1460728075-e54d1470-2f70-4e7e-9929-2a7712637ddd

1. A tire monitoring system comprising:
a vehicle body side controller able to transmit a wireless signal to each tire through a vehicle body side antenna arranged near each tire in a vehicle in which tires are mounted on both transversal sides orthogonal to a running direction so as to form a pair; and
a sensor unit arranged in each tire and measuring a state of each tire and able to transmit information based on its measuring result as a wireless signal,
wherein said vehicle body side controller respectively transmits a request signal to each sensor unit through each vehicle body side antenna, and the tire monitoring system has each sensor unit able to receive this request signal through a tire side antenna arranged in each tire;
said vehicle body side antenna and the tire side antenna are constructed by a coil antenna;
said tire side antenna is arranged in each tire such that a coil axis of said tire side antenna approximately becomes parallel to a rotating axis of each tire; and
said vehicle body side antenna is arranged near each tire such that no coil axis of said vehicle body side antenna becomes parallel to the rotating axis of each tire.
2. The tire monitoring system according to claim 1, wherein said vehicle body side antenna is arranged above each tire so as to incline the coil axis of said vehicle body side antenna with respect to the rotating axis of each tire; and
an inclination direction of the coil axis of said vehicle body side antenna is set so as to incline the coil axis of said vehicle body side antenna on a transversal outside of the vehicle toward a downward direction.
3. The tire monitoring system according to claim 1, wherein a central position of said vehicle body side antenna is arranged outside a central position of said tire side antenna in a transversal direction of the vehicle.
4. The tire monitoring system according to claim 2, wherein a central position of said vehicle body side antenna is arranged outside a central position of said tire side antenna in a transversal direction of the vehicle.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A sample inspection apparatus comprising:
a sample stage to hold a wafer to be inspected,
an electron optical system to direct electrons to the sample,
a power source connected to the sample stage,
an image detector that detects the reflected electrons, and
an image processor that inspects the sample based on image signal from the image detector,
wherein said power source applies a potential to the sample stage so that the directed electrons are substantially reflected before the directed electrons reach a surface of the sample.
2. A sample inspection apparatus, according to claim 1, wherein,
said electron optical system directs electrons to an area of the sample.
3. A sample inspection apparatus, according to claim 1, wherein, said image detector is comprised of TDI sensor.
4. A sample inspection apparatus, according to claim 1, said electron optical system further comprising:
a Schottky electron source.
5. A sample inspection apparatus comprising:
means for holding a sample to be inspected,
means for directing electrons to the sample,
means for reflecting the electrons directed to the sample before the electrons reach a surface of the sample,
means for detecting at least the reflected electrons,
and
means for inspecting the sample based on output signal from the means for detecting.
6. A sample inspection apparatus comprising:
an electron optic system to direct electrons to an area of a sample to be inspected,
a power source to apply a predetermined voltage to the sample to be inspected, and
an image detector to detect an image of the reflected electrons from the sample,
a signal processor,
wherein the directed electrons are substantially reflected just before reaching a surface of the sample, and
said signal processor analyzes the image signal to detect a defect in the sample.
7. A sample inspection apparatus comprising:
a sample stage to hold a wafer to be inspected,
an electron optical system to direct electrons to the sample,
a power source that gives a potential to the sample,
an image detector that detects an image due to the electrons reflected from the sample before the directed electrons reach a surface of the sample,
an image signal processor that inspects the sample by comparing image signals obtained in the image detector.
8. A sample inspection apparatus comprising:
a sample stage to hold a wafer to be inspected,
an electron optical system to direct electrons to the sample,
a power source that gives a potential to the sample,
an image detector that creates an image signal based on detection of least electrons which are reflected from the sample before the directed electrons reach a surface of the sample, and
a signal processor that inspects the sample based on the output of the image detector.
9. A sample inspection apparatus comprising:
means for holding a sample to be inspected,
means for decelerating a directed electron beam before the sample,
means for detecting the reflected electrons turned before impinging on the sample,
means for creating an image attributed to the reflected electrons, and
means for inspecting the sample by comparing obtained images.

