Method, computer program and recording medium for improving automation level when computer system prepares to access to network
Abstract
[Subject] Raise the level of automation, when you prepare so that a computer system may access a network. [Solution means] If accessing the 1st network is not permitted when a computer system tends to obtain the permission which accesses the 1st network from a server in response to attestation, The permission which accesses the 2nd network in order to download the file needed for accessing the 1st network can be given. The document of the 1st schema base including user input information is transmitted to a server. When a server judges with user input information being suitable, the 2nd schema document including directions of the permission which accesses the 1st network is received. The document of the 3rd schema base is performed in a computer system, and a computer system is constituted so that it may suit accessing the 1st network. [Selection figure] Fig. 2

Term
Term ended
Projected expiry passed 4 December 2023, 2.8 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
40 claims: 9 independent, 31 dependent
- 1A network that can connect to both a second network that contains multiple resources through an intermediate computer system and at least a first network that contains resources to prepare the computer system to access the second network. In a computer system, the intermediate computer system determines whether the data from the computer system is transferred to the first network or the second network to access the first network. Allowing access to the second network while being forbidden, the first network further includes a server that can allow the computer system to access the second network. , A method of preparing a computer system to access a second network to reduce user input, the process of sending a certificate to the server and attempting to be authenticated by the server, Automatically presenting a user interface that can receive user input information so that the user of the computer system does not need to have prior knowledge of how the user interface is presented. , The process of receiving user input information in the user interface, the process of passing the first schema-based document containing the user input information to the server, and the process of submitting the first schema-based document. The process of receiving a second schema-based document that provides instructions that the server has allowed the computer system to access resources located on the second network, and the third running of the third schema-based document. A method characterized by including the process of configuring a computer system to access the network of 2 and freeing the user from having to manually configure the computer system. 中間コンピュータシステムを介して複数のリソースを含む第2のネットワークと、少なくともコンピュータシステムが第2のネットワークにアクセスするように準備するためのリソースを含む第1のネットワークの両方に接続可能なネットワークであるコンピュータシステムにおいて、中間コンピュータシステムは、コンピュータシステムからのデータが第1のネットワークに転送されるか、又は第2のネットワークに転送されるかを決定して、第1のネットワークへのアクセスを、第2のネットワークへのアクセスが禁止されている間に、許すことが可能であるようにし、第1のネットワークは、コンピュータシステムが第2のネットワークにアクセスすることを許可することができるサーバをさらに含む、第2のネットワークにアクセスするようにコンピュータシステムを準備してユーザ入力を減らすようにする方法であって、 証明をサーバに送信してサーバから認証を受けようと試みる工程と、 ユーザ入力情報を受け取ることができるユーザインターフェースを自動的に提示して、コンピュータシステムのユーザが、どのようにユーザインターフェースが提示されるようにするかについての事前の知識を有することを必要としないようにする工程と、 ユーザインターフェースの中にユーザ入力情報を受け取る工程と、 ユーザ入力情報を含む第1のスキーマベースのドキュメントをサーバに渡す工程と、 第1のスキーマベースのドキュメントをサブミットした後に、第2のネットワーク上に配置されたリソースにコンピュータシステムがアクセスすることをサーバが許可したという指示を提供する第2のスキーマベースのドキュメントを受け取る工程と、 第3のスキーマベースのドキュメントを実行して第2のネットワークにアクセスするためにコンピュータシステムを構成して、コンピュータシステムを手作業で構成しなければならないことからユーザを解放するようにする工程とを含むことを特徴とする方法。
- 20The process of executing a third schema-based document and configuring a computer system to access a second network is characterized by including the process of executing an XML document defined according to the XML configuration schema. The method described in Item 1. 第3のスキーマベースのドキュメントを実行して、第2のネットワークにアクセスするためにコンピュータシステムを構成する工程は、XML構成スキーマに従って定義されたXMLドキュメントを実行する工程を含むことを特徴とする請求項1に記載の方法。
- 27A network that can connect to both a second network that contains multiple resources through an intermediate computer system and at least a first network that contains resources to prepare the computer system to access the second network. In a computer system, the intermediate computer system determines whether the data from the computer system is transferred to the first network or the second network to access the first network. Allowing access to the second network while being forbidden, the first network further includes a server that can allow the computer system to access the second network. , A method of preparing a computer system to access a second network to reduce user input, the process of sending a certificate to the server and attempting to be authenticated by the server, Automatically presenting a user interface that can receive user input information so that the user of the computer system does not need to have prior knowledge of how the user interface is presented. To the resources placed on the second network, after submitting the first schema-based document, and the steps to request permission to access the resources placed on the second network. The process of receiving a second schema-based document that provides instructions that the server has allowed access to the computer system, and the computer system to run the third schema-based document to access the second network. A method comprising the steps of configuring a computer system to free the user from having to manually configure the computer system. 中間コンピュータシステムを介して複数のリソースを含む第2のネットワークと、少なくともコンピュータシステムが第2のネットワークにアクセスするように準備するためのリソースを含む第1のネットワークの両方に接続可能なネットワークであるコンピュータシステムにおいて、中間コンピュータシステムは、コンピュータシステムからのデータが第1のネットワークに転送されるか、又は第2のネットワークに転送されるかを決定して、第1のネットワークへのアクセスを、第2のネットワークへのアクセスが禁止されている間に、許すことが可能であるようにし、第1のネットワークは、コンピュータシステムが第2のネットワークにアクセスすることを許可することができるサーバをさらに含む、第2のネットワークにアクセスするようにコンピュータシステムを準備してユーザ入力を減らすようにする方法であって、 証明をサーバに送信してサーバから認証を受けようと試みる工程と、 ユーザ入力情報を受け取ることができるユーザインターフェースを自動的に提示して、コンピュータシステムのユーザが、どのようにユーザインターフェースが提示されるようにするかについての事前の知識を有することを必要としないようにする工程と、 第2のネットワーク上に配置されたリソースにアクセスする許可を要求するためのステップと、 第1のスキーマベースのドキュメントをサブミットした後に、第2のネットワーク上に配置されたリソースにコンピュータシステムがアクセスすることをサーバが許可したという指示を提供する第2のスキーマベースのドキュメントを受け取る工程と、 第3のスキーマベースのドキュメントを実行して第2のネットワークにアクセスするためにコンピュータシステムを構成して、コンピュータシステムを手作業で構成しなければならないことからユーザを解放するようにする工程とを含むことを特徴とする方法。
- 28A network that can connect to both a second network that contains multiple resources through an intermediate computer system and at least a first network that contains resources to prepare the computer system to access the second network. In a computer system, the intermediate computer system determines whether the data from the computer system is transferred to the first network or the second network to access the first network. Allowing access to the second network while being prohibited, the first network further includes a server that can allow the computer system to access the second network. , A computer program for implementing a method that prepares a computer system to access a second network to reduce user input, sending proofs to the server and attempting to authenticate from the server. With computer executable instructions for To present a user interface that can receive user input information so that users of the computer system do not need to have prior knowledge of how the user interface is presented. Computer-executable instructions, computer-executable instructions to receive user-input information in the user interface, computer-executable instructions to pass a first schema-based document containing user-input information to the server, and so on. A computer for receiving a second schema-based document that provides instructions that the computer system has allowed access to resources located on the second network after submitting the first schema-based document. Configure the computer system to run executable instructions and a third schema-based document to access the second network, freeing the user from having to manually configure the computer system. A computer program characterized by containing computer-executable instructions for. 中間コンピュータシステムを介して複数のリソースを含む第2のネットワークと、少なくともコンピュータシステムが第2のネットワークにアクセスするように準備するためのリソースを含む第1のネットワークの両方に接続可能なネットワークであるコンピュータシステムにおいて、中間コンピュータシステムは、コンピュータシステムからのデータが第1のネットワークに転送されるか、又は第2のネットワークに転送されるかを決定して、第1のネットワークへのアクセスを、第2のネットワークへのアクセスが禁止されている間に、許すことが可能であるようにし、第1のネットワークは、コンピュータシステムが第2のネットワークにアクセスすることを許可することができるサーバをさらに含む、第2のネットワークにアクセスするようにコンピュータシステムを準備してユーザ入力を減らすようにする方法を実施するためのコンピュータプログラムであって、 証明をサーバに送信してサーバから認証を受けようと試みるためのコンピュータ実行可能命令と、 ユーザ入力情報を受け取ることができるユーザインターフェースを提示して、コンピュータシステムのユーザが、どのようにユーザインターフェースが提示されるようにするかについての事前の知識を有することを必要としないようにするためのコンピュータ実行可能命令と、 ユーザインターフェースの中にユーザ入力情報を受け取るためのコンピュータ実行可能命令と、 ユーザ入力情報を含む第1のスキーマベースのドキュメントをサーバに渡すためのコンピュータ実行可能命令と、 第1のスキーマベースのドキュメントをサブミットした後に、第2のネットワーク上に配置されたリソースにコンピュータシステムがアクセスすることをサーバが許可したという指示を提供する第2のスキーマベースのドキュメントを受け取るためのコンピュータ実行可能命令と、 第3のスキーマベースのドキュメントを実行して第2のネットワークにアクセスするためにコンピュータシステムを構成して、コンピュータシステムを手作業で構成しなければならないことからユーザを解放するようにするためのコンピュータ実行可能命令とを含むことを特徴とするコンピュータプログラム。
