1460729529-cae9173d-518c-45b6-9c13-2be7ca420bef

1. An apparatus, comprising:
a membership logic to control membership in a group key system, where establishing membership in the group key system includes receiving a set of keys from a group controller and being assigned one or more roles by the group controller;
a key store to store the set of keys;
a receive logic to receive secure network traffic; and
a behavior logic to selectively perform one or more of, inspection of the secure network traffic, rewriting of the secure network traffic, and validation of the secure network traffic, and to selectively provide processed secure network traffic based, at least in part, on the set of keys and the one or more roles.
2. The apparatus of claim 1, where the membership logic requests membership into the group key system from the group controller, and where the membership logic requests one or more roles from the group controller.
3. The apparatus of claim 2, where the receive logic drops the secure network traffic upon a determination by the membership logic that membership in the group key system was denied by the group controller.
4. The apparatus of claim 1, where the set of keys includes group decryption keys, where the apparatus is assigned the role of an inspection point by the group controller, and where performing the role of inspection point includes performing inspection of the secure network traffic using the group decryption keys.
5. The apparatus of claim 4, where inspection of the secure network traffic includes decrypting the secure network traffic into decrypted network traffic based on the group decryption keys, and analyzing the decrypted network traffic.
6. The apparatus of claim 5, where analyzing the decrypted network traffic includes performing one or more of, virus scanning, signature comparison, malware detection, denial of service detection, intrusion detection, and network monitoring.
7. The apparatus of claim 1,
where the set of keys includes group authentication keys, where the apparatus is assigned the role of a validation point by the group controller, and where performing the role of validation point includes performing validation of the secure network traffic by using the group authentication keys; and
where validation of the secure network traffic includes performing one or more of, verification that the secure network traffic was generated by a trusted source, and verification that the secure network traffic was unmodified in transit.
8. The apparatus of claim 7,
where verification that the secure network traffic was generated by a trusted source includes one or more of, determining a security level of a security parameter index (SPI), and authenticating a message authentication code based at least in part on the group authentication keys; and
where verification that the secure network traffic was unmodified in transit includes authenticating a message authentication code based at least in part on the group authentication keys.
9. The apparatus of claim 1, where the set of keys includes both group authentication keys and group decryption keys, where the apparatus is assigned the role of a rewriting point by the group controller, where performing the role of rewriting point includes rewriting the secure network traffic by using both group decryption keys and group authentication keys, and where rewriting the secure network traffic includes authenticating the secure network traffic based on the set of keys, decrypting the secure network traffic into decrypted network traffic based on the set of keys, altering the decrypted network traffic, re-encrypting the decrypted network traffic into rewritten secure network traffic based on the set of keys, and re-authenticating the rewritten secure network traffic based on the set of keys.
10. The apparatus of claim 9, where altering the decrypted network traffic includes one or more of, rewriting network address headers, compressing data, and streamlining protocols.
11. The apparatus of claim 1, where the apparatus is a router, and where the router utilizes one or more of, network address translation (NAT), and port address translation (PAT).
12. The apparatus of claim 1, where the set of keys include one or more of, keyed-Hash Message Authentication Code (HMAC) keys, cryptographic keys, and symmetric keys.
13. The apparatus of claim 1, where the apparatus is one of, a firewall, an intrusion detection system (IDS) device, a distributed denial of service (DDoS) mitigation system device, a wide area network (WAN) optimization device, a content caching device, a router, and a network monitoring device.
14. The apparatus of claim 1, where the group key system is part of a group virtual private network (VPN);
where the group VPN uses the internet protocol security (IPSEC) protocol;
where the group controller is a key server; and
where the group key system utilizes one or more of, the group secure association key management protocol (GSAKMP), and the group domain of interpretation (GDOI) protocol.
15. The apparatus of claim 1, where the receive logic determines if a packet of the secure network traffic will be processed by the behavior logic based, at least in part, on a security parameter index (SPI) that identifies a security association (SA).
16. The apparatus of claim 1, where a security association (SA) identifies the secure network traffic as one of, decryptable, undecryptable but authenticated, and undecryptable, where the membership logic receives a determination of membership to the group key system from the group controller based, at least in part, on the SA, and where the group controller determines if a request for membership to the group key system is admissible based, at least in part, on the identity of the apparatus.
