System and method for enhanced network client security
Abstract
Provide systems and methods for advanced network access. One aspect of an embodiment described is a step of receiving a user-related connection request to a network, a step of determining a user-related policy, a step of identifying at least one available network connection, and at least one. It includes determining at least one characteristic of the available network connection, evaluating the characteristic based on at least some policies, and selecting at least one available network connection based on the evaluation. In another embodiment, a computer-readable medium (eg, random access memory, or computer disk) comprises code that performs the above method.
Term
Term ended
Projected expiry passed 27 June 2025, 1.2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
28 claims: 6 independent, 22 dependent
- 1ユーザに関連するネットワークへの接続要求を受信するステップと、 前記ユーザに関連するポリシーを決定するステップと、 少なくとも1つの利用可能なネットワーク接続を特定するステップと。 前記少なくとも1つの利用可能なネットワーク接続の少なくとも1つの特性を決定するステップと、 少なくとも一部前記ポリシーに基づいて前記特性を評価するステップと、 前記評価に基づいて前記少なくとも1つの利用可能なネットワーク接続を選択するステップ とを含むことを特徴とする方法。
- 2前記ポリシーが、接続許容リストを含むことを特徴とする請求項1に記載の方法。
- 3前記ポリシーが、接続非許容リストを含むことを特徴とする請求項1に記載の方法。
- 4前記特性が、セキュリティ、信頼性、速度、および経費を構成上含むグループから選択する特性を含むことを特徴とする請求項1に記載の方法。
- 5前記少なくとも1つの特性が、複数の特性を含み、更に前記複数の特性に正規化アルゴリズムを適用するステップを含むことを特徴とする請求項1に記載の方法。
- 6前記ポリシーを決定するステップが中央ポリシー格納装置から前記ポリシーを抽出するステップを含むことを特徴とする請求項1に記載の方法。
- 7前記少なくとも1つの利用可能なネットワーク接続が公的接続を含むことを特徴とする請求項1に記載の方法。
- 8前記少なくとも1つの利用可能なネットワーク接続が私的接続を含むことを特徴とする請求項1に記載の方法。
- 9前記少なくとも1つの利用可能なネットワーク接続に関連するサービス品質データを受信するステップを更に含むことを特徴とする請求項1に記載の方法。
- 10前記少なくとも1つの利用可能なネットワーク接続が、複数の利用可能なネットワーク接続を含むことを特徴とする請求項1に記載の方法。
- 11新規ネットワーク接続が、ユーザに付属するクライアント装置にとって利用可能であるとの指示を受信するステップと、 前記新規ネットワーク接続に関連する少なくとも1つの第1の特性を決定するステップと、 既存ネットワーク接続に関連する少なくとも1つの第2の特性を決定するステップと、 前記ユーザに関連するポリシーを決定するステップと、 少なくとも一部前記ポリシーに基づいて前記少なくとも1つの第1の特性を評価するステップと、 少なくとも一部前記ポリシーに基づいて前記少なくとも1つの第2の特性を評価するステップと、 前記既存ネットワーク接続を切断にするステップと、 前記新規ネットワーク接続に接続するステップ とを含むことを特徴とする方法。
- 12前記新規ネットワーク接続が利用可能であることを信号通知するステップを更に含むことを特徴とする請求項11に記載の方法。
- 13前記既存ネットワーク接続を切断にする前に、切断中のデータをバッファするためにデータキャッシュを開くステップを更に含むことを特徴とする請求項11に記載の方法。
- 14前記新規ネットワーク接続に接続後、 前記データキャッシュからデータを受信するステップと、 前記データキャッシュを閉じるステップ とを更に含むことを特徴とする請求項13に記載の方法。
- 15前記データキャッシュの大きさを決定するための尺度を受信するステップを更に含むことを特徴とする請求項13に記載の方法。
- 16前記尺度が見積もり切断継続時間を含むことを特徴とする請求項15に記載の方法。
- 17新規ネットワーク接続が利用可能であるとの指示が、ハードウェア装置からの信号を含むことを特徴とする請求項11に記載の方法。
- 18前記ハードウェア装置が、Wi-Fiアダプタ、LANアダプタ、セルラーアダプタ(WWAN)、およびダイヤルアップ(WAN)アダプタを構成上含むグループから選択するアダプタを含むことを特徴とする請求項17に記載の方法。
- 19符号化プログラムコードが存在する、コンピュータ可読媒体であって、該プログラムコードが、 ユーザに関連するネットワークへの接続要求を受信するためのプログラムコードと、 前記ユーザに関連するポリシーを決定するためのプログラムコードと、 少なくとも1つの利用可能なネットワーク接続を特定するためのプログラムコードと、 前記少なくとも1つの利用可能なネットワーク接続の少なくとも1つの特性を決定するためのプログラムコードと、 少なくとも一部前記特性に基づいて前記特性を評価するプログラムコードと、 前記評価に基づいて前記少なくとも1つの利用可能なネットワーク接続を選択するプログラムコード とを含むことを特徴とするコンピュータ可読媒体。
- 20前記少なくとも1つの利用可能なネットワーク接続に関連するサービス品質データを受信するプログラムコードを更に含むことを特徴とする請求項19に記載のコンピュータ可読媒体。
- 21符号化プログラムコードが存在するコンピュータ可読媒体であって、該プログラムコードが、 新規ネットワーク接続が利用可能であるとの指示を受信するためのプログラムコードと、 前記新規ネットワーク接続に関連する少なくとも1つの第1の特性を決定するためのプログラムコードと、 既存ネットワーク接続に関連する少なくとも1つの第2の特性を決定するためのプログラムコードと、 ユーザに関連するポリシーを決定するためのプログラムコードと、 少なくとも一部前記ポリシーに基づいて前記少なくとも1つの第1の特性を評価するためのプログラムコードと、 少なくとも一部前記ポリシーに基づいて前記少なくとも1つの第2の特性を評価するためのプログラムコードと、 前記既存ネットワーク接続を切断にするためのプログラムコードと、 前記新規ネットワーク接続に接続するためのプログラムコードとを含むことを特徴とするコンピュータ可読媒体。
- 22前記新規ネットワーク接続が利用可能であることの信号通知を更に含むことを特徴とする請求項21に記載のコンピュータ可読媒体。
- 23前記既存ネットワーク接続を切断にする前に、切断中のデータをバッファするためにデータキャッシュを開くことを更に含むことを特徴とする請求項21に記載のコンピュータ可読媒体。
- 24前記新規ネットワーク接続に接続後、 前記データキャッシュからのデータの受信と、 前記データキャッシュの閉鎖 とを更に含むことを特徴とする請求項23に記載のコンピュータ可読媒体。
- 25前記データキャッシュの大きさを決定するための尺度の受信を更に含むことを特徴とする請求項23に記載のコンピュータ可読媒体。
- 26ユーザに関連するポリシーを決定するために動作可能なポリシー読取装置と、 ユーザに関連するネットワークへの接続要求を受信し、少なくとも1つの利用可能なネットワーク接続を特定し、前記少なくとも1つの利用可能なネットワーク接続の少なくとも1つの特性を決定し、少なくとも一部前記ポリシーに基づいて前記特性を評価し、前記評価に基づいて少なくとも1つの利用可能なネットワーク接続を選択する動作可能な接続マネージャ とを備えることを特徴とするシステム。
- 27前記少なくとも1つの利用可能なネットワーク接続に関連するサービス品質データを受信するために動作可能なサービス品質収集装置を更に備えることを特徴とする請求項26に記載のシステム。
- 28ユーザに関連するポリシーを決定するために動作可能なポリシー読取装置と、 新規ネットワーク接続が利用可能であるとの指示を受信し、前記新規ネットワーク接続に関連する少なくとも1つの第1の特性を決定し、既存ネットワーク接続に関連する少なくとも1つの第2の特性を決定し、少なくとも一部前記ポリシーに基づいて前記少なくとも1つの第1の特性を評価し、少なくとも一部前記ポリシーに基づいて前記少なくとも1つの第2の特性を評価し、前記既存ネットワーク接続を切断し、前記新規ネットワーク接続を接続する動作可能な接続マネージャ とを備えることを特徴とするシステム。
Independent claims28
125 paragraphs, as filed
The present invention generally relates to computer networks. In particular, the present invention relates to a system and a method for enhancing network access.