- 32It is possible to connect to both a first virtual network that provides multiple services through an intermediate computer system and a second virtual network that provides at least a subset of the services, and the intermediate computer system is from the computer system. A server connected to a second virtual network in a computer system, which is a network that determines whether data should be transferred to the first virtual network or to the second virtual network. Updates the computer system to access the service on the first virtual network, which can provide update information to update the computer system to access the service on the first virtual network. A way to reduce user input, automatically instructing the process of trying to access a service on the first virtual network and the computer system should be updated for access that matches the service. The process of presenting to the application user does not need to have prior knowledge of how to update the computer system, and The process of receiving user input information indicating a request to update the computer system, the process of passing the first schema-based document containing the user input information to the server, and the process of submitting the first schema-based document, and then the computer system. Free the user from the process of receiving a second schema-based document containing update information and running the second schema-based document to update the computer system and manually updating the computer system. A method characterized by including steps to do so. 中間コンピュータシステムを介して複数のサービスを提供する第1の仮想ネットワークと、複数のサービスの少なくともサブセットを提供する第2の仮想ネットワークの両方に接続可能であり、中間コンピュータシステムが、コンピュータシステムからのデータが第1の仮想ネットワークに転送されるべきか、又は第2の仮想ネットワークに転送されるべきかを決定するようにしているネットワークであるコンピュータシステムにおいて、第2の仮想ネットワークに接続されたサーバは、第1の仮想ネットワーク上のサービスにアクセスするようにコンピュータシステムを更新するための更新情報を提供することができる、第1の仮想ネットワーク上のサービスにアクセスするようにコンピュータシステムを更新してユーザ入力を減らすようにする方法であって、 第1の仮想ネットワーク上のサービスにアクセスしようと試みる工程と、 サービスに適合するアクセスのためにコンピュータシステムが更新されるべきであるという指示を自動的に提示して、アプリケーションのユーザが、どのようにコンピュータシステムを更新するかについての事前の知識を有することを必要としないようにする工程と、 コンピュータシステムを更新する要望を示すユーザ入力情報を受け取る工程と、 ユーザ入力情報を含む第1のスキーマベースのドキュメントをサーバに渡す工程と、 第1のスキーマベースのドキュメントをサブミットした後に、コンピュータシステムに関する更新情報を含む第2のスキーマベースのドキュメントを受け取る工程と、 第2のスキーマベースのドキュメントを実行してコンピュータシステムを更新して、コンピュータシステムを手作業で更新しなければならないことからユーザを解放するようにする工程とを含むことを特徴とする方法。
- 33An activity that defines a name field that defines the format for naming the preparation master document, and an activity time format that indicates when the preparation master document named according to the naming format defined within the name field should be updated. It is characterized by storing a data structure that includes a time field and a subfile field that defines a format for representing subfiles in a preparation master document named according to the naming format defined within the name field. One or more computer-readable recording media. 準備マスタドキュメントを命名するための形式を定義する名前フィールドと、 名前フィールド内で定義された命名形式に従って命名された準備マスタドキュメントがいつ更新されるべきかを表わすための活動時間形式を定義する活動時間フィールドと、 名前フィールド内で定義された命名形式に従って命名された準備マスタドキュメント内のサブファイルを表わすための形式を定義するサブファイルフィールドとを含むデータ構造を記憶していることを特徴とする1つ又は複数のコンピュータ可読記録媒体。
- 36One or more of claims 33, characterized in that it further comprises an update field that defines a format for indicating where the updates for the preparatory master document defined according to the naming format within the naming field are located. Computer-readable recording medium. 命名フィールド内の命名形式に従って定義された準備マスタドキュメントに関する更新がどこに配置されているかを表わすための形式を定義する更新フィールドをさらに含むことを特徴とする請求項33に記載の1つ又は複数のコンピュータ可読記録媒体。
- 37Data that includes a connection field that defines the format for representing the types of connections supported by the network, and an authentication field that defines the format for representing the types of authentication supported by the connection types defined within the connection field. A computer-readable recording medium, characterized in that it stores a structure. ネットワークによってサポートされる接続のタイプを表わすための形式を定義する接続フィールドと、 接続フィールド内で定義された接続タイプによってサポートされる認証のタイプを表わすための形式を定義する認証フィールドとを含むデータ構造を記憶していることを特徴とする1つ又は複数のコンピュータ可読記録媒体。
- 39One or more of claims 37, wherein the authentication field consists of a conventional authentication field that defines a format for representing a location that can be accessed to authenticate a computer system that does not support EAP. Computer-readable recording medium. 認証フィールドは、EAPをサポートしないコンピュータシステムを認証するのにアクセスすることができるロケーションを表わすための形式を定義する従来の認証フィールドから成ることを特徴とする請求項37に記載の1つ又は複数のコンピュータ可読記録媒体。
Independent claims9
106 paragraphs, as filed
The present invention relates to configuring a computer system to communicate properly on a network, and more specifically, to automatically provide the computer system with appropriate information so that the computer system is ready to communicate on the network. Regarding providing to.
Computer systems and related technologies are affecting many aspects of society. In fact, the ability of computer systems to process information is changing the way people live and work. Computer systems now routinely perform a number of manual tasks (eg, word processing, scheduling, and database management) that were performed manually prior to the advent of computer systems. More recently, computer systems have been combined with each other to form a computer network, through which the computer system can electronically communicate and share data. As a result, many of the tasks performed on a computer system (eg, accessing email and browsing the Web) involve electronic communication with one or more other computer systems over a computer network (eg, the Internet). Is included.
In order to communicate electronically over a computer network, the computer system may need to be authorized to access the computer network. For example, before a computer system can perform electronic communications over the Internet, users of the computer system are often allowed access to the Internet by an Internet service provider (hereinafter referred to as "ISP"). It is required to register with. Registering with an ISP usually involves some form of communication other than electronic communication on the network. For example, a user may be required to initiate a telephone communication with an ISP's agent in order to establish an account at the ISP.
During this telephone communication, the user can provide the ISP agent with general information (eg, name, address, etc.) and form of payment (eg, credit card number). In exchange, the ISP can provide the user with a username and password that can be used to authenticate the user and grant access to the Internet. Often, ISPs have access software (eg, dialers, web browsers, etc.) and / or hardware (eg, eg dialers) that must be installed on the computer system via postal services or other delivery services. , DSL modem, or cable modem). All access software and hardware must be properly installed on the computer system in order for the user to connect to the ISP and thereby access the Internet. For this reason, users who wish to access the Internet are often required to wait until they receive such software and hardware. Then, after receiving the access software and / or access hardware, the user must properly install the access software and / or access hardware on the computer system to enable internet access.
If installed correctly, the user can connect to the ISP and enter the username and password provided by the ISP. The ISP can authenticate the user based on its username and password, and if appropriate (for example, if the user's payment is up to date), the ISP will allow the user's computer system to be on the Internet. Can be allowed to access. Unfortunately, if the user is not currently registered with an ISP, in most cases there is no way to initiate the registration process using electronic communication over the Internet. This is because most ISPs have no way to access the ISP for registration if they are accessed from the Internet and the user has no way to access the Internet.
Therefore, in many cases, users who wish to access the Internet will have to contact their ISP by telephone and wait for the appropriate access software and / or access hardware to be delivered. In addition, users attempting to connect to an ISP without proper proof (eg, username and password) or without permission (eg, late payment) will typically see all networks to both the ISP and the Internet. Completely blocked from access. Therefore, even if the user knows the ISP access number (or the ISP network address that attempts to connect) to dial, he / she uses other means of communication to register with the ISP (or correct the deficiency in the account). You may still need to contact your ISP.
In some cases, for example when connecting to an ISP from home, delays in waiting for access software and access hardware may be acceptable. However, in other cases, such delays may be unacceptable. For example, when traveling through an airport or staying at a hotel, a user with a mobile computer system, such as a laptop, may want access to the Internet. To some extent, as a result of this demand for mobile access, many hotels and airports offer internet access via both wired and wireless services. Obtaining permission to access the Internet through these services usually requires some form of electronic communication with the service for entering user and payment information.
These services typically involve the user plugging a cable into a network interface card inside a mobile computer system (or using a wireless network interface card to initiate a connection) before opening a web browser. Needs. However, the user must have the knowledge that these actions should be taken before attempting to register with the service. For example, if the user does not know that a web browser must be opened, there is basically no way for the user to register for the service. When the web browser is opened, the service forwards any communication from the web browser through a web-based registration process. The user can be presented with an interface to enter information for registration (eg, name, room number, credit card number, etc.). If the registration information is appropriate, the user can be authorized to access the Internet using the service.
Unfortunately, many services are unique and each service may require different computer system configurations and / or different registration information to allow access to the Internet. However, the user may not have the means to know what system configuration and / or registration information is required before attempting to register for the service. Therefore, even if a user succeeds in registering for a service in one location (eg, an airport), in another location (eg, a hotel), an improperly configured computer system, or proper registration information, The lack may prevent you from registering.
