Method, apparatus, and system for maintaining persistent wireless network connection
Abstract
[Subject] The method, device, and system which enable it to maintain the permanent wireless network connection with a safe remote computing device are provided. [Means for Solution] The surveillance component can judge whether a user logs in to a network. When a user does not log in to a network, the surveillance module can search a persistent profile and can apply it to a device. A machine certificate can be used, a device can be attested to a network, and even if it is a time of a user not logging in, a device enables it to connect to a wireless network safely, when a machine certificate is related with a persistent profile. [Chosen drawing] Drawing 2
Term
Projected expiry 18 February 2031.
- Priority
- Filed
- Published
- Today
- Projected expiry
20 claims: 10 independent, 10 dependent
- 1Identifying that the user has logged off from a device attached to a wireless network, applying a persistent profile to the device, examining the persistent profile, and so on. To determine if a machine certificate is associated with, to find out, to search for the machine certificate if the persistent profile is associated with the machine certificate, and to use the machine certificate. A method comprising establishing a secure connection from the device to the wireless network. ユーザが無線ネットワークに結合された装置からログオフしたと特定すること、 前記装置に、前記ネットワークに合ったパーシステントプロファイル(persistent profile)を適用すること、 前記パーシステントプロファイルを調べることであって、それによってマシン証明書が関連付けられているか否かを判断する、調べること、 前記パーシステントプロファイルに前記マシン証明書が関連付けられている場合、該マシン証明書を検索すること、及び 前記マシン証明書を利用して前記装置から前記無線ネットワークに安全な接続を確立することを含む方法。
- 4Establishing the secure connection from the device to the wireless network using the machine certificate further comprises authenticating the device to the wireless network using the machine certificate. The method described in Item 1. 前記マシン証明書を利用して前記装置から前記無線ネットワークに前記安全な接続を確立することは、前記マシン証明書を使用して前記無線ネットワークに対して前記装置を認証することをさらに含む、請求項1に記載の方法。
- 6Applying a persistent profile to the device attached to the wireless network when the user is not logged in to the device, examining the persistent profile, thereby attaching the machine certificate to the persistent profile. Determining if it is associated, examining it, and, if the machine certificate is associated with the persistent profile, using the machine certificate to establish a secure connection to the wireless network. How to include. ユーザが装置にログインしていないときに、無線ネットワークに結合された前記装置にパーシステントプロファイルを適用すること、 前記パーシステントプロファイルを調べることであって、それによってマシン証明書が前記パーシステントプロファイルに関連付けられているか否かを判断する、調べること、及び 前記マシン証明書が前記パーシステントプロファイルに関連付けられている場合、該マシン証明書を利用して前記無線ネットワークへの安全な接続を確立することを含む方法。
- 9When executed by a machine, it identifies to the machine that the user has logged off from a device attached to the wireless network, applies the device to a persistent profile suitable for the network, and applies the persistent profile. To find out, to determine if a machine certificate is associated with it, to look up, and if the persistent profile is associated with the machine certificate, to look up the machine certificate. And a product comprising a machine-accessible medium that stores an instruction to execute from the device to establish a secure connection to the wireless network using the machine certificate. マシンにより実行されると、該マシンに、 ユーザが無線ネットワークに結合された装置からログオフしたと特定すること、 前記装置に、前記ネットワークに合ったパーシステントプロファイルを適用すること、 前記パーシステントプロファイルを調べることであって、それによってマシン証明書が関連付けられているか否かを判断する、調べること、 前記パーシステントプロファイルに前記マシン証明書が関連付けられている場合、該マシン証明書を検索すること、及び 前記マシン証明書を利用して前記装置から前記無線ネットワークに安全な接続を確立することを実行させる命令を記憶したマシンアクセス可能媒体を含む製品。
- 10When the instruction is executed by the machine, the machine is further searched for the persistent profile of the device, the persistent profile is evaluated, and whether one of the persistent profiles fits the network. 9. The device is made to apply the persistent profile suitable for the network by determining whether or not, selecting the persistent profile suitable for the network, and applying the persistent profile. Products listed in. 前記命令は前記マシンによって実行されると、該マシンにさらに、 前記装置のパーシステントプロファイルを検索すること、 前記パーシステントプロファイルを評価して、該パーシステントプロファイルのうちの1つが前記ネットワークに合うか否かを判断すること、 前記ネットワークに合った前記パーシステントプロファイルを選択すること、及び 前記パーシステントプロファイルを適用することによって前記ネットワークに合った前記パーシステントプロファイルを前記装置に適用させる、請求項9に記載の製品。
- 1328. The instruction, when executed by the machine, further causes the machine to establish an insecure connection to the wireless network if the machine certificate is not associated with the persistent profile. Product. 前記命令は前記マシンによって実行されると、該マシンにさらに、前記パーシステントプロファイルに前記マシン証明書が関連付けられていない場合、前記無線ネットワークに安全ではない接続を確立させる、請求項9に記載の製品。
- 14When run by a machine, applying the persistent profile to the device attached to the wireless network when the user is not logged in to the device, examining the persistent profile, machine certificate To determine if is associated with the persistent profile, and if the machine certificate is associated with the persistent profile, use the machine certificate to make a secure connection to the wireless network. A product that contains a machine-accessible medium that stores instructions to perform an establishment. マシンにより実行されると、該マシンに、 ユーザが装置にログインしていないときに、無線ネットワークに結合された該装置にパーシステントプロファイルを適用すること、 前記パーシステントプロファイルを調べて、マシン証明書が該パーシステントプロファイルに関連付けられているか否かを判断すること、及び マシン証明書が前記パーシステントプロファイルに関連付けられている場合、該マシン証明書を利用して前記無線ネットワークへの安全な接続を確立することを実行させる命令を記憶したマシンアクセス可能媒体を含む製品。
- 1614. The instruction, when executed by the machine, further causes the machine to establish an insecure connection to the wireless network if the machine certificate is not associated with the persistent profile. Product. 前記命令は前記マシンにより実行されると、該マシンにさらに、前記マシン証明書が前記パーシステントプロファイルに関連付けられていない場合、前記無線ネットワークに安全ではない接続を確立させる、請求項14に記載の製品。
- 17When the monitoring component that can determine whether the user is logged on to the device connected to the wireless network, the machine certificate, and the persistent profile, and the persistent profile matches the wireless network. , The monitoring component can select the persistent profile, and the monitoring component further applies the persistent profile to the device, examines the persistent profile, and machine-certifies the persistent profile to the persistent profile. A system with a persistent profile that can determine if a document is associated. ユーザが無線ネットワークに結合された装置にログオンしているか否かを判断可能な監視構成要素と、 マシン証明書と、 パーシステントプロファイルであって、該パーシステントプロファイルが前記無線ネットワークに合っている場合、前記監視構成要素は該パーシステントプロファイルを選択することができ、前記監視構成要素はさらに、該パーシステントプロファイルを前記装置に適用し、該パーシステントプロファイルを調べて、該パーシステントプロファイルにマシン証明書が関連付けられているか否かを判断することができる、パーシステントプロファイルとを備えるシステム。
- 1817. The monitoring component further comprises claim 17, wherein if a machine certificate is associated with the persistent profile, the machine certificate can be used to establish a secure connection to the wireless network. system. 前記監視構成要素はさらに、前記パーシステントプロファイルにマシン証明書が関連付けられている場合、該マシン証明書を利用して前記無線ネットワークに安全な接続を確立することができる、請求項17に記載のシステム。
Independent claims10
14 paragraphs, as filed
Computing devices connected over a wired network typically maintain a persistent connection to the network via a physical connector (eg, an Ethernet cable). This physical connection ensures that the device can maintain a network connection even when the user is not logged on to the device. This persistent connection can provide various advantages. For example, in a corporate environment, a wired network computing device can maintain a persistent network connection so that an information technology (IT) administrator can access the device regardless of whether the user is logged on or not. Can be done. This ability can prove useful and / or useful when an IT administrator needs to "push" a patch onto a device when the user is not logged on or physically does not exist. it can.
However, in the case of wireless networks, computing devices are currently unable to maintain a secure persistent wireless network connection if the user is not logged on to the device. Under certain circumstances, the device can be connected to the wireless network through a "persistent profile" when the user is logged out of the device, but this connection usually involves insecure connections. Profiles are known to those of skill in the art and typically include various computing environments and / or user's stored settings and other such customized information. A persistent profile is a profile created for situations where a user cannot log on to a device.
In summary, if the wireless device is not currently near a wireless access point (WAP) and the user is not logged on to the device, the device will not be able to maintain a secure connection to the wireless network. Without a secure connection, IT administrators cannot securely access the device and push patches, or perform any other administrative work that typically requires a secure connection.
By way of example, but not limiting, the invention is shown in the accompanying drawings where similar references show similar elements.
Embodiments of the present invention provide methods, devices, and systems for maintaining a secure, permanent wireless connection. In particular, embodiments of the present invention utilize machine-based certificates to maintain a secure persistent wireless network connection when the user is not logged on to the device. As used herein, the term "when the user is not logged on" includes situations where the computing device has just started and the user has not yet logged on, as well as situations where the user has just logged off the device. .. Whenever the term "one embodiment" or "embodiment" of the present invention is used herein, a particular feature, structure, or property described in connection with that embodiment is at least one embodiment of the invention. Means to be included in. Therefore, the appearance of terms such as "in one embodiment" and "according to one embodiment" found in various places throughout the present specification does not necessarily refer to the same embodiment.
As mentioned above, wireless computing devices are typically unable to maintain a secure persistent wireless network connection when the user is not logged on. At best, the device can only establish an insecure connection to the wireless network by using the persistent profile. The "secure" connections used herein include certificate-based connections, and "insecure" connections have a lower level of security than any unsecured and / or certificate-based connections (eg, users). Can point to a connection that has a name / password). Certificate-based security is known to those of skill in the art and will be discussed further below. As shown in FIG. 1, when the device "(radio device 150") is near the wireless network ("network 100"), the device user ("user 125") can log in to the network. The user 125 can have a user certificate associated with each, and the wireless device 150 can have a machine certificate associated with itself. Normally, when the user 125 logs on to the wireless device 150 and the wireless device 150 is recognized by the network 100, the network 100 can authenticate the user by using the user certificate. If desired, the network 100 can also use the machine certificate to authenticate the wireless device 150. It is known to those skilled in the art to authenticate users and devices on a network using user and machine certificates, and further herein so as not to unnecessarily obscure embodiments of the present invention. I will omit the explanation of. The user and / or device remain securely connected to network 100 while the user is logged on to wireless device 150. If the user then logs out of network 100, wireless device 150 loses a secure connection to network 100. The radio 150 can then apply a persistent profile to establish an insecure connection to network 100 (configured to do so). If so). Alternatively, if not configured to do so, the radio 150 would not be able to establish any connection to network 100 at all.
According to one embodiment of the present invention, the wireless device is a case where the user is not logged on to the device and / or is not recognized by the network (hereinafter collectively referred to as "logged on to the system"). Can also be securely connected to a wireless network. Embodiments of the present invention utilize the machine certificate associated with the device described above to provide the required level of security for the device so that the device can securely connect to the wireless network when the user is not logged on to the system. To be able to establish and maintain. As conceptually shown in FIG. 2, the radio device 250 can include a monitoring component 200 that includes hardware, software, firmware, and / or any combination thereof. In one embodiment, the monitoring component 200 can receive notification that user 125 has logged off the system (eg, from the operating system via an operating system event). If the monitoring component 200 determines that the wireless device 250 is not connected to the network 100 (for example, the user 125 is not logged on to the system), the monitoring component 200 selects various profiles of the wireless device 250 (collectively, "profile 205"). You can look it up. Profile 205 can include all profiles on radio device 250, including one or more persistent profiles for use when the user is not logged on to the device. In particular, the monitoring component 200 examines the various profiles on the radio device 250, identifies the persistent profiles available on the radio device 250, and then selects the persistent profile based on criteria suitable for the current network 100. Can be applied.
According to one embodiment of the invention, a machine certificate can be associated with at least one of the persistent profiles on the radio device 250 (in FIG. 2, "machine certificate 215" is associated with the "machine certificate 215". Persistent profile 210 "). By associating a machine certificate with a profile, one embodiment of the invention allows the wireless device 250 to securely connect to network 100 when the user is not logged on to the system. Therefore, in the above scenario where the monitoring component 200 determines that the user 125 is not logged on to the system, one of the persistent profiles in the profile 205 can be selected and applied to the radio device 250. In one embodiment, the monitoring component 200 can then examine the applied persistent profile to determine if a machine certificate is associated. As mentioned above, the persistent profile 210 is an example of a persistent profile with which the machine certificate 215 is associated. Therefore, if the persistent profile 210 is selected and applied, the monitoring component 200 can then examine the persistent profile to determine if a machine certificate is associated with it. If the persistent profile 210 is found to have a machine certificate 215 associated with it, the monitoring component 200 finds and uses the machine certificate 215 to authenticate the radio device 250 on network 100. This authentication allows the wireless device 250 to establish a secure connection to the network. When the user 125 logs in to the system, the monitoring component 250 is aware of this event and can disable the persistent profile 210 so that the radio 250 does the traditional method (eg, authenticating the user 125). Allows you to establish a secure connection to the wireless network 100 through.
FIG. 3 is a flow chart showing how a typical radio can now function as well as according to one embodiment of the invention. The following operations can be described as a series of processes, but many of the operations can actually be performed in parallel and / or simultaneously. Moreover, the order of actions can be rearranged without departing from the spirit of the embodiments of the present invention. Operations 301 to 307 describe a scenario in which a wireless device can now be connected to a wireless network and can be authenticated by the wireless network. At 301, the monitoring component can determine if the user is logged on to the system. When the user is logged on, in 302, the user's profile list can be searched, and in 303, one of the profiles can be selected and applied. At 304, the monitoring component can examine the applied profile to determine if the profile has an associated user certificate. If so, at 305, the user certificate can be used to authenticate the user on the network, and then at 307, the user can be authenticated against the wireless network with a secure connection. However, if the profile does not have a user certificate, in 306 the monitoring component can determine that certificate-based security is not possible on the network, and in 308 without a certificate, i.e. secure. Users can be authenticated without a connection.
Embodiments of the present invention will be described in Operations 309 to 313. According to one embodiment, if the monitoring component determines at 301 that the user is not logged on to the system, the monitoring module searches the persistent profile list from the device at 309 and the appropriate persistent at 310. Profiles can be selected and applied. At 311 the monitoring module can then determine if there is a machine certificate associated with the persistent profile. In some cases, the machine certificate can be used in 312 and the device can be authenticated against the network in 313, thus establishing a secure connection to the network. However, if the persistent profile does not have a machine certificate, at 306 the monitoring component can determine that certificate-based security is not possible on the network, and at 308 the device is not certificated. Can be authenticated with (ie, without a secure connection).
Embodiments of the present invention can be implemented in various computing devices. According to one embodiment of the present invention, a computing device can include various components capable of executing instructions to realize one embodiment of the present invention. For example, a computing device comprises at least one machine-accessible medium and / or can be coupled to at least one machine-accessible medium. As used herein, "machine" includes, but is not limited to, any computing device having one or more processors. Machine-accessible media as used herein include any mechanism for storing and / or transmitting information in any form accessible by a computing device, and is recordable / non-recordable medium (read-only memory). (ROM), Random Access Memory (RAM), Magnetic Disk Storage Medium, Optical Storage Medium, and Flash Memory Devices) and Electrical, Optical, Acoustic, or Other Forms of Propagation Signals (Carriers, Infrared Signals, and Digital) (Signals, etc.), but not limited to these.
According to one embodiment, the computing device may include a variety of other known components, such as one or more processors. The processor (s) and machine-accessible media can be communicably coupled using a bridge / memory controller, and the processor may be able to execute instructions stored on the machine-accessible media. .. The bridge / memory controller can be coupled to the graphics controller, which can control the display data output on the display device. The bridge / memory controller can be coupled to one or more buses. One or more of these elements may be integrated with the processor in a single package, or multiple packages or dies may be used. A host bus controller such as a universal serial bus (USB) host controller can be coupled to the bus (s), and multiple devices can be coupled to the USB. For example, a user input device such as a keyboard and a mouse can be included in the computing device to provide input data. In an alternative embodiment, the host bus controller may comply with PCI, PCI Express, Firewire, and various other interconnect standards, including other such current and future standards.
In the above specification, the present invention has been described with reference to specific exemplary embodiments of the present invention. However, it will be appreciated that various modifications and variations can be made without departing from the broad spirit and scope of the invention set forth in the appended claims. Therefore, the specification and drawings should be regarded as an example, not as a limitation.
<figref num="1">A device of a typical wireless network is shown.</figref><figref num="2">An embodiment of the present invention is shown.</figref><figref num="3">It is a flowchart which shows how a typical wireless device can function now and by one embodiment of the present invention.</figref>
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2000231331A | Cites | Japan | Search report |
| JP2003532185A | Cites | Japan | Search report |
| JP2004260447A | Cites | Japan | Search report |
| JPH0974408A | Cites | Japan | Search report |
15 members in 8 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10956980 | United States of America | – | |
| 95698004 | United States of America | A | |
| 95698004 | United States of America | A | |
| 2004956980 | – | – | – |
| US20040956980 | – | – | – |
Members15
| Document | Office | Kind | |
|---|---|---|---|
| US2006068757A1 | United States of America | A1 | |
| WO2006039178A1 | World Intellectual Property Organization (WIPO) | A1 | |
| GB0704918D0 | United Kingdom | D0 | |
| KR20070046964A | Republic of Korea | A | |
| GB2432090A | United Kingdom | A | |
| EP1794981A1 | European Patent Office (EPO) | A1 | |
| DE112005002423T5 | Germany | T5 | |
| CN101032145A | China | A | |
| JP2008514162A | Japan | A | |
| GB2432090B | United Kingdom | B | |
| KR100920497B1 | Republic of Korea | B1 | |
| JP2011146054AThis record | Japan | A | |
| DE112005002423B4 | Germany | B4 | |
| JP5149623B2 | Japan | B2 | |
| JP5289481B2 | Japan | B2 |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Report on retrievalA977 | A977 |
Numbers
- Publication
- 2011146054
- Publication, DOCDB
- 2011146054
- Publication, EPODOC
- JP2011146054
- Application
- 33518
- Application, DOCDB
- 2011033518
- Application, EPODOC
- JP20110033518
Titles2
- Japanese
- 永続無線ネットワーク接続を維持する方法、装置、及びシステム
- English
- How to maintain a lasting wireless network connection, equipment, and systems
Classification
- CPC, 4
- H04L41/28
- H04L63/0428
- H04L63/0823
- H04L63/102
- IPC, 4
- G06F21 20
- G06F21 00
- G06F21 33
- H04W8 24