1461151129-39192607-5c39-4425-bd0d-c5c21719221f

What is claimed is:

1. A method for monitoring transmissions between a network application server and a client, the method comprising:
incorporating security metadata in a server transmission from a network application server to a client, wherein the security metadata includes a description of the intended network application semantics;
receiving a client transmission from the client, wherein the client transmission includes returned metadata; and
determining, using the returned metadata, whether the client transmission conforms to the intended network application semantics.
2. The method of claim 1, wherein the security metadata is transmitted with application data.
3. The method of claim 1, wherein the security metadata is transmitted separate from application data.
4. The method of claim 1, wherein the security metadata further comprises authorization information for client transmissions, wherein the authorization information indicates which client transmissions are authorized.
5. A method applied between a network application server and a client to ensure data security:
intercepting a transmission of application data from a network application server to a client;
identifying one or more Uniform Resource Locators (URLs) embedded in the transmission;
generating security metadata containing constraints on the manner in which the client requests the one or more URLs; and
transmitting the transmission of application data and the security metadata to the client.
6. The method of claim 5, further comprising:
receiving a client transmission from the client, wherein the client transmission includes a URL request and the security metadata; and
validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs.
7. The method of claim 5, further comprising generating a cryptographic signature over the predicted form of the client request containing the one or more URLs previously transmitted by the application server, and wherein transmitting further comprises transmitting the cryptographic signature to the client.
8. The method of claim 7, further comprising:
receiving a transmission from the client, wherein the transmission from the client includes a URL request and the security metadata;
validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs; and
verifying the cryptographic signature.
9. An apparatus for monitoring transmissions between a network application server and a client, the apparatus comprising:
a transmitter for incorporating security metadata in one or more server transmissions from a network application server to a client, wherein the security metadata includes a description of the intended network application semantics;
a receiver for receiving one or more client transmissions from the client, wherein the one or more client transmissions include returned metadata; and
an analyzer for determining, using the returned metadata, whether the one or more client transmissions conform to the intended network application semantics.
10. The apparatus of claim 9, wherein the security metadata is transmitted with the application data.
11. The apparatus of claim 9, wherein the security metadata is transmitted separate from the application data.
12. The apparatus of claim 9, wherein the security metadata further comprises authorization information for client transmissions, wherein the authorization information indicates which client transmissions are authorized.
13. An apparatus for insuring data security, comprising:
a receiver for intercepting a transmission of application data from a network application server to a client;
a parser for identifying one or more URLs embedded in the transmission;
a metadata generator for generating security metadata containing constraints on the manner in which the client requests the one or more URLs; and
a transmitter for transmitting the transmission of application data and the security metadata to the client.
14. The apparatus of claim 13, further comprising:
a second receiver for receiving a client transmission from the client, wherein the client transmission includes a URL request and the security metadata; and
a validator for validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs.
15. The apparatus of claim 13, further comprising a generator for generating a cryptographic signature over the predicted form of the client request containing the one or more URLs previously transmitted by the application server, and wherein the transmitter further transmits the cryptographic signature to the client.
16. The method of claim 15, further comprising:
a second receiver for receiving a transmission from the client, wherein the transmission from the client includes a URL request and the security metadata;
a validator for validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs; and
a verifier for verifying the cryptographic signature.
17. A system for performing state signing of network resources, comprising:
a first subsystem for receiving one or more resource requests from a client to an application server; and
a state signing subsystem for signing responses to resource requests delivered to a client from the application server, wherein the resource requests are signed to indicate authenticity.
18. The system of claim 17, wherein the state signing subsystem includes a cryptographic signature for the generation of a cryptographic signature over at least a portion of the response to the resource request.
19. The system of claim 18, wherein the state signing subsystem further includes a verification subsystem for the determination as to whether a resource request has been altered.
20. A computer program embodied on a computer-readable medium for signing the state of application data transmitted over a network, the computer program comprising:
a source code segment for intercepting a transmission of application data from an application server to a client;
a source code segment for identifying one or more URLs embedded in the transmission;
a source code segment for generating security metadata containing constraints on the manner in which the client requests the one or more URLs;
a source code segment for transmitting the transmission of application data and the security metadata to the client.
21. The computer program of claim 20, further comprising:
a source code segment for receiving a client transmission from the client, wherein the client transmission includes a URL request and the security metadata; and
a source code segment for validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs.
22. The computer program of claim 20, further comprising a source code segment for generating a cryptographic signature over the predicted form of the client request containing the one or more URLs previously transmitted by the application server, and wherein the source code segment for transmitting further transmits the cryptographic signature to the client.
23. The computer program of claim 22, further comprising:
a source code segment for receiving a client transmission from the client, wherein the client transmission includes a URL request and the security metadata;
a source code segment for validating the URL request against the security metadata to ensure that the URL request fits within the constraints on the manner in which the client requests the one or more URLs; and
a source code segment for verifying the cryptographic signature.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. An apparatus for applying a plasterstucco-like material to a plurality of elongate foam cores having a decorative exposed surface, said apparatus comprising of:
a. Means for constraining elongate foam core in all directions other than forward and reverse to guide the core into a coating chamber.
b. Means for supporting the said core while in the coating chamber.
c. Means for guiding the said core while in the coating chamber.
d. Means for driving the foam core through the apparatus.
e. Means for applying the coating to the surface profile of the said core.
2. An apparatus as claimed in claim 1 wherein said means for constraining the said core includes a plurality of rollers of various lengths, with openings to allow chain drives to engage the said core on the bottom.
3. An apparatus as claimed in claim 1 wherein said constraining include a plurality of hold down wheels that are adjustable vertically and horizontally to constrain the cores from the top against the roller table and the force of engagement from the bottom drive chains.
4. An apparatus as claimed in claim 3 wherein said hold down wheel attaches to a slotted extrusion, which adjust vertically through a lockable tee connection, which slides horizontally on a second slotted extrusion.
5. An apparatus as claimed in claim 1 wherein said constraining includes side fence guides that adjust laterally to constrain the said cores parallel to the forward direction of the drive chains.
6. An apparatus as claimed in claim 5 wherein said fence guides comprise of one inboard guide kept parallel to the direction of advancement by means of two racks and two pinions and one axle, to allow lateral adjustment, and is lockable it its set position.
7. An apparatus as claimed in claim 1 wherein said support in the coating chamber are two or more insertable plates, resting on two slotted extrusions, and adjust laterally independent of the coating chamber.
8. An apparatus as claimed in claim 1 wherein said guiding in the coating chamber is a knife plate, protruding above the support plate level, attached to the two slotted extrusions supporting the coating chamber.
9. An apparatus as claimed in claim 8 wherein said knife plate can be aligned with the bottom slot on the core, and inserted into the slot to keep it aligned.
10. An apparatus as claimed in claim 1 wherein said drive means are three vertically adjustable commercial attachment chains.
11. An apparatus as claimed in claim 10 wherein said vertical adjustment is accomplished with ramped plates and rollers and racks and pinions.
12. An apparatus as claimed in claim 1 wherein said drive means are three drive chains, selectable to be engaged or not engaged, that penetrate into the bottom of the positioned core with a plurality of sharpened metal teeth attached.
13. An apparatus as claimed in claim 12 wherein said engagement can be varied to control the penetration depth into the core.
14. An apparatus as claimed in claim 1 wherein said profile is accomplished with a pair of input and output templates corresponding to the surface profile of the core, specific to the height and width settings of the coating chamber.