1. A method comprising:
intercepting, at a cloud connector device of a network, a request from a user for content;
when the content is not cached in the network:
redirecting the request to a cloud-based security as a service server;
receiving the content from the cloud-based security as a service server;
routing the content to a cache server; and
receiving at a cloud connector identity-based security policy from the cloud-based security as a service server for the content;
when the content is cached in the network:
determining at the cloud connector device for the cached content whether the request satisfies an identity-based security policy that is a same policy as at the security as a service server;
sending the request to the cache server when the request satisfies the identity-based security policy; and
rejecting the request when the request fails to satisfy the identity-based security policy.
2. The method of claim 1 wherein intercepting comprises intercepting all requests, including the request, received at the cloud connector device and wherein all of the cached content, including the content routed to the cache server, is filtered by the cloud-based security as a service server prior to caching.
3. The method of claim 1 wherein intercepting at the cloud connector device of the network comprises intercepting with a transparent proxy at an edge router of an enterprise network.
4. The method of claim 1 further comprising storing a list of cachable target uniform resource locators, and determining whether the content is cached from the cachable target uniform resource locators.
5. The method of claim 1 wherein redirecting comprises redirecting to the security as a service server outside the network.
6. The method of claim 1 wherein receiving the content comprises receiving the content after filtering of the content by the cloud-based security as a service server.
7. The method of claim 1 wherein routing the content comprises routing the content to the cache server for caching and response, by the cache server, of the content to the request from a client other than the cache server.
8. The method of claim 1 further comprising notifying the security as a service server of web caching in the network, wherein receiving the content comprises receiving the content with an altered caching header as compared to the content as provided by a content server.
9. The method of claim 8 wherein the receiving the content with the altered caching header comprises receiving the content with an indication of no caching.
10. The method of claim 1 wherein determining whether the request satisfies the identity-based security policy comprises determining an identity of a source of the request by user, user group, device group, security clearance, location of the source, or combinations thereof.
11. The method of claim 1 further comprising receiving the identity-based security policy from the cloud-based security as a service server.
12. The method of claim 1 wherein determining whether the request satisfies the identify-based security policy comprises determining whether an identity of a source of the request is in a white list or a black list for the content.
13. The method of claim 12 wherein further comprising requesting a policy from the security as a service server where the identity is not in the white or black lists.
14. Logic encoded in one or more non-transitory computer-readable media that includes code for execution and when executed by a processor is operable to perform operations comprising:
receiving, within a network, identity-based security information from a security as a service server outside the network;
receiving, from an identified source, a request for content cached within the network;
determining that the content is cached within the network, the cached content comprising content filtered by the cloud-based security as a service;
verifying, with the identity-based security information, that the identified source is allowed access to the filtered content cached within the network; and
providing the content to the identified source.
15. The logic encoded in the one or more non-transitory computer readable media of claim 14 wherein receiving the identity-based security information comprises receiving user identities, user-group identities, location identities, device identities, or combinations thereof and corresponding security policies implemented by the security as a servicer server, and wherein verifying comprises applying the security policies to the request for the cached content.
16. The logic encoded in the one or more non-transitory computer readable media of claim 14 further comprising:
receiving a further request for content not cached in the network;
redirecting the further request to the security as a service;
receiving a response to the further request from the security as a service; and
providing the response for caching in the network.
17. The logic encoded in the one or more non-transitory computer readable media of claim 16 wherein the response comprises further content responsive to the further request, the further content comprising security filtered content with a caching lifetime adjusted by the security as a service server.
18. An apparatus comprising:
a client device connected to a network, the client device configured to request content; and
a gateway device of the network, the gateway device configured to restrict serving, in response to the request, of cached content within the network based on an identity-based security policy received from a cloud-based security as a service.
19. The apparatus of claim 18 further comprising a cache server storing the cached content, a lifetime of the cached content set by the security as a service to be different than a setting of a source of the content.
20. A method comprising:
receiving, at a security service processor, a request for content from a host in an enterprise network;
requesting the content from a web server;
receiving from the web server the content in response to the request;
filtering, by the security service processor, the content received from the web server;
adjusting a freshness setting of the content, the freshness setting corresponding to caching;
transmitting the content with the adjusted freshness setting to the enterprise network as a response to the request; and
transmitting an identity-based security policy to a cloud connector in the enterprise network for providing the content from cache within the network using the identity-based security policy.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.
