Encrypted tape access control via challenge-response protocol
Abstract
This record has no abstract on file.
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
12 claims: 12 independent, 0 dependent
- 1By asymmetric encryptionencryptionA step of receiving the symmetric key, the public key related to the asymmetric encryption, and a removable computer-readable medium recording the encoded symmetric encrypted data using the symmetric key by a reader. The public key andGenerated for use as a disposable passwordSend information including random values to the automatic hostHave them select a matching private key using the public keySteps and the public keyThe said selected in connection withSigned by private keyIncluding the above random valueThe step of receiving the response from the host and the signedTo confirm the random value included in the responseIn response, the secret key is used to obtain the symmetric key.AutomatichostTo decryptSteps andThe decryptedA method comprising a step of decrypting the encrypted data using a symmetric key. 非対称暗号化によって暗号化された対称鍵、前記非対称暗号化に関連した公開鍵、前記対称鍵を使って暗号化された対称暗号化データを符号化したものを記録した取外し可能コンピュータ可読媒体を読取装置によって受取るステップと、 前記公開鍵および使い捨てパスワードとして使用するために生成したランダム値を含む情報を自動ホストに送付して当該公開鍵を使用して適合する秘密鍵を選択させるステップと、 前記公開鍵に関連して選択された前記秘密鍵によってサインした前記ランダム値を含む応答を前記ホストから受取るステップと、 前記サインされた応答に含まれる前記ランダム値の確認に応答して、前記秘密鍵を使って前記対称鍵を前記自動ホストに復号させるステップと、前記復号された対称鍵を使って前記暗号化データを復号化するステップと、 を含む方法。
- 2The random value includes a nonce,Claim 1The method described in. 前記ランダム値はナンスを含む、請求項1に記載の方法。
- 3The step of decoding the dataThe hostMade by,Claim 1The method described in. 前記データを復号化するステップは前記ホストによって行われる、請求項1に記載の方法。
- 4The step of decoding the data is performed by the reader.Claim 1The method described in. 前記データを復号化するステップは前記読取装置によって行われる、請求項1に記載の方法。
- 5Encrypted by the asymmetric encryptionThe symmetric key mentioned aboveAutomaticThe step of supplying the host with the reader and the automatic host for use when decrypting the encrypted data.Decrypted with the private key of your choiceThe symmetric key is the readerButIncluding further steps to receive,Claim 4The method described in. 前記非対称暗号化によって暗号化された対称鍵を前記自動ホストに前記読取装置によって供給するステップと、前記暗号化データを復号化するときに使うために前記自動ホストが選択した秘密鍵によって復号化された対称鍵を前記読取装置が受取るステップと、を更に含む、請求項4に記載の方法。
- 6The step of receiving the removable computer-readable medium by the reader comprises the step of receiving a computer tape.Claim 1The method described in. 前記取外し可能コンピュータ可読媒体を読取装置によって受取るステップは、コンピュータ・テープを受取るステップを含む、請求項1に記載の方法。
- 7Information processing device by asymmetric encryptionencryptionA step of receiving the symmetric key, the public key related to the asymmetric encryption, and a removable computer-readable medium recording the encoded symmetric encrypted data using the symmetric key by a reader. The public key andGenerated for use as a disposable passwordSend information including random values to the automatic hostHave them select a matching private key using the public keySteps and the public keyThe said selected in connection withSigned by private keyIncluding the above random valueThe step of receiving the response from the host and the signedTo confirm the random value included in the responseIn response, the secret key is used to obtain the symmetric key.AutomatichostTo decryptSteps andThe decryptedA computer-executable program for performing the steps of decrypting the encrypted data using a symmetric key. 情報処理装置が、 非対称暗号化によって暗号化された対称鍵、前記非対称暗号化に関連した公開鍵、前記対称鍵を使って暗号化された対称暗号化データを符号化したものを記録した取外し可能コンピュータ可読媒体を読取装置によって受取るステップと、 前記公開鍵および使い捨てパスワードとして使用するために生成したランダム値を含む情報を自動ホストに送付して当該公開鍵を使用して適合する秘密鍵を選択させるステップと、 前記公開鍵に関連して選択された前記秘密鍵によってサインした前記ランダム値を含む応答を前記ホストから受取るステップと、 前記サインされた応答に含まれる前記ランダム値の確認に応答して、前記秘密鍵を使って前記対称鍵を前記自動ホストに復号させるステップと、前記復号された対称鍵を使って前記暗号化データを復号化するステップと、 を実行するためのコンピュータ実行可能なプログラム。
- 8The random value includes a nonce,Claim 7The computer program described in. 前記ランダム値はナンスを含む、請求項7に記載のコンピュータ・プログラム。
- 9The step of decoding the data is performed by the automatic host.Claim 7The computer program described in. 前記データを復号化するステップは前記自動ホストによって行われる、請求項7に記載のコンピュータ・プログラム。
- 10The step of decoding the data is performed by the reader.Claim 7The computer program described in. 前記データを復号化するステップは前記読取装置によって行われる、請求項7に記載のコンピュータ・プログラム。
- 11The target key encrypted by the asymmetric encryptionSupply to the host by the readerStepAnd the unwrapped symmetric key from the automatic host for use when decrypting the encrypted data is received by the reader.StepAnd moreTo execute, claim 7.The listed computer program. 前記非対称暗号化によって暗号化された対象鍵を前記ホストに、前記読取装置によって供給するステップと、前記暗号化データを復号化するときに使うために前記自動ホストからの前記アンラップされた対称鍵を、前記読取装置によって受取るステップと、を更に実行する、請求項7に記載のコンピュータ・プログラム。
- 12The step of receiving the removable computer-readable medium by the reader comprises the step of receiving a computer tape.Claim 7The computer program described in. 前記取外し可能コンピュータ可読媒体を読取装置によって受取るステップは、コンピュータ・テープを受取るステップを含む、請求項7に記載のコンピュータ・プログラム。
Independent claims12
107 paragraphs, as filed
The present invention relates to techniques for the secure processing and encryption of data on removable media such as computer tapes and tape drives.