As the workforce becomes more mobile, businesses often have to provide their users with the means to remotely connect to the corporate network. Enterprises and their users have much more flexibility in choosing how to connect to enterprise networks and other resources such as the Internet. With this added flexibility, the associated complications and risks increase. Therefore, remote access is necessary, but businesses are reluctant to provide remote access to users.
Each method for remote connectivity to corporate networks creates security holes that can be exploited. A person who listens in a network, such as a wrongdoing access point, may be able to determine a user username / password combination to access the network.
Also, each connection type can be purchased from various network providers. The enterprise must adapt the billing from each provider to each user's remote network access.
In addition, each of the traditional connectivity products that connect to the corporate network provides a unique interface. And while each interface is relatively clear, users want to connect to different networks, and businesses and users have to handle multiple interfaces, which adds complexity.
<p> An embodiment of the present invention provides a system and a method for enhancing network access. One embodiment of the present invention is a step of receiving a connection request to a network associated with a user, a step of determining a policy associated with the user, a step of identifying at least one available network connection, at least one. It includes determining at least one characteristic of one available network connection, evaluating the characteristic based on at least some policies, and selecting at least one available network connection based on this evaluation. In another embodiment, a computer-readable medium (eg, random access memory, or computer disk) comprises code that performs the above method.</p><p> The embodiments for this description are not described to limit or define the invention, but provide an example to aid in its understanding. Embodiments for explanation will be described in "Best Modes for Carrying Out the Invention", wherein further description of the present invention will be given. The advantages provided by the various embodiments of the invention can be further understood by considering this specification.</p><p> These and other features, aspects, and advantages of the present invention will be better understood by reading the following "Best Modes for Carrying Out the Invention" with reference to the accompanying drawings.</p>
An embodiment of the present invention provides a system and a method for enhancing network access. There are multiple embodiments of the present invention. As an introductory part and, by way of example, an embodiment for illustration of the present invention provides a method for a client device to seamlessly switch from a first network connection to a second connection.
When the mobile client device moves from the first position to the second position, the device is instructed that a second network connection is available. The device determines a set of characteristics for the second connection, such as speed, reliability, and cost for the connection. The client device then evaluates these characteristics based on a set of policies, which are specified by the company to which the user belongs, so that the user connects to the "best" network at any given time from the company's point of view. Will be done. The rules engine automatically determines the best of the two connections based on the connection's policies and characteristics.
For example, the second connection can be faster and cheaper than the first. However, the first connection is more reliable. Corporate policy emphasizes speed and expense over reliability. Therefore, the client device automatically switches from the first connection to the second connection without user intervention.
This introduction is provided to introduce the reader to the general subject matter of the present application. The present invention is by no means limited to such subject matter. Embodiments for explanation are described below.
(System Configuration) Various systems according to the present invention can be constructed. Next, referring to a drawing in which the same number indicates the same element throughout several drawings, FIG. 1 is a block diagram showing an environment for explaining an implementation of one embodiment of the present invention. The system shown in Figure 1 includes the client 102. The client communicates with the security server 104.
Communication with the security server 104 occurs over network 108. Network 108 can include public or private networks and can include the Internet. The network can also include a plurality of networks, including, for example, dedicated telephone lines between various components. In one embodiment, the client 102 communicates with the security server 104 via a virtual private network (VPN) established over the Internet.
The security server 104 also communicates with the corporate server 106 over the network. The network 108 can include various elements, both wired and wireless. In one embodiment, communication between the security server 104 and the corporate server 106 occurs via a static VPN established via a leased line.
In one embodiment, the user uses a network access user interface to connect the client device 102 to the network 108. The network access user interface is always in operation and only allows users to connect to network 108 through the interface. The network access user interface causes the client 102 to automatically connect to the security server 104 over network 108. Security server 104 provides value-added services to client 102 and one or more enterprises. Access to other services, such as the Internet, can be provided via security server 104.
Although FIG. 1 includes only a single client 102, a security server 104, and a corporate server 106, embodiments of the present invention typically include a plurality of clients 102, including a plurality of security servers 104 and a corporate server 106. Can be done.
2 to 4 are block diagrams illustrating components in the client 102, the security server 104, and the corporate server 106. Each of the components presented can be a third party application, a custom application, or a combination of both. Each of the components can also be implemented in hardware, software, or a combination of hardware and software.
(Client device) FIG. 2 is a block diagram illustrating a module existing in the client device 102 according to the embodiment of the present invention. Examples of client device 102 are personal computers, digital assistants, personal digital assistants, cellular phones, mobile phones, smart phones, pagers, digital tablets, laptop computers, internet devices, and other processor-based devices. In general, the client device 102 is any suitable type of processor-based platform that connects to network 108 and interacts with one or more application programs. The client device 102 can include a processor coupled to a computer-readable medium such as RAM. The client device 102 can operate on any operating system such as Microsoft (Registered Commercial Code) Windows® or Linux. Client device 102 is, for example, a laptop computer that performs a network access user interface.
