsoft domain server logon or other user certificates that can be read by the firewall. Includes the user "passport" associated with the connection. This passport associates the identified user with a particular IP address, MAC address or other identifier so that connections coming from the user can be identified as belonging to that user.
0022User-based filtering can then be performed in the firewall. For example, a firewall may know that Alice is a member of a management group, while Bob is a member of an employee group but not a member of the management group. Both users log on to the computer and run Skype to participate in the video conference, and the firewall uses Skype through the firewall for both users to have a video conference with an external vendor or customer, etc. Determine that you are allowed to send video conferencing traffic.
0023Bob attempts to send the file using Skype, and the firewall enforces a rule that allows only members of the management group to send the file outbound using Skype. The firewall was associated with Bob's connection<u style="single">Passport user information</u>And use the IP address information to identify that Bob is trying to send the file and thus block Bob's file. Alice then attempts to send the same file using Skype, and the passport associated with Alice's connection identifies Alice as the user associated with the connection and is allowed to send the file.
0024However, if the firewall is distributed across multiple nodes, each node has the same firewall rules, while only the node that manages the connection knows user information such as the username and IP address (or passport) of the connection. So it is more difficult to apply the proper rules for connections.
0025Therefore, some embodiments of the present invention distribute user passport information between nodes in a firewall cluster, such as by multicasting the user passport information or transmitting the user passport information to a master node to distribute the user passport information. Including that.
0026FIG. 3 is a flow chart illustrating the use of shared user passport information in a firewall cluster according to an exemplary embodiment of the invention. At 301, a link is initiated between the computer in the local network 202 and the Internet 201. Links between nodes are handled by node 1. At 302, as soon as the network connection is established, node 1 retrieves the user passport information from the Microsoft domain server login or the like, or the user logs in directly to the firewall. Next, at 303, firewall node 1 shares this user passport data for the connection with other nodes, and at 304, it uses this user passport data to apply user-specific rules to the firewall.
0027At 305, node 1 fails and at 306 the connection is redirected to node 2. Since node 2 has previously received user passport data for the connection from node 1, at 308 node 2 may resume filtering the data stream, including applying user-specific rules to the connection. it can.
0028This example shows how a node can resume filtering connections after it fails, but for purposes such as load balancing or reallocating a node to various tasks. Similar methods can be used to move connections from one node to another within a firewall cluster.
0029In one such example, the firewall node 1 does not fail, but one of the two intrusion protection system nodes (not shown) fails the intrusion protection system node. The system wants to maintain a certain balance between the number of nodes that provide firewall services and the number of nodes that provide intrusion protection, in this example the intrusion protection system is of the two nodes. When one of them fails, it loses half of its functionality. Therefore, the system reallocates firewall node 1 to replace the failed intrusion protection node, and as a result, as shown in Figure 2, the connections previously processed by firewall node 1 are firewall nodes 2-5. Redistributed over.
0030These examples facilitate load balancing, failover and other features within a firewall cluster by sharing user passport data within the firewall cluster, and better user-based filtering of network traffic in the firewall cluster. It shows whether it can be easy to handle and reliable.
0031Although a particular embodiment has been shown and described herein, one of ordinary skill in the art can replace any configuration calculated to serve the same purpose with the particular embodiment shown. Will understand. The present application is intended to include any adaptation or modification of the exemplary embodiments of the invention described herein. The present invention is intended to be limited only by the claims and the full scope of their equivalents.
0032As described above, firewalls configured by operating methods and certain methods are disclosed. For example, a way to get a firewall cluster to work is to receive a connection on the first node of a firewall cluster that has three or more nodes, identify the user data associated with this connection, and extract this user data. Can include sharing with at least another node in the firewall cluster. In addition, the firewall cluster can share connection information about the received connection with at least another node in the firewall cluster after receiving the connection but before sharing user data. User data can include the user's identification information and the IP address of the connection. Sharing can include broadcasting user data to other nodes in the firewall cluster or sending user data to the master node. The master node can also be configured to broadcast user data to other nodes in the firewall cluster. Optionally, the firewall cluster can use the shared user data associated with the connection to filter the connection on another node in the event of a failure of the first node, or filter the connection on another node. It can also provide load balancing in firewall clusters.
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2006054770A | Cites | Japan |
| JP2003052067A | Cites | Japan |
| JP2002141903A | Cites | Japan |
| JP2006502503A | Cites | Japan |
| JP2008263581A | Cites | Japan |
| US20071802226A1 | Cites | United States of America |
| US2006075478A1 | Cites | United States of America |
| US20050240989A1 | Cites | United States of America |
| US20110030049A1 | Cites | United States of America |
| US20080028456A1 | Cites | United States of America |
| US20120057597A1 | Cites | United States of America |
| US7254834B2 | Cites | United States of America |
| 関原 優 Masaru Sekihara,既存システムの総点検と一歩進んだ使い方 ファイアウォール最適活用のポイント Fire Wall,N+I NETWORK 第3巻 第8号,日本,ソフトバンクパブリッシング株式会社,2003年 9月 1日,第3巻,68~71ページ,2003年7月29日受入 | Non-patent | – |
18 members in 6 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 13227848 | United States of America | – | |
| 201113227848 | United States of America | A | |
| 2012053976 | United States of America | W |
Members18
| Document | Office | Kind | |
|---|---|---|---|
| US2013067557A1 | United States of America | A1 | |
| WO2013036651A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20140058616A | Republic of Korea | A | |
| CN103858383A | China | A | |
| EP2754266A1 | European Patent Office (EPO) | A1 | |
| JP2014526739A | Japan | A | |
| US8887263B2 | United States of America | B2 | |
| KR20150015027A | Republic of Korea | A | |
| EP2754266A4 | European Patent Office (EPO) | A4 | |
| KR101529839B1 | Republic of Korea | B1 | |
| KR101586972B1 | Republic of Korea | B1 | |
| EP2991276A1 | European Patent Office (EPO) | A1 | |
| CN105407099A | China | A | |
| JP5908090B2This record | Japan | B2 | |
| CN103858383B | China | B | |
| CN105407099B | China | B | |
| EP2754266B1 | European Patent Office (EPO) | B1 | |
| EP2991276B1 | European Patent Office (EPO) | B1 |
20 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of nameJAPANESE INTERMEDIATE CODE: R313533S533 | S533 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 5908090
- Application
- 2014529857
Titles2
- Japanese
- ファイアウォールクラスターにおける認証共有
- English
- Authentication sharing in a firewall cluster
Classification
- CPC, 14
- H04L63/0218
- H04L67/1036
- H04L63/029
- H04L63/0254
- H04L67/10
- H04L63/0236
- H04L63/102
- H04L67/1008
- H04L67/1027
- H04L63/0876
- H04L63/0227
- H04L63/20
- H04L41/12
- H04L63/0209
- IPC, 3
- G06F13 00
- H04L12 66
- H04L69 40