More and more data is written to tape as encrypted data to protect the information in transit. Generally, this data is encrypted with a symmetric key, and it is necessary to have the key in order to decrypt the tape.
Symmetrical encryption, also known as private key cryptography, refers to an encryption method in which both the cryptographic side (or device) and the decryption side (or device) share a single common key value. Symmetrical encryption is a simple one that uses only one key or password value and is designed to run faster. One commonly used encryption method is the Data Encryption Standard (DES).
For example, if a set of database records is written to a tape in preparation for unloading a tape from one data center to another, the administrator will have the data stored on that tape. When present, you may specify a password for a DES encryption routine that encrypts that data. Therefore, the administrator will securely share the password with the intended receipt administrator at the destination data center.
If the tape is stolen, lost, or duplicated in transit, the person or system attempting to decrypt the data will have a private key (eg, password) or cryptographic destruction tool. Without it, the decryption would not be possible. Password breaches are common, but cryptographic decryption tools can also be used against weak cryptographic methods.
When the tape arrives at its destination data center, the administrator there loads the tape, supplies the password to the DES decryption routine, and when the data is read from the tape, it is decrypted and of the database. Will be stored locally in something like.
Thus, the existing means of decrypting a tape is based on the encryption key being loaded into a reading tape drive by an external entity, which encrypts the tape so that it is easily accessible. This is to allow key loading and data reading. This results in a relatively unsafe environment that is difficult to automate.
<p> Therefore, it is an object of the present invention not only to provide data security, but also to provide methods and systems for encrypting and decrypting computer media that are relatively easy to operate.</p>
<p> The present inventor has recognized the unsolved problem that existing tape encryption and processing methods are easy to use, but easy to leak and difficult to automate. The present invention states that a host system that most wants to read the data has a given knowledge of the tape itself when the tape is loaded and before any data is read. Automate the tape loading and decryption process by proving to the drive. This tapes that the tape drive is a "challenge," that is, it generates an appropriate sequence of random numbers, that the host reorders the challenge with known information, and that the reordering is as expected. -This is done by checking the drive. The "challenge" here is a procedure in which a certain value is sent to the other party, the other party encrypts it and sends it back, decrypts it, and compares it with the original value. In this way, tape reading systems and data formats on tape are enhanced to use strong forms of encryption and to use "challenge response" authentication methods.</p>
A. System diagram FIG. 13 shows a component and system configuration 60 according to the invention, which configuration includes a system 62 for creating or creating a removable computer-readable medium 61 with stored encrypted data. Several commonly used removable media 61 to which the present invention can be applied include computer tapes and tape cartridges 52, floppy discs 43, removable hard discs 40, flash or thumb drives 49, compact discs. Discs (eg, CD, CD-ROM, CD-R, CD-RW, etc.) and digital versatile discs (eg, DVD, DVD-R, DVD-RW, etc.) 46, Removable Memory Module (401), And various memory cards (eg CompactFLASH, Secure Data SD, Sony Memory Includes Sticks®, etc.) 47. The present invention is not limited to application to these particular media, but other types of removable computer media in which encrypted data is stored or encoded can also be used. Throughout the following parts of this specification, we will refer to many types of removable media that use computer tapes as a representative example.
The medium 61 is transported to a compatible reader or drive and interconnected to the destination system 64. According to the present invention, the authentication process of the destination system 64 is fully automated, and therefore the administrator does not need to be present to operate the present invention, and if there is an administrator, the administrator interaction is unnecessary.
B. Data structure FIG. 1 shows a removable computer-readable medium, i.e., a data structure according to the invention placed on or within a plurality of media 61, as reference number 100. At least one header area 101 is provided and associated with one or more encrypted data areas 102, such as encrypted data blocks or files. Within the header are at least one asymmetrically encrypted symmetric encryption key EEK103 and at least one associated public asymmetry encryption key KEK-PUB104, both of which are at least one encrypted data area 102. Associated with.
C. General purpose logical process 14 and 15 show the general purpose logic process 70 according to the present invention. FIG. 14 shows the general process of one or more removable computer-readable (CR) media 61, as it yields an asymmetrically encrypted control cryptographic key (EEK). In addition, the administrator-specified symmetric encryption key (EK) itself is encrypted (wrapped) by an asymmetric encryption key (eg, key encryption key KEK) (step 71). The EEK is stored in the header of medium 61 along with a copy of the public part (KEK-PUB) of the asymmetric cryptographic key (step 72).
One or more blocks of data, data files, records, etc. are then symmetrically encrypted using EK (step 73) and the encrypted data is on or in medium 61. Stored or encoded (step 74). The medium 61 is then removed and transported to the destination system (step 75).
Figure 15 is for determining whether the destination system is allowed to access the data and allow it to decrypt the data without requiring the administrator to share the private key. The general purpose logical process 700 according to the present invention is shown. First, the medium 61 is received, installed, and inserted so that a compatible reader or drive can access the encrypted or stored data on or within the removable medium 61. , Attached, or placed (step 701).
The drive or reader generates a random value (eg, a "nonce" (disposable password)) (step 702), which is sent to the destination host with a copy of the public part (KEK-PUB) of the asymmetric cryptographic key (step 703). ).
The destination host receives the nonce and KEK-PUB and uses the KEK-PUB to select a matching secret asymmetric encryption key (KEK-PRIV) (step 704). It then signs a nonce using the KEK-PRIV and the signed nonce is returned to the drive or reader (step 706).