The module shown in Figure 2 represents the functionality of client 102. Modules can be implemented as one or more computer programs that contain one or more modules. For example, in one embodiment, the modules shown in FIG. 2 are all contained within a single network access application. Further, the functionality shown in the client 102 can be implemented in the server according to another embodiment of the present invention. Similarly, the functionality shown in FIGS. 3 and 4 as being on the server can be implemented in client 102 in some embodiments of the invention.
The client 102 shown in FIG. 2 includes the VPN client 202. The VPN client 202 allows the client 102 to connect to the corporate server 106. In one embodiment of the invention, the VPN client 202 is used to determine if the VPN client 202 is running and whether the VPN client 202 should connect to the VPN server. For example, according to an embodiment of the present invention, it is possible to determine whether or not to connect to an individual service based on whether or not the VPN client 202 can operate.
In another embodiment of the invention, the VPN client 202 is used for four purposes: (1) Managing a policy file, which is a gateway Internet Protocol (IP) address, security and authentication. Includes information such as level and hash; (2) automatic VPN connection; (3) automatic VPN disconnection; and (4) VPN status monitoring. Each of these four objectives may be affected by other modules, including, for example, Connection Manager 210.
Client 102 also includes secure storage 204. The secure storage device 204 protects the content on the client 102. In one embodiment, the secure storage 204 is responsible for storing the encrypted content on the client 102 and granting a set of permissions or access to the encrypted content based on the policy. In such an embodiment, the content creator provides secure access to the content through the viewer, grants the recipient read-only access to the content, or allows the recipient to modify the content, and the like. It is possible to allow the execution of other tasks such as transfer to the user. In another embodiment, the secure storage device 204 allows the user to create secure content and deliver it to other clients 102, the content creator decides to send some documents to the user, and the user's Full access to two people and read-only access to one of the users can be allowed.
The client 102 shown in FIG. 2 also includes a firewall 206. Firewall 206 allows port blockage through a pre-specified policy. For example, in one embodiment, an information technology (IT) manager specifies port blockage based on two areas: a safe area and a dangerous area. The IT manager specifies one of these two areas for each of the network interface devices implemented in client 102. IT managers can then set port blockage rules by area in Firewall 206.
For example, IT managers can classify "Wireless Fidelity (" Wi-Fi ") network interfaces as dangerous because" Wi-Fi "has traditionally been considered fairly unsafe. IT managers then provide secure area and network interface devices, such as those used to connect to wired local area networks (LAN) or personal handyphone systems (PHS) cellular connections. More restrictive port blockage rules can be applied to hazardous areas. The PHS standard is a TDD-TDMA-based microcellular wireless communication technology that was traditionally considered to be relatively safer than Wi-Fi connections. PHS cellular connections are also referred to as wireless wide area networks (WWAN) as opposed to dial-up connections that provide access to wide area networks (WAN). Can be done.
In various other embodiments, the firewall 206 port blocking rules can be based on daytime hours, client IP addresses, incoming IP addresses, incoming and outgoing ports, protocols, and other variables. In one embodiment, the port blocking rule is based on policy data related to individual users logging in to client 102.
In one embodiment, the firewall 206 port blocking rules include a blacklist. The blacklist allows the IT manager to prevent the application from running on the client 102. For example, an IT manager can blacklist a DVD player so that the user cannot see the DVD on the client 102. Firewall 206 sends a message to the user to inform the user that the application is unavailable.
In another embodiment, firewall 206 implements a whitelist. The whitelist is somewhat more restrictive than the blacklist above. The white list allows execution of only the specified application. For example, IT managers can only allow execution of MS Word, Excel, PowerPoint, and Outlook. Execution of other applications is not allowed. Firewall 206 can be a custom firewall or a third party firewall incorporated into an embodiment of the invention.
The embodiment shown in FIG. 2 also includes an antivirus module 208. The presented Antivirus module 208 determines the expiration of a policy file, virus dictionary, or other virus-related resource and provides client 102 with a file or data update mechanism. Antivirus module 208 can block access to various connections, applications, and other features if the policy file has expired. For example, Antivirus module 208 can prevent client 102 from connecting to a single gateway where policy files are available. In one embodiment, the antivirus module 208 comprises a third party antivirus product that is integrated with other modules in client 102.
Client 102 also includes a connection manager 210 that includes a rule processor. In one embodiment, the connection manager 210 assigns each connection a priority number, eg, 1 to 100, and selects the connection with the highest number to connect to.
The connection manager 210 can be, for example, dial-up, LAN, digital subscriber line (DSL), cable modem, Wi-Fi, wireless local area network (WLAN), PHS, and It can provide connectivity to a variety of networks, including satellites.
In one embodiment, the connection manager 210 distinguishes between public and private connections. A public connection is a connection provided by a service provider, who has a relationship with the supervisor of security server 104, who allows the security server 104 to authenticate the connection. For example, the supervisor of security server 104 can have a business agreement with a hotspot provider. To connect, the client 102 connects to the local access point and user authentication occurs automatically on the security server 104. In contrast, private connections can provide some equipment where the connection manager allows automated authentication if possible, but the authentication mechanism on all sides for the connection should be managed without the security server 104. is required.
In one embodiment, the connection manager 210 makes an available or unavailable connection to the client 102 based on a policy that exists on the client 102. Connection Manager 210 can download changes in policy data and send quality of service (QoS) and other data to Security Server 104 or Enterprise Server 106.
In one embodiment, the connection manager 210 determines the type of connection available based on the signal provided by the hardware attached to the client 102. For example, when the client 102 passes near the hotspot, the Wi-Fi card in the client 102 is sensitive to the hotspot and sends a signal to the connection manager 210. For example, a Wi-Fi card can be sensitive to a broadcast service set identifier (SSID). Once the signal crosses the threshold, the connection manager 210 signals the user of client 102 that the network is available or that it can automatically connect to the hotspot. Alternatively, the Wi-Fi card can look up the non-broadcast SSID. The connection manager 210 can provide one connection to client 102 at a time, or can provide multiple connections to client 102.
The client 102 shown in FIG. 2 also includes a QoS collector 212. The QoS collector 212 collects data values including, for example, the number of transmitted / received bytes, the average transmission rate, the average signal strength in the connection, the cause of the connection termination, the connection failure, and the network identifier. In another embodiment, the QoS collector 212 collects data during the session that determines when the connection exhibits unstable performance.
In one embodiment, the QoS collector 212 collects data about connections during a session but does not send data for the session until the next session. Therefore, even if the session ends abnormally, the QoS data is still collected and successfully transmitted. In another embodiment, the QoS collector 212 transmits data only when individual types of connections, such as fast or low cost connections, are detected.
Client 102 also includes session statistics module 214. The session statistics module stores data that represents user characteristics. For example, the session statistics module 214 can store a list of applications commonly accessed by the user, how often the user is connected, typical CPU and memory utilization measures, keyboard sequences, and other user characteristics. If an individual user is greater than a threshold such as N standard deviation and deviates from expected characteristics, and the meaning of the statistics is greater than the specified amount, session statistics module 214 identifies the current user as a potentially unauthorized user. be able to.
