Mobile unit configuration management for wlans
Abstract
A normal communications inhibitor comprising: an electronic device comprising a data representation; and a program running on the electronic device to allow or inhibit wireless communications through at least one wireless local area network between a wireless device (18) and at least one resource, the wireless local area network being subjected to a or more of the IEEE 802.11 family of specifications; the program being configured to allow or inhibit communications between the wireless device (18) and at least one resource based on a determination of compliance with whether the wireless device (18) complies with at least one standard corresponding to an identifier of a point of access (14) or a subnet (26); wherein the program is configured to select the at least one standard from a collection of one or more requesting standards based on the identifier of the access point (14) or subnet (26), characterized in that the program is configured to determine the determination of compliance based on at least one determination of the structure / function of at least one aspect of structure or function of the wireless device (18), Compliance determination includes determining whether the wireless device (18) is inhibited from communicating with the at least one resource.

Term
Term ended
Projected expiry passed 8 August 2023, 3.1 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
49 claims: 3 independent, 46 dependent
- 1ES 2 333 862 T3 REIVINDICACIONES 1. Un inhibidor de comunicaciones normal que comprende:un dispositivo electrónico que comprende una representación de datos;y un programa que se ejecuta en el dispositivo electrónico para permitir o inhibir comunicaciones inalámbricas a través de al menos una red de área local inalámbrica entre un dispositivo inalámbrico (18) y al menos un recurso, estando sometida la red inalámbrica de área local a una o más de la familia de especificaciones IEEE 802.11;estando configurado el programa para permitir o inhibir comunicaciones entre el dispositivo inalámbrico (18) y al menos un recurso basado en una determinación de cumplimiento de si el dispositivo inalámbrico (18) cumple con al menos una norma que corresponde a un identificador de un punto de acceso (14) o de una subred (26);en el que el programa se configura para seleccionar la al menos una norma de una colección de una o más normas solicitantes basadas en el identificador del punto de acceso (14) o de la subred (26), caracterizado porque el programa se configura para determinar la determinación de cumplimiento basado en al menos una determinación de la estructura/función de al menos un aspecto de estructura o función del dispositivo inalámbrico (18), la determinación de cumplimiento incluye determinar si el dispositivo inalámbrico (18) se inhibe de comunicarse con el al menos un recurso.
- 2El inhibidor de comunicaciones normal de la reivindicación 1, en el que el programa se configura para seleccionar al menos una norma de una o más normas solicitantes basadas en un identificador de un punto de acceso (14).
- 3El inhibidor de comunicaciones normal de la reivindicación 1, en el que el programa se configura para seleccionar al menos una norma de una colección de una o más normas solicitantes basadas en un identificador de una subred.
- 4El inhibidor de comunicaciones normal de la reivindicación 1, en el que el programa se configura para verificar periódicamente la integridad del software y de los datos almacenados.
- 5El inhibidor de comunicaciones normal de la reivindicación 1, en el que la norma contiene información sobre las versiones requeridas del software de la unidad móvil y de los datos almacenados, o del hardware de la unidad móvil.
- 6El inhibidor de comunicaciones normal de la reivindicación 1, en el que el programa se configura para verificar periódicamente el funcionamiento del software y de las conexiones o sesiones de red.
- 7El inhibidor de comunicaciones normal de la reivindicación 1, en el que el programa se configura para verificar periódicamente el funcionamiento del hardware de la unidad móvil.
- 8El inhibidor de comunicaciones normal de la reivindicación 2 ó 3, en el que el programa se configura para determinar el identificador de un punto de acceso (14) o de una subred (26) a partir de la información recibida a través de un punto de acceso (14).
- 9El inhibidor de comunicaciones normal de la reivindicación 2 ó 3, en el que el identificador de un punto de acceso (14) o de una subred (26) comprende al menos una porción de una dirección IP.
- 10El inhibidor de comunicaciones normal de la reivindicación 2 ó 3, en el que el identificador de un punto de acceso (14) o de una subred (26) comprende un ESSID.
- 11El inhibidor de comunicaciones normal de la reivindicación 1, en el que el programa se configura para inhibir las comunicaciones de la unidad móvil (18) si la unidad móvil (18) no se puede autentificar.
- 12El inhibidor de comunicaciones normal de la reivindicación 1, en el que la norma comprende información seleccionada de un grupo que consiste en información de seguridad, en el que la información de seguridad comprende además una o más claves maestras, claves pre-compartidas, fichas, y/o certificados;o información de radio, en el que la información de radio comprende además uno o más códigos de países, indicaciones de potencia de la señal transmitida, y/o indicaciones de canal;o información de hardware, en el que la información de hardware comprende además una o más indicaciones del sistema operativo, y/o indicaciones de la interfaz de red;o información de software, en el que la información de software comprende además una o más indicaciones de soportes lógicos inalterables de la interfaz de red, indicaciones de aplicaciones de software, indicaciones del controlador de la interfaz de red, indicaciones de activar/ desactivar el protocolo, indicaciones de software antivirus, indicaciones de red privada virtual, indicaciones de compartición de archivos, y/o indicaciones de compartición de impresora.
- 13El inhibidor de comunicaciones normales de la reivindicación 1, en el que:ES 2 333 862 T3 el programa se configura para permitir o inhibir las comunicaciones normales entre el dispositivo inalámbrico (18) y al menos un recurso basado en la existencia de datos que representan una norma correspondiente a un identificador de un punto de acceso (14) o de una subred (26).
- 14Un sistema para el refuerzo de configuraciones de unidades móviles (18) que comprende:un cliente de software de gestión de configuración (34) en las unidades móviles (18), uno o más servidores (10, 20) para controlar el hardware, el software y las configuraciones de datos almacenados en las unidades móviles (18), una o más subredes (26) conectadas al uno o más servidores (10, 20), uno o más perfiles de configuración (30) específicos para alguna de las una o más de las subredes (26) en las que las unidades móviles (18) pueden transitar, uno o más puntos de acceso inalámbricos (14) conectados a cada una de la una o más subredes (26) y capaz de comunicarse con las unidades móviles (18);en el que las unidades móviles (18) que no son capaces de cumplir los requerimientos de gestión de configuración para una subred (26) particular no se les permite asociarse con aquella subred (26), caracterizado porque la determinación de conformidad con los requerimientos de gestión de configuración se basa en al menos una determinación de estructura/función de al menos un aspecto de la estructura o función de la unidad móvil (18), y se lleva a cabo en el uno o más servidores.