The drive or reader then verifies that the signed value from the host matches the nonce (step 707), and if it is affirmed, either the reader and the host, or two of them. The community uses KEK-PRIV to decrypt the symmetric encryption key EK (step 708), followed by decryption of the data from medium 61 (step 709).
D. Detailed examples 11 and 12 provide embodiments of the invention in the form of more detailed signal flows and show the interactions between the various systems and components arranged according to the invention.
Referring to FIG. 11, according to the first aspect of the present invention, the symmetric encryption key EK is stored in the header data structure on computer tape 52 (transmission step 501). The header data structure itself is encrypted by the tape creation system 51 using an asymmetric encryption key called the key encryption key KEK. The tape maker or user specifies the public portion of the KEK used to "wrap" the EK, resulting in the asymmetrically encrypted symmetric encryption key EEK being stored on the tape. To. In addition, the public part KEK-PUB of the asymmetric cryptographic key is placed on the tape (transmission step 502). The data is then encrypted using the EK through a symmetric key process and then placed on tape (transmission step 503).
According to another aspect of the invention, when a tape should be read or loaded in another system 54, the tape 52 is inserted into the tape drive 53 and the tape drive firmware removes header information from that tape. Read. The tape drive also generates a random value of known length (eg, nonce), such as the 20-byte nonce it holds, and sends it to the host system that is trying to read the tape data (transmission step). 504). The host system provides the public key KEK-PUB by tape drive (transmission step 504) and uses it to respond to the "challenge" and ultimately to decrypt the EK in the header. ..
The host system receives the nonce and KEK-PUB (transmission steps 502, 504), uses the KEK-PUB to determine which private key (KEK-PRIV) to use (step 5100), and then its Sign the nonce with the selected KEK-PRIV and return it to drive 53 (transmission step 505).
The tape drive 53 is then signed by the host using the KEK-PRIV found from the tape header.<u style="single">The value that should be a nonce is</u>Make sure it is the same as the nonce sent to that host (step 5200). If it is affirmed, it successfully completes the challenge (nance to host and KEK-PUB occurrence) and response (correct selection of KEK-PRIV and sign of nonce by host) process. It proves that the host is allowed to access the tape data.
Finally, according to another embodiment of the invention, the host receives a KEK-protected EK from the tape drive (transmission step 501) and uses its selected and proven KEK-PRIV to create a symmetric EK. The decryption (step 5300) is followed by decryption of the encrypted data on the tape using the decrypted EK and the matching symmetric compounding process (step 5400). This Example 50 assumes that the tape driver does not decrypt the tape data for the host, but instead supplies the host with encrypted data and the host decrypts that data. There is.
However, according to another embodiment of the invention as shown in FIG. 12, this latter part of process 50'is tape data if the host supplies the correct symmetric encryption key (transmission step 506). Is adjusted to perform decryption (unwrap) (step 5400'). Therefore, in this modification of this embodiment, the host decodes the EK using the KEK-PRIV selected during the challenge-response phase (step 5100) (step 5300), and then tapes the EK. Send to drive 53 (transmission step 506). The tape drive 53 then doubles the tape data (step 5400') and sends the unprotected or decrypted data to the host (transmission step 507).
E. Appropriate encryption method It is also possible to use some suitable standard or proprietary asymmetric encryption method to protect the symmetric encryption key. For example, use asymmetric cryptography according to the well-known Rivest-Shamir-Adlema (RSA) method, the well-known "pretty good privacy" (PGP), or separately, according to the well-known "Digital Signature Algorithm (DSA)". It is also possible to use a well-known process such as DES for symmetric encryption.
F. Appropriate computing platform In one embodiment of the invention, the logical process described above may be a computer such as an embedded microcontroller, personal computer, web server, web browser, or personal digital assistant (PDA), web enable. It is performed partially or entirely by software that is run by a unique computing platform such as a wireless telephone or other type of personal information management (PIM) device.
Therefore, it is beneficial to review the general-purpose architecture of computing platforms in embodiments ranging from high-end web or enterprise server platforms to personal computers, portable PDAs, or web-enabled radiotelephones.
Refer to Figure 2 to show a general purpose architecture that includes a central processing unit (CPU) 21. The CPU 21 generally consists of a random access memory (RAM) 24 and a microprocessor 22 associated with a read-only memory (ROM) 25. In many cases, CPU 21 also includes cache memory 23 and programmable flash ROM 26. The interface between the microprocessor 22 and various types of CPU memory is often referred to as the "local bus", but may be a more general bus or industry standard bus.
Many computing platforms include hard disk drives (HDDs), zip disk drives, compact disc drives (CDs, CD-Rs, CD-RWs, DVDs, DVD-Rs, etc.), as well as proprietary discs. It also has a tape drive (eg, Iomega Zip®, Jaz®, Addonics SpurDisk®, etc.). Further, some storage drives may be accessible via a computer network.
Many computer platforms have one or more communication interfaces according to the intended functionality of the computer platform. For example, personal computers often have high-speed serial ports (RS-232, RS-422, etc.), enhanced parallel ports (EPP), and one or more universal serial bus (USB) ports. It has. Computing platforms include local area network (LAN) interfaces such as Ethernet cards and other high-speed interfaces such as High Performance Serial Bus IEEE-1394. It is also possible to provide.
Computing platforms such as radiotelephones and wireless network PDAs can also have radio frequency (RF) interfaces along with antennas. In some cases, the computing platform can also include an infrared data configuration (IrDA) interface.