17. Logic encoded in one or more tangible media for execution and when execution operable to:
receive secure network traffic in a device;
upon determining that the device is a preconfigured member of a group key system, access a previously stored set of keys and a previously assigned role;
upon determining that the device is not a member of the group key system, request membership in the group key system from a group controller and requesting a role from the group controller, where establishing membership in the group key system includes receiving a set of keys from the group controller and being assigned a role by the group controller, the role being one of a rewriting point, an inspection point, and a validation point; and
selectively process the secure network traffic as one or more of, an inspection point, a rewriting point, and a validation point as controlled by the roles.
18. The media of claim 17, where selectively processing the secure network traffic as an inspection point includes inspecting the secure network traffic using the set of keys,
where selectively processing the secure network traffic as a rewriting point includes rewriting the secure network traffic using the set of keys, and
where selectively processing the secure network traffic as a validation point includes validating the secure network traffic using the set of keys.
19. The media of claim 18, where inspecting the secure network traffic includes decrypting the secure network traffic into decrypted network traffic based on the set of keys and performing one or more of, virus scanning, signature comparison, malware detection, denial of service detection, intrusion detection, and network monitoring on the decrypted network traffic, and where the set of keys includes group decryption keys;
where validating the secure network traffic includes performing one or more of, authenticating a message authentication code based at least in part, on the set of keys, and determining a security level of a security parameter index (SPI), and where the set of keys includes group authentication keys; and
where rewriting the secure network traffic includes authenticating the secure network traffic based on the set of keys, decrypting the secure network traffic into decrypted network traffic based on the set of keys, altering the decrypted network traffic, re-encrypting the decrypted network traffic into rewritten secure network traffic based on the set of keys, and re-authenticating the rewritten secure network traffic based on the set of keys, where altering the secure network traffic includes, rewriting network address headers, compressing data, and streamlining protocols, and where the set of keys includes both group authentication keys and group decryption keys.
20. A system, comprising:
means for determining whether a device that receives secure network traffic is a preconfigured member of a group key system;
means for selectively requesting membership in the group key system from a group controller; and
means for selectively processing the secure network traffic as one or more of, an inspection point, a rewriting point, and a validation point as controlled by one or more roles and in light of one or more keys, where the roles and the keys are provided by the group controller.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A top cover for use in a disk drive apparatus, the top cover comprising:
a plate made of a metal; and
a gasket made of an elastomer, and fixed to the plate; wherein
a surface of the plate includes a fixing region to which the gasket is fixed; and
in plan view, the fixing region includes a plurality of ridges and a plurality of filamentous projections extending from each of the plurality of ridges.
2. The top cover according to claim 1, wherein at least one of the plurality of ridges is annular or substantially annular in shape.
3. The top cover according to claim 1, wherein at least some of the plurality of ridges overlap with one another.
4. The top cover according to claim 1, wherein
the plurality of ridges included in the fixing region include a first row of ridges overlap with one another; and
the first row extends in a first direction.
5. The top cover according to claim 4, wherein
the plurality of ridges included in the fixing region further include a second row of ridges overlap with one another;
the second row extends in a second direction different from the first direction; and
the first row and the second row cross each other.
6. The top cover according to claim 4, wherein the fixing region has a width greater than that of the gasket.
7. The top cover according to claim 4, wherein the fixing region has a width smaller than that of the gasket.
8. The top cover according to claim 1, wherein
the top cover is square, substantially square, rectangular or substantially rectangular;
the gasket extends along an outer edge of the top cover;
the gasket includes:
a body portion with a uniform or substantially uniform width; and
a projecting portion projecting from a side surface of the body portion toward an outer circumference of the plate along the surface of the plate; and

each of the body portion and the projecting portion is in contact with the fixing region.
9. The top cover according to claim 8, wherein
the gasket includes a gate mark; and
the gate mark is located in the projecting portion.
10. The top cover according to claim 1, wherein the fixing region includes:
a first rugged portion in which a distribution density of the ridges is a first density; and
a second rugged portion in which the distribution density of the ridges is a second density greater than the first density.
