A method and an apparatus for providing a switch-over of the same session between the terminals of an end-user
Abstract
Method and apparatus for performing switchover of a session between different user terminals. The method and apparatus includes means for receiving, from a first device, data representing a session, where the session data includes any application and authentication data required to reestablish the session. The method and apparatus facilitates suspending the session at the first device, and reestablishing the suspended session on a second device using the suspended session data.

Term
Term ended
Expired 28 December 2025, 0.7 years ago.
- Priority and filed
- Granted
- Expired
- Today
10 claims: 3 independent, 7 dependent
- 1第1のデバイスから第2のデバイスにセッションの切り替えを実行する方法であって、 前記第1のデバイスおよび前記第2のデバイスは移動体エンドユーザ・エージェント・デバイス(MEAD)と通信するように適合された異なるユーザ端末であり、 前記方法は、 前記セッションを再確立するために十分なアプリケーションデータおよび認証データを含むセッション・データを前記第1のデバイスから前記MEADに受信する工程と、 前記受信したセッション・データを前記MEADに記憶する工程と、 前記第1のデバイスで 前記セッションを一時停止する工程と、 前記第2のデバイス上で、 前記一時停止されたセッション・データを用いて 、前記MEADを介して 前記一時停止セッションを再確立する工程とを含む方法。
- 2第1のアクセス・ネットワークに接続された前記第1のデバイスから前記セッションを起動する工程と、 第2のアクセス・ネットワークに接続された前記第2のデバイスから前記一時停止セッションを再確立する工程とをさらに含む請求項1に記載の方法。
- 3前記第1のデバイスから、集中セキュリティ・サーバからのユーザ識別を確認する工程をさらに含む請求項1に記載の方法。
- 4前記第1のデバイスのローカルなアプリケーション・プログラムを起動することで前記セッションを実行する工程をさらに含む請求項1に記載の方法。
- 5ネットワーク・サービス・プロバイダへの接続機能を起動することで前記セッションを実行し、少なくとも1つのサービスにアクセスする工程をさらに含む請求項1に記載の方法。
- 6前記セッションの前記一時停止工程が、 前記第1のデバイスでエンドユーザ識別情報を消去する工程を含む請求項1に記載の方法。
- 7前記一時停止されたセッションを第2のデバイスで再確立する工程が、 集中セキュリティ・サーバにユーザ識別確認を要求する工程と、 前記集中セキュリティ・サーバからの確認を用いて前記一時停止されたセッションをアンロックする工程とを含む請求項1に記載の方法。
- 8第1のデバイスから第2のデバイスにセッションの切り替えを実行する装置であって、 前記第1のデバイスおよび前記第2のデバイスは移動体エンドユーザ・エージェント・デバイス(MEAD)と通信するように適合された異なるユーザ端末であり、 前記装置は、 前記セッションを再確立するために十分なアプリケーションデータおよび認証データを含むセッション・データを前記第1のデバイスから受信する手段と、 前記受信したセッション・データを前記MEADに記憶する手段と、 前記第1のデバイスで 前記セッションを一時停止する手段と、 前記第2のデバイス上で、 前記一時停止されたセッション・データを用いて 、前記MEADを介して 前記一時停止セッションを再確立する手段とを含む装置。
- 9第1のアクセス・ネットワークに接続された前記第1のデバイスから前記セッションを起動する手段と、 第2のアクセス・ネットワークに接続された前記第2のデバイスから前記一時停止セッションを再確立する手段とをさらに含む請求項8に記載の装置。
- 10第1のデバイスから第2のデバイスにセッションの切り替えを実行する移動体エンドユーザ・エージェント・デバイス(MEAD)であって、 前記第1のデバイスおよび前記第2のデバイスは前記MEADと通信するように適合された異なるユーザ端末であり、 前記MEADは、 前記セッションを再確立するために十分なアプリケーションデータおよび認証データを含むセッション・データを前記第1のデバイスから受信するように構成された少なくとも1つのポートと、 前記受信したセッション・データおよびユーザ・プロファイル情報を記憶するように構成された記憶デバイスと、 前記少なくとも1つのポートおよび前記記憶デバイスに接続され、前記第1のデバイスで前記セッションを一時停止するコマンドを実行し、前記一時停止されたセッション・データを用いて前記一時停止セッションを前記第2のデバイス 上 で再確立するように構成されたプロセッサとを含 み、 携帯機器であることを特徴とする、 MEAD。
Independent claims10
77 paragraphs, as filed
The present invention relates to the provision of network services, and more specifically to the provision of switching of the same session between end-user terminals.
Different entities are building technologies and capabilities that provide seamless and secure roaming of wireless devices across different types of wireless networks, including wireless LANs, cellular networks, private mobile wireless networks, and satellite networks. There is. For example, you can roam on different types of networks using different types of wireless devices, move between locations, and access important business data at all times.
Currently, wireless gateways can automatically detect the most suitable wireless network at any given time and switch networks without restarting the device or application. Such roaming capabilities allow, for example, a home-based businessman to access data from the office using a mobile device (eg, a PDA) connected to his home wireless LAN network. Alternatively, when you go out and move out of the service area of the wireless LAN network, the device automatically switches to the cellular network. Upon entering the office or customer location, the device can switch to high-speed wired or wireless LAN. In each of the above roaming techniques, the end user uses the same computer device to roam between networks.