Computing platforms are often one or more internal extensions such as Industry Standard Architecture (ISA), Enhanced Industry Standard Architecture (EISA), Peripheral Component Interconnect (PCI). It has slot 211, or a unique interface slot for adding other hardware such as voice cards, memory boards, and graphics accelerators.
In addition, many units such as laptop computers and PDAs have hardware expansion devices such as PCMCIA cards, SmartMedia® cards, and removable hard drives, CD drives, and floppy drives. It features one or more expansion slots 212 that allow the user the ability to easily install and remove a variety of unique modules.
Often, the storage drive 29, communication interface 210, internal expansion slot 211, and external expansion slot 212 are with CPU 21 via standard or industry open bus architecture 28 such as ISA, EISA, or PCI. To be interconnected. In many cases, the bus 28 may be of its own design.
Computing platforms typically include one or more input devices such as a keyboard or keypad 216 and a mouse or pointer device 217 and / or a touch screen display 218. For personal computers, a full-size keyboard is provided with a mouse or pointer device such as a trackball or TrackPoint®. For web-enabled radiotelephones, a simple keypad has one or more function-specific keys. In the case of PDAs, the touch screen 218 is often equipped with handwriting recognition.
Microphones 219, such as web-enabled radiotelephone microphones or personal computer microphones, are supplied with computing platforms. This microphone is used simply to convey audio and voice signals, it uses voice recognition capabilities to enter user choices such as voice navigation on websites, or to auto-dial phone numbers. It can also be used for.
Many computing platforms also include a camera device 2100, such as a steel digital camera or a full-motion video digital camera.
One or more user output devices, such as the Display 213, are provided with most computing platforms. The display 213 can take many forms, including a cathode ray tube (CRT), a thin film transistor (TFT) array, or a simple set of light emitting diodes (LEDs) or liquid crystal displays (LCDs).
Often, one or more speakers 214 and / or alarm 215 are also associated with the computing platform. Speakers 214 can be used to play voice and music, such as radiotelephone speakers or personal computer speakers. The alarm 215 can also take the form of a simple beep generator or buzzer commonly found in certain devices such as PDAs and PIMs.
User input and output devices may be interconnected directly to CPU 21 via a proprietary bus structure and / or interface, or one or more industry open such as ISA, EISA, PCI, etc. -It may be interconnected via a bus.
A computing platform can also include one or more software and firmware 2101 programs to embody the desired functionality of the computing platform.
Next, reference to FIG. 3 provides further details regarding the general purpose configuration of software and firmware 2101 in this range of computing platforms. One or more operating system (OS) native application programs such as word processors, spreadsheets, contact management utilities, address books, calendars, email clients, presentations, financial and bookkeeping programs 223 It can also be installed on a computing platform.
In addition, it is possible to implement one or more "portable" or device independent programs 224. The program must be interpreted by an OS native platform-specific interpreter 225, such as Java® scripts and programs.
Often, the computing platform is provided in the form of a web browser or micro browser 226 that may include one or more extensions to the browser, such as the browser plug-in 227 .
Computing devices are often Microsoft Windows®, UNIX®, IBM OS / 2®, IBM AIX®, open source LINUX, and Apple's MAC OS (registered). It has an operating system 220, such as a trademark), or other platform-specific operating system. Small devices such as PDAs and radiotelephones can also include real-time operating systems (RTOS) or other types of operating systems such as Palm Computing's PalmOS®.
A set of basic input / output systems (BIOS) and hardware device drivers 221 often allow the operating system (220) and programs to interface with specific hardware features provided by the computing platform. And it is provided to make it possible to control it.
In addition, one or more embedded firmware programs 222 share many computing platforms in common, with a microcontroller or hard drive, communication processor, network interface card, or voice or graphics card. It is run by an onboard or "embedded" microprocessor as part of a peripheral such as.
As such, FIGS. 2 and 3 include, but are not limited to, personal computers, PDAs, PIMs, web enabled phones, and other devices such as WebTV® units. The various hardware components of the platform, as well as the software and firmware components, are generally shown. Next, we will pay attention to the disclosure of the present invention regarding processes and methods that should be implemented as software and firmware on such computer platforms. Apart from this, it will be readily apparent to those skilled in the art that the following methods and processes can also be implemented as hardware features in part or in whole without departing from the spirit and scope of the invention. Will.
G. Service-based examples Another embodiment of the present invention is to configure software, deploy software, download software, distribute software, or distribute software to provide a logical control process for a high-performance washing machine. Includes some or all of the aforementioned logical processes and functions of the invention provided by servicing clients remotely in an on-demand environment.
H. Examples of software development According to an embodiment of the invention, the methods and processes of the invention are distributed or deployed as a service by a service provider to a client's computing system.
With reference to Figure 4, the deployment process, when it starts (step 3000), determines if any resident program exists on the server when the process software runs (step 3001). If it exists, the server containing the executable is identified (step 309). The process software for the server is transferred directly to the server storage device, either via FTP or some other protocol, or by copying through the use of a shared file system (step 310). After that, the process software is installed on the server (step 311).
The decision is then made as to whether the process software should be deployed by giving the user access to the process software on the server (step 3002). If the user should access the process software on the server, the server address that is likely to store the process software is identified (step 3003).
In step 3004, by sending the process software to the user via email, a decision is made as to whether the process software should be developed. The set of users on which the process software should be deployed is identified along with the address of the user client computer (step 3005). The process software is sent by email to each of the user's client computers. The user then receives the email (step 305) and then retrieves the process software from the email to a directory on the client computer (step 306). The user runs a program that installs the process software on his client computer (step 312) and then terminates the process (step 3008).