In addition, most hotel and airport services only allow Internet access for a short period of time (eg, 24 hours) before the account expires. After the account expires, the user may need to reopen the web browser (and possibly reconnect the cable) and re-enter all of the previously entered registration information. Therefore, users may initially be aware that they must open a web browser to register for the service, but may not know that they must open a web browser every day to re-register for the service. .. Often, the registration information entered in the previous registration (eg, the day before) must be re-entered, even if the registration information has not changed at all. If the registration information is somewhat large, re-registering after a short period of time may be annoying to users who have entered the appropriate registration information in the past.
Moreover, most, if not all, of these services lack a mechanism for changing the software configuration of a computer system. That is, the service is usually unable to provide the computer system with machine-readable instructions that can be processed in the computer system that make the computer system compatible with the service. The service may provide HyperText Markup Language ("HTML") as part of a web-based interface for receiving registration information. However, HTML instructions are usually not available for processing by a computer system to change the configuration of the computer system. Therefore, any software incompatibility must be resolved by a user who may lack technical expertise or may wish to reconfigure the software to adapt it to the service.
<p> To provide systems, methods, computer programs, and data structures to increase the level of automation in preparing and configuring computer systems to access networks.</p>
<p> The problems of the prior art are the principles of the present invention for methods, systems, computer programs, and data structures for increasing the level of automation in preparing and configuring computer systems to access networks. Overcome by.</p><p> The server includes the ability to allow clients to access a second network (eg, the Internet). The server can be located on the first network, which is separate from the second network, or can be located on the second network. The client attempts to authenticate by sending the certificate to the server. Based on the proof, the server allows the client for at least partial access to the second network and / or denies access to the second network and the client for at least partial access to the first network. It is possible to allow. The server can be a Remote Authentication Dial-In User Service (RADIUS) server located on the first network. The client is provisioning, at least for the purpose of being authenticated by the server, and for gaining full access to the second network. It is possible to provide partial access to the first or second network for the purpose of downloading file). Therefore, a computer system that currently does not have access to resources located on the second network can electronically download the preparation file to gain access to those resources.</p><p> Determining whether data from the client is forwarded to the first network or the second network is determined, for example, by virtual local area network (VLAN), Internet Protocol (IP) filtering, It can be implemented using any number of technologies, such as the use of virtual private networks (VPN), or IP security (IPSec) protocols. In some embodiments, similar techniques can be used within a single network. In those embodiments, the server (at least to some extent based on the proof received) is single, for example, by allowing client access to selected computer systems or computer modules on a single network. Clients can be granted at least partial access to the network.</p><p> Sending proof can include sending an Extensible Authentication Protocol (EAP) response / proof of identity message from the client to the server. If the client is trying to connect to the network through the access point, the EAP response / identification message can be encapsulated within some other type of message that can be forwarded through the access point. Is. In the VLAN embodiment, the access point can insert the tag header into the encapsulating message to indicate to the data routing device that the encapsulated message should be forwarded to the first network. The access point can also be configured to block communication from clients that use protocols other than EAP and 802.1X.</p><p> If the certificate does not allow full access to the second network (eg, the certificate cannot be authenticated, the certificate is a guest certificate, or the authenticated user is not allowed), the server is protected, for example. It can respond by sending an EAP notification within the EAP (PEAP) or a notification such as a Type-Length-Value (TLV) object to the client. Notifications are encrypted according to PEAP and can be checked for integrity. The notification can include a Uniform Resource Identifier (URI) for the master document that contains information for preparing the client. The notification can also include conditions that the user must meet (eg, sign-up, update, etc.) to be granted full access to resources located on the second network.</p><p> Notifications enable communication using the HTTP protocol (block) so that clients can download the master document by accessing the contained URI (eg, by executing an HTTP get or HTTPS get). It is possible to indicate to the access point that it must be released). In response to the notification, the client can automatically download the master document. The master document can contain URIs for subfiles that also contain configuration and sign-up subfiles that can be downloaded automatically. One ISP provides services from another ISP uses , one master document can also contain a URI for the other master document. Therefore, there is little need to contact a service provider who uses other communication methods to request files to gain access to the network. The master document and all related subfiles are eXtensible Markup It can be defined according to the Language (XML) schema. For example, configuration subfiles can be defined according to the XML configuration schema.</p><p> In some embodiments, the master document and subfiles are, for example, by accessing the master document and / or subfiles from a removable computer-readable recording medium (floppy® disk, flash card, etc.). , Can be accessed by mechanisms other than the URI provided in the notification. This is advantageous in environments where preparation information is first required to be able to configure a network connection, for example remote dial-up. After the connection is established, the master document and subfiles can be updated later from the network.</p><p> The downloaded sign-up subfile can be processed by the client to automatically present a user interface that can receive user input information. Therefore, the user does not have to have prior knowledge of how to make the user interface presented. The user interface can be presented in various written languages such as English, Japanese, French, or German. When presented, user input information is received in the user interface. When the user interface is presented for the purpose of updating the registration, it is possible to reduce the amount of user input information received by the user interface. For example, previously entered user information can be retrieved from the user database. The user interface presented can include only "yes" and "no" controls to allow further credit card payments.</p><p> A first schema-based document containing user input information is submitted to the server (for example, by performing an HTTP post or an HTTPS post). This can include passing an XML document defined according to the XML signup schema. After submitting the first schema-based document, the client can receive instructions that the server has allowed the client to access resources located on the second network. This can include receiving a second schema-based document that includes a user identifier and password, or instructions that credit card payments have been approved. In the VLAN embodiment, if the client is allowed to access resources located on the second network, the access point inserts a tag header into the client data so that the client data goes to the second network. It can indicate to the data routing device that it should be transferred. The access point is, for example, the Simple Mail Transfer Protocol (Simple). You can also enable communication using other currently blocked protocols, such as Mail Transfer Protocol (SMTP) and Dynamic Host Control Protocol (DHCP).</p><p> A third schema-based document is executed to configure the client for the process of adapting to the second network. This can include executing the configuration subfiles received from the server. Configuration subfiles can be executed to configure connection types, communication protocols, authentication types, encryption types, and so on. The configuration subfile can be executed at virtually any point in time after it has been downloaded. There is no requirement that the configuration subfile be executed before or after the user input information is received. Through the execution of schema-based documents, clients can be reconfigured with little or no user intervention. This frees the user from having to manually reconfigure the client for the process of adapting to the second network.</p><p> Further features and advantages of the present invention will be presented in the following description and, to some extent, will be apparent from this description or will be known by practicing the present invention. The features and advantages of the present invention can be realized and acquired using the instruments and combinations specifically pointed out in the claims. The above features, and other features of the invention, become more completely apparent from the following description and claims, or can be found by practicing the invention as presented below.</p><p> In order to illustrate the above-mentioned advantages and features of the present invention, as well as other advantages and ways in which the features can be obtained, a specific embodiment which provides a more detailed description of the present invention outlined above in the accompanying drawings. Refer to. Understanding that these drawings depict only conventional embodiments of the invention and therefore should not be considered to limit the scope of the invention, the invention is made through the use of the accompanying drawings. More specifically, it will be described and described in more detail.</p>
The principles of the present invention provide to increase the level of automation in preparing and configuring a computer system to access a network. The client attempts to gain permission to access resources located on the second network (eg, the Internet). The client is attached to an access point coupled to communicate with a server (located on the first network or located on the second network) that can allow access to the second network. , Send proof. The server receives the client certificate and determines whether the client certificate allows access to the second network.
If full access to resources located on the second network is not allowed, the server may download a preparation file for the client to gain full access to resources located on the second network. As possible, restricted access to the first network, or the second network, can be granted. In some embodiments (eg, when the server is located on the first network), the server (at least) to the first network while denying access to the second network. Allowed (restricted) access. In other embodiments (eg, if the server is located on a second network), the server can allow restricted access to the second network. Prohibiting and / or restricting access to a network can be, for example, a virtual local area network (VLAN), Internet Protocol (IP) filtering, a virtual private network (VPN), or IP security. It can be implemented using a wide variety of technologies such as (IPSec) protocols.
The server provides the client with a URI for the master document that contains the information to prepare the client. The master document can include subfiles containing configuration and sign-up subfiles, or additional URIs for other master documents. After receiving the URI, the client can automatically download any suitable preparation file. The master document and any associated subfiles can be defined according to the eXtensible Markup Language (XML) schema.
The downloaded sign-up subfile can be processed by the client to automatically present a user interface that can receive user input information. The client can pass a first schema-based document containing user input information to the server. This can include passing an XML document defined according to the XML Schema. After submitting the first schema-based document, the client indicates that the client is allowed access to resources located on the second network (eg, by including the user identifier and password). You can receive a second schema-based document.
A third schema-based document is run on the client to configure the client for the process of adapting to the second network. This can include executing the configuration subfiles received from the server. Configuration subfiles can be executed to configure connection types, communication protocols, authentication types, encryption types, and so on. The configuration subfile can be executed at virtually any point in time after it has been downloaded. There is no requirement that the configuration subfile be executed before or after the user input information is received.