1460728068-b0f95ba7-453f-40bc-af88-61fde8bdff05

1. An article of manufacture comprising computer readable program code embodied thereon, which when executed by a computer, performs a method for controlling access to a network, the method comprising:
receiving, by a gateway server, an access request from a client application running on a computing device for accessing a remote network, wherein the access request comprises a username and a user password as contextual information for use in authorizing access to the remote network,
wherein the access request comprises at least one of a first type of access request and a second type of access request, wherein the username associated with said first type of access request includes a user identifier, and wherein the username associated with said second type of access request includes a user identifier in combination with other contextual information, wherein the other contextual information comprises contextual information about the computing device and the client application requesting access to the remote network;

submitting, by the gateway server, an authorization query to a directory server, wherein the authorization query comprises the contextual information contained in the access request received from the client application to access the remote network;
receiving, by the gateway server, an authorization result from the directory server in response to the authorization query, the authorization result being dynamically generated in real-time by the directory server based on a determination by the directory server as to the type of access request associated with the submitted authorization query,
wherein for the first type of access request, the authorization result indicates whether the user is authorized to access the remote network based on an evaluation of the user identifier and the user password included in the submitted authorization query, and
wherein for the second type of access request, the authorization result is generated by evaluating the user identifier in combination with the other contextual information included in the submitted authorization query using one or more network connection rules, wherein the authorization result comprises a connection object comprising a network connection rule which specifies at least one rule to be applied by the gateway server to establish a network connection between the client application and the remote network based on the user identifier in combination with the other contextual information;

establishing, by the gateway server, a network connection between the client application and the remote network, when a successful authorization result is generated in response the first type of access request; and
establishing, by the gateway server, a network connection between the client application and the remote network in accordance with the network connection rule, when a successful authorization result is generated in response the second type of access request.
2. The article of manufacture of claim 1, wherein the directory server comprises an LDAP (Lightweight Directory Access Protocol) server, and wherein in response to a first type of access request, the directory server performs a BIND process and a SEARCH process using the username and user password to authenticate the user and to determine if the user is authorized to access the remote network.
3. The article of manufacture of claim 1, wherein submitting an authorization query to a directory server further comprises submitting an authentication request to the directory server to authenticate an identity of an endpoint, wherein the endpoint comprises one of the user, the computing device, the client application or a combination thereof.
4. The article of manufacture of claim 1, wherein the connection object is a data structure comprising a plurality of data blocks, wherein a first data block comprises the network connection rule, wherein a second data block comprises at least a portion of the contextual information of the access request.
5. The article of manufacture of claim 1, wherein the network connection rule comprises a firewall rule.
6. The article of manufacture of claim 5, wherein the firewall rule comprises one of a rule that specifies an IP address that the client application can access and a rule that specifies which port the client application can connect to or both.
7. The article of manufacture of claim 1, wherein the network connection rule comprises a network condition.
8. The article of manufacture of claim 7, wherein the network condition specifies a network configuration.
9. The article of manufacture of claim 1, wherein the contextual information about the client application comprises an application identifier.
10. The article of manufacture of claim 1, wherein the contextual information about the client application identifies an application type of the client application.
11. The article of manufacture of claim 1, wherein the user identifier and the user password comprise contextual information about the user.
12. The article of manufacture of claim 1, wherein the contextual information further comprises a role of the user.
13. The article of manufacture of claim 1, wherein the contextual information about the computing device comprises a device identifier that identifies a device type of the computing device.
14. The article of manufacture of claim 1, wherein the contextual information about the computing device comprises information regarding an operating system of the computing device.
15. The article of manufacture of claim 1, wherein the contextual information about the computing device comprises location information regarding a location of the computing device.
16. The article of manufacture of claim 1, wherein the contextual information further comprises connection information regarding a type of network connection.
17. The article of manufacture of claim 1, wherein the contextual information further comprises information regarding a date or time of day or both of the access request.
18. A gateway server for controlling access to a network, comprising:
a memory; and
a processor coupled to the memory and configured to execute code stored in the memory for:
receiving, by the gateway server, an access request from a client application running on a computing device for accessing a remote network, wherein the access request comprises a username and a user password as contextual information for use in authorizing access to the remote network,
wherein the access request comprises at least one of a first type of access request and a second type of access request, wherein the username associated with said first type of access request includes a user identifier, and wherein the username associated with said second type of access request includes a user identifier in combination with other contextual information, wherein the other contextual information comprises contextual information about the computing device and the client application requesting access to the remote network;

