随着Internet的普及和电子邮件的广泛使用,电子邮件的安全问题已经逐渐受到人们的关注,对于通过电子邮件泄露涉密信息的问题已经受到了使用者和相关安全开发人员的重视.本文对代理技术进行研究,提出了一种通过使用代理技术对进出内网的电子邮件进行监控的方法,以防止内部人员通过电子邮件有意或者无意的情况下泄露涉密信息.
Cloud computation allows the users with limited computing power outsource their data to the cloud of large-scale computing power through payment method. However, the security issue has been always the obstacles to the widely use of the computing outsourcing, especially when the end-user’s privacy data need to be processed on the cloud. Secure outsourcing mechanisms are in great need to not only protect privacy information, but also protect customers from malicious behaviors by validating the computation result. A mechanism of general secure computation outsourcing was recently shown to be feasible in theory, but to design mechanisms that are practically efficient is a very challenging problem. General research is based on a basic model. The model we used in this paper including Data Owner (DO), Cloud Service Provider (CSP) and End-User (EU). Focus on considering the DO, CSP and EU. Over-encryption is a good method to protect the security of the users’ data. Our proposal is based on the application of selective encryption as a means to enforce authorizations. Two layers of encryption are imposed on the data blocks. This paper talks about the over-encryption mechanism and proposes a novel over-encryption mechanism which can protect the security of the data on the Cloud. Last, we do some experiments to verify the performance of our mechanism.
In order to get the information of BT clients instantly and provide data for the analysis of the download behavior of BT clients,this paper has designed a BT clients information collection system.Using the technology of stealing process memory and controlling BT clients,it can get the download information,control the BT clients,and summary data through database.
Traditional network access control approaches are inflexible and low efficient, so they cannot be deployed in large-scale network. This paper presents a new network access control system (NACS) based on routing diffusion. Then this system has been designed and implemented. Then two key optimization programs — parallel router and tunnel technology — are proposed to improve the performance of NACS. At last, a large number of experiments are given to verify its high efficiency.
<计算机设计与实践>课程作为<计算机组成原理>的后续课程和重要实践环节,是探索综合性、创新性实践教学模式的具体实现形式.本文探讨了这门课程的建设目标:培养学生的系统性的认识能力、理论联系实际的能力、完成工程项目的能力,同时总结了教学实践中的一些心得体会.
“计算机组成原理”是计算机科学与技术专业核心课程,也是师生普遍反映难教难学的课程之一。本文简要介绍了“计算机组成原理”课程教学实施方案的总体框架,并结合科学型、工程型和应用型不同类型计算机人才培养的特点和要求,对“计算机组成原理”教学过程中重点难点的讲授、教学实验设置与要求等问题进行了详细的说明。
Briefly introduce the feature and the structure of JPEG2000, as well as DWT and Embedded Block Coding which are the most important parts of JPEG2000 codec. Analyze the difference between DWT and DCT, and the advantage of DWT. Introduce the core algorithm of JPEG2000——EBCOT in detail. Introduce the application of JPEG2000 in low bitrate case. Give a comparison of JPEG2000 and JPEG in low image bitrate case.
本文主要探讨了计算机专业主干课程"计算机组成原理"的课程实现问题,分析比较了University of California at Berkeley、Carnegie Mellon University、清华大学和我校等几所大学"计算机组成原理"课程的教学情况,探讨了作为"计算机组成原理"的重要实践环节的"计算机设计与实践"课程的综合性、创新性实践教学模式,有助于提高"计算机组成原理"课程的教学质量。
This paper reviewed the situation of macro alert research in internal and abroad,summarized the characters of existing technology according to the implementing process of the macro alert system.
A method for selecting path in radio transducer network based on AOMDV protocol includes storing information of multiple next jump neighbor node in itself route table when each sending node is initialized, enabling to select secondary priority next jump neighbor node to carry out routing continuously according to itself route table in routing course when routing of primary priority next jump neighbor node is failure, treating that routing of sending node is failure till routing of all next neighbor nodes in said route table is failure.