- 15El sistema de la reivindicación 14, en el que el uno o más perfiles de configuración para la unidad móvil (18) es específico para el tipo de unidad móvil 18, o para el cometido de la unidad móvil (18).
- 16El sistema de la reivindicación 14, en el que el uno o más perfiles de configuración es específico para el usuario de la unidad móvil (18).
- 17El sistema de la reivindicación 14, en el que el software y los datos almacenados de la unidad móvil o las configuraciones de hardware de unidad móvil están bajo la gestión de configuración.
- 18El sistema de la reivindicación 17, en el que la integridad del software y de los datos almacenados o del software de funcionamiento y de las conexiones o sesiones de red se verifica periódicamente.
- 19El sistema de la reivindicación 17, en el que el uno o más perfiles de configuración (30) contiene información de las versiones requeridas del software y de los datos almacenados de la unidad móvil.
- 20El sistema de la reivindicación 14, en el que la integridad del hardware se verifica periódicamente.
- 21El sistema de la reivindicación 14, en el que uno o más perfiles de configuración (30) contienen información de las versiones requeridas del hardware de la unidad móvil.
- 22El sistema de la reivindicación 14, en el que el funcionamiento del hardware de la unidad se verifica periódicamente.
- 23El sistema de la reivindicación 14, en el que un servidor de gestión de configuración (10) determina el perfil a ser utilizado por el punto de acceso (14) de la unidad móvil (18) con la que se asocia.
- 24El sistema de la reivindicación 14, en el que el cliente (34) determina en la unidad móvil (18) la identidad de la subred (26) a partir de la información recibida a través de los puntos de acceso (14).
- 25El sistema de la reivindicación 24, en el que el identificador de la subred es la IP de la máscara de dirección de la subred.
- 26El sistema de la reivindicación 24, en el que la subred (26) se identifica por el ESSID como se especifica en la familia de protocolos IEEE 802.11.
- 27El sistema de la reivindicación 14, en el que uno o más perfiles de configuración (30) se almacenan en la unidad móvil (18) y se invocan cuando la unidad móvil (18) transita a una subred especifica (26) de la una o más subredes (26).
- 28El sistema de la reivindicación 27, en el que uno o más perfiles de configuración (30) se sincronizan periódicamente entre el uno o más servidores (10, 20) y cada unidad móvil (18). ES 2 333 862 T3
- 29El sistema de la reivindicación 28, en el que un servidor (10, 20) autentifica la unidad móvil (18) antes de que se sincronicen el uno o más perfiles de configuración (30).
- 30El sistema de la reivindicación 28, en el que la unidad móvil (18) autentifica un servidor antes de que se sincronicen el uno o más perfiles de configuración (30).
- 31El sistema de la reivindicación 28, en el que el sistema verifica la integridad del uno o más perfiles de configuración (30) con anterioridad a su utilización.
- 32El sistema de la reivindicación 28, en el que se cargan o actualizan en la unidad móvil (18) uno o más perfiles de configuración (30) de modo que resulte disponible el perfil (30) requerido por una subred (26).
- 33El sistema de la reivindicación 14, en el que uno o más servidores (10, 20) pueden actualizar el software y los datos almacenados en las unidades móviles (18).
- 34El sistema de la reivindicación 33 en el que un servidor (10, 20) autentifica la unidad móvil (18) antes de cargarse el software, o en el que la unidad móvil (18) autentifica un servidor (10, 20) antes de que se cargue el software.
- 35El sistema de la reivindicación 33, en el que el sistema verifica la integridad del software cargado y de los datos almacenados antes de su utilización.
- 36El sistema de la reivindicación 33 en el que el servidor (10, 20) mantiene los registros usados para asegurar la conformidad con los términos y condiciones de la licencia de software.
- 37El sistema de la reivindicación 33, en el que el software se carga o actualiza en la unidad móvil (18) de modo que pueda cumplir los requerimientos de gestión de configuración para una subred particular (26).
- 38El sistema de la reivindicación 14, en el que dos o más servidores de gestión de configuración (10) están organizados jerárquicamente.
- 39El sistema de la reivindicación 38, en el que las normas de gestión de configuración de un nivel superior de la jerarquía se pueden modificar en niveles inferiores.
- 40El sistema de la reivindicación 38, en el que las normas de gestión de configuración se pueden crear en los servidores (10, 20) en cualquier nivel de la jerarquía.
- 41El sistema de las reivindicaciones 39 ó 40, en el que las normas establecidas en un nivel superior de la jerarquía no se pueden modificar en niveles inferiores de la jerarquía.
- 42El sistema de la reivindicación 14, en el que los usuarios de unidades móviles individuales (18) pueden crear y modificar el uno o más perfiles de configuración (30) para sus unidades móviles (18).
- 43El sistema de la reivindicación 42, en el que las normas de gestión de configuración establecidas por el uno o más servidores (10, 20) no pueden modificarse por los usuarios.
- 44El sistema de la reivindicación 14, en el que la red inalámbrica utiliza señales de radiofrecuencia.
- 45El sistema de la reivindicación 44, en el que la red inalámbrica de área local es conforme con la familia de especificaciones IEEE 802.11, o con las especificaciones promulgadas por la Bluetooth SIG, Inc.
- 46El sistema de la reivindicación 14, en el que el perfil de configuración (30) comprende información procedente de un grupo que consiste en información de seguridad, en el que la información de seguridad comprende además una o más claves maestras, claves compartidas con anterioridad, fichas y/o certificados;o información de radio, en la que la información de radio comprende además uno o más códigos de países, indicaciones de potencia de la señal de transmisión y/o indicaciones de canal;o información de hardware, en el que la información de hardware comprende además una o más indicaciones del sistema operativo, y/o indicaciones de la interfaz de red;información de software, en el que la información de software comprende además una o más indicaciones de soportes lógicos inalterables de la interfaz de red, indicaciones de aplicaciones de software, indicaciones de controlador de interfaz de red, indicaciones para habilitar/deshabilitar el protocolo, indicciones de software antivirus, indicaciones de red virtual privada, indicaciones de compartición de archivos, y/o indicaciones de compartición de impresoras.
- 47El sistema de la reivindicación 23 ó 24, en el que se inhiben las comunicaciones normales de la unidad móvil (18), si no se puede autentificar la unidad móvil (18).
- 48El sistema de la reivindicación 14, en el que el servidor del perfil de configuración (10) gestiona también las configuraciones de los puntos de acceso (14), u otros dispositivos de infraestructura de red. ES 2 333 862 T3
- 49El sistema de la reivindicación 14, en el que los puntos de acceso (14) se adaptan para autentificar las unidades móviles (18), o para actuar como servidores apoderados para uno o más servidores de seguridad (20).