1. A traction apparatus that impresses a desired traction force to a body to be pulled, the traction apparatus comprising:
a traction mechanism that includes a harness coupled to the body to be pulled, a rope having a first end attached to the harness, and a take-up drum attached to a second end of the rope and impressing the traction force on the body to be pulled by taking up the rope;
a first pulley that engages, at a predetermined wrapping angle, the rope to which the traction force is impressed by being taken up by the take-up drum, a rope load being impressed to the first pulley from the rope;
a coupling plate that rotatably holds the first pulley, the rope load being impressed to the coupling plate from the rope via the first pulley;
a load sensor plate that holds the coupling plate at a first end portion thereof, the rope load being impressed to the load sensor plate from the rope via the first pulley and the coupling plate;
an outer frame that fixes a second end portion of the load sensor plate;
a load cell adhered to a surface of the load sensor plate, the load cell detecting an amount of strain of the load sensor plate caused by the rope load; and
a rotation mechanism that rotates the outer frame in agreement with a take-up position of the rope on a take-up surface of the take-up drum,
the first pulley rotating in accordance with rotation of the outer frame.
2. The traction apparatus according to claim 1, comprising a second pulley that engages the rope closer to the harness than the first pulley.
3. The traction apparatus according to claim 2, wherein a lengthwise direction of the load sensor plate is a direction that forms equal angles with each of a first movement path of the rope from the second pulley to the first pulley and a second movement path of the rope from the first pulley to the take-up drum.
4. The traction apparatus according to claim 3, wherein the rope engages the first pulley so that the first movement path and the second movement path are orthogonal.
5. The traction apparatus according to claim 1, comprising a load sensor mechanism that includes the first pulley, the coupling plate, and the load sensor plate, wherein the load sensor mechanism is configured to be rotatable in compliance with a rope take-up position of the take-up drum.
6. The traction apparatus according to claim 5, comprising a second pulley that engages the rope closer to the harness than the first pulley, the second pulley is configured to be rotatable in compliance with movement of a first movement path of the rope from the first pulley to the second pulley accompanying rotation of the load sensor.
7. The traction apparatus according to claim 1, wherein the rope load is a tensile load.
8. A rope take-up mechanism of a traction apparatus impressing a desired traction force on a body to be pulled by a harness coupled to the body to be pulled and a rope having a first end of the rope attached to the harness, the rope take-up mechanism comprising:
a take-up drum that attaches to a second end of the rope and that impresses the traction force on the body to be pulled by taking up the rope;
a first pulley that engages, at a predetermined wrapping angle, the rope to which the traction force is impressed by being taken up by the take-up drum, and on which a rope load is impressed from the rope;
a second pulley that engages the rope closer to the harness than the first pulley;
a load sensor mechanism that includes: a coupling plate rotatably holding the first pulley, the rope load being impressed to the coupling plate from the rope via the first pulley; a load sensor plate holding the coupling plate at a first end portion thereof, the rope load being impressed to the load sensor plate from the rope via the first pulley and the coupling plate; an outer frame fixing a second end portion of the load sensor plate; and a load cell adhered to a surface of the load sensor plate, the load cell detecting an amount of strain of the load sensor plate caused by the rope load; and
a rotation mechanism that rotates the outer frame in agreement with a take-up position of the rope on a take-up surface of the take-up drum,
the first pulley rotating in accordance with rotation of the outer frame.
9. The rope take-up mechanism of the traction apparatus according to claim 8, wherein a lengthwise direction of the load sensor plate is a direction that forms equal angles with each of a first movement path of the rope from the second pulley to the first pulley and a second movement path of the rope from the first pulley to the take-up drum.
10. The rope take-up mechanism of the traction apparatus according to claim 9, wherein the rope engages the first pulley so that the first movement path and the second movement path are orthogonal.
11. The rope take-up mechanism of the traction apparatus according to claim 8, wherein the rope load is a tensile load.
12. The rope take-up mechanism of the traction apparatus according to claim 8, wherein the load sensor mechanism is configured to be rotatable in compliance with a rope take-up position of the take-up drum, and
the second pulley is configured to be rotatable in compliance with movement of a first movement path of the rope from the first pulley to the second pulley accompanying rotation of the load sensor.