"计算机设计与实践"课程作为"计算机组成原理"的后续课程和重要实践环节,是探索综合性、创新性实践教学模式的具体实现形式。开展实践环节的教学研究,开发真正以学生为中心的教学模式,开展设计性与创新性实践教学内容的研究,完善实践教学环境,可以锻炼学生的设计能力和动手能力,培养学生的综合能力和创新能力,提高学生的综合素质。
This paper introduced the medicine grid system,including its origin,conception and research actuality,descripted an overall structure based on OGSA and a framework design mechanism for 3-tier regional medicine grid system,and presented an implement model for the system's information service.The system solve the problems such as imbalance of the medical resources in allocation,secluded regions difficulties in getting medical treatment,medical resources unshared among hospitals etc.
Introduces the development and characteristic of the firewall,analyses the working principle of the stateful-inspection firewall.The data structure of the state table and rule table is built.Considering the security and performance of the firewall,pre ̄sents the structural design for TCP,UDP,ICMP,ARP,which is the main protocol in the TCP/IP stack.Method of TCP sequence number check,UDP virtual connection,ICMP package inspection ensure the security and high performance of the network.
State detection is the main stream of the current firewall technologies. This paper introduces the principle of state detection firewall.The flowchart of state detection and the model of state transition for the TCP packets are presented.A method of sequence number scope check and dynamic timeout management ensures the system security.A hash algorithm is adopted to manage the state table,and the design is implemented on FPGA.The experiment shows that the design can work well in a Gigabit network environment.
In order to catch the events that satisfy the given importance among the relative frequent events,RFAI is proposed,which first gathers the relative frequent events and puts them in buffers and then marks them with the given importance.Making use of such events in the Run-time optimization can gain better optimization value and higher stability.
Summary The paper introduced the design of the data channel between the hardware firewall and the host computer based on the advanced Virtex-II-series FPGA from Xilinx, Inc. and the bridge chipPCI9656 from PLX Technology. The design of FIFO with double channels, double ports and double clocks, three control logics and the queue descriptors makes it a high work frequency and transfer speed, then a good performance in capability and stability.
The idea of two-level Trace Cache is proposed which provide a second-level trace cache that captures replaced traces from first-level trace cache due to capacity conflict,to partly lighten this problem and improve processor performance. Accordingly,the access pressure of instruction cache is alleviated and such a free resource can be used in others aspects,such as trace preconstruction.Results show that for big-work-set programs,such as go and gcc,adding 1MB second-level trace cache to 64KB first-level trace cache increases processor performance by 13% and reduces access pressure of instruction cache by 27%.
Trace preconstruction mechanism proposed in this paper observes the instruction stream, and marks the frequent miss trace andconstructs a set of traces using the instruction fetched from the conventional instruction cache in advance of when they are needed. Path-based tracepreconstruction tracks the execution history of the traces, when predicting the next trace to be fetched, it also predicts the next nth trace and decidesweather it should be pre-constructed or not. Constructing these traces before using them, the trace cache miss rate is reduced significantly.
模拟器是计算机系统设计中非常重要的一种技术.Oracle研究能够用来确定所研究问题的最优或最差情况,为正常研究提供有用的辅助信息.但是现在常用的一些同步多线程(SMT)模拟器都不能提供支持Oracle研究所需的信息.文章结合原有模拟器的基础,提供了一种新的支持Oracle研究的模拟平台.同时原SMT模拟器只支持ICOUNT这一种取指策略,文章在原模拟器基础上,又增加了BRCOUNT和MISSCOUNT这两种通用的取指策略.
千兆硬件防火墙将在网络安全体系中起到非常重要的作用,数据缓冲是连接MAC与规则匹配和状态检测的枢纽.高速数据缓冲的良好设计是突破吞吐速率瓶颈的关键.提出了一种基于FPGA的千兆硬件防火墙高速数据缓冲的实现方法,订制并精简了WISHBONE总线互连的方式,提出MAC与数据缓冲数据透明的设计方案从而大大提高通讯性能,给出了利用FPGA的BLOCK RAM实现同步/异步FIFO的一般方法,提出延迟判定和数据预取的方式解决空满判定和串联BLOCK RAM访问时延问题.高速数据缓冲的设计具有一定的通用性.
Mingshu Li (李明树)合作论文数University of Chinese Academy of Sciences;Laboratory for Internet Software Technologies, Institute of Software, Chinese Academy of Sciences4