Independent claims49
114 paragraphs in 7 sections, as filed
ES 2 333 862 T3
DESCRIPTION
Mobile unit configuration management for WLANs.
This application is in part a continuation of US Patent Application No. 10 / 215,701 entitled Mobile Unit Configuration Management for Wireless Local Area Networks (WLANs), filed August 9, 2002, which is incorporated herein in its entirety. as a reference in its entirety for each of its teachings and achievements
Field of the invention
The present invention relates to the management of configurations of mobile units that operate in a Wireless Local Area Networks (WLAN) environment. More specifically the invention relates to a system for managing hardware and software configurations to enforce configuration management standards on mobile units.
Background of the invention
Currently, WLANs are in common use in large and small businesses, as well as in public Internet access points and in home environments. Millions of access points and mobile units are currently deployed. Enterprises typically deploy wireless access points in one or more subnets frequently in multiple geographic locations. There is also a growing trend towards the use of wireless local area network (WLAN) technology for public Internet access points used by travelers or other mobile users.
In a WLAN, one or more base stations or Access Points (AP) are bridged between a cable network and radio frequency or infrared connections to one or more mobile stations or Mobile Units (UM), the UMs can be any of one wide variety of devices including laptops, personal digital assistants (PDAs), wireless barcode scanners, wireless points of sales systems or payment terminals, and many more specialized devices. Most WLAN systems used in business and public access environments adhere to one or more of the IEEE 802.11 family of specifications.
In a typical corporate environment mobile units roam between one or more subnets used by that company. The environments and services for these subnets are often markedly different. The configuration requirements for hardware and software for mobile units can therefore change markedly between subnets. Managing these configurations for large numbers of mobile units using a large number of subnets can be a significant problem. This problem is made more difficult by the fact that third-party service providers operate some subnets used by mobile units, while other networks are operated by the company itself. Finally any practical WLAN configuration management system must provide a method for updating software and configuration information on mobile units.
Dynamic node configuration management is widely practiced in local area networks. Various examples of well established dynamic configuration management protocols are known. A widely deployed example is the BOOTP protocol (see document RFC951) and its extensions (see for example document RFC2132) that allows a server to configure parameters and upload files to a network node under management. However, these protocols and the corresponding Dynamic Host Configuration Protocol (DHCP; RFC2131) only work at startup or initial load time of the network node and do not attempt to control network access based on configuration management rules.
Many standard network management tools include dynamic network node configuration management capabilities. Some examples of these tools include Hewlett Packard's Open View, IBM's Tivioli network management products, and Computer Associates' Unicenter management product. In all cases, these products are based on an existing network connection (that is, coupled to a TCP / IC protocol) and therefore none of these products can limit network access based on the application of management standards. setting.
US5367635 assigned to Bauer and Kepke describes a system that uses the Simple Network Management Protocol (SNMP) to manage parameters and configuration files on network nodes. This system requires an existing TCP / IP connection for SNMP sessions, and therefore cannot limit network access based on the application of configuration management rules.
WO 01/61965 describes a method and apparatus for reconfiguring parameters to establish a connection with a new host after a computer has moved to a new location or a new network. A self-sensing algorithm is proposed that processes all available network profiles in order to establish a connection with a new host. If no suitable profile is present, the most suitable work profile is used.
US 2002/0007407 describes a method and apparatus for configuring a wireless network adapter. The adapter is configured to recognize and connect to one or more networks based on software profiles
ES 2 333 862 T3 loaded in or created in the adapter. In order to establish a connection with an access point, all available profiles are tested within the network.
Document US 2002/0077094 proposes a software database connected to a mobile communication network containing the most important versions of software loaded on mobile stations. A download unit checks the software of the mobile unit using the database and, if necessary, uploads the software to the mobile station.
In US 5651006 assigned to Fujino, et al., A hierarchical network management system is described, in which one or more servers distributed along a hierarchy of subnets use the SNMP protocols to manage the configurations of the nodes in specific bases of sub-networks. This system requires a TCP / IP connection for SNMP sessions, and therefore cannot limit network access based on compliance with configuration management standards.
US 5655081 assigned in its entirety to Bonelli, et al., Describes a system, in which a network management server uses agents that execute a set of specific scripts on network nodes to discover and manage the use of network services. net. This system requires an existing network connection or sessions (typically running over the TCP / IP protocol), and therefore cannot limit network access based on compliance with configuration management standards.
US 55872931 assigned to Chivaluri describes a system, in which a hierarchy of management agents tries to autonomously execute correction scripts when a failure is detected. This system does not attempt to limit network access based on compliance and focuses on correcting the failure rather than complying with configuration management standards.
Summary of the invention
The present invention overcomes the shortcomings of prior art WLAN configuration management systems by providing a system for creating, updating, and managing hardware and software profiles for mobile units that roam across multiple WLAN subnets.
In one aspect, the invention comprises a normal communications jammer, further comprising: an electronic device comprising a representation of data; the data comprising a program for inhibiting normal wireless communications over at least one wireless local area network between a wireless device and at least one resource; the program being configured to allow or inhibit normal communications between the wireless device and the at least one resource; the program being configured to allow or inhibit normal communications between the wireless device and at least one resource based on a compliance determination of whether the wireless device complies with at least one standard; the compliance determination being based on at least one structure / function determination of at least one aspect of the structure or function of the wireless device performed by a program executed on the wireless device. In a preferred embodiment, the at least one rule is selected from a collection of one or more selected rules based on an access point or subnet identifier.
In another aspect, the invention comprises a management configuration system, further comprising: a client program running on a wireless device; the client program being configured to determine an identifier of an access point through which the wireless device can communicate, and based on the determination, selecting a configuration profile from a collection of one or more configuration profiles and configuring the device according to the configuration profile. In a preferred embodiment, the system further comprises a standard by which the wireless device is configured according to a determinable profile; the client program being further configured to provide an indication that the wireless device is configured according to the profile in order to produce a normal communication jammer to allow normal communications between the wireless device and at least one server program.
In another aspect, the invention comprises a normal communications inhibitor, further comprising: an electronic device comprising a representation of data; the data comprising a program for inhibiting normal wireless communications over at least one wireless local area network between a wireless device and at least one resource; the program being configured to allow or inhibit normal communications between the wireless device and at least one resource based on the existence of data representing a rule that corresponds to an identifier of an access point or a subnet.