Embodiments within the scope of the present invention include computer-readable recording media for carrying or storing computer-executable instructions or data structures. Such a computer-readable recording medium can be any usable medium accessible by a general purpose computer or a special purpose computer. By way of example, but not exclusively, such computer-readable recording media are physical computer-readable recording media such as RAM, ROM, EEPROM, CD-ROM or other optical disc storage, magnetic disk storage or other magnetic storage devices, or Include any other medium that can be used to carry or store the desired program code means in the form of computer-executable instructions or data structures and is accessible to general purpose or special purpose computers. Is possible.
When information is transferred or provided to a computer system via a network or another communication connection (wired connection, wireless, or a combination of wired connection and wireless), the computer system makes the connection computer readable. Correctly consider it as a recording medium. Therefore, any such connection can be correctly referred to as a computer-readable recording medium. The combination of media described above should also be included within the scope of computer-readable recording media. Computer-executable instructions include, for example, any instruction and data that causes a general purpose computer system, special purpose computer system, or special purpose processing device to perform a function or a set of functions. Computer-executable instructions can be, for example, binary, intermediate-form instructions such as assembly language, or even source code.
Within the scope of this description and claims, a "logical communication link" is defined as any communication path that allows the transport of electronic data between two entities such as a computer system or computer module. The actual physical representation of the communication path between two entities is not important and may change over time. Logical communication links facilitate the transport of electronic data, including parts of system buses, parts of local area networks (eg Ethernet (registered trademark) networks), parts of wide area networks, parts of the Internet, parts of the above combinations, or parts of electronic data. It is possible to include any other part of the path that can be. The logical communication link can include a hard wire drink, a wireless link, or a combination of a hard wire drink and a wireless link. The logical communication link can also include software or hardware modules that condition or format parts of the electronic data so that the electronic data has access to components that implement the principles of the invention. Is. Such modules include, for example, proxies, routers, firewalls, switches, or gateways. The logical communication link can also include, for example, a portion of a virtual network such as a virtual private network (VPN) or a virtual local area network (VLAN).
Within the scope of this description and claims, a "schema" is defined as a representation of a vocabulary shared between multiple computer systems that allows multiple computer systems to process documents according to the represented shared vocabulary. To. For example, XML Schema defines and describes an XML document for a class that uses the schema syntax of the XML Schema language. Use their schema syntax to constrain the meaning, usage, and relationships of data types, elements and element content, attributes and attribute values, entities and entity content, and notifications, as used in XML documents. , Can be documented. Therefore, any computer system that has access to the XML Schema can process the XML document according to the XML Schema. In addition, any computer system that has access to the XML Schema can create or modify the XML document for use by other computer systems that also have access to the XML Schema.
The schema is defined to include a Document Type Definition ("DTD"), such as a DTD file ending with a ".dtd" extension. Also, the schema is World Wide, for example, an XML Schema file ending with a ".xsd" extension. It is also defined to include the Web Consortium ("W3C") XML Schema. However, the actual file extension for a particular DTD or XML schema is not important. Logical data types, binary data types, octal data types, decimal data types, hexadecimal data types, integer data types, floating point data types, characters used to define data structures using schemas Virtually any data type can be defined, including data types, character string data types, user-defined data types, and combinations of the above data types. XML elements and attributes can be defined to represent the data types defined by the schema. In the scope of this definition and claims, "schema-based" means defined by and / or within a schema.
FIG. 1 and the following description are intended to provide a brief general description of a suitable computing environment in which the present invention can be practiced. Although not required, the present invention will be described in the general context of computer executable instructions such as program modules executed by a computer in a network environment. In general, a program module includes routines, programs, objects, components, data structures, etc. that perform a particular task or implement a particular abstract data type. Computer executable instructions, associated data structures, and program modules represent examples of program code means for performing the steps of the methods disclosed herein. The particular sequence of such executable instructions represents an example of the corresponding steps for performing the functions described in such steps.
Referring to FIG. 1, an exemplary system for carrying out the present invention is a system bus 123 that connects a processing unit 121, a system memory 122, and various system components including the system memory 122 to the processing unit 121. Includes general purpose computing devices in the form of conventional computers 120, including. System bus 123 can be any of several types of bus structures, including memory buses or memory controllers, peripheral buses, and local buses that use any of the various bus architectures. System memory includes read-only memory (ROM) 124 and random access memory (RAM) 125. A basic input / output system (BIOS) 126 containing basic routines that help transfer information between elements inside the computer 120, such as during startup, can be stored in ROM 124.
The computer 120 may include a magnetic hard disk drive 127 for reading and writing on a magnetic hard disk 139, a magnetic disk drive 128 for reading and writing on a removable magnetic disk 129, and a CD-ROM or other optical medium. It is also possible to include an optical disk drive 130 for reading and writing with respect to the removable optical disk 131. The magnetic hard disk drive 127, the magnetic disk drive 128, and the optical disk drive 130 are connected to the system bus 123 by the hard disk drive interface 132, the magnetic disk drive interface 133, and the optical drive interface 134, respectively. These drives, and associated computer-readable recording media, provide the computer 120 with non-volatile storage of computer-executable instructions, data structures, program modules, and other data. The exemplary environment described herein uses a magnetic hard disk 139, a removable magnetic disk 129, and a removable optical disk 131, but includes a magnetic cassette, a flash memory card, a digital video disk, a Bernoulli cartridge, RAM, Other types of computer-readable recording media for storing data, such as ROMs, can also be used.
A program code means that includes one or more program modules, including an operating system 135, one or more application programs 136, another program module 137, and program data 138, is a hard disk 139, a magnetic disk 129, an optical disk 131, It can be stored in ROM 124 or RAM 125. The user can enter commands and information into the computer 120 via a keyboard 140, a pointing device 142, or other input device (not shown) such as a microphone, joystick, gamepad, satellite dish, or scanner. The above input devices and other input devices are often connected to the processing unit 121 via the serial port interface 146 coupled to the system bus 123. Alternatively, the input device can be a parallel port, a game port, or a Universal Serial bus. It may be connected by another interface such as Bus) (USB). A monitor 147 or another display device is also connected to the system bus 123 via an interface such as a video adapter 148. In addition to monitors, personal computers typically include other peripheral output devices (not shown) such as speakers and printers.
Computer 120 can operate in a networked environment using logical communication links to one or more remote computers, such as remote computers 149a and 149b. The remote computers 149a and 149b can be different personal computers, clients, servers, routers, switches, network PCs, peer devices, or other common network nodes, respectively, as described above in connection with computer 120. Although it is possible to include many or all of these elements, only the memory storage devices 150a and 150b and the related application programs 136a and 136b are shown in FIG. The logical communication links depicted in FIG. 1 include, by way of example, the local area network (LAN) 151 and the wide area network (WAN) 152 presented herein, as examples. Such networking environments are common in office-wide computer networks, or enterprise-wide computer networks, intranets, and the Internet.
When used in a LAN networking environment (eg, an Ethernet® network), the computer 120 is connected to the LAN 151 via a network interface or network adapter 153 that can be a wired or wireless interface. When used in a WAN networking environment, the computer 120 can include, for example, a wired link such as a modem 154, a wireless link, or other means for establishing communication over the WAN 152. Modem 154, which can be internal or external, is connected to system bus 123 via serial port interface 146. In a networked environment, a program module drawn in connection with the computer 120, or a portion of the program module, can be stored in a remote memory storage device. It will be appreciated that the network connections illustrated are exemplary and other means of establishing communication over the wide area network 152 can also be used.
Although FIG. 1 shows an example of a computer system capable of implementing the principles of the present invention, any computer system can implement the features of the present invention. Within the scope of this description and claims, a "computer system" is broadly defined as any hardware component, or set of hardware components, that can use software to use one or more functions. .. Examples of computer systems include desktop computers, laptop computers, personal digital assistants (PDAs), phones (both wireless and mobile), wireless access points, gateways, firewalls, proxies, routers, switches, handheld devices. , Multiprocessor systems, microprocessor-based or programmable consumer electronics, network PCs, minicomputers, mainframe computers, or any other system or device with processing power.
It will also be acknowledged by engineers in the art that the present invention can be implemented in a network computing environment that uses virtually any computer system configuration. The present invention is also a distributed system in which a local computer system and a remote computer system linked via a network (hard wire drink, wireless link, or a combination of hard wire drink and wireless link) perform tasks together. It can also be implemented in the environment. In a distributed system environment, program modules can be located in both local and remote memory storage devices.
According to the present invention, a user interface module, a provisioning module, an account maintenance module, and an authentication module, and related data including preparation data and user data are placed on any of the computer-readable recording media associated with the computer 120. It can be stored and accessed there. For example, a portion of such a module, and a portion of the associated program data, may be stored in the operating system 135, the application program 136, the program module 137, and / or the program data 138 in order to be stored in the system memory 122. It can be included. For example, when a large capacity storage device such as a magnetic hard disk 139 is coupled to the computer 120, it is also possible to store such modules and related program data in the large capacity storage device. In a networked environment, the program module drawn in connection with computer 120, or part of the program module, may be, for example, system memory and / or mass storage device associated with remote computer system 149a and / or remote computer system 149b. It can be stored in a remote memory storage device such as. Execution of such a module can be done in a distributed environment, as described above.