submitting, by the gateway server, an authorization query to a directory server, wherein the authorization query comprises the contextual information contained in the access request received from the client application to access the remote network;
receiving, by the gateway server, an authorization result from the directory server in response to the authorization query, the authorization result being dynamically generated in real-time by the directory server based on a determination by the directory server as to the type of access request associated with the submitted authorization query,
wherein for the first type of access request, the authorization result indicates whether the user is authorized to access the remote network based on an evaluation of the user identifier and the user password included in the submitted authorization query, and
wherein for the second type of access request, the authorization result is generated by evaluating the user identifier in combination with the other contextual information included in the submitted authorization query using one or more network connection rules, wherein the authorization result comprises a connection object comprising a network connection rule which specifies at least one rule to be applied by the gateway server to establish a network connection between the client application and the remote network based on the user identifier in combination with the other contextual information;

establishing, by the gateway server, a network connection between the client application and the remote network, when a successful authorization result is generated in response the first type of access request; and
establishing, by the gateway server, a network connection between the client application and the remote network in accordance with the network connection rule, when a successful authorization result is generated in response the second type of access request.
19. An article of manufacture comprising computer readable program code embodied thereon, which when executed by a computer, performs a method for controlling access to a network, the method comprising:
receiving, by a directory server, an authorization query from a gateway server, wherein the authorization query comprises a username and a user password as contextual information contained in an access request received by the gateway server from a client application running on a computing device requesting access to a remote network,
wherein the access request comprises at least one of a first type of access request and a second type of access request, wherein the username associated with said first type of access request includes a user identifier, and wherein the username associated with said second type of access request includes a user identifier in combination with other contextual information, wherein the other contextual information comprises contextual information about the computing device and the client application requesting access to the remote network;

determining, by the directory server, the type of access request associated with the received authorization query;
performing, by the directory server, an authorization process based on the determined type of access request,
wherein for the first type of access request, the authorization process comprises evaluating the user identifier and the user password included in the received authorization query to determine whether the user is authorized to access the remote network, and
wherein for the second type of access request, the authorization process comprises evaluating the user identifier in combination with the other contextual information included in the received authorization query using one or more network connection rules, wherein the network connection rules specify different rules by which the gateway server can establish a network connection between the client application and the remote network based on the user identifier in combination with the other contextual information;

dynamically generating, by the directory server, an authorization result in real-time based on results of the evaluation of the contextual information,
wherein for the first type of access request, the authorization result indicates whether the user is authorized to access the remote network based on the user identifier and the user password, and
wherein for the second type of access request, the authorization result comprises a connection object comprising a network connection rule which specifies at least one rule to be applied by the gateway server to establish a network connection between the client application and the remote network based on the user identifier in combination with the other contextual information;