A decision is made as to whether a proxy server should be formed to store the process software (step 300). A proxy server is a server located between a client application such as a web browser and a real server. The server intercepts all requests to the real server to see if it can meet the request itself. If it cannot meet the request, it sends the request to the real server. The two main benefits of a proxy server are improving performance and filtering requests. If a proxy server is required, it will be installed (step 301). The process software is sent to the server via a protocol such as FTP, or it is copied directly from the source file to the server file via file sharing (step 302). Another embodiment sends a transaction to a server containing the process software to have the server process process the transaction, after which it receives the process software and copies it to the server's file system. Once the process software is stored on the server, the user accesses the process software on the server through their client computers and copies the file system to those client computers (step 303). Yet another embodiment causes each client to automatically copy the process software to a server and run an installation program for the process software on each client computer. The user runs a program that installs the process software on his client computer (step 312) and then terminates the process (step 3008).
Finally, a decision is made as to whether the process software will be sent directly to the user directory on those client computers (step 3006). If it is affirmed, the user directory is identified (step 3007). The process software is transferred directly to the user's client computer directory (step 307). This can be a shared file system directory, then a copy from the sending file system to the receiving user's file system, or a separate transfer, such as the File Transfer Protocol (FIP). It can be done in several ways, such as using a protocol, but is not limited to it. The user accesses the directories in their client file system in preparation for installing the process software (step 308). The user runs a program that installs the process software on his client computer (step 312) and then terminates the process (step 3008).
I. Software integration example According to another embodiment of the invention, software that implements the methods and processes disclosed herein is integrated into another software application, applet, or computing system as a service by a service provider. ..
The integration of the present invention generally provides the process software to coexist with the software of the application, operating system, and network operating system, and then the client and in the environment in which the process software works. Includes installing process software on the server.
Generally speaking, the first task is on the client and server, including the network operating system in which the process software is deployed, and is required by or works in connection with the process software. It is to identify with any software. It includes network operating systems, which are software that enhances the underlying operating system by adding networking features. The software application and version number will then be identified and compared to the list of tested software application and version number to work with the process software. Software applications that are not found or that do not match the correct version will be upgraded with the correct version number. Program instructions that send parameters from the process software to the software application will be checked to ensure that the parameter list matches the parameter list required by the process software. Conversely, the parameters sent by the software application to the process software will be checked to ensure that those parameters meet the parameters required by the process software. Client operating systems, including network operating systems, and server operating systems are identified and compared to a list of operating systems, version numbers, and network software that have been tested to work with process software. There will be. The client and the operating system, version number, and network software that do not match the list of tested operating systems and version numbers.
The integration is completed by installing the process software on the client and server after ensuring that the software on which the process software should be deployed is at the correct version level that has been tested to work with the process software. To do
Reference is made to the details of the integration process according to the present invention. When the integration starts (step 320), it determines if any process software program to be executed exists on the server (step 321). If it does not exist on the server, the integration proceeds to step 327. If it is affirmed, the server address is identified (step 322). The server is checked to see if the server has software, including operating system (OS), applications, and network operating system (NOS), along with their version numbers tested with process software. (Step 323). The server is also checked to determine if there is any software missing required by the process software (step 323).
A determination is made as to whether the version number matches the OS, application, and NOS version numbers tested by the process software (step 324). If all version numbers match and there are no missing software requirements, the integration will continue (step 327).
If one or more version numbers do not match, the unmatched version is updated with the correct version on the server (step 325). In addition, any software oversights required are updated on the server (step 325). The server integration is complete by installing the process software (step 326).
Step 327, which follows step 321, 324, or 326, determines if there is a process software program running on the client. If there is no process software program running on the client, the integration proceeds to step 330 and ends. If there is such a process software program, the client address is identified (step 328).
The client is checked to find out if the client has software that includes an operating system (OS), application, and network operating system (NOS), along with a version number tested by the process software ( Step 329). The client is also checked to determine if there is any software missing required by the process software (step 329).
A determination is made as to whether the version number matches the OS, application, and NOS version numbers tested by the process software (step 331). If all version numbers match and there are no missing software requirements, the integration proceeds to step 330 and ends.
If one or more version numbers do not match, the client updates the unmatched version with the correct version (step 332). In addition, any missing software required is updated on the client (step 332). Client integration is completed by installing the process software on the client (step 333). The integration proceeds to step 330 and ends.
Examples of J. On-Demand Computing Services According to another aspect of the invention, the processes and methods disclosed herein are carried out by a service provider through an on-demand computing architecture to serve a client.
With reference to FIG. 6, generally speaking, the process software that implements the methods disclosed herein is shared and at the same time works in a flexible and automated manner for multiple customers. It is standardized with little customization, and it is extensible to provide the ability on demand in the "pay-as-you-go" model.
The process software can also be stored on a shared file system that can be accessed by one or more servers. Process software is executed through transactions that include data and server processing requests that use per CPU on the accessed server. CPU units are time units such as minutes, seconds, and hours in the server's central processor. Furthermore, the accessed server can also make a request to another server that requires a CPU unit. A CPU unit is just an example of a single usage measurement. Other usage measurements include, but are not limited to, network bandwidth, memory usage, storage device usage, packet forwarding, complete transactions, and the like.
When multiple customers use the same process software application, those transactions are distinguished by the parameters contained in that transaction that identify the only customer and the type of service for that customer. All CPU units and other usage measurements used to service each customer are recorded. When the number of transactions for one server reaches the number that begins to affect the performance of that server, the other server is accessed to increase capacity and share the workload. Similarly, when other usage measurements such as network bandwidth, memory usage, storage usage, etc. approach capacity that is likely to affect performance, additional network bandwidth, memory usage, storage, etc. Usage etc. are added to share the workload.