11. A disk drive apparatus comprising:
a base plate including a bottom portion and a wall portion extends upward from an outer circumferential portion of the bottom portion, and surrounds the bottom portion;
the top cover of claim 1 arranged to close an upper side of the base plate to define a case together with the base plate;
a spindle motor; and
an access portion configured to perform at least one of reading and writing of information from or to a disk supported by the spindle motor; wherein
the gasket is in contact with an upper end portion of the wall portion; and
a rotating portion of the spindle motor and the access portion are accommodated in an interior of the case defined by the base plate and the top cover.
12. A disk drive apparatus comprising:
a base plate including a bottom portion and a wall portion extending upward from an outer circumferential portion of the bottom portion, and surrounding the bottom portion;
a top cover made of a metal, and arranged to close an upper side of the base plate to define a case together with the base plate;
a gasket made of an elastomer, fixed to an upper end surface of the wall portion, and in contact with a lower surface of the top cover;
a spindle motor; and
an access portion configured to perform at least one of reading and writing of information from or to a disk supported by the spindle motor; wherein
a rotating portion of the spindle motor and the access portion are accommodated in an interior of the case defined by the base plate and the top cover;
the base plate includes, in the upper end surface of the wall portion, a fixing region to which the gasket is fixed; and
in plan view, the fixing region includes a plurality of ridges and a plurality of filamentous projections extending from each of the plurality of ridges.
13. The base plate of the disk drive apparatus of claim 12, wherein at least one of the ridges is annular or substantially annular in shape.
14. The base plate of the disk drive apparatus of claim 12, wherein at least some of the plurality of ridges overlap with one another.
15. The base plate of the disk drive apparatus of claim 12, wherein
the plurality of ridges included in the fixing region include a first row of ridges overlap with one another; and
the first row extends in a first direction.
16. The base plate according to claim 15, wherein
the plurality of ridges included in the fixing region further include a second row of ridges overlap with one another;
the second row extends in a second direction different from the first direction; and
the first row and the second row cross each other.
17. The base plate according to claim 15, wherein the fixing region has a width greater than that of the gasket.
18. The base plate according to claim 15, wherein the fixing region has a width smaller than that of the gasket.
19. The disk drive apparatus according to claim 12, wherein
the gasket includes:
a body portion with a uniform or substantially uniform width; and
a projecting portion projecting from a side surface of the body portion toward an outer circumference of the wall portion along an upper surface of the wall portion; and

each of the body portion and the projecting portion is in contact with the fixing region.
20. The disk drive apparatus according to claim 19, wherein
the gasket includes a gate mark; and
the gate mark is located in the projecting portion.
21. The disk drive apparatus according to claim 12, wherein the fixing region includes:
a first rugged portion in which a distribution density of the plurality of ridges is a first density; and
a second rugged portion in which the distribution density of the plurality of ridges is a second density greater than the first density.
22. A method of manufacturing a top cover for use in a disk drive apparatus, the method comprising the steps of:
a) defining, in a surface of a plate, a fixing region including a plurality of ridges and, in plan view, a plurality of filamentous projections extending from each of the plurality of ridges;
b) cleaning the plate after step a); and
c) injection-molding a gasket on the plate after step b); wherein in step c), the gasket is fixed to the fixing region.

1460729521-0ec9daa4-8b21-44f2-a993-a944e2bade09

1. A food heating device comprised of:
a metal plate having a plurality of separately heated regions separated by a thermal break.
2. The food heating device of claim 1, wherein a first separately heated region includes a first embedded heating element and wherein a second separately heated region includes a second embedded heating element.
3. The food heating device of claim 2, wherein the plate is configured such that the first heated region can be selectively heated to at least a first temperature within a first temperature range and the second heated region can be selectively heated to at least a second temperature within a second temperature range.
4. The food heating device of claim 1, wherein first and second separately heated regions have first and second thicknesses respectively.
5. The food heating device of claim 1, wherein at least one of the separately heated regions has a first section and a second section and wherein one of the first and second sections have first and second different thickness.