Session statistics module 214 can also perform other tasks. For example, in one embodiment, the session statistics module 214 preloads the application based on the user's general usage pattern.
The client 102 shown in FIG. 2 also includes a policy reader 216. In one embodiment, the company policy is stored on the company server 106. For example, individual groups and users within an enterprise are identified and associated with policies such as the type of connection they can access and the user VPN profile. The user can also specify the VPN policy on the client 102. In such an environment, the policy reader 216 downloads the policy rules from the corporate server 106, accesses the local user policy, and arbitrates the contradiction between the two.
For example, an IT manager can establish a VPN profile for users to use when connecting to a Wi-Fi network. However, users may wish to create a second VPN profile to use if the first VPN becomes unavailable. Policy reader 216 loads both local and corporate VPN profiles and resolves inconsistencies between the two VPN profiles.
In one embodiment, the policy reader 216 accesses enterprise, department, and user level data. In such an environment, some of the policy rules can be stored on the lightweight directory access protocol (LDAP) server on the client 102, security server 104, or corporate server 106. In another embodiment, the policy reader 216 receives only changes to the policy data and typically does not download all of the policy data at once. The policy downloaded by the policy reader 216 can be provided to the rule processor of Connection Manager 210.
Client 102 also includes client security module 216. In one embodiment, client security module 216 implements a client asset protection process. If the client security module 216 receives a signal instructing the client asset protection process to be performed, the client security module 216 disables the devices and interfaces in the client 102, for example, and in some embodiments the client. You can encrypt the 102 hard drive to make the files stored on the drive inaccessible.
Client 102 can also include user interface 220. The user interface 220 can control the underlying operating environment or the underlying environment visible to the user. For example, in one embodiment, the user interface 220 replaces the Microsoft® Windows operating system interface from the user's point of view. In other words, users do not have access to many of the standard Windows features. Such a user interface can be implemented to limit the applications and configuration settings that the user can access. In some embodiments, such as a personal digital assistant (PDA), the user interface is not provided by the embodiments of the present invention. The standard PDA user interface is used.
The user interface 220 provides the user with an easy-to-use mechanism for accessing the network connection. In one embodiment, if the user interface 220 is visible, the user interface 220 provides a very easy-to-use format, which displays the network connection type and provides other functionality to the user. During complex operations, such as connecting to a new network type, the user can easily select a single button in user interface 220, and client 102 accurately disconnects the old network and disconnects the new network. It then enforces all authentication and policy-based requirements, then allows the user to continue using the application on the new network. This simple, hidden complexity, and fully automated, easy-to-use user interface 220 allows less technical users to successfully run the client 102. All network connections, authentication, secure signatures, VPN parameters, and other aspects of the connection are managed by user interface 220.
The client 102 shown in FIG. 2 also includes a security agent 222. In some embodiments, the security agent 222 is also referred to as a "bomb." In one embodiment, the IT manager directs that the security agent 222 should be started the next time the client 102 connects to the enterprise server 106. IT managers can do so because client 102 receives reports of being stolen. The client 102 then connects to the enterprise server 106 either directly or indirectly and receives a message that initiates the security agent 222.
In one embodiment, when the security agent 222 is running, the security agent 222 stops all applications from running and encrypts the data on the hard drive of the client 102. For example, security agent 222 can implement a whitelist as described above, and then implement a secure storage device for all data on client 102. The connection manager 210 can also be configured so that connections are not possible.
In one such embodiment, the data is simply encrypted by the security agent 222 rather than being erased, so that the data can be recovered if the client 102 subsequently recovers. For example, a company can hold the key needed to decrypt a local drive. Client 102 returns to the enterprise, which then decrypts the drive. In another embodiment, the data on the client's local drive is made inaccessible, for example by overwriting the data multiple times.
The client 102 shown in FIG. 2 also includes an out-of-band communication receiver 224. The out-of-band communication receiver 224 allows the client to receive other communications rather than making a network-based connection. The connection manager 210 can manage out-of-band communication. For example, the instruction to activate the security agent 222 can be transmitted via the short messaging service (SMS) received by the out-of-band communication receiver 224.
(Security Server) FIG. 3 is a block diagram illustrating a module existing in the security server 104 according to the embodiment of the present invention. The security server 104 shown in FIG. 3 includes a remote authentication dial-in user service (RADIUS) server 302, which is AAA (authentication, authorization, and accounting). Accounting) It can also be called a server. RADIUS is a standard that allows applications and devices to communicate with AAA servers.
The RADIUS server 302 provides the authentication service on the security server 104. In some embodiments of the invention, the RADIUS server 302 represents the RADIUS server in the corporate server 106. In one embodiment, the RADIUS server 302 uses Extensible Authentication Protocol Transport Layer Security (EAP-TLS) to provide mutual authentication for the client 102. Although EAP-TLS itself is strictly an 802.1x authentication protocol designed primarily for Wi-Fi connectivity, the underlying TLS authentication protocol can be deployed in both wired and wireless networks. EAP-TLS is a mutual secure sockets layer (secured sockets) Authenticate layer, "SSL"). This requires both client device 102 and RADIUS server 302 to own the certificate. Mutual authentication allows each side to use its certificate and its private key to prove its identity to others.
The security server shown in FIG. 3 also includes an LDAP server 304. LDAP Server 304 uses the LDAP protocol, which provides a mechanism for locating users, organizations, and other resources in the network. In one embodiment of the invention, the LDAP server 304 provides network access control to various components that corporate customers may or may not purchase. For example, as described in connection with FIG. 1, the customer can choose to implement a secure storage device. In such cases, the customer or user or group associated with the customer is also associated with the firewall module. Using LDAP input, then determine that the firewall is operational on the client.
In some embodiments, the LDAP server 304 is implemented as a list of user identifiers that do not use the LDAP protocol. In another embodiment, the data in LDAP server 304 propagates from the data present in enterprise server 106.
The security server 104 shown in FIG. 3 also includes a session manager 306. Session manager 306 controls sessions, including sessions between client 102 and corporate server 106. In some embodiments, the session manager 306 also determines how to route the data request. For example, session manager 306 can determine that a particular data request should be routed to the Internet rather than corporate server 106. This can be called "splitting the pipe", and "splitting the pipe" on the client device (the traditional configuration option with most standard VPN clients) is addressed to the enterprise on the security server. It provides a mechanism to replace unthinkable traffic with a safer split, allowing monitoring of all traffic without including companies that incur the extra bandwidth costs required.
In some embodiments, the client 102 and the corporate server 106 establish a VPN for communication. In such an embodiment, session manager 306 may not be able to route the request to a location other than the enterprise-packets are encrypted and therefore cannot be evaluated independently.