Usage measurements for each service and customer are usage measurements for each customer processed somewhere in the network of servers that perform shared execution of the process software. Sent to the collection server to sum. The sum of the measurements for the units of use is multiplied by the unit cost, and the resulting total process software application service cost is sent to the customer and displayed on the website accessed by the customer. Therefore, the customer entrusts the payment to the service provider.
In another embodiment, the service provider directly requests payment from the customer's account at a bank or financial institution.
In another embodiment, if the service provider is also a customer who uses the process software application, the payment incurred by the service provider is incurred by the service provider to minimize the transfer of payments. Will be arbitrated for payment.
FIG. 6 shows a detailed logical process that makes the invention available through an on-demand process. A transaction is created that includes a unique customer identification, the type of service requested, and any service parameters that further specify the type of service (step 341). The transaction is then sent to the main server (step 342). In the on-demand embodiment, the main server is initially the only server, and then as capacity is customized, other servers are added to the on-demand environment.
The capacity of the server's central processing unit (CPU) in an on-demand environment is queried (step 343). The CPU requirements of the transaction are estimated, then the available CPU capacity of the server in the on-demand environment is compared to the CPU requirements of the transaction, and which server has enough CPU available to process the transaction. Also know if it exists (step 344). If sufficient server CPU capacity is not available, additional server CPU capacity is allocated to handle the transaction (step 348). If sufficient CPU capacity already exists, the transaction is sent to the selected server (step 345).
Before executing a transaction, the remaining on-demand environment is checked to determine if it has sufficient available capacity to handle the transaction (step 346). .. The capacity of the environment includes, but is not limited to, network bandwidth, processor memory, storage devices, and the like. If there is not enough capacity, capacity is added to the on-demand environment (step 347). The software needed to process the transaction is then accessed, loaded into memory, and then the transaction is executed (step 349).
Usage measurements are recorded (step 350). Usage measurements include the portion of a function in an on-demand environment that is used to process that transaction. Use of such features records usage of features including, but not limited to, features such as network bandwidth, processor memory, storage, and CPU cycles. Usage measurements are added up, multiplied by the unit cost, and then recorded as usage to the requesting customer.
If the customer requests that the on-demand costs be sent to the website (step 352), they will be sent (step 353). If the customer requests that the on-demand costs be sent by email to the customer address (step 354), they will be sent (step 355). If the customer requests that the on-demand cost be paid directly from the customer's account (step 356), the payment is received directly from the customer's account (step 357). The final step is to get out of the on-demand process (step 358).
Example of K.VPN deployment According to another aspect of the invention, the methods and processes disclosed herein are partially or wholly implemented by software that may be deployed to a third party as part of a service. In this case, a third party virtual private network (VPN) service is proposed as a secure deployment means or is formed on demand when needed for a particular deployment.
A virtual private network (VPN) is any combination of technologies used to secure non-secure or non-trusted networks in other situations. A VPN utilizes a public network, typically the Internet, to connect remote sites or users to each other. Instead of using a dedicated real-world connection, such as a dedicated line, a VPN uses a "virtual" connection that is routed to a remote site or employee over the Internet from a company's dedicated network. Access to software over a VPN is provided as a service by specifically configuring the VPN for the distribution or execution of process software (ie, the software exists elsewhere). Note that the lifetime of a VPN is limited to a given period or number of deployments, based on the amount paid.
The process software is deployed, accessed, and executed through a remote access VPN or site-to-site VPN. When using a remote access VPN, the process software is deployed, accessed, and executed through a secure encrypted connection between the enterprise's private network and remote users through a third-party service provider. .. Enterprise service providers (ESPs) set up network access servers (NAS) and provide desktop client software for their computers to remote users. Teleworkers dial a free call number to reach the NAS to connect directly via a cable or DSL modem, use VPN client software to access the corporate network, access process software, and It can be downloaded and run.
When using a site-to-site VPN, the process software is deployed through dedicated facilities and large-scale encryption used to connect multiple fixed sites of the enterprise over a public network such as the Internet. Is, accessed, and executed.
Process software is carried over a VPN by tunneling, which is the process of putting an entire packet into another packet and sending it over a network. The protocol for external packets is understood by the network and both points, called tunnel interfaces, where packets enter and exit the network.
With reference to Figure 7, the VPN deployment process begins by deciding if a VPN is needed for remote access (step 361). If it is not needed, the process proceeds to step step 362. If it is required, the process determines if a remote access VPN exists (step 364).
If a VPN exists, the VPN deployment process proceeds to access the network connected to the server (step 365). Otherwise, the process identifies a third-party provider that provides a secure encrypted connection between the enterprise's private network and the enterprise's remote users (step 376). The remote user of the enterprise is identified (step 377). Third-party providers then set up a network access server (NAS) that allows remote users to dial free call numbers or connect directly via a broadband modem. (Step 378), access, download, and install desktop client software for remote access VPN (step 379).
After a remote access VPN is formed, or if it was pre-installed, remote users can dial the NAS or connect directly to the NAS via a cable or DSL modem. You can access the process software (step 365). This allows entry into the enterprise network where the process software is accessed (step 366). The process software is transported over the network to the remote user's desktop by tunneling. That is, the process software is split into packets, and each packet containing the data and protocol is placed within another packet (step 367). When the process software reaches the remote user's desktop, it is removed from the packet, reconfigured, and executed on the remote user's desktop (step 368).
A decision is made to know if a VPN is required for site-to-site access (step 362). If it is not needed, the process proceeds to termination (step 363). If it is required, it is determined whether site-to-site VPN access exists (step 369). If it exists, the process proceeds to step 371. If it does not exist, the dedicated equipment needed to set up a site-to-site VPN will be installed (step 370). There, large-scale encryption is formed in the VPN (step 371).
