Method and arrangement to secure access to a communications network
Abstract
A method for configuring session profiles of Pseudo-Connectionless Technology, PCT (¿Pseudo-Connectionless Technology¿), in a System of Introduction of Information for Remote Access, RAL (¿Remote Access Login¿), (201), which is acting on a computer to establish a secure and remote access session from the computer to a data communication network, through a PCT device (403), wherein said PCT requires certain establishment information and uses a specialized access network and gateways for exclusive or dedicated use, such that said computer comprises communication capabilities, and in which said RAL system comprises: a Graphic Interface User, GUI (¿Graphical User Interface¿), (228), which includes connection means for a user to carry out a single connection action; a processing or processing core (227), which translates the user input taken from the GUI into signals for the appropriate underlying components, the processing core (227) also coordinates the procedures for defining a Data Protocol context into Packages, PDP (¿Packet Data Protocol¿), a PCT session that passes or transfers the session context to the PCT device (403), establishing a dial-up connection and establishing, when required, a session of Virtual Private Network, VPN (¿Virtual Private Network¿), secure between the computer (401) and the VPN gateway within the data communications network (440), so that the method comprises the steps of : - give access, by the RAL system, in a single window of said GUI, to all Information Elements, IE (¿Information Elements¿), required to establish a secure end-to-end network connection session, of such that the information elements comprise configuration information pertaining to the PCT device (403), the Pseudo-Lacking Connections Technology and the Virtual Private Network, - carrying out the configuration, by the RAL system, after a single action by the user, when importing a configuration file distributed by a PCT operator or by an IT department of the corporation or company.

Term
Term ended
Projected expiry passed 13 June 2021, 5.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
4 claims: 1 independent, 3 dependent
- 1ES 2 255 012 T3 REIVINDICACIONES 1. Un método para configurar perfiles de sesión de Tecnología Pseudo-Carente de Conexiones, PCT (“PseudoConnectionless Technology”), en un sistema de Introducción de Información para Acceso a Distancia, RAL (“Remote Access Login”), (201), que está actuando en una computadora para establecer una sesión de acceso a distancia y seguro desde la computadora a una red de comunicación de datos, a través de un dispositivo de PCT (403), en la que dicha PCT requiere una cierta información de establecimiento y utiliza una red de acceso especializado y pasarelas de uso exclusivo o dedicadas, de tal modo que dicha computadora comprende capacidades de comunicación, y en el cual dicho sistema de RAL comprende:una Interfaz Gráfica de Usuario, GUI (“Graphical User Interface”), (228), que comprende medios de conexión para que un usuario lleva a cabo una única actuación de conexión;un núcleo de procesamiento o tratamiento (227), que traduce la entrada de usuario tomada de la GUI en señales para los componentes subyacentes apropiados, el núcleo de procesamiento (227) coordina también los procedimientos para definir un contexto de Protocolo de Datos en Paquetes, PDP (“Packet Data Protocol”), de sesión de PCT que pasa o traslada el contexto de sesión al dispositivo de PCT (403), estableciendo una conexión de marcación y estableciendo, cuando se requiere, una sesión de Red Privada Virtual, VPN (“Virtual Private Network”), segura entre la computadora (401) y la pasarela de VPN dentro de la red de comunicaciones de datos (440), de tal modo que el método comprende las etapas de: - dar acceso, por parte del sistema de RAL, en una única ventana de dicha GUI, a todos los Elementos de Información, IE (“Information Elements”), requeridos para establecer una sesión de conexión a red de extremo a extremo segura, de tal manera que los elementos de información comprenden información de configuración perteneciente al dispositivo de PCT (403), a la Tecnología Pseudo-Carente de Conexiones y a la Red Privada Virtual, - llevar a cabo la configuración, por parte del sistema de RAL, tras una única actuación por parte del usuario, al importar un archivo de configuración distribuido por un operador de PCT o por un departamento de IT de la corporación o empresa.
- 2Un producto de programación informática que comprende porciones de código de programa o software para llevar a cabo todas las etapas del método de acuerdo con la reivindicación 1, cuando dicho producto se ejecuta o hace funcionar en una computadora.
- 3Un producto de programación informática de acuerdo con la reivindicación 2, de tal manera que el producto de programación informática es susceptible de cargarse directamente en una memoria interna de la computadora.
- 4Un producto de programación informática de acuerdo con la reivindicación 2, de tal manera que el producto de programación informática está almacenado en un medio utilizable por una computadora.
Independent claims4
259 paragraphs in 74 sections, as filed
ES 2 255 012 T3
DESCRIPTION
Method and arrangement for setting up a communication session in a communication network.
Field of the invention
The present invention relates to a method and an arrangement in a data communication system in Internet Protocol (IP - "Internet Protocol") environments according to the preamble of the independent claims. More specifically, it refers to remote and secure access to a data communications network, such as a company or corporation Intranet, through a device called Pseudo-Connectionless Technology (PCT - “Pseudo-Connectionless Technology "), such as a General Packet Radio Service (GPRS -" General Packet Radio Service ").
Description of Related Art
In the very near future, when commercial GPRS and other similar services are introduced, mobile or mobile personnel of companies, for example, commercial executives, consultants, sales personnel, supply fleets, etc., will be able to access your corporate network on the go, in a cost-effective way, as opposed to circuit-switched data from the previous Global System for Mobile Communications (GSM - “Global System for Mobile Communications”), which carried high per minute charges regardless of whether the data was actually transmitted. (A list of acronyms will be found at the end of the description.)
In order to achieve remote access, various procedures are required for the storage and handling of configuration information, as well as for the dynamic establishment of communication channels.
More specifically, configuration information and dynamic setup procedures belong to three different areas:
- Data link between a computing device and a mobile data communications device.
