JP2004213632A

Method, computer program and recording medium for improving automation level when computer system prepares to access to network

Abstract

[Subject] Raise the level of automation, when you prepare so that a computer system may access a network. [Solution means] If accessing the 1st network is not permitted when a computer system tends to obtain the permission which accesses the 1st network from a server in response to attestation, The permission which accesses the 2nd network in order to download the file needed for accessing the 1st network can be given. The document of the 1st schema base including user input information is transmitted to a server. When a server judges with user input information being suitable, the 2nd schema document including directions of the permission which accesses the 1st network is received. The document of the 3rd schema base is performed in a computer system, and a computer system is constituted so that it may suit accessing the 1st network. [Selection figure] Fig. 2

JP2004213632A, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Projected expiry passed 4 December 2023, 2.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

40 claims: 9 independent, 31 dependent

  1. 1
    A network that can connect to both a second network that contains multiple resources through an intermediate computer system and at least a first network that contains resources to prepare the computer system to access the second network. In a computer system, the intermediate computer system determines whether the data from the computer system is transferred to the first network or the second network to access the first network. Allowing access to the second network while being forbidden, the first network further includes a server that can allow the computer system to access the second network. , A method of preparing a computer system to access a second network to reduce user input, the process of sending a certificate to the server and attempting to be authenticated by the server, Automatically presenting a user interface that can receive user input information so that the user of the computer system does not need to have prior knowledge of how the user interface is presented. , The process of receiving user input information in the user interface, the process of passing the first schema-based document containing the user input information to the server, and the process of submitting the first schema-based document. The process of receiving a second schema-based document that provides instructions that the server has allowed the computer system to access resources located on the second network, and the third running of the third schema-based document. A method characterized by including the process of configuring a computer system to access the network of 2 and freeing the user from having to manually configure the computer system. 中間コンピュータシステムを介して複数のリソースを含む第2のネットワークと、少なくともコンピュータシステムが第2のネットワークにアクセスするように準備するためのリソースを含む第1のネットワークの両方に接続可能なネットワークであるコンピュータシステムにおいて、中間コンピュータシステムは、コンピュータシステムからのデータが第1のネットワークに転送されるか、又は第2のネットワークに転送されるかを決定して、第1のネットワークへのアクセスを、第2のネットワークへのアクセスが禁止されている間に、許すことが可能であるようにし、第1のネットワークは、コンピュータシステムが第2のネットワークにアクセスすることを許可することができるサーバをさらに含む、第2のネットワークにアクセスするようにコンピュータシステムを準備してユーザ入力を減らすようにする方法であって、 証明をサーバに送信してサーバから認証を受けようと試みる工程と、 ユーザ入力情報を受け取ることができるユーザインターフェースを自動的に提示して、コンピュータシステムのユーザが、どのようにユーザインターフェースが提示されるようにするかについての事前の知識を有することを必要としないようにする工程と、 ユーザインターフェースの中にユーザ入力情報を受け取る工程と、 ユーザ入力情報を含む第1のスキーマベースのドキュメントをサーバに渡す工程と、 第1のスキーマベースのドキュメントをサブミットした後に、第2のネットワーク上に配置されたリソースにコンピュータシステムがアクセスすることをサーバが許可したという指示を提供する第2のスキーマベースのドキュメントを受け取る工程と、 第3のスキーマベースのドキュメントを実行して第2のネットワークにアクセスするためにコンピュータシステムを構成して、コンピュータシステムを手作業で構成しなければならないことからユーザを解放するようにする工程とを含むことを特徴とする方法。
  2. 20
    The process of executing a third schema-based document and configuring a computer system to access a second network is characterized by including the process of executing an XML document defined according to the XML configuration schema. The method described in Item 1. 第3のスキーマベースのドキュメントを実行して、第2のネットワークにアクセスするためにコンピュータシステムを構成する工程は、XML構成スキーマに従って定義されたXMLドキュメントを実行する工程を含むことを特徴とする請求項1に記載の方法。
  3. 27
    A network that can connect to both a second network that contains multiple resources through an intermediate computer system and at least a first network that contains resources to prepare the computer system to access the second network. In a computer system, the intermediate computer system determines whether the data from the computer system is transferred to the first network or the second network to access the first network. Allowing access to the second network while being forbidden, the first network further includes a server that can allow the computer system to access the second network. , A method of preparing a computer system to access a second network to reduce user input, the process of sending a certificate to the server and attempting to be authenticated by the server, Automatically presenting a user interface that can receive user input information so that the user of the computer system does not need to have prior knowledge of how the user interface is presented. To the resources placed on the second network, after submitting the first schema-based document, and the steps to request permission to access the resources placed on the second network. The process of receiving a second schema-based document that provides instructions that the server has allowed access to the computer system, and the computer system to run the third schema-based document to access the second network. A method comprising the steps of configuring a computer system to free the user from having to manually configure the computer system. 中間コンピュータシステムを介して複数のリソースを含む第2のネットワークと、少なくともコンピュータシステムが第2のネットワークにアクセスするように準備するためのリソースを含む第1のネットワークの両方に接続可能なネットワークであるコンピュータシステムにおいて、中間コンピュータシステムは、コンピュータシステムからのデータが第1のネットワークに転送されるか、又は第2のネットワークに転送されるかを決定して、第1のネットワークへのアクセスを、第2のネットワークへのアクセスが禁止されている間に、許すことが可能であるようにし、第1のネットワークは、コンピュータシステムが第2のネットワークにアクセスすることを許可することができるサーバをさらに含む、第2のネットワークにアクセスするようにコンピュータシステムを準備してユーザ入力を減らすようにする方法であって、 証明をサーバに送信してサーバから認証を受けようと試みる工程と、 ユーザ入力情報を受け取ることができるユーザインターフェースを自動的に提示して、コンピュータシステムのユーザが、どのようにユーザインターフェースが提示されるようにするかについての事前の知識を有することを必要としないようにする工程と、 第2のネットワーク上に配置されたリソースにアクセスする許可を要求するためのステップと、 第1のスキーマベースのドキュメントをサブミットした後に、第2のネットワーク上に配置されたリソースにコンピュータシステムがアクセスすることをサーバが許可したという指示を提供する第2のスキーマベースのドキュメントを受け取る工程と、 第3のスキーマベースのドキュメントを実行して第2のネットワークにアクセスするためにコンピュータシステムを構成して、コンピュータシステムを手作業で構成しなければならないことからユーザを解放するようにする工程とを含むことを特徴とする方法。
  4. 28
    A network that can connect to both a second network that contains multiple resources through an intermediate computer system and at least a first network that contains resources to prepare the computer system to access the second network. In a computer system, the intermediate computer system determines whether the data from the computer system is transferred to the first network or the second network to access the first network. Allowing access to the second network while being prohibited, the first network further includes a server that can allow the computer system to access the second network. , A computer program for implementing a method that prepares a computer system to access a second network to reduce user input, sending proofs to the server and attempting to authenticate from the server. With computer executable instructions for To present a user interface that can receive user input information so that users of the computer system do not need to have prior knowledge of how the user interface is presented. Computer-executable instructions, computer-executable instructions to receive user-input information in the user interface, computer-executable instructions to pass a first schema-based document containing user-input information to the server, and so on. A computer for receiving a second schema-based document that provides instructions that the computer system has allowed access to resources located on the second network after submitting the first schema-based document. Configure the computer system to run executable instructions and a third schema-based document to access the second network, freeing the user from having to manually configure the computer system. A computer program characterized by containing computer-executable instructions for. 中間コンピュータシステムを介して複数のリソースを含む第2のネットワークと、少なくともコンピュータシステムが第2のネットワークにアクセスするように準備するためのリソースを含む第1のネットワークの両方に接続可能なネットワークであるコンピュータシステムにおいて、中間コンピュータシステムは、コンピュータシステムからのデータが第1のネットワークに転送されるか、又は第2のネットワークに転送されるかを決定して、第1のネットワークへのアクセスを、第2のネットワークへのアクセスが禁止されている間に、許すことが可能であるようにし、第1のネットワークは、コンピュータシステムが第2のネットワークにアクセスすることを許可することができるサーバをさらに含む、第2のネットワークにアクセスするようにコンピュータシステムを準備してユーザ入力を減らすようにする方法を実施するためのコンピュータプログラムであって、 証明をサーバに送信してサーバから認証を受けようと試みるためのコンピュータ実行可能命令と、 ユーザ入力情報を受け取ることができるユーザインターフェースを提示して、コンピュータシステムのユーザが、どのようにユーザインターフェースが提示されるようにするかについての事前の知識を有することを必要としないようにするためのコンピュータ実行可能命令と、 ユーザインターフェースの中にユーザ入力情報を受け取るためのコンピュータ実行可能命令と、 ユーザ入力情報を含む第1のスキーマベースのドキュメントをサーバに渡すためのコンピュータ実行可能命令と、 第1のスキーマベースのドキュメントをサブミットした後に、第2のネットワーク上に配置されたリソースにコンピュータシステムがアクセスすることをサーバが許可したという指示を提供する第2のスキーマベースのドキュメントを受け取るためのコンピュータ実行可能命令と、 第3のスキーマベースのドキュメントを実行して第2のネットワークにアクセスするためにコンピュータシステムを構成して、コンピュータシステムを手作業で構成しなければならないことからユーザを解放するようにするためのコンピュータ実行可能命令とを含むことを特徴とするコンピュータプログラム。
  5. 32
    It is possible to connect to both a first virtual network that provides multiple services through an intermediate computer system and a second virtual network that provides at least a subset of the services, and the intermediate computer system is from the computer system. A server connected to a second virtual network in a computer system, which is a network that determines whether data should be transferred to the first virtual network or to the second virtual network. Updates the computer system to access the service on the first virtual network, which can provide update information to update the computer system to access the service on the first virtual network. A way to reduce user input, automatically instructing the process of trying to access a service on the first virtual network and the computer system should be updated for access that matches the service. The process of presenting to the application user does not need to have prior knowledge of how to update the computer system, and The process of receiving user input information indicating a request to update the computer system, the process of passing the first schema-based document containing the user input information to the server, and the process of submitting the first schema-based document, and then the computer system. Free the user from the process of receiving a second schema-based document containing update information and running the second schema-based document to update the computer system and manually updating the computer system. A method characterized by including steps to do so. 中間コンピュータシステムを介して複数のサービスを提供する第1の仮想ネットワークと、複数のサービスの少なくともサブセットを提供する第2の仮想ネットワークの両方に接続可能であり、中間コンピュータシステムが、コンピュータシステムからのデータが第1の仮想ネットワークに転送されるべきか、又は第2の仮想ネットワークに転送されるべきかを決定するようにしているネットワークであるコンピュータシステムにおいて、第2の仮想ネットワークに接続されたサーバは、第1の仮想ネットワーク上のサービスにアクセスするようにコンピュータシステムを更新するための更新情報を提供することができる、第1の仮想ネットワーク上のサービスにアクセスするようにコンピュータシステムを更新してユーザ入力を減らすようにする方法であって、 第1の仮想ネットワーク上のサービスにアクセスしようと試みる工程と、 サービスに適合するアクセスのためにコンピュータシステムが更新されるべきであるという指示を自動的に提示して、アプリケーションのユーザが、どのようにコンピュータシステムを更新するかについての事前の知識を有することを必要としないようにする工程と、 コンピュータシステムを更新する要望を示すユーザ入力情報を受け取る工程と、 ユーザ入力情報を含む第1のスキーマベースのドキュメントをサーバに渡す工程と、 第1のスキーマベースのドキュメントをサブミットした後に、コンピュータシステムに関する更新情報を含む第2のスキーマベースのドキュメントを受け取る工程と、 第2のスキーマベースのドキュメントを実行してコンピュータシステムを更新して、コンピュータシステムを手作業で更新しなければならないことからユーザを解放するようにする工程とを含むことを特徴とする方法。
  6. 33
    An activity that defines a name field that defines the format for naming the preparation master document, and an activity time format that indicates when the preparation master document named according to the naming format defined within the name field should be updated. It is characterized by storing a data structure that includes a time field and a subfile field that defines a format for representing subfiles in a preparation master document named according to the naming format defined within the name field. One or more computer-readable recording media. 準備マスタドキュメントを命名するための形式を定義する名前フィールドと、 名前フィールド内で定義された命名形式に従って命名された準備マスタドキュメントがいつ更新されるべきかを表わすための活動時間形式を定義する活動時間フィールドと、 名前フィールド内で定義された命名形式に従って命名された準備マスタドキュメント内のサブファイルを表わすための形式を定義するサブファイルフィールドとを含むデータ構造を記憶していることを特徴とする1つ又は複数のコンピュータ可読記録媒体。
  7. 36
    One or more of claims 33, characterized in that it further comprises an update field that defines a format for indicating where the updates for the preparatory master document defined according to the naming format within the naming field are located. Computer-readable recording medium. 命名フィールド内の命名形式に従って定義された準備マスタドキュメントに関する更新がどこに配置されているかを表わすための形式を定義する更新フィールドをさらに含むことを特徴とする請求項33に記載の1つ又は複数のコンピュータ可読記録媒体。
  8. 37
    Data that includes a connection field that defines the format for representing the types of connections supported by the network, and an authentication field that defines the format for representing the types of authentication supported by the connection types defined within the connection field. A computer-readable recording medium, characterized in that it stores a structure. ネットワークによってサポートされる接続のタイプを表わすための形式を定義する接続フィールドと、 接続フィールド内で定義された接続タイプによってサポートされる認証のタイプを表わすための形式を定義する認証フィールドとを含むデータ構造を記憶していることを特徴とする1つ又は複数のコンピュータ可読記録媒体。
  9. 39
    One or more of claims 37, wherein the authentication field consists of a conventional authentication field that defines a format for representing a location that can be accessed to authenticate a computer system that does not support EAP. Computer-readable recording medium. 認証フィールドは、EAPをサポートしないコンピュータシステムを認証するのにアクセスすることができるロケーションを表わすための形式を定義する従来の認証フィールドから成ることを特徴とする請求項37に記載の1つ又は複数のコンピュータ可読記録媒体。