After a site-to-site VPN is formed, or if it was preconfigured, users access the process software over the VPN (step 372). The process software is tunneled to the site user over the network. That is, the process software is split into packets, and each packet containing the data and protocol is placed within another packet (step 374). When the process software reaches the remote user's desktop, it is removed from the packet and executed on the site user's desktop (step 375). The process proceeds to termination (step 363).
L. Examples of computer-readable media In another embodiment of the invention, the logical process according to the invention and described herein for controlling a washing machine is encoded on or within one or more computer-readable media. To. Some computer-readable media are read-only (eg, the media must first be programmed with a different device than the device ultimately used to read the data from the medium). The media are write-only (eg, from the data encoder's point of view, they can only be encoded, but not read at the same time), or they are read-write. Yet other media are one-time writes and multiple reads.
Some media are relatively fixed within their mounting mechanism, while other media are removable or even transportable. When all computer-readable media are encoded by data and / or computer software, they form two types of systems: That is, (a) When removed from a drive or reading mechanism, they are memory devices that produce useful data-driven outputs when activated by appropriate electromagnetic, electronic, and / or optical signals. (b) When loaded into a drive or reading mechanism, they form a data repository system that can be accessed by a computer.
FIG. 8 shows several computer-readable media, including a computer hard drive 40 with one or more magnetically coded platters or disks 41. It should be noted that the platter or disc 41 can be read, written, or both by one or more heads 42. Such a hard drive is typically mounted semi-permanently on a complete drive unit, which is then a configurable computer system such as a personal computer, server computer, etc. May be integrated into.
Similarly, another example of a computer-readable medium is a flexible removable "floppy disk" 43 that is inserted into a drive containing an access head. Floppy disks typically include magnetically codeable disks that can be accessed by the drive head through the window 45 on the slide cover 44.
A compact disc (CD) 46 is a plastic disc that is typically encoded using an optical process and / or a magneto-optical process and then generally read using an optical process. Some CDs are read-only (CD-ROM) and are mass-produced prior to distribution and use by read-type drives. Other CDs are writable only once or multiple times (eg, CD-RW, CD-R). Digital versatile discs (DVDs) are often high-end CDs that also include double-sided coding of data, as well as multi-layer coding of data. Like floppy disks, CDs or DVDs are removable media.
Another popular removable medium is CompactFlash (CF) 47, Secure Data (SD), Sony MemoryStick, Universal Serial Bus (USB) FlashDrive. And some types of removable circuit-based (eg, solid state) memory drives such as "Thumbdrives" 49, and others. These devices are typically in plastic housings that incorporate digital memory chips such as random access memory chips (RAM) with battery backup or flash read-only memory (FrashROM). is there. One or more electronic connectors 48, 400 for engaging connectors such as CF drive slots or USB slots can be used on the outer part of the medium. Devices such as USB FlashDrive are accessed using the serial data method, while other devices such as CF are accessed using the parallel method. These devices often provide faster access times than disk-based media, providing increased reliability and reduced sensitivity to mechanical shocks and vibrations. In many cases, they offer lower storage capacity than comparable priced disk-based media.
Yet another type of computer-readable medium device is the memory module 403, often referred to as SIMM or DIMM. Like CF, SD, and FlashDrive, these modules contain one or more memory devices 402, such as dynamic RAM (DRAM) mounted on circuit board 401. The circuit board 401 has one or more electronic connectors for engaging and interfacing other circuits such as the motherboard of a personal computer. These types of memory modules are usually not confined within the outer housing when they are intended for installation by a skilled technician, and are generally protected by a larger outer housing, such as the chassis of a personal computer. Will be done.
Next, with reference to FIG. 9, another embodiment option 405 of the present invention is shown, in which the computer-readable signal is encoded by software, data, or both that embody a logical process in accordance with the present invention. Will be done. FIG. 9 is generalized to represent the functionality of wireless transmission systems, wired transmission systems, electro-optical transmission systems, and optical signal systems. For example, the system shown in FIG. 9 can be implemented in a manner suitable for radio frequency (RF) radio transmission and optical signal radio transmission such as infrared data arrangement (IrDA). The system of FIG. 9 is a data transmitter for a USB system, such as a drive for reading the USBFlashDrive, or a drive for accessing data stored directly in a disk, such as a CD or hard drive platter. , A data receiver, or another way to act as a data transmitter / receiver.
In general, the microprocessor or microcontroller 406 reads, writes, or both reads and writes data, programs, or both to and from storage 407. The data interface 409, which optionally includes a digital-to-analog converter, works with the optional protocol stack 408 to send, receive, or send and receive data between the system front end 410 and the microprocessor 406. .. The protocol stack adapts to the type of signal sent, received, or sent / received. For example, in a local area network (LAN) embodiment, the protocol stack may implement Transmission Control Protocol / Internet Protocol (TCP / IP). In computer-to-computer or computer-peripheral embodiments, the protocol stack may implement all or part of USB, FireWire, RS-232, Point-to-Point Protocol (PPP), and so on.
The front end or analog front end of the system adapts to the type of signal being modulated, demodulated, or transcoded. For example, in RF-based system 413, the analog front end embodies signal formats such as frequency modulation (FM), amplitude modulation (AM), phase modulation (PM), pulse code modulation (PCM), etc. Includes various local transmitters, modulators, demodulators, etc. Such RF-based embodiments typically include antennas for transmitting, receiving, or transmitting electromagnetic signals over the atmosphere, water, earth, or over RF waveguides, and coaxial cables. Including 414. Some common aerial transmission standards are BlueTooth, Global System for Mobile Communications (GSM), Time Division Multiple Access (TDMA), Advanced Mobile Telephone Service (AMPS), and Wireless Fidelity (Wi-Fi). ).