In one embodiment, the session manager 306 performs automated authentication of the client device 102 or the user. For example, if session manager 306 determines that client 102 is approaching a Wi-Fi hotspot, session manager 306 may pre-occupy the hotspot with a certificate that the hotspot needs to authenticate the user. it can. In this way, authentication is issued to the user very quickly. Session manager 306 can also control how the queue is queued for downloading data to client device 102.
In one such embodiment, session manager 306 provides two modes for the data queue. In the first mode, the session manager 306 determines that the network downtime is short, eg, the user is moving through a tunnel that interferes with network access. In such cases, the session manager queues the smallest amount of data. In the second mode, Session Manager 306 determines that the network downtime is relatively long-lasting, for example, the user is on a plane from New York to Tokyo. In such cases, Session Manager 306 queues a relatively large amount of data. In one such embodiment, the session manager 306 determines the mode by queuing the user during downtime. When the user reconnects to the security server 104, Session Manager 306 determines the best way to download the queue data and initiates the download.
In one embodiment, the session manager 306 includes a packet forming device (not shown). The packet former provides session manager 306 with various functional capabilities. For example, in one embodiment, the packet forming apparatus provides a prioritization mechanism for packets transmitted between the corporate server 106 and the client 102. In one embodiment, the packet forming apparatus utilizes Multiprotocol Label Switching (MPLS). MPLS allows you to specify a particular route for a given sequence of packets. MPLS allows most packets to be forwarded at the exchange (Layer 2) level rather than at the (Routing) Layer 3 level. MPLS provides a means of providing QoS for data transmission, especially when the network initiates the transport of more changing traffic.
Session manager 306 can also provide session sustainability. For example, in one embodiment, if the user suspends the connection or moves from one provider's network service area to another, the first connection is terminated and the second connection is initiated, the connection manager 306 is virtual. Sustain the session.
Session manager 306 can include a server-side rules engine. The server-side rules engine can use historical information, such as the session statistics described above, to determine statistical attacks. For example, session manager 306 has access to stored statistics about client device 102 and determines that an unauthorized user is using client device 102 based on monitoring the current statistics for client device 102. be able to.
The security server 104 shown in FIG. 3 also includes a real-time monitor 308. The real-time monitor 308 monitors communication status such as logged-on clients and users, amount of data transmitted, QoS measurements in progress, ports in use, and other information.
If the real-time monitor 308 detects a problem, it can alert network support. In one embodiment, the data from the real-time monitor 308 is provided to the user via the portal available on the security server 308. In another embodiment, the real-time monitor 308 transmits information to the corporate server 106, where the user accesses the data.
The embodiment shown in FIG. 3 also includes a history monitor 310. The history monitor 310 provides information similar to the real-time monitor 310. However, the underlying data is effectively history-related. For example, in one embodiment, the history monitor 310 makes intellectual business decisions and provides audit information for dealing with regulatory compliance issues.
Information available through the history monitor 310 includes, for example, historical QoS data, registration compliance data, and metric matching data. The historical data monitor 310 can be used to determine that a client is not working optimally by comparing the weigh-in of various clients over time. By assessing the information available, for example, through the historical data monitor 310, support personnel may be able to determine the failure of the wireless tuner of a particular client device 102. If a user of one client device 102 complains about the availability of a service, but another user has successful access to the service, then the radio of the client device can be a problem.
The historical data monitor 310 can also be used to reconcile the information obtained on the security server 104 with respect to the connection and the data provided by the telecommunications carrier. The data can be used to determine when a resource needs to be increased and when a carrier is not working properly.
The security server also includes database 312. In embodiments of the invention, the database 312 can be any type of database, including, for example, MySQL, Oracle, or Microsoft SQL. Also, although database 312 is shown as a single database in Figure 2, database 312 actually contains multiple databases, multiple schemas in one or more databases, and multiple tables in one or more schemas. be able to. The database 312 can also exist on one or more other machines, such as a database server.
In one embodiment of the invention, the database 312 is serviced by a security server 104 such as a valid user list, a valid cellular card list, relationships between individual users and groups within the enterprise, and other customer information. Store customer information about the company.
For example, in one embodiment, database 312 stores the association between the user and the cellular data card. Companies can assign one user to a particular data card. Alternatively, the enterprise can associate a user group with a cellular data card group. Other types of data, such as billing data, can also be stored in database 312.
The security server 104 shown in FIG. 3 also includes a QoS server 314. The QoS server 314 uploads information from the QoS collection device 212 in the client device 102 and stores the QoS data. QoS server 314 can collect data from multiple clients and store the data in database 312.
The security server also includes a QoS tool engine 316. The QoS tool engine 316 displays the data made available by other processes such as the QoS server 314 and the real-time monitor 308.
In one embodiment, the QoS tool engine 316 provides a collection of QoS data in a spreadsheet. In another embodiment, the QoS tool engine 316 provides data using map landscapes, pie charts, and graphs. The QoS tool engine 316 can also provide capabilities for QoS-based alarm configuration and can provide data to users via the portal.
In the embodiment shown in FIG. 3, security server 104 also includes portal server 318. The portal server 318 can be, for example, a web server. You can use Microsoft® Internet Information Server (IIS) or any standard web server application, including Apache.
Although the security server 104 shown in FIGS. 1 and 3 is illustrated as a single server, the security server 104 can include multiple servers. For example, in one embodiment of the invention, the security server 104 includes a plurality of regional servers.
The above description also suggests that the data is provided to the security server 104 and is queried by the client 102 from the security server 104, that is, the client retrieves the data. On the other hand, in some embodiments, the client 102 also includes a listening device (not shown), so that the security server 104 can output data to the client 102.
(Corporate Server) FIG. 4 is a block diagram illustrating a module existing in the corporate server 106 according to the embodiment of the present invention. The enterprise server 106 may also be referred to herein as a customer server and may include one or more servers for one or more enterprises connected to one or more security servers 104.
The corporate server 106 shown in FIG. 4 includes the policy server 402. Policy server 402 includes connection rules, such as available VPN profiles, available transmission mechanisms (eg Wi-Fi, LAN, PHS, dial-up), firewall rules, blacklists and whitelists, and antivirus rules. Provides a means to manage policy rules. Policy server 402 can also include other rules, such as the level of data regulation to be performed on each client or group of clients. Data adjustment can limit the data transmission rate to individual clients 102 and optimize connection resources.
Policies can be managed at one or more levels. For example, IT managers can want enterprises to create VPN profiles as a whole, but technology groups to create different VPN profiles because technology groups require access to a variety of unique applications. Is.
The policy server 402 can also provide a mechanism for positioning various servers used by the client 102. For example, policy server 402 can allow the IT manager to specify the IP address of acceleration server 404 or storage server 406.
