1460728541-639fff3f-0ce9-48ea-aecc-e18128f7ed3e

1. A fixation plate comprising:
an upper surface, a lower surface, a longitudinal axis, and an elongated slot, the elongated slot extending from said upper surface to said lower surface, the elongated slot including a first end, a second end, a first side, a second side and a centerline; first and second inner peripheral regions formed in the fixation plate adjacent the first and second sides of the elongated slot respectively; a first blind bore formed in the plate adjacent the first end of the slot and a second blind bore formed in the plate adjacent to the second end of the slot, wherein the first and second blind bores are substantially collinear with the centerline of the slot; and
a resilient element having a first end, a second end and an intermediate portion, the resilient element extending across at least a portion of the elongated slot, wherein the intermediate portion of said resilient element is deflectable from a first condition wherein the resilient element is received within one of the first and second inner peripheral regions to a second condition wherein the resilient element is configured to overlay at least a portion of a head of a bone screw when the head of the bone screw is at least partially inserted into said elongated slot;
wherein the first end of the resilient element is slidably received within the first blind bore and the second end of the resilient element is slidably received within the second blind bore, the elongated slot is configured to receive at least one bone fixation element so that said fixation element is permitted to translate within said slot in a direction substantially parallel to the longitudinal axis of the fixation plate, and the bone fixation element includes a head region having a groove formed thereon and a shank region, the resilient element being seated within the groove formed in the head of the bone screw when said bone screw is at least partially inserted into said elongated slot.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A system for providing Internet Protocol (IP) services, comprising:
a switch fabric;
a line interfacenetwork module coupled to the switch fabric;
a plurality of virtual routing engines (VREs) coupled to the switch fabric; and
a virtual services engine (VSE) coupled to the switch fabric;
wherein the line interfacenetwork module includes an ingress forwarding manager which maintains a steering table mapping virtual local area networks (VLANs) to one or more VREs of the plurality of VREs, receives packets and steers ingress packets across the switch fabric to a selected VRE of the plurality of VREs and transmits egress packets according to their relative priority;
wherein the selected VRE determines if a packet associated with a packet flow requires processing by the VSE by performing flow-based packet classification on the packet and evaluating forwarding state information associated with previously stored flow learning results based on a previously received packet of the packet flow; and
if the packet is determined to require processing by the VSE, then steering the packet across the switch fabric to the VSE for processing.
2. The system of claim 1, wherein the VSE comprises an advanced security engine (ASE).
3. The system of claim 2, wherein the ASE comprises a plurality of encryption accelerators, a key accelerator and a security manager configured to load balance and manage security sessions across the one or more encryption accelerators.
4. The system of claim 1, wherein the line interfacenetwork module includes an egress forwarding manager which applies priority queuing to the egress packets based on DiffServ marking and transmits the egress packets out of the line interfacenetwork module.
5. A system for providing Internet Protocol (IP) services, comprising:
a switch fabric;
a line interfacenetwork module coupled to the switch fabric;
a plurality of virtual routing engines (VREs) coupled to the switch fabric; and
a virtual services engine (VSE) coupled to the switch fabric;
wherein the line interfacenetwork module receives packets and steers ingress packets across the switch fabric to a selected VRE of the plurality of VREs and transmits egress packets according to their relative priority via an egress forwarding manager of the line interfacenetwork module which applies priority queuing to the egress packets based on DiffServ marking and transmits the egress packets out of the line interfacenetwork module;
wherein the selected VRE determines if a packet associated with a packet flow requires processing by the VSE by performing flow-based packet classification on the packet and evaluating forwarding state information associated with previously stored flow learning results based on a previously received packet of the packet flow; and
if the packet is determined to require processing by the VSE, then steering the packet across the switch fabric to the VSE for processing.
6. The system of claim 5, wherein the VSE comprises an advanced security engine (ASE).
7. The system of claim 6, wherein the ASE comprises a plurality of encryption accelerators, a key accelerator and a security manager configured to load balance and manage security sessions across the one or more encryption accelerators.
8. The system of claim 5, wherein the line interfacenetwork module includes an ingress forwarding manager which maintains a steering table mapping virtual local area networks (VLANs) to one or more VREs of the plurality of VREs.
9. A method operable within an Internet Protocol (IP) Service Generator (IPSG) system including a switch fabric, a line interfacenetwork module coupled to the switch fabric, a plurality of virtual routing engines (VREs) coupled to the switch fabric, and a virtual services engine (VSE) coupled to the switch fabric, the method comprising:
maintaining, by an ingress forwarding manager of the line interfacenetwork module, a steering table mapping virtual local area networks (VLANs) to one or more VREs of the plurality of VREs;
steering received ingress packets, by the ingress forwarding manager, across the switch fabric to a selected VRE of the plurality of VREs;
determining, by the selected VRE, if a packet received from the ingress forwarding manager and associated with a packet flow requires processing by the VSE by performing flow-based packet classification on the packet and evaluating forwarding state information associated with previously stored flow learning results based on a previously received packet of the packet flow;
if the packet is determined to require processing by the VSE, then steering the packet, by the selected VRE, across the switch fabric to the VSE for processing; and
transmitting received egress packets, by the line interfacenetwork module, according to their relative priority.