FIG. 4 generally shows an example of network architecture 400 that can provide access to the first network while banning access to the second network. Network architecture 400 includes client 405 and server 415. Although not required, the client 405 and the server 415 can each be structured with respect to the computer 120 as described above. As used herein, the terms "client" and "server" mean that client 405 receives services from server 415, such as access to network 413. Client 405 and server 415 are (respectively) clients and servers in this context, but in another context client 405 can act as a server and in another context server 415 acts as a client. It is possible.
As depicted in Network Architecture 400, the data routing device 414 is connected to network 411, network 412, and network 413 by the corresponding logical communication links 433, 434, and 435, respectively. The data routing device 414 logically represents a computer system that can determine where to transfer data received from network 411, such as data received from client 405. That is, when the data routing device 414 receives data from the network 411, it can determine whether the data should be transferred to the network 412 or to the network 413. Therefore, the data routing device 414 is configured to allow access to one network (eg, network 412) while at the same time prohibiting access to another network (eg, network 413). It is possible. The data routing device 414 can make this decision using a variety of different techniques.
In some embodiments, access to resources located on network 413 can be prohibited by using a virtual local area network (VLAN). In those embodiments, networks 411, 412, and 413 can each be part of a different VLAN. A VLAN-aware device within network architecture 400 can "tag" a data frame to indicate to the data routing device 414 where the data frame should be routed. For example, if client 405 is not authorized to access resources located on network 413, a component in network 411, or logical communication link 433, tags a data frame from client 405 and its It can indicate that the data frame should be routed to server 415 (or any other resource located on network 412). If client 405 is authorized to access network 413, a component in network 411, or logical communication link 433, tags a data frame from client 405 and the data frame is on network 413 as appropriate. Can indicate that a resource (eg, to the Internet) or a resource on network 412 (eg, server 415) should be routed.
In other embodiments, access to resources located on network 413 can be prohibited by using Internet Protocol (IP) filtering. A component in the data routing device 414, network 411, or logical communication link 433 filters Internet Protocol (IP) addresses to restrict client 405 access to resources with a particular IP address. can do. If client 405 is not authorized to access resources located on network 413, client 405 will be exposed to the IP address of the resource located on network 412, but the resource located on network 413. IP addresses can be filtered so that they are not exposed. If client 405 is authorized to access network 413, the IP address can be filtered so that client 405 is exposed to the IP addresses of resources located on both networks 412 and 413. Is. Alternatively, if client 405 is authorized to access network 413, IP filtering may not be complete.
In yet another embodiment, access to resources on network 413 can be prohibited by using a virtual private network (VPN). If client 405 is not authorized to access resources located on network 413, the resources placed on network 412 will be exposed to client 405, but resources placed on network 413 will not be disclosed. It is possible to configure a VPN in. If client 405 is authorized to access resources located on network 413, the VPN may be configured to expose resources located on both networks 412 and 413 to client 405. It is possible. Alternatively, if client 405 is authorized to access resources located on network 413, it is possible that no VPN will be used at all.
VLAN technology, IP filtering technology, and VPN technology can be used to distinguish networks so that they allow access to one network while banning access to another. Please understand that it is just a few examples. It should be understood that access to a single network can be restricted using VLANs, IP filtering, or VPNs. For example, a server located on network 413 can provide client 405 with limited access to resources located on network 413. After scrutinizing this description, in addition to VLAN technology, IP filtering technology, and VPN technology, other technologies can be used to allow access to one network while banning access to another. It will be clear to engineers in the field that they can.
In addition, it should be understood that the techniques used to ban access to the network can also be used to provide restricted access to the network. In some embodiments, a server on the network can provide clients with restricted access to the network. For example, a server located on network 413 can perform IP filtering to provide restricted access to network 413 to client 405. Restricted access can include access to a computer system or computer module that stores the preparation files needed to obtain full access to network 413. Client 405 may be granted permission to download preparation files from their computer system or computer module while denying access to other resources located on network 413.
Next, an exemplary embodiment of the present invention using VLAN technology will be described. Figure 2 shows an example of a network architecture 200 that can facilitate increasing the level of automation when preparing a client. Network architecture 200 includes client 205 and server 215, which can be structured as described above for computer 120, respectively.
In some embodiments, the server 215 logically represents a remote authentication dial-in user service (RADIUS) server. That is, the server 215 is visually depicted as a single system, but can include a separate network access server (NAS), a separate authentication server, and a separate shared accounting server. The above servers, represented as logical by server 215, can be configured to communicate using the RADIUS protocol, more specifically the RADIUS attribute EAP message and the message authentication code (Authenticator). ) Can be supported. Server 215 may include, for example, an Internet Information Service (IIS) module, an Internet Authentication Service (IAS) module, a Dynamic Host Control Protocol (DHCP) module, to facilitate the implementation of the principles of the present invention. And it is possible to have modules from a variety of different services loaded into system memory, such as Active Directory (AD) modules.
The network architecture 200 also includes a data routing device 214. The data routing device 214 can logically represent a special purpose computer system such as a router and / or a switch that can determine how data is transferred between the ports contained within the data routing device 214. To do. That is, when a part of data such as a data frame is transferred and entered on the first port (for example, port 242), the data routing device 214 uses the configuration rule to transfer the frame to the second port. You can decide what should be forwarded and exited on (eg, port 243). For example, the data routing device 214 can determine that the data frame received from the access point 209 should be sent to the server 215. Data frames may also be forwarded to and from the data routing device 214 on the same port.
As depicted in Network Architecture 200, the data routing device 214 is connected to network 213, server 215, and access point 209 by corresponding logical communication links 233, 234, and 235, respectively. The network 213 can be, for example, a company-wide network, a company-wide network, or virtually any type of network, such as the Internet. The data routing device 214 is a device that can group computer systems together into a single broadcast domain based on criteria other than their physical location (eg, the physical location on a particular side of the router). It is possible that Therefore, the data routing device 214 can be configured to separate the computer systems into different VLANs. As depicted in Figure 2, the data routing device 214 VLANs network architecture 200. It is configured to separate into A, B, and C. The data routing device 214 can be configured to forward both tagged and untagged data frames between the VLANs depicted in FIG.
A tagged data frame is a data frame that includes instructions such as tag headers that identify the VLAN and / or frame classification associated with the tagged data frame. A tag header can be inserted into the data frame by the VLAN cognitive device to indicate to the data routing device 214 the VLAN ID of the source VLAN of the received tagged data frame. For example, access point 209 can insert a tag header into data from client 205 to indicate to data routing device 214 that the data has been received from VLAN A. The tag header can also include other control information that can be used by the data routing device 214 to classify the corresponding data frame. An untagged data frame is a frame that does not include a tag header. The port VLAN ID (PVID) can be used to indicate the VLAN that is the source of the received untagged data frame. For example, an untagged data frame received on port 243 is a VLAN. It can be classified as received from B.
Any of the ports contained within the data routing device 214 (eg, ports 242, 243, and 244) are configured to forward tagged data frames, but drop untagged data frames. It is possible. On the other hand, any of the ports of the data routing device 214 forwards untagged data frames, but tagged data frames can also be configured to drop. Also, any of the ports on the routing device 214 can be configured to forward both tagged and untagged data frames (mixed port configuration).
The network architecture also includes access point 209. The access point 209 can be a wired or wireless access point that facilitates communication between the client 205 and the data routing device 214. As depicted in Network Architecture 200, access point 209 is connected to client 205 by the corresponding logical communication link 231. The access point 209 can be connected to another client (not shown) by another corresponding logical communication link (also not shown). Access point 209 includes ports 251 and 252. Data can be transferred between access point 209 and client 205 over port 251. Similarly, data can be transferred between the access point 209 and the data routing device 214 over port 252. The access point 209 can include other ports (not shown) for communicating with other computer systems, such as other clients and / or other data routing devices.
In some embodiments, the access point 209 has access to a wired computer system on VLAN B (eg, server 215) and a wired computer system on VLAN C (eg, a computer system contained within network 213). A wireless access point that enables it. Access point 209 can be configured as a VLAN-aware device and data received from client 205 (or any other computer system on VLAN A) that should be forwarded to VLAN B and / or VLAN C. You can insert a tag header inside the frame. Access point 209 can be configured to communicate using the RADIUS protocol, and more specifically, RADIUS access authorization (or other client) that includes a VLAN tag for client 205 (or any other client). access-accept) can support messages.
In some embodiments, the client 205 may optionally connect to one or more other access points (not shown) in addition to the access point 209. Access point 209, and one or more of them, can all be access points for the same service provider. On the other hand, the access point may be one or more access points for one or more other service providers that are different from the service provider to which the access point 209 provides access. Client 205 can be presented with a list of available service providers. It is possible to receive a user selection to initiate a connection to a service provider included in the list.
Client 205 detects an available wireless network, for example by receiving an IEEE 802.11 beacon frame and / or transmitting an IEEE 802.11 probe request frame and receiving an IEEE 802.11 probe response frame. It is possible to do. Beacon frames can essentially include a service set identifier (SSID), which is a network identifier used to distinguish one radio network from another. Through the use of beacon frames and probe frames, the client 205 can use, for example, data transfer speed, supported types of authentication (eg, open authentication, or shared authentication), supported types of encryption (eg, Wired Equivalent Protection). It can also detect other configuration settings on the access point, such as (Wire Equivalent Protection) (WEP) or Temporal Key Integrity Protocol (TKIP)).