In addition, the current roaming capabilities of wireless networks can recognize the most suitable time and network for transferring large amounts of data between mobile devices and back-end systems. This feature is, for example, the use of the most costly and slowest cellular networks, where large amounts of data transfer can await participation in high bandwidth Wi-Fi or wireless LAN networks without being more costly. Helps avoid. Therefore, today's roaming capabilities allow access to data regardless of the wireless network available at a given location.
<p> While mobile device users can roam between networks, current technology does not allow mobile device users to switch between different end-user terminals while maintaining their current session. That is, if a user establishes a service session of information with a first end-user terminal and attempts to transfer this session to, for example, different end-user terminals in different locations, the end user is at the beginning of the first terminal. You must first end the session and then reconnect through the second session of the second end-user terminal to continue the service or application.</p><p> For example, suppose an end user is playing a video game on the Internet established on a first computer terminal at the user's home. A user may want to continue the same game in different locations (eg, an airport) without ending the game. To do this, the end user first ends the current session on the user's home first computer terminal (eg, a laptop computer device) and then a new computer device at the airport (eg, a PDA). The session must be reestablished. When a user ends a session in the middle of a game, the user often has to restart a new game without being able to continue the same session from where it ended on the first computer terminal. Therefore, there is a need in the art to perform seamless session switching between different end-user terminals without establishing a new session at the second end-user terminal.</p>
<p> The present invention can be used to track authentication, end-user application sessions, and user profiles to provide seamless switching between different end-user terminals (ie, computer devices) mobile end-user agents. -Device (MEAD). The mobile end-user agent device of the present invention facilitates roaming capabilities between different end-user terminals that can connect to different networks. MEAD allows the end user to start a service and / or information session from the first end user terminal, pause the current session (ie, quiesce or pause), and later have the same session on a different end user terminal. You can start.</p><p> In one embodiment, the method of the invention comprises switching sessions between different user terminals. The method comprises receiving data from the first device that is data representing the session and that the session data includes any application and authentication data necessary to reestablish the session. MEAD can be used to stop a session on the first device and reestablish the stopped session on the second device using the stopped session data.</p><p> The teachings of the present invention can be easily understood by reading the following detailed description with reference to the accompanying drawings. For ease of understanding, the same reference numbers are used as appropriate to indicate the same common elements throughout the drawings.</p>
The present invention can be used to track authentication, end-user application sessions, and user profiles to provide seamless switching between different end-user terminals (ie, computer devices) mobile end-user agents. -Device (MEAD). The mobile end-user agent device of the present invention facilitates roaming capabilities between different end-user terminals that can connect to different networks. MEAD allows the end user to start a service and / or information session from the first end user terminal, pause the current session (ie, quiesce or pause), and later have the same session on a different end user terminal. You can start.
In particular, session information (eg, session data and status) is recorded (ie, stored) on MEAD while the session is initiated by the end user and is in active use. Therefore, MEAD can store session data and data related to the application that the user uses during the session. The user can stop the session and remember the relevant session information so that the end user can roam (ie move) from place to place and later the same from a different computer device than the device where the session started. You can start a session.
To transfer a single session from one end-user terminal to another, the terminal stores information related to the end-user network and the services and application attributes provided, and different end-users with networking capabilities. Automatically provide network access from the terminal. The end-user terminal is independent of the type of network in which the session started. That is, end-user terminals can connect to networks through different types of network access, including cables, FTTH, ADSL, wifi, cellular, private mobiles, and satellite networks, among others. For example, a user starts a session on a first terminal associated with a radio access network, records information about this session on the first terminal until the session is paused, and then on a different type of network (eg, intranet). The same session can be resumed on a second terminal related to (access network).
In addition, mobile end-user agent devices ensure end-user privacy and provide authentication and security features to put end-users under the control of that information. Therefore, transactions between MEAD and end-user terminals are completely secure and are based on end-user authentication. In one embodiment, security is provided by storing data from a transaction with an end-user terminal on MEAD in a coded format. In one embodiment, the code of the coding key is changed at regular intervals and the data is coded with the new key code and stored at these intervals. In one embodiment, the end user application / service session data on the end user terminal is also encoded. Further, in one embodiment, the memory on the end user terminal that stores the data associated with the encoded session is erased before the end user leaves the terminal. This ensures that no other individual has access to any end-user session information. In one embodiment, the key code is also stored in the coded format. To decrypt the key code, the end user must initiate an authentication process (eg, provide a password or biometric authentication).
Therefore, MEAD can initiate and terminate communication between itself and end-user terminals associated with the same or different networks, allowing end-users to apply from one end-user terminal to another. And provide the same look and feel of service. For example, the present invention gives the end user access to the same attributes established within a particular application used on the first terminal, such as bookmarks in a web browser, when switching to the second end user terminal. Can be provided. Each embodiment of the present invention will be described in detail below with reference to FIGS.
FIG. 1 is a block diagram of a network environment 100 suitable for carrying out the present invention. Network 100 is terminals A to E106<sub>a</sub>~106<sub>e</sub>Multiple end-user terminals, such as (collectively end-user terminals 106), access network 104<sub>1</sub>~104<sub>n</sub>Multiple access networks (collectively access networks 104), core networks 102, at least one security server 112, and multiple network service centers 110.<sub>1</sub>~110<sub>n</sub>Includes (collectively Network Service Center 110).