10. The method of claim 9, wherein the VSE comprises an advanced security engine (ASE).
11. The method of claim 10, wherein the ASE comprises a plurality of encryption accelerators, a key accelerator and a security manager, wherein the method further comprises load balancing and managing security sessions across the one or more encryption accelerators, by the security manager.
12. The method of claim 9, wherein the line interfacenetwork module includes an egress forwarding manager and the method further comprises applying priority queuing, by the egress forwarding manager, to the egress packets based on DiffServ marking and transmitting, by the egress forwarding manager, the egress packets out of the line interfacenetwork module.
13. A method operable within an Internet Protocol (IP) Service Generator (IPSG) system including a switch fabric, a line interfacenetwork module coupled to the switch fabric, a plurality of virtual routing engines (VREs) coupled to the switch fabric, and a virtual services engine (VSE) coupled to the switch fabric, the method comprising:
steering received ingress packets, by the line interfacenetwork module, across the switch fabric to a selected VRE of the plurality of VREs;
determining, by the selected VRE, if a packet received from the line interfacenetwork module and associated with a packet flow requires processing by the VSE by performing flow-based packet classification on the packet and evaluating forwarding state information associated with previously stored flow learning results based on a previously received packet of the packet flow;
if the packet is determined to require processing by the VSE, then steering the packet, by the selected VRE, across the switch fabric to the VSE for processing; and
transmitting received egress packets, by an egress forwarding manager of the line interfacenetwork module, out of the line interfacenetwork module according to their relative priority by applying priority queuing to the received egress packets based on DiffServ marking.
14. The method of claim 13, wherein the VSE comprises an advanced security engine (ASE).
15. The method of claim 14, wherein the ASE comprises a plurality of encryption accelerators, a key accelerator and a security manager, wherein the method further comprises load balancing and managing security sessions across the one or more encryption accelerators, by the security manager.
16. The method of claim 13, wherein the line interfacenetwork module includes an ingress forwarding manager and the method further comprises maintaining, by the ingress forwarding manager, a steering table mapping virtual local area networks (VLANs) to one or more VREs of the plurality of VREs.

1460728533-83980502-df7a-40d0-bae3-e39c140e8b46

1. A payment number intermediation method performed by an intermediary positioned along a communication path between a client and a server, comprising:
receiving a payment message from the client;
detecting an account number in the payment message after receiving the payment message;
after detecting the account number, sending a request for a limited-use payment number associated with an account identified by the account number, wherein the request identifies at least one payment limitation selected from the group consisting of i) an identity of a payee, ii) a payment amount, and iii) a time limitation;
receiving a limited-use payment number, wherein use of the limited-use payment number is subject at least to the identified payment limitation;
replacing the account number with a limited-use payment number to create a modified message; and
sending the modified message along the communication path to the server.
2. The method of claim 1, wherein detecting the account number includes identifying a user who sent the payment message and comparing an account number in the payment message with one or more stored account numbers associated with the user.
3. The method of claim 1, wherein the account number is a credit card number.
4. The method of claim 1, wherein the limited-use payment number is a one-time use credit card number.
5. The method of claim 1, wherein the limited-use payment number is a one-time use credit card number, wherein the sending of the request comprises requesting the one-time use credit card number from an account service provider.
6. The method of claim 1, wherein receiving the payment message comprises receiving a payment message addressed to the server.
7. The method of claim 1, wherein receiving the payment message comprises receiving a payment message from the client over a secure socket layer session.
8. The method of claim 1, wherein sending the modified message comprises sending the modified message to the server over a secure socket layer session.
9. The method of claim 1, wherein receiving the payment message comprises receiving the payment message from the client over a first secure socket layer session, and wherein sending the modified message comprises sending the modified message to the server over a second secure socket layer session.
10. The method of claim 1, wherein the payment limitation is the identity of the payee.
11. The method of claim 1, wherein the payment limitation is the payment amount.
12. The method of claim 1, wherein the payment limitation is a time limitation.
13. A payment number intermediation system, comprising:
a network interface;
a processor; and
data storage, wherein the data storage stores instructions executable by the processor (i) to receive a payment message from a client over the network interface; (ii) to identify a credit card number in the payment message; (iii) to replace the credit card number with a one-time use credit card number to create a modified message; and (iv) to send the modified message to a server over the network interface.
14. A payment number intermediation method performed by an intermediary positioned along a communication path between a client and a server, comprising:
receiving a payment message from the client;
after receiving the payment message, detecting a credit card account number in the payment message;
after detecting the credit card account number, replacing the credit card number with a one-time use credit card number to create a modified message; and
sending the modified message along the communication path to the server.
15. The method of claim 14, wherein the replacing of the credit card account number includes requesting the one-time use credit card number from a credit card account service provider.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A method for a wireless communication device, comprising:
determining a mode of the communications based on traffic characteristics;
setting a snooze interval based on the determined mode; and
placing the wireless communication device in a reduced power state for the snooze interval,
adjusting the snooze interval as a function of a communication data rate.
2. The method of claim 1, further comprising:
setting the snooze interval to zero for a high data rate mode of communications when a number of received data packets exceeds a first threshold value.
3. The method of claim 2, further comprising:
setting the snooze interval to a best effort value as a default value when a throughput for the communications is below a second threshold value;
processing further data communications; and
adjusting the snooze interval based on the number of packets received in the further data communications
4. The method of claim 3, wherein adjusting the snooze interval further comprises:
reducing the snooze interval when the number of packets received in the further data communications is greater than the second threshold value; and
increasing the snooze interval when the number of packets received in the further data communications is equal to zero.
5. The method of claim 1, further comprising:
setting the snooze interval to a constant bit rate value when a number of transmitted data packets exceeds a first threshold value
6. The method of claim 5, further comprising:
when communications are bi-directional communications, placing the device in the reduced power state until transmission of a data packet;
when the communications are uni-directional communications, setting a maximum snooze interval value;
processing further data communications; and
adjusting the snooze interval based on a number of packets received in the further data communications.
7. The method of claim 6, further comprising:
reducing the snooze interval when the number of packets received in the further data communications is greater than a second threshold value; and
increasing the snooze interval when the number of packets received in the further data communications is equal to zero.
8. The method of claim 1, wherein the wireless communication device is a network interface controller configured to communicate in accordance with one of the IEEE 802.11n standards.
9. A machine-readable medium comprising instructions, which when implemented by one or more machines, cause the one or more machines to:
process communications of packets of data;
determine a mode of the communications based on traffic characteristics;
set a snooze interval based on the determined mode;
place the wireless communication device in a reduced power state for the snooze interval; and
adjust the snooze interval as a function of a communication data rate.
10. The machine-readable medium of claim 9, further comprising instructions to:
set the snooze interval to zero for a high data rate mode of communications when a number of received data packets exceeds a first threshold value.
11. The machine-readable medium of claim 10, further comprising instructions to:
set the snooze interval to a best effort value as a default value when a throughput for the communications is below a second threshold value;
processing further data communications; and
adjust the snooze interval based on the number of packets received in the further data communications.
12. An apparatus, comprising:
a communication module to send and receive data packet communications in a wireless communication network;
a processor to set a snooze interval based on traffic characteristics of the communications, and to adjust the snooze interval based on a communication data rate; and
a power module to place the apparatus in a low power mode for the snooze interval.
13. The apparatus of claim 12, wherein the processor is further to:
set the snooze interval to zero for a high data rate mode of communications when a number of received data packets exceeds a first threshold value.
14. The apparatus of claim 13, wherein the processor is further to:
set the snooze interval to a best effort value as a default value when a throughput for the communications is below a second threshold value;
process further data communications; and
adjust the snooze interval based on the number of packets received in the further data communications.
15. The apparatus of claim 14, wherein the processor is further to:
reduce the snooze interval when the number of packets received in the further data communications is greater than the second threshold value; and
increase the snooze interval when the number of packets received in the further data communications is equal to zero
16. The apparatus of claim 12, further comprising:
set the snooze interval to a constant bit rate value when a number of transmitted data packets exceeds a first threshold value.
17. The apparatus of claim 16, wherein the processor comprises:
a snoozing interval determiner to:
determine whether the communications are bi-directional communications;
place the device in a reduced power state until transmission of a data packet when communications are bi-directional communications; and
set a maximum snooze interval value when the communications are uni-directional communications;

wherein the apparatus is further to:
process further data communications; and
adjust the snooze interval based on a number of packets received in the further data communications.
18. The apparatus of claim 17, wherein the snoozing interval determiner is further to:
reduce the snooze interval when the number of packets received in the further data communications is greater than a second threshold value; and
increase the snooze interval when the number of packets received in the further data communications is equal to zero.
19. The apparatus of claim 18, wherein the snoozing interval determiner is to adjust the snooze interval such that the snooze interval does not exceed the maximum snooze interval value.
20. The apparatus of claim 12, wherein the apparatus is a wireless network interface controller.