It should be understood that the configuration settings listed are just examples of some of the possible configuration settings, and in addition to these exemplary configuration settings, a number of other configuration settings can also be determined. For example, when establishing a connection between computer systems, use the link control protocol (LCP) to configure connection settings such as packet size, protocol used for authentication, protocol used for link quality monitoring, compression, and so on. You can negotiate. You can include numbers in the option fields of LCP packets (eg, configuration request packets, configuration Ack packets, configuration Nak packets, and configuration denial packets) to negotiate their connection settings. You can include a number (eg, number 3 for authentication protocol negotiations) in the type field within the options field of the LCP packet to indicate the type of configuration option to be negotiated. A number (eg, hexadecimal value C227 for EAP) can be included in the data field in the option field of the LCP packet to provide the corresponding data for the type of negotiation indicated in the type field. If an EAP configuration is indicated, the LCP packet may include an additional number (eg, number 13 for EAP-TLS, or number 25 for PEAP) to indicate the particular EAP type of desired authentication. it can.
A particular EAP type can be decisively selected (eg, by the administrator of server 215 and / or the user of client 205) if both the client and the server support that particular EAP type. is there. Therefore, the need to negotiate using LCP packets is reduced. After the EAP type is selected (whether through negotiation or decisively), the computer system will follow the selected EAP type for EAP messages (eg, start message, response message, request message, approval message, deny). It is possible to attempt to authenticate each other via the transfer of messages, etc.). For example, if EAP-TLS is selected, client 205 communicates with server 215 via a series of EAP messages according to EAP-TLS to authenticate and possibly access resources located on VLAN C. It is possible to get permission to do so.
In some embodiments, the EAP message is encapsulated within another protocol. Therefore, computer systems cannot natively support a particular EAP type, but can transfer encapsulated EAP messages. One protocol used for encapsulation is the 802.1X protocol, which can be called EAP encapsulation over a LAN (EAPOL). The access point 209 and the data routing device 214 can be configured to support EAPOL. Therefore, the access point 209 and the data routing device 214 can transfer an EAP message of a specific EAP type even if the specific EAP type is not natively supported. Another protocol used for encapsulation is EAP-RADIUS, which encapsulates EAP messages within RADIUS messages. You can use EAP-RADIUS to understand the RADIUS protocol, but you can forward EAP messages through computer systems that do not understand EAP natively.
FIG. 3 is a flow chart showing a method for preparing a computer system. Method 300 will be described in relation to the components depicted in Network Architecture 200.
Method 300 includes the step of transmitting the proof (step 301). This can include the client sending a certificate to the server and attempting to authenticate from the server. For example, client 205 can send a certificate to server 215 and attempt to authenticate from server 215. When client 205 connects to access point 209, access point 209 can detect that the connection is active and can send an EAP request / identification message to client 205. Alternatively, client 205 can send an EAP start message to access point 209, which can trigger an EAP request / identification message. Client 205 can respond to the EAP request / identification message with an EAP response / identification message that can include a user identifier. If the user of client 205 has an account with server 215, this user identifier can be the user identifier assigned to the user by server 215. If server 215 has not assigned a user identifier to a user on client 205, client 205 may send a guest user identifier.
Access point 209 can enable forwarding of EAPOL packets on port 251. That is, the EAPOL packet received on port 251 can be forwarded so that it exits access point 209 on port 252. However, access point 209 authenticates client 205 to forward other types of protocols, such as HyperText Transfer Protocol (HTTP), DHCP, and Simple Mail Transfer Protocol (SMTP). Can be blocked until (and allowed). The access point 209 can insert a tag header inside an EAPOL packet (eg, an EAP response / identification message) to indicate that the EAPOL packet should be forwarded to VLAN B.
The data routing device 214 can process the inserted tag header and forward the EAPOL packet to VLAN B. Server 215 can receive EAPOL packets, which are forwarded to authentication module 217 for authentication. Alternatively, access point 209 and / or data routing device 214 removes 802.1X encapsulation and instead encapsulates the EAP response / identification message within the EAP-RADIUS message forwarded to VLAN B. Is also possible. Therefore, if the logical communication link 234 contains other RADIUS servers, the EAP response / identification message can be forwarded to the server 215 via those other servers.
Depending on the particular EAP type, Server 215 can respond to EAP responses / identification messages in a variety of ways. Server 215 can request that client 205 provide the password associated with the user identifier. The user of client 205 can respond by providing the password to server 215. It is also possible for client 205 and server 215 to exchange EAP messages to pass certificates, keys, and supported cipher suites. Other credentials can be exchanged between client 205 and server 215, depending on the EAP type.
Returning to FIG. 3, the method 300 includes a step (step 302) of automatically presenting the user interface. It automatically provides a user interface that can receive user input information so that the user of the computer system does not need to have prior knowledge of how the user interface is presented. It is possible to include presenting. For example, the user interface module 206 can automatically present the user interface on the client 205.
When the certificate is sent to the server 215, the authentication module 217 receives the certificate (eg, the user identifier and password) and can compare the certificate with the entries in the user database 218. If the credentials match an entry in the user database 218, the user's identity is authenticated (ie, server 215 considers the user represented by the user identifier to be the user who entered the credentials). If an authenticated user of client 205 is allowed access to resources located on VLAN C (for example, the user has not overdue payments for his account), client 205 is on VLAN C. It is possible to get permission to access the resources located in.
On the other hand, if client 205 is denied access to resources located on VLAN C, server 215 grants client 205 limited access to resources located on VLAN B. Is possible. Therefore, if client 205 is currently unable to access a resource located on VLAN C (eg, an internet resource), it will be allowed to access the resource located on VLAN C. Can be downloaded electronically (from VLAN B). Client 205 is unauthenticated, the user sends a guest certificate, or the authenticated user is not allowed to access resources located on VLAN C (eg, payment). (If is overdue), access to resources located on VLAN C may be denied.
If client 205 is denied access to a resource located on VLAN C, server 215 can send an EAP notification encrypted according to PEAP and checked for integrity to client 205. The EAP notification can include a URI to the master document that contains information for preparing the computer system to access resources located in VLAN C. The URI for the master document can be an HTTP Uniform Resource, for example https://www.provider12.com/provisioning/master.xml, or http://www.provider9.com/provisioning/master.xml. It can be a Locator) ("URL"). EAP notification is VLAN It can also include conditions that the user must meet (eg, sign-up, update, etc.) to be allowed access to resources located on C. If client 205 should make the download by accessing the provided URI, access point 209 can enable forwarding of HTTP packets on port 251. Server 215 can send commands to access point 209 to enable access point 209 to forward HTTP packets.
Alternatively, server 215 can send an EAP type-length-value (TLV) object within PEAP to client 205. A TLV object can contain a URI to a master document that contains information for preparing a computer system to access resources located on VLAN C. In some embodiments, the master document (and subfiles), such as by accessing the master document and / or subfiles on a removable computer-readable recording medium (floppy (registered trademark) disk, flash card, etc.). It can be accessed by mechanisms other than URIs. This is advantageous in environments where preparation information is first required to be able to configure a network connection, for example remote dial-up. After the connection is established, the master document (and subfiles) can be updated later from the network.
The master document can be an XML file defined according to the XML master document schema accessible to the computer system drawn in Network Architecture 200. For example, various types such as wireless, digital subscriber line (DSL), remote access server (RAS), LAN, Internet service provider (ISP) referral, wireless ISP (WISP), etc. It is possible to generate various master documents regarding the connection of. Thus, the principles of the invention can be practiced to prepare a computer system for network access using virtually any type of connection, including the listed types of connections. The master document can include URLs for subfiles such as help files, configuration files, sign-up files, and location files. The master document can also include URLs for other master documents, for example, when the first ISP uses the services of the second ISP.
The master document may also include a time-to-live (TTL) value (eg, 5 minutes, 24 hours, etc.) that indicates when an inspection on the updated master document should take place. It is possible. If the inspection indicates that an updated master document is available, the updated master document can be downloaded (for example, to client 205). The master document can include a version number for each subfile. When the master document is updated, the version number of the subfile can be checked, and if a newer version of the subfile is available, the newer version can be downloaded ( For example, to client 205).
It should be understood that the invention is not limited to any particular type of schema. However, one type of schema that can be used to implement the principles of the invention is XML Schema. XML Schema can define the elements used in an XML document and the corresponding data types. The following is an exemplary XML master document schema that defines the elements that can be used within an XML master document and the corresponding data types.
<tables num="1"><img file="JP2004213632A_D0001.tif" /></tables>
<tables num="2"><img file="JP2004213632A_D0002.tif" /></tables>
This exemplary XML master document schema defines a "master" complexType (lines 5-22) that can be used to generate a master document to prepare a computer system. The "master" complexType further defines a "TTL" element (line 7) that represents the activity time. You can use the TTL element in the master document to indicate when the master document should be updated. The "master" complexType also defines an "UpdateFrom" element (line 10). If the value of the TTL element in the XML master document indicates that the XML master document should be updated, you can access the URL associated with the UpdateFrom element to download the updated version of the XML master document. .. The "master" complexType also further defines a "subfile" element (lines 11-20) that can be used within the master document to define access to the subfile. The "maxOccurs" attribute of the subfile element indicates the number of subfiles that can be included in the master document. The value "unlimited" means that there is no limit on the number of subfiles that can be included in the master document.