Each access network 104 supports multiple end-user terminals 106 to provide the ability to connect to services and the content and content providers of the services. The access network 104 is interconnected via the core network 102. For the sake of brevity of the present invention, the core network 102 will be discussed as a packet-switched network such as the Internet and / or an intranet. However, it will be apparent to those skilled in the art that the core network 102 may be any type of network capable of providing content, services and transport between the terminal 106 and the service center 110.
The access network 104 is any type of conventional access network. The illustrated network 100 in FIG. 1 is, for example, the WiFi access network 104.<sub>1</sub>, Wireless Broadband Access Network 104<sub>2</sub>, Intranet 104<sub>3</sub>, And Wired Broadband Access Network 104<sub>n</sub>including. However, it will be apparent to those skilled in the art that the access network may be any type of access network that can provide terminal access (ie, communication path) to the packet-switched network 100.
As shown in Figure 1, the end-user terminal A106<sub>a</sub>And terminal B106<sub>b b</sub>For example Wi-Fi access network 104<sub>1</sub>Connected to the end user terminal C106<sub>c</sub>For example, Broadband Access Network 104<sub>n</sub>Connected to the end user terminal D106<sub>d</sub>For example, intranet 104<sub>3</sub>Connected to terminal E106<sub>e</sub>For example, Wireless Broadband Access Network 104<sub>2</sub>It is connected to the. Access network 104<sub>1</sub>Each of the -n (collectively access networks 104) is connected to the core network 102. Although FIG. 1 illustrates a single end-user terminal 106 connected to each access network 104, it is practicable that each access network 104 can provide access to packet-switched networks to multiple end-user terminals. Will be clear. For example, a broadband access network such as a DSL or cable provider can provide broadband services to hundreds or thousands of terminals 106.
End user terminal 106<sub>a</sub>~106<sub>e</sub>(Aggregately terminal 106) may be any computer device that can process information and access the network through the access network. For example, the end-user terminal 106 can include, among other computer devices, laptops, desktops, workstations, PDAs, and mobile devices that can provide information to the end user.
In one embodiment, each access network 104 provides access to one or more network service centers 110. In the illustrated network 100 shown in FIG. 1, the network service center 110<sub>1</sub>And 110<sub>n</sub>Is connected to core network 102. In addition, the illustrated wireless broadband access network 104<sub>2</sub>Is the associated network service center 110<sub>2</sub>Has an intranet network 104<sub>3</sub>Is the associated network service center 110<sub>3</sub>Have. It will be apparent to those skilled in the art that packet-switched networks 104 can be interconnected to one or more (ie, multiple) network service centers 110.
Network Service Center 110 is a private and / or public end-user service (eg, email, chat, video /, etc.) related to intranet services (eg, office email, databases, web-based education, etc.). Can provide audio-on-demand, single-user or networked games, web browsing, etc.). In addition, the network service center 110 can provide authentication and security services as well as end-user profiles and service management.
Figure 1 shows the time t<sub>1</sub>To terminal C106<sub>c</sub>An example is a mobile end-user agent device (MEAD) 108 communicating with. With MEAD108, session status, security information, and user terminal C106<sub>c</sub>It can store user session information, such as session activity information, including information about the application or service (both standalone or networked) interacting with it. Terminal C106<sub>c</sub>During user activity during a session in, the user may wish to suspend the current session for a while and then continue the session elsewhere. Figure 1 also shows the time t<sub>2</sub>Terminal E106<sub>e</sub>Shows MEAD108 interacting with. Therefore, the user has time t<sub>1</sub>Pause the current session on the first end-user terminal, roam to another end-user terminal in another location, and time the temporarily stopped session.<sub>2</sub>To reestablish.
To provide users with roaming capabilities (ie, switching) between end-user terminals in the same session, MEAD108 is a terminal C106.<sub>c</sub>Stores information related to the user's session activity. This information is available on Broadband Access Network 104<sub>n</sub>Contains information about session initiation and status in, and information about user activity about the application (ie, content or program) with which the user is interacting on the terminal. In addition, MEAD108 continuously updates the session information and the status stored in it until the time when the user chooses to suspend the current session.
The user can suspend the current session by issuing a command to terminal 106 via MEAD108. When the pause command is initiated by MEAD108, the session with the first end-user terminal is temporarily suspended and the user can terminate the first end-user terminal. The user then uses the session information recorded (ie, stored) on MEAD108 to time t<sub>2</sub>The same session can be resumed on another end-user terminal at a later time such as. When MEAD reaches the range where it can communicate with the second end-user terminal, the user issues a new command to MEAD108 to terminal E106.<sub>e</sub>You can resume the session on a second end-user terminal such as.
Note that MEAD108 provides user and session security by encoding the session information stored therein. In addition, MEAD requires proper user authorization by requesting a user ID number and password. In one embodiment, the MEAD108 may include a fingerprint pad (also any biometric security) on the keypad to enhance the prevention of unauthorized access to the user's session. Therefore, the MEAD108 pauses (ie, quiesces or pauses) the current session at the first time and at the second end-user terminal (eg, terminal E106).<sub>e</sub>You can resume the same session later).
