System and method for provisioning universal stateless digital and computing services
29 claims: 18 independent, 11 dependent
- 1通信網を介してデジタル・サービスに遠隔アクセスすることを可能にするために、 ユーザによってデジタル・サービスを要求し、前記デジタル・サービスからの出力を前記ユーザに提示するために前記通信網に接続された複数のクライアント装置と 、 前記クライアント装置により前記ユーザに対して表示されるコンテンツを生成し、前記ユーザにより前記クライアント装置に入力されたコマンドを受信する前記デジタル・サービスを提供するための複数のサービス・センターと 、 前記複数のサービス・センターにより提供されるデジタル・サービスに対する要求を受信するために前記通信網に接続され、前記クライアント装置および/またはデジタル・サービスを要求したユーザを認証するように構成され、前記クライアント装置および/またはユーザが認証された後に前記デジタル・サービスを提供するように構成されたサービス・センターに通知すると共に、前記通信網における前記クライアント装置のネットワークアドレスを前記サービス・センターに提供するネットワーク・オペレーション・センターと 、 を備え、 前記複数のサービス・センターのそれぞれは、前記ネットワーク・オペレーション・センターにより当該サービス・センターに提供されたネットワークアドレスにおいて、当該サービス・センターから認証されたクライアント装置へのネットワーク接続を確立するための少なくとも一つのコネクターを含み、当該少なくとも一つのコネクターは、前記デジタル・サービスに対する遠隔アクセスを提供するために、前記確立されたネットワーク接続を介して、前記デジタル・サービスにより生成されたコンテンツを前記認証されたクライアント装置に転送し、当該クライアント装置からのコマンドを前記サービス・センターに転送するように適合されているサービス提供システム。
- 2前記デジタル・サービスは、それぞれのネイティブプロトコル中にコンテンツを生成し、 前記少なくとも一つのコネクターは、前記デジタル・サービスのうちの要求されたものの前記ネイティブプロトコルを遠隔の対話型プロトコルに翻訳し、 前記遠隔の対話型プロトコルは、前記クライアント装置において人間の知覚可能なプレゼンテーション生成用の情報を含んでおり、 人間の知覚可能なプレゼンテーション生成用の前記情報が、前記クライアント装置による表示用のスクリーンイメージ・データを含む請求項1に記載のサービス提供システム。
- 3前記デジタル・サービスは、それぞれのネイティブプロトコル中にコンテンツを生成し、 前記少なくとも一つのコネクターは、前記デジタル・サービスのうちの要求されたものの前記ネイティブプロトコルを遠隔の対話型プロトコルに翻訳し、 前記遠隔の対話型プロトコルは、前記クライアント装置において人間の知覚可能なプレゼンテーション生成用の情報を含んでおり、 人間の知覚可能なプレゼンテーション生成用の前記情報が、ビットマップ画像データを含む請求項1に記載のサービス提供システム。
- 4前記デジタル・サービスは、それぞれのネイティブプロトコル中にコンテンツを生成し、 前記少なくとも一つのコネクターは、前記デジタル・サービスのうちの要求されたものの前記ネイティブプロトコルを遠隔の対話型プロトコルに翻訳し、 前記遠隔の対話型プロトコルは、前記クライアント装置において人間の知覚可能なプレゼンテーション生成用の情報を含んでおり、 前記少なくとも1つのコネクターが、前記デジタル・サービスの前記要求されたもの から生成されたデータ を前記遠隔の対話型プロトコルに翻訳し、 対応する 前記クライアント装置に 前記 データの仮想表現を表示して、 ネイティブプロトコル中の 前記データがそれぞれのサービス・センター外へ送信されないことを保証するよう動作可能であり、これによってデジタル・サービスに対する安全な遠隔アクセスを可能にする請求項1に記載のサービス提供システム。
- 5前記ネットワーク・オペレーション・センターが、前記ユーザおよび前記クライアント装置を認証し、認証されたクライアント装置と前記ネットワーク・オペレーション・センターの間に認証接続を確立して管理する認証サービスモジュールを備える請求項1に記載のサービス提供システム。
- 6前記認証サービスモジュールが、キーを分配し、スマートカードを使用してセッションキーを生成するための、トークンにもとづくセキュリティ・システムをさらに備える請求項 5 に記載のサービス提供システム。
- 7前記ユーザおよび前記クライアント装置の認証されたものに利用可能なクライアント特有のカスタマイズされたメタデスクトップを表示するデジタル・サービスを生成し、前記クライアント装置の認証されたものから選択されたデジタル・サービスの要求を受け取るためのメタデスクトップ・サービスモジュールを 前記ネットワーク・オペレーション・センターに 備える請求項 5 に記載のサービス提供システム。
- 8前記メタデスクトップ・サービスモジュールが、前記認証されたクライアント装置のプロファイル情報にもとづいて前記特有のカスタマイズされたメタデスクトップを生成するよう動作可能である請求項 7 に記載のサービス提供システム。
- 9前記ネットワーク・オペレーション・センターが、前記選択されたデジタル・サービスに関連したサービス・センターを決定して担当サービス・センターとし、前記認証されたクライアント装置に対する前記セッションを確立するよう前記担当サービス・センターを制御する請求項 7 に記載のサービス提供システム。
- 10前記クライアント装置のそれぞれが、ディスプレイ装置、入力装置、オーディオ装置、ビデオ装置およびユニバーサル・シリアル・バス装置のうちから選ばれる周辺機器を備える請求項1に記載のサービス提供システム。
- 11前記デジタル・サービスは、それぞれのネイティブプロトコル中にコンテンツを生成し、 前記少なくとも一つのコネクターは、前記デジタル・サービスのうちの要求されたものの前記ネイティブプロトコルを遠隔の対話型プロトコルに翻訳し、 前記遠隔の対話型プロトコルは、前記クライアント装置において人間の知覚可能なプレゼンテーション生成用の情報を含んでおり、 前記クライアント装置が前記遠隔の対話型プロトコルをサポートしない不承諾クライアント装置である請求項1に記載のサービス提供システム。
- 12複数の代理装置をさらに備え、各代理装置が前記不承諾クライアント装置のうちの1つに連係し、前記不承諾装置のプロトコルを前記遠隔の対話型プロトコルに変換するよう動作可能である請求項1 1 に記載のサービス提供システム。
- 13前記通信網が所定のタイムリーな応答時間を保証する所定レベルのサービス品質保証を提供する請求項1に記載のサービス提供システム。
- 14前記ネットワーク・オペレーション・センターが、前記クライアント装置の状態にかかわらず、前記セッションを連続的に維持するよう動作可能である請求項1に記載のサービス提供システム。
- 15前記サービスが、テレビ会議、IP電話、ボイスメッセージ、デジタル音楽、デジタル映画、電子商取引およびコンピュータ・サービスのうちから選ばれるサービスを備える請求項1に記載のサービス提供システム。
- 16通信網を介してデジタル・サービスに安全に遠隔アクセスすることを可能にす る方 法 であって、 ネットワーク・オペレーション・センターにおいて、サービス・センターで利用可能なデジタル・サービスの要求をクライアント装置上のユーザから前記通信網を介して受け取るステップ と、 前記ネットワーク・オペレーション・センターによって前記ユーザおよび/または前記クライアント装置を認証するステップ と、 前記ネットワーク・オペレーション・センターにおいて、前記認証されたクライアント装置のネットワークアドレスを前記サービス・センターに提供するステップ と、 前記ユーザおよび/または前記クライアント装置が正当であるとして認証されたら、前記サービス・センターにより、セッションを確立するために前記クライアント装置とのネットワーク接続を前記ネットワーク・オペレーション・センターから提供されたネットワークアドレスにおいて確立するステップ と、 前記要求されたデジタル・サービスにより生成されたコンテンツを前記確立されたネットワーク接続上で前記クライアント装置に提供するステップ と、 を備え、 これによって、前記サービス・センター上の前記要求されたデジタル・サービスから前記クライアント装置に対する遠隔アクセスを可能にする 方法 。
- 17前記通信網上で1つ以上のデジタル・サービスを提供するために各サービス・センターをコネクターに接続し、その際前記コネクターは前記デジタル・サービスのそれぞれのネイティブプロトコルを共通の遠隔の対話型プロトコル中にカプセル化するステップと 、 前記コネクターにより、前記要求されたデジタル・サービスの入力/出力コマンドを前記遠隔の対話型プロトコルに変換し、前記正当なクライアント装置に人間の知覚可能なプレゼンテーション生成用の情報を提供するステップをさらに含む請求項16に記載の方法。
- 18前記情報を提供するステップが前記正当なクライアント装置による表示用のスクリーンイメージ・データを提供する請求項1 7 に記載の方法。
- 19前記情報を提供するステップがビットマップ画像データを提供する請求項1 7 に記載の方法。
- 20前記正当なクライアント装置にデータの仮想表現を表示するステップをさらに含み、前記 ネイティブプロトコル中の データがそれぞれのサービス・センター外へ送信されないことを保証し、これによってデジタル・サービスに対する安全な遠隔アクセスを可能にする請求項17に記載の方法。
- 21クライアント装置と前記ネットワーク・オペレーション・センターの間に認証接続を確立して管理するステップをさらに含む請求項1 6 に記載の方法。
- 22トークンにもとづくセキュリティ・システムを使用してキーを分配し、スマートカードを使用してセッションキーを生成するステップをさらに含む請求項2 1 に記載の方法。
- 23前記正当なユーザおよび前記正当な装置に利用可能なデジタル・サービスを表示し、前記正当なクライアント装置から選択されたデジタル・サービスの要求を受け取るクライアント特有のカスタマイズされたメタデスクトップを生成するステップをさらに含む請求項2 1 に記載の方法。
- 24前記クライアント特有のカスタマイズされたメタデスクトップを 生成するステップ は 、前記正当なクライアント装置のプロファイル情報にもとづいて前記特有のカスタマイズされたメタデスクトップを生成するステップを含む請求項2 3 に記載の方法。
- 25前記選択されたデジタル・サービスに関連したサービス・センターを決定して担当サービス・センターとし、前記正当なクライアント装置に対する前記セッションを確立するよう前記担当サービス・センターを制御するステップをさらに含む請求項2 3 に記載の方法。
- 26代理装置によって、 前記遠隔の対話型プロトコルをサポートしない 不承諾装置のプロトコルを前記遠隔の対話型プロトコルに変換するステップをさらに含む請求項17に記載の方法。
- 27前記通信網によって、所定のタイムリーな応答時間を保証する所定レベルのサービス品質保証を提供するステップをさらに含む請求項1 6 に記載の方法。
- 28前記正当なクライアント装置の状態にかかわらず、前記セッションを連続的に維持するステップをさらに含む請求項1 6 に記載の方法。
- 29テレビ会議、IP電話、ボイスメッセージ、デジタル音楽、デジタル映画、電子商取引およびコンピュータ・サービスのうちから選ばれるサービスに安全な遠隔アクセスを提供するステップをさらに含む請求項1 6 に記載の方法。
Independent claims29
6 paragraphs, as filed
[0001] The present invention relates generally to service delivery system architectures for providing remote access to digital data and services, in particular universal stateless digital and computer services.
[0002] The configuration of corporate computer systems has evolved over the last 50 years since the introduction of software-programmable digital computers. In the first multi-user system, some users, such as corporate employees, used a "dumb terminal" connected to a mainframe computer by a communication network to use one or more centrally installed mainframe computers. Accessed processing power. Mainframe computers provided all the processing power and data storage capabilities. The dumb terminal was only used to input data to the mainframe computer and display the output data generated by the mainframe computer. That is, the dam terminal did not have the ability to process and store data locally. In essence, dam terminals were useless unless they were connected to mainframe computers by dedicated, mainframe and installation-specific communications networks. [0003] However, the high costs associated with acquiring and maintaining mainframe computers fueled the usefulness and popularity of desktop or personal computers (PCs) in the 1980s. Originally configured as a stand-alone platform, the PC is a stand-alone computing system where all processing is done locally and all applications and data are executed and stored locally. Also, the relatively low price of PCs allowed individual users and small businesses to easily acquire and use the processing power of PCs instead of relying on large, centrally installed mainframe systems. However, users could not easily share data with each other because those PCs were not part of a centralized network and did not necessarily use the same operating system. In addition, because each PC required its own local copy of the software, incompatible versions of the same software application on different PCs prevented users from communicating and sharing data with each other. [0004] Connectivity and compatibility issues with these stand-alone PCs gave rise to client / server systems. PCs (that is, clients) were connected to each other and to a common server that stored data and applications by a private communication network such as a corporate network. The server maintains common data and provides a copy of the data to the client upon request. However, because the client / server system depends on the processing power of the PC, the hardware and software components of each PC in the client / server network must be constantly synchronized and therefore upgraded. In many corporate settings, there are many PCs and they are widely distributed in various places. Depending on the age and type of PC system, hardware components such as microprocessors, random access memory (RAM), and hard disk devices can be upgraded or replaced without replacing the entire PC system. But even if PC systems can be upgraded, the cost of upgrading thousands of PC systems can be enormous. [0005] If the PC system cannot be upgraded already, the entire system must be replaced. For example, newer versions of software