Within the subfile element, the "schema" element (line 14), the URL element (line 15), and the version element (line 16) are defined. Schema elements can be included in the master document to represent the name of the schema associated with the subfile. You can include a version element in the master document to indicate the version of the subfile. A URL element can be included in the master document to indicate where the schema associated with the subfile can be downloaded. In this exemplary XML master document schema, URL elements are defined as text strings (lines 23-27) starting with the text prefix "https: //". However, in practicing the principles of the invention, virtually any text prefix such as "http: //", "ftp: //", "telnet: //" can be used. Subfile elements can also define an optional "fragment" attribute (line 18) that can be included in the master document to represent a particular subfile. For example, the "#signup" fragment attribute can be used to represent a signup subfile. Fragment attributes can be combined with URL elements in an XML master document to provide an absolute location for subfiles, for example "https://www.provisioning.com/master.xml#signup" it can.
Master documents and subfiles can be stored in prepared datastore 219. Client 205 can access the provided URL (or URI) to download the master document and the appropriate subfile. Master documents and subfiles can be downloaded using HTTP Get or HTTPS Get. It uses an HTTP or HTTPS get to file from a computer system located on VLAN B, for example, a Hot Spot Provider (HSP), an ISP web server, or a prepared datastore 219. Including downloading. The downloaded master document and subfile can be stored in the preparation data 207.
The help subfile can be an XML document defined according to an XML help schema that can be accessed by a computer system drawn with Network Architecture 200. The help file can contain a URL that links to a HyperText markup language ("HTML") file provided by server 215 to help the user prepare client 205. The help file can also contain information about the service provider so that the user can know about the service provider before signing up.
The location subfile can be an XML document defined according to an XML location schema that can be accessed by a computer system drawn with Network Architecture 200. The location subfile can contain a list of HSPs and the corresponding postal addresses, hotels, and airports where the HSPs are located. Therefore, it is possible for a user heading to a particular location to download a preparatory file for accessing the network (eg, the Internet) from that particular location before arriving at that particular location.
It should be understood that the present invention is not limited to connecting to a network at any particular location. The following is an exemplary XML location schema that defines the elements that can be used in the location subfile to indicate the physical location where network access is available, and the corresponding data types.
<tables num="3"><img file="JP2004213632A_D0003.tif" /></tables>
This exemplary XML location schema defines a "location" complexType (lines 7-31) that can be used to provide physical location information about network access. Include one, some, or all of the elements defined in lines 9-17 in the location subfile, for example, street, city, state, country, zip code, area code, phone number, support number. , And various types of location information such as provider name can be indicated. The location complexType further defines a "category" element (lines 18-29) that further defines the categories of locations where access to the network can be physically located, such as hotels, airports, and bars.
The configuration subfile can be an XML document defined according to an XML configuration schema accessible to a computer system drawn in Network Architecture 200. The configuration subfile can contain configuration profiles for networks accessible to client 205. If client 205 attempts to access the wireless network, the configuration subfile can contain a profile that corresponds to the SSID that client 205 can access. The configuration subfile can contain information for configuring authentication, encryption, supported protocols, and the like. The received configuration subfile is stored in the preparation data 207 and processed by the preparation module 208 so that the client 205 can be configured for a process on a particular network.
It should be understood that the present invention is not limited to connecting to a network using any particular interface. However, one type of interface that can be used to connect to a network is a wireless interface (eg, network interface 153 can be a wireless network interface). The following is an exemplary XML configuration schema that defines the elements that can be used in a configuration subfile to connect to a network via a wireless interface (eg, a wireless access point), and the corresponding data types.
<tables num="4"><img file="JP2004213632A_D0004.tif" /></tables>
<tables num="5"><img file="JP2004213632A_D0005.tif" /></tables>
<tables num="6"><img file="JP2004213632A_D0006.tif" /></tables>
<tables num="7"><img file="JP2004213632A_D0007.tif" /></tables>
This exemplary XML configuration schema defines an "SSID" complexType (lines 7-92) that can be used to configure parameters for connecting to a network represented by an SSID through a wireless access point. .. SSID complexType includes "connection" element (rows 11-18), "authentication" element (rows 19-28), "encryption" element (lines 29-39), "KeyIndex" element (row 40), "802.1Xauth" Further define the "Non802.1XURL" element (lines 50), the "PEAP parameter" element (lines 51-76), and the "TLS parameter" element (lines 77-90).
The defined connection elements (lines 11-18) further define the types of connections that can be supported by the network. The defined "IBSS" element (line 14) represents the name of the Basic Service Set. IBSS elements can be included in the configuration subfile to associate a more meaningful network name with the SSID for networks that may be accessed through a single wireless access point. The defined "ESS" element (line 15) represents the name of the Extended Service Set. The ESS element is used to associate more meaningful network names with multiple SSIDs that form a single network, and / or when the network may be accessed via multiple wireless access points. It can be included in the configuration subfile.
The defined authentication factors (lines 19-28) further define the types of authentication that can be supported by the network. The defined "open" element (line 22) can be included in the configuration subfile to indicate open authentication. That is, authentication does not use the pre-shared key required to authenticate the access point. A defined "shared" element (line 23) can be included in the configuration file to indicate that credentials are shared between applications. A defined "WPA" element (line 24) can be included in the configuration file to indicate that authentication is done according to WiFi protected access. A defined "WPAPSK" element (line 25) can be included in the configuration subfile to indicate that authentication is performed according to WiFi protected access pre-shared key authentication.
The defined cryptographic elements (lines 29-39) further define the types of cryptography that can be supported by the network. Include one, some, or all of the defined elements on lines 32-36 in the configuration subfile, eg, no encryption, WEP encryption, TKIP encryption, wireless robust authenticated protocol (Wireless). Various types of encryption, including Robust Authenticated Protocol (WRAP) encryption, Counter with Cipher Block Chaining Message Authentication Code Protocol (CCMP) encryption. Can be shown.
A defined KeyIndex element (line 40) can be included in the configuration subfile to indicate the location of a key, such as a key that can be used to encrypt or validate information, for example.
The defined "802.1Xauth" element (lines 41-49) further defines the types of 802.1X authentication that can be supported by the network. One, some, or all of the elements on lines 44-46 can be included in the configuration subfile to indicate various types of 802.1X authentication, such as no authentication, TLS, and PEAP.
The defined "non-802.1X URL" element (line 50) can be included in the configuration subfile to indicate the URLs that can be accessed for non-802.1X authentication. This can be done to adapt to traditional systems that do not support EAP.
The defined "PEAP parameters" element (lines 51-76) further defines the PEAP options that can be supported by the network. Include one, some, or all of the elements on lines 54-57 and 66 in the configuration subfile, eg, server validation, server name list, server certificate hash, certificate revocation. Various PEAP options such as list) (CRL), fast reconnect, etc. can be shown. Also, the defined "PEAP parameter" element (lines 51-76) is included in the configuration subfile to be used by the server to authenticate from the client and / or to authenticate the client from the server. It also defines an "EAP type" element that can indicate the type of EAP used. Include one or both of the elements on lines 61 and 62 in the configuration subfile, for example, various EAP types such as EAP-TLS and EAP Microsoft Challenge / Response Handshake Protocol Version 2 (EAP-MSChapV2). Can be shown. When EAP-MSChapV2 is indicated, the "MSChapV2 Parameter" element on line 67 can be included in the configuration subfile to indicate whether the operating system certificate should be used for authentication.
The defined "TLS parameter" element (lines 77-90) further defines the EAP-TLS options that can be supported by the network. Include one, some, or all of the elements on lines 80-87 in the configuration subfile, for example, using smart cards, using certificates on the client, using simple certificate selection, certificate selection. You can indicate various EAP-TLS options that you do not use, such as server validation, server name list, server certificate hash, and certificate revocation list (CRL).
The sign-up (or update) subfile can be an XML document defined according to an XML sign-up schema that can be accessed by a computer system drawn in Network Architecture 200. In response to receiving an EAP notification (or TLV object) that further information is needed (eg, to allow access to resources located on VLAN C), client 205 Sign-up files can be downloaded automatically. The sign-up file can be processed by the user interface module 206 and the user interface can be automatically presented at the client 205. Therefore, the user does not need to have prior knowledge of how to ensure that the user interface is presented.
The XML sign-up schema includes branding information, subscription information (eg period, price, etc.), provider contact information, payment method (eg credit card, paypal, pre-pad card, certification). You can define entry fields for documents, etc., entry fields for contact information (name, address, phone number, etc.), certification type, user name, password, RADIUS server certificate, etc. In addition, the user interface can be presented in various written languages such as English, Japanese, French, or German. Support for various written languages can be facilitated by using XML language tags.
When the user interface is presented for the purpose of updating the registration, the amount of user input information received in the user interface can be reduced. The user interface presented may include only "yes" and "no" controls to allow additional credit card payments, or other electronic payment options.