By interacting with security server 112, MEAD108 can pause and resume sessions on two different terminals 106 in a secure manner. In one embodiment, the security server 112 may be the centralized security server illustrated by the imaginary line in FIG. In an alternative embodiment, the security server 112 can be distributed among a plurality of network service centers 110 associated with each of the access networks.
In particular, security server 112 (drawn in imagination) centralizes end-user terminals that initiate secure sessions so that they are routed directly to central security server 112 by local access network 104. be able to. In an alternative embodiment, the security server function 112 can be distributed locally within the network service center 110 and MEAD108. In either embodiment, the security server 112 provides authentication and authorization for the session connection function initiated by MEAD108 and terminal 106. In another embodiment, the security server can also conveniently provide accounting services to service providers in a manner similar to authentication, authorization, and accounting (AAA) servers known in the art.
FIG. 2 is a block diagram of a mobile end-user agent device (MEAD) 108 suitable for carrying out the present invention. In particular, the mobile end-user agent device 108 includes a controller 250 and a wireless communication circuit 222. The controller 250 includes a processor 254, a support circuit 256, an I / O circuit 252, an encoder / decoder logic 240, and a memory 258. The processor 254, the support circuit 256, the memory 258, the I / O circuit 252, and the logic circuit 240 interact with each other (that is, exchange information) via at least one bus 260.
Memory 258 stores various control programs 282 and data files associated with the user session. Processor 254 works with support circuits such as encoder / decoder 240, among others, conventional support circuits 256 such as power supplies, clock circuits, and caches, as well as circuits that help execute software routines 282 stored in memory 258. To do. Therefore, some of the process steps described herein are intended to be implemented in hardware, for example, as circuits that work with processors 254 to perform various steps.
The controller 250 also includes an input / output (I / O) circuit 252 that forms an interface between the various functional elements that communicate with the controller 250. In the exemplary embodiment of FIG. 2, the controller 250 optionally communicates with an output device (eg, a display) 224 and a user interface (ie, an input device) 226 such as a keyboard or mouse device. Input and output devices 226 and 224 allow the user to receive (eg, display) and input information to and from the mobile end-user agent device 108.
The control device 250 also communicates with the wireless communication circuit 222 via one or more bus 262s connected to the I / O circuit 252. The wireless communication circuit 222 can provide wireless communication with the end user terminal 106 according to, for example, the Bluetooth standard or any other conventional wireless communication standard. In an alternative embodiment, the I / O circuit 252 is a USB port, a wired networking function such as Ethernet®, or any other communication that exchanges information between the MEAD 108 and the end-user terminal 106 within network 100. Can include ports. In one embodiment, the data transferred between the MEAD 108 and the end-user terminal 106 is always encoded, thereby avoiding any security threat.
The memory 258 may be any conventional memory such as RAM, programmable memory, flash memory, disk drive, or any other conventional memory device. The memory is the routine 282 that implements the present invention and, among other information, security data 272, user application data 274, and user, among the information required to establish and maintain a user session between different end-user terminals 106. To store user session information such as profile data 276, user session data 278, user application authorization 280, local operating system (not shown), application program (not shown), etc. used.
Note that the encoder / decoder logic 240 includes an encoder 242 and a decoder 244 for encoding and decoding data to and from memory 258. The encoder / decoder logic 240 can be implemented as software programming, hardware, and / or a combination thereof, as is conventionally known in the art.
The control unit 250 of FIG. 2 is shown as a general purpose computer programmed to perform various control functions in accordance with the present invention, which invention describes, for example, hardware such as an application specific integrated circuit (ASIC). Can be carried out at. Therefore, each process described herein is broadly construed as being performed either by software, hardware, or any combination thereof.
3A and 3B collectively show a flow diagram of a first embodiment of method 300 that provides session switching between different end-user terminals 106. Method 300 of Figures 3A and 3B describes the provision of session authentication and authorization through the central security server 112. In another embodiment, method 400 is described with respect to FIG. 4, where security server 112 is provided locally within network service center 110 and MEAD108.
More specifically, FIG. 3A shows the terminal C106 shown in FIG.<sub>c</sub>Shows a flow diagram of starting, running, and pausing an active session on the first end-user terminal, such as. FIG. 3B shows the terminal E106 shown in FIG.<sub>e</sub>The flow diagram of the start, execution, and end of the same session on the second end user terminal such as is shown.
Referring to FIG. 3A, in step 301, the end user is assigned MEAD108 (of central security server function) by an authorized agency. Referring to FIG. 3A, steps 302-306 provide authentication and security as well as between MEAD108 and the end user terminal 106. In particular, at step 302, the end user is assigned a security token at MEAD108. Specifically, MEAD108's end-user identification manager generates a security code that must be used in conjunction with an end-user-selected passcode or end-user-specific biometric code (eg, a fingerprint). In step 303, the user uses the terminal C106 shown in FIG.<sub>c</sub>Approach networked terminals such as, and establish communication via communication interfaces such as wireless communication (eg Bluetooth) or wired channels (eg Ethernet®, USB in particular) as described above with respect to FIG. To do. In step 304, the user activates MEAD108 and ends user terminal 106.<sub>c</sub>Establish a service with. In one embodiment, the MEAD 108 includes an input (eg, a button or switch) on a keypad that initiates service.