applications or operating systems may require hardware capabilities that cannot be met by existing PC systems. In general, PC systems are considered to be old in 3 to 5 years, requiring expensive replacement of thousands of PCs as often as every 3 years. [0006] In addition to the cost of purchasing new hardware and software, the cost of resolving software-to-hardware compatibility issues in client / server systems can be significant. For example, many software applications do not have easy upward compatibility, which puts a considerable burden on the enterprise to maintain compatible versions of the software applications on all PC systems. The administrative effort and expense of upgrading each system, providing a licensed copy of the software, installing and maintaining the software is the recurring cost of operating a client / server network within the enterprise. Is the largest part of. Even with remote management capabilities, tracking and cataloging software applications can be very tedious. [0007] Also, installing new software puts enterprise users at risk of security. The integrity and security of corporate networks can be easily breached by hackers, partially or by accidental or deliberate introduction of computer viruses, even when users install or download unauthorized and licensed software applications or files. The whole can be hindered. [0008] There is often a continuous need for individuals outside the office to access the corporate network. They will need access to files, emails, applications and programs on their "desktop" etc. ("Desktop" refers to a top-level, local graphical user interface environment customized by the user to display and access data, folders and applications.) One way is for the user. To use a laptop computer to access the corporate network for remote access to files and emails. That is, if the appropriate communication software is installed on each client laptop PC, the user can remotely access e-mail and corporate networks, dial-up telephone lines (or digital subscriber lines (DSL), T1, cables, etc.) You can send and receive files to and from network servers via a broadband connection). All application programs reside on the local client laptop PC and run locally. This approach is simple, but all such software applications need to be installed, established, and maintained on each laptop PC. Therefore, in the long run, this approach can be quite expensive, especially considering the cost of continuing to support installed software applications. [0009] Alternatively, a traditional virtual private network (VPN) is used to obtain a wide area network (WAN) connection from a remote user location to a central corporate local area network (LAN). The VPN / WAN connection can implement the second layer extension of the Open Systems Interconnection (OSI) between the LAN and the remote user location. The remote client PC connected to the LAN by VPN seems to be directly connected to the LAN. However, a VPN connection requires expensive VPN terminations (ie, client site VPN routers) or VPN client software installed and configured on the client device at each end of the connection. In either case, the VPN terminator provides second-tier packet processing and proper packet encryption / decryption capabilities. Both PC operating systems and client-based VPN software can reduce the cost of VPN terminators, but both require significant packet processing to assemble and reverse assemble packets, which is a significant process for the PC. Imposing a burden. Therefore, a separate dedicated VPM terminator is often required at the remote user location to support VPN connections with the required level of security and reliability without imposing an unreasonable processing burden on the client PC itself. Therefore, VPN devices are not only expensive, but also cumbersome to set up and expensive to manage and maintain. [0010] In all of the above cases, sensitive enterprise data is transmitted and copied between the secure enterprise network and the PC / laptop. Once the data is downloaded and physically copied, there is no access or transport security system that can prevent unauthorized distribution and misuse of the data, which occurs without the knowledge of the legitimate data owner. [0011] Yet another way to extend the office environment to a remote user location is the Citrix Corporation MetaFrame using the Independent Computing Architecture (ICA)® protocol. ) Utilizes an application service provider (ASP) model that requires the installation of specialized server software, such as (registered trademark) software, on network servers. A network server located on a LAN will function as an ASP by acting as a host for multiple virtual machines for a variety of remote client PCs. Alternatively, Microsoft's Windows Terminal Services (Windows® Terminal) using Remote Desktop Protocol (RDP). Services) (WTS) can be used to provide multiple virtual machines. However, both Metaframe® and WTS software impose a considerable processing burden on client PCs and are vulnerable to network flaws and security breaches, such as "intermediary" attacks. Moreover, the ASP-based approach, at best, provides limited remote execution capabilities. Traditional systems have been designed and developed to overcome the bandwidth limitations of previous telecommunications networks. Current technological advances have dramatically increased the bandwidth of telecommunications networks. Network bandwidth grows faster than microprocessor speeds and doubles about every nine months, reducing the value of traditional systems and technologies and making them virtually obsolete. Users from anywhere in the world, desktops, software applications, as if they were in the office, without compromising security, investing in new hardware / software infrastructure, in view of the shortcomings of traditional systems and networks. It is desirable to provide systems and methods that allow secure access to your client equipment, including e-mail, data files, etc. [0012] Efficient management of information systems has never been so difficult and essential to success. As the cost of owning desktop systems rises, businesses need ways to reduce purchases and improve costs, management and maintenance costs. However, these savings cannot result in loss of functionality or performance. Unlimited access to high-performance applications remains an important requirement for efficient management of information systems. Therefore, it is desirable to have a service delivery system architecture that can provide unlimited, native and secure remote access without modifying or modifying the existing hardware and software infrastructure.
<p>[0013] Therefore, an object of the present invention is to provide a service delivery system architecture that provides universal stateless digital and computing services and overcomes the above drawbacks. [0014] Another object of the present invention is to secure, trust, and enrich enterprise systems such as legacy enterprise data centers with no or minimal modifications to existing hardware and software infrastructure. The purpose is to provide a service provision system architecture that enables high-performance access. Corporate data centers can be equipped with connectors or connectivity service devices that provide secure remote access from anywhere in the world.</p>