Returning to FIG. 3, Method 300 includes a result-oriented functional step (step 307) for requesting permission to access resources located on the second network. Step 307 can include any corresponding step to achieve the result of requesting permission to access a resource located on the second network. However, in the example shown in FIG. 3, step 307 includes a corresponding step (step 303) of receiving user input information. Using the presented user interface, user input information (eg, user identifier, password, name, address, credit card information, etc.) can be received from the user on the client 205. If the user has updated their account, it is possible to receive a smaller amount of information. For example, the user has a VLAN If you have previously signed up to access a resource located on C, the account maintenance module 216 will access the user database 218 to retrieve the previously entered user information and the user will be able to access the user information. It is possible to be freed from having to re-enter. The user can select the "Yes" control to provide user input information to approve credit card payments or other electronic payment options.
Step 307 also includes a corresponding step (step 304) of passing a schema-based document. This can include the client passing a first schema-based document containing user input information to the server. For example, client 205 can pass a first XML document defined according to an XML sign-up schema, including user input information received in the presented user interface. Client 205 can use HTTP or HTTPS posts to upload schema-based documents to HSPs, ISP websites, or to server 215. Account maintenance module 216 can have a web-based interface for receiving schema-based documents uploaded using HTTP posts or HTTPS posts. In some embodiments, the web-based interface to account maintenance module 216 can process user input information contained within a schema-based document to update user database 218.
Method 300 also includes a step of receiving a permit instruction (step 305). This can include the client receiving a second schema-based document that provides instructions that the server has allowed access to resources located on the VLAN. For example, client 205 may receive a second XML document defined according to the XML sign-up schema that provides instructions that client 205 is allowed to access resources located on VLAN C. Receipt of the second schema-based document can occur in response to submitting the first schema-based document. For example, in response to submitting the appropriate user input information, client 205 may receive an instruction that server 215 has allowed client 205 to access resources located on VLAN C. .. This can include receiving a user identifier and password, or receiving an instruction that the credit card payment has been accepted.
If client 205 is allowed to access resources located on VLAN C, access point 209 enables any currently blocked protocol for port 251 from client 205. You can insert a tag header to indicate that your data should be forwarded to VLAN C. Server 215 can send commands to access point 209 to enable access point 209 to enable the protocol and to have access point 209 insert the appropriate tag headers.
Server 215 can set a session timeout, for example one hour, after which access point 209 can request client 205 to authenticate again. If the enrollment is still valid at the time of re-authentication, client 205 can be re-authenticated in the background by passing the appropriate certificate to server 215. On the other hand, if the subscription period has expired at the time of re-authentication, the server 215 can send an EAP notification (or TLV object) that allows the updated user interface to be presented to the client 205. The subscription period is after a specified period of time (eg, 1 month, 24 hours, etc.) or after a specified number of connections (eg, 1 connection, 10 connections, etc.) through a particular service provider. It can expire later. After proper completion of the update user interface, client 205 can be authenticated again.
If the user does not properly complete the update user interface, access point 209 stops inserting the tag header for VLAN C in the data from client 205 and the tag header for VLAN B in the data from client 205. It is possible to start inserting. Access point 209 can also begin to block the protocol for port 251. Server 215 can send commands to access point 209, causing access point 209 to block the protocol and insert the appropriate tag headers.
In parallel with steps 302 to 305, method 300 also includes step (step 306) of executing a schema-based document. This can include running a third schema-based document and configuring the client to access the second network. For example, preparation module 208 can execute XML documents defined according to the XML configuration schema to properly configure client 205 to access resources located on VLAN C. Preparation module 208 can retrieve previously downloaded XML documents from preparation data 207, for example configuration subfiles.
You can run configuration subfiles to configure connection types, communication protocols, authentication types, encryption types, and so on. The configuration subfile can be executed at virtually any time after it is downloaded. Therefore, the client can be properly configured to access resources located on the network, even if access to the network is denied. Through the execution of schema-based documents, clients can be reconfigured with little or no user intervention. This frees the user from having to manually reconfigure the client for network-friendly behavior.
In some embodiments, the computer system currently prepared for Internet access using the first network configuration is pre-prepared for Internet access using the second network configuration. For example, a computer system with internet access through an ISP can sign up at an ISP website for internet access through a wireless hotspot. During the registration process with your ISP, your computer system can download a preparation file for your wireless hotspot. Therefore, upon connecting to a wireless hotspot, the computer system is already properly configured to access the Internet via the wireless hotspot. In addition, if your account information (eg name, address, payment information, etc.) is entered during the registration process with your ISP, your computer system may already be authorized to access the Internet via wireless hotspots. It is possible.
The present invention can be practiced in other particular embodiments without departing from the spirit or basic features of the invention. The embodiments described above should be considered in all respects to be exemplary and not limiting. Therefore, the scope of the present invention is shown not by the above description but by the scope of claims. All changes contained in the meaning and scope equivalent to the claims shall be included in the claims.
<figref num="1">It is a figure which shows the operating environment suitable for the principle of this invention.</figref><figref num="2">It is a diagram showing an example of a network architecture that can facilitate an increase in the level of automation when preparing a client.</figref><figref num="3">It is a flow chart which shows an example of the method for preparing a computer system.</figref><figref num="4">It is a diagram generally showing an example of a network architecture that can provide access to the first network while prohibiting access to the second network.</figref>
Code description
200 Network Architecture 205 Client 206 User Interface Module 207 Prepared Data 208 Prepared Module 209 Access Point 213 Network 214 Data Routing Device 215 Server 216 Account Maintenance Module 217 Authentication Module 218 User Database 219 Prepared Data Store 231, 233, 234, 235 Logical Communication Links 242, 243, 244, 251, 252 ports
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2007207067A | Cited by | Japan | Search report |
| JP2008541590A | Cited by | Japan | Search report |
| JP2012073893A | Cited by | Japan | Examiner |
| US8271792B2 | Cited by | United States of America | Applicant |
| JP2006099780A | Cited by | Japan | Examiner |
| JP2007199880A | Cited by | Japan | Examiner |
| JP2008042882A | Cited by | Japan | Search report |
| US9363285B2 | Cited by | United States of America | Applicant |
| JP2014509474A | Cited by | Japan | Search report |
| JP2011018347A | Cited by | Japan | Examiner |
| JP2008042882A | Cited by | Japan | Examiner |
| JP2006072682A | Cited by | Japan | Search report |
| US11949562B2 | Cited by | United States of America | Applicant |
| JP2014509474A | Cited by | Japan | Examiner |
| WO0131843A2 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| WO02080467A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| EP1182591A2 | Cites | European Patent Office (EPO) | Examiner |
| JP2000324104A | Cites | Japan | Examiner |
22 members in 12 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10313084 | United States of America | – | |
| 31308402 | United States of America | A | |
| 31308402 | United States of America | A | |
| 2002313084 | – | – | – |
| US20020313084 | – | – | – |
Members22
| Document | Office | Kind | |
|---|---|---|---|
| CA2448946A1 | Canada | A1 | |
| EP1427163A2 | European Patent Office (EPO) | A2 | |
| US2004111520A1 | United States of America | A1 | |
| KR20040049822A | Republic of Korea | A | |
| AU2003266437A1 | Australia | A1 | |
| CN1514619A | China | A | |
| JP2004213632AThis record | Japan | A | |
| BR0305307A | Brazil | A | |
| MXPA03011281A | Mexico | A | |
| EP1427163A3 | European Patent Office (EPO) | A3 | |
| RU2003135540A | Russian Federation | A | |
| US7284062B2 | United States of America | B2 | |
| EP1427163B1 | European Patent Office (EPO) | B1 | |
| AT390008T | Austria | T | |
| DE60319791D1 | Germany | D1 | |
| RU2342700C2 | Russian Federation | C2 | |
| DE60319791T2 | Germany | T2 | |
| AU2009208127A1 | Australia | A1 | |
| AU2003266437B2 | Australia | B2 | |
| CN100581154C | China | C | |
| KR101004504B1 | Republic of Korea | B1 | |
| AU2009208127B2 | Australia | B2 |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Written withdrawal of applicationA761 | A761 | |
| Notification of revocation of power of sub attorneyRD15 | RD15 | |
| Written amendmentA521 | A521 | |
| Notification of appointment of power of sub attorneyRD13 | RD13 | |
| Decision of refusalA02 | A02 | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2004213632
- Publication, DOCDB
- 2004213632
- Publication, EPODOC
- JP2004213632
- Application
- 406559
- Application, DOCDB
- 2003406559
- Application, EPODOC
- JP20030406559
Titles2
- Japanese
- コンピュータシステムがネットワークにアクセスするように準備する際に自動化のレベルを高める方法、コンピュータプログラム及び記録媒体
- English
- How to increase the level of automation in preparing a computer system to access a network, computer programs and recording media
Classification
- CPC, 6
- H04L63/08
- H04L9/32
- H04L63/0272
- H04L63/162
- H04L67/306
- H04L69/329
- IPC, 8
- G06F21 00
- G06F15 00
- G06F21 31
- G09C1 00
- H04L9 32
- H04L12 22
- H04L29 06
- H04L29 08