- Public communication channels, that is, data services such as, for example, GPRS, the Internet, which use the so-called IP protocol suite.
- Secure private communication channels, such as Virtual Private Networks (VPN - “Virtual Private Networks”), Authentication Services, etc.
In WO 98/32301, for example, a system and method for remote access from a central or main computer to a private network via a GPRS telephone are described.
Document US 6,012,088 describes a method for configuring an Internet access device for communication with a data transmission network.
Remote access to data networks
The so-called "manual dialing clients" and "connection managers" make it possible to automatically configure and manage network connections for computers, for example, desktop PCs, laptops, Personal Digital Assistants (PDA's - "Personal Digital Assistants"), etc. . More generally, such software or programming can be incorporated into any consumer or industrial electronic device, for example, a game console, a digital camera, a vending machine, a digital measuring device, etc., that uses a device. internal or external communications device for accessing a data network through a different telecommunications network, often public.
There are mainly two kinds of programming that are used for remote access to data networks:
- Programming for basic manual dialing connectivity, and
- Programming for manual dialing managers.
The first type of software or programming provides the basic components that are required by a computer or an integrated communications device for access to the Internet using a modem over a public telecommunications network, generally the fixed-line telephone by cable and analog. , or a mobile phone service, either analog or digital.
Said programming includes:
- Modem control procedures, which allow dialing a telephone number destined for the Point of Presence (POP - “Point Of Presence”) of the Internet Service Provider (ISP - “Internet Service Provider”), a
ES 2 255 012 T3 installation that provides a "gateway" between the telephone network and the Internet through the private network of the ISP, and that allow subsequent control of the connection.
- The formatting of the data for its adequate transfer through the telephone lines, with the use of the Point-to-Point Protocol (PPP - “Point to Point Protocol”).
- Basic user authentication mechanisms, which use standardized protocols, for example, the Password Identification Protocol (PAP), the Authentication Protocol for the Initiation of Interrogation or Demand Dialogue (CHAP - “Challenge Handshake Authentication Protocol”), or proprietary algorithms (for example, MS-CHAP, from Microsoft ™, Shiva ™ Password Identification Protocol (SPAP), and RSA ™ Securid).
- “System” functions, intended to link the different functions, the stack or stack of data communication protocols within the system, for example, the Transmission Control Protocol (TCP - “Transmission Control Protocol”) / IP, and so-called "top coat" applications.
The second type of programming, manual dialing managers, builds on the functionality of the first by providing some “value-added” functions, such as:
- Provide statistical and session information to the user, such as the time consumed during the connection, the volume of data transferred, the status of communication, information regarding network addresses, etc.
- Maintain a list of phone numbers for the ISP's POPs around the world, that is, a phone book.
- Manage all communication establishments for the different positions or services, and automatically configure all this depending on the position and service selected by the user.
- Allow the export or import of communication establishments, for example, in order to enable an IT manager to distribute establishment profiles to end users of corporations or companies. Mobile Data Technologies
There is a wide variety of fixed and mobile data communication technologies. All these technologies have in common the fact that they are always connected but require some complex establishment information. In the following, these features will be referred to as "pseudo-connectionless". These technologies also have in common the fact that they use a specialized access network and use dedicated gateways, or for exclusive use, to access the Internet. These technologies are hereinafter referred to as Pseudo-Connectionless Technologies (PCT - "Pseudo-Connectionless Technologies").
One such mobile data communication technology is the so-called GPRS technology. GPRS is a telecommunications service that is especially intended for digital cellular networks such as GSM, the Universal Mobile Telecommunications System (UMTS - “Universal Mobile Telecommunications System”) and the Multiple Access by Division in Time (TDMA - “Time Division Multiple Access”), which are digital mobile services with a presence in the United States and in other markets, and that operate in the 800 and 1,900 MHz frequency band. GPRS makes use of the principle of packet radio and is used to transfer data via eg IP and X.25 protocols from one GPRS terminal to other GPRS terminals or external data networks. GPRS has been standardized or standardized in the European Telecommunication Standardization Institute (ETSI - “European Telecommunication Standardization Institute”) (ETSI GSM 09.61, 07.07, 04.60 for GPRS and GSM technologies), and in the Society Project Third Generation Partnership Project (3GPP), for example, in the 3GPP specification 23.060. GPRS makes use of a packet data technique to transmit high-speed data and low-speed data in an efficient way, over, for example, GSM radio networks. GPRS optimizes the use of network resources and radio resources. A strict separation of radio subsystems and network subsystems is obtained, resulting in the network subsystems that can be reused by other radio access technologies.
GPRS is therefore a packet-switched data service that provides high-speed mobile data transmission that efficiently uses available bandwidth. In theory, you can achieve transmission speeds of up to several hundred kb / s. With a third-generation air link interface, such as Wideband Code Division Multiple Access (WCDMA), as used in global UMTS, standard data transfer or flow raw or raw can reach 2,000 kb / s, compared to 9.6 kb / s that GSM can provide today. Data transmission via GSM can be carried out in two different ways: circuit-switched, as in today's voice transmissions, or packet-switched, as in GPRS.
However, other fixed or mobile data communication technologies can fulfill a similar "support" role and share some characteristics with GPRS, such as the fact that they are "pseudo-connectionless" and use a network. dedicated and specialized access, as well as dedicated gateways, to access
ES 2 255 012 T3
Internet. An example is the Cellular Digital Packet Data (CDPD - “Cellular Digital Packet Data”), which refers to the standardized technology of “TR-45.6 (IS-732 and IS-732-A) of the Industry Association. of the Telecommunications (TIA - “Telecommunications Industry Association”) for CDPD ”. A “pseudo-lacking” technology of similar connections, but with a fixed line, is the Asymmetric Digital Subscriber Line (ADSL - “Asymetric Digital Subscriber Line”).
Manual dialing programming needs to be adapted to the “pseudo-lack” characteristics of connections of these technologies, and to incorporate configuration parameters and session establishment procedures specific to these technologies.
Current implementations reuse the existing programming developed for the manual dialing of the Public Switched Telephone Network (PSTN), and use certain tricks or manipulations to manage the GPRS connection from a computing device. This will be described later.
Remote Access Virtual Private Network (VPN - “Virtual Private Network”) programming
Establishing secure networks covers three areas:
Authentication: there are techniques that make it possible to guarantee that both ends of the session, the user and the remote network access server, are really who they say they are. This is achieved in a number of ways, although it generally requires that the user provide some input, for example a password, a smart card, etc., and that the machines carry out some cryptographic processing, for example , fragmentation functions. Examples of standard authentication techniques that exist in the market are the Password Authentication Protocol (PAP), the Authentication Protocol for the Initiation of Interrogation or Demand Dialogue (CHAP - “Challenge Handshake Authentication Protocol”). ”), The Extensible Authentication Protocol (EAP -“ Extensible Authentication Protocol ”), the Message Compendium algorithm number 5 (MD-5) and the Public Key Infrastructure (PKI - “Public Key Infrastructure”).
Encryption or encryption: with the use of a previously agreed encryption algorithm, the machines can treat the data they exchange by altering or distorting them in such a way that they are capable of detecting any attempt to misuse or unauthorized them, as well as guarantee the end-to-end confidentiality. However, this generally requires that the two machines have an identical set of cryptographic material or keys to generate the encryption algorithm. There are a number of encryption algorithms, such as the Data Encryption Standard (DES - “Data Encryption Standard”), the 3-DES, the Blowfish algorithm, that of Carlisle Adams and Stafford Tavares (CAST), the Standard International Data Encryption Standard (IDEA - “International Data Encryption Standard”), the Ron Code (RC-40/128), etc., as well as a certain number of key exchange mechanisms, such as Key Exchange on the Internet (IKE - “Internet Key Exchange”), Diffie-Helhnan, Rivest, Chamir and Aldeman (RSA) public key encryption algorithm, etc., with various parameters from which users can choose.
Tunnel routing or Virtual Private Networks (VPN's): In recent times, private networks, for example, of corporations, need to be isolated from the public Internet network. However, remote mobile communication users communicate through a public network, which is generally the Internet. Consequently, establishing secure networks requires a protocol that conceals the fact that traffic between private “islands” is transferred across the public “ocean” of the Internet. This is illustrated in Figure 1. This is necessary because outbound traffic from a local computer 100, within a private network 101, and transferred to a remotely connected computer 102, must be routed through a dedicated security gateway 103, for example, a VPN routing device ("router") that applies a cryptographic treatment to data traffic.
In order to achieve this, a so-called "tunnel routing protocol" is required. This protocol provides the illusion that a distant computer 102 is directly connected to the private network 101. This prevents local machines from sending data in an intelligible way through an insecure public gateway 104, when responding to a distant computer. Instead, the data sent to the remote computer is intercepted by the secure gateway 103, for example, through the use of an Address Resolution Protocol (ARP), optionally encrypted and "Encapsulated" then, and finally routed, through the Internet 105, to the remote computer 102. This private and secure data traffic is indicated in Figure 1 by a dashed line 106.
Again, there is a variety of protocols at the user's choice, each of which has its own peculiarities and requires specific configuration data. The standards of the Internet Engineering Task Force (IETF - “Internet Engineering Task Force”), such as Secure IP (IPSec - “Secure IP”), Layer 2 Tunnel Routing Protocol (L2TP - “Layer 2 Tunneling Protocol ”), General Routing Encapsulation (GRE -“ General Routing Encapsulation ”), etc., are examples of such protocols.
Commercial and secure VPN client programming generally comprises two components:
ES 2 255 012 T3
- A drive device in Kernel mode, which is installed in the operating system of the machine and intercepts all network traffic and carries out the appropriate transformations, such as formatting of packet headers, sum of checking, sequential numbering, encryption, etc.
- A configuration tool in user mode, which allows setting the parameters for the particular VPN protocol trigger device, as well as setting policy or criteria related to security, for example, what traffic should be made secure , under what conditions, with the use of what techniques, etc.
Typical use scenario with current techniques
In the very near future, when commercial GPRS and other similar services are introduced, mobile or roaming staff of a company or corporation who need to access their corporate network while on the move will be faced with two alternatives:
- carry out the installation and configuration of the appropriate software or programming and communication parameters, and
- launch or launch various applications and carry out various access information entry procedures each time you want to access your remote corporate network.
The following provides an overview of the installation and configuration stages that are required with current techniques:
1. Install and configure a modem in the PC, perhaps by using some additional actuators and / or scripts provided by the manufacturer of the equipment or GPRS handheld terminal.
2. Define a context of one or more Packet Data Protocols (PDP). This can be accomplished in a number of ways, such as:
- Statistical configuration through factory settings on the equipment or handheld terminal.
- Definition by the GPRS operator at the time of service provision, through the activation of the Subscriber Identity Module (SIM - “Subscriber Identity Module”), or by activation through an air link.
- Direct manual typing of the PDP context data on the equipment or hand-held terminal, with the use of menus.
- Through the PC, through the introduction of standard GPRS-specific initiation commands, such as “AT + CGDCON = 0, IP, internet.gprs.telia.se„ 0.1 ”(PDP context definition) in the modem parameters, or by using a Hyper Terminal ™ session and communicating the parameters to the handheld terminal through a port or serial port on the PC.
This PDP definition stage can also be carried out at the time of session establishment (see next sub-section).
3. Configure a username and password on the handheld terminal. This is optional and again can be accomplished in a number of ways:
- Introduction by manual click of these authentication credentials.
- Factory settings made by the manufacturer of the GPRS handheld terminal.
- Adjustment by the GPRS operator during the service provision procedure, for example, activation by SIM card or activation by air link.
Four. Create and configure a dial-up networking connection with a GPRS “service string” provided in the form “* 98 ** #” instead of the phone number. This is the so-called "modem compatibility" trick or manipulation, which has to be able to use existing manual dial programming.
5. Install VPN programming, for example, from a Compact Disk (CD - “Compact Disk”), and then configure the appropriate addressing and authentication options, which may involve additional programming installation and configuration, for example , the RSA SecurID, which imports a digital certificate.
When a user wishes to access a network, for example, their corporate network, through the use of the GPRS service, the procedure currently followed is as follows:
ES 2 255 012 T3
1. Physically link the PC and the hand-held terminal, for example using a serial cable, or by activating the infrared link in the hand-held terminal.
2. Optionally, start a specific GPRS schedule or script in order to carry out step 2 above (PDP context definition), and select the PDP context to be activated.
3. Start or start manual dialing programming. This activates the PDP context.
Four. Entering a username and a password is invited to do so. These are the ones that were established in stage 3 above.
5. Wait for the connection to be established, and then start the VPN software or programming.
6. Enter, if invited, authentication credentials, eg username / password, smart card / Personal Identification Number (PIN - “Personal Identification Number”) code.
As can be seen in the “Typical Use Scenario” above, the installation and session establishment can be quite complex and can be an obstacle to initial acceptance by corporate users and to additional massive use of GPRS services. .
Notably, the configuration requires a large amount of information to be entered by manual keystroke at the handheld, as well as manual configuration of programming in many places in the operating system and manual dialing / VPN programming. This requires in-depth technical knowledge that most end users will lack.
Also, the session establishment procedure requires the user to launch different applications and make multiple entries of username / password combinations, as well as optionally follow a script of some kind in order to configure the parameters. specific GPRS session data (PDP context data). This is time consuming and requires extensive technical knowledge that most end users will lack.
Furthermore, the current way of configuring and establishing such remote GPRS access is not flexible and does not allow to take advantage of the future capabilities of, for example, GPRS terminals, such as PDP context support, browsing or "browsing". using a "visited" Access Point Name (APN - "Access Point Name"), alternative ISP support and quality of service options.
This is primarily due to the fact that the PDP context data is configured either on the handheld or with the use of modem initialization commands or instructions. For this reason, depending on the PC operating system and the capabilities or capabilities of the GPRS handheld terminal, only one set of PDP context information can be stored, or else supporting several will be embarrassing.
In summary, the disadvantages of today's remote access to a private data communications network, via a PCT device, is that the management of PCT session parameters (for example, the PDP context of GPRS) they lack flexibility.
Summary of the invention
The object of the invention is to overcome the aforementioned disadvantages and to provide a configuration procedure when configuring session profiles of data communication technology in a computer, in order to establish a remote and secure access session from the computer. computer to the data communication network, which is additionally provided to the user.
This is achieved in accordance with the method and arrangement set forth in the characterizing parts of the independent claims.
Thanks to the provision of the Information Entry system for Remote Access, the information and instructions needed for the configuration and establishment of the secure network session are brought together or combined in a single interface, and thanks to the provision of the method of entering information for remote access, a single act of connection by a user will carry out remote and secure access.
Preferred embodiments are set forth in the dependent claims.
An advantage of the present invention is that the procedures for setting up and configuring the session are shorter and require less user intervention.
Another advantage of the present invention is that configuration is made easier.
ES 2 255 012 T3
Brief description of the drawings
Figure 1 shows a block diagram of a communication system according to the prior art.
Figure 2 shows a block diagram of the programming components involved according to the invention.
Figure 3 shows a flow chart of the method according to the invention.
Figure 4 shows signaling sequences according to the invention.
Description of preferred embodiments
The present invention can be briefly described as a "dialer" or remote access dialing device for manual dialing, integrated into a secure VPN client and endowed with features to support devices and services of the so-called Pseudo-Technology. lacking Connections (PCT - “PseudoConnectionless Technology”), such as GPRS devices and services, as well as an improved user interface to achieve higher capacity utilization. The invention, which comprises software or programming logic and programming components, is implemented in a computer, for example, a Personal Computer (PC "Personal Computer") - a desktop computer or a laptop, a Personal Digital Assistant (PDA - "Personal Digital Assistant") or any other industrial or consumer electronic device that has communication capabilities or intermediate connection or interface, and which will be referred to hereinafter as the Remote Access Information Entry System (RAL - "Remote Access Login").
Figure 2 illustrates an overview of the scheduling components involved in a secure GPRS remote access client, in accordance with the present invention. The RAL programming components according to the present invention are represented by reference numeral 201, and the rest of the programming components in Figure 2 belong to the prior art. The dashed lines represent the flow of configuration data, the thick solid lines represent the path or path followed by the diagrams of “user” data, from the upper layer applications, through the Kernel components and towards the terminal GPRS handheld. Microsoft's Windows ™ operating system is used as an example, although the present invention can also be applied in combination with other operating systems, such as Mac ™ OS, Palm ™ OS, EPOC ™, and the like.
The vertical areas in the Figure represent user mode 202, Kernel mode transport drive devices 203, as well as drive devices 204 Network Driver Interface Specification (NDIS). ) of Kernel mode, and are separated by horizontal lines of dots and dashes.
The programming components involved are, starting from the bottom layer, the Kernel mode NDIS 204 drive devices, which are the 205 Serial Asynchronous / Gate Drive Devices, the Network Drive Device Proxy 206 ( ND - “Network Driver”), the so-called dial-up adapter, the PPP NDIS Wide Area Network (WAN) 207, the 802.3 virtual adapter (using the Ethernet network (IEEE 802.3)) 208, Component 209 of the Point-to-Point Tunnel Routing Protocol / Layer 2 Tunnel Routing Protocol (PPTP / L2TP), provided with a virtual adapter 218, and two instances of a Third Party IPSec 210 actuation device and your virtual 211 adapter. This Third Party IPSec is an NDIS driver provided by an independent programming vendor. The virtual adapter 211 fulfills a role similar to that of the previously mentioned 802.3 virtual adapter 208. When operating in so-called “tunnel mode”, the second instance of the Third Party IPSec actuator should resemble a Network Interface Card (NIC) from the point of view of the first instance. of the Third Party IPSec actuator.
The programming components involved in the Kernel mode transport drive devices 203 are the Microsoft ™ IPSec 212 and the Transmission Control Protocol / Internet Protocol (TCP / IP) protocol drive device 213, and the UNImodem 217.
The programming components involved in user mode 202 are the Telecommunication Application Programming Interface (TAPI) 214, the Remote Access Service (RAS) 215 and the top-layer application 216, for example, a web browser or browser.
User mode 202 further comprises the RAL system 201, that is, the programming components in accordance with the present invention, which will now be described in more detail.
Starting with the lower layers, these 202 user mode components primarily include:
An Application Programming Interface (API) in connection with GPRS 220 devices and an API in connection with VPN 221 devices. In order to provide support for devices that are not standardized for
ES 2 255 012 T3 the operating system, the RAL system comprises component APIs that allow abstracting a generic behavior of these devices from the other higher programming components. This generic behavior is materialized by means of a standardized set of commands for each of the GPRS devices and the VPN device, which will be sent by the upper layer components and translated into device or system specific signals, which are indicated by arrows 222 and 223, imparted to the appropriate underlying kernel devices.
If required, a set of RAS 224 functions for VNP's and GPRS, due to possible limitations of the operating system. These components allow specific session establishment procedures to be carried out that are not covered by existing programming, eg specific GPRS functions, such as defining the PDP context.
A 225 Database of User Profiles. The RAL 201 system maintains a database containing all data relevant to the end-to-end string of configuration data that is required, by the different programming components outside of the RAL 201 system, in order to establish a secure mobile communications data connection. Notably, it allows you to flexibly manage PDP context data. Where appropriate, data will be passed or transferred to components outside of the RAL system, for example, the RAS, for manual dialing parameters such as phone numbers, etc.
Generic APIs come in two forms:
- Platform API's 226, which provide support for multiple OS platforms, eg Windows ™, Palm ™, EPOC ™, Mac ™, etc., and are only relevant in the context of programming code implementation .
- Plug-in or coupling API's, which are a set of public commands and parameters that the RAL understands or generates to support autonomous couplings 229.
The processing core 227 is the control part of the RAL 201 system. It translates input provided by the user, such as text, numbers, mouse marks, etc., taken from the Graphical User Interface (GUI) 228, into signals for the appropriate underlying components, and coordinates and activates the different procedures according to the appropriate logic, for example, define a PCT session PDP context, pass the session context to the PCT device, activate the establishment of a manual dial-up connection, and then establish the VPN connection.
The GUI 228 of the RAL system combines in the same application all the interfaces necessary for the configuration and establishment of a network connection session through pseudo-connectionless support devices, for example, GPRS, or devices standard manual dialing support, for example, from PSTN, Integrated Services Digital Network (ISDN).
An example of a GUI of the RAL system comprises a generic control window, which allows session management and provides access to "session profiles" for the three layers involved in the connection to a secure mobile communication network, VPN, GPRS (PDP), and mobile device (manual dialing by modem). An expanded background box comprises the settings for the particular configuration of the selected profile. An information element allows the three layers to be linked together, making it possible to automate the establishment for a specific session from end to end.
As an addition to the main RAL 201 system, various autonomous latching modules 229 can be communicated with the RAL 201 through a generic part of API 226, in order to carry out value-added functions that make use of features or special functions of PCT connection or PCT device. In the case of GPRS, such a hook module 229 could consist, for example, of a measuring device that records the volume of data transferred and translates it into the amount of money that the user would have to pay to the GPRS operator (this last load usage per unit volume of data transferred); the amount of money is then presented visually, immediately or in real time, to the user, by means of a GUI implemented in the hook programming code 229, which is independent of the main RAL system 201. The governing principles These hooks are that they are completely self-contained and based solely on API 226.
Figure 3 shows a flow diagram of establishing a secure remote access session from a computer, comprising the programming logic and programming components of the RAL system, to a private data communications network, through of a device of the so-called Pseudo-Connectionless Technology (PCT - “Pseudo-Connectionless Technology”), for example, a device of General Packet Radio Service (GPRS - "General Packet Radio Service").
The method includes the following stages:
301. A computer user performs a single act of connecting, for example, a dial or mouse click, which automatically activates or triggers the RAL system to carry out the following steps:
ES 2 255 012 T3
302. Define a PCT session Packet Data Protocol (PDP) context, comprising pseudo-connectionless characteristics of a PCT session.
303. Pass or pass the session context that has been defined to the PCT device.
304. Activate the establishment of a manual dial-up connection, and
305. Activate the establishment of a secure Virtual Private Network (VPN - “Virtual Private Network”) session.
The method is implemented by means of a computer programming product comprising the portions of programming code intended to carry out the steps of the method. The computer programming product is carried out on the computer.
The computer programming product is loaded, either directly or from a medium that can be used by a computer, such as a floppy disk, a CD, the Internet, etc.
The installation and configuration required for the RAL system
- A modem must be installed and configured in a computer, perhaps with the use of some additional drive devices and / or scripts provided by the manufacturer of the GPRS equipment or handheld terminal (as discussed above in the “ Description of Related Art ”).
- The user installs the RAL system programming on the computer.
- The user configures pseudo-connectionless session profiles, with all the Information Elements (IE's - “Information Elements”) necessary for the establishment of the secure end-to-end mobile network connection session. The RAL provides a single window for access to all relevant IE's. Two possible methods are:
1. The user creates a profile and fills it in or completes it using information provided by the GPRS operator or by the IT department of the corporation or company.
2. The user performs a one-click configuration by importing a configuration file distributed by the GPRS operator or by the IT department of the corporation or company.
- Optionally, configure authentication credentials in the hand-held terminal if these cannot be configured using the RAL system as a consequence of the limitations of the GPRS hand-held terminal.
The establishment of the session according to the RAL system
When a computer user wishes to access his corporate network through the GPRS service, using the RAL system, the following procedure will be followed:
- The user physically links the computer and the hand-held terminal, either with the use of a serial cable, or by activating the infrared link existing in the hand-held terminal, as previously described under the heading of the description of the related art.
- The user starts or starts the programming for the RAL system; optionally, the RAL system can be started automatically when the computer starts up, and
- marks or clicks with a cursor on a connection icon contained in the GUI or an equivalent markup symbol in the GUI, for example, pressing the “enter” button on a keyboard that acts on the computer. Future technologies may make other interface metaphors or symbolizations possible, for example, voice commands, eye movements, etc.
The diagram in Figure 4 outlines what happens on the network once the user clicks "connect." The networks involved are the trunk bus 420 of the GPRS Public Land Mobile Network (PLMN), the Public Internet network 430 and the Private IP Network 440. The procedure can be divided into the four main parts following:
302. Define a GPRS session Packet Data Protocol (PDP) context, which comprises pseudo-connectionless characteristics of a GPRS session.
303. Transfer the defined session context to the GPRS device.
304. Trigger the establishment of a dial-up connection by activating the PDP context, and
ES 2 255 012 T3
305. Activate the establishment of a secure Virtual Private Network (VPN - “Virtual Private Network”) session.
Once the user has clicked "connect", the RAL system programming, contained in the computer 401, will first communicate a message 402 to the GPRS device 403, the message 402 comprising the GPRS session parameters that they were configured when the session profile was created. These parameters define the pseudo-connectionless characteristics of the GPRS session, and form the so-called "PDP context".
These parameters are, for example, PDP Type, Access Point Name (APN), compression options, IP address, and quality of service options. All of these parameters are optional in a PDP context definition message. In the event that they have not been explicitly set, it is possible to set them later, either by the computer 401 during the PPP negotiation phase 405, provided by the GPRS network in the interrogation step 407 on the Location Register of Address (HLR - “Home Location Register”), either by default setting in the 403 handheld terminal.
With current GPRS terminals, the 402 message is transferred with the use of a standard AR command, which is sent to the terminal through a PC peripheral interface, such as, for example:
- a door or serial access,
- a door or access in parallel,
- an interface of the International Association of Memory Cards for Personal Computers (PCMCIA “Personal Computer Memory Card International Association”),
- a computing bus, for example, Micro Channel Architecture (MCA - "Micro Channel Architecture"), Industrial Standard Architecture (ISA - "Industry Standard Architecture"), Enhanced ISA (EISA - "Enhanced ISA"), a local bus of the Association of Electronic and Video Standards (VESA - “Video Electronics Standards Association”), a Peripheral Component Interconnect (PCI - “Peripheral Component Interconnect”) a miniPCI, a Small Computer System Interface (SCSI), a Fiber Channel, a Serial Bus Protocol with a Firewire physical layer conforming to IEEE 1394,
- a Universal Serial Bus port (USB - “Universal Serial Bus”),
- an Infrared Data Association (IrDA - “Infrared Data Association”) interface,
- a short-distance radio interface with Bluetooth technology.
Next, the RAL 401 system programming logic appeals to the manual dialing capabilities of the Operating System in which it resides. For Windows ™ 98, NT or 2000, it makes use of the functions provided by the Remote Access Service (RAS) component. Alternatively, said operating system can be any of the existing ones, such as Palm ™, EPOC ™, Mac ™, Unix ™; in which case such manual dialing capabilities make use of capabilities provided by RAS equivalent OS functions, or by functions provided by independent third party programming. The parameters that are transferred to the RAS are manual dialing parameters, for example, the authentication protocol, the policy or criteria for assigning addresses, compression, etc., as well as authentication credentials that are optionally used for the case of the non-transparent GPRS access.
In Windows ™, RAL's system programming logic writes manual dialing parameters to a system file, a file called a phone book, which is then ready for the RAS when the RAS performs the dial-up procedure. manual dialing. The RAL system programming logic also indicates the RAS from which the file is to be read when it activates RAS manual dialing. This file also contains, with strong encoding, the service string, ie the phone number, for GPRS, eg * 98 ** 1 #.
The authentication credentials are placed in an “opaque” memory position (Random Access Memory (RAM - “Random Access Memory”)) by the RAL system programming logic, from where they will be later retrieved by the RAS with the use of standard functions of the Operating System (OS - “Operating System”). A pointer indicating this position is passed to the RAS.
Once the RAS has been activated or commissioned, it performs the following operations without the intervention of the RAL system programming logic:
Send a "Dial" command 404 to the GPRS device 403 with the GPRS "service string". Introduce the so-called “PPP negotiation phase” 405 (which ends in 414), a stage that comprises, in turn, three consecutive stages:
ES 2 255 012 T3
1. PPP Link Control Protocol (LCP): computer 401 and GPRS device 403 exchange various messages in order to negotiate link parameters, for example, Maximum Receive Unit (MRU - " Maximum Receive Unit ”), the Authentication Protocol.
2. PPP Authentication: Optionally, the RAS component 215 of the computer 401 retrieves the authentication credentials from RAM and transfers them through the GPRS phone 403.
3. PPP Network Control Protocol (NCP - “Network Control Protocol”) / IP Control Protocol (IPCP - “IP Control Protocol”): the RAS requests certain IP network parameters (as per the communicated requirements by the RAL system) in a "PPP IPCP configuration request" message. These parameters include, for example, the criteria for assigning IP addresses, name servers, end-to-end compression, and so on.
This third stage activates, in turn, the GPRS handheld terminal 403, in order to initiate, at 406, a PDP context activation procedure with the GPRS Support Node in Service (SGSN - "Serving GPRS Support Node ”) From the GPRS network. This "PDP Context Request Activation" message 406 contains the APN and optionally the authentication credentials.
The PPP IPCP configuration phase will end when the GPRS network confirms the end of the PDP context activation procedure 413. The handheld terminal will then return to the computer 401 a "PPP IPCP configuration confirmation" 414, which notifies the RAS of the conclusion of the session establishment. The focus of control then returns to the RAL system.
Depending on the service scenario, the PDP context activation procedure within the GPRS network will be more or less complex.
Various combinations of cases are possible here, for example the Transparent or Non-Transparent case, and the Navigation or No Navigation case.
The behavior of the network is determined by the APN that is transferred through the GPRS Support Node in Service (SGSN) and the Gateway GPRS Support Node (GGSN - “Gateway GPRS Support Node”) at the time of the PDP context activation. This is independent of the RAL system.
It is the SGSN that determines, based on the APN, the behavior with respect to navigation, the SGSN then establishes a GPRS Tunneling Protocol (GPT - “GPRS Tunneling Protocol”) tunnel and passes the APN to the GGSN, which is the one that determines behavior with respect to access transparency.
For example, in the most complicated case, which is the non-transparent navigation access:
- The SGSN will interrogate, 407, the HLR in order to verify the activation parameters of the PDP context with the subscriber's records, thus allowing to prevent fraudulent use and filling in or completing the optional parameters that may not have been defined with anteriority.
- The SGSN will interrogate, 408, the Domain Name Service (DNS - “Domain Name Service”) about the APN.
- The DNS will return an IP address destined to be used by the GGSN, that is, the home GGSN or a GGSN belonging to the visited network, depending on the operator's navigation criteria implemented in the DNS.
- The SGSN sends a message, 409, of "PDP Context Request Creation", which contains the APN and the authentication credentials, to the GGSN.
- Based on the APN, the GGSN determines that it has to carry out a non-transparent access procedure. Consequently, it contacts a 410 server located on the private corporate network (for example, a Remote Authentication Dial-in User Service (RADIUS) and / or a Dynamic Configuration Protocol of Main Computer (DHCP - “Dynamic Host Configuration Protocol”)), in order to obtain an IP address, which it assigns to the Mobile Station that activated the PDP context in the first place, 411.
- The GGSN returns a message 412 of "generate PDP context acceptance", which contains the IP address that it assigned to the GPRS handheld terminal 403 and to the computer 401.
- The SGSN transfers this message to the GPRS handheld terminal 403 in a "PDP context response activation" message 413.
ES 2 255 012 T3
- The GPRS handheld terminal 403 generates a PPP IPCP configuration confirmation message 414, which it transfers to the RAS of the computer via, for example, the serial link or via infrared. This message 414 comprises the IP settings.
Once the RAS receives this PPP IPCP configuration confirmation message 414, it correctly configures the TCP / IP stack or stack of the computer Operating System 401 and binds or associates it with the NDIS level actuators. bottom for manual NDISWAN dialing -See Figure 2.
The RAS then generates a response to the RAL system software or programming to confirm that the GPRS connection has been established successfully.
In cases where the VPN components are to be used, as indicated in the user-defined profile, the RAL system then activates the next stage, with the necessary procedures to establish a secure VPN session.
For example, based on the user configuration parameters it stores, the RAL system selects a VPN device, for example, Microsoft ™ IPSec 212, illustrated in Figure 2, and Microsoft ™ L2TP 209, or a Third Party IPSec actuator 210, and transfers, either through the RAS, 215, either directly, 223, the additional required parameters, such as the VPN Gateway Name or the IP address, the authentication protocol, the pointer pointing to the authentication credentials, eg digital certificates or username / password, which may have been defined using the RAL system.
The VPN programming will then carry out the necessary steps to establish the secure connection through the negotiation of encryption keys or bulk encryption with the VPN gateway 415, with the use of the Internet Key Exchange Protocol (IKE - “Internet Key Exchange”) of Ipsec 416, and to then establish the VPN tunnel, for example, the L2TP 417, and authenticate the user 418, which may optionally involve a RADIUS Question 419 / Authentication, Authorization, Computation (AAA).
The invention is not limited to the above-described embodiments. Various alternatives, modifications, and equivalents can be used. Consequently, the foregoing embodiments are not to be construed as limiting the scope of the invention, which is defined by the accompanying claims.
Acronyms
3GPP Third Generation Participatory Society Project.
AAA Authentication, Authorization, Computation, by extension of the IETF protocol suite to carry out these functions.
ADSL Asymmetric Digital Subscriber Line.
API Application Programming Interface.
APN Access Point Name.
ARP Address Determination Protocol.
CAST Carlisle Adams and Stafford Tavares.
Compact Disc CD.
CDPD Cellular Digital Packet Data.
CHAP Authentication Protocol for Initiation of Interrogation or Demand Dialogue.
DECT Enhanced Digital Cordless Telephone.
DES Data Encryption Standard.
DHCP Dynamic Host Configuration Protocol.
DNS Domain Name Service.
EAP Extensible Authentication Protocol.
EISA ISA Enhanced.
ES 2 255 012 T3
ETSI
GGSN
GPRS
GRE
GSM
GTP
GUI
HLR
IDEA
IE
IETF
IKE
IP
IPSec
IPCP
IrDA
ISA
ISDN
ISP
L2TP
LCP
MCA
MD-5
MRU
MS-CHAP
MSC
NCP
ND
NDIS
NIC
YOU
PAP
Pc
PCI
European Institute for Telecommunications Standardization. Gateway GPRS Support Node.
General Packet Radio Service.
General Addressing Encapsulation.
Global System for Mobile Communications.
GPRS Tunnel Routing Protocol.
Graphical User Interface.
Domicile Location Record.
International Data Encryption Algorithm.
Information Element.
Internet Engineering Working Group.
Key Exchange on the Internet.
Internet Protocol.
Secure IP (according to the IETF).
IP Control Protocol.
Infrared Data Association.
Standard Industrial Architecture.
Digital Network of integrated services.
Internet Service Provider.
Layer 2 Tunnel Routing Protocol (according to the IETF). Link Control Protocol.
Micro Channel architecture.
Message Compendium Algorithm number 5.
Maximum Reception Unit.
CHAP from Microsoft.
Mobile Switching Center.
Network Control Protocol.
Network Drive Device.
Network Drive Device Interface Specification. Network Interface Card.
Operating system.
Password Authentication Protocol.
Personal computer.
Interconnection of Peripheral Components.
ES 2 255 012 T3
PCMCIA
PCS
PCT
PDA
PDP
PIN
PKI
PLMN
POP
PPP
PPTP
PSTN 25 QoS
RADIUS
RAL
RAM
RAS
RC
RC-40/128
RSA
SCSI
SGSN
SIM
SPAP
TCP
AUNT
UI
UMTS
USB
VESA
VPN
WAN
WCDMA
International Association of Memory Cards for Personal Computers.
Personal Communications System.
Pseudo-Connectionless Technology.
Personal Digital Assistant.
Packet Data Protocol.
Number of personal identification.
Public Key Infrastructure.
Public Land Mobile Network.
Point of Presence.
Point to Point Protocol.
Point-to-Point Tunnel Routing Protocol (Microsoft).
Public Switched Telephone Network.
Quality of service.
Remote Authentication Dialing User Service.
Information Entry System for Remote Access.
Random access memory.
Remote Access Server.
Ron code.
RC with 40-bit or 128-bit key.
Public key encryption algorithm from Rivest Shamir and Aldeman, or company of the same name, specializing in security software or programming.
Small Computer System Interface.
GPRS Support Node in Service.
Subscriber Identity Module.
Shiva's Password Authentication Protocol.
Transmission Control Protocol.
Telecommunications Industry Association.
User interface.
Universal Mobile Telecommunications System.
Universal Serial Bus.
Local bus of the Association of Electronic and Video Standardizations.
Virtual Private Network.
Wide Area Network.
Multiple Access by Division in Broadband Code.
Contents74
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
23 members in 10 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 0002446 | Sweden | A | |
| 0002446 | Sweden | A | |
| 20000002446 | Sweden | – | |
| 000244604007772 | – | – | – |
| SE20000002446 | – | – | – |
Members23
| Document | Office | Kind | |
|---|---|---|---|
| SE0002446D0 | Sweden | D0 | |
| SE0002446L | Sweden | L | |
| WO0201822A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU7473701A | Australia | A | |
| SE518604C2 | Sweden | C2 | |
| EP1302032A1 | European Patent Office (EPO) | A1 | |
| JP2004502345A | Japan | A | |
| US2004054794A1 | United States of America | A1 | |
| EP1450571A1 | European Patent Office (EPO) | A1 | |
| EP1302032B1 | European Patent Office (EPO) | B1 | |
| AT278303T | Austria | T | |
| ATE278303T1 | Austria | T1 | |
| DE60106047D1 | Germany | D1 | |
| ES2228881T3 | Spain | T3 | |
| HK1071651A1 | Hong Kong, China | A1 | |
| DE60106047T2 | Germany | T2 | |
| EP1450571B1 | European Patent Office (EPO) | B1 | |
| AT312485T | Austria | T | |
| ATE312485T1 | Austria | T1 | |
| DE60115725D1 | Germany | D1 | |
| ES2255012T3This record | Spain | T3 | |
| DE60115725T2 | Germany | T2 | |
| US7152160B2 | United States of America | B2 |
Numbers
- Publication
- 2255012
- Publication, DOCDB
- 2255012
- Publication, EPODOC
- ES2255012T
- Application
- 4007772
- Application, DOCDB
- 04007772
- Application, EPODOC
- ES20040007772T
Titles2
- Spanish
- METODO Y DISPOSICION PARA CONFIGURAR UNA SESION DE COMUNICACION EN UNA RED DE COMUNICACIONES.
- English
- METHOD AND PROVISION TO CONFIGURE A COMMUNICATION SESSION IN A COMMUNICATIONS NETWORK.
Classification
- CPC, 13
- H04L63/0272
- H04L12/1425
- H04L12/2856
- H04L12/4633
- H04L63/083
- H04L63/164
- H04W8/18
- H04W74/00
- H04W80/04
- H04W76/10
- H04W12/02
- H04W12/03
- H04W12/069
- IPC, 10
- G06F13 00
- H04L12 28
- H04L12 46
- H04L12 56
- H04L29 06
- H04W12 00
- H04W12 06
- H04W74 00
- H04W76 02
- H04W80 04