In one embodiment, the policy server also allows the IT manager to specify a user to receive updates for various components on the client 102. Policy server 402 can also allow the IT manager to perform the connection configuration. For example, an IT manager can use a policy server to specify a phone number for a PHS connection, a Wi-Fi SSID phone number for a private connection, and other connection configuration information.
The corporate server 106 shown in FIG. 4 also includes an acceleration server 404. Acceleration server 404 performs a process that improves the performance of data transmission. For example, the acceleration server 404 can automatically compress the image transmitted to the client 102.
In one embodiment, the acceleration server 404 communicates with the policy server 402. The IT manager uses policy server 402 to set acceleration rules, and acceleration server 404 uses these rules to determine the acceleration level to use for individual communications. In one embodiment, the IT manager sets an unspecified acceleration level for all communications and a specific acceleration level for a group of users. A specific level of acceleration can be called priority acceleration.
The enterprise server 106 also includes a storage server 406. The storage server contains two components, an automatic component and a supervisory component. In one embodiment, the automatic component incorporates a corporate mail server (not shown) to perform actions related to email entering and exiting the mail server. For example, storage server 406 quarantines email, automatically encrypts and then sends the email, adds legal denial to the email, or performs other functions related to the email.
In one embodiment, the automatic component of storage server 406 searches for email based on terminology or based on the domain or specific address of the email's destination or origin. This information can be used by the user to perform e-mail related functions such as those mentioned above.
The supervisory component of storage server 406 allows a user to terminate access to secure content by either a specific user or all users. The supervisory component also fills in the action. Using one embodiment of storage server 406, the user can indicate that the end-employed set of users can no longer access any secure content. In an alternative embodiment of storage server 406, the user states that secure content, eg, a given element of the price list, is now expired, so that a portion of the secure content can no longer be viewed by any user. Can be shown. When each user accesses secure content, storage server 406 notes the event. Therefore, for each secure content element, storage server 406 creates a record of all actions related to the secure content.
In one embodiment, the storage server 406 also compresses the data. For example, in one embodiment, standard PKZIP compression is used to compress all content. In another embodiment, the IT manager can identify three types of images and specify different levels of compression for each type of image based on the required resolution level for each type of image.
Enterprise server 108 also includes RADIUS server 408 and LDAP server 410, which are similar to the above servers associated with security server 104. The RADIUS server 302 in the security server 104 can represent the RADIUS server 408 in the corporate server 106. Similarly, the data in the LDAP server 410 can be propagated to the LDAP server 204 in the security server 104.
Enterprise server 106 also includes a one-time password (OTP) server 412. The OTP server 412 provides a mechanism for authentication. For example, in one embodiment of the invention, the enterprise server 106 uses the OTP server 412 to perform a mutual authentication process.
The corporate server 106 also includes a concentrator 414. Concentrator 414 provides remote access capability to client 102. For example, the concentrator 414 can serve as a means of terminating the VPN between the client 102 and the corporate server 106.
The corporate server 104 shown in FIG. 4 also includes a portal server 416. Portal server 416 can include a standard web server such as IIS or Apache. Portal server 416 may provide one or more portals. For example, in one embodiment, portal server 416 provides two portals, portal 1 and portal 2.
Portal 1 provides a configuration interface for managing the various elements shown in FIGS. 2 and 3, including, for example, Policy Server 402 and LDAP Server 410. Portal 2 provides an interface for accessing data such as QoS data and session data.
For example, users can use historical QoS data in Portal 2 to determine the performance status of individual providers for throughput, user connectivity, and other QoS metrics. Portal 2 can also provide real-time information such as the number of currently connected users.
For example, in one embodiment, the IT manager determines that 20 users have been denied by the carrier in the last 3 minutes due to an authentication failure, and 5 users with the same user identifier are currently logged on to 5 different devices. To do. IT managers use this information to detect potential security issues. Portal 2 can also be used to set alerts as described above.
It should be noted that the present invention can include systems having configurations different from those shown in FIGS. 1 to 4. For example, in some systems according to the invention, the security server 104 and the enterprise server 106 can include multiple security and enterprise servers. The system 100 shown in FIGS. 1 to 4 is for illustration purposes only and is used to aid in the description of the descriptive systems and processes described below.
(Explanation of Method for Sophisticating Network Access) In the following above-described embodiment, the central policy server 402 in the corporate server 106 is used. The client device 102 downloads the policy from the policy server 402, and the connection manager 210 uses the policy to make a connection. In another embodiment, the policy file is created and distributed to the client device 102 by another method. For example, email attachments or discs can be delivered to each client device 102. Deliver new discs or emails whenever updates are needed.
In an embodiment of the invention, a policy is created and delivered to the client device 102. The client device 102 utilizes the policy to make the connection. FIG. 5 is a flowchart illustrating a process for creating a group policy according to an embodiment of the present invention.
In the embodiment shown in FIG. 5, the policy supervisor first determines policy 502. Policies include, for example, regulatory issues, the data type and / or application used, the level of control desired by the enterprise, the physical environment in which the client device or client device group operates, the experience and technical knowledge of the user group related to the policy, and It can be based on a variety of factors, such as jobs run by one or more groups related to a policy. The policy can include various elements, including, for example, an acceptable connection or application list and a non-acceptable connection or application list, accelerated preferences, and a VPN profile. The policy can also include attempting to connect with a company or user. For example, a company can decide not to use a Wi-Fi hotspot. Policies can change depending on the time of day.
The policy is a security crisis felt based on the company's need to minimize overall transmission costs, for example when billed on a usage basis, and the assumed insecurity for some transmission mechanisms and specific connections. It can be based on several factors, including the company's desire to minimize and the company's desire to guarantee the fastest and most reliable experience for its users. The policy can also be based on the parameters of the third party. For example, policies can be based on the wishes of corporate security providers to minimize transmission costs overall.
The policy supervisor then selects the group associated with policy 504. The supervisor can manually enter the group name and user identifier. Alternatively, the supervisor can select a group from a central directory such as LDAP410 or Microsoft's Active Directory server. Each policy can relate to, for example, a company, an intra-company or inter-company group, or an individual.
Once the supervisor creates the policy and associates the policy with the group, the supervisor stores the policy group concatenation 506. The policy group concatenation can be stored in a database (not shown) that communicates with the policy server 402. Alternatively, the policy group concatenation can be stored in a file, eg, in XML format.
The supervisor then delivers the policy and policy group concatenation to client device 508. For example, policy and policy group concatenation can be located in a database that communicates with policy server 402, and when a client device attempts to download a policy, it uses policy group concatenation to determine one or more policies to download. .. Policy and policy group concatenation can be distributed over a network such as Network 108 or by media such as CD-ROM. In one embodiment, only policy changes are downloaded. In other embodiments, all policies are downloaded each time a download occurs.