Communication between MEAD108 and terminal 106 is facilitated by any conventional communication medium. For example, wireless communication such as Bluetooth and 3G wireless communication can be used. Alternatively, wired communication can be provided via USB, Ethernet®, or any other conventional wireless or wired standard. Note that terminal 106 facilitates compliant ports, circuits and software for receiving communication signals from MEAD108.
As mentioned in steps 308-324, the service opens a session with the end-user terminal 106 and then a session of information (eg, content) with one or more network service centers 110. .. In step 306, the end user provides terminal 106 with a user identification number and password. In one embodiment, the ID number and password are keyed into the keypad by the user. Alternatively, the ID number and / or password can be stored in memory 258 of MEAD108. In the latter embodiment, the ID number and / or password is transmitted to the terminal 106 only with the service start button. In another embodiment, biometric inputs such as a fingerprint pad, also also on the MEAD108 keypad, provide additional and / or additional security. In any of these embodiments, the MEAD 108 and the first terminal 106<sub>c</sub>Performs a handshake as previously known in the art so that the MEAD108 communicates with the first end-user terminal 106. The end-user terminal 106 is also software programming (eg, an application program) designed to exchange information (eg, messages) with MEAD108, a network service center 110, and a central security server 112. Remember.
At step 308, the end user uses MEAD108 to ensure end user identification from the central security server 112. The identification confirmation is used by the network service center 110 to authenticate the user who receives the service. In one embodiment, identification confirmation is required by transmitting end user qualifications (user ID, password, etc.) and information on the requested service from MEAD to terminal 106. Terminal 106 makes this request to the local access network 104 (eg, the broadband access network 104 in FIG. 1).<sub>n</sub>) To the central security server 112.
In step 312, the security server 112 confirms the end user's identification by comparing the information sent to the server 112 with the client information stored in the server 112. If the user is not confirmed, a denial message is replied to network center 110 and terminal 106, which denies user confirmation. Otherwise, if the security server 112 confirms the end user's entitlement, a confirmation message is sent to the network service center 110, which in step 314 returns the confirmation message to terminal 106.
In step 316, MEAD108 uses the security token to send a secure request for service establishment to the first terminal 106. The secure request includes user identification information, including information that identifies the MEAD 108 in a coded format. In step 318, the first terminal 106<sub>c</sub>Makes a Secure Service Connection Establishment Request to Local Access Network 104<sub>n</sub>Network Service Center 110 via<sub>n</sub>Send to. At this point in Method 300, the network service center 110 initiates a user session.
In optional step 320, the local application can be started on the end user terminal. Local applications include various software programs (ie, applications) that the user wants to interface with during the session. For example, these applications include game programs, web browsing programs, word processing, email, intranet access to corporate databases, audio / video on demand, and CRM, among other traditional application programs. Can be included.
At step 322, alternative or additionally, the user can request the network service center for secure service session data as an option. Session data should include secure service requests with associated end-user IDs and passwords, such as logging on to an intranet using a VPN, among other session data types from the network service center 110. Can be done.
At step 324, the network service center 110 interacts with the end-user terminal to receive the session data request and, in response, returns such session data to the end-user terminal 106 in a secure manner. The dialogue between the first terminal 106 and the network service center 110 continues as long as the user desires. During the user's dialogue between the first terminal 106 and the network service center, in step 326, MEAD108 records the latest data retrieved by the terminal and the status and data of the latest session. MEAD108 continuously records and updates information as the user session progresses. That is, MEAD records all relevant information (status and data), including information from the first end-user terminal 106, service center 110, and centralized security server 112, and maintains the current session.
Ultimately, the end user is the first end user terminal 106<sub>c</sub>Determined to leave the session or suspend the current session according to the principles of the invention. In step 328, the user is terminal 106<sub>c</sub>Decide to leave. At step 330, MEAD108 sends a service session end request. In one embodiment, the user presses the end-of-service button on the MEAD108 keypad, thereby the first terminal 106.<sub>c</sub>A termination request is sent to. In step 332, the first terminal 106 of the example<sub>c</sub>Sends a message to the network service center 110 to enter standby mode. In standby mode, the network service center 110 suspends service to the end-user terminal 106 and waits for the next session instruction to be received.
In step 334, service center 110 is the first terminal 106<sub>c</sub>Send a confirmation message to. In step 336, terminal 106 sends the final service session data / status to MEAD108 for storage and updates MEAD108 with the latest session information. For example, MEAD108 stores final session information such as final user session data 278, user application data 274, security data 272, user profile data 276, and any other applicable information about the session.
In step 338, MEAD is the first terminal 106 of the example.<sub>c</sub>Send a session destruction / lock information message to. In step 340, terminal 106<sub>c</sub>Locks the session data for a session in standby mode and destroys (ie, erases) the end-user identification information stored in terminal 106. When the end user identification information is deleted from the memory of the terminal 106, a confirmation signal confirming the destruction of the user identification information is returned to the MEAD 108 in step 342. In addition, in step 344, terminal 106<sub>c</sub>Sends a replication corruption confirmation message to the central security server 112. Thus, both MEAD108 and security server 112 are notified that the user's identity has been removed from the terminal and the current session of the first terminal has ended.