<p>[0015] The systems and methods of the invention allow users of client devices, preferably stateless client devices, to access remote resources, including applications and data. Thus, users can surf the Internet and access their desktop operating systems, files and applications without the need for local copies of software or data or corresponding hardware resources. Users can also use a television-like client device to access other digital services such as digital video and music broadcasting, Internet Protocol (IF) telephones, and more. The system preferably includes an authentication system or mechanism such as a smart card. [0016] By clarifying new ways to perform digital services, the service delivery system architecture of the invention offers multiple levels of functionality, security and long-term investment protection at a significantly lower total cost than previous methods, data. Allows delivery of any digital service to remote locations without the need for a local copy of the device, any application or supporting hardware. [0017] According to one embodiment of the invention, the system of the invention simply does not compromise security and does not modify any of its functionality, operation and hardware / software infrastructure or existing networks. Run digital services from an existing network, system or data center via a single "digital dial tone" network. The service delivery system architecture of the present invention is simple and can be implemented in various forms such as desktop, portable, wireless, or incorporated into existing legacy appliances such as televisions, PDAs and PCs. Connect low-cost, low-maintenance client equipment. [0018] According to one embodiment of the invention, the service delivery system allows remote access to digital services over a communication network.<u style="single">By user</u>Request digital services and output from digital services<u style="single">To the user</u>Multiple client devices connected to the communication network for presentation<u style="single">And a plurality of service centers for providing the digital service to generate the content displayed to the user by the client device and receive the command input to the client device by the user.</u>To be equipped.<u style="single">To receive requests for digital services provided by multiple service centers</u>The network operation center connected to the communication network is the client device.<u style="single">And / or requested digital services</u>Authenticate the user and<u style="single">Notifies the client device and / or the service center configured to provide the digital service after the user is authenticated, and provides the service center with the network address of the client device in the communication network.</u>.. Each service center<u style="single">Is at least one for establishing a network connection from the service center to the authenticated client device at the network address provided to the service center by the network operations center.</u>connector<u style="single">At least one connector transfers content generated by the digital service to the authenticated client device over the established network connection to provide remote access to the digital service. It is adapted to forward commands from the client device to the service center.</u>[0019] According to one embodiment of the invention, the service delivery method provides secure remote access to digital services over a communication network. This method<u style="single">At the Network Operations Center</u>Receive requests for digital services available at the service center from users on client devices over the communication network. The Network Operations Center authenticates the user and the client device.<u style="single">The network operation center provides the service center with the network address of the authenticated client device.</u>User and client devices are legitimate<u style="single">Is</u>If authenticated as,<u style="single">By the service center</u>With the client device to start a session<u style="single">network</u>The connection is<u style="single">At the network address provided by the Network Operations Center</u>Established. The method is<u style="single">The content generated by the requested digital service is provided to the client device over the established network connection.</u>This will result in the requested digital service on the service center<u style="single">To the client device</u>Allow access. The present invention can be implemented in a network of computer systems, including a set of dedicated servers adapted by a set of software components, all configured according to the service delivery system architecture. This architecture has the ability to connect, generate, manage, and execute digital service sessions to a variety of networked client devices, and simply authenticate users with smart cards or other applicable access control technologies. This allows for "hot swapping" or "switching" of such sessions between devices. Due to the unique and novel aspect of the present invention, the user interaction with each service is independent of the type, location or connectivity of the equipment used. [0021] Various other objectives, advantages and features of the present invention will be readily apparent from the detailed description below and the appended claims.</p>
The following detailed description, given as an example and not intended to limit the invention, will be best understood in the context of the accompanying figures. [0027] The present invention is readily practiced using the communication devices and electronic components currently available. The invention is an intranet, local area network (LAN), wireless LAN (WLAN), wide area network (WAN), internet, private and public communication networks, wireless communications, satellites, cable networks or other online wide area networks, bi-points. Find applications that can be run on virtually any communication system, including, but not limited to, other networks, etc. [0028] The present invention provides a variety of computing, communications, entertainment and other digital services (here "digital") while providing enhanced security without the need for expensive conversions to new hardware / software infrastructures. It provides the basis for safe, reliable, rich and high-performance access to services). The system utilizes inexpensive, low-maintenance equipment that runs digital services over various networks around the world. The service delivery system architecture of the invention can operate to manage multiple user sessions from a variety of different client devices. The system keeps each session continuous, thereby allowing users to easily access their sessions from different locations and client devices. [0029] According to an embodiment of the present invention, as shown in FIG. 1, the service providing system architecture 100 includes one or more client devices 400, services connected to each other by a communication network such as the Internet or a wide area network (WAN) 110. -Equipped with Center 300 and Network Operations Center (NOC) 200. Service delivery system architecture 100 includes intranets, local area networks (LANs), wireless networks including wireless LANs (WLANs), wide area networks (WANs), the Internet, private or public communication networks, satellite networks, cable networks, and others. Virtually any communication system, such as an online wide area network, can be used. In view of the present invention, the service delivery system architecture 100 includes security tokens associated with each authorized user of a universal stateless digital and computing service. [0030] According to an embodiment of the present invention, WAN110 is a packet network that uses, for example, the Transmission Control Protocol / Internet Protocol (TCP / IP). Since all processing and computation is centralized at service center 300, WAN110 is at the desired level to ensure timely response time and timely delivery of data between client device 400 and service center 300. Will support quality of service (QOS). For example, the round-trip delay imposed by WAN110 should be, for example, less than 60 ms to ensure that the user does not experience unacceptable or noticeable delays. Therefore, the total time from user input to rendering the resulting text or graphical representation (ie, round-trip delay) should be less than the user's perceptual threshold (ie, about 100 milliseconds). The quality of service requirements for WAN110 characterized by round-trip delays average less than 60 ms and, in the worst case, less than l00 ms. From the user's point of view and perception, a high mean delay with a low variance is generally preferred over a low mean delay with a high variance. [0031] Depending on the current and expected architecture of wide area networks, the bandwidth requirements of WAN110 are highly asymmetric for typical computing. The remote processing and rendering aspects of the service delivery system architecture 100 of the invention typically flow downstream (ie, service) rather than upstream (ie, data flow from client device 400 to service center 300). -Data flow from the center 300 to the client device 400) is generated considerably more. In a typical application, the bandwidth requirement for upstream flow is on the order of a few kilobits per second (Kbps), and the average downstream flow is between a few hundred Kbps and a few Mbps. For example, for digital broadcasts, if the user selects a particular broadcast or channel similar to wireless broadcast television and cable television (the latter requires a single upstream transmission of less than 1 kilobyte), the flow will be: It consists mainly of broadcast video / audio information from the service center 300 to the client device 400 (ie downstream flow) at 1.554 Mbps. A remote device 430, such as a CD-ROM, video camera, scanner, printer, etc. connected to the client device 400, may increase upstream flow and impose additional bandwidth requirements on the WAN 110. However, these upstream bandwidth requirements for WAN110 can be easily measured, which tend to be constant and often isochronous. [0033] According to an embodiment of the invention, the service providing system architecture 100 of the invention utilizes an industrial standard compression scheme for transmitting audio and / or video content (eg, MPP, MP3, etc.). .. Therefore, bandwidth requirements for WAN 110 from multimedia and telephone applications can be clarified. Increased WAN performance, such as higher WAN guarantees, can reduce the need for memory and data buffers and reduce the cost of client equipment 400. For example, the approximate bandwidth requirements for various multimedia on WAN110 include: Uncompressed Analog National Television Broadcasting Standards Board (NTSC) 160 Mbps for video and audio, 2 for compressed DVD quality video: ~ 7Mbps, 384Kbps ~ 1Mbps for VCR quality video using the latest coder / decoder (codec), 1.5Mbps for raw (eg pulse width modulated (PWM) encoded) CD quality audio, and for MP3 compressed music 128Kbps. In contrast, the bandwidth requirement for simple phone-grade compressed audio is only 8Kbps. [0034] According to an embodiment of the invention, the service delivery system architecture 100 of the invention provides various public and / or proprietary remote dialogues, preferably through end-to-end encryption, to ensure user authentication and privacy. Type protocols can be used. For example, as long as the protocol provides user authentication and the user can securely connect to and disconnect from the session, the system will be Remote Desktop Protocol (RDP), Independent Computing Architecture (ICA (ICA). Protocols such as Registered Trademarks)), Hypertext Transfer Protocol (HTTP), Stateless Low Level Interface Machine (SLIM), and Instrument Link Protocol (ALP) can be used as remote interactive protocols. WAN110 should be equipped with a virtual private network (VPN) service that isolates the data flow and provides a high level of network performance. [0035] The user can use the client device 400 to access the various digital services available in the service center 300. The client device 400 can be installed in a group office, home, hotel, airplane, car, other mobile or franchised commercial space, and the like. The service delivery system architecture 100 of the present invention takes into account different client device implementations and users using different types of client devices to access the digital services provided and supported by the service center 300. I have put it in. These client device implementations are terminal emulation software from hardware-intensive solutions such as stateless devices (eg video display terminals) to standard PCs (ie stateful devices) to emulate client device 400. Can extend to software-based solutions where is installed. The client device 400 is a simple "walkman-like" personal audio playback device, to a full-featured "PC-like" that is comparable to high-end workstations in both functionality and performance. It can extend to devices. Therefore, the client device 400 is a public telephone box, a "dumb" terminal, a personal digital assistant (PDA), a laptop computer, a desktop PC, a network PC, a wireless handheld PC, a smart phone, a set-top box (STB), It may include a television receiver and the like in a non-limiting manner. [0036] According to the embodiment of the present invention, the client device 400 can be various input / output peripheral devices (for example, a display, a keyboard, a speaker, a microphone, a smart card reader, etc.) connected to the WAN 110. Client device 400 implements a remote interactive protocol (or a subset of the remote interactive protocol, a "simplified" or "mini" version of the protocol) to communicate with the NOC 200 on WAN 110 and the service center 300. Is desirable. Each client device 400 has one or more display devices (eg, full color, black and white, LCD, directly mapped frame buffer device, etc.), input devices (eg, mouse, keyboard, touch screen, scanner, card reader, buttons, etc.). ), Audio equipment (eg speakers, microphones, etc.), video equipment (eg cameras, codecs, clip / overlay regions, etc.), and storage devices (eg printers, CDs). It can consist of a clear combination of peripherals (USB devices such as ROMs, DVDs, hard disks, etc.). Specific examples and / or quantities of each class of peripherals associated with a particular client device 400 are counted at power-up and reported to NOC200 as part of the device authentication and connection setup process. In this way, the service center 300 has an input / output (I / O) interface to support the capabilities of the particular client device 400 configuration currently in use to support many different types of client device 400. Can be adapted. For example, in the case of bus-connected peripherals such as the TJSB device, a "plug" operation (ie, connect / disconnect) allows the service center 300 to take appropriate action to communicate with the client device 400. All actions) are signaled or reported to NOC200 by a remote interactive protocol. Such actions may include, for example, the appropriate rendering command to send to the client device 400. Signaling is also required because the device driver associated with the installed bus-based peripherals resides and executes on the service center 300 rather than on the client device 400. According to an embodiment of the invention, the client device 400 encapsulates or wraps the native protocol of the attached peripheral (ie, the native USB protocol) in a suitable remote interactive protocol to accommodate the attached peripheral. It transmits native commands between the service center 300, that is, the one that is currently communicating and servicing the client device 400. According to an embodiment of the invention, the remote interactive protocol overlays, or operates "on top of," an existing native protocol, whereby any device connects and communicates with the service delivery system architecture 100. Will be possible. Installed The actual measures that govern the operation of these peripherals are set by the corresponding service center 300. For example, the service center 300 in charge determines how to interact, that is, what to do with the installed peripherals and how to respond to various events such as hot plug / unplug, device-specific exceptions, and so on. .. [0037] According to an embodiment of the invention, a surrogate device 410 can be utilized to allow the disapproving client device 420 to connect to the WAN 110 and communicate with the service center 300 and NOC 200. The disapproving client device 420 may itself represent a device that does not currently support the remote interactive protocol of the service delivery system architecture 100. To provide the proper interface, surrogate device 410 is received by WAN 110 as client device 400 and acts as a protocol converter or "tunnel device" for disapproving client device 420. For example, instead of installing emulating software on the "Dam" terminal, the "Dam" terminal can connect to a surrogate device 410 that connects to the WAN 110, thereby causing the "Dam" terminal to connect to the surrogate device 410 and WAN 110. Allows communication with NOC200 and Service Center 300. [0038] For example, surrogate device 410 can be used to connect a disapproving thin client to a WAN 110 by converting the thin client's native protocol to its analog in a remote interactive protocol. Therefore, from the point of view of the service delivery system architecture, the disapproval thin client is a common client device 400 connected to the WAN 110. On the other hand, from a thin client's point of view, it simply connects to a standard thin client server. Therefore, the service delivery system architecture 100 connects existing networks, devices or systems with no or minimal modifications to the hardware and / or software infrastructure of existing networks, devices or systems. Can communicate. Therefore, connecting to the service delivery system architecture 100 does not change the functionality, operation and infrastructure of an existing network, device or system, but enhances and extends its capabilities. By connecting to the service delivery system architecture 100, companies, organizations or individuals can existing without the risk of security and without investing in new hardware / software infrastructure such as new client-server systems and firewalls. Allows worldwide remote access to available services on your network, equipment or system. [0039] In the in-service delivery system architecture 100, the "real" computing resources and the data associated with the service reside in the service center 300. Service Center 300 is a legacy corporate data center with one or more connectors or connectivity service modules 310, or video conferencing, Internet Protocol (IP) phones, voice messages, cable television, digital music, digital movies, e-commerce. It can be a special site set up to specifically support certain services. The service delivery system architecture 100 allows a service provider to provide its services by establishing a service center 300 that connects the system to the WAN 110 via a connector 310. The connector or connection service module 310 encapsulates or wraps the existing native protocol of the corresponding service center 300 into a suitable remote interactive protocol. This allows the service center 300 to send its native command to the client device 400. The connector or connection service module 310 of the service center 300 also opens or disassembles a remote interactive protocol message or packet containing native commands of the client device 400 directed to the service center 300. According to an embodiment of the present invention, all services provided by the service center 300 are sent to the client device 400 under the direction and continuous control of the NOC 200 described below. [0040] According to an embodiment of the invention, the service delivery system architecture 100 allows a service provider to service a data center with no or minimal modifications to existing hardware and software infrastructure. Allows conversion or establishment to center 300. For example, a company seamlessly transforms a legacy enterprise infrastructure into a service center 300 and services so that its employees have secure remote access to some or all of the services available in that legacy enterprise infrastructure. -The center 300 can be connected to the WAN 110 with the connector 310. To provide secure remote access to authorized employees, the remote interactive protocol of the service delivery system architecture 100 operates "on" the native protocol of the legacy enterprise system. For Unix-based servers, remote access to the application can be provided by "xhost'ing" the application or by running a special "virtual frame buffer" driver in the server's X11 server software. For Microsoft Windows-based servers, remote access to applications can be provided by enabling the Window Terminal Server feature and using Microsoft's RDP protocol. Both of these methods provide remote access to applications running on servers within Service Center 300. In each case, the service center 200 has one or more connection service modules 310 connected to LAN320 (ie, the corporate intranet) on the one hand and WAN110 on the other. Alternatively, the connector or connection service module 310 can be connected to WAN 110 by a firewall device (not shown). The connection service module or connector 310 maintains a secure connection to one or more NOC200s and reliably connects one of its offered services to the client device 400 designated by one of the NOC200s. Wait for the command to do. Therefore, it is desirable to use a smart card (discussed below) for anything previously available directly from the data center (eg user applications, email clients, voice processing, internet connectivity, etc.). Users can access it remotely from any location and the data does not leave the service center 300. Therefore, a laptop or personal digital assistant (PDA) can still be used while on the move, but it is not necessary. According to Service Delivery System Architecture 100, companies and businesses no longer need to buy and maintain desktops and laptops and provide technical and software support to the location of personal client equipment, thereby unprecedented. It saves a lot of money, time, and overhead while providing a level of security and performance. [0001] According to an embodiment of the invention, the connectivity service module 310 is a software and hardware component, such as one or more low-cost, horizontally expandable servers 315 that connect individual digital services to the WAN 110. To be equipped. For example, digital services include specific operating systems (ie Windows®, Macintosh®, Linux®, Unix®, Solaris®, etc.), digital television broadcasts, IP phones, etc. Can represent a computer or server running. The connection service module 310 acts as a local user interface for each service, interprets the display / sound and user commands configured for each service, and translates the command set between remote interactive protocol formats. Once the session is established between the client device and the service center 300, the connection service module 310 uses the client device 400 to receive and display the human-perceptible output of the digital service that it subscribed to or requested. And send basic and atomic input to the digital service you have subscribed to or requested. The connection service module 310 or server 315 collects video or display images (ie pixels), sound and I / O datasets for digital services and also generates stateless sessions with client device 400. Server 315 requires minimal maintenance and has the "instrument-like" nature of performing a single function. That is, server 315 only manages device connections between applications or services running on server 330 in the service center 300 and client devices 400 that request such services. [0042] The Network Operations Center (NOC) 200 is the gateway to all services provided by the various service centers 200 connected to the WAN 110. The NOC 200 confirms all connection requests received from the client device 400 and ensures that the connection is transferred to the appropriate service center 300 to send the requested service to the client device 400. Therefore, the service delivery system architecture can support a large number of NOC200s to support many client devices. According to the embodiments of the present invention, not only is the number of NOC200s extensible vertically, but the functionality within a single NOC is horizontally extensible (the number of hardware / software components within the NOC200 is NOC). May be increased to extend the capabilities of). [0001] According to an embodiment of the present invention, the NOC200 comprises one or more authentication service modules 210, a Meta-Desktop service module 220, a user database 230 and a client database 240. The authentication service module 210 responds to an authentication request from the client device 400 and performs a remote interactive protocol authentication process to establish and maintain a valid authenticated connection between the client device 400 and the NOC200. The authentication service module 210 stores and maintains a valid client device, user ID, and their associated public key in the user database 230 and the client database 240. Each client device 400 may correspond to a specific NOC200. Alternatively, the client device 400 may also support a primary NOC200 and a secondary NOC200 in case the primary NOC200 is unavailable, respectively. With reference to FIG. 3, the authentication process according to the embodiment of the present invention is shown. Client device 400 is assigned NOC200 (ie, in step 1000).<u style="single">www.xds.net</u>, <u style="single">www.xds.co.jp</u>, <u style="single">www.xds.de</u>The certification request can be sent directly to (etc.), or the certification request can be broadcast on the WAN 110 so that it can be received and processed by the assigned NOC200. It is desirable that the client device 400 use the public key associated with the NOC200 assigned to encrypt the authentication request before sending or broadcasting the authentication request to the NOC200 assigned in step 1000. [0044] Each NOC200 is assigned its own private key. Using the NOC private key, the authentication service module 210 decrypts the authentication request or message received from the client device 400 in step 1010. Authentication service module 210 was encrypted for a particular client device 400 in step 1020 by using the public key associated with that client device 400 or the user on that client device 400 to encrypt the response. Send or broadcast your answer. The service providing system architecture 100 of the present invention uses symmetric public key exchange such that the public key of the authentication service module 210 corresponds to the user or the client device 400 and the public key of the client device 400 corresponds to the authentication service module 210. Is desirable. That is, the client device 400 uses the public key associated with the assigned NOC200 to encrypt the authentication request, and that, that is, the user's private key, is used to receive an answer or an answer received from the assigned NOC200. Decrypt the message. This symmetric authentication procedure ensures that the legitimate NOC 200 communicates with the legitimate client device 400. [0045] Once the authentication request and response have been successfully exchanged between the requesting client device 400 and the authentication service module 210, the requesting client device 400 and the authentication service module 210 have a session key or clog in step 1030. It will share a unique value (a value that is difficult to identify or guess) that can be used as the initial session key. According to an embodiment of the present invention, each client device 400 includes a smart card reader 430. Each smart card uniquely identifies a user and stores user information such as a user ID, a user's private key, and a NOC public key. To initiate a session between client device 400 and NOC 200, the user inserts the smart card into smart card reader 430 of client device 400. The smart card generates an authentication request based on the client ID of the client device 400, encrypts the authentication request using its stored public key, and receives it from NOC200 using the stored private key. Decrypt the answer or message. Once the authentication request and answer are successfully exchanged, the smart card and authentication service module 210 share a session key, or initial session key, to establish a session with each other. The use of smart cards allows the NOC 200 and thin or "dumb" client devices 400 (ie low-cost client devices that lack encryption and decryption capabilities) to authenticate each other to establish a session. [0046] Once the session key and authentication of the requesting client 400 are established, the authentication service module 210 sends the client ID associated with the requesting client device 400 to the metadesktop service module 220 in step 1040. At step 1050, the metadesktop service module 220 establishes a device connection with the requesting client device 400 and displays a customized metadesktop on the requesting device 400. [0047] According to an embodiment of the present invention, the meta desktop module 220 comprises one or more meta desktop servers 225. The MetaDesktop Service Module 220 searches the client database 240 based on the client ID provided by the remote user's smart card, finds the client profile, and finds the client device type, client device location (eg, geographic location). And / or network location such as IP address), read and search client profile to determine attached peripherals, etc. Based on the client profile information, the metadesktop module 220 uses the appropriate metadesktop server 225 (eg, one with reserve capacity) to generate and request a metadesktop session on the client device 400. Establish a secure device connection with the client device 400 that is required to display a customized meta desktop specific to the client. As a security measure, the meta-desktop service module 220 may initiate a device connection to the client device 400 to ensure that the meta-desktop service module 220 communicates with a legitimately authenticated client device 400. desirable. [0048] Metadesktop is a top-level selection interface for connecting users to a particular service connection, that is, connecting a client device 400 to a particular service center 300 for receiving a special digital service. According to aspects of the invention, since the meta desktop is the first screen displayed to the user by the client device 400, the meta desktop is an advertisement 450, branded, with user customizable features, as shown in FIG. 2A. , Gives the opportunity to provide other features related to the service. The metadesktop preferably includes an icon 440 indicating various services available to a particular authenticated user on a particular authenticated client device 400, as shown in FIGS. 2A-2D. For example, if a user subscribes to an Internet telephone service but the client device 400 is not equipped with a microphone, they will not be able to access the telephone service. According to an embodiment of the present invention, based on the client profile information and the information received from the client device 400, the meta-desktop service module 220 may have a specific client device, a specific user, a specific location of the user, a specific time, and the like. You can customize or adjust the contents of the meta desktop for this purpose. It is desirable that the meta-desktop module 220 sends, pushes or broadcasts a dynamically changing, always-up-to-date display to the client device 400. Although the service delivery system architecture 100 has been described as providing meta-desktop services, meta-desktop services are only one of many services that can be provided by NOC200. Therefore, as with the meta-desktop service, the authentication service module 210 can authenticate via a secure device connection and manage any digital service connected to the client device 400. For example, one authentication module 210 can manage digital service A, such as meta-desktop service, and another authentication module 210 can manage digital service B. When the user selects a specific service from the meta desktop displayed on the client device 400 in step 1060 (for example, by clicking the icon 440 associated with that specific service), the person in charge who is securely connected to the client device 400 The assigned NOC200 determines the service center 300 that corresponds to the selected service. In step 1070, the responsible NOC200 is responsible for its safety with the connection service module 310 of the desired service center 300 to initiate a new device connection (also referred to here as a render connection) between the server 330 and the requesting client device 400. Use a good connection. The NOC200 in charge manages the session between the server 330 of the connection module 310 and the requesting client device 400, and keeps a record of the session (that is, the current state of the session). That is, the responsible NOC200 supplies the client profile information of the requesting client device 400 to the connection service module 310, and makes a device or render connection on the WAN 110 between the server 330 that provides the requested service and the requesting client device 400. By starting, it instructs the connection service module 310 to establish a session with the client device 400. This approach provides enhanced security by ensuring that the connection service module 310 initiates all inbound and outbound connections to the client device 400 and does not allow ingress and egress connections to the service center 300. That is, the client device 400 cannot use or initiate a connection to the service center 300. In