In some embodiments, once the policy is downloaded to the client device, the user can change the policy. For example, if the VPN associated with the VPN profile downloaded from Policy Server 402 is temporarily unavailable, the user can configure an alternative VPN profile on the client.
FIG. 6 is a flowchart illustrating a process for updating policy information regarding a client according to an embodiment of the present invention. In the presented embodiment, the policy reader 216 on the client device 102 loads the policy 602. For example, a policy can exist in an XML file, which the policy reader 216 opens and reads.
Connection Manager 210 then determines the availability of the most recently used connection and the most recently used connection 604. While the client device 102 is connected to a Wi-Fi hotspot, for example, the user may shut down the client device 102. When the user initiates the client device 102, the client device attempts to connect to the Wi-Fi hotspot.
If client device 102 cannot connect to the most recently used connection, client device 102 attempts to identify the new connection 606. For example, client device 102 may have moved out of range of the Wi-Fi hotspot to which the client was connected. Client device 102 identifies all currently available connections. Client device 102 also identifies one or more policies associated with the user. Client device 102 then identifies the characteristics of one or more network connections and compares the network characteristics with policies (rules). The network characteristic can be a quality of service measure such as security, reliability, etc., and speed can be utilized. The client device 102 can also use an expense or a combination of an expense with a plurality of other characteristics that make a decision. In one embodiment, the client device 102 applies a normalization algorithm to a plurality of characteristics to obtain a single number for each network connection. The client device 102 then compares a single number to determine which network to connect to.
The client unit connects to Policy Server (402) using either the most recently used connection or the newly identified connection 608. For example, the client device 102 connects to the most recently used Wi-Fi hotspot and then establishes a connection with the policy server 402 and the QoS server 310 over the Internet.
Once client device 102 establishes a connection to the network, client device uploads QoS data to the QoS server (310) 610. In one embodiment, QoS data from a previous session can be uploaded at the start of the current session, thus accurately tracking service interruptions such as broken connections.
The client device then downloads recent policy data from the policy server (402) 612. Policy data can only contain changes since the last connection. For example, the client device 102 can store only the last download data and download policy from the policy server 402 that has been created or modified since the last update data. The client device can also download other information. For example, the supervisor may determine that a particular client device 102 has been stolen and has set an index that causes the client device to encrypt data on its hard drive. When the client device 102 connects, the client device 102 downloads the index.
The process can be transparent to the user. In one embodiment, the download process operates as a service. Each time client device 102 begins operation, the process performs the operation. The process can also include having the client device 102 automatically connect to the VPN so that the user can access the enterprise application.
FIG. 7 is a flowchart illustrating a method for changing the network connection during data download according to an embodiment of the present invention. In one embodiment presented, the connection manager 210 receives an instruction to change the network connection 702. The instructions can be by identifying the newly available network, manually selecting by the user, or some other instruction. A hardware device, such as a cellular data card, can indicate that a new connection is available. The user receives the instructions, decides to change to the new network, clicks a button in the user interface, and indicates the desire to change.
In one embodiment, the connection manager 210 identifies a new network. The connection manager then compares the first characteristic of the currently connected (existing) network with the first characteristic of the second new network. A characteristic may mean the same or similar information about two networks, eg, the type of network. Based on the policy, Connection Manager 210 determines which network to connect to.
In one embodiment, the rules engine of the connection manager 210 is based on the six core items of data for a connection that are physically available (the correct device is implemented, operating, and signals are available). Make a connection decision.
(1) Is the connection allowed for this user, (2) How secure is the connection, (3) How reliable is the connection, (4) How fast is the connection? Items in this list: (5) How expensive a connection is for an enterprise compared to others, and (6) How expensive a connection is for a service provider, such as a network security service provider, compared to others. (1) is whether or not the connection is generally available to the enterprise, and the enterprise has made the connection available to the user (or, in some embodiments, more precisely prohibits the user from connecting). Not specified). Item (2) is based on the instructions of the company's taste. Item (2) can also be based on an automatically applied attack detection algorithm, for example, if a relatively large number of attacks are detected at a particular type of connection or a particular location, then there are relatively many attacks. It is happening.
Item (3) is based on connection statistics. In one such embodiment, the entity has options for directing the relative reliability perceptual measure. Item (4) is also based on connection statistics. Item (5) is based on the pricing plan entered by the company with the provider. Item (6) is then based on the carrier's pricing arrangements and assumptions of use for various connections.
One embodiment of the invention takes up each of these six items and uses a normalization algorithm to "weight" these elements within a range (due to their relative strength). The rules engine in client device 102 then simply selects the connection with the highest weight.
In some cases, despite rule-based analysis, the enterprise may not want to use a particular connection for a given, short time of the user. In one embodiment, the system specifically allows the enterprise to exclude short-term connections.
Prior to disconnection, Connection Manager 210 signals the session maintenance server 316 to stop any currently running data transmission 704. By stopping data transmission, Connection Manager 210 helps eliminate the possibility of data loss.
The connection manager 210 then disconnects the client device 102 from the network (108) 706. The disconnect process can vary between different networks. The session maintenance server 316 caches data during the period when the client device 102 is disconnected. It can be very short, but after some time Connection Manager 210 attempts to reconnect to the network 708. Network 108 may be the most recently used network or a newly identified network. The connection can be down for some time. In one embodiment, if disconnection occurs, the user can specify the expected disconnection time of the user. Session maintenance server 316 uses this information to determine the amount of data to cache during disconnection.
The connection manager 210 or session maintenance server 316 then decides whether to continue the download that occurred before the disconnect 710. For example, Connection Manager 210 determines that a new connection is too late to support data downloads. The connection manager 210 also looks at the policy to determine the rules that apply to the connection.
If the download should continue, Connection Manager 210 restores data transmission 712. Data transmission may then be completed or left to later disconnection. If the new network is not suitable for download support or the download is complete, the process ends 714.
For example, in one embodiment, the salesperson requires the download of a thick document containing a price list. The salesperson's computer is currently connected via a relatively slow, wide area network connection. The salesperson enters a coffee shop where the salesperson learns that he has a high-speed Wi-Fi connection.
If the client device 102 indicates that a Wi-Fi connection is available, the user indicates that the client device 102 should change the network. The client device seamlessly connects to the Wi-Fi network and starts downloading documents based on the rules established in the policy. If the user must leave the coffee shop before the download is complete, Connection Manager 210 signals the session maintenance server 316 to download until the user reenters the coffee shop or connects to another high-speed network. Can be paused.