At step 346, the user names the currently suspended session. The session name can be any suitable name. MEAD108 time stamps the session and locks the session information with a secure key. In this way, the session information in MEAD108 is protected. In step 348, the session name, timestamp information, and secure key for session information are terminal 106.<sub>c</sub>Will be sent to. In step 350, terminal 106<sub>c</sub>Sends the secure key to the central security server 112, which stores the secure key for future access. Therefore, in steps 328-350, the user locks the session data, encodes the locked data with a secure key, and secures the key to centralized security server 112 for future access at different end-user terminals. You can pause the current session by remembering.
FIG. 3B is a diagram showing a method in which the user restarts the pause session described in steps 301 to 350 of FIG. 3B. Referring to FIG. 1, the user, for example, in a different location, i.e. terminal E106.<sub>e</sub>Have moved to. In step 351 the user becomes a second end-user terminal (eg, terminal E106).<sub>e</sub>), In step 352, the end user initiates a security token on MEAD108 and a second terminal 106<sub>e</sub>Establish a service from.
In step 354, the first terminal 106 of step 306 of FIG. 3A<sub>c</sub>Second terminal 106 in the same way as described above with respect to<sub>e</sub>A handshake between and MEAD108 is performed. In step 356, MEAD108 is the second terminal 106<sub>e</sub>Send a secure end-user identification confirmation message to the second terminal 106<sub>e</sub>Sends an identification confirmation message to the central security server 112 in step 358. In step 360, security server 112 returns an end-user identification and confirmation message to the network service center 110 indicating that the information has been authenticated. In step 362, the network service center 110 is the second terminal 106<sub>e</sub>Sends a confirmation message to the second terminal, thereby facilitating the user session.
The user is the second terminal 106<sub>e</sub>You can start a new session with, or the first terminal 106<sub>c</sub>You can restart a previously suspended session that was run in. That is, MEAD108 can record session data for multiple sessions and restart previously suspended sessions.
At step 364, the user decides to unlock the previous session. In particular, the end user initiates a suspended session with the identification confirmation information used. The user can unlock the previous session by providing the appropriate user ID and password information and / or biometric information such as fingerprints to MEAD108.
In step 366, the user has a second terminal 106 to establish a service with the required information.<sub>e</sub>Instruct MEAD108 to send a secure request to. Using the security token, MEAD108 initiates the secure request described above for step 316 in FIG. 3A. In particular, the secure token contains the session name, time stamp information, and any other session and user identification information. In step 368, the second terminal 106<sub>e</sub>Sends a secure service connection establishment request to the network service center 110. At this point, the user can resume the suspended session in Network Services Center 110 by invoking the session (ie, the suspended session is no longer in standby mode).
At step 370, the user optionally chooses a second terminal 106, such as the web browser mentioned above for step 320.<sub>e</sub>Launch the above local application program. Alternatively, at step 372, the user may request service session data from the network service center 110 as described above for step 322. In step 374, the running secure service connection is terminal 106<sub>e</sub>And the network service center 110. Therefore, the user is the second terminal 106<sub>e</sub>You can request and retrieve information from the network service center 110 at.
At step 376, session information and session status are continuously stored and updated by MEAD108. MEAD108 stores session information in memory in the same manner as described above for step 326 of FIG. 3A. As the session progresses and a little while later, in step 378 the user becomes the second terminal 106.<sub>e</sub>Decide to leave.
At step 380, the user sends a termination signal (ie, from the MEAD108 keypad) to the second terminal, including a session termination request. Second terminal 106<sub>e</sub>Is notified that the user wants to suspend or terminate the session. At step 382, the second terminal instructs the network service center 110 to switch from active session to standby mode. At step 384, the network service center 110 switches to session standby mode and the second terminal 106<sub>e</sub>Return a confirmation message to. In step 388, the second terminal transmits the final service session status and data stored in MEAD108.
In step 388, MEAD is the illustrated second terminal 106<sub>e</sub>Send a session destruction / lock information message to. In step 390, the second terminal 106<sub>e</sub>Locks the session data for a session in standby mode and erases the end-user identification information stored in terminal 106. When the end user identification information is deleted from the memory of the terminal 106, a confirmation signal confirming the destruction of the user identification information is returned to the MEAD 108 in step 392. In addition, in step 394, terminal 106<sub>e</sub>Sends a replication corruption confirmation message to the central security server 112. Thus, both MEAD108 and security server 112 are notified that the user's identity has been removed from the terminal and the current session of the first terminal has ended.
In step 396, the user names the currently suspended session. MEAD108 time stamps the session and locks the session information with a secure key. In addition, any other session created on the second terminal will also be given a unique name and time stamp that identifies the session of later further interaction on different terminals 106.
In this way, the session information in MEAD108 is protected. In step 398, the session name, timestamp information, and secure key for session information are in the second terminal 106.<sub>e</sub>Will be sent to. In step 399, the second terminal 106<sub>e</sub>Sends the secure key to the central security server 112, which stores the secure key for future access. Therefore, in steps 378-399, the user locks the session data, encodes the locked data with a secure key, and provides the central security server 112 with a secure key for future access on different end-user terminals. You can pause the current session by remembering it.