6. The food heating device of claim 1, wherein the metal plate has a first top portion and a first bottom and wherein the metal plate has a thickness, which varies between said first top portion and the first bottom portion.
7. The food heating device of claim 6, wherein the first top portion and the first bottom portion are located in one of the plurality of separately heated regions.
8. The food heating device of claim 2, wherein the food heating device is a toaster and wherein the metal plate and embedded heating elements are configured to toast a bread product.
9. The food heating device of claim 8, wherein the food heating device includes a heated, food storage compartment.
10. The food heating device of claim 1, wherein the thermal break is non-linear.
11. The food heating device of claim 1, wherein the thermal break is comprised of at least one, air-filled channel that extends at least part way across the metal plate and wherein the metal plate has a thickness such that the at least one air-filled channel extends at least part way through the thickness of the metal plate.
12. The food heating device of claim 1, wherein the metal plate has a heat transfer coefficient k1 and wherein the thermal break is comprised of a solid material sandwiched between first and second regions of the plurality of regions such that the thermal break extends at least part way through and at least part way across the metal plate and has a heat transfer coefficient k2, that is less than k1.
13. The food heating device of claim 1, wherein the thermal break is comprised of at least one void formed within the metal plate, between the first and second regions and which extends at least part way across the metal plate.
14. The food heating device of claim 1, wherein the metal plate has first and second opposing sides, at least one of which is substantially planar.
15. The food heating device of claim 14, wherein the first and second sides are substantially parallel to each other.
16. The food heating device of claim 1 wherein the plurality of regions include first and second regions and wherein the first separately heated region and the second separately heated region are of different geometric areas, having equal length dimensions but different width dimensions.
17. The food heating device of claim 1, wherein a first separately heated region is heated by a first heating element and wherein a second separately heated region is heated by a second heating element, said first and second heating elements being individually controllable and embedded in the material from which the platen is made.
18. The food heating device of claim 17, wherein the first and second heating elements are electrically resistive material.
19. The food heating device of claim 18, wherein at least one of the first and second heating elements is boustrophedonic.
20. The food heating device of claim 18, wherein at least one of the first and second heating elements is crenellated.
21. The food heating device of claim 1, further comprised of a friction-reducing material adjacent the surface of the metal plate.
22. The food heating device of claim 1, wherein the metal plate is comprised of aluminum, and wherein the food heating device is further comprised of a friction-reducing material adjacent the surface of the aluminum plate.
23. The food heating device of claim 1, including a layer of polytetrafluoroethylene (PTFE) adjacent the surface of at least one of the first and second separately heated regions.
24. The food heating device of claim 1, including a sheet of polytetrafluoroethylene (PTFE), essentially free of fiberglass and comprised essentially of PTFE filaments that interlock each other at angles between 15 and 175 degrees.
25. A food heating device comprised of:
first and second metal plates, each of which has at least one heated regions, the first and second metal plates being separated from each other by a thermal break;
at least one conveyor, configured to move a food product across the surface of at least one of the first and second metal plates.
26. The food heating device of claim 25, wherein the first metal plate includes a first embedded heating element and wherein the second metal plate includes a second embedded heating element.
27. The food heating device of claim 26, wherein the first and second heating elements can be selectively heated to at least a first temperature within a first temperature range and the second heated region can be selectively heated to at least a second temperature within a second temperature range.
28. The food heating device of claim 26, wherein first and second separately metal plates have first and second thicknesses respectively.
29. The food heating device of claim 26, wherein at least one of the first and second metal plates has a first top portion and a first bottom and wherein said at least one of the first and second metal plates has a thickness, which varies between said first top portion and the first bottom portion.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A method of recovering data in a storage system, the method comprising:
upon failure to fulfill an IO request for requested data to a primary volume, determining whether the IO request references data at data addresses that may exist in a snapshot or replica;
consulting a change set to determine whether data at the data addresses referenced by the IO request are current in the snapshot or replica, the change set indicating whether data at data addresses have changed without including any changes; and
fulfilling the IO request, by providing the requested data, by accessing the snapshot or replica without further accessing the change set, if the referenced data at the data addresses are current, or issuing an error or failure status, if the referenced data at the data addresses are not current.
2. The method of claim 1, wherein the change set indicates at least one address in the snapshot or replica that is no longer current.
3. The method of claim 2, wherein the data at the at least one address has changed on a disk that services or houses the snapshot or replica.
4. The method of claim 1, further comprising:
if the change set exists on a copy-on-write region, fulfilling the IO request by employing the change set to identify a delayed copy-on-write having the requested data.
5. The method of claim 1, wherein the system supports synchronous replicas, and further comprising:
determining whether the IO request references data at data addresses that may exist in a synchronous replica;
determining whether the synchronous replica is synchronized with the primary volume;
consulting the change set, if the replica is unsynchronized, to determine whether the data at the referenced data addresses in the snapshot or replica are current;
fulfilling the IO request by accessing the synchronous replica, if the replica is synchronized or if the replica is unsynchronized but the data at the referenced data addresses are current according to the change set; or
issuing an error or failure status, if the replica is unsynchronized and the data at the referenced data addresses are not current according to the change set.
6. The method of claim 1, wherein the system supports synchronous replicas, and further comprising:
determining whether the IO request references data at data addresses that may exist in a synchronous replica;
determining whether the synchronous replica was synchronized with the primary volume at the time of the IO request, and has remained synchronized since that time;
if the replica is synchronized in this way, fulfilling the IO request by accessing the synchronous replica;
if the replica is not synchronized in this way, attempting to insert into a change log an access operation to fulfill the IO request, as follows:
if the IO request occurred before the loss of synchronization, inserting the access operation at the head of the change log, if the head of the change log is still valid;
if the IO request occurred after the loss of synchronization, inserting the access operation at the tail of the change log, if the tail of the change log is still valid;
if the IO request occurred during the loss of synchronization, inserting the access operation within the change log in chronological order, if such a location in the change log is still valid;

issuing an error or failure status, if the access operation cannot be inserted into a valid position in the change log;
applying or replaying the change log to the replica to restore synchronization, wherein any inserted access operations are fulfilled in chronological order with the applied changes.
7. The method of claim 6, wherein the change log includes at least one of an ordered list of changes to be applied to a replica to restore synchronization, and other operations such as data access requests; and entries in the change log are invalidated when successfully applied to the replica.
8. A system for coordinating data recovery in a storage system, the system comprising:
a processor; and
a memory with computer code instructions stored therein, the memory operatively coupled to said processor such that the computer code instructions configure the processor to implement:
a look up module configured to, upon failure to fulfill an IO request for requested data to a primary volume, determine whether the IO request references data at data addresses that may exist in a snapshot or replica;
a change set module configured to consult a change set to determine whether data at the data addresses referenced by the IO request are current in the snapshot or replica, the change set indicating whether data at data addresses have changed without including any changes; and
a response module configured to either fulfill the IO request, by providing the requested data, by accessing the snapshot or replica without further accessing the change set, if the referenced data at the data addresses are current, or issue an error or failure status, if the data at the referenced data addresses are not current.
9. The system of claim 8, wherein the change set indicates at least one address in the snapshot or replica that is no longer current.
10. The system of claim 9, wherein the data at the at least one address has changed on a disk that services or houses the snapshot or replica.
11. The system of claim 8, wherein the response module is further configured to, if the change set exists on a copy-on-write region, fulfill the IO request by employing the change set to identify a delayed copy-on-write having the requested data.
12. The system of claim 8, wherein the system supports synchronous replicas, and wherein the look up module is further configured to determine whether the IO request references data at data addresses that may exist in a synchronous replica and determine whether the synchronous replica is synchronized with the primary volume;
wherein the change set module is further configured to consult the change set, if the replica is unsynchronized, to determine whether the data at the referenced data addresses in the snapshot or replica are current; and
wherein the response module is further configured to fulfill the IO request by accessing the synchronous replica, if the replica is synchronized or if the replica is unsynchronized but the data at the referenced data addresses are current according to the change set, or issue an error or failure status, if the replica is unsynchronized and the data at the referenced data addresses are not current according to the change set.
13. The system of claim 8, wherein the system supports synchronous replicas, and wherein the look up module is further configured to determine whether the IO request references data at data addresses that may exist in a synchronous replica and determine whether the synchronous replica was synchronized with the primary volume at the time of the IO request, and has remained synchronized since that time; and
wherein the response module is configured to, if the replica is synchronized in this way, fulfill the IO request by accessing the synchronous replica, or, if the replica is not synchronized in this way, attempt to insert into a change log an access operation to fulfill the IO request, as follows:
if the IO request occurred before the loss of synchronization, inserting the access operation at the head of the change log, if the head of the change log is still valid;
if the IO request occurred after the loss of synchronization, inserting the access operation at the tail of the change log, if the tail of the change log is still valid;
if the IO request occurred during the loss of synchronization, inserting the access operation within the change log in chronological order, if such a location in the change log is still valid,

issue an error or failure status, if the access operation cannot be inserted into a valid position in the change log, and applying or replaying the change log to the replica to restore synchronization, wherein any inserted access operations are fulfilled in chronological order with the applied changes.
14. The system of claim 13, wherein the change log includes at least one of an ordered list of changes to be applied to a replica to restore synchronization, and other operations such as data access requests; and wherein entries in the change set are invalidated when successfully applied to the replica.
15. A non-transitory computer readable medium configured to store instructions for coordinating data recovery in a storage system to be executed by a processor, the instructions comprising:
upon failure to fulfill an IO request for requested data to a primary volume, determining whether the IO request references data at data addresses that may exist in a snapshot or replica;
consulting a change set to determine whether data at the data addresses referenced by the IO request are current in the snapshot or replica, the change set indicating whether data at data addresses have changed without including any changes; and
fulfilling the IO request, by providing the requested data, by accessing the snapshot or replica without further accessing the change set, if the referenced data at the data addresses are current, or issuing an error or failure status, if the referenced data at the data addresses are not current.
16. The non-transitory computer readable medium of claim 15, wherein the change set indicates at least one address in the snapshot or replica that is no longer current, such as if the data at that address has changed on a disk that services or houses the snapshot or replica.
17. The non-transitory computer readable medium of claim 15, wherein the system supports synchronous replicas, and further comprising:
determining whether the IO request references data at data addresses that may exist in a synchronous replica;
determining whether the synchronous replica is synchronized with the primary volume;
consulting the change set, if the replica is unsynchronized, to determine whether the data at the referenced data addresses in the snapshot or replica are current;
fulfilling the IO request by accessing the synchronous replica, if the replica is synchronized or if the replica is unsynchronized but the data at the referenced data addresses are current according to the change set; or
issuing an error or failure status, if the replica is unsynchronized and the data at the referenced data addresses are not current according to the change set.
18. The non-transitory computer readable medium of claim 15, wherein the system supports synchronous replicas, and further comprising:
determining whether the IO request references data at data addresses that may exist in a synchronous replica;
determining whether the synchronous replica was synchronized with the primary volume at the time of the IO request, and has remained synchronized since that time;
if the replica is synchronized in this way, fulfilling the IO request by accessing the synchronous replica;
if the replica is not synchronized in this way, attempting to insert into a change log an access operation to fulfill the IO request, as follows:
if the IO request occurred before the loss of synchronization, inserting the access operation at the head of the change log, if the head of the change log is still valid;
if the IO request occurred after the loss of synchronization, inserting the access operation at the tail of the change log, if the tail of the change log is still valid;
if the IO request occurred during the loss of synchronization, inserting the access operation within the change log in chronological order, if such a location in the change log is still valid;

issuing an error or failure status, if the access operation cannot be inserted into a valid position in the change log;
applying or replaying the change log to the replica to restore synchronization, wherein any inserted access operations are fulfilled in chronological order with the applied changes.
19. The non-transitory computer readable medium of claim 18, wherein the change log comprises an ordered list of changes to be applied to a replica to restore synchronization, and may also contain other operations such as data access requests; and entries in the change log are invalidated when successfully applied to the replica.
20. The non-transitory computer readable medium of claim 15, wherein the system supports synchronous replicas, and wherein the instructions further comprise:
if the change set exists on a copy-on-write region, fulfilling the IO request by employing the change set to identify a delayed copy-on-write having the requested data.