In yet another aspect, the invention comprises a system for applying mobile unit configurations, further comprising a configuration management software client on the mobile units, one or more servers to control hardware, software and data configurations. in mobile units, one or more subnets connected to one or more servers, one or more specific configuration profiles for one of the one or more subnets through which the mobile units can transit, one or more wireless access points connected to each of the one or more subnets and capable of communicating with the mobile units .
ES 2 333 862 T3
It will be appreciated that the following statements of the features of the invention are not intended to be exhaustive or limiting, the proper scope thereof being appreciated by reference to this entire disclosure and the substance of the claims.
Brief description of the drawings
The invention will be described with reference to its preferred and alternative embodiments in conjunction with the drawings in which:
Figure 1 is a complete diagrammatic view of one embodiment of this invention;
Figure 2 is a schematic diagram of a configuration management profile for one embodiment of the invention;
Figures 3A, 3B, 3C, 3D and 3E is a flow chart of the configuration management procedure for an embodiment of the invention;
Figure 4 is a complete diagrammatic view of an alternative embodiment of the invention; Y,
Figure 5 is a flow chart of a simplified procedure for one embodiment of the invention.
Detailed description of alternative and preferred embodiments
The following detailed description refers to the accompanying drawings and describes exemplary embodiments of the present invention. It is possible to make other embodiments and modifications to exemplary embodiments. Therefore, the following detailed descriptions are not meant to limit the invention.
Compendium of the invention
The invention provides the capabilities to enforce hardware and software requirements in mobile units operating on Wireless Local Area Networks (WLANs). The invention allows to dynamically change the configuration rule with the access point or subnet association. When a mobile unit connects to a new subnet or access point, the system falls back to, and then checks the appropriate configuration profile for that subnet or access point. In this way, the system ensures that the configuration of the mobile unit meets the requirements of the subnet being used. Capabilities under configuration management may include:
1. security and software capabilities including, antivirus programs, software detection programs, PKI programs and certificates, VPN programs, shared security keys, master security keys, and other authentication and encryption programs or tokens;
2. software applications;
3. allowed network protocols and protocol parameters and settings;
Four. permitted operating system versions and settings or parameters;
5. radio and network interface card configurations including, transmitted signal strength, transmit and receive channel, and country codes;
6. miscellaneous devices, device drivers and firmware for network cards and other devices, and;
7. access to stored data, network printers, file shares, and other network services.
Thus the invention provides organizations with the ability to ensure the security, compatibility and capacity of mobile units as they move through various subnets. In a preferred embodiment and in other embodiments the mobile unit profile information is provided by the same procedures that enforce standards at access points (APs) and other infrastructure components. In some infrastructures, a completely closed system is provided in which configuration management profile settings are applied to mobile units and access points, thus combining the management of access points (APs) and mobile devices and ensuring the consistency between mobile units and access points. Therefore, a more robust system is further provided, among other things, because the best source of access point configuration is the network management component. Such an integrated environment helps ensure consistency of the mobile unit configuration with other managed network components.
ES 2 333 862 T3
In some embodiments, the mobile unit maintains one or more configuration profiles. The correct configuration profile is invoked based on subnet addresses, access point associations, or other subnet or access point identifiers. Examples of subnet identifiers include subnet address masks or the Extended Service Setting Identifier (ESSID) as defined in the IEEE 802.11 family of specifications. Examples of access point identifiers include MAC addresses or Base Station Service Identifier (BSSID). The mobile unit can receive the subnet identifier or the access point identifier issued by the access points from beacons.
A mobile unit determines the subnet identifier or access point identifier when it receives information from a beacon or initializes an association, or the mobile unit may search for a known ESSID and BSSID. The mobile unit then falls back to the correct configuration profile for that subnet. The configuration requirements for hardware and software can be checked against the capability of the mobile unit and the applied parameter settings. Configuration requirements can be defined for particular hardware components, executable programs, or stored data items. In some embodiments, the version of the hardware component, the software component, or the stored data is verified. If the configuration requirements can be met and the required capacity is available, the hardware and software configuration parameters are set to the values specified in the profile. Once configured, the mobile unit can create a full association with an access point on the subnet.
In some embodiments, the system authenticates the mobile unit before normal communications are established. In most cases, the authentication operation takes place before the configuration of the mobile unit is verified. The configuration management server typically grants a period of time to the mobile unit to communicate the authentication and configuration management information that follows the authentication. If the configuration cannot be verified or is incorrect, communication with the mobile unit can be terminated or restricted as required. In other cases, the authentication operation may follow the configuration verification operation. Typically, the authentication server will grant the access point a period of time to verify the configuration and then authenticate it. Communications with unauthenticated mobile units will be terminated or restricted as appropriate. Those skilled in the art will be familiar with the many suitable existing and emerging authentication schemes. In some embodiments, in order to better coordinate this procedure, the authentication server may be integral with the configuration management server. In some embodiments, the mobile unit may also authenticate a server or network association in yet another possible security operation.
As an additional security operation, the configuration management system can verify the integrity of any executable programs and data stored on the mobile unit to ensure that they have not been altered either accidentally or maliciously. At the same time, integrity and functional checks can be carried out on the mobile unit hardware.
If the mobile unit cannot meet the configuration management requirements, it may not be allowed to associate with the subnet, or it may only be granted restricted access. An unidentified or unverified mobile unit may also not be allowed access to the network or may have restricted access. Limited network access can be achieved in a number of ways, including the use of Virtual Local Area Networks (VLANs) or access control lists.
In some alternative embodiments, the configuration management server directly checks, controls and maintains the configurations in the mobile unit, possibly with the help of a configuration management client in the mobile unit. The configuration management servers determine the subnet or access point identification, and invoke the correct profile before the mobile unit can complete the association with that access point or subnet. The identification information can be acquired from the access point or from the information transmitted from the configuration management client in the mobile unit. The server uses the identification information to call up the correct profile and to check, configure and manage the mobile unit. In some embodiments, the configuration management servers are distributed among the access points. In some of these embodiments the access points will communicate with the mobile units using protocol communications (data connection layer) Layer 2 Open Systems Interconnection (OSI) until the association between the mobile unit and the access point has been established. access. These alternative embodiments eliminate the need to store configuration management profiles in mobile units or to synchronize these profiles. In some alternative embodiments the access points may also act as authentication servers, or as proxies for the authentication server. Otherwise the alternative embodiments have the same capabilities and functionality as already discussed.
A configuration management server or configuration management client will periodically check the configuration of the mobile unit once it has associated it with a particular subnet. The server or the client can verify that the configuration parameters and the hardware and software versions have not been altered. You can also periodically check the integrity and functionality of hardware and software. At the same time, the server or client can verify that the executable programs intended to run still work and that the required network connections or sessions are still active. These checks ensure that the configuration of the mobile unit has not been altered due to a malfunction, inadvertent action, or malicious action.
ES 2 333 862 T3
One or more configuration management servers control the configuration profiles for the mobile units. The servers can periodically synchronize the stored profiles with those of the mobile units. In general, the synchronization will be carried out over a secure connection. In most cases, the configuration management server will authenticate the mobile unit using the services of the security server and the mobile unit will authenticate the configuration management server before synchronization takes place. If the configuration profiles or the configuration management client are up-to-date on the mobile unit, a check can be carried out to ensure the integrity of the update. The synchronization procedure can be applied before an association has been completed, in the case where a mobile unit does not have the correct profile for a particular subnet. The servers can also initiate synchronization when profile updates are available for some mobile units. In some alternative embodiments, the one or more configuration management servers may maintain and store the profiles and remotely manage the configurations of the mobile units. In this alternative case it is not necessary to upload profile information to the mobile unit.
In some embodiments, the one or more configuration management servers may have the capabilities to update stored data and software modules. The configuration management server can determine which versions of stored data and software modules are present in the mobile unit and the versions updated to those specified in the profiles. In most cases, the configuration management server will authenticate the mobile unit and the mobile unit will authenticate the configuration management server before the software is updated. This procedure may involve upgrade and version upgrade and rollback. Once the software or stored data has been updated, the installation can be verified to ensure its integrity. The software update procedure can be applied before a partnership is completed in the case where the mobile unit does not have the correct software or data to operate on a given subnet. In some embodiments, the configuration management servers can track the licensed software deployed and used on each mobile unit to ensure adherence to the license terms and conditions.
In some embodiments, the subnets may be connected to each other in a hierarchical manner using one or more major networks. The use of routers, firewalls, or other network isolation or filtering methods can segregate those subnets. Configuration management servers can also be organized in a hierarchy. In the hierarchy, each server can control mobile unit configurations in one or more subnets. Some servers, of a higher level in the hierarchical establishment, can exercise the role of masters for other servers. The management of the hierarchical configuration management servers can itself be hierarchical. In general, profile information or standards set higher in the hierarchy can be supplemented or made more specific, but cannot be changed lower. By way of example, a corporate configuration management server can directly control mobile unit configurations on one or more main office networks. This server will also propagate the base profiles to other servers used by specific departments or at remote sites. These other servers can control mobile unit configurations in one or more departmental or remote site subnets. Personnel at remote sites or department levels can make permissible changes to configuration management profiles to support specific local requirements.
In some embodiments, mobile unit users can make changes to the configuration management profiles for their specific devices. These changes may allow users to modify the configurations of their mobile units to meet specific application requirements. In general, these changes will supplement or make more specific, the requirements of the profiles distributed by the configuration management servers, but they cannot change already established rules.
In some embodiments the configuration profiles used are specific to the subnet and the particular mobile unit. These specific mobile unit profiles allow a heterogeneous mix of mobile units to use the same subnets. At the same time, mobile unit configuration profiles can be optimized for a specific application or for a set of applications. Finally, the configuration profile can reflect specific requirements or preferences of an individual user.
Overview of a realization
In some embodiments of the invention, the configuration management profile information is stored in the mobile unit and used by a local client. In these embodiments, a configuration management server synchronizes the configuration profiles stored in the mobile units. A general block diagram of a possible embodiment is shown in Figure 1.
One or more configuration management servers 10 store the profiles 28 for one or more mobile units 18. As a mobile unit roams between the one or more access points 14 in the one or more subnets 26, the configuration profile 30 used at the mobile unit is determined by the identity of the access point or subnet to which the mobile unit is associated. The configuration management client 34 invokes the correct configuration profile and runs it. Periodically, the configuration management client verifies that the required configuration is being maintained. The configuration management server can also distribute software and data updates
ES 2 333 862 T3 stored to mobile units. The one or more subnets 26 are connected by one or more major networks 24. These networks can be organized in a hierarchy of any required depth. In some deployment situations a network can serve as a backbone for other subnets and as a subnet with access points 14. In some embodiments the configuration management server 10 can be distributed among the one or more access points. Typically one or more routers 12, and possibly firewalls, connect major networks and subnets together. A configuration management server 10 and a firewall 20 will provide services to one or more subnets. If multiple configuration management servers or multiple firewalls are used in one or more of the subnets, these servers can be arranged hierarchically to facilitate administration complexity.
The one or more security servers 20 authenticate the one or more mobile units 18 associated with the access points 14 in the subnets 26. In some embodiments, the mobile unit can authenticate its network connection through the access point using the server. of security. Security servers typically use a security client 32 on the mobile unit in conjunction with stored security information 22 to complete the authentication procedure. Depending on the implementation, a wide range of authentication schemes may be available including, username and password schemes, symmetric and asymmetric authentication key, and Public Key Infrastructure methods.
A mobile unit 18 can synchronize configuration profiles 30, software or stored data through one or more wired subnets 26, through the network interface of the MU 16. Once connected to the network interface of the MU the mobile unit can communicate directly to the one or more configuration servers 10 and to the one or more security servers 20. The UM network interface can be of any suitable type including, a network interface card for direct cable connection, a serial interface, or a docking station.
In some embodiments of the invention the configuration management server 10 and the security server 20 can be implemented using a combination of Lightweight Directory Access Protocol (LDAP) servers and PKI certified authority servers. These servers can be in one or more servers, in the subnets 26 or in the main networks 24 or distributed in the access points 14.
Profile structure
There are many suitable structures for UM 28, 30 configuration profiles. For example, UM configuration profiles can be stored and maintained in a related table or data structure or in a suitable Extensible Markup Language (XLM) schema. . An example of a suitable data structure is illustrated in Figure 2.
Configuration management profiles are identified using a profile identifier 292, which can include any unique set of identifying information including, a company number 294, a profile number 296, and / or a profile name 298, and a profile version identifier 290. The UM configuration profile 28, 30 can be classified 300 by one or more different parameters. Configuration management client 34 or configuration management server 10 will match one or more of these indexes to determine which profile to use in a given situation. Possible indices can include the following:
1. a subnet indicator 304 which may be comprised of one or more parameters including, an access point identifier 306 (ie, a BSSID or MAC address), a subnet identifier 308 (ie, an ESSID), or an address, or other identifier 310, used to identify which subnet or access point of the profile is valid;
2. a user indicator 312, which may include, a user group identifier 314, or an individual user identifier 316, used to allow profile information to be assigned to a given user in a user group regardless of the mobile unit 18 that they are using; Y,
3. a device indicator 318, which may include, a device type indicator 320, a specific identification device 322, and the role of the device 324 or application, used to assign specific profiles and behaviors for specific types of mobile unit classes 18.
UM configuration profiles 28, 30 preferably contain configuration parameter sets 328 for mobile units 18. These configuration parameters may include:
1. parameters for hardware configuration 330 including those specific to a type for device 332 (ie, a radio controller, a network card controller), which may include both parameters 334 and rules 336 for applying or checking the parameters; Y,
2. parameters for software configuration 338 including those specific to an executable program 340 (i.e. operating system, application, driver, security client) or stored data and which may include both parameters 342 and rules 344 for applying or checking the parameters .
ES 2 333 862 T3
Preferably the UM configuration profiles 28, 30 contain sets of capacity requirements 346 for the mobile units 18. These capacity requirements may include:
1. requirements for hardware configuration 348 which include those specific to a type of device 350 (i.e. a radio, a network card controller) which may include version information 352 and rules 354 for applying or verifying the version of information; Y
2. requirements for software configuration 356 which include those specific to executable software 356 (i.e., an operating system, an application, a driver, a security client) or stored data, and which may include version information 360 and rules 362 to apply or check version information.
Propagation of changes
The invention provides capabilities for one or more configuration management servers 10 to propagate changes to configuration data, software or profiles 28, 30 to mobile units 18. The mobile unit configuration management client 34 will periodically poll the mobile unit. server to determine if synchronization is required. Alternatively, when changes to configuration profiles, data or software occur, configuration management will notify the configuration management client of pending synchronization. In this case, the server can keep the records used to determine which mobile units need the updates. In either case the server generally verifies that the mobile units are authenticated, possibly using the services of the security server 20, the security information store 22, and the security client 32. Optionally, the mobile unit can authenticate the server or association. 26 before receiving the software or profile update. The changes are transmitted, through the access points 14, to the configuration management clients 34, in the mobile unit, which updates the affected files. Alternatively, if the unit is connected to a wired subnet 26, via the MU network interface, synchronization occurs over this connection. The client and / or the server verify the updates to ensure their integrity. The configuration management server can keep track of licensed software and renewals. Tracking capabilities may include keeping records of which mobile units have each type of licensed software and updating these records when new software or software updates are installed.
Hierarchical Configuration Management
In many practical situations, multiple configuration management servers 10 will be used. The invention provides the ability to manage these multiple servers in a hierarchical structure. In general, this hierarchy is organized in relation to a mobile unit 18 or a group of mobile units belonging to a particular organization. In other words, each organization with mobile unit management responsibility will create and manage an appropriate hierarchy for its association rules. Typically, an organization will constitute a set of servers, under its control, with the head of the hierarchy for the mobile units under its control. The one or more configuration management servers 10 can manage mobile unit associations 18 in one or more subnets 26. For example, a company may choose to constitute the servers in the main office, the head of the hierarchy with servers in departments and other subnets or geographic positions organized in a tree structure.
The UM configuration profiles 28 in the configuration management server hierarchy 10 can be propagated to the other servers by any suitable methods. Two of the possible methods are:
1. servers synchronize lists of information and security information up and down the hierarchy so that common information is maintained by all servers; Y
2. The servers act as proxy servers for others higher and lower in the hierarchy and therefore do not store all the information locally, however, it traverses the hierarchy quite a bit to find the information or services required.
Progress of the procedure
An example of a process progress for one embodiment is shown in Figures 3A, 3B, 3C, 3D and 3E. This process progress is for the purpose of one possible example only. Various other procedural advancements may be employed, including adding operations, deleting operations, or changing the order of operations without changing the scope or spirit of the invention.
When a mobile unit 18 initializes 100 the mobile unit determines whether the profiles 30 or the software require a synchronization or update 234 and begins searching 102 for access points 14 to associate with it. In some embodiments the configuration management client 34 periodically polls the configuration management server 10 to determine if a synchronization is required. In other embodiments, the configuration management server determines, before the configuration management client, the need to synchronize and trigger updates to the mobile unit.
ES 2 333 862 T3
Access point 14 associated with mobile unit 18 is chosen in the usual way using criteria, such as, Received Signal Strength Indication (RSSI). When one or more suitable access points are detected, the configuration management client 34 will try to adapt to the correct configuration profile 30. The configuration management client will first try to adapt to a profile 104 by the access point BSSID. If this procedure is unsuccessful, the client will try to adapt to another AP or network identifier 106 including the ESSID or the MAC address of the access point.
Once the correct profile 30 has been identified, the configuration management client 34 will invoke or load it 108. The client can then optionally verify110 that the mobile unit 18 has the correct software, stored data, and hardware to execute the profile. The client then executes the instructions and rules 112 for the profile. If the profile can be executed without error 114 the mobile unit 116 completes the association with the access point 14. If the mobile unit does not have the ability to execute profile 110, or errors 114 occur, the configuration management client will log any errors 235 and the client will determine if the configuration profiles of the UM 30, data or software need to be synchronized 234, and the mobile unit will continue searching for other access points 102.
Then, the security server 20 can authenticate 118, optionally, the mobile unit 18, possibly using the security client 32 and the security information store 22. The mobile unit can also authenticate the connection (not shown) of the access point. or subnet 26. As mentioned above, the authentication operation can take place immediately following the association with an access point and before the configuration verification.
If a correct profile 30 cannot adapt 104, 105 to any available access points, the access points 14, the configuration management client 34, or another procedure in the mobile unit 18 determines whether an association with the access point is allowed. unmanaged 230. If not, the client will determine if the UM configuration profiles 30, data or software need to be synchronized 234, and the mobile unit will continue to search for other access points 102. If so, the mobile unit establishes the VLAN or other limited connection 232, and begins the main communications loop.
Once association 116 is completed at access point 14 and mobile unit 18 has authenticated 118, client 34 begins a continuous loop. During the execution of the loop the configuration management client and / or the configuration management server 10 periodically verify that procedures, network connections, and other sessions are still running 120. The client periodically polls the configuration management server 10 to determine 122 if any of the information profiles 30, software or stored data, needs to be synchronized with the information 28 stored in the configuration management server. In other embodiments, the configuration management server determines before the configuration management client the need to synchronize and triggers updates to the mobile unit.
As configuration management client 34 continues the loop, mobile unit 18 may determine that RSSI is below a required level and should move 132 to another access point 14. If association with new access point is required, the The client 34 will determine if the configuration profiles of the UM 30, data or software need to be synchronized 234, and the mobile unit begins searching for other access points 102. For most of the time spent on the loop, the mobile unit engages in normal communication 134.
If a configuration management client 34 has determined 234, 122 that the software or stored data of the configuration profiles 30 of the UM should be synchronized with the profiles 28, the data or software on the configuration management server 10 , it is first determined whether a wireless network association 144 can be used. If so, mobile unit 18 optionally authenticates 154 its connection to access point 14 or subnet 26, possibly using the services of firewall 20, stored security information 22, and security client 32. Then , the configuration management client 34 synchronizes 156 the configuration management profiles 30, the software and data with the profiles 28, the software and the data in the configuration management server 10. The client and / or server then verify 158 the integrity of the synchronized information. Integrity checking can use any combination of suitable techniques including file size, file execution or evaluation, sum checking, more sophisticated error detection codes, or error code correction. The client 34 will determine if the configuration profiles 30 of the UM, data or software needs to be synchronized 234, and then the mobile unit begins to scan 102 acceptable access points or returns to the main communications loop and checks the RSSI level 132 . In other cases the client returns to the main communications loop and checks RSSI level 132.
If a configuration management client 34 determines 146 that the mobile unit 18 can synchronize the profiles 30, data and software through the network interface 16 of the MU the mobile unit connects to the interface 160. Optionally, the server Security 20 authenticates 162 the mobile unit, possibly using security information 22 and security client 32. Optionally, then the mobile unit authenticates 164 to the server or subnetwork association 26, generally using the services of the security server and the security client. The profiles, software and data are then synchronized 166 using the services of the management server. configuration and configuration management client 34. The server and / or client then verify the integrity of the synchronization 168. Identity checking can use any combination of suitable techniques including file size, file execution or evaluation, sum checking, error detection codes plus so
ES 2 333 862 T3 files, or error correction codes. The mobile unit then disconnects from the UM network interface 170 and the client 34 will determine whether the UM configuration profiles 30, data or software need to be synchronized 234, and the mobile unit 18 begins tracking 102 of points. acceptable access. In other cases the client returns to the main communications loop and checks the RSSI132 level.
If the configuration management client 34 at the mobile unit 18 or the configuration management server 10 determines that a required procedure, connection, or network session has been prematurely stopped or terminated 120, the client or server will terminate the association 250 from mobile units with an access point 14. The client then determines whether the procedure, connection or session can be restarted 252. If so, the client attempts to restart the procedure, session, or connection 254 and records or reports the results 256. Finally, the client verifies 258 that the restart was successful and verifies that the procedures, connections, and sessions are still operational 260. If the procedure, connection or session cannot be restarted 252 or the restart is unsuccessful 260, the client will log or report 262 the error (if possible), and notify the user of the failure 264. Once the procedure is completed (with or without success) the client 34 will determine if the configuration profiles 30 of the UM, data or software need to be synchronized 234, and the mobile unit 18 begins to scan 102 access points 14 with the that the mobile unit is able to associate.
Alternative realization
Some alternative embodiments do not require the profiles to be stored in mobile units or synchronized between the mobile units and a configuration management server. In these embodiments the configurations of the mobile units are managed and verified by one or more servers. A block diagram of a possible alternative embodiment is shown in Figure 4.
One or more configuration management servers 400 store the profiles 402 for one or more mobile units 416. As a mobile unit transits between one or more access points 414 in one or more subnets 412, the configuration profile 402 used to the mobile unit is determined by the identity of the access point or subnet with which the mobile unit is associated. The configuration management server invokes the correct configuration profile and executes it, typically using the services of the configuration management client 418. For some embodiments, the configuration profile will use a structure almost identical to that already described. Periodically, the management configuration server verifies that the required configuration is being maintained. This verification can include verifying that the configuration parameters have been set, that the required procedures are running, and that the required connections and sessions are running. As with other embodiments, the configuration management server may attempt to restore configurations or restart required procedures, sessions, and connections. If these attempts fail, the mobile unit can disconnect from the access points or attempt to connect the mobile unit to other access points with different configuration requirements. The configuration management server can also distribute and verify mobile unit software updates, much as is done in other embodiments.
The one or more subnets 412 are connected by a series of one or more major networks 410. These networks can be organized in a hierarchy of any required depth. In some deployment situations a network can serve as a backbone for other subnets and as a subnet with access points 414. In some embodiments the configuration management server 400 can be distributed among the one or more access points. Typically, one or more 408 routers, and possibly firewalls, connect major networks and subnets together. A configuration management server 400 and a firewall 404 will provide services to one or more subnets. If multiple configuration management servers or multiple firewalls are used in the one or more of the subnets, these servers can be arranged in a hierarchy to facilitate administration complexity. The hierarchical structure can be almost identical to one already described.
The one or more security servers 404 authenticate the one or more mobile units 416 associated with access points 414 in subnets 412. In some embodiments, the mobile unit can authenticate its network connection through the access point using the firewall. Security servers typically use a client 420 on the mobile unit in conjunction with stored security information 406 to complete the authentication procedure. Depending on the implementation, a wide range of authentication schemes may be suitable including, username and password schemes, symmetric and asymmetric authentication key, and Public Key infrastructure methods.
In some embodiments, the one or more major networks 410 and one or more networks 412 will use one of the Internet Protocol (IP) versions. One or more Dynamic Host Configuration Protocol (DHCP) servers 422 assign IP addresses to mobile units 416. DHCP servers can be organized and managed hierarchically. Each DHCP server can provide dynamic IP address assignments to one or more subnets. In some embodiments, the management configuration server 400 may act as a proxy for the DHCP server or it may contain or encapsulate the DHCP server. In these embodiments, the configuration management server will not allow the DHCP server to assign an IP address for a mobile unit, while the mobile unit is associating with an access point 414, until it has been properly configured and verified.
In some embodiments of the invention, configuration management server 400, DHCP servers 422, and firewall 404 can be implemented using a combination of Access Protocol servers.
ES 2 333 862 T3 to the Lightweight Directory (LDAP) and PKI certified authority servers. These servers can be in one or more servers in subnets 412 or in major networks 410 or distributed in access points 414.
A possible simplified process progress for an alternative embodiment of the invention is shown in Figure 5. It will be understood that the functionality, scope and spirit of this embodiment is identical to those already described and that this brief description is not intended to impose limitations.
When a mobile unit 416 detects an access point 414 it tries to associate it with it 450. The decision to associate with a new access point is based on a variety of standard criteria, such as the strength indication of the received signal. The access point responds 452 as required by the protocol being used (ie the IEEE 802.11 family of specifications). This protocol can include an authentication operation using for example the RADIUS protocol. As part of the association procedure, the mobile unit will make a DHCP IP address assignment request (or other suitable address assignment request) 454, which will be passed through access point 456 to configuration management server 400. In some embodiments, the configuration management server acts as a proxy for the DHPC server 422 and will only assign an IP address if the mobile unit is under required configuration management. Communications with the mobile unit, before assigning an IP address can use OSI Layer 2 addresses (ie the MAC addresses of the mobile unit, the access point, the configuration management server).
Configuration management server 400 will optionally require 458 that security server 404 authenticate mobile unit 416. Security server issues an identification signal 460, which is passed through access point 414 to the unit. mobile 462. The mobile unit issues a response 464 to the identification signal, which is passed through the access point, to the security server 466. The security server then transmits an authentication or confirmation response 468 to the configuration management server. Mobile units that cannot authenticate may have the association discontinued, they may be allowed to complete a limited association, using, for example, a VLAN, or the mobile unit must find another access point to associate with.
The configuration management server, 400 issues a configuration request 470, which is transmitted 472 through the access point 414, to the mobile unit 416. The mobile unit responds 474 with information about its configuration and capabilities, which are transmitted 476 through the access point, to the configuration management server. In some embodiments, this information is collected and supplied by the configuration management client 418. This message may contain information on which access points the mobile unit can associate with them. The configuration management server uses the configuration information to determine if the mobile unit has the capabilities to complete the required association. If not, the configuration management server may try to update the software or data stored on the mobile unit. Alternatively, the mobile unit may attempt to locate an access point, which has the ability to associate with it. As another alternative the mobile unit may be allowed to complete a limited association, using, for example, a VLAN. In some embodiments, the configuration management server will use information stored in the configuration and capabilities of the mobile unit, rather than polling the mobile unit about this information.
Once the configuration management server 400 has been able to determine the configuration of the mobile unit 416, it sends configuration messages 478, which are transmitted 480 through the access point, to the mobile unit. This message may include a listing of access points with which the mobile unit is required to associate, is preferred to associate, or of an access point with which the mobile unit is prohibited from associating. Configuration management client 418 uses this information to set configuration parameters on the mobile unit. The configuration management client verifies the configuration and parameter setting, and sends an acknowledgment message 482, via 484 to the access point, to the configuration management server.
Once the configuration management server 400 has been able to establish and verify the configuration of the mobile unit 416, the configuration management server sends a DHCP request 486 to the DHCP server 422. The DHCP server sends a message 488 of IP address assignment, to the configuration management server, which transmits 490 the address assignment, via 492 to access point 414, to the mobile unit. Then the mobile unit and the access point will perform any actions required by the protocol to complete the association and the mobile unit can begin communications.
Other alternative realizations
It will be understood that many more embodiments are possible, obtaining the same functionality and scope as the described embodiments. For example, some embodiments may store and use part of a configuration profile 28, 402 from mobile unit 18, 416 on the mobile unit itself and part on the configuration management server 10, 400. Other parts of the configuration management profile 30 will be stored in the mobile unit and used directly by the configuration management client 34. In effect, this embodiment is a hybrid of two embodiments already described.
As is known, in some embodiments, the configuration management server 10 described above can be functionally distributed to one or more access points 14. Thus, for example, an access point AP can be adapted to validate a configuration profile. before allowing normal communication with a UM, or
ES 2 333 862 T3 giving power to another server adapted to carry out this function. If desired, a PA can also be adapted to manage the information standard settings and allow authorized personnel to access and modify such information. In some embodiments, the firewall 20 may be distributed among the one or more access points. Reciprocally, the one or more access points can act as proxy servers for one or more security servers.
Although the invention has been described in conjunction with specific embodiments, it is obvious that numerous alternatives, modifications, and variations will be apparent to those skilled in the art in light of the foregoing description.
Contents7
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
18 members in 11 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 21570102 | United States of America | A | |
| 21570102 | United States of America | A | |
| 25284902 | United States of America | A | |
| 25284902 | United States of America | A | |
| 21570103785061 | – | – | – |
| 252849 | – | – | – |
| US20020215701 | – | – | – |
| US20020252849 | – | – | – |
Members18
| Document | Office | Kind | |
|---|---|---|---|
| WO2004015930A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003264013A1 | Australia | A1 | |
| AU2003264013A8 | Australia | A8 | |
| US2004198319A1 | United States of America | A1 | |
| US2004203593A1 | United States of America | A1 | |
| WO2004015930A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1527565A2 | European Patent Office (EPO) | A2 | |
| US7363022B2 | United States of America | B2 | |
| US7522906B2 | United States of America | B2 | |
| EP1527565B1 | European Patent Office (EPO) | B1 | |
| AT445271T | Austria | T | |
| ATE445271T1 | Austria | T1 | |
| PT1527565E | Portugal | E | |
| DE60329600D1 | Germany | D1 | |
| DK1527565T3 | Denmark | T3 | |
| SI1527565T1 | Slovenia | T1 | |
| ES2333862T3This record | Spain | T3 | |
| CY1110632T1 | Cyprus | T1 |
Numbers
- Publication, DOCDB
- 2333862
- Publication, EPODOC
- ES2333862T
- Application
- 3785061
- Application, DOCDB
- 03785061
- Application, EPODOC
- ES20030785061T
Titles2
- Spanish
- GESTION DE CONFIGURACION DE UNIDAD MOVIL PARA WLANS.
- English
- MOBILE UNIT CONFIGURATION MANAGEMENT FOR WLANS.
Classification
- CPC, 14
- H04W48/02
- H04L63/0823
- H04L63/123
- H04W8/18
- H04W12/06
- H04W12/08
- H04W84/12
- H04L69/329
- H04L63/102
- H04W88/02
- H04W12/35
- H04W12/73
- H04L67/61
- H04L9/40
- IPC, 9
- H04L12 28
- H04L12 56
- H04L29 06
- H04L29 08
- H04W8 18
- H04W12 06
- H04W12 08
- H04W48 02
- H04W84 12