FIG. 4 is a flow diagram of a second embodiment of method 400 that provides session switching between different end-user terminals 106. In this second embodiment, session switching between different end-user terminals is provided without the centralized security server 112. In this second embodiment, user identification and session information verification are established on the terminal, and verification is not performed on the central security server.
Referring to FIG. 4, step 301 is the first step in which the end user is assigned MEAD108 (of the distributed security server function) by an authorized agency. Steps 302-306 provide authentication and security similar to between MEAD108 and the end user terminal 106, as described above for method 300 in FIGS. 3A and 3B. In particular, at step 302, the end user is assigned a security token at MEAD108. In particular, MEAD108's end-user identification manager generates a security code that must be used in conjunction with an end-user-selected passcode or end-user-specific biometric code (eg, a fingerprint). In step 303, the user uses terminal C106, as shown in FIG.<sub>c</sub>Approach networked terminals such as, and establish communication via communication interfaces (eg, Bluetooth, Ethernet®, USB, among others). In step 304, the user activates the token to establish the service.
In step 306, the end user provides terminal 106 with a user identification number and password. In one embodiment, the ID number and password are keyed into the keypad by the user. Alternatively, the ID number and / or password can be stored in memory 258 of MEAD108, just as the ID number and / or password is sent to the terminal 106 with just the service start button. A handshake is returned from terminal 106 to MEAD108, and terminal 106 authenticates the user and MEAD108.
Method 400 then proceeds to step 316. Note that steps 308-314 of method 300 are not used in method 400. This is because these steps facilitate the exchange of information regarding the step of confirming the user identification on the central security server 112. Note that this second embodiment does not use the centralized security server 112, but instead uses the distributed security server 112.
In step 316, MEAD108 uses the security token to send a secure request for service establishment to the first terminal 106. The secure request includes user identification information, including information that identifies the MEAD 108 in a coded format. In step 318, the first terminal 106<sub>c</sub>Makes a Secure Service Connection Establishment Request to Local Access Network 104<sub>n</sub>Network Service Center 110 via<sub>n</sub>Send to. At this point in Method 400, the network service center 110 initiates a user session.
In optional step 320, the local application can be started on the end user terminal. Local applications include various software programs (ie, applications) that the user wants to interface with during the session. For example, these applications include game programs, web browsing programs, word processing, email, intranet access to corporate databases, audio / video on demand, and CRM, among other traditional application programs. Can be included. At step 322, alternative or additionally, the user can request the network service center for secure service session data as an option.
At step 324, the network service center 110 interacts with the end-user terminal to receive the session data request and, in response, returns such session data to the end-user terminal 106 in a secure manner. The interaction between the terminal 106 and the network service center 110 continues as long as the user so desires. During the user's dialogue between the first terminal 106 and the network service center, in step 326, MEAD108 records the latest data retrieved by the terminal and the status and data of the latest session. MEAD108 continuously records and updates information as the user session progresses. That is, MEAD records all relevant information (status and data), including information from the first end-user terminal 106, service center 110, and centralized security server 112, and maintains the current session.
Ultimately, the end user is the first end user terminal 106<sub>c</sub>Determined to leave the session or suspend the current session according to the principles of the invention. In step 328, the user is terminal 106<sub>c</sub>Decide to leave. At step 330, MEAD108 sends a service session end request. In one embodiment, the user presses the end-of-service button on the MEAD108 keypad, thereby the first terminal 106.<sub>c</sub>A termination request is sent to. In step 332, as described above with respect to FIGS. 3A and 3B, an exemplary first terminal 106<sub>c</sub>Sends a message to the network service center 110 to enter standby mode.
In step 334, service center 110 is the first terminal 106<sub>c</sub>Send a confirmation message to. In step 336, terminal 106 sends the final service session data / status to MEAD108 for storage and updates MEAD108 with the latest session information. For example, MEAD108 stores final session information such as final user session data 278, user application data 274, security data 272, user profile data 276, and any other applicable information about the session. ..
In step 338, MEAD is the first terminal 106 of the example.<sub>c</sub>Send a session destruction / lock information message to. In step 340, terminal 106<sub>c</sub>Locks the session data for a session in standby mode and destroys (ie, erases) the end-user identification information stored in terminal 106. When the end user identification information is deleted from the memory of the terminal 106, a confirmation signal confirming the destruction of the user identification information is returned to the MEAD 108 in step 342. In addition, in step 344, terminal 106<sub>c</sub>Sends a replication corruption confirmation message to the central security server 112. Thus, both MEAD108 and security server 112 are notified that the user's identity has been removed from the terminal and the current session of the first terminal has ended.
In step 346, as described above for method 300, the user names the currently suspended session. MEAD108 time stamps the session and locks the session information with a secure key. In this way, the session information in MEAD108 is protected. Therefore, in steps 328-346, the user locks the session data, encodes the locked data with a secure key, and stores the session information in MEAD108 for future access on different end-user terminals. , The current session can be paused. That is, the user can use the illustrated terminal E106 in FIG.<sub>e</sub>You can resume exactly the same session by moving to another end-user terminal, such as, and repeating method 400 on the second terminal.