addition, NOC200 terminates the device connection to the client device 400 that provided the meta desktop. The connection service module 310 translates I / O commands from the application service into a remote interactive protocol format to manage the connection to the client device 400. That is, the connection service module 310 is profitable at the service center 300. Switch to any format suitable for any client device 400 (resolution, color depth, keystrokes, mouse coordinates, etc.) for any of the available digital services. If the application supports native remote interactive protocols, for example via X11 virtual device driver software, Connection Service Module 310 does not require conversion. [0051] After the NOC200 initiates the establishment of a session between a particular service center 300 and the client device 400, the requesting client device 400 is in step 1080 to the user to the appropriate service center 300 via WAN 110. Send the input. Upon receiving it, service center 300 processes the input or performs calculations in step 1090 to produce output / results. The service center 300 sends a rendering command to the client device 400 in step 1100. [0052] According to the embodiments of the present invention, each NOC200 can operate to manage a large number of sessions for various client devices 400. The NOC200 dynamically updates the display format of each metadesktop based on the type of client device 400 currently used by the user to access digital services from the service delivery system architecture 100. [0053] The service delivery system architecture 100 enhances security by maintaining a secure (eg, TCP-based) connection between one of the client unit 400 and the NOC200. The lifetime of the authentication performed by inserting the first user token, that is, inserting the smart card into the client appliance 400 to access the digital service, is the lifetime of the connection established between the client appliance 400 and the NOC200. Corresponds to. As long as this connection is maintained, the NOC200 will send a "keepalive" message to connection service module 310 in service center 300. As an additional security precaution, if the connection service module 310 does not receive a "keepalive" message within a predetermined period of time, it is desirable that the connection service module 310 terminate the device connection to the client device 400. It will be appreciated that the "keepalive" feature is part of a remote interactive protocol. [0054] As part of the authentication handshake or process, the authentication service module 210 performs public key processing to ensure that both the individual user and the particular client device 400 are legitimate. However, secure key distribution is a problem with public key cryptography, and a secure system is needed to ensure that keys are securely distributed and protected. According to an embodiment of the present invention, the service delivery system architecture 100 utilizes a token-based security system that uses smart card technology to distribute keys and generate session keys. For example, a legitimate user can log on to his session through the client device 400 and use a smart card or smart card to access various meta-desktop or digital services. According to aspects of the invention, smart cards / tokens are the user's private key, user credentials (eg client / user ID), NOC200 public key, uniform resource identifier or locator (URI) that can be used to find the appropriate NOC. Or URL) (for example, the character string "xtp: // <uid> .xds.com /") is stored. The smart card contains a suitable pseudo-random number source, so the service delivery system architecture 100 does not have to rely on the client device 400 with these capabilities. As described herein, the client device 400 can span a wide range of device capabilities, from simple I / O devices to full-featured PCs. [0055] According to an embodiment of the invention, the smart card / token can be used to authenticate both the client device 400 and the user. It is desirable that the smart card is the type used for the wide area system subscriber identification module (GSM-SIM) for mobile communication. For additional security from the point of view of the present invention, the authentication service module 210 requires the user to enter a PIN or password to unlock the smart card, similar to a traditional automated teller machine (ATM) card. .. This helps prevent smart cards from being used by unauthorized users. [0056] For software-based client devices 400 such as web browsers (ie those without a smart card reader), the invented service delivery system architecture 100 is a secure socket for privacy and fingerprint readers. -Other authentication / confirmation methods such as layer (SSL), password or challenge / response system for authentication may be used. [0057] Digital services such as word processor applications, web browsers, video services, telephone connections, etc. can be connected to the WAN 110 via a connector or connection service module 310. Once the session is established between the service center 300 and the client device 400, the connection service module 310 of the service center 300 activates the requested digital service and represents the incoming digital data (eg, Windows desktop, etc. Convert the display / mouse and keystrokes) into a data representation compatible with the remote interactive desktop protocol format and encapsulate it with the user session ID. That is, the connection service module 310 can generate a bitmap pixel image of the service output, such as generating a virtual image of a desktop, an application, or the like. The connection service module 310 also reports its status and availability to the NOC200. However, if the user or user session does not require digital service, the NOC200 or MetaDesktop Service Module 220 simply keeps the session enabled and idle, as shown in Figure 2A. This allows the NOC200 to provide a virtually immediate response to user requests for digital services, maintaining the state of the service session at all times. [0058] With reference to FIG. 4, an embodiment of the present invention illustrates the process of transferring control of a client device 400 to another NOC200. When there is a digital service user request in step 2000 (eg, inserting a smart card into client device 400), the NOC200 Authentication Service Module 210 requests the client device 400's geographic and / or network location in step 2010. The distance between the client device 400 and the service center 300 associated with the digital service (ie, the responsible service center 300) is within the service center's direct service area (eg, thousands of miles) to determine (eg IP address). Check if it is in. The authentication service module 210 searches the client database 240 for client profile information, including information such as client device type, installed peripherals, and location. The size of the direct service area depends on the round-trip delay or response time and is preferably below the user's perceived threshold. If the authentication service module 210 determines that the requesting client device 400 is within the direct service area of the responsible service center 300, the authentication service module 210 authenticates and requests the user and client device 400 in step 2020. The client ID associated with the request client associated with the device 400 is provided to the meta desktop service module 220 of the NOC200. In step 2030, the metadesktop service module 220 establishes a device connection with the requesting client device 400, customizes the metadesktop based on the client profile information of the requesting client device 400, and customizes it to the requesting client device 400. Display the meta desktop that has been created. When the user selects the desired service from the meta desktop displayed on the requesting client device 400 in step 2040, the NOC200 responds in step 2050 to establish a device connection or session with the requesting client device 400. Determine and instruct Center 300. [0059] If the client device 400 is outside the direct service area of the service center 300, according to an embodiment of the present invention, at step 2060, the home NOC 200 encapsulates the user session and is closer to the client device 400. Transmit and reestablish the user session to the NOC200 (ie, the remote NOC200). That is, the original user session at home NOC200 is "frozen" or suspended. According to aspects of the invention, a set of dedicated servers and software (ie, session caching servers) provides users with widespread hot desking (ie, synchronizing the state of user sessions between various NOC200s). -Encapsulate and transmit the session. When the user returns to the home service area, in step 2070 the home NOC200 recovers / updates the user session to the home service area and synchronizes (that is, stores the user session state in the user database 230 of the home NOC200). .. The NOC200 hosts and maintains the user session continuously, thereby allowing the user to be between different types of client devices 400 and / or locations while maintaining the user session on the NOC200 and / or connection service module 210. Allows you to switch freely in real time. The user can continue the session from the time it was last accessed. Therefore, if the connection service module 210 does not receive a "keepalive" message from the NOC within a predetermined period of time, the connection service module 210 terminates the render or device connection to the client device 400. Similarly, if the user logs off or removes the token or smart card from the client device 400, the NOC200 will continue the user session, but will terminate the authenticated connection to the client device 400 and render or device to the client device 400. Command the connection service module 210 to terminate the connection. The user can re-enter the user session by logging in again. When using a smart card or token, the token can be reinserted into the same or different client device 400. In this way, logon and logoff for switching between client devices 400 can be completed. Therefore, a user who is connected to one client device 400 and presents a presentation logs off and logs on to another client device 400 by removing the token from the first client device 400 and inserting it into the second client device 400. be able to. Other than the pause in the time required to switch between client devices, the state of the presentation is maintained and the user can move around while continuing to show the presentation. If there is a delay before the user logs off and logs on to the session again, the session is set while the NOC200 authenticates with the new client device and reestablishes a properly configured connection. It will be cached and stored on the connection service module 310 or NOC200. Therefore, a laptop or personal digital assistant (PDA) can still be used while on the move, but it is not necessary. According to the service delivery system architecture 100, users simply bring a smart card or token for remote access to their corporate network from anywhere. [0061] The connection service module 310 receives incoming data from the service provider or server 330 and parses the information for transmission to the client device 400. The present invention utilizes the basic user interface of each client device 400 to display the representation of the data on the client device 400, rather than the code conversion information based on the features and functionality of each client device 400. Code conversion is the process of converting a media file or object from one format to another. For example, code conversion converts video formats and converts hypertext markup language (HTML) and graphic files to smaller screen dimensions, smaller memory and slower bandwidth rates on mobile devices and other webs. Used to meet the constraints of compatible products. The computing overhead for processing and managing client sessions and each user session is on the NOC200. [0062] The connection service module 310 transmits data to each client device 400 (that is, uploads and downloads). According to an embodiment of the present invention, the connection service module 310 is a standardized virtual media buffer capable of operating to transmit data using a set of protocols such as ALP, RDP, IP and the like. The connectivity service module 310 transmits data using a remote interactive protocol optimized to enable high-level performance of encrypted delivery of stream data representations such as stream video and audio. Is desirable. User Datagram Protocol (UDP) and / or proprietary tunneling protocol architectures are associated with stream video and audio, as these formats allow data loss while reducing data latency. Those skilled in the art will understand that information can be transmitted. The graphical user interface (GUI) and visual information for each session is driven by each service driver with its own rendering engine or window processing engine, such as Microsoft Windows® or Java® virtual machines. be able to. [0063] With this service delivery system architecture, the NOC200 establishes a secure communication path between the connection service module 300 and the client device 400 to give both the service provider and the user an unmatched level of security. Can be done. In addition, the present invention makes all sessions available to users without the data moving outside the service center 300, providing secure and continuous access to the data from any location, including insecure remote locations. To do. From the above description, many modifications and alternative embodiments of the invention will be apparent to those skilled in the art. Therefore, this description should be construed as an example only and is intended to teach one of ordinary skill in the art the best way to carry out the invention. The details of the structure can be changed without substantially deviating from the idea of the invention, and the exclusive right to use all modifications within the scope of the claims added is reserved.
<figref num="1">Block diagram illustrating the service provision system architecture of the present invention</figref><figref num="2">Screenshots illustrating a Meta-Desktop according to an embodiment of the present invention.</figref><figref num="3">Flowchart of authentication processing according to one embodiment of the present invention</figref><figref num="4">Flow chart of the process of transferring control of the client device to another NOC according to one embodiment of the present invention.</figref>
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP11027283A | Cites | Japan |
| WO00062540A1 | Cites | World Intellectual Property Organization (WIPO) |
| JP2002041407A | Cites | Japan |
| JP2002007454A | Cites | Japan |
22 members in 11 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 60381532 | United States of America | – | |
| 38153202 | United States of America | P | |
| 10328660 | United States of America | – | |
| 32866002 | United States of America | A | |
| 0308352 | United States of America | W |
Members22
| Document | Office | Kind | |
|---|---|---|---|
| US2003217166A1 | United States of America | A1 | |
| CA2485426A1 | Canada | A1 | |
| WO03100642A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003233408A1 | Australia | A1 | |
| EP1509849A1 | European Patent Office (EPO) | A1 | |
| KR20050027091A | Republic of Korea | A | |
| CN1653441A | China | A | |
| JP2005526336A | Japan | A | |
| IL164554A0 | Israel | A0 | |
| ZA200408546B | South Africa | B | |
| US2008071860A1 | United States of America | A1 | |
| US2008072298A1 | United States of America | A1 | |
| US7363363B2 | United States of America | B2 | |
| CN100407186C | China | C | |
| CN101394401A | China | A | |
| JP4257967B2This record | Japan | B2 | |
| US7783701B2 | United States of America | B2 | |
| EP1509849A4 | European Patent Office (EPO) | A4 | |
| IL164554A | Israel | A | |
| US2011093940A1 | United States of America | A1 | |
| SG187266A1 | Singapore | A1 | |
| CN101394401B | China | B |
28 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4257967
- Application
- 2004508026
Titles2
- Japanese
- ユニバーサルなステートレスのデジタルおよびコンピュータ・サービスを提供するためのシステムと方法
- English
- Systems and methods for providing universal stateless digital and computer services
Classification
- CPC, 9
- H04L67/08
- G06F15/16
- H04L63/0272
- H04L63/0442
- H04L63/08
- H04L67/14
- H04L69/08
- H04L67/56
- H04L67/565
- IPC, 4
- G06F15 00
- G06K17 00
- H04L29 06
- H04L29 08