sending, by the directory server, the authorization result to the gateway sever as a response to the authorization query to authorize the gateway server to establish a network connection between the client application and the remote network, when a successful authorization result is generated in response to the first type of access request; and
sending, by the directory server, the authorization result comprising the connection object to the gateway sever as a response to the authorization query to authorize the gateway server to establish a network connection between the client application and the remote network in accordance with the network connection rule, when a successful authorization result is generated in response to the second type of access request.
20. The article of manufacture of claim 19, wherein the directory server comprises an LDAP (Lightweight Directory Access Protocol) server, and wherein in response to a first type of access request, the directory server performs a BIND process and a SEARCH process using the username and user password to authenticate the user and to determine if the user is authorized to access the remote network.
21. The article of manufacture of claim 19, wherein receiving an authorization query from a gateway server further comprises receiving an authentication request from the gateway server to authenticate an identity of an endpoint, wherein the endpoint comprises one of the user, the computing device, the client application or a combination thereof, wherein the method further comprises performing an authentication process to authenticate an identity of the endpoint using the contextual information contained in the authorization query and directory information accessed by the directory server.
22. The article of manufacture of claim 21, further comprising verifying the identity of the endpoint using secondary data from one or more remote or local data sources other than the directory information.
23. The article of manufacture of claim 19, wherein the network connection rule comprises a firewall rule.
24. The article of manufacture of claim 23, wherein the firewall rule comprises one of a rule that specifies an IP address that the client application can access and a rule that specifies which port the client application can connect to or both.
25. The article of manufacture of claim 19, wherein the network connection rule comprises a network condition.
26. The article of manufacture of claim 25, wherein the network condition specifies a network configuration.
27. A directory server for controlling access to a network, comprising:
a memory; and
a processor coupled to the memory and configured to execute code stored in the memory for:
receiving, by the directory server, an authorization query from a gateway server, wherein the authorization query comprises a username and a user password as contextual information contained in an access request received by the gateway server from a client application running on a computing device requesting access to a remote network,
wherein the access request comprises at least one of a first type of access request and a second type of access request, wherein the username associated with said first type of access request includes a user identifier, and wherein the username associated with said second type of access request includes a user identifier in combination with other contextual information, wherein the other contextual information comprises contextual information about the computing device and the client application requesting access to the remote network;

determining, by the directory server, the type of access request associated with the received authorization query;
performing, by the directory server, an authorization process based on the determined type of access request,
wherein for the first type of access request, the authorization process comprises evaluating the user identifier and the user password included in the received authorization query to determine whether the user is authorized to access the remote network, and
wherein for the second type of access request, the authorization process comprises evaluating the user identifier in combination with the other contextual information included in the received authorization query using one or more network connection rules, wherein the network connection rules specify different rules by which the gateway server can establish a network connection between the client application and the remote network based on the user identifier in combination with the other contextual information;

dynamically generating, by the directory server, an authorization result in real-time based on results of the evaluation of the contextual information,
wherein for the first type of access request, the authorization result indicates whether the user is authorized to access the remote network based on the user identifier and the user password, and
wherein for the second type of access request, the authorization result comprises a connection object comprising a network connection rule which specifies at least one rule to be applied by the gateway server to establish a network connection between the client application and the remote network based on the user identifier in combination with the other contextual information;

sending, by the directory server, the authorization result to the gateway sever as a response to the authorization query to authorize the gateway server to establish a network connection between the client application and the remote network, when a successful authorization result is generated in response to the first type of access request; and
sending, by the directory server, the authorization result comprising the connection object to the gateway sever as a response to the authorization query to authorize the gateway server to establish a network connection between the client application and the remote network in accordance with the network connection rule, when a successful authorization result is generated in response to the second type of access request.
28. The directory server of claim 27, wherein the directory server comprises an LDAP (Lightweight Directory Access Protocol) server, and wherein in response to a first type of access request, the directory server performs a BIND process and a SEARCH process using the username and user password to authenticate the user and to determine if the user is authorized to access the remote network.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A leveling arrangement for a vehicle, comprising:
a support plate coupled to a frame of the vehicle;
a rocker plate rotationally coupled to a wheel of the vehicle at a first rotational axis and pivotally coupled to the support plate at a pivot point, the pivot point offset a preset distance from the first rotational axis;
an actuator arranged to pivot the rocker plate with respect to the support plate about the pivot point in response to a leveling signal; and
a free link pivotally coupled to the actuator at a first end of the free link and pivotally coupled to the rocker plate at a second end of the free link, and arranged to lengthen a rotation of the rocker plate when the actuator is extended at least a preset length.
2. The leveling arrangement of claim 1, further comprising a leveling module arranged to output the leveling signal in response to receiving a first vehicle sensor signal representing a lateral tilt of the vehicle andor a second vehicle sensor signal representing a pitch angle of the vehicle.
3. The leveling arrangement of claim 1, further comprising a control component arranged to receive the leveling signal and to cause the actuator to pivot the rocker plate with respect to the support plate an amount as represented by a property of the leveling signal.
4. The leveling arrangement of claim 1, further comprising a grooved guide plate coupled to the support plate and arranged to guide an action of the actuator through multiple stages of extension, the free link arranged to lengthen the rotation of the rocker plate during one or more stages of the multiple stages.
5. The leveling arrangement of claim 4, wherein a length of the free link is held against the rocker plate and not allowed to pivot during one or more other stages of the multiple stages and the free link is allowed to pivot with respect to the rocker plate during the one or more stages of the multiple stages, the free link lengthening the rotation of the rocker plate when allowed to pivot with respect to the rocker plate.
6. The leveling arrangement of claim 5, wherein the rocker plate is rotated by the actuator from a first point on the rocker plate during the one or more stages of the multiple stages and the rocker plate is rotated by the actuator from a second point on the rocker plate during the one or more other stages of the multiple stages.
7. The leveling arrangement of claim 1, wherein the free link provides a positive mechanical advantage to the actuator in pivoting the rocker plate throughout a full range of action of the actuator.
8. The leveling arrangement of claim 1, wherein the actuator adjusts a distance of a center of the wheel from a preselected feature of the vehicle and adjusts a ground clearance of the vehicle at the wheel, via pivoting the rocker plate with respect to the support plate.
9. The leveling arrangement of claim 1, wherein the leveling arrangement is configured to be field-installed on an existing vehicle, the field-installation using drive components of the existing vehicle.
10. A leveling system for a vehicle, comprising a plurality of the leveling arrangements of claim 1, and a processorcontroller arranged to independently control each leveling arrangement of the plurality of leveling arrangements.
11. A method of leveling a vehicle, comprising:
receiving, from a first vehicle sensor, a first signal representing a lateral tilt of the vehicle;
receiving, from a second vehicle sensor, a second signal representing a pitch angle of the vehicle; and
leveling the vehicle based on at least one of the first signal and the second signal, the leveling including independently adjusting a location of one or more wheels of the vehicle with respect to a body of the vehicle.
12. The method of claim 11, further comprising pivoting one or more offset rocker plates with respect to the body of the vehicle in response to the first signal andor the second signal, the one or more wheels of the vehicle individually coupled to the one or more offset rocker plates.
13. The method of claim 11, further comprising adjusting a vertical distance of a center of the one or more wheels of the vehicle from a preselected feature of the vehicle.
14. The method of claim 13, wherein the preselected feature includes one of a portion of the body of the vehicle, a portion of a frame of the vehicle, or a portion of a chassis of the vehicle.
15. The method of claim 13, further comprising concurrently increasing a vertical distance of a first quantity of wheels of the vehicle from the preselected feature of the vehicle andor concurrently decreasing a vertical distance of a second quantity of wheels of the vehicle from the preselected feature of the vehicle.
16. The method of claim 15, wherein the first quantity of wheels is located at a fore end of the vehicle and the second quantity of wheels is located at an aft end of the vehicle.
17. The method of claim 15, wherein one wheel of the first quantity of wheels is located at a fore end of the vehicle and another wheel of the first quantity of wheels is located at an aft end of the vehicle, and one wheel of the second quantity of wheels is located at a fore end of the vehicle and another wheel of the second quantity of wheels is located at an aft end of the vehicle.
18. The method of claim 11, further comprising generating a plurality of different leveling signals, each of the different leveling signals of the plurality based on at least the first signal and the second signal, and each of the plurality of different leveling signals generated for a different wheel position of the vehicle.
19. The method of claim 11, further comprising receiving a different leveling signal at each of a plurality of leveling arrangements, and leveling the vehicle via the plurality of leveling arrangements, the one or more wheels of the vehicle individually coupled to a leveling arrangement of the plurality.
20. The method of claim 11, further comprising leveling the vehicle longitudinally and laterally based on the vehicle traversing sloped terrain having a longitudinal slope component and a lateral slope component.