According to the embodiments illustrated and described herein, a person who wants to interact with a network such as the Internet can obtain information (eg, content) from different end-user terminals. In particular, the user starts an information session on that access network, suspends the current session on the first terminal, and then resumes the same session on the other end user terminal, thereby later another end user. You can move to the terminal. The methods described herein are irrelevant to the type of network to which the terminal is connected. Further, the user can connect to the first network through the first terminal and connect to different networks through different second end-user terminals.
The end user uses a mobile end user agent device (MEAD) 108 that securely establishes a session with the end user terminal, and in one embodiment uses the centralized security server 112 for relevant session information and. Record the data. MEAD108 continuously updates session-related information, and when the user wants to pause the current session, the latest session information is stored there and the session can be restarted later. A suspended session can be restarted on any end-user terminal connected to any type of network.
MEAD108 provides authentication and security features to ensure end-user privacy. Therefore, the transaction between MEAD108 and the end-user terminal 106 is secure and based on end-user authentication. The transaction data with the end user terminal 106 stored in MEAD is stored in the coded format. In one embodiment, the key code coding is changed at regular intervals and the data is encoded and stored at these intervals. Another security feature involves erasing session-related coded data on the end-user terminal when the user suspends or terminates the current session.
Network 100 includes a centralized security server 112, as shown in Figures 3A and 3B and described in this regard. The advantage of implementing a centralized security server 112 is that you can constantly check and monitor end-user security. Further, more end-user information can be stored in the central security server 112 as compared with MEAD108, and the information stored in the central security server 112 can be appropriately downloaded.
Alternatively, the centralized security server 112 is not used, as shown in Method 400 of FIG. 4 and described in this regard. The advantage of this distributed embodiment is that it provides full control of the end user. This embodiment may place more load (or risk) on the end user to make MEAD108 safe. This means that the end user has to carry more authentication and service information on MEAD108. However, the session information stored in MEAD108 is encoded to reduce such security risks.
One advantage of the present invention is that the user can continue the application from where it left off at the previous end-user terminal. Another advantage is that the small size of MEAD eliminates the need for end users to carry (heavy) terminals (such as laptops). For example, the MEAD108 can be integrated with a PDA / phone to form a single device.
Other benefits are that session access / information is available 24/7, at a multi-end user security level, one user can act as a primary user, access a group of users, and end. If the user loses the MEAD108, all the data is encoded and stored securely so that the data is not compromised.
Although various embodiments of the present invention have been described above, other embodiments of the present invention can be devised without departing from the basic scope of the present invention. Therefore, the appropriate scope of the present invention is determined according to the claims set forth above.
<figref num="1">It is a block diagram of the network environment suitable for carrying out this invention.</figref><figref num="2">FIG. 3 is a block diagram of a mobile end-user agent device suitable for performing session switching between end-user terminals according to the principles of the present invention.</figref><figref num="3A">It is a collective flow diagram of the first embodiment of the method of providing session switching between different end-user terminals.</figref><figref num="3B">FIG. 5 is a flow diagram of a first embodiment of a method of providing session switching between different end-user terminals.</figref><figref num="4">FIG. 5 is a flow diagram of a second embodiment of a method of providing session switching between different end-user terminals.</figref>
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| WO2004034192A1 | Cites | World Intellectual Property Organization (WIPO) |
| JP2004511965A | Cites | Japan |
| JP2004537094A | Cites | Japan |
| JP2004201288A | Cites | Japan |
| JP2001523864A | Cites | Japan |
| JP2006502496A | Cites | Japan |
| 蕨野 貴之,端末間のシームレスな切り換えを実現するデバイスハンドオフ方式の提案,情報処理学会研究報告,社団法人情報処理学会,2003年11月14日,第2003巻 第114号,pp.105~112 | Non-patent | – |
| 太田 賢,新概念通信特集,NTT DoCoMoテクニカル・ジャーナル,社団法人電気通信協会,2003年 4月 1日,第11巻 第1号,pp.48~55 | Non-patent | – |
| 太田 賢,モバイルコミュニケーションスタイルを変革する新インタフェース技術,NTT技術ジャーナル,社団法人電気通信協会,2003年 9月 1日,第15巻 第9号,pp.66~70 | Non-patent | – |
13 members in 7 offices
Members13
| Document | Office | Kind | |
|---|---|---|---|
| CN1798083A | China | A | |
| EP1677489A1 | European Patent Office (EPO) | A1 | |
| US2006146767A1 | United States of America | A1 | |
| JP2006191617A | Japan | A | |
| EP1677489B1 | European Patent Office (EPO) | B1 | |
| AT353519T | Austria | T | |
| ATE353519T1 | Austria | T1 | |
| DE602005000543D1 | Germany | D1 | |
| ES2279485T3 | Spain | T3 | |
| DE602005000543T2 | Germany | T2 | |
| CN1798083B | China | B | |
| JP4808024B2This record | Japan | B2 | |
| US8515490B2 | United States of America | B2 |
28 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4808024
- Application
- 377391
Titles2
- Japanese
- エンドユーザ端末間の同一セッションの切り替えを提供する方法および装置
- English
- Methods and devices that provide switching of the same session between end-user terminals
Classification
- CPC, 5
- H04L67/30
- H04W80/04
- H04W80/10
- H04L67/306
- H04L67/14
- IPC, 5
- H04L12 56
- G06F15 00
- H04W40 34
- H04W80 04
- H04W80 10