CA2414830C

Proxy method and system for secure wireless administration of managed entities

Abstract

A method, system and apparatus are described for avoiding the use of a web- server or generic security when providing network administration services remotely to managed entities using wireless technology. Instead a true Proxy device, not operating as a web-server, is used to pre-process all command traffic from wireless input devices (WID). The intervention between the WID and the managed entiti es of the Proxy isolating the managed entities from the WID, enhanced by encoding using a novel messaging protocol, further enhanced by a novel security model based on multiple pre-shared keys and algorithms together with identifiers and passwords that are not transmitted, achieves several bandwidth and security advantages including the ability to deliver TELNET services across the Internet and behind a firewall.

CA2414830C, drawing sheet 1
Sheet 1 of 12

Term

No projected expiry on record.

  1. Priority and filed
  2. Granted
  3. Today

26 claims: 13 independent, 13 dependent

  1. 1
    CA 02414830 2008-05-05 We claim:1. A method for wirelessly administering at least one managed computer via a proxy server trusted by said at least one managed computer, the method comprising: from a wireless device, transmitting an encoded message, said message including at least one command, wherein said at least one command included in said message corresponds to and is distinct from one or more operating system (OS) commands for said at least one managed computer;at the proxy server, receiving and decoding said encoded message, authenticating said wireless device and authorizing said at least one command included in said message;and sending said one or more OS commands from said proxy server to said at least one managed computer.
  2. 10
    A system, for a user to wirelessly administer at least one managed computer, the system comprising:a wireless device, constructed and adapted to create and transmit an encoded message, said message including at least one command for said at CA 02414830 2008-05-05 least one managed computer, wherein said at least one command corresponds to and is distinct form one or more operating system (OS) commands for said at least one managed computer;a proxy message processor, trusted by said at least one managed computer, said proxy message processor constructed and adapted to receive and decode said message, to authenticate said wireless device and to authorize said commands, and to send said one or more OS commands from said proxy message processor to at least one managed computer.
  3. 16
    A method as in claim 1 wherein said at least one command comprises a sequence of two or more commands, and wherein said message is encoded by mapping said sequence of two or more commands to a symbolic representation of said sequence of two or more commands.
  4. 17
    A method as in claim 16 wherein said symbolic representation is based, at least in part, on an encryption of said sequence of two or more commands.
  5. 18
    A method as in claim 1 wherein said at least one managed computer is an entity selected from the group comprising:servers, routers, desktop computers, modems, printers, switches, and mainframe computers.
  6. 19
    A method as in claim 2 wherein said wireless device comprises a portable digital computing device having access to the Internet through a radio network.
  7. 20
    A method for wirelessly administering at least one managed computer via a proxy server trusted by said at least one managed computer, the method comprising:from a wireless device, transmitting an encoded message, said message including at least one command for said at least one managed computer, said at CA 02414830 2008-05-05 least one command corresponding to and distinct from a sequence of one or more operating system (OS) commands for said at least one managed computer;at the proxy server, receiving and decoding said encoded message, authenticating said device and authorizing said at least one command;expanding said at least one command into said sequence of one or more OS commands;and then sending said sequence of one or more OS commands from said proxy server to said at least one managed computer.
  8. 21
    A method as in claim 20 wherein at least one of said one or more OS commands requires at least one parameter, and wherein said encoded message further includes said at least one parameter, and wherein said step of expanding associates said at least one parameter with said sequence of OS commands.
  9. 22
    A method as in claim 1 wherein at least one of said one or more OS commands requires at least one parameter, and wherein said encoded message further includes said at least one parameter, and wherein said method further comprises the step of associating said at least one parameter with said OS commands.
  10. 23
    A system for wireless administration of at least one managed computer, the system comprising:a proxy message processor, trusted by said at least one managed computer, wherein said at least one managed computer is selected from the group comprising: servers, routers, desktop computers, modems, printers, switches, and mainframe computers;said proxy message processor constructed and adapted to: CA 02414830 2008-05-05 (a) receive an encoded message originating from a wireless device, said message corresponding to and distinct from a sequence of one or more operating system (OS) commands for said at least one managed computer;(b) decode said message;(c) authenticate said wireless device;(d) authorize said one or more commands;(e) expand said one or more commands into the sequence of one or more OS commands;(f) send said sequence of one or more OS commands from said proxy message processor to said at least one managed computer.
  11. 24
    A system as in claim 23 wherein at least one of said one or more OS commands requires at least one parameter, and wherein said encoded message further includes said at least one parameter, and wherein said proxy message processor is further constructed and adapted to associate said at least one parameter with said sequence of OS commands.
  12. 25
    A system as in claim 23 wherein said at least one managed computer comprises a plurality of computers.
  13. 26
    A system as in claim 25 wherein said plurality of computers are organized in at least two distinct domains.