In another embodiment, the analog front end signals through a laser-based optical interface (eg, wavelength division multiplexing, SONET, etc.) or an optical interface 415 such as an infrared data communication standard (IrDA). Can be adapted to send, receive, or send and receive. Similarly, the analog front end uses a cable interface that can include examples such as USB, Ethernet, LAN, twisted pair cable, coaxial cable, plain old telephone service (POTS), etc. , Can be adapted to transmit, receive, or transmit and receive signals via cable 412.
Signals transmitted, received, or transmitted and received and data encoded on disk or in memory can also be coded to protect it from unauthorized decoding and use. Other types of coding may be used to enable error detection and, in some cases, error correction, such as by adding a parity bit or cyclic redundancy check (CRC). Other types of coding can also be used to allow directing or "routing" of data to the correct destination, such as packet and frame-based protocols.
FIG. 10 shows a conversion system that converts parallel data to serial data and parallel data from serial data. Parallel data is most often directly available to the microprocessor and is often formatted in 8-bit wide bytes, 16-bit wide words, 32-bit wide double words, and so on. Parallel data can represent executable or interpretable software, or can represent data values for use by a computer. Data is often serialized to transmit it over a medium such as an RF or optical channel, or to record it on a medium such as a disk. As such, many computer-readable media systems include circuits, software, or both for serializing and reparalleling data.
Parallel data 421 is each bit D<sub>0</sub>-D<sub>n</sub>Is represented as a time-aligned flow of data signals such that parallel data units (bytes, words, double words, etc.) 422, 423, 424 are transmitted by being on a bus or signal carrier at the same time. The "width" of the data unit is n-1. On some systems D0 is used to represent the least significant bit (LSB) and on other systems it is used to represent the most significant bit (MSB). Data is serialized by sending one bit at a time so that each data unit is sent one after another in a serial fashion, generally according to a protocol.
Thus, the parallel data stored in computer memory 407, 407'is often accessed via the parallel bus 421 by the microprocessor or parallel / series converters 425, 425', and the series bus 421'. Exchanged via (eg, send, receive, or send and receive). The received serial data is usually converted to parallel data before it is stored in computer memory. The serialized data 421'generalized in FIG. 10 may be a wired bus such as USB or Firewire, or may be a wireless communication medium such as RF or optical channel as described above.
As such, the various embodiments of the invention include software, data, or both according to the logical process of the invention, including, but not limited to, computer-readable media of the type described above. Computer programs and systems that can be achieved by encoding within, thereby providing useful programming instructions, data, or both when properly read, received, or decoded. Occurs.
M. Knot Although the details of the various examples have been described, it is possible to introduce changes at the time of embodiment such as various programming methods, computing platforms, and processing techniques without departing from the gist and scope of the present invention. It will be obvious to those skilled in the art. Therefore, the scope of the present invention should be determined by the description of "Claims".
<figref num="1">It is the schematic of the data structure by this invention.</figref><figref num="2">It is a schematic diagram of a general-purpose computing platform architecture.</figref><figref num="3">FIG. 2 is a schematic diagram of a general-purpose organization of software and firmware for the computing platform architecture shown in FIG.</figref><figref num="4">It is a flowchart which shows the logical process for deploying software to the client which carries out the method and process of this invention.</figref><figref num="5">It is a flowchart which shows the logical process which integrates software into another software program. The integrated software implements the methods and processes of the present invention.</figref><figref num="6">It is a flowchart showing a logical process for executing software on behalf of a client in an on-demand computing system. The executed software implements the methods and processes of the present invention.</figref><figref num="7">It is a flowchart which shows the logical process for deploying software to a client via a virtual private network. The deployed software implements the methods and processes of the present invention.</figref><figref num="8">FIG. 6 is a schematic representation of various removable and fixed computer readable media.</figref><figref num="9">It is a schematic diagram of the coding of a computer-readable signal in a signal transmitter / receiver.</figref><figref num="10">It is the schematic of the system which converts parallel data into serial data, and serial data into parallel data.</figref><figref num="11">FIG. 5 is a schematic diagram showing communication and interaction between systems and components arranged and co-used according to the present invention.</figref><figref num="12">FIG. 5 is a schematic diagram showing communication and interaction between systems and components arranged and co-used according to the present invention.</figref><figref num="13">It is a schematic diagram which shows the arrangement of the system and the component by this invention.</figref><figref num="14">It is a flowchart which shows the logical process for creating a data structure according to this invention.</figref><figref num="15">FIG. 5 is a flow chart showing a logical process for controlling access to encrypted data on a removable computer medium according to the present invention.</figref>
4 priority claims, no other members on record
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 11557776 | United States of America | – | |
| 55777606 | United States of America | A | |
| 2006557776 | – | – | – |
| US20060557776 | – | – | – |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Notification of resignation of power of sub attorneyRD14 | RD14 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Transfer of reconsideration by examiner before appeal (zenchi)AppealA911 | A911 | |
| Written amendmentA521 | A521 | |
| Decision of refusalA02 | A02 | |
| Written amendmentA521 | A521 | |
| Written amendmentA521 | A521 | |
| Notification of acceptance of power of sub attorneyRD12 | RD12 | |
| Notification of reasons for refusalA131 | A131 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 5390086
- Publication, DOCDB
- 5390086
- Publication, EPODOC
- JP5390086B
- Application
- 278473
- Application, DOCDB
- 2007278473
- Application, EPODOC
- JP20070278473
Titles2
- Japanese
- チャレンジ・レスポンス・プロトコルによる暗号化テープ・アクセス制御方法およびシステム
- English
- Cryptographic tape access control method and system using challenge-response protocol
Classification
- CPC, 2
- G06F21/6209
- G06F2221/2107
- IPC, 1
- H04L9 08