In one embodiment, session maintenance operates in the following process. In the event of a disconnect event, the connection manager 216 buffers the application data that arrives at the client device 102 and causes the application to "believe" that the application is still connected. At the same time, the session maintenance server 216 buffers the information on the server side and causes the server 104 to "believe" that the server 104 is still connected. Once the network connection is reconnected, Connection Manager 210 and Session Maintenance Server 316 empty the buffers stacked on both sides.
In one such embodiment, the kernel mode driver is implemented at the NDIS layer in the Microsoft protocol stack (roughly equivalent to layer 3 of the OSI model). This kernel mode driver is implemented as an "intermediate driver" in the Microsoft W2K / WXP operating system. The driver operates as a single "virtual device" throughout the course of all network communications. Depending on the current physical connection, this single device routes this traffic to the appropriate physical device (where appropriate, it is addressed through a virtual device associated with a third party VPN).
To make the application layer component believe that the network is still alive and working, no "disconnect" signal is sent to the application layer component when a network interruption occurs. In this way, the application layer component handles the connection as if it were just slow.
In such an embodiment, the original interface component between the client 102 and the server 104 is that the client is disconnected for a long time, but dictates the desire to maintain the session for this extended time. In this case, the client 102 provides the user with a means of inputting the time during which the system is disconnected (eg, during domestic flight time), and the client notifies the server of the expected length of the disconnect event.
In server 104, session maintenance server 316 acts as a proxy for connections from clients to network resources. These resources are in corporate data centers or in public leases. The server implementation includes an intermediate driver configuration similar to that in the client combined with application layer components that manage caching locations and records for billing. It is possible that a company wants caching to occur in the company. In this case, the system allows the cache to be on the other side of the static tunnel to the enterprise.
(Other Embodiments) The previous description of embodiments of the present invention has been presented for purposes of illustration and illustration only and limits the invention to the exact form disclosed or exhausted. It wasn't conceived to do. Numerous modifications and applications thereof that do not deviate from the spirit and scope of the present invention will be apparent to those skilled in the art.
<figref num="1">It is a block diagram which shows the environment for demonstrating the implementation of one Embodiment of this invention.</figref><figref num="2">It is a block diagram explaining the module existing in the client apparatus 102 in one Embodiment of this invention.</figref><figref num="3">It is a block diagram explaining the module existing in the security server 104 in one Embodiment of this invention.</figref><figref num="4">It is a block diagram explaining the module existing in the enterprise server 106 in one Embodiment of this invention.</figref><figref num="5">It is a flowchart explaining the process for creating the policy of a group in one Embodiment of this invention.</figref><figref num="6">It is a flowchart explaining the process for updating the policy information about a client in one Embodiment of this invention.</figref><figref num="7">It is a flowchart explaining the method for changing a network connection during data download in one Embodiment of this invention.</figref>
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JPWO2015102055A1 | Cited by | Japan | Search report |
| US10003475B2 | Cited by | United States of America | Applicant |
| JP2016540428A | Cited by | Japan | Search report |
| JPWO2015102055A1 | Cited by | Japan | Search report |
| JP2002238067A | Cites | Japan | Examiner |
| JP2003032290A | Cites | Japan | Examiner |
| JP2003522490A | Cites | Japan | Examiner |
| WO2004008693A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| JP2004062416A | Cites | Japan | Examiner |
| JP2004126887A | Cites | Japan | Examiner |
| JP2005532759A | Cites | Japan | Examiner |
27 members in 4 offices
Priority claims24
| Document | Office | Kind | Date |
|---|---|---|---|
| 58376504 | United States of America | P | |
| 58376504 | United States of America | P | |
| 60583765 | United States of America | – | |
| 59836404 | United States of America | P | |
| 59836404 | United States of America | P | |
| 60598364 | United States of America | – | |
| 60652121 | United States of America | – | |
| 65212105 | United States of America | P | |
| 65212105 | United States of America | P | |
| 60653411 | United States of America | – | |
| 65341105 | United States of America | P | |
| 65341105 | United States of America | P | |
| 2005022982 | United States of America | W | |
| 2005022982 | United States of America | W | |
| 2004583765 | – | – | – |
| 2004598364 | – | – | – |
| 2005652121 | – | – | – |
| 2005653411 | – | – | – |
| 2005022982 | – | – | – |
| US20040583765P | – | – | – |
| US20040598364P | – | – | – |
| US20050652121P | – | – | – |
| US20050653411P | – | – | – |
| WO2005US22982 | – | – | – |
Members27
| Document | Office | Kind | |
|---|---|---|---|
| US2005289655A1 | United States of America | A1 | |
| WO2006004784A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006004785A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006004786A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006004928A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006004930A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2006023738A1 | United States of America | A1 | |
| US2006026268A1 | United States of America | A1 | |
| WO2006012044A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006012058A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006012346A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2006064588A1 | United States of America | A1 | |
| US2006072583A1 | United States of America | A1 | |
| US2006075467A1 | United States of America | A1 | |
| US2006075472A1 | United States of America | A1 | |
| US2006075506A1 | United States of America | A1 | |
| WO2006004928A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1766926A1 | European Patent Office (EPO) | A1 | |
| EP1766927A1 | European Patent Office (EPO) | A1 | |
| EP1766928A2 | European Patent Office (EPO) | A2 | |
| EP1766931A1 | European Patent Office (EPO) | A1 | |
| JP2008504630A | Japan | A | |
| JP2008504631A | Japan | A | |
| JP2008504792AThis record | Japan | A | |
| JP2008505400A | Japan | A | |
| US7725716B2 | United States of America | B2 | |
| US7760882B2 | United States of America | B2 |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2008504792
- Publication, DOCDB
- 2008504792
- Publication, EPODOC
- JP2008504792
- Application
- 2007519369
- Application, DOCDB
- 2007519369
- Application, EPODOC
- JP20070519369
Titles2
- Japanese
- ネットワークアクセス高度化のためのシステムおよび方法
- English
- Systems and methods for advanced network access
Classification
- CPC, 38
- G06F21/316
- G06F21/6227
- H04L9/3273
- H04L41/0213
- H04L41/0681
- H04L41/5009
- H04L41/5016
- H04L41/5067
- H04L41/509
- H04L43/045
- H04L43/0817
- H04L47/11
- H04L47/22
- H04L47/24
- H04L63/0227
- H04L63/0263
- H04L63/0272
- H04L63/08
- H04L63/0823
- H04L63/0869
- H04L63/102
- H04L63/1408
- H04L63/145
- H04L63/162
- H04L63/166
- H04L63/20
- H04W48/18
- H04L9/321
- H04L2209/56
- H04L2209/60
- H04L2209/805
- H04L67/30
- H04L67/14
- H04L67/04
- H04L67/02
- H04L69/329
- H04W12/088
- H04L67/61
- IPC, 4
- H04L12 56
- H04W12 08
- H04W36 14
- H04W48 18
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo