Alias hiding in network data repositories
Abstract
This record has no abstract on file.
Term
1.5 yearsto projected expiry
Projected expiry 8 April 2028, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
19 claims: 17 independent, 2 dependent
- 1Objections to patent Zastrzeżenia patentowe 1. A method of transmitting data in the directory (900) multiple spot units outside of the system, comprising:1. Sposób udostępniania danych w katalogu (900) przez liczne żądające jednostki spoza systemu, zawierający: moduł rozpoznawania nazw (909) skonfigurowany do wyznaczenia położenia danych w katalogu (900) poprzez znalezienie ścieżki do wpisu (504f) zawierającego dane z wykorzystaniem ścieżki aliasu i instrukcji do dereferencji aliasu, przy czym moduł rozpoznawania nazw (909) jest dodatkowo skonfigurowany do wyznaczania lokalizacji poprzez wyznaczenie rozróżnionej nazwy dla wpisu (504f), gdzie rozróżniona nazwa dla wpisu (504f) identyfikuje lokalizację wpisu (504f) w katalogu (900);the recognition module names (909) configured to determine the location of data in the directory (900) by finding the way to the entry (504f) that contains the data using a path alias and the user to dereferencji alias, and the recognition module names (909) further configured to determine the location by assigning rozróżnionej a name for the entry (504f), where rozróżniona a name for the entry (504f) determines the location of the entry (504f) in the directory (900);moduł wyszukiwania/aktualizacji (911) skonfigurowany do wykonywania działań na danych wpisu (504f) z wykorzystaniem lokalizacji wpisu (504f) w katalogu (900) oraz instrukcji dereferencji aliasu;a także moduł ukrywania aliasu (903) skonfigurowany do: search module/upgrade (911) configured to work on data entry (504f) using the location of the entry (504f) in the directory (900) and instructions dereferencji alias;and module suppression the alias (903) configured to: accept requests to perform operations on the data in the first post (902) stored in the directory (900) sent by demand unit (920), where the query includes a path alias to the first entry (902) in the directory (900);a search of the user stored within the system about dereferencji alias relating to the sender unit (920);przejmowania żądania w celu wykonania działania na danych w pierwszym wpisie (902) przechowywanym w katalogu (900) wysłanego przez żądającą jednostkę (920), gdzie żądanie to zawiera ścieżkę aliasu do pierwszego wpisu (902) w katalogu (900);lokalizowania instrukcji przechowywanych wewnątrz systemu dotyczących dereferencji aliasu odnoszących się do żądającej jednostki (920);deliver tracks the alias for the recognition module names (909) along with the located instructions for alias dereferencji in relation to the sender unit (920);and receiving from the recognition module names (909) detection of location data in the directory (900), as well as trails generated from dereferencji alias for the element that contains the data;and require the search module/upgrade (911) on data of the recognized locations through dostarczenia ścieżki aliasu do modułu rozpoznawania nazw (909) wraz ze zlokalizowanymi instrukcjami dla dereferencji aliasu dotyczącej żądającej jednostki (920);a także odbioru z modułu rozpoznawania nazw (909) rozpoznanej lokalizacji danych w katalogu (900) oraz ścieżki powstałej z dereferencji aliasu do znalezionego wpisu, który zawiera dane;i żądania od modułu wyszukiwania/aktualizacji (911) wykonania działania na danych w rozpoznanej lokalizacji poprzez 55P31384PL00 55P31384PL00 109 109 EP 2 156 649 B1 dostarczenie żądanego działania i zlokalizowanych instrukcji dla dereferencji aliasu;EP 2 156 649 B1 giving the desired action and localized guidelines for dereferencji alias;przy czym system ten jest znamienny tym, że: what this system differs in that: moduł ukrywania aliasu (903) jest ponadto skonfigurowany do wykonania raportu do żądającej jednostki (920) o tym, że wykonano działanie na danych w pierwszym wpisie (902) zastępując ścieżkę do danych uzyskaną z dereferencji aliasu oryginalną ścieżką poprzez zmodyfikowanie wyników wygenerowanych przez moduł wyszukiwania/aktualizacji (911) tak, aby odnosiły się do ścieżki aliasu dostarczanej przez żądającą jednostkę (920) zamiast rozpoznanego wpisu ścieżki uzyskanej z dereferencji aliasu. the module hide the alias (903) further is configured to run the report for the sender unit (920) that the work was performed on the data in the first post (902) replacing the data path obtained from dereferencji alias original way, changing the results generated by the search module/upgrade (911) therefore, to treat the path of the alias provided by the demand unit (920) is detected the recording of the track value dereferencji alias.
- 2The system according to objection 1, wherein the search module/upgrade (911) in addition, is configured to:2. System według zastrzeżenia 1, w którym moduł wyszukiwania/aktualizacji (911) jest ponadto skonfigurowany do: determining that the second child record in relation to the detected location comprises a second alias;wyznaczania, że drugi wpis podrzędny względem rozpoznanej lokalizacji zawiera drugi alias;rozpoznania drugiego aliasu w celu wyznaczenia trzeciego wpisu w drugiej ścieżce uzyskanej z dereferencji aliasu;a także wykonania działania na danych w trzecim wpisie;the diagnosis of the second alias to determine a third parameter to another trajectory obtained dereferencji alias;as well as run data in the third post;gdzie moduł ukrywania aliasu (903) jest ponadto skonfigurowany do zastąpienia drugiej ścieżki uzyskanej z dereferencji aliasu do trzeciego wpisu ścieżką do drugiego wpisu, który zawiera ścieżkę uzyskaną z dereferencji aliasu. where the module hide the alias (903) further is configured to replace the second circuit value dereferencji alias for the third parameter the path to another record that contains the path obtained dereferencji alias.
- 3The system according to clause 2, wherein the search module/upgrade (911) in addition, configured to recursively perform dereferencji alias. 3. System według zastrzeżenia 2, w którym moduł wyszukiwania/aktualizacji (911) jest ponadto skonfigurowany do rekurencyjnego wykonywania dereferencji aliasu.
- 4System according to any one of the previous objections in which the directory (900) is stored on multiple directory servers, where the recognition module names States that the location for data in the directory (900) is located on another directory server among many servers, directories, moreover, this system also includes:4. System według dowolnego z poprzednich zastrzeżeń, w którym katalog (900) jest magazynowany na wielu serwerach katalogowych oraz gdzie moduł rozpoznawania nazw stwierdza, że lokalizacja dla danych w katalogu (900) rezyduje na innym serwerze katalogowym wśród licznych serwerów katalogowych, przy czym system ten zawiera ponadto: 55P31384PL00 55P31384PL00 110 110 EP 2 156 649 B1 moduł łańcuchowania (917) skonfigurowany do kierowania żądania oraz zlokalizowanych instrukcji dereferencji aliasu do innego serwera katalogowego. EP 2 156 649 B1 łańcuchowania module (917) configured to request and localized leadership dereferencji alias for another directory server.
- 6System according to any one of the previous objections in which the directory (900) is stored on multiple directory servers, where the search module/upgrade (911) argues that the location of the data in the directory resides on a different directory server from the set of directory servers, wherein the system contains, in addition:6. System według dowolnego z poprzednich zastrzeżeń, w którym katalog (900) jest magazynowany na wielu serwerach katalogowych oraz gdzie moduł wyszukiwania/aktualizacji (911) stwierdza, że lokalizacja danych w katalogu rezyduje na innym serwerze katalogowym spośród licznych serwerów katalogowych, przy czym system zawiera ponadto: moduł łańcuchowania (917) skonfigurowany do kierowania żądania oraz zlokalizowanych instrukcji dereferencji aliasu do innego serwera katalogowego. łańcuchowania module (917) configured to request and localized leadership dereferencji alias for another directory server.
- 7The opposition system of 6, wherein the search module/upgrade (911) additionally configured to receive from the module łańcuchowania (917) recognition of location for data received from another directory server and conclusions this detected location in the report to the module hide the alias (903). 7. System według zastrzeżenia 6, w którym moduł wyszukiwania/aktualizacji (911) jest ponadto skonfigurowany do odbioru z modułu łańcuchowania (917) rozpoznanej lokalizacji dla danych otrzymanych z innego serwera katalogowego i zawarcia tej rozpoznanej lokalizacji w raporcie do modułu ukrywania aliasu (903).
- 8System according to any one of the previous objections in which the module hide the alias (903) is located on a server directory that resides in the attached network that contains multiple directory servers. 8. System według dowolnego z poprzednich zastrzeżeń, w którym moduł ukrywania aliasu (903) rezyduje na serwerze katalogowym, który rezyduje w przyłączonej sieci zawierającej liczne serwery katalogowe.
- 9System according to any one of the previous objections in which the module hide the alias (903) further is configured to receive the request perform actions, at least one of the protocols LDAP and DAP and/or transmission report to the sender unit (920) at least one of the protocols LDAP and DAP. 9. System według dowolnego z poprzednich zastrzeżeń, w którym moduł ukrywania aliasu (903) jest ponadto skonfigurowany do odbierania żądań wykonania działań według co najmniej jednego z protokołów LDAP i DAP i/lub wysłania raportów do żądającej jednostki (920) według co najmniej jednego z protokołów LDAP i DAP.
- 10System according to any one of the previous objections in which the requesting unit (920) is one of the following components:a client application, the end user or the directory server usiłującym 10. System według dowolnego z poprzednich zastrzeżeń, w którym żądająca jednostka (920) jest jednym z następujących elementów: aplikacją kliencką, użytkownikiem końcowym albo serwerem katalogowym usiłującym 55P31384PL00 55P31384PL00 111 111 EP 2 156 649 B1 to complete the data request and where the module hide the alias (903) further is configured to prepare reports transmitted to the sender unit (920) in the format available for the sender unit (920). EP 2 156 649 B1 zakończyć żądanie danych oraz gdzie moduł ukrywania aliasu (903) jest ponadto skonfigurowany do przygotowania raportów wysłanych do żądającej jednostki (920) w formacie dostępnym dla żądającej jednostki (920).
- 12System according to any one of the previous objections, in which the action is a read operation or record. 12. System według dowolnego z poprzednich zastrzeżeń, w którym działaniem jest operacją odczytu lub zapisu.
- 13System according to any one of the previous objections that contains, in addition:13. System według dowolnego z poprzednich zastrzeżeń, zawierający ponadto: module creations alias (905) configured to create a record alias (902) in the directory (900). moduł kreacji aliasu (905) skonfigurowany do tworzenia wpisu aliasu (902) w katalogu (900).
- 14Way to access data in the directory (900) from sender unit (920), comprising the steps of:14. Sposób dostępu do danych w katalogu (900) od żądającej jednostki (920), zawierający etapy: przejęcia żądania w celu wykonania działania na danych w pierwszym wpisie (902) magazynowanym w katalogu (900), wysłanego przez żądającą jednostkę (920), gdzie żądanie to zawiera ścieżkę aliasu do pierwszego wpisu (902) w katalogu (900);take the queries for performing operations on data in the first post (902) magazynowanym in the directory (900) sent by demand unit (920), where the query includes a path alias to the first entry (902) in the directory (900);to settle instructions dereferencji the alias that refers to the sender entity (920);ulokowania instrukcji dotyczących dereferencji aliasu odnoszącego się do żądającej jednostki (920);to assign the path obtained dereferencji alias for the data in the directory (900), describing the path from the first entry (902) the second element (504f) that contains the data using a path alias and localized user dereferencji alias, where the path obtained dereferencji rozróżnioną alias is a name that identifies the location of the second item in a folder;wyznaczenia ścieżki uzyskanej z dereferencji aliasu do danych w katalogu (900) poprzez rozpoznanie ścieżki z pierwszego wpisu (902) do drugiego wpisu (504f), który zawiera dane z wykorzystaniem ścieżki aliasu oraz zlokalizowane instrukcje dereferencji aliasu, gdzie ścieżka uzyskana z dereferencji aliasu jest rozróżnioną nazwą identyfikującą lokalizację drugiego wpisu w katalogu;55P31384PL00 55P31384PL00 112 112 EP 2 156 649 B1 perform actions on the data in the second post (504f);and characterized in that the method comprises also the stage of conclusion of the report sender unit (920) that the action was done for the data in the first post (902) with replacement, the data path obtained from dereferencji alias path alias by modifying the results obtained by using this action, so that it is touching the track on the alias provided by the demand unit (920) is the second parameter (504f) track obtained dereferencji alias. EP 2 156 649 B1 wykonania działania na danych w drugim wpisie (504f);a także znamienny tym, że sposób ten zawiera ponadto etap zawarcia raportu żądającej jednostki (920) o tym, że działanie to zostało wykonane na danych w pierwszym wpisie (902) z zastąpienie, ścieżki do danych uzyskanej z dereferencji aliasu ścieżką aliasu poprzez zmodyfikowanie wyników wygenerowanych przez to działanie, tak aby dotyczyło ścieżki aliasu dostarczanej przez żądającą jednostkę (920) zamiast drugiego wpisu (504f) ścieżki uzyskanej z dereferencji aliasu.
- 15Thus, according to clause 14, wherein the step of performing an action on data in the second post (504f) also contains stage:15. Sposób według zastrzeżenia 14, w którym etap wykonania działania na danych w drugim wpisie (504f) zawiera ponadto etap: determining that a child towards another record contains aliasowe data;wyznaczenia, że wpis podrzędny wobec drugiego wpisu zawiera aliasowe dane;rozpoznania drugiego aliasu w celu wyznaczenia trzeciego wpisu w drugiej ścieżce uzyskanej z dereferencji aliasu;a także wykonania działania na danych w trzecim wpisie;a także zastąpienia drugiej ścieżki uzyskanej z dereferencji aliasu do trzeciego wpisu ścieżką do drugiego wpisu, który zawiera ścieżkę uzyskaną z dereferencji aliasu. the diagnosis of the second alias to determine a third parameter to another trajectory obtained dereferencji alias;as well as run data in the third post;and to replace the second track value dereferencji alias for the third parameter the path to another record that contains the path obtained dereferencji alias.
- 16Thus, according to clause 15, in which the action execution, the data in the second post (504f) contains, in addition, the recursive execution dereferencji alias. 16. Sposób według zastrzeżenia 15, w którym wykonanie działania na danych w drugim wpisie (504f) zawiera ponadto rekurencyjne wykonywanie dereferencji aliasu.
- 17A method according to any of the objections from 14 to 16, wherein the directory (900) is stored on multiple directory servers, where the step of determining the path with dereferencji alias for the data indicates that the data resides on another directory server among many servers, directories, and the method comprises, in addition:17. Sposób według dowolnego z zastrzeżeń od 14 do 16, w którym katalog (900) jest magazynowany na licznych serwerach katalogowych oraz gdzie etap wyznaczenia ścieżki z dereferencji aliasu do danych wskazuje, że dane rezydują na innym serwerze katalogowym wśród licznych serwerów katalogowych, przy czym sposób ten zawiera ponadto: etap łańcuchowania żądania oraz zlokalizowanych instrukcji dereferencji aliasu do innego serwera katalogowego. stage łańcuchowania requests and localized leadership dereferencji alias for another directory server.
- 18A method according to any of the objections from 14 to 17, wherein the directory (900) is stored on multiple directory servers, where the execution of the work under the second entry (504f) is related to the appointment, 18. Sposób według dowolnego z zastrzeżeń od 14 do 17, w którym katalog (900) jest magazynowany na licznych serwerach katalogowych i gdzie wykonanie działania na danych pod drugim wpisem (504f) wiąże się ze wyznaczeniem, 55P31384PL00 55P31384PL00 113 113 EP 2 156 649 B1 that the location for data in the directory resides on a different server in the plurality of directory servers, and this method also contains stage:EP 2 156 649 B1 że lokalizacja dla danych w katalogu znajduje się na innym serwerze katalogowym pośród licznych serwerów katalogowych, przy czym sposób ten zawiera ponadto etap: łańcuchowania requests and localized leadership dereferencji alias for another directory server. łańcuchowania żądania oraz zlokalizowanych instrukcji dereferencji aliasu do innego serwera katalogowego.
- 19A method according to any of the objections from 14 to 18, containing also the stage of preparation of the report for the sender unit (920) that you've done the work so that the requesting unit (920) does not receive path information data for the second parameter (504f). 19. Sposób według dowolnego z zastrzeżeń od 14 do 18, który zawiera ponadto etap przygotowania raportu do żądającej jednostki (920) o tym, że wykonano działanie tak, że żądająca jednostka (920) nie otrzymuje informacji dotyczącej ścieżki danych do drugiego wpisu (504f). Apertio Limited Pełnomocnik:Apertio Limited Representative: 55P31384PL00 55P31384PL00 114 114 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 1 FIG. 1 STAN TECHNIKI THE STATE OF THE ART 55P31384PL00 55P31384PL00 115 115 EP 2 156 649 B1 EP 2 156 649 B1 55P31384PL00 55P31384PL00 116 116 EP 2 156 649 B1 ro o EP 2 156 649 B1 ro on QJ ω QJ? N ω N? -o <D ώ -o <D? FIG. 3 <D FIG. 3 <D O On CM CM 55P31384PL00 55P31384PL00 117 117 EP 2 156 649 B1 EP 2 156 649 B1 FIG.4 FIG.4 408 408 55P31384PL00 55P31384PL00 118 118 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 5 FIG. 5 55P31384PL00 55P31384PL00 119 119 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 6 FIG. 6 55P31384PL00 55P31384PL00 120 120 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 7A FIG. 7A 55P31384PL00 55P31384PL00 121 121 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 7B FIG. 7B 55P31384PL00 55P31384PL00 122 122 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 8 FIG. 8 55P31384PL00 55P31384PL00 123 123 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 9A ω ω FIG. 9A?? 55P31384PL00 55P31384PL00 124 124 EP 2 156 649 B1 EP 2 156 649 B1 55P31384PL00 55P31384PL00 125 125 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 10A FIG. 10A 55P31384PL00 55P31384PL00 126 126 EP 2 156 649 B1 EP 2 156 649 B1 My Company Contact — Web Site My Company Contact — Web Site Company X Contact L Company X Contact L 55P31384PL00 55P31384PL00 127 127 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 11A FIG. 11A The Entry The Entry The Entry Wpis Wpis Wpis 504c 504d 504e 504c 504d 504e 55P31384PL00 55P31384PL00 128 128 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 11B FIG. 11B 55P31384PL00 55P31384PL00 129 129 EP 2 156 649 B1 EP 2 156 649 B1 55P31384PL00 55P31384PL00 130 130 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 11D FIG. 11D 55P31384PL00 55P31384PL00 131 131 EP 2 156 649 B1 EP 2 156 649 B1 55P31384PL00 55P31384PL00 132 132 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 12 FIG. 12 Moduł Rozpoznawania Dane Konfiguracji The Recognition Module Configuration Data Name 909 1210 Nazw 909 1210 55P31384PL00 55P31384PL00 133 133 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 13A FIG. 13A 55P31384PL00 55P31384PL00 134 134 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 13B FIG. 13B 55P31384PL00 135 EP 2 156 649 B1 55P31384PL00 135 EP 2 156 649 B1 FIG. 13C FIG. 13C 55P31384PL00 55P31384PL00 136 136 EP 2 156 649 B1 EP 2 156 649 B1 55P31384PL00 55P31384PL00 137 137 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 14 FIG. 14 55P31384PL00 55P31384PL00 138 138 EP 2 156 649 B1 EP 2 156 649 B1 Korzeń Root 1501 1501 55P31384PL00 55P31384PL00 139 139 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 15Β FIG. 15Β 55P31384PL00 55P31384PL00 140 140 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 16A FIG. 16B FIG. 16A FIG. 16B 55P31384PL00 55P31384PL00 141 141 EP 2 156 649 B1 > EP 2 156 649 B1 > c > c > FIG. 16C FIG. 16C 55P31384PL00 55P31384PL00 142 142 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 17 FIG. 17 55P31384PL00 55P31384PL00 143 143 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 18A FIG. 18A 55P31384PL00 55P31384PL00 144 144 EP 2 156 649 B1 EP 2 156 649 B1 55P31384PL00 55P31384PL00 145 145 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 18C FIG. 18D FIG. 18C FIG. 18D 55P31384PL00 55P31384PL00 146 146 EP 2 156 649 B1 EP 2 156 649 B1 FIG. 18E FIG. 18E
Independent claims17
429 paragraphs in 134 sections, as filed
Technical field [0001] the embodiments of the invention relate to systems and methods of delivering data and services on the network. More specifically, an exemplary embodiment of an exemplary embodiment of the invention relates to systems and methods that ensure reliable, fast access to data for use in a communication network having a large number of subscribers whose respective data may be located in a centralized data store to access them through various applications running within the network.
BACKGROUND [0002] network Operators of mobile and fixed would like to make the transition to a fully converged Communications Service Providers (CSP). Changing business strategies and the introduction of new services, the subscriber causes silosowanie systems and functional data within a typical CSP. Many conventional communication networks based on nieustrukturalizowanej a medley of functional pads on frame network, which was built primarily for voice traffic. In subscription databases, there is often a duplication of data, creation of services and processes prowizjonowania, administration, support, and billing.
[0003] Many CSPS pragnęłoby capitalization to provide new services based on content, which is referred to for a wide range of market segments. This new area of growth is driven by new applications and devices that have been specifically designed for multimedia services. However, there are still strong boundaries between mobile services and the link table, because the products were formed around the access methods and devices, and not around the needs of subscribers.
55P31384PL00
EP 2 156 649 B1 [0004] FIG. 1 depicts a representative network architecture 100 used by the CSP in the state of the art. The network architecture 100 includes system operations support/business support/IT
Operations Support System (OSS)/Business Support System (BSS)/IT Domain
102, one or more applications, such as applications 106a 106c and frame network and happens Core Signaling Network 108. System OSS/BSS/it Domain 102 includes Prowizjonowania System (Provisioning System) 110 and a Network Management System 112. Each Application 106a 106c has a Logic Portion 107a and a Portion 107b of the Data. Part of the Puzzle 107a each Application 106a - 106c has access mainly, if not exclusively, in the right part of the Data 107b. The Data portion 107b of each Application 106 is typically in some kind of database such as a relational database. Applications 106a - 106c can supply, for example, the Register of Subscribers of Stem cells (Home Location Register (HLR)), server, Home Subscriber Server (HSS), voice mail system, voice mail, Authentication, Authorization, and Accounting (Authentication, Authorization and Accounting (AAA)), number portability mobile Mobile Number Portability (MNP), and others. These applications are known in the art.
[0005] When a CSP adds to a growing number of new services for their systems, such as, for example, the IP Multimedia Subsystem (IP Multimedia Subsystem (IMS)), and Nielicencjonowany Mobile Access (Unlicensed Mobile Access (UMA)), they may notice that the shared relational database technology are too difficult to implement due to too much kastomizację introduced in the development process. As a consequence, the measure seeks new services and types of subscribers, the relevant diagrams can be too hard for enrichment. In other words, when the number of Applications 106a - 106c grows to large numbers, CSPS are experiencing more and more problems in systems, such as scalability, performance and management. These problems will increase cost and lead to operational stagnation, causing further increase in cost. Platform based on standard disk appears to be
55P31384PL00
EP 2 156 649 B1 it is difficult to scale because the underlying technology imposes practical limits on access time.
[0006] equipment Suppliers often have difficulties with the production of crops product features that can be provided in the price, and at the time, which is economically survivable for the CRYPTOGRAPHIC service provider. In the result, CSPS often find themselves "tied" to the hardware supplier who has limited interoperability with systems from other manufacturers, limiting the operational flexibility of CSP and the selection of equipment suppliers, when modernization is required. In addition, proprietary hardware platform tends to nieekonomicznego scaling, which often leads to blocks of free capacity that can not be effectively used by CSP.
[0007] therefore, until the moment when a CSP to improve the systems and methods they use to implement new applications in their networks, their businesses and subscribers will not be able to fully use modern communication network at your disposal.
[0008] Byrne D., and others in the "Use of Aliases within LDAP; draft_byrneldap=alias=00.txt" IETF STANDARD-WORKING - DRAFT, INTERNET ENGINEERING TASK FORCE, IETF, CH, 20, April 1998, XP015011291 ISSN: 0000-0004 describes the suggested behavior for Aliases for LDAPv3 and above to improve LDAP server interoperability.
[0009] Zeilenga OpenLDAP Foundation K, "Lightweight Directory Access Protocol (LDAP): Directory Information Models; rfc4512.txt" IETF STANDARD, INTERNET ENGINEERING TASK FROCE, IETF, CH, 1 June 2006,
XP015046289 ISSN: 0000-0003 describes the implementation of the recording Aliases of Entries in the LDAP Protocol and the implementation of short names Short Names - which are easier to read with aliases for object identifiers.
[0010] WO 02/075572A for technology, thanks to which the entity that is available via the communication system can be defined with multiple alternative symbolic names.
55P31384PL00
EP 2 156 649 B1
ABSTRACT [0011] the above-mentioned shortcomings, disadvantages and problems are solved according to the example implementation of the present invention, which will be understood by reading and studying the following descriptions.
[0012] an exemplary embodiment of the invention proposes a system for accessing data in a folder that requires one. This system may include the recognition module names configured for determining the position of the data in the directory, aware of the way to the entry containing the data using an original path and the instructions to dereferencji alias. The recognition module can be further configured to determine the location by assigning rozróżnionej login where rozróżniona name defines the location of directory entries. This system can also include a search module/update is configured to perform actions on the record data using the recording position in the catalog and in the guide dereferencji alias. This system may also contain a module to hide the alias configured for the perception of requests to perform operations on the data in the first record is stored in the directory received within a sought after block, where the request includes an original path to the first directory entry, the search instructions dereferencji alias relating to the sender unit delivery of the original tracks for the recognition module names along with the located instructions for alias dereferencji in relation to the sender unit, and receiving from the recognition module of the recognized names of the data in the directory, and the path formed from dereferencji an alias for the fixed record that contains the data. The module hide the alias can also be configured to request from the search module update/perform action on data of the recognized locations through the provision of the required action and localized leadership dereferencji alias, and run the report for the sender unit that the work was performed on the data in the first post replacing the path to the data obtained from dereferencji alias original way, changing the results generated by the module
55P31384PL00
EP 2 156 649 B1 search/updates so that they belonged to the path alias provided by the demand unit is the recognized track records value dereferencji alias.
[0013] an exemplary embodiment of the invention may provide access to data in the directory from the sender unit. This method may call for the acquisition of requests to perform operations on the data in the first post, stored in the directory sends the requiring unit, where the request includes an original path to the first entry in the directory. This method may cause the user definitions dereferencji alias against the senders units. This method can also cause the determination of the trajectories obtained with dereferencji an alias for the data directory using the decision path from the first record to another record that contains the data using an original path and localized user dereferencji alias. The path obtained dereferencji alias is probably rozróżnioną name that identifies the location of the second entry in the directory. This method can also in addition, to call to perform work on the data in the second post and reporting for the sender unit that the work was performed on the data in the first post replacing the path to the data obtained from dereferencji alias for original path by modifying the results of the action so that they belonged to the path alias supplied on demand unit is the second parameter of the trajectory obtained dereferencji alias.
BRIEF DESCRIPTION OF THE DRAWINGS [0014]
FIG. 1 depicts a representative network architecture 100 used by the CSP in the state of the art;
FIG. 2 shows a block diagram depicting a telecommunication system 200 in which can work embodiments of the invention;
55P31384PL00
EP 2 156 649 B1
FIG. 3 shows a block diagram depicting another part of the backbone of a communication network CN such as the backbone network CN 206 shown in FIG. 2, which can interact with the examples of the invention;
FIG. 4 illustrates a functional view of a data storage network 400 according to the embodiment of the invention;
FIG. 5 is a Database Directory (Directory Information Base (DIB)) 500 according to the embodiment of the invention;
FIG. 6 depicts a Directory Information Tree (Directory Information Tree (DIT)) 600 according to the embodiment of the invention;
FIG. 7A illustrates the System structure of Directories (Directory System Agent (DSA)) 702 and a User Agent Directory (Directory User Agent (DUA)) 704 according to the embodiment of the invention;
FIG. 7B illustrates a distributed hierarchy comprising three DSA 702a, 702b and 702c, according to the embodiment of the invention;
FIG. 8 illustrates optimized routing in the distributed hierarchy of agents, DSA, shown in FIG. 7B according to the embodiment of the invention;
FIG. 9A depicts a DIT 900 having an alias entry, the Alias Entry 902, according to the embodiment of the invention;
FIG. 9B illustrates the Module Hide the alias 903 is compatible with DIT 900 that contains the alias 903 to perform masking of aliases in the data request from the Sender Unit 920 according to the embodiment of the invention;
FIG. 10A depicts a DIT 1000 with wariantowym entry 1002, according to the embodiment of the invention;
FIG. 10B is wariantową processing in the DIT 1000, containing the Variant 1002 of a data request from the Sender Unit 1020 according to the embodiment of the invention;
FIG. 11A represents the Adaptation Module 1107 Protocol, according to the embodiment of the invention;
FIG. 11B shows an example of serial or sequential processing of Protocol adaptation, according to the embodiment of the invention;
55P31384PL00
EP 2 156 649 B1
FIG. 11C represents the Adaptation Module 1107 Protocol, essentially running as a server virtual directory (or server proksy LDAP/DAP), engaged in communication (e.g., LDAP or DAP operations) to the Server 1109 Operations Directory, such as the DS 706a shown in FIG. 7A, according to an alternative embodiment of the invention;
FIG. 11D represents a DIT 1100 having an adaptive naming configuration supplied via Protocol adaptation, according to the embodiment of the invention;
FIG. 11E shows the DIT 1150 aimed at the adaptation of the attribute in further adaptation of the Protocol according to the embodiment of the invention;
FIG. 12 illustrates the Access Control system (Access Control (AC)), implemented using some form of Protocol adaptation, according to the example implementation of the present invention;
FIG. 13A illustrates a Nomadic Subscriber Data System (Nomadic Subscriber Data System) for enhanced data transmission between the subscriber data stores in communication networks, such as, for example, the Mobile Communication System 204, according to the embodiment of the invention;
FIG. 13B illustrates representative components comprising the System of the Nomadic Subscriber Data, such as illustrated in FIG. 13A, according to the embodiment of the invention;
FIG. 13C illustrates representative configuration data 1310 for a DSA agent partycypującego in the System of the Nomadic Subscriber Data, according to the embodiment of the invention;
FIG. 13D provides a high-level algorithm for the System
Nomadic Subscriber Data, according to the embodiment of the invention;
FIG. 14 illustrates a system 1400 logging, according to the embodiment of the invention;
55P31384PL00
EP 2 156 649 B1
FIG. 15A shows a block diagram showing the hierarchy of the data stored in the Directory 1500, such as data used by the server HSS 301 shown in FIG. 3, according to the embodiment of the invention;
FIG. 15B shows a block diagram depicting a server architecture of HSS, such as HSS 301 main server of a communication network CN 206, shown in FIG. 3, according to the embodiment of the invention;
FIG. 16A and FIG. 16B depict a flowchart representing respectively współhostowany system 1600 and współlokowany system 1620 for the HSS 301 and the server registry HLR 307, according to the embodiment;
FIG. 16C illustrates a front end interface (front-end) 1601 that has been configured to hold service data 1619 for applications such as server HSS 301 and the HLR 307 registry, according to the embodiment of the invention;
FIG. 17 shows a block diagram showing a data hierarchy stored in a directory 1700 facilitating static access to entries, according to the embodiment of the invention;
FIG. 18A illustrates a communications network 1800 using a quick access point (HSAP) that may possibly benefit from the improved clock mechanism according to the embodiment of the invention;
FIG. 18B depicts a physical view of a communication network 1800 shown in FIG. 18A that may benefit from improved clock mechanism according to the embodiment of the invention;
FIG. 18C shows a Subscriber Entry 1841 from a directory, such as directory agent supported by the DSA 1831, according to the embodiment of the invention;
FIG. 18D represents 1850 Hours, having a record of the Hours 1851 in the catalogue of the excess through the agent DSA 1831, according to the embodiment of the invention; and
55P31384PL00
EP 2 156 649 B1
FIG. 18E is to escape the clock mechanism, implemented on the agent DSA 1831, shown in FIG. 18B, according to example of the invention.
A DETAILED DESCRIPTION OF THE EXAMPLE OF THE INVENTION
OVERVIEW [0015] Conventional mobile telecommunications networks are the result of evolution, not revolution. To the extent that it seeks communications market mergers and acquisitions together with changing business strategies resulted in data silos, operational and functional at a typical Communications Service Provider (CSP). A typical network was created from a number of functional overlays on frame network, which was built mainly intended for voice traffic. In this regard, the subscriber databases often have breeding, the processes of creation and prowizjonowania services, administration, support, and billing. Many CSPS pragnęłoby to make rationalization and consolidation of their businesses to eliminate duplication to reduce costs, increase productivity, and, eventually, to improve service to subscriber. Simultaneously, the CSP often there is still a need to increase capacity, add functional extensions and replacement of aging infrastructure. In addition, CSPS may also want to prepare for further convergence between voice communication and other technologies.
[0016] a New paradigm of telecommunication can focus on abonentach providers CSP and to a lesser extent on the hardware and software of the network. Instead of complicated and uncomfortable silos of corporate data, is shown in FIG. 1, CSPS can move to a new paradigm in which these systems are open, thus allowing for greater integration and interaction of network applications. In this regard, this new paradigm is, in essence, puts the subscriber data in the core network as the access and sharing of information should not in principle be
55P31384PL00
EP 2 156 649 B1, is limited by factors such as where the subscriber is located, what type of connection the subscriber has or what choice of interaction with the CSP that the subscriber makes. Addressing these limitations may allow providers CSP to bring together conventional sectional provides a consistent, multimedia, wielodostępowej communication services.
[0017] In this regard, embodiments of the invention may offer one catalog database, logical that contains the merged data source subscriber and/or service offered for these processes of control and management which require information of the subscriber. Centralized data storage may allow the mutual combination of conventional databases, networks and applications in a scalable, efficient cost-effective way that destroys the individual databases present in conventional networks, such as the database shown in FIG. 1. In this regard, embodiments of the invention may provide one source of information for applications, network backbone, and through multiple or all domains. [0018] Through the transition to the paradigm of the data focused on the subscriber as action center providers CSP, the CSP may achieve greater integration and interaction. Putting the subscriber in the center of your actions can also facilitate the CSPS behavior full and accurate information of the subscriber. Many bunkers databases conventional network, such as shown in FIG. 1, can be converted into a separate, highly scalable, directory AC high performance, which can be access through web applications or business that have a need for data processing, subscription.
[0019] in Accordance with what has been said, the examples of the invention may use one catalog database, logical that contains a single source of information of the subscriber and services available for control and management that need this information. Win-win catalog database uses the example of the invention is X. 500. The catalog database can offer an open centralized database compatible with the standard ITU-T X. 500
55P31384PL00
EP 2 156 649 B1 the system directory data according to the embodiment of the invention. The database directory contains, as a rule, subscriber information, service and networking, as well as uruchamialne software routines that are available to apps using industry standard directory protocols such as, for example, Lightweight Directory Access Protocol (LDAP) and Directory Access Protocol (DAP) and others, according to the embodiment of the invention.
[0020] Sent on the network subscriber may allow the qualitative improvement of conventional network components, such as, for example, a server, Home Subscriber Server (HSS), register, Home Location Register (HLR), and also to help when using the services of IP Multimedia Subsystem (IMS). In accordance with what was said examples of embodiment of the invention may include subsystems advanced HSS and/or HLR advanced.
[0021] an Example implementation of the present invention may also provide a common authentication that allows the subscriber to define at once, usually at the entry point to the network, and the affirmation of the importance of the full range of services. This procedure removes, as a rule, the need to re-commit authorization of the subscriber every time he tries to use a different type of service.
[0022] an exemplary embodiment of the invention, in addition, can offer a scalable solution to the database that allows applications the gear ratio the same logical and scalable X. 500 directory, which usually contains the information needed for most subscribers. So prowizjonowanie (provisioning) is required, usually once. Then applications can just use the same set of data. An exemplary embodiment of the invention may use a directory-based database X. 500 that provides data to the subscribers in the existing network applications and systems support. [0023] an exemplary embodiment of the invention may work in conjunction with a data repository of a certain type, for example, a database. As in other repositories, data warehouse, used in the examples of the invention, as a rule, protected by the system control base
55P31384PL00
EP 2 156 649 B1 (DBMS). DBMS serves as a rule, different functions, high level and low level. Determined and zastrzegany this invention does not contain low level functions that are performed, usually through a system of DBMS. For this type of low level functions are very basic steps, such as, for example, the physical process of receiving a data item, the determination of prostate-specific sector in a specific memory of a certain type, and then the interaction with the platform hardware memory for storing the received data. Components of DBMS high-level revealed zastrzegane here to interact with different components of the system DBMS low level. One this kind of component DBMS lowest level is known as DirecTree™, a high-performance wewnątrzpamięciowy system low-level database, which is owned by Apertio Limited, to achieve the transfer here ujawnianego of the invention. The structure and operation of DirecTree™ are supported as trade secrets at Apertio Limited. Despite the fact that the examples of the invention may operate in conjunction with DirecTree™, this special low-level DBMS is not part of ujawnianego and claimed invention here.
[0024] FIG. 2 shows a block diagram depicting a telecommunication system 200 in which can work embodiments of the invention. Communication system 200 can be functionally classified as a Fixed Telecommunication System 202 and Mobile Telecommunications System of communication 204. For examples of the Telecommunication System 202 belong to the Fixed telephone network of General use (PSTN) (PSTN). System Mobile Telecommunications communication 204 provides mobile telecommunication servants, such as, for example, communication between two people using mobile phones. System for Mobile Telecommunications 204 is bordered by the Fixed Telecommunication System 202 through functional interfaces 216 to provide, among other things, communications between mobile and stationary.
[0025] the Mobile Telecommunications 204 is logically divided into a Frame Network (CN) 206 and an Access Network (AN) 208. Network CN 206
55P31384PL00
EP 2 156 649 B1 contains, as a rule, three main domains: domain circuit-switched links (Circuit Switched (CS)) 210, a domain with packet switching (Packet Switched (PS)) 212, and domain (IP Multimedia Subsystem (IMS)) 214. The name of these differ, as a rule, in such a way that support the movement of a subscriber and to contain system hardware and software, which together perform a specific technical function for this domain. For example, the PS domain 212 includes hardware and software that perform the communications komutowaną pakietowo, typically the recognized standard.
[0026] the CS Domain 210 refers to the hardware and software components, which provide communications on the basis of the switching links, which support signaling and traffic of the subscriber. A CS connection is made, as a rule, the allocation of network resources in the mode of a connection and releases these network resources when releasing the connection. For components these belonged, as a rule, in the CS domain 210, the mobile telephone exchange (Mobile services Switching Center (MSC)), the control panel Gateway MSC (GMSC) server, MSC Server, CS-Media Gateway Function (CS-MGW), the server UMS Server and the Interworking Function (IWF). CS domain 210, and these components are known in the art.
[0027] the PS Domain 212 refers to the hardware and software components that provide the connection based on packet switching that supports traffic and signaling abonencki. Connect your PS transportorul, as a rule, the subscriber information using Autonomous concatenation of bits that are grouped into packages, where each package can be trasowany independently of other packets. The PS domain 212 typically includes components that are designed to service General Packet Radio Service (GPRS), such as the node Serving GPRS Support Node (SGSN) and the Gateway node, GPRS Support Node (GGSN). The PS domain 212 also includes a component, typically to perform Border Gateway Protocol (BGP). The PS domain 212, and these components are known in the art.
[0028] the IMS Domain 214 refers to components that offer IP multimedia services, such as sound, image, video, text, conversation, etc., and combinations thereof, delivered by the name of PS 212.
55P31384PL00
EP 2 156 649 B1
The IMS domain 214 typically includes components such as Call Session Control Function (CSCF), a Media Gateway Control Function (MGCF) and Media Gateway Function (MGF), function of the IMS-Media Gateway Function (IMS-MGW), controller Multimedia Resource Function Controller (MRFC), Multimedia Resource processor Function Processor (MRFP) function Breakout Gateway Control Function (BGCF), application server (Application Server (AS), and Policy Decision Function (PDF). The IMS domain 214 and these components are known in the art.
[0029] the access Network AN 208 contains, as a rule, the system base station Base Station System (BSS) configured for the supply of communications that is compatible with a standard communication system such as global System for Mobile Communications (Global System for Mobile communication (GSM) and/or Radio network System (Radio Network System (RNS)) for Universal Mobile Telecommunications (Universal Mobile Telecommunications System (UMTS)). These conventional systems known in the art.
[0030] FIG. 3 shows a block diagram that provides additional information for the main communications Network, such as network-frame CN 206 in the System of Mobile Telecommunication, 204 shown in FIG. 2, which can work embodiments of the invention.
[0031] in Accordance with what was said above, the CS Domain 210 contains, as a rule, the MSC area 313 and the GSMC area 315. The MSC area 313 provides a substitute ringer for calls, circuit-switched links, mobility management, and other services for the movement of mobile subscribers within the area supported by the MSC area 313. Despite the fact that in FIG. 3 given one piece 313 MSC, CS Domain 210 that contain likely numerous MSC area 313 in many implementations of the system of Mobile Telecommunication, 202. Incidentally, the MSC area 313 provides a functional interface for the connection of samples in the CS domain 210 between the Fixed Telecommunication System 202 and Mobile Telecommunications 204 within a common numbering plan and the General plan of the trace. The GSMC area 315 is located, the MSC area 313, which includes caller who called. Thus, the MSC area 313
55P31384PL00
EP 2 156 649 B1 trasuje call from the Telecommunication System 202 of the Stationary System for Mobile Telecommunication, 204, and trasuje call within the Mobile Telecommunications 204.
[0032] in Accordance with what was said above, the PS domain 212 typically contains, the SGSN area 317 and the GGSN area 319. The SGSN area 317 and provides a functional interface in the PS domain 212 between the Fixed Telecommunication System 202 and Mobile Telecommunications 204 for making a call within the common numbering plan and the General plan of the trace. In this context, the SGSN area 317 performs the interaction with the radio network used in Mobile Telecommunications 204. The GGSN area 319 provides a gateway between the wireless network and another network such as the Internet or a private network.
[0033] in Accordance with what was said above, the IMS domain 214 includes a Call Session Control Function (CSCF) 321. Function CSCF 321 typically contains servers and linked servers proksy that reach the processing of signaling packets in the IMS domain 214. The CSCF 321 function supports various functions, such as, for example, registration of IMS, news check, authentication of subscriber, policy control, bandwidth management, records download. Function CSCF 321 may use one or more standard protocols in the exercise of their functions, such as the Diameter Protocol.
[0034] the Backbone Network CN 206 also includes, as a rule, components that interact with different domains within a backbone network connection, the CN 206, such as the CS domain 210, the PS domain 212 and the IMS domain 214. These components, those known in the art, include the server Home Subscriber Server (HSS) 301, a register Visitor Location Register (VLR) 303, and a register Equipment Identity Register (EIR) 305.
[0035] the HSS Server 301 contains the application, responsible for maintaining information concerning subscribers of Mobile Telecommunications 204 shown in FIG. 2.
[0036] Different domains use this information for various purposes, as, for example, a connection/session on behalf of the subscribers.
55P31384PL00
EP 2 156 649 B1
For example, the server HSS 301 supports procedures for tracing through the creation and/or performance of such stages like Authentication,
Authorization, Accounting (AAA), recognizing names/addressing, depending on the site.
[0037] in Accordance with what has been said HSS server 301, is, as a rule, information regarding the subscriber, such as the identity of the subscribers, numbering & addressing, security information to control access to the network for AAA, location information of the subscriber; and information about the subscriber's profile. Regular identifiers are supported in subscriber server HSS 301 may include one or more of the following: international number of the subscriber International Mobile Subscriber Identity (IMSI) 323, an international number of mobile station Mobile Station International ISDN (MSISDN) 325, 327 private identity and public identity 329. Examples of the application servers and the HSS 301 may be based on such standards, such as 3GPP.
[0038] the HSS Server 301 is bordered by three domains (the CS domain 210, the PS domain 212 and the IMS domain 214) and impacts the functionality of these domains. Despite the fact that in FIG. 3 shows only one server HSS 301, typical of the Backbone Network CN 206 may contain multiple servers HSS. Place the multiple servers HSS is based usually on various factors such as number of subscribers, the amount of equipment used in the communication system 200, as well as the General organization of telecommunication system 200.
[0039] the Server HSS 301 may include applications such as, for example, the registry stem subscribers Home Location Register (HLR) 307, the authentication centre Authentication Centre (AuC) 309 and a Logical Functional module of HSS (HSS-LF) 311. These applications are known in the art.
[0040] the Register HLR 307 includes a data store, such as, for example, the directory that stores the location information for a set of subscribers. In other words, the subscriber of the communication system is assigned in the register HLR 307, for the purposes of the record, such as additional subscriber. The register HLR 307 typically provides support for components
55P31384PL00
EP 2 156 649 B1 name PS 212, such as the SGSN area 317 and the GGSN area 319 in order to provide subscribers access to services within the PS domain 212. Also, in the register HLR 307 provides support for the components of the CS domain 210, such as the MSC area 313 and the GMSC area 315 to provide the subscribers access to services such as roaming within the CS domain 210. Despite the fact that in FIG. 3 shows only one register HLR 307, this is a typical Backbone Network CN 206 may include a plurality of registers HLR.
[0041] in the authentication Centre AuC 309 is affiliated with the register HLR 307 and stores an identity key, such as, for example, the key PrivateID 327, for each subscriber registered in the register HLR 307. The same key safe makes it easier to create data security for the subscriber, for example, the key PublicID 329. In addition, the authentication centre AuC 309 may include authentication information IMSI 323 devices and Mobile Telecommunications 204. In addition, the authentication centre AuC 309 includes information to ensure the integrity and security of communication through the way of radio communication between mobile station (MS) and Mobile Telecommunications 204. Each authentication centre AuC 309 typically communicates only with its affiliated register HLR via the interface 307 marked, as a rule, the interface H. The register HLR 307 requests information from the authentication centre AuC 309 through the H-interface, stores the information and provides it to the appropriate components in the backbone communication Network 206 CN, and may be required.
[0042] Module HSS-LF 311 includes functional modules which provide services such as mobility management, and the convolution of the session generation information security subscriber security support caller support caller ID, access authorization, authorization support services and support prowizjonowania services.
[0043] the control Register VLR 303 typically the MSC area 313 in the CS domain 210 and effectively controls the roaming station to the mobile device MS in the MSC area 313. When the mobile station MS is part of the Mobile Telecommunications 204 covered by the MSC area 313, the MSC area 313 writes
55P31384PL00
EP 2 156 649 B1 the mobile station MS using the register VLR 303. The procedure of registration of oblast, MSC 313 to control this part of the Telecommunications Network 204 detects a Mobile station, the mobile MS and provides information about the mobile station MS in the register VLR 303. After receiving the information from the MSC area 313, the VLR 303 checks the register, the registration status of the mobile station MS. If the mobile station MS is not registered in the VLR 303 register, the register VLR 303 requires that the register HLR 307 provided information about a mobile station MS to facilitate proper maintenance calls associated with the mobile station MS. Registers VLR known in the art.
[0044] Information regarding a mobile station MS, to which the registry goes back to the VLR 303 typically includes data such as the IMSI 323, the MSISDN 325 number, number Mobile Station Roaming Number (MSRN), the MSC area 313 where the registered mobile station MS, the identity of the SGSN area 317 where the registered mobile station MS (where the mobile network supports GPRS and provides an interface between the register VLR 303 and the SGSN area 317). In the example implementation of the invention, the register VLR 303 can work with more than one MSC area 313.
[0045] the Magazine EIR 305 provides a logical entity that is responsible for storing the international mobile International Mobile Equipment Identities (IMEI). The equipment can be classified as a "white list, grey list, black list", or may be unknown. In the conventional backbone communication network 206 the CN journal EIR 305 stores at least the white list.
Data storage focused on subscriber [0046] FIG. 4 illustrates a functional view of a data storage network 400 according to the embodiment of the invention. Network architecture 400 includes a system 402 Operations Support System (OSS)/Business Support System (BSS), the Data Repository 404, one or more applications, such as, for example, Application 406a - 406e and frame network and happens Core Signaling Network 408.
55P31384PL00
EP 2 156 649 B1 [0047] the OSS/BSS 402 includes a System Prowizjonowania (Provisioning System) 410 and the Network Management System Network Management System 412. The OSS/BSS 402 includes various computing systems used by the CSP. OSS/BSS 402 covering System Prowizjonowania 410 and the Network Management System 412 contain a "network system" telecommunication networks of mobile devices that support processes such as maintaining reserves network, prowizjonowania services, configuring network components, and managing faults. Schemes contain "system for business" for transactions with subscribers, supporting processes such as taking orders, invoice processing, and payment collection.
[0048] the Data Repository 404 provides a centralized data domain that supports open access to data, such as subscriber data, or provides data, via one or more applications, such as the Application 406a, 406b, 406c, 406d, and 406e as well as systems of BSS/OSS, such as Prowizjonowania System 410 and the Network Management System 412, according to the embodiment of the invention. For example, Data Storage 404 may contain data destined for the server HSS, as, for example, data associated with the server HSS 301 shown in FIG. 3, and the dataset for the entire Telecom Network of the Mobile 204. In accordance with what you said, the Application 406a - 406e may contain, respectively, the server HSS 301 and/or the register HLR 307, according to the embodiment of the invention. The application 406a - 406e may also include applications such as voice mail system voice mail system Authentication, Authorization, and Accounting (AAA), the mobile number portability Mobile Number Portability (MNP), according to the embodiment of the invention. These applications are well known in the art. Additional Applications 406 may also be included in the network 400. The Data store 404 can be configured as an application specification ITU-T X. 500 according to the embodiment of the invention.
[0049] In the embodiment of the invention, the software architecture of the Data Warehouse 404 supplies a unit of one logical directory. Each physical unit has access to each data record,
55P31384PL00
EP 2 156 649 B1, giving high reliability and performance, according to the embodiment of the invention. In various examples of the invention the Data Store 404 supports a variety of open interfaces such as, for example Directory Access Protocol (DAP), Lightweight Directory Access Protocol (LDAP), Structured Query Language (SQL), OBDC/JDBC, and so on. These open interfaces, which are known in the art, facilitate linking data stored in Data Store 404 to business applications, such as system of customer relationship management Customer Relationship Management (CRM).
[0050] In the example embodiment of the invention the Data Store 404 is implemented as wewnątrzpamięciowe data warehouse. Wewnątrzpamięciowe of Data Storage operation 404, typically much faster than disk systems. In this regard, the Data Store 404 can achieve the performance they give better performance and lower costs for providers CSP according to the embodiment of the invention.
[0051] FIG. 5 is a database Directory Information Base (DIB) 500, according to the embodiment of the invention. For example, the DIB 500 represents the directory structure of the Data Repository 404 shown in FIG. 4. The DIB 500 includes a root node 502 and one or more records, such as records 504a, 504b, 504c, 504d, and so on. Records 504a - 504d may, known as "objects". Each entry 504 in the DIB 500 database can contain one or more attributes, such as the entry 504c contains attributes 506a, 506b, 506c, 506d, and so on. Attributes 506a - 506b are defined further as the attribute 506. Each attribute 506 may include a type 508 and one or more values 510. The DIB 500 represents the set of data stored in the directory. For example, the DIB 500 may contain data describing subscribers to the communication network, for example, subscribers of Mobile Telecommunication, 204.
[0052] FIG. 6 depicts a Directory Information Tree (DIT) 600, according to example of the invention. The DIT 600 represents the structure (schema) in the DIB 500 shown in FIG. 5. The DIT 600 includes a root node 602 and record 504, such as records 504a - 504i and so
55P31384PL00
EP 2 156 649 B1 next. The DIT 600 is presented here as a hierarchical tree structure with the root node 602 at the base. Each node in the tree represents the entry 504. If the DIT 600 is designed to przylegało for formats of different standards, for example, the X. 500 standard, then each entry 504 in the DIB 500 database is unique and is uniquely determined by the rozróżnioną name Distinguished Name (DN). Name the DN of the entry 504c, for example, based on the name record DN of the master, as, for example, the record 504a, in addition to specially identified attributes of the entry 504c (select values). Rozróżniona value and its associates of the type known as Rozróżniona relative Name (Relative Distinguished Name (RDN)), which is unique identificeret the entry 504c with respect to his ancestor, such as records 504a. Therefore, to describe the name of the RDN uses the attribute type and rozróżnioną the value of the entry 504c. For example, the record 504a, if the DN "c=UK", where "c" is the attribute type (short for "country" ("country")), and "UK" rozróżnioną value for a record, the record 504c of contents "o=MyCompany" where, o is the attribute type (the abbreviation for "organization"), and "MyCompany" rozróżnioną the value for the entry, the DN for the entry 504c will be " o= MyCompany, c=UK" or "MyCompany.IN THE UK”. DN name is the same for the URLS used on the world wide web the World Wide Web.
AGENTCI DIRECTORY SYSTEM - OPTIMIZED ROUTING [0053] a system of Mobile Telecommunication 204 may comprise huge numbers of subscribers. For example, some telecommunication systems contain millions of individual subscribers. In accordance with what was said, despite the fact that data associated with these subscribers can be logically represented as, for example, shown in the Central Data Repository 404 with digit 4, this physical implementation may be such that the data are sections on significant subgroups for more speed and overall strength of the telecommunications system. Data can be
55P31384PL00
EP 2 156 649 B1, for example, stored and played back in the network server according to the embodiment of the invention. The X. 500 standard data partition supported (controlled) by the Agent Directory Server (Directory Server Agent (DSA)).
[0054] FIG. 7A illustrates Agent Directory System (DSA) 702 User Agent Directory (Directory User Agent (DUA)) 704 according to the embodiment of the invention. Agent DSA 702 includes one or more directory servers, such as directory servers 706a
- 706c and so on. Each of these directory servers 706a - 706c includes a data store 708a - 708c, and so forth, which we consider here as a data store 708, according to the embodiment of the invention. The data store 708 preferably contains wewnątrzpamięciową database. Directory servers 706a - 706c also include software, directory servers, such as software, applications, directory servers 707a - 707c, according to the embodiment of the invention.
[0055] the Agent DSA 702 is configured to refer to the capacity and load for each of their respective directory servers 706a
- 706c according to the embodiment of the invention. Agent DSA 702 may also indicate when none of the directory servers 706a - 706c does not communicate, whether it's for scheduled maintenance or is it because of the connection, equipment or other accidents. In accordance with that shown in FIG. 7A, agent DSA 702 is implemented as a cluster of different directory servers, such as, for example, directory servers 706a - 706c. In this regard, the agent of the DSA 702 may use its knowledge of the condition and capacity of the directory servers for quick and efficient servicing of requests for data. In fact, the agent DSA 702 operates as a more powerful and reliable server in the catalog than any of the directory servers under its control, acting independently. Of course, the agent DSA 702 may also be implemented with a greater or lesser number of directory servers 706, as shown in FIG. 7A. In the example embodiment of the invention each of the directory servers 706 runs the same software components and keeps an identical copy of at least part
55P31384PL00
EP 2 156 649 B1 of the base of the DIB 500 (shown in FIG. 5) in wewnątrzpamięciowym the data store 708 for which the agent DSA 702 has responsibility. [0056] Agent DUA 704 is a common term for a client of directory services like LDAP client or DAP. For example, agent DUA 704 makes a request for data as LDAP operations on behalf of various client applications, according to the embodiment of the invention. How can this be shown in FIG. 7B, a typical system includes multiple DSA 702. Agent DUA 704 is connected to one of the servers DS 706 in one of the agents DSA 702. Agent DSA 702, the server can keep the data for the query (in this case, he can handle the request) or may know the agent DSA 702, which is better suited to service this request. In the latter case, the server DS 706 selects one of the servers 706 in that alternative DSA 702 agent and sends request to it (łańcuchowanie). This process is described again below in the section Optimal Routing.
[0057] In this regard, the agent of the DSA 702 determines which server in the catalog 706 must respond to the data request. Operations agent DSA 702 and servers DS 706a - 706c they are typically transparent to the DUA 704 agent. In accordance with what has been said, in various examples of the invention, the agent DUA 704 could connect to any of the directory servers 706a - 706c to obtain the same data. If the data store 708 agent DSA contain only the base part of the DIB 500, then a complete database of the DIB 500 can be constructed using one or more additional agents DSA where the data store 708 contains other part of the base of the DIB 500. In such embodiment, the DSA 702 also need information to dopomożenia them in choosing the right agent DSA 702 for this promotion.
[0058] the software running on the directory servers 706a 706c includes software, directory servers 707a - 707c according to the embodiment of the invention. PRgramowanie directory server 707 provides a distributed data infrastructure and providing access to the directories for the directory servers 706. In accordance with what was said
55P31384PL00
EP 2 156 649 B1 and above, operations of a lower level are wewnątrzpamięciowe data warehouse 708a - 708c are not part ujawnianego and claimed invention here. The examples of the invention can be configured to work with datastore low level.
[0059] FIG. 7B illustrates a distributed hierarchy comprising three DSA 702a, 702b and 702c, according to the embodiment of the invention. These DSA 702a 702c illustrate how given the DIB 500 can be deployed and replicated for quick access in a communication network.
[0060] for Example, the DIT 600 may be so large that it requires to distribute to multiple agents DSA, such as DSA 702a - 702c. Server HSS 301, for example, need to know how big or small the DIT 600 is, or on which agent the DSA stores a piece of information. Server HSS 301, for example, it needs only to send your work through an agent DUA 704, which directs the request to the agent DSA 702, which either answers the request or is itself the agent of the DSA 702, which will respond to the request, according to the embodiment of the invention.
[0061] furthermore, Assume that given the DIB 500 includes data relating to subscribers in a communication network, including the IMSI of the subscribers (the unique number that is affiliated with all subscribers of mobile communication network GSM and UMTS), and related data, MSISDN of the subscribers (fixed number of digits that is used to identify a particular device). This kind of the DIB 500 can be decomposed in agents DSA 702a - 702c as follows: subscriber information, such as their names and addresses must be placed in agent DSA 702a, which acts as " the main agent DSA. The relevant data of the subscribers IMSI can be located in the agent DSA 702b, which will act as an IMSI domain (such as the IMSI 323 shown in FIG. 3) and the corresponding data of the MSISDN numbers of the subscribers may be located in the agent DSA 702c, which will work as a MSISDN domain (as, for example, the MSISDN 325 as shown in FIG. 3).
55P31384PL00
EP 2 156 649 B1 [0062] In this regard, in this exemplary configuration, the agent DSA 702a can serve as a "primary" agent DSA ; DSA 702b agent can be used as an agent DSA the name "IMSI", and the agent DSA 702c can be used as an agent DSA the name of "MSISDN". Chief agent DSA 702a includes one or more directory servers 706a - 706c; the server name is "IMSI" 702b includes one or more directory servers 706d - 706f; while the agent DSA the name "MSISDN" 702c includes one or more directory servers 706g - 706i. One or more directory servers 706a to 706i from include software, directory servers, such as, for example, software, directory servers 707 shown in FIG.
7A and data warehouse such as data warehouse 708 is shown in FIG. 7A, according to the embodiment of the invention. Chief agent DSA 702a keeps the main element; the agent DSA 702b name "IMSI" stores data related to "IMSI", while the agent DSA 702c name "MSISDN" stores data of "MSISDN".
[0063] In this regard, various examples of the invention one or more agents DSA 702 may be implemented together to save the DIB 500, such as a complete database of DIB for the whole communication network. Each agent DSA 702 is typically responsible for a particular dataset, which contains a database of the DIB 500. In the example above, the agent, the DUA 704 could connect to any of the available agents DSA 702, for example, the main agent DSA 702a, 702b agent DSA the name "IMSI" and the agent DSA 702c name "MSISDN. The request coming from the agent DUA 704 is transparently processed by the DSA agent, e.g., agent DSA 702b name "IMSI", masterując data.
OPTIMIZED ROUTING [0064] FIG. 8 illustrates optimized routing in the distributed hierarchy of agents DSA shown in FIG. 7B according to the embodiment of the invention. In accordance with what was said above, DSA 702a 55P31384PL00
EP 2 156 649 B1
702c work together to provide a distributed directory. Each agent DSA 702 holds a subset of records on their servers DS 706, along with knowledge about the possible locations of the records that he keeps. In accordance with the fact that said agent DSA 702 may be capable of performing operations directory locally when it comes to data located within its own subset of the directory. Otherwise, the DSA 702 agent (e.g., agent DSA 702a) uses its knowledge of the directory to make the choice that the agent of the DSA (e.g., DSA 702b agent) is the best agent DSA to perform the operation, and then associate this transaction with the other agent DSA 702b.
[0065] in Accordance with what was stated above, each agent DSA 702 is implemented as a collection of servers DS 706, each of which stores, as a rule, completely almost identical copy of the subset of the directory. In this regard, each of these servers processes the DS, as a rule, the operation of the directories in the same way. As part of the process chain, the DS server 706 agent DSA 702 has a choice to make servers DS 706 in another agent DSA 702 to receive related operations. This choice is conventionally implements the sharing of the load, on the basis of the Moscow ring road or heavily used and may include the ability of the DS server to service this request. For example, if you know that the DS server 706 is not nearly the same version of the directory in the result of the preliminary issue, he will not be elected.
[0066] however, a conventional physical implementation of the DS server 706 are such that they are scattered geographically. In addition, it is often the case, when a particular physical place is there will be one or more servers DS for other agents, the DSA 702. In other words, the DS server 706 various agents DSA 702 can be klasterowane times in relatively close physical, close and/or on and/or near the point of view of communication distance.
[0067] for Example, the set of agents DSA 702 shown in FIG. 8 is physically located so that the server DS 706a, DS 706d, the server and the server DS 706g physically reside in the site 1 804a; DS 706b, the server, the DS server
55P31384PL00
EP 2 156 649 B1
706e and server DS 706h physically reside on site 2 804b, and DS 706c server, server, DS 706f, and DS 706i server are physically in
Site 3 804c. Such a distribution provides, among other things, additional flexibility in the communications network. For example, if a failure occurs in Site 1 804a, operations can be continued smoothly for agents DSA 702a - 702c using DS server 706 found on the site 2 804b, and 804c 3.
[0068] communication channels (e.g., WAN) with a single cluster DS (i.e. the DS server in the same location) to another cluster DS, as a rule, have less bandwidth and higher latency than communications within a single cluster DS (i.e. the DS server in the same location). In other words, in General, takes less time 706a server DS server DS 706d what 706s server DS server DS 706e as the DS 706a server which server the DS 706d located in the same place, i.e. the site 1 804a.
[0069] provided that the accesses to the data share from the point of view of the workload between the DS, then the server selection DS 706 for communication based on the physical location of the server DS 706 can give optimize the use of transport (for example, optimal use of external networks) and reduce response time for operations directory. In other words, the server needs a positive DS 706a to communicate more with the server DS 706d, when it needs data associated with the DSA 702b agent than with DS 706e server if server DS 706 f because the DS server server 706a and DS 706d are in the same place, namely, in Site 1 704a. Of course, if the server is DS 706a requires data from DSA 702b agents and the server DS 706d is unavailable for any reason, the server DS 706a would be configured to relationships, servers, DS 706e or DS 706f servers, which are also part of the DSA 702b agent, but are in a different place than the server DS 706a. [0070] Agent Trace Locations 808 on the server DS 706 is configured to determine that the second server DS 706 can finish data data query with the lowest cost relative to many other
55P31384PL00
EP 2 156 649 B1 the DS server according to the embodiment of the invention. Agent Trace
Space 808 can be configured to account for the distances between all possible DS server or any subset of the DS server. For example, can be more disadvantageous to the Agent Trace Locations to calculate the distance to another DS server in China, when the DS server has a mirror in six other places in Europe. Easier approach polegałoby in the periodic calculation Agent Trace Space 808 distances to other places in Europe, the default principle of space utilization in China if the other European servers DS was not available, according to the embodiment of the invention.
[0071] in addition, the server selection DS 706 Agent Trace Space 808 may take into account a multitude of factors, according to the embodiment of the invention. For example, Agent Trace Space 808 may base its selection of another DS 706 server using the ranking of connectivity between nodes (e.g., places), where rank values are obtained based on such factors as throughput, latency and cost. Assume from the example above that the server DS 706a requires data from DSA 702b agents and the server DS 706d is not available. Assume moreover that the 2-804b much "closer" of site 1 804a than 3 804c regarding the site 1 804a, where the concept of "closer" contains a component based on at least one factor from the bandwidth, latency, and cost, for example, the minimum amount of points for the amount of bandwidth + latency + cost. In line with this, Agent Trace Space 808a may recommend that the DS 706a server connected to server DS 706e of site 2 804b. If the server is DS 706e is not available, then the Agent Trace Space 808a may recommend that the DS 706a server made attempts to complete its operation on the agent DSA 702b with the server DS 706f on Site 3 804c.
[0072] In another embodiment of the invention the Agent
Trace Space 808 can be configured to dynamically select a server DS 706. For example, suppose based on the example that the device próbkujące 806 affiliated with each of the field periodically controls the "distance" between this Place and all other Places
55P31384PL00
EP 2 156 649 B1 of interest. For example, the Device Próbkujące 806a with of site 1 804a may periodically monitor the "distance" to the site 2 804b, where "distance" is measured using at least one of the parameters: bandwidth, latency, and prices, for example as the smallest value for the sum of the bandwidth + latency + cost. Próbkujące device 806a may then provide the result of this calculation the "distance" for the Agents Trace the Place 808a, 808d, 808g on Site 1 804a. Próbkujące device 806a may also be configured from the point of view of how it measures "distance" and how often is this measurement. In addition, the Device Próbkujące 806a may base its definition of "distance" to the actual measurements, such as response time, obtained with a DS server 706 and reported to the unit Disk 806a. This dynamic approach takes account of changing network conditions and problems with the data servers DS or ways of communication. The Device may Próbkujące 806a can be hidden inside the DS server 706, for example, in the Agent Trace Space 808.
[0073] In another embodiment of the invention, assume that the Agent Trace Space 808 calculates "distance" or "closeness" between the two DS servers from the point of view of "value." Moreover, we assume that the elements of cost represent the cost of bandwidth, delay and cost of access according to the embodiment of the invention. Of course, other components may include the main elements driving the cost. Suppose in addition that the weighted cost equation could be expressed in a pattern such as, for example: (Waga1 x bandwidth) + (Waga2 x Latency) + (x Waga3 Cost of Access). Agent Trace Space 808 may be configured to periodically calculate new results for this equation, for example, every day, every hour, every minute, and the like. Agent Trace Space 808 may be, then, to make sure that when it was necessary to bind to the DS server 706 was trying to select a server DS 706 lowest price. This, of course, may mean that the DS server that was not located in the same place. The device may próbkujące 806 can perform these equations and then provide the results
55P31384PL00
EP 2 156 649 B1 for a target set of Agents Trace Space 808, according to the embodiment of the invention.
ALIASES AND ALIAS HIDING [0074] FIG. 9A depicts a DIT 900 having an alias Entry 902, according to example of the invention. The DIT 900 includes one or more records, such as records 504a - 504a and so forth, the root node 602, and the alias Entry 902.
[0075] As mentioned earlier, the basis of the DIB 500 shown in FIG. 5 case record or object is unique and is uniquely determined by the DN. However, the DN should not be the sole name under which the entry, as the entry 504f can be determined through a client application. Record the alias, as the alias Entry 902, the entry in the DIT, such as DIT 900, which has an attribute, such as, for example, "aliasedEntryName", which contains the name of another element in the DIT 900. For example, the alias Entry 902 might have an attribute with the name "aliasedEntryName", whose value is the name of the "Initial 504f". The second entry (e.g., the entry 504f) does not necessarily exist in the DIT 900, although Yes, in this example. It should also be noted that the structure of the alias Entry 902 in the DIT 900 should not be fundamentally different than in the records 504a - 504g, the difference in names ("record" and "alias record"), presented here as an aid in understanding the function of the alias record.
[0076] Recording Alias, such as, for example, an alias Entry 902, provide alternative names for the record, for example, the entry 504f. An alias is a special entry in the database of the DIB 500 which points to another element, such as the entry 504f. the alias is similar to a symbolic link in the file system. Therefore, the alias is a useful way to ensure the database record, such as record 504f, numerous personality without duplicating data. Aliases are especially useful if the data is saved under a unique name (or key), which will not be too often changed (can be selected through System Prowizjonowania 410), but they should be publicly available
55P31384PL00
EP 2 156 649 B1 through different personalities, as, for example, the application associated with the number of the IMSI 323, the MSISDN 325, the Uniform Resource Locator (Uniform Resource Locator (URL)) and others, which may vary, according to the embodiment of the invention. Using aliases allows a one-time write data, and then reference them using the many different personalities that are implemented as aliases. Recording alias, such as, for example, an Alias Entry 902, can be added, changed and/or removed without affecting the data.
[0077] a New alias can be implemented in the DIT 900 with Module Creation Alias 905. Module Creations Alias 905 can be configured to create an Alias in the DIT 900 so that other components, for example, Recognition Module Name 909 shown in FIG. 9B, could do dereferencji an Alias for data requests received from client applications according to the embodiment of the invention. Module Creations Alias 905 may include a user interface, so that aliases can be created after the initial prowizjonowaniu (e.g. "on the fly"), so as to ensure the rapid development of new aliases. The Module of Creation of the Alias 905 may be accessed using normal operations in directory "addentry method", such as LDAP or DAP.
[0078] In some examples of the invention, the Creation Module 905 implements the Alias the alias as the database entry in the DIB 500 with a mandatory attribute that provides the DN of the entry pointed to by the alias. For example, suppose that the entry 504a has the name DN "c=UK", the entry 504c has the name DN "o=MyCompany, c=UK" and the entry 504d has the name DN "=CompanyX, c=UK". The entry 504f has the name DN "employeeId=111, o=MyCompany, c=UK". Therefore, the Recording Alias 902 may have an alternative name "cn=Joe, o=MyCompany, c=UK" and specify the entry 504f.
[0079] the service Provider directory, such as CRYPTOGRAPHIC provider, may want to use aliases, but does it in a different way than offering this to various known protocols and methods you need to use the alias. For example, the the directory service provider may be required to provide services, you must use the alias for client applications, such as, a server HSS 301, which can be designed
55P31384PL00
EP 2 156 649 B1 with the thought of the possibility of using aliases. In addition, the directory service provider may also wish to hide from the one or more applications, the fact that it was done aliasowanie, even when the client application can implement, you must use the alias. This kind of hide the alias can be performed, for example, because of security reasons.
[0080] FIG. 9B illustrates the Module Hide the Alias 903 is compatible with DIT 900 that contains the alias 903 to perform alias to hide the data, one with a Sender Unit 920, such as, for example, a client application, according to the embodiment of the invention.
[0081] the Module Hide the Alias 903 hotel is located in the directory server, such as server DS 706, shown in FIG. 7A, mediates during queries performed Popular Block 920 and control dereferencję Alias for queries and updates, regardless of the expectations of the Senders in Block 920, according to the embodiment of the invention. In accordance with what you said, Requiring the Block 920 may represent a unit, such as a client application, end user agent or a remote DSA that may be need data to complete the procedure łańcuchowania initiated in the catalogue section under the control of the agent DSA. For example, in the Block 920 can be a server HSS 301, which has not been configured for control is also necessary to use a pseudonym and/or server HSS 301 for which the CSP would like to hide aliasowanie.
[0082] in Accordance with the fact that said Module Hide the Alias 903 can replace in the results presented Senders Block 920 name in the records names that coincide with the vision of the tree DIT 900 on-Demand Unit according to the embodiment of the invention.
[0083] With use of the Module Hide the Alias 903 recording, such as recording 504f can include data that can have access, Requiring Unit 920, for example, a server HSS 301, using another name, for example, the name of the Record-Alias 902. Requiring Unit 920 may be, for example, must address the message, such as record 504f, using a name that is unique to the Sender Unit 920.
55P31384PL00
EP 2 156 649 B1
However, assume that the Requesting Unit 920 was not designed so that it can use you must use the alias as it is conventionally applied. The module Hide the Alias 903 efficiently supplied, so that this kind of Spot Unit 920 in the possibility to use the alias without requiring any changes relative to the Sender Unit 920.
[0084] in Fact, the record, such as record 504f, can have different recording aliases (for example, many instances of the alias 902), with each entry of the alias is the name used by other Request Unit 920 to access the data contained in the record 504f. This approach allows the Central location of the data associated with the communication network, for example, Data Store 404 without the need to change existing Queries 920 Units (e.g., client applications) according to the embodiment of the invention. In this regard, the Module Hide the Alias 903 allows the CSP to use the application inherited, such as significant server HSS 301, even after switching to a different architecture of the telecommunication network.
[0085] the Module Hide the Alias 903 can also remove any statement that was made aliasowanie, with the approval and transmission of data to the Sender Unit 920 according to the embodiment of the invention. In short, embodiments of the invention provide data in the native format of the Sender Unit 920, so that these data can be presented Senders Block 920 with the expected attribute value and name. In such cases, the Requesting Unit 920 only needs to know an alternative or aliasową the title of the record.
[0086] Hiding the alias is a mechanism that can be used depending on your application, to hide the existence of the alias, according to the embodiment of the invention. How to hide the alias for a given application can be included in the data file stealth the alias Hiding Data File 91.4, according to the embodiment of the invention. When Sender Unit 920 performs hide the alias operations needed sought after Block 920 involving an alias, such as, for example, an Alias Entry 920, appear Sender Unit 920 as an operation on normal
55P31384PL00
EP 2 156 649 B1 of the recording, such as, for example, the entry 504f. The module Hide the Alias 903 may apply dereferencję that alias, and therefore performs name mapping on any returned entries names, to touch the source database name in the query Sender Unit than the actual element name. Therefore, the search results are presented Sender Unit 920 may include the name aliasową and not the actual name in the DIT 900 records returned by the search. From the point of view of the Sender Unit looks like an alias of the actual parameter. Similarly, all child elements in relation to the real records look like child elements in relation to the alias. In this regard, Requiring Block 920, such as, a server HSS 301, can update and search for records using the name aliasowej.
[0087] According to the example embodiment of the invention, the Module Hide the Alias 903 may perform three different functions:
• monitor dereferencję alias the Recognition Module Names 909 may be in contradiction with the expectations of the Sender Unit 920 (e.g., client applications), which began the application data and/or • monitor dereferencję the alias Module the Search/Update operations 911 or directories associated Łańcuchowania Module 917 may be in contradiction with the expectations of the Sender Unit 920 (e.g., client applications), which there is a request for data and/or • to change the name in the results generated by the Search Module/Upgrade 911 or returned by the Module Łańcuchowania 917, to refer to the base name provided by the Demand Unit 920 (e.g., client application), which began the application data and not a diagnosis base name (RDN), and in addition, for all of the nicknames, which I encountered in the process of finding under the tree, recursively replace the relative real entry names with the relative names of the entries
55P31384PL00
EP 2 156 649 B1 aliases, so it looks as if there was one present under the tree under the diagnosis of a basic element, without aliasing.
[0088] FIG. 9B illustrates processing operations, the directory application Module Hide the Alias 903 in the three cases above, according to the embodiment of the invention.
[0089] Requests to access data in the directory can be supplied from different units or sources. For example, requests for access to data, such as search and updates can originate from a client application of the user or even agent directory system, such as an agent of the DSA 702 shown in FIG. 7A. In accordance with what has been noted above that Require Block 920 may represent a unit of measurement, such as a client application, end user agent or a remote DSA that may be need data to complete the procedure łańcuchowania initiated in the catalogue section under the control of the agent DSA.
[0090] And in any case Requiring Block 920 sends a data request to the Server Operations Directory 907. Server 907 Operations Directory represents a unit configured to receive data requests and then deliver them to the relevant units for processing associated with the directory server DS, so that the requested operation can be performed. For example, an LDAP server is a typical server operations directory such as for example, the Server Operations Directory 907. [0091] the Server Operations Directory 907 receives from the Sender Unit 920-a query about data stored in the directory, such as DIT 900 and passes the request to the Module Hide the Alias 903 (step A). The module Hide the Alias 903 passes it the request to the Recognition Module Names 909 after modifying the data request to reflect any operating system, hide the alias (step B). When you assign the operating mode of concealment, the alias Hiding Module 903 Alias can view the Data File Stealth Alias 914, which may contain data associated with concealment, the Alias configured based on such principles as to the application, to the user, ogólnosystemowy and the like. In this regard, the Module Hide the Alias 903 may
55P31384PL00
EP 2 156 649 B1 to modify the data request to control dereferencji the alias can be, in contrast to the expectations of the Senders in Block 920, according to the embodiment of the invention. In the case of a chain query received from the remote agent DSA, operating modes, hide the alias that can be specified in query parameters łańcuchowania where equivalent treatment to that remote agent DSA has determined the operating system hide the alias may be based on your own Data File Stealth alias 914 or on the basis of chain operations. [0092] the Recognition Module 909 Name recognize name in the future-Module Hide the Alias 903, according to the embodiment of the invention. The Recognition module 909 Name is in the directory server, such as server DS 706, shown in FIG. 7A, performs the recognition process, which is the initial part of the processing operations of the directory, according to the embodiment of the invention. The Recognition module Names 909 headquartered basic element of the operation of the directories in the DIT 900 by using the name supplied as an operation parameter, a directory via the Module Hide the Alias 903. The Recognition module Names 909 account name of each RDN in turn and is headquartered element corresponding to the name of an RDN, which is directly a child of the previously lokowanego record (or record main for the first name, RDN). This process continues until, until all the names of the RDN will be considered or until the name cannot be fully addressed to permit operation in łańcuchowania for the remote agent DSA, which can be able to fully diagnosis the names, according to the embodiment of the invention.
[0093] If in the process of recognition name Recognition Name 909 encounters an alias entry, the name resolution process may be restarted, currently known part of the file name is replaced with the value of the parameter alias, such as the above mentioned record attribute "aliasedEntryName", according to the embodiment of the invention. this restart operation, which is known in the art as "dereferencja alias" can happen more than once to resolve the name.
55P31384PL00
EP 2 156 649 B1 [0094] the Detection name is a common processor in protocols such as X. 500, although the recognition of names according to the embodiment of the invention does not necessarily have to be performed on any one particular Protocol. The usual LDAP Protocol, for example, restricts dereferencję alias only for operations zapytywania, although this limitation is not present in the normal Protocol X. 500. More importantly, this conventional process is controlled by Requiring Unit 902, such as, for example, the client application how the server HSS 301, and the Module does not Hide the alias 903. In other words, the client application must determine that the operation dereferencji alias has to happen. In addition, the usual result of dereferencji alias indicates that alias dereferencja was due to the inclusion of, among other things, fully dereferencyjnych the names of the entries in the results provided to the client application. According to the example of the invention Requires a Block 920 there is no need to specify that dereferencja alias should occur, as well as Requiring Unit 920 would not necessarily have to fully reference the record name in the provided results.
[0095] Suppose, for example, the Recognition Module Names 909 received requests to read data located at "Root.Entry1.Entry2.Alias” in the DIT 900. The Recognition module 909 Name dates back to the first Node of the root 602 (step C1). The Recognition module 909 Name dates back further to the entry 504a for this particular request (step C2) from the access to the record 504c (step C3). The Recognition module 909 Name dates back further to the Alias Entry 902 is an indication that the Alias Entry 902 is an alias entry and that aliasowany entry has name "Root."Entry1.Entry2.Entry3” (step C4). In accordance with the fact that said Recognition Module Names 909 restarts the name resolution process, and repeats steps C1, C2, C3 according to the embodiment of the invention. The Recognition module Names 909 reaches then record 504f, and believes that this is the actual item and therefore has fully diagnosed original name (step C5).
[0096] the Recognition Module 909 reports the Names of the localized recording 504f together with the track uploaded into the Module Hide the Alias 903 (step D). Module
55P31384PL00
EP 2 156 649 B1
To hide the Alias 903 stores information about dereferencyjnej way, at least temporarily, according to the embodiment of the invention.
[0097] If required the local processing of the search/update for request to complete (that is, the name was fully recognised locally), the Module Hide the Alias 903 transmits the localized record (for example, recording 504f) and the original request, modified for the assigned operational mode, hide the alias for a Module the Search/Update 911 (step E).
[0098] it is Possible, if łańcuchowanie is required to complete the request (i.e. the name was not fully recognized), the Module Hide the Alias 903 passes the original operation, with a previously established diagnosis mode control stealth alias and every dereferencyjną information aliasową Łańcuchowaną Module 917 (step E').
[0099] the Search Module/Update 911 is working on the entry (e.g., entry 504 f). Is the directory server, e.g., server DS 706, shown in FIG. 7A, the Search Module/Update 911 performs the need through the Module Hide the Alias 903 to the result of the enumeration supplied by the Recognition Module Names, 909, according to the embodiment of the invention. In the case of updating the Module Search/Update 911 performs the update on the record, e.g., the entry 504f (step F1). In the case of the search Module the Search/Update 911 performs the search starting from the located record supply Recognition Module Names 909, e.g., the entry 504f (step F1) and may also search a subset or the face of their child records, e.g., entry 504g (step F2). In the study sub-tree under the diagnosis entry, the Search Module/Update 911 might face other Alias (for example, suppose that the entry 504 g is an alias) and execute dereferencję alias in the same way, which makes the Recognition Module Names 909.
[0100] the Search Module/Update 911 can also be a child links to remote agents DSA, which indicate that the subtree is split and the child elements from this point there is
55P31384PL00
EP 2 156 649 B1 supported remotely. In such cases łańcuchowaną new search operation (system mode stealth alias) for the remote agent DSA (via Module Łańcuchowaną 917) (phase I), and all the results (step J) with this łańcuchowanej operations are included in the generated locally.
[0101] the Search Module/Update 911 reports that the response received information (locally and/or łańcuchowanych requests), and also the path taken in the Module, Hide the Alias 903 (step G). Search module/Update 911 typically reports the path information to the Module to Hide the Alias 903 using completely dereferencyjnych names for entries in the search.
[0102] the Łańcuchowania Module 917 acts as a unit that requires przywoływanym agent remote DSA, passing łańcuchowane operations to the Server Remote Operations Directory 931. Is the directory server, such as server DS 706, shown in FIG. 7A, Module Łańcuchowania 917 works in conjunction with the Recognition Module Names 909, alternatively, for a Module the Search/Update of 911 in the case when a Directory was distracted and where the Recognition Module 909 Name can not fully resolve the name locally, and called the appropriate link, which indicates that the remote agent DSA may be able to resolve the name. Module Łańcuchowania 917 sends the resulting operation of the directory and all dereferencyjne alias, the Server Operations Directory 931, which is similar to Server Operations Directory 907, but is on a remote agent DSA. Module Łańcuchowania 917 according to the results received back from the agents DSA Module Hide the Alias 903 (step G') or the Module the Search/Update 911 (step J), depending on which module sent the request łańcuchowania.
[0103] the Module Hide the Alias displays the results of queries to get the data back to the Server Operations Directory 907 (phase H), which, in turn, passes information back to the Sender Unit 920. Module
To hide the Alias 903 may be configured for removing each reading that finding the right information was due to the alias and after
55P31384PL00
EP 2 156 649 B1 simply passes the data back to the Server 907 Operations Directory. The module Hide the Alias 903, depending on its management, may reconstruct the tree as if it contained the Aliases, and return to a normal respectively, for example tree: root.entry1.entry2.alias902.entry4 (a tree that can be canceled within a sought after Block 920, instead of the actual tree in the directory: root.entry1.entry2.entry3.entry4). In this regard, the Module Hide the Alias 903 can change the name in the results generated by the Search Module/Update 911, so they belong to the base name provided by Block 920 in Demand than the recognized base name (RDN), and also so that all the required entries in the result podrzędności recording alias to record the base presents "on the spot" and not the additional subtree, according to the embodiment of the invention.
[0104] In the example embodiment of the invention, if the Module is Hide the Alias 903 returns the target of any alias in the search result, and the RDN attribute specified is returned in the attribute list, may be replaced on the RDN attribute, it means the alias RDN replaces the real name RDN in the list. Perhaps, the alias RDN may be appended to the returned list of attributes, or may be already present in the list if the alias RDN is also an attribute of real-time recording.
[0105] in Accordance with that shown in FIG. 4, the solution to the problem of multiple independent data silos for each application in the network is the data connection in the same datastore.
[0106] in Accordance with what was discussed earlier, in some cases, exactly the same data exist in different pre-existing data stores, such as both the data store of the subscriber "John Smith". However, in some cases, the application may require that DN had the name "Customer", and another application may require that DN had the name "Subscriber". The name DN in the data store may have the name "Name". In all three cases, DN, "Subscriber", "Customer" and "Name" indicates the data record having the value "John Smith". Instead of having to play three times, "John Smith" in the database name DN can be
55P31384PL00
EP 2 156 649 B1 is "Name" with two aliases "Subscriber" and the Client". Suppose that the application requires the name of the "Subscriber" is removed from the system, the alias for "Subscriber" can be removed, according to the embodiment of the invention. Suppose in addition that adds a new application that uses the name DANIEL "Name" for the name of the caller, you add can be just alias "Name".
OPTIONS [0107] FIG. 10A depicts a DIT 1000 with a record wariantowym
1002 according to the embodiment of the invention. The DIT 1000 contains one or more records, such as records 504a - 504e, and so forth, the root node 602 and record wariantowy 1002. Striping such as wariantowy entry 1002, give an alternative representation of the data stored in the Data Store 404. Alternation of entry 1002 defines an entry which groups together all the attributes of the various entries in the DIT 1000, such as entries 504c and 504d. Therefore, when the requiring unit, such as a client application, goes back to wariantowego entry 1002, the requesting unit receives access to attributes from other entries, such as entries 504c and 504d. Access to these other records may be transparent to the sender unit that is not need to know how the underlying data are ustrukturalizowane.
[0108] In this regard, unless the requesting unit receives the data in its expected manner, the requesting unit can work as if the data is still there was, for example, in one corporate silo of data. In other words, relative to the sender unit should not be made any changes to accommodate the presence of the variant according to example of the invention. More importantly, the implementation of wariantowego record can be sometimes crucial, to avoid having to make changes on sender unit for proper interaction with the DIT 1000. Also, to make any necessary changes to the sender units can be achieved by creating wariantowego
55P31384PL00
EP 2 156 649 B1 which complies with the new requirements that senders units. In fact the options make redirects at the attribute level, whereas aliases, such as alias 902 shown in FIG. 9B, doing redirects at the item level, according to the embodiment of the invention. [0109] Wariantowy entry 1002 is an element in the DIT 1000, which has no requirements specified attributes different from the attributes "objectclass", according to the embodiment of the invention. Branch of the definition of "objectclass" is called "variant" and contains a number of attributes. Membership option objectclass means that a certain rule must be provided when processing one or more attributes of this record. For example, in accordance with that shown in FIG. 10A, the value of the "Variant" attribute objectclass indicates that the attributes "My Company "Contact" and "Company X Contact have a rule for obtaining their values from other attributes (the attributes "real") in other records (records, "concrete") in the DIT 1000, such as the entry 504c. For example, so that wariantowym post 1002, the value for the attribute "My Company Contact" znajdywany in the attributes of the "Address, Contact, and Website" entry 504c.
[0110] In various examples of the invention, the Module Creations Option 1005 may be active at the initial provide. Options can be supplied together with data, which are determined by options. Module Creations Option 1005 may also create variations on the fly, as needed, for some time after the initial prowizjonowaniu, according to the embodiment of the invention.
[0111] in This variant (for example, 1002) can be implemented in the DIT 1000 using Module Creations Option 1005, according to the embodiment of the invention. For example, in accordance with that shown in FIG. 10A, the Module of Creation of the Version 1005 may create the Variant 1002 so that it is an element wariantowego attribute objectclass that contains the attribute "my company "contact" and the attribute "company X" contact", the attribute "my company contact" gets its data from the record 504c whose attributes are "address", "contact" and "website" and "company x contact gets its data from the entry 504d whose attributes are "address", "contact" and "website".
55P31384PL00
EP 2 156 649 B1
Module Creations Option 1005 may provide a user interface so that options can be created "on the fly" for rapid deployment of new variants. The Module of Creation of the Version 1005 may be invoked via the usual operations directory addentry method, for example, through LDAP or DAP.
[0112] After creating a Module Creations 1005 Variant variant 1002 in the DIT 1000, the query attributes 1002 can be transparently provided at the request of departments that require data represented by these attributes, according to the embodiment of the invention. Suppose, for example, that the requesting unit requires data for the attribute "address ""My Company" Contact", because the version of the objectclass attribute defines the address attribute for "My Company Contact" so that is the address attribute of the entry 504c, that is, the data that the variant 1002 returns the sender unit.
[0113] FIG. 10B illustrates a variant processing in the DIT 1000, containing the Variant 1002 of a data request from the Sender Unit 1020, such as, for example, a client application, according to the embodiment of the invention. The requesting Unit 1020 can be any unit, such as a client application, end user agent or a remote DSA that may be need data to complete the procedure łańcuchowania initiated in the catalogue section under the control of the agent DSA.
[0114] the Server Operations Directory 1007 is a unit that is configured to receive data requests and then deliver them to the relevant units for processing associated with the Directory Server so that the requested operation can be completed, according to the embodiment of the invention. For example, an LDAP server is a typical server operations directory like, for example, the Server Operations Directory 1007. The server Operations Directory 1007 is located in the heart of the access in close proximity (e.g., współlokowany) with the storage mechanism of the data Manager data tree the DIT 1000. In this regard, the processing wariantowego record (for example, obtaining attribute values), as the Variant 1002, can be performed in the access point
55P31384PL00
EP 2 156 649 B1/from the data storage mechanism. For example, processing wariantowego record on the Server Operations Directory 1007 can occur in the agent directory system, such as agent DSA 702 shown in FIG. 7A where the data is actually stored. Layers protokołowe, such as, for example, X. 500 does not need to be aware of the presence or existence of the recording options. This wariantowa treatment can give better performance in hard real time conditions, such as, for example, Mobile Telecommunication, 204, but this kind of productivity could require that option and its particular record was współlokowane within the same agent DSA, according to the embodiment of the invention.
[0115] the Data Request Receiver 1009 is configured to receive requests to receive data from a Sender Unit 1020 according to the embodiment of the invention. for example, suppose that the Data Request Receiver 1009 receives a data request associated with the Variant 1002. The receiver 1009 Data requests argues that the Variant 1002 contains the objectclass attribute "Variant. In accordance with what has been said, the Data Request Receiver 1009 determines the relevant rules for the objectclass attribute is "variant". The receiver 1009 Data requests can find these rules in the Variant 1002 and/or Rules file Options 1009.
[0116] the Data Request Receiver 1009 provides a location for the Variant 1002 along with the applicable rules for variant processing Unit the Location 1011 (Location Deriver). Unit Location 1011 receives the request for data within the data storage mechanism using the relevant rules for obtaining the location data according to the embodiment of the invention. For example, when obtaining space for the attribute "My Company Contact" Option 1002, Block Location 1011 would find a rule explaining that these data can be obtained from the attributes "Address", "Contact" and "Web Site" stored for the entry found at Root.Entry1.Entry2. also, when getting a place for "Company X" Contact," Block Location-1011 would find a rule that this data can be obtained from the attributes "Address", "Contact"
55P31384PL00
EP 2 156 649 B1 and "Web Site" stored for the entry found at Root.Entry1.Entry3.
[0117] as a Rule, use the Block Location-1011 to obtain the DN of the specific element in the DIT 1000 may include variable data extracted from the DN name primary wariantowego records, such as, for example, wariantowy entry 1002, according to the embodiment of the invention. For example, suppose the entry 504a has the name DN "c=UK", the entry 504c has the name DN "o=MyCompany, c=UK" and the entry 504d has the name DN "=CompanyX, c=UK". Wariantowy the entry 1002 has the name DN "varianto=MyCompany, c=UK". Rule of specific entry DN "o=valueof(varianto), c=UK". Because the value of "varianto" is "CompanyX", a specific element has the name DN "o=MyCompany, c=UK" - in other words, its value znajdywana under the entry 504c.
[0118] Block Location 1011 may then provide the received places in the Module Read/Update Data 1013, which could then perform the desired action on the data conducted through the data storage mechanism according to the embodiment of the invention. The module Read/Update Data 1013 are used any operating rules (e.g., comparison values) about the data (e.g., format) in the performance of their tasks. For attributes in wariantowym the objectclass attributes (e.g. the attribute "My Company Contact" Option 1002) are the actual attributes in the specific post (for example, the attributes "Address", "Contact", "Web Site" Record 2), which contain the values of attributes that are subject to mapping values or functions, according to the embodiment of the invention. For example, the Module Read/Update Data 1013 may apply the mapping rule values that modifies the total value of the attribute obtained from a real attribute to the actual value for the attribute in wariantowym record, for example, from "1" to "1,0". The module Read/Update Data 1013 may apply, for example, for the attribute that is loaded with real attribute the attribute to wariantowym record, for example, you can add the value 12 to the time to convert it to the format expected time
55P31384PL00
EP 2 156 649 B1
US ("1 day") at the expected European format ("1300"). The module Read/Update Data 1013 provides information about its activities, which can be presented back to the Sender Unit 1020 according to the embodiment of the invention. In addition, in accordance with what was said earlier, the reports can be ustrukturalizowane so that the actual nature trees DIT 1000 is transparent (e.g., hidden) from the Sender Unit 1020 according to the embodiment of the invention.
[0119] Block Location 1011 can conclude for this data request that some portion of the data for the variant is located in a remote directory. In accordance with the fact that the Block Location 1011 directs this part of the request data to Łańcuchowaną Module 1017 that interacts with a Remote Server 1031 Operations Directory to access the required data. The remote Server 1031 Operations Directory like, for example, the Server Operations Directory 1007, configured was to support operations for the recording options, according to the embodiment of the invention.
[0120] In an alternative embodiment, the Block Location 1011 can reach to spread out search operations in the directory on option on one or more search operations, the directory to child-specific records. These derived operations łańcuchowane through the Module Łańcuchowania 1017 or Remote Server 1031 Operations Directory or to the same Server 1007 Operations Directory for processing as part of regular operations on the directory. Łańcuchowane results are then used by the Module Read/Update Data 1013 to create the outgoing results. For example, entering a basic search in the basic variant entry 1002 (all user attributes), it would have been decomposed into two basic searches, one on entry 504c, and the second on the entry 504d. The attribute values contained in the results of these two search uses the Module Read/Update Data 1013 to obtain the values of the attributes returned in the output result. Unit Location 1011 can also do
55P31384PL00
EP 2 156 649 B1 to decompose the update operation of the directory on the embodiment, one or more update operations of the directory on child specific records, and then łańcuchować them, according to the embodiment of the invention.
[0121] In another example implementation, this procedure of subdivision can be serviced by a Block Location as part of the Adaptation of the Protocol described below. The Adaptation module 1107 Protocol, which is discussed further in FIG. 11A, can work with wariantową finish, according to the embodiment of the invention. Adaptation Protocol is not required for wariantowej processing according to the embodiment of the invention.
[0122] the Concept of the recording options can be extended to wariantowy the entry 1002 can contain a mixture of real values attributes, and the received attribute values, according to the embodiment of the invention. Maybe it is the result of a mixture of the real and the versions of the objectclass attribute for which the entry is an element or because the single object class can have a combination of real and perceived attributes. In addition, one attribute can have the actual values stored in wariantowym post 1002, and the values obtained from other specific records. For example, wariantowy element 1002 may have one additional actual attribute "Alternative Contact" and the attribute itself can hold the actual data for an alternative contact. In this case, the Block Location 1011 dostarczałaby just this particular location to the Module Read/Update Data 1013.
[0123] Further examples of the invention provide for the extension of the various rules associated with finishing wariantową. For example, as a rule, wariantowego attribute to retrieve the full names of the records that must be fetched attribute values, as a rule, to identify specific attributes within records, as well as the identification rules, the mapping of the attribute values based on specific records can all be stretched so that they included items such as:
• the use of real attribute values within the wariantowego entry 1002, and/or
55P31384PL00
EP 2 156 649 B1 • the use of contextual information such as time and day, as well as claiming that the user and/or • other rules contained the actual values of the attributes inside wariantowego record.
[0124] for Example, in terms of contextual information may also be implemented and so that corresponds to the "official" and "man after work" for a subscriber, so that at certain times of the day Block Location 1011 when accessing the variant you will find some attributes in one dataset and in other times of the day, the Block Location 1011 when you access this option, you can find data from another location. Other rules may, for example, include a permanent rule for one special for option.
[0125] Striping, such as the variant 1002, can simplify the update data in the DIT 1000. For example, due to the fact that the attribute "address", "My Company Contact" is the address attribute of data record 504c, this update enter the address for "My Company" Contact" and write data 504c is as simple as updating an address record for the data record 504c. The simplicity of this approach it is possible to notice, if we imagine that the DIT 1000 includes not only the one variant 1002 but a dozen options, each of which can be the Deputy of another Demand Unit, but everything points to a data record 504c.
[0126] In some examples of the invention variants allow design data hierarchy method is appropriate for modeling business structure, but without taking into account the specific needs of individual Queries Units such as the register HLR 307, the HSS server 301, and the like. In this approach, the striping can be added for each of the required units after the establishment of the data hierarchy. Striping grouped the attributes needed sought after block on the simple entry or into a simple hierarchy of entries. In this regard, the request unit does not require special knowledge hierarchy of data, where the attributes are actually located. Variant, such as, for example,
55P31384PL00
EP 2 156 649 B1
1002 provides the same mapping from the attribute that requires the requesting unit to the actual location of the attribute in the data hierarchy.
ADAPTATION - PROTOCOL ADAPTATION [0127] FIG. 11A represents the Adaptation Module 1107 Protocol, according to the embodiment of the invention. Module 1107 Protocol Adaptation can provide custom processing operations of the directory, such as LDAP or DAP.
[0128] the Requests for data in the catalog can come from different sources. For example, access to data can originate from a client application, user or even agent directory system, such as, for example, the agent DSA 702 shown in FIG. 7A. In accordance with what you said, Requiring Unit 1115 may represent a unit, such as a client application, end user agent or a remote DSA that may be need data to complete the procedure łańcuchowania initiated in the catalogue section under the control of the agent DSA, according to the embodiment of the invention. In any case, Requiring Unit 1115 sends the request data to the Server Operations Directory 1109. The server 1109 Operations Directory represents a unit configured to receive data requests and then deliver them to the appropriate processing unit associated with the directory server so that the requested operation can be completed, according to the embodiment of the invention. For example, an LDAP server can provide the server operations directory such as for example, the Server Operations Directory 1109.
[0129] the Adaptation Module 1107 Protocol the consideration of the incoming operation for the Server Operations Directory 1109, according to the embodiment of the invention. Module 1107 Protocol Adaptation, napływająca the transaction is matched with zero, one, or more ongoing operations. The Adaptation module 1107 Protocol then combines the results of each of the mapped operations into a single result so that they can be returned to initialize the Sender Unit 1115. The Selection Unit
55P31384PL00
EP 2 156 649 B1
Rules 1135 Module 1107 Protocol Adaptation makes the choice of a set of rules (set of rules) which allows the user to match the incoming operation and outgoing results, according to the embodiment of the invention. The Rule Selection unit 1135 receives a set of rules with zero, one or more fields of the incoming operations such as "operation type" and "entry name in operation," according to the embodiment of the invention. Block 1135 Selection Rules can find a set of implied rules from which to choose a set of rules in the Configuration Data 1121', as well as in the directory, following the example of the invention.
[0130] Block 1135 Selection Rules can use any field or combination of fields coming into operation to determine the correct set of rules, according to the embodiment of the invention. In addition, the initial user (for example, Requiring Unit 1115) can be used in the selection process rules, as there may be other contextual data, such as, for example, the time of day. The Rules Selection unit 135 may also use the current "working" data on the desired data as part of the selection process rules, such as when there is a process of adaptation after the start of processing. For example, the content dereferencyjnych aliases can be used in selection rules, if the Protocol adaptation takes place after the names. In accordance with what you said, Block 1135 Selection Rules can work in combination with the Recognition Module Names 909 shown in FIG. 9B, according to example of the invention. despite the fact that it is not shown in FIG. 11A, the Module 1107 Protocol Adaptation can be configured to work with other functionality, such as components associated with alias hiding, is shown in FIG. 9B, according to example of the invention.
[0131] All such data, which can be used in the selection process rules are defined as data selection rules. The choice of the set of rules associated generally with the selection of data selection rules for claims value in the alleged rules, or associated with individual values or in logical combinations, such as "and" and "OR". Approval
55P31384PL00
EP 2 156 649 B1 values can be simple równościami or bumps can also be associated with other criteria such as "best match" within a certain number of standard rules. For example, if some rule must be chosen according to entry name in the incoming operation, the rule selected Block 1135 Selection Rules can be one in which the maximum number of ordered names RDN matches the name on incoming transactions - in other words, the longest prefix match of the name. Approval values can also contain variables or substitution rules, and can be extended to enable adding new types of claims, when required, according to the embodiment of the invention. For example, if suitable to the name of the RDN, asercja can be designed in such a way that only the attribute type needs to match any attribute value you think is right.
[0132] the set of rules selected Rules Selection Unit 1135 determines the set of current operations performed (executed) under the control of the Module 1107 Protocol Adaptation, according to the embodiment of the invention. The set of rules may also specify results or errors to immediately access the Sender Unit 1115 and/or a set of updates, such as "add" operation. Current operations can be processed either sequentially or in parallel. In the case of processing, as well as the results of one operation can be used by the Adaptation Module 1107 Protocol as input for the next operation, as, for example, in the example shown in FIG. 11B below. Field of the operations can be employed, the Adaptation Module 1107 Protocol with a combination of variables the data extracted from any field in the incoming operation, additionally placed in juxtaposition and/or any other data selection rules and/or persistent data that you provide through the selected rules, according to the embodiment of the invention. the Module Adaptation of the Protocol might take the field, outgoing results of the combination of variable data extracted from any field in the results, additionally placed in the map, and set data provided by the selected rule.
[0133] FIG. 11B illustrates an example of serial or sequential processing of Protocol adaptation, according to the embodiment of the invention. BSS 402
55P31384PL00
EP 2 156 649 B1 sends a request for the maiden name of the wife of the subscriber. Here, the BSS 402 operates as a Unit, Requiring 1115 shown in FIG. 11A. Block 1135 Selection Rules combined with the Adaptation Module 1107 Protocol considers the resulting transaction ("Download" the Maiden Name of his Wife"), received by the Server Operations Directory 1109 and identifies a rule that specifies two ongoing operations. The first of the ongoing operation "to Download the wife's Name" gets the name of the wife of the subscriber, for example, "Becky Jones". The results of the first supply current operation data for the other continuing operation "Search" Maiden Name", which gets a maiden name for "Becky Jones". The Adaptation module 1107 Protocol the Server supports Operations on Directories 1109 return the answer "Becky Romanov" system BSS 402. Using this approach, the BSS 402 does not know, or do not need to know all the steps that have been taken by the Adaptation Module 1107 Protocol in response to this request.
[0134] the Adaptation Module 1107 Protocol can be configured to work in various stages inside the processing area taken in the direction of the Server Operations Directory 1109. In this regard, the Protocol adaptation can take place after the process of recognition of names, such as the proposed Recognition Module Names 909 shown in FIG. 9B, but before processing the search/update, as we offer a Search engine/Updates 91 shown in FIG. 9B.
[0135] Because the Requesting Unit 1115 may be remote from the agent DSA, the Adaptation Module 1107 Protocol can achieve a processing chain of operations, giving a fully distributed Protocol adaptation, according to the embodiment of the invention. The implementation of the adaptation Protocol on łańcuchowanych operations means of numerous levels of such adaptation - in other words, an extra time of adaptation for each stage łańcuchowania.
[0136] the Adaptation Module 1107 Protocol can be configured to work with variants such as the Variant 1002, shown in FIG. 10.
In this regard, for example, wariantowy entry may occur in the operations of the fittest view of the Protocol, in accordance with what
55P31384PL00
EP 2 156 649 B1 indicates the presence of the Adaptation Module 1107 Protocol in FIG. 10B, according to the embodiment of the invention.
[0137] in Accordance with that shown in FIG. 11A, the Adaptation Module
1107 Protocol works as doklejony module for the Server Operations Directory 1109, according to the embodiment of the invention. In this embodiment, the Adaptation Module 1107 Protocol is on the server and simply access/close relative to the physical Servers, Operations Directory 1109. In some examples of the implementation of the Adaptation Module 1107 Protocol may even reside on the same machine (e.g., computer, server) which is a host for the Server Operations Directory 1109. This example of execution with the "doklejonym module" can offer the best performance, especially in some difficult conditions in real time, compared to an example implementation in which an Adaptation Module 1107 Protocol is running as a virtual server operations directory such as the example shown in FIG. 11C.
[0138] In an alternative embodiment of the invention shown in FIG. 11C, the Adaptation Module 1107 Protocol basically works as a virtual server for the directory (or proksy server LDAP/DAP), engaged in communication (e.g., LDAP or DAP operations) to the Server 1109 Operations Directory such as, for example, the server DS 706a shown in FIG. 7A. in this embodiment, the Adaptation Module 1107 Protocol delivers the modified queries to the Server 1109 Operations Directory for processing in the directory represented in the DIT 1160. In this regard, the Adaptation Module 1107 Protocol considers all the incoming transactions to the Server Operations Directory 1109, according to the embodiment of the invention. The unit Selection Rules 1135 displays upcoming operation to zero, one or more of the operations. The Adaptation module 1107 Protocol then combines the results of each of the mapped operations for a single result and sends it back to initialize Sender Unit 1115. As a rule, for mapping of the incoming operation and outgoing result of the selected one or more fields of the incoming operations such as "operation type" and
55P31384PL00
EP 2 156 649 B1 "entry name in operation," according to the embodiment of the invention. The matching rules for the incoming operation and outgoing result can also be saved to a file the Configuration Data 1121. In this example, the performance data for the choice of rules is limited to the external representation of the contents of the tree DIT 1160, for example, LDAP message and Protocol adaptation to and/or after processing of the Server Operations Directory 1109.
ADAPTATION - ADAPTATION OF THE NAME [0139] FIG. 11D represents a DIT 1100 having an adaptive configuration.from the naming of adaptation Protocol, in accordance with the embodiment of the invention. The DIT 1100 includes one or more records, such as records 504a - 504f, and so on, virtual records 504g 504i and the root node 602. The DIT 1100 also includes an entry that is marked as an Adaptive Name Entry 1102 that is a real item, such as records 504a - 504f, which is mapped by virtual records labeled Adaptive Name Entry 1102b.
[0140] the Adaptive terminology gives a different mechanism for different names for entries in the DIT 1100. However, unlike aliases and variants, adaptive names are not records in the catalog. Adaptive terminology, is implemented by configuration data , e.g. Configuration Data 1121. The unit Selection Rules in the Module 1135 Adaptation Protocol 1107 uses the data selection rules and a Dedicated control channel 1121 to identify a set of adaptive name 1104 between alternative names and their "real" równoważnikami names, according to the embodiment of the invention. In the case of search queries, the search range of the filter can be adapted to search for a much more narrow field, if the filter criteria can be adapted to the base part of the name of the search; for example, in order to use aliases, which may exist but which Require Unit 1115 is not aware. Search
55P31384PL00
EP 2 156 649 B1 complex filter that contains a number of sentences "or" can be set to a certain number of queries, one for each of the options or, according to the embodiment of the invention.
[0141] during data retrieval and other operations, the use of adaptive naming may be transparent to the sender unit (e.g., client applications), which used the name, according to the embodiment of the invention. In this regard, the requesting unit (for example, Requiring Unit 1115) uses what it considers the real name and receives back the necessary information. For example, assume that the DN of the entry 1102a "employeeId=112, o=MyCompany, c=UK" and in addition, suppose that an adaptive name entry exists between 1102a and 1102b. Finally, suppose the requesting unit back to the data in entry 1102b using what it believes the correct name, e.g., "employeeId=1 12, area=employeeAdmin, o=AnotherCompany, c=DE", it is because the adaptive relationship between 1102a and 1102b are obtained the same data. In this regard, the name for 1102b is an alternative name for data 1102a.
ADAPTATION - ATTRIBUTE ADAPTATION [0142] FIG. 11E shows the DIT 1150 aimed at the adaptation of the given attribute for the Protocol adaptation, according to the embodiment of the invention. The DIT 1150 includes one or more records, such as records
504a - 504f, and so forth, and the root node 602. The DIT 1150 also includes entry 1105a, having real attributes 1108a - 1108e, which is mapping the virtual record adapted attributes 1105b having virtual attributes 1108f - 1108j.
[0143] the Actual record 1105a contains one or more attributes, such as attributes 1108a - 1108e, and recording the adapted attributes 1102b contains one or more attributes, such as attributes 1108f - 1108j and so on. In the example of the invention
55P31384PL00
EP 2 156 649 B1 is one or more attributes to 1108e 1108a 1105a records contain data such as subscriber data, such as "name", "last name" "address" "County" and "postcode". In addition, one or more attributes 1108f to 1108j record adapted 1105b attributes contain information such as, for example, any of the following "name (first name)", "surname" (last name), "address", "state" "postal code" and the like.
[0144] the adaptation of the attributes provides alternative names and/or values of attributes, such as attributes 1108a - 1108e. In the example implementation of the invention, the Block Selection Rules 1135 Module 1107 Protocol Adaptation is the identification of the adaptation mapping 1106 between various attributes of the attributes using the Configuration Data 1121.
For example, a Dedicated control channel 1121 instructs the Adaptation Module 1107 Protocol to perform a variety of mappings from the attribute name 1108a to the alternative name of the attribute 1108f. In various examples of the invention, when the requesting unit (for example, a client application) executes an operation that relates to an attribute having an attribute mapping, the attribute mapping is carried out the names of attributes, such as attributes 1108a - 1108e, and the value refers to the correct attribute names and values understood through the DIT 1150. For example, assume that the attribute 1108a has the format "actual" and assume that its value is equal to "1,0". Suppose in addition that adapted attribute 1108f has the format "General" and assume that 1108f has been adapted for the attribute 1108a. if the application branch 1108f performs a read request for 1108f, the application expects that it will return the integer "1" and not real "to 1.0". Because of the addictive attribute performed by the adaptation module 1107 attribute that requires a unit length zaadaptowanego attribute 1108f receives data in the expected format full.
[0145] In the example embodiment of the invention, when the adaptation attribute is used in combination with adaptive terminology, such combination allows not only the use of alternative names for the inputs, but also translate the names and/or values of attributes of the entry. In addition, some
55P31384PL00
EP 2 156 649 B1 the examples of the invention adaptive terminology and adaptation of the attributes can be combined to ensure the independence of applications from the underlying database structure. Adaptive terminology and adaptation of the attributes allow us to design and naming pieces of shells in the data warehouse taking into account the immediate needs of the spinal business on other issues, for example, for applications that are hereditary, according to the embodiment of the invention. Then can be added adaptive name and attribute mappings to obtain the kom pletnych alternative hierarchy naming specific applications, such as the register HLR 307, the HSS server 301, and so on. these alternative hierarchies may use a different DN as well as alternative attribute names links to the meningitis database record. The Data store 404 the DIB 500 performs transformation of the application requests using the defined mappings to the record database 500 DIB and attribute names. The mappings may be determined based on the application (either on the basis of subscriber base of the DIB 500), according to the embodiment of the invention. When more than one application that requires a different hierarchy of naming, each of these applications can connect with another person's name with appropriate mappings, in the example of the invention.
SIMPLIFIED ACCESS CONTROL FOR TREES CHILD [0146] FIG. 12 illustrates the Access Control (AC), implemented using some form of Protocol adaptation, according to the embodiment of the invention.
[0147] the ALTERNATING current System are, as a rule, part of the communication protocols used in the network (e.g., network communication, an LDAP-compliant) and may be implemented as a device Access Control (ACU) 1201. The units ACU, as a rule, contain different modules, for example, a module that permits the subscriber, the authentication module, and the module priority. Unit ACU is
55P31384PL00
EP 2 156 649 B1 then combine different files to create a cohesive and useful set of permissions. Unit ACU can group with plenty of resolution to create a set of permissions for different groups/users. For example, the Protocol X. 500 standard unit ACU provides flexible access control, which provide very precise control of access, up to the level of a separate entrance or can be applied to trees for the child directory, for example, the directory 600 shown in FIG. 6. Such a conventional circuit, while flexible, can lead to significant excess administrator when saving the data controlling unit ACU (Information Access Control (ACI) 1217), and a significant excess of the processing unit through the ACU when using access control during the process. This is especially inconvenient for a directory containing several million records, which can be individually implemented to control access, and where these records should be available in real-time. Office abundance also has implications for security, in the sense that, the more complicated the control scheme, the greater the probability that it contains errors, and hence the possible errors of security.
[0148] In various examples of the invention the server directory, such as, for example, the server DS 706a, for decision-making in the field of access control for the request data may request information such as username, authentication level operation and additional ACI 1217 associated with the target element and its attributes.
[0149] In the example embodiment of the invention, an administrative area per DSA agent, e.g., agent DSA 702 shown in FIG. 7A, gives you the access control level of the schema, so that information ACI 1217 is configured based on the objectclass and attribute type, not on individual directory entries, and applies to all records managed by that agent DSA. This kind of control schema level is easier to control and inspection under
55P31384PL00
EP 2 156 649 B1 correct, and can be optimized for access in real-time. In the example of the invention, the administrative area uses an approach based on wielodzierżawie (multitenancy) for access control. In this regard, each "tenant" (e.g. a client application) is allocated one or more child trees within the administrative area of and has access only to entries within those trees subordinates, even if these records use the common object classes and attribute types with records in other trees child and, therefore, exploit information the ACI 1217.
[0150] Unit ACU 1201 is configured to make decisions on access control in the Server name Operations Directory 1213 when processing transactions, catalogs received from hungry units, such as, for example, a client application, end users and DSA were able to complete the operation łańcuchowania, according to the embodiment of the invention. For example, a User A 1203 may request an operation on the recording 54c, and the User B 1205 may request modification of a record 504e. Server 1213 Operations Directory like, for example, the Server Operations Directory 1109 shown in FIG. 11A and FIG. 11C, is a block that is configured to receive data requests and then deliver them to the relevant units for processing associated with the directory server so that the requested operation can be completed, according to the embodiment of the invention. For example, an LDAP server reprezentowałby the server operations directory such as for example Server Operation the Directories 1213. Server 1213 Operations Directory uses the ACU unit 1201 for making a decision that all, part or none of the requested operations are allowed to implement, as well as all, part or none of the results are not allowed to appeal to the initiator, according to the embodiment of the invention.
[0151] the Adaptation Module a Security Protocol 1215 reviewing incoming operation for the Server Operations Directory 1213, according to the embodiment of the invention. The Adaptation module a Security Protocol 1215 works similarly for Module Adaptation Protocol
55P31384PL00
EP 2 156 649 B1
1107 shown in FIG. 11A and FIG. 11C. Also in the Module Protocol Adaptation Module 1107 Adaptation Protocols Security 1215 may change, directed operations in the catalog for one or more selected rules (a rule set). The Adaptation module a Security Protocol is configured before the communication between the Server Operations Directory 1213 and unit ACU 1201. It should be noted that the application of the Adaptation Module a Security Protocol 1215 does not prohibit the use of the Module 1107 Protocol Adaptation in the same or other stages of the processing operation. Similarly, the Adaptation Module 1107 Protocol can be configured to offer nadzbioru functionality provided by the Adaptation Module a Security Protocol 1215.
[0152] the Adaptation Module a Security Protocol 1215 can be configured to match the base name of a loading operation for a set of prefixes of names, according to the embodiment of the invention. A set of prefixes to configure a can be configured for sender unit (for example, a client application as the User 1203), which initiated the necessary operations. The set of namespace prefixes delivers the selection criteria of the rules, and can also be in the Configuration Data 1210 and/or remain in the section of directory, such as DIT 600.
[0153] According to the example embodiment of the invention with a suitable name prefix defines the rules of application. For example, if the client application requests an operation on the recording "A,B,C,D,E", where A-E are names of RDN in LDAP order, and there are usually configured with prefiksami names "E", "C,D,E, B,C,D,E and Z,B,C,D,E", then the selected rule one with the name prefix "B,C,D, E", because it represents the longest prefix in the set of rules that is suitable for zone "A,B,C,D,E". According to the example embodiment of the invention the selected set of rules may contain child activities, such as, for example: "reply with error", "registration attempt the or operation to continue the operation, as is customary, but create another user and/or the level of authentication (user effective) for the purpose of access control". In the latter case, when the unit ACU 1201 is then applied to decision-making, access control, used
55P31384PL00
EP 2 156 649 B1 the user effective, causing the adoption of other decisions of access control depending on the combination of the initiating user, the corresponding name prefix. In short, the result is a scheme of access control at the schema level, which somehow gives you control of access to the tree of child, according to the embodiment of the invention. In principle, this approach can be applied, up to the level of a separate entrance.
[0154] for Example, in accordance with that shown in FIG. 12, And You the User 1203 and 1205 B are external users. Suppose also that the unit ACU 1201 administrative region configured that neither user a 1203 and User B does not have permission to read or write for each entry in the DIT 1200. Suppose in addition that was established two special users, User R and User 1207 To 1209. The user R 1207 has read permissions on any subscriber entries in the DIT 1200, and In 1209 the User has permissions to read and write on all records of the subscriber in the DIT 1200. Suppose also that external client applications, such as, for example, a User A 1203, you do not have permission to link or as a User R 1207 or 1209 In You.
[0155] in Accordance with what has been said by the Adaptation Module a Security Protocol 1215 locates a rule in the configuration data 1210 so that if the User performs the operation on the entry in the tree the child with the name prefix "P1" (that is, each of the records 504a, 504c, 504d) the user effective is adopted as a User In 1209. For all other operations effective user remains You And 1203. The Adaptation module a Security Protocol 1215 also includes a second rule so that if a User B 1205 performs an operation on the record in the tree the child with the name prefix "P1", the effective user is adopted as the User R 1207, and the third rule is that if a User B 1205 performs an operation to write inside children tree with prefix "P2" (i.e. any of the records 504b, 504e) the user effective is adopted as a User In 1209. For all other operations effective user remains as User B 1205.
55P31384PL00
EP 2 156 649 B1 [0156] the Result of these three rules is that User A 1203 has access to read/write to records within the child tree P1, and the User B 1205 has read access to the entry in the tree a child of P1, and also has access to read/write to the entry in the tree a child of P2.
[0157] as in the case Adaptation Module 1107 Protocol, the Adaptation Module a Security Protocol 1215 can be configured to run after the name but before the rest of the processing operations according to the embodiment of the invention. This means that as a result, the access control trees a child may be based on a fully dereferencyjnych pseudonazwach, without setting any access control on the names, aliases. In this regard, when customers have numerous personalities and are accessible via aliases representing these individuals, only the real entries representing the subscribers need be grouped into the trees a child for the purposes of access control, according to the embodiment of the invention. In accordance with what has been said, the Adaptation Module a Security Protocol 1215, as, for example, the Adaptation Module 1107 Protocol, can communicate with the Recognition Module Names 909 shown in FIG. 9B, according to example of the invention. also, despite the fact that it is not shown in FIG. 12, the Adaptation Module a Security Protocol 1215 may interact with other components to hide the alias is shown in FIG. 9B, according to example of the invention. also, despite the fact that it is not shown in FIG. 12, the Adaptation Module a Security Protocol 1215 can interact with the finish wariantową, such as, for example, processing wariantowa shown in FIG. 10B, according to the embodiment of the invention. In this regard, for example, processing components wariantowej affiliated with the Server 1007 Operations Directory shown in FIG. 10B, can be affiliated with the Server Operations Directory 1213 shown in FIG. 12, according to the embodiment of the invention.
[0158] the results of the operation of catalogs usually do not include information about the user who made the operation, and therefore require the application
55P31384PL00
EP 2 156 649 B1 is not aware that the necessary action has already been actually accomplished the replacement of a user security reasons, according to the embodiment of the invention.
The Nomadic Subscriber Data system [0159] FIG. 13A is a Nomadic Subscriber Data System for improved data transmission between a subscriber data store in a communication network, such as, for example, Mobile Telecommunication, 204, according to the embodiment of the invention.
[0160] Often appears a problem while trying to implement a large scale system directory server more than geographical borders/network where performance/network latency is not expected, cannot be guaranteed and/or overall limited. This situation often occurs in systems that use satellite communication line (for example, the Islands of Indonesia), or long distance calls (for example, from North America to Europe/UK). In such systems, the duplication of the data in real-time at large distances is often impractical, and łańcuchowanie in real-time of X. 500 requests to support a "single logical directory" for all locations is also often impractical because of the relatively long waiting time for the transmission of IP packets. For example, the transmission IP packet one-way from new York, NY, Seattle, WA, may exceed 50 MS in any network operator in the United States. Also, she only transmission delay, not including the processing time of directories in many cases exceeds the maximum time client applications through which the directory could count on the response to the update or query.
[0161] the Solution to this communication problem should minimize the bandwidth required between the pickup having problems with bandwidth/latencją, and thus offer one directory, logical, in which each server may handle all data residing on distributed
55P31384PL00
EP 2 156 649 B1 according to the embodiment of the invention. This kind of decision, for example, the server can support HSS, which combines the North America and the UK, or a single logical register HLR, which connects the Islands of Indonesia. [0162] In the example implementation of the System to the Nomadic Data of the Subscriber profile data the subscriber's dynamically allocated by the agent DSA 1302 based on the location of reference/access in the same way as conventional wireless networks support moving parts of a subscriber's wireless profile (e.g., profile abonencki is determined via GSM or ANSI-41) from the HLR 307 registry (database mobility in home network) to register the VLR 303 (database, mobility współlokowana with a switching device in the network where the subscriber's device is currently included) on the basis of the connection point/network access of the subscriber. After the initial connection to the network, the register VLR contains all the necessary information of the subscriber and the device to ensure completion of the local switching system; if the data has not been invested locally, the connection may become too long if the remote registry HLR need to apply every time the connection must be processed. The concept of HLR-VLR and branches profiles are very specific to wireless technology and specification (GSM/ANSI-41) and cannot be the generation that is used for each profile of a subscriber of any telecommunication network. Nomadic Subscriber Data to enrich this concept is much more General level that agnostyczny for the type of network in which they are located, and also allows the generic profile abonencki, which is able to handle the demand for data, each working in real time applications, telecommunication backbone network connection, according to the embodiment of the invention. The Nomadic Subscriber Data system is based on highly distributed and scalable X. 500 Directory, according to the embodiment of the invention. The X. 500 directory allows geographic dispersion of the profile data of the subscriber and at the same time showing the client network as a single logical database where all data can be retrieved from any server of the X. 500 Directory. In the case where the system looks for various
55P31384PL00
EP 2 156 649 B1
DSA in the regions, which bring large latency transmission, in accordance with what is described above, embodiments of the Nomadic Subscriber Data system detects when the client's access to the data exceeds a configurable minimum threshold of quality of service and dynamically transfers the profile data of the subscriber of the remote agent DSA to the local DSA agent where they are currently available. In this regard, the System of the Nomadic Subscriber Data, the data is placed on the agent DSA in the vicinity of the place where they are used, avoiding the need of duplication or łańcuchowania delay the work for each request, at the same time giving a unified directory for prowizjonowania. Other embodiments of the Nomadic Subscriber Data system to allow independent relokowanie specific services or applications, or portions of sets of profile data of the subscriber on the same principles described above. In this regard, for a specific subscriber and service system expansion of the Nomadic Subscriber Data allows relocation for a specific application/data services and allows for placement of various data and allows for placement of various data of the subscriber in various agents DSA simultaneously, which allows their use where necessary, according to the embodiment of the invention.
[0163] In the case of this approach on data originally prowizjonowane special agent DSA, such as DSA 1302a agent; however, after the initial access, for example, queries or updates with a DSA agent, such as, for example, the agent DSA 1302c, subscriber data is transmitted immediately to the remote agent DSA supported query/update. The remote agent DSA is, presumably, a local agent DSA to the subscriber or application running on customer's behalf. After a data transfer, all local queries associated with these subscriber data, locally interrupted at the DSA agent, according to the embodiment of the invention. In fact, an example of execution of the Nomadic Subscriber Data System provides a generic profile abonencki determined, as a rule, the CSP, and the data are nomadic on the basis of the access point to the database (for example, by use of such
55P31384PL00
EP 2 156 649 B1 Protocol as LDAP or DAP). In this regard, for example, data is moved, if the quality of service is not fulfilled due to the excessive latency of the data transmission, and other properties and transmission rates are or are not, according to the embodiment of the invention.
[0164] Assume, for example, that subscriber data for HSS 1305 server was originally prowizjonowane on agent DSA 1302a. Suppose also that some of these data subscriber associated with the subscriber 1309a configured to fit for transmission. When the subscriber 1309a (and/or the device or server representing the subscriber) interacts with the HSS 1305 server so that your query and/or update data, agent DSA 1302a performs data transmission subscriber agent DSA 1302s, which is closer physically (and hence provides faster access because less than the latency of the transmission) for a subscriber 1309a than agent DSA 1302a. After this transfer, agent DSA 1302c will be delayed and will be responsible for the data subscriber 1309a about the server HSS 1305.
[0165] in addition, it is assumed that the subscriber data register HLR 1307 was initially prowizjonowane on agent DSA 1302d (on the island 1303. Suppose also that some of these data subscriber associated with the subscriber 1309b configured as suitable for transfer. When the subscriber 1309b (or the device or server representing the subscriber) interacts with the HLR 1307 register so that the required query and/or update the data, the agent DSA 1302d transmitting data of the subscriber agent the DSA 1302e, which is located on the island 1304 and closer physically the plan of the subscriber 1309b than agent DSA 1302e, giving, thus, faster data access. After this transfer, agent DSA 1302e will linger and will be responsible for the data subscriber 1309b on the register HLR 1307.
[0166] FIG. 13B illustrates representative components containing
The system of the nomadic subscriber data, such as shown in FIG. 13A, according to example of the invention.
[0167] Ekspedytor Events NSD 1312a is at the point of access to the data store agent in DSA 1302a and scans the requests for access to
55P31384PL00
EP 2 156 649 B1 subscriber profile (e.g., monitoring LDAP access) in repository data 1318a and then measures the response time in function of the configuration data 1320, such as a preconfigured channel quality profile of services according to the embodiment of the invention. If Ekspedytor Events NSD 1312a detects that the subscriber's access (e.g., LDAP operations) exceeded thresholds for acceptable performance for client applications, in accordance with what is defined in the configuration data 1320, the Ekspedytor Events NSD sends these events, with relevant details for a specific subscriber profile data, the NDS Transfer Manager 1314. Ekspedytor Events NSD 1312a is usually on the DSA agent is configured to provide memory access subscriber profile, such as agent DSA 1302 shown in FIG. 13A. In this regard, the System of the Nomadic Subscriber Data may contain numerous cases Ekspedytora Events NSD 1312, according to the embodiment of the invention.
[0168] the NSD Transfer Manager 1314 provides a centralized collection point for events forwarded from distributed Ekspedytorów Events NSD 1312, according to the embodiment of the invention. Manager 1314 Transfer NSD list of events received from Ekspedytorów Events NSD 1312 and argues, on the basis of the configuration data 1320, such as pre-configured profiles for quality of service and performance when/if you need to migrate the profile data of the subscriber one agent to another DSA, for example, with the agent DSA 1302a in DSA agent 1302b shown in FIG. 13B. Manager 1314 Transfer NSD can be in one or more specialized agents DSA or may exist separate and/or external management platform/prowizjonowania, according to the embodiment of the invention.
[0169] the NSD Transfer Controller 1316 controls the movement of subscriber profiles from a source agent of the DSA (e.g., DSA agent 1318a) to assign the agent of the DSA (e.g., DSA agent 1312b) according to the instructions of the Manager 1314 Transfer NSD. The controller 1316 Transfer NSD ensures that the correct data of subscribers or a subset of the subscriber is transferred intact without error for agent, DSA, for example
55P31384PL00
EP 2 156 649 B1 of the invention. The controller 1316 Transfer NSD can simultaneously ensure that all the relevant links to directories (the Hierarchical relationship of the Objects (Hierarchical Object Bindings - HOBBS)) the right to change and/or support according to the embodiment of the invention. if errors, such as, for example, a network failure, a server failure, DSA or other problem prevents successful transmission of the subscriber profile, the Controller 1316 Transfer NSD ensures that the original data location of the subscriber is preserved exactly as it was before attempting the transfer. The controller 1316 Transfer NSD uses the possibility to perform such movements (e.g., transaction support Directory and LDAP), according to the embodiment of the invention. In this regard, the entire profile abonencki or a subset of the subscriber profile can be directly imported from one agent to another DSA. Also in the NDS Transfer Manager 1314, the Controller 1316 Transfer NSD can reside on one or more specialized agents DSA or may exist separate and/or external management platform/prowizjonowania, according to the embodiment of the invention.
[0170] the NDS Approach is not generally intended for boundaries between agents DSA 1302, where the access point for the data changes in real time as, for example, the situation that might arise for a subscriber moving along a wide network supported by two neighboring access point (apn). In such situations, it is probably more beneficial it would be more regular system of data servers (meaning not nomadic), because each of the neighboring agents DSA is able to process queries and updates that access data with the corresponding quality of service QoS. In this case, the system NDS can be configured to prevent data from becoming mobile with the help of several solutions. Manager 1314 Transfer NSD can be configured to prevent the transmission of subscriber profiles between two geographically neighboring agents DSA or DSA between agents, where the time delay is very small (it means has no real benefits from moving data). In addition, the Manager 1314 Transfer NSD
55P31384PL00
EP 2 156 649 B1 can be configured to detect when there szamotanie (destruction) between two points agents DSA. Szamotanie means that there is generally common traffic profiles, subscriber back and forth between these agents DSA. In this situation, the Manager 1314 Transfer NSD can limit or reduce the traffic by more stringent criteria for transfer, as, for example, raising the priority you want the client application in order to cause the transmission, increasing the number of client requests causing transmission or only to allow transfer between all agents DSA. [0171] FIG. 13C illustrates representative configuration data 1310 for a DSA participating in the agent System of the Nomadic Subscriber Data according to the embodiment of the invention. The configuration data 1310 may reside in the configuration data file 1320, shown in FIG. 13B. The configuration data 1310 for the Nomadic Subscriber Data windows can include data such as:
• the data indicate that the DSA have/do not have permission to partycypowanie in exchanges of data on request 1312a. In accordance with what is shown in the data 1310, the DSA 1302a agent has permission to partycypowanie in exchanges on demand. In particular, the agent
DSA 1302a has permission to partycypowanie in the exchanges with agent DSA 1302c.
• restrictions 1312b on partitions or subsets of the tree DIT, for example, wood DIT 600 that may be exchanged between specific agents DSA. Restrictions 1312b presented for the data 1310 indicate that only data for subscribers in California, Washington, Oregon, Nevada and Arizona may be exchanged for this special agent DSA, and • other restrictions 1312c on factors such as ranges of data values, maximum size of data, time of day and others that can be evaluated before data is exchanged between agents DSA. Other examples of restrictions 1312c presented data indicate that no transmission of data safe, such as passwords, and no data transfer can not
55P31384PL00
EP 2 156 649 B1 exceed 50 Megabytes. These restrictions are just examples of some of the restrictions that can be imposed on data according to the embodiment of the invention.
[0172] Other restrictions 1312c, which can be applied include the size of transmitted data, which can be customizable and its value can be calculated based on the latency associated with transferowaniem and transmitowaniem the size of the data as valid for client applications, for example, 50 KB, 500 KB, 1 MB, 10 MB, according to the embodiment of the invention. Other some console can be private and/or secure data/attributes that can be transferred for security reasons. For example, the user's password may not have permissions to send through a connection, who are unable and/or encrypted. Some console can be levels of network load. For example, employment levels may be checked to determine that no data needs to be transferred in a certain time of day when there are peaks in network load. You can also consider a work status agent DSA. For example, data transmission may not be allowed in the case of States involving the DSA are in a state of overload, or does the DSA in the condition of limited capacity (e.g., one node agent DSA withdrawn from use). In the end, the other parts of the profile data of the subscriber can be defined as nomadic or stationary by nature, so these data should not be relokowane in the access point. This may include static information used by the BSS, as, for example, the address of the subscriber.
[0173] FIG. 13D is gives the algorithm a high-level System of the Nomadic Subscriber Data according to the embodiment of the invention.
[0174] component of NSD is pre-configured to exchange request data of the subscriber (step 1320). Partycypujące DSA D1 and D2, such as, for example, DSA 1302a and 1302c is shown in FIG. 13A, pre-configured to exchange subscriber data with each other on request. In addition, it should be drafted Ekspedytor(y)
55P31384PL00
EP 2 156 649 B1
NSD events, such as, for example, Ekspedytor Events NSD 1312a, the Manager 1314 Transfer NSD and the Controller Transfer NSD, together with the Configuration Data 1320, according to the embodiment of the invention. The initial configuration may include data such as, for example, the configuration data 1310 shown in FIG. 13B.
[0175] the Data for subscriber S1, masterowane on agent DSA D1 (for example, the agent DSA 1302a) and configured to transferowalne agent DSA D2 (e.g., agent DSA 1302c) (step 1322). Here S1 represents that subset of the tree CHILD of subscriber or subscriber service/application that can be used with the DSA agent D1 agent D2 DSA (e.g., DSA 1302a agents in the agent DSA 1302c). [0175] in Accordance with what is discussed in FIG. 13B, as a rule, and the right to transfer controlled Ekspedytor Events Manager and NSD Transfer NSD, according to the embodiment of the invention. Conditions, if they arise for this transmission, can be set in configuration data such as configuration data 1310 shown in FIG. 13C. For example, the data of the subscriber S1 may be limited to a specific set of subscriber profile, such as a special recording services/applications (or recording) or even a specific subset of record attributes of the subscriber profile. S1 may also contain restrictions on what the profile abonencki possible to transfer as a whole or various subsets of the profile (for example, for a particular application) can be transferred separately and simultaneously. Here, for example, S1 might be just enough to make the whole profile abonencki was nomadic, including trees, utility/subsets, as well as all data, applications/services. Another example can decline to have the entire profile abonencki were nomadic, and only customized for specific applications/services, trees, child/subset can be independently nomadic. In accordance with what was said in FIG. 13B, each DSA agent partycypujący in the Nomadic Subscriber Data System has Ekspedytor Events NSD is configured with a specific quality of service (QoS), and profile criteria data transfer to access data of a subscriber according to the embodiment of the invention. this profile defines, for example, the threshold value for the delay
55P31384PL00
EP 2 156 649 B1 request (e.g. delayed LDAP query), which take into account can be transfer of the subscriber profile.
[0177] the Agent DSA D1 receives a request (e.g., search or update an LDAP) for subscriber data set within the boundaries of S1, which is currently stored in the agent DSA D2 (step 1324). As a rule, the study of service quality criteria QoS and the transmission and following the relocation of subscriber data is specific to a single request for a single subscriber profile. However, it is possible, could be to configure the agent DSA D1 for transferring the relevant data of the subscriber, in accordance with S1, for a given set of subscribers upon the request for data for a single subscriber within the set, according to the embodiment of the invention.
[0178] a Request for data typically processed so as to be handled and any other request by the agent DSA-D1 and DSA agent D2. For example, using the rules of the X. 500 Protocol, the request may be łańcuchowane from agents DSA DSA D1 via the Home agent DSA D2 where the demand is matched and the response is returned along the same path of the request.
[0179] According to the embodiment of the invention Ekspedytor Events NSD agent DSA D1 considers these queries of branches and properties of answers and performance of the branches and the properties of response and efficiency, and argues that the threshold for transferring data set S1 has been exceeded (step 1326). An example threshold value may be, for example, such that the allowable delay of the LDAP query has been exceeded. If the threshold is not exceeded (step 1326), then Ekspedytor Events NSD returns to normal processing.
[0180] If the threshold is not exceeded (step 1326), then Ekspedytor Events NSD agent DSA D1, initiate a load event to the NSD Transfer Manager (step 1328).
[0181] the NSD Transfer Manager receives the event message, together with others occurring simultaneously in the system claims that the transfer is guaranteed and, if so, then instructs the NSD Transfer Controller to
55P31384PL00
EP 2 156 649 B1 initiated the transfer of the subscriber profile from the agents DSA agent DSA D1 D2 (step 1330). In determining whether the transfer is guaranteed, the NSD Transfer Manager can check items such as the condition and overloading of system components and networks that are affected, according to the embodiment of the invention. If the transfer is not guaranteed (step 1330), then the Migration Manager NSD returns to normal processing.
[0182] If the transfer is guaranteed (step 1330), then the Migration Manager NSD requires that the NSD Transfer Controller to read the subscriber data set, determined and/or constrained by S1, to migrate agents from DSA D1, initiate a database transaction to delete the subscriber data set S1 from DSA D1 of agents, and then initiate a transaction to add the subscriber data set S1 to agent DSA D2 (step 1332). After successful completion of the adding operation of the subscriber data set S1 to agent DSA D2, the NSD Transfer Manager requires operation of the reset agent DSA D1 when finalizing the transfer (step 1332).
[0183] As part of the transfer process, the NSD Transfer Manager would ask to any agent DSA, compressing data relating to the whole subscription profile for subscriber S1 data collection were updated accordingly, according to the embodiment of the invention. As mentioned earlier, the profile abonencki and/or the profile reference can strain many DSA. Typically, the profile abonencki can exist on a single agent DSA, but it may have a failure from lead agent of the DSA and one or more agents DSA the name of the person, according to the embodiment of the invention. Profile abonencki must be physically moved (along with important pseudonazwami that współlokowane profile) and, accordingly, needs to be updated all references to the profile/aliases to point to the new target DSA agent, according to the embodiment of the invention.
[0184] When S1 allows to the child tree/subsets of the subscriber profile was independently and simultaneously transferred to other agents DSA can be used specjalizowaną procedure to ensure that local access to transferowanego wood child/the subset profile
55P31384PL00
EP 2 156 649 B1 subscriber, for example, wood sub-applications of high-speed steel, not cause unnecessary X. 500 łańcuchowania back to the original agent DSA, where is the main element of the subscriber according to the embodiment of the invention. This basic element of the subscriber is considered to be the root of the whole tree subsidiary profile of the subscriber and, therefore, is a parent to each subset of the auxiliary tree or the profile of the subscriber. When S1 imposes that the entire profile is abonencki koczowniczo relokowany from one agent DSA to another, the subscriber root is passed as part of the profile and, consequently, change all links/references to this root, according to the embodiment of the invention. However, when the subset or tree children profile subscriber is transferred, the root of the subscriber does not move with the tree, child, because, maybe, there are other subordinate trees that should remain intact on the agent DSA, which is currently stored, according to the embodiment of the invention. In order to avoid łańcuchowania X. 500 back to the original agent DSA, where is the root of the subscriber in a local access relokowanego wood attached appointment of agent DSA, the main element of the subscriber zacieniany locally or copied to a local agent, DSA, when a tree child is relokowane using the described procedures, according to the embodiment of the invention. this allows the initiation of local queries or updates on the tree the slave to use for the local end, because the whole name (DN) Rozróżniona name) of the destination record is the local agent DSA. If the DN of the tree contains sub-applications and other records, between the root and caller root of the tree sub-applications, they can also be shaded to ensure that it will be possible local processing of data without łańcuchowania X. 500 according to the embodiment of the invention.
[0185] According to the example implementation of the invention, it is possible to use an additional specialized mechanism to ensure that access to locally transferowanego subscriber profile or tree a child of the subscriber profile from one of many possible aliases to a fixed subscriber, resulting in a locally held the answer. Alias records
55P31384PL00
EP 2 156 649 B1 the root of the subscriber are implemented as standard recording Alias X. 500 or LDAP, in accordance with the embodiment of the invention. These Alias records contain reference DN of the entry pointed to by the. In this example, the alias of the root of the subscriber indicates the specific primary element of the subscriber. For example, the subscriber may have the name of the RDN "cn=William" recording alias that the name of the RDN "cn=Bill" also contains a reference to the main entry "cn=William". In this example, if the profile is moved from abonencki agents DSA D1 to D2 is the alias for it is left to the agent DSA D1. Queries using the entry alias result in result in that the request goes first to the agent DSA D1 to obtain and solve the alias "cn=bill" main entry "cn=William" which is currently on the agent DSA D2. In order to avoid the necessity of obtaining an alias D1 when the subscriber root is located on D2, the alias is also moved along with the profile abonenckim or tree slave profile using the same NSD procedures defined here. It is that of many aliases needs to be transferred, may also be included as part of the criteria of Transmission and the configuration is defined in Ekspedytorze Events NSD, the Migration Manager NSD and the Controller Transfer NSD, according to the embodiment of the invention. In this regard a specific alias can be passed only on the basis of the identification of the customer making the access, the priority of the customer accessing or based on the alias used by the client when invited access awakening koczowniczą move the data to the subscriber.
[0186] alternatively, to delete the subscriber data set S1 from DSA D1 agent, the NSD Transfer Controller may mark the subscriber profile, to remain in the shadow (or hidden) in the DSA D1 after the agent successfully moved the profile and appointment of agent DSA, agent DSA D12, according to the embodiment of the invention. The status "inactive" is determined, that data can be outdated immediately that there is a "active" copy is in another agent DSA. This approach can support return after disasters, and reduction of traffic when/if the access point to record S1 in the telecommunication network returns from the DSA D2 agents agent DSA D1 or
55P31384PL00
EP 2 156 649 B1 in accordance with that shown in FIG. 13A from agents DSA 1302c agent DSA 1302a.
[0187] All subsequent accesses to the agent DSA D1 for data collection subscriber S1 may be locally interrupted from agents DSA D2 and above, according to embodiment of the invention.
[0188] According to the embodiment of the invention, the system NSD can be performed depends on the profile of the subscriber. Typically a certain percentage of suppliers subscribers of the CSP moves around the coverage area. Consequently, the profile abonencki changes with the change of the position of the actual user of the subscriber, suggesting that the change results in unacceptable latency in children. Perhaps the collection limitations data of the subscriber S1 may contain a group of subscribers, although it may not be easy to determine how to group subscribers into nomadic collection. Also, S1 may contain the part of the subscriber profile or even part of subscriber profiles from a set of subscribers.
[0189] the implementation of the algorithm System of the Nomadic Subscriber Data can use the concept of X. 500 DISP for dimming or transfer records in accordance with what was said above, or may be implemented using the ordered interfaces according to the embodiment of the invention.
[0190] the Nomadic Subscriber Data System described here proposes one possible mechanism to solve the problem of nomadic data, although other options are possible. For example, the location of the NSD Transfer Manager and NSD Transfer Controller may be either part of the software itself directory, or divided into different components that operate on a centralized management system or in the system prowizjonowania. In addition, for scalability these components can be made of a scalable on multiple servers to provide throughput and flexibility for functionality of an NSD according to the embodiment of the invention.
[0191] May, in accordance with what was said above, the NSD functionality may include the ability to make changes
55P31384PL00
EP 2 156 649 B1 texture of the transmitted data of the subscriber. In accordance with what was said above, the entire profile abonencki is imported from one agent to another DSA. However, suppose two different customers with a higher priority accesses a subscriber profile from two different access points, each of which requires different subsets of the data services to subscribers. In accordance with the statement of the functionality of the NSD, such as, for example, Ekspedytor NSD Events and/or shift Manager NSD, may include the ability to share the same profile of the subscriber into subsets or tree of child components of the service (for example, HSS provides data, data services, HLR, data, prepaid) , and each of the individual subsets can be independently nomadic on the basis of such factors as access point, client system to achieve the access attempt, of course, the profile quality of service (QoS), according to the embodiment of the invention. In this alternative embodiment, only one copy of the subscriber profile would exist at any time (with the possible exception of recording a darkened root, or the root of the child that are stored locally are stored the names of the DN to avoid łańcuchowania X. 500), but its constituent elements (services) can be scattered in different agents DSA on the basis of locality of access and quality of services QoS.
[0192] In still another embodiment, instead of transferring and deleting a subscriber data set S1, the system NSD can be configured to hide the subscriber data set S1 to numerous agents DSA on the basis of factors based on the DSA agent, such as access points and profiles quality of service QoS, according to the embodiment of the invention. In such embodiment, the NSD system will also contain a mechanism that synchronizes multiple copies to ensure data consistency. The synchronization mechanism can be added to a component such as, for example, the Manager 1314 Transfer NSD, according to the embodiment of the invention.
JOURNALING AND BACKUP PROCESSES
55P31384PL00
EP 2 156 649 B1 [0193] FIG. 14 illustrates a system 1400 logging, according to the embodiment of the invention. The logging system 1400 see wewnątrzpamięciową database 1403, such as, for example, the data store 708a shown in FIG. 7A, the update 1402, 1404 wewnątrzpamięciową chronicle, a backup file 1409, and one or more files, the Chronicles 1406a - 1406c, Duplicator/Synchronizer 1411, a data logger, Backup, 1413, and so on. Wewnątrzpamięciowa chronicle 1404 contains a list of updates 1408a-1408g and so on.
[0194] In the application of the reinforced update Duplicator/Synchronizer 1411 may control the process of replicating updates to one or more servers DS. Duplicator/Synchronizer 1411 is typically associated with a directory server, such as server DS 706, shown in FIG. 7A. In particular, the DS server Powielacza/Synchronizer 1411 may be a primary server DS within the DSA agent, e.g., agent DSA 702. As noted earlier, the DSA agent has, as a rule, the main DS server with any number of auxiliary DS server, each of which has its own wewnątrzpamięciową database 1403, according to the embodiment of the invention. Updates 1402 are typically made in relation to the main servers DS DSA agent, and then reproduced for the other servers DS to a DSA agent, according to the embodiment of the invention. Of course, the Duplicator/Synchronizer 1411 may be put on any server DS within the DSA agent, according to the embodiment of the invention.
[0195] Duplicator/Synchronizer 1411 applied the updates 1408a - 1408g to wewnątrzpamięciowej database 1403. In addition, in various examples of the invention, the directory server also stores transactions in the data warehouse presented wewnątrzpamięciową database 1403 in the annals of wewnątrzpamięciowej 1404. Information is stored in wewnątrzpamięciowej chronicle may contain changes to the record, time for change, and the growing ID for each change and record status before change (for example, the value changed in the update), according to the embodiment of the invention.
55P31384PL00
EP 2 156 649 B1
Then the example of the invention, at regular intervals, or as fast as possible within these factors, such as the limitation of the disk subsystem, the completed operations are recorded wewnątrzpamięciowej Chronicles 1404 in the storage files of the chronicle 1406 as the preservation of the transaction.
[0196] Wewnątrzpam ięciowa chronicle 1404 is a common area of memory that stores information on all transactions in wewnątrzpamięciowej database 1403. The information wewnątrzpamięciowej chronicle 1404 is used during mirroring and synchronization. [0197] during playback Duplicator/Synchronizer 1411 may use the information in wewnątrzpamięciowej chronicle 1404 to scroll powielonej updates, for example, the update 1402, which is faulty. During synchronization, the Repeater/Synchronizer 1411 may use the information in wewnątrzpamięciowej chronicle 1404 to transfer the latest updates to the synchronization host, for example, from another server DS. In the example of the invention the transaction'stowarzyszone with updates 1408 are stored in a circular buffer. [0198] In various examples of the invention Wewnątrzpamięciowa Chronicle 1404 is configured to write transactions to disk with the file Chronicles 1406. In the example of the invention wewnątrzpamięciowa chronicle 1404 can create a new file Chronicles 1406 each time the node (e.g., the directory server containing wewnątrzpamięciową database 1403) is activated or when the current log file 1406 reaches a given size. The files of the chronicle 1406 may contain factual information, updates, identifier changes, as well as information about when the transaction was made, and by whom. [0199] the Chronicles Files 1406 are a key component when you play a node after a scheduled downtime or server failure, according to the embodiment of the invention. in various examples of the invention, when the Duplicator/Synchronizer 1411 uses the files of the chronicle 1406 in conjunction with a Backup File 1409, wewnątrzpamięciowa database 1403 may be restored to the last transaction successfully performed before a planned
55P31384PL00
EP 2 156 649 B1 exception (or failure), thereby minimizing the number of transactions that a master server must then transmit to synchronize playback with additional servers (e.g., DS server containing wewnątrzpamięciową database 1403).
[0200] In various examples of the invention, the Backup File 1409 may automatically be created in a certain period of time, for example once a day. The Backup file 1409 may also be necessary through the operator, other times.
[0201] the backup Process includes writing a name of each entry in the DIT 600 to the Backup File 1409. This description contains sufficient information to fully restoring a wewnątrzpamięciowej database 1403 when playing the Backup File 1409. The backup process will take a certain period of time, potentially several minutes in the case of a large wewnątrzpamięciowej database. This period of time is defined as the period of the backup. Some examples of the invention the data repository 1403 is available for normal activity in the period of the backup. The Backup file is saved in a persistent data store, according to the embodiment of the invention.
[0202] When restoring from the backup, Duplicator/Synchronizer 1411 associated with wewnątrzpamięciową database 1403 requires a Backup File 1409, and the files of the Chronicle 1406 at least for update operations performed during the backup. In the example of the invention Repeater/Synchronizer 1411 reproduces the first recording from their descriptions in the Backup File 1409. Duplicator/Synchronizer 1411 repeats associated with the files of the Chronicle 1406 all update operations that occurred during the backup period, in the order in which occurred, allowing for the fact that the update can be applied to recording or not, as long as the description of this input was saved in the backup 1409. Duplicator/Synchronizer 1411 may further use the updates that occurred during backup, in the order in which
55P31384PL00
EP 2 156 649 B1 occurred before a specific point in time or a specified change ID or until all available updates.
Played the DS server is now in a position to synchronize with the updates that happened on the other servers DS within the DSA agent after the latest updates applied file Chronicles.
[0203] Duplicator/Synchronizer 1411 may see and use information stored in the data Logger, Backup 1413 during the procedure of playback, according to the embodiment of the invention. Registrar Information Backup 1413 is configured to record the start time and end time for the period of backup with a Backup File 1409, and also ID change the start, which identificeret first update 1402 1403 wewnątrzpamięciowej database after backup started, and the code changes end which determines the final update wewnątrzpamięciowej database 1403 before the end of the backup. This information can be used to ensure the consistency of the recreated backup, according to the embodiment of the invention.
The catalog-oriented caller [0204] FIG. 15A shows a block diagram showing the hierarchy of the data stored in the Directory 1500, such as, the data used by the server HSS 301 shown in FIG. 3, according to the embodiment of the invention. When the HSS 301 server work, updates to the Directory 1500 typically add or modify data in subscriber and zapoczątkowywane from different domains, such as IMS domain 214 shown in FIG. 2. For example, the Directory 1500 may provide authentication information during procedures, AAA, to provide information about the profile of services in the registration and carry out transparent data services services.
55P31384PL00
EP 2 156 649 B1 [0205] the Directory 1500 typically provides a single directory, the logical networks for mobile telecommunication, such as a catalog, compliant with ITU-T X. 500 Directory. 1500 directory uses a hierarchical data structure in a tree is generally identified as a Directory Information Tree (DIT) that includes various entries in the directory. These records are placed in a tree view, where each record can be a parent to a certain number of records. Directory 1500 begins from the Root Node 1501. Of course, in certain embodiments, the Directory 1500, the Root Node 1501 can itself contain multiple node key of a lower order, which form together the root of the Directory 1500. For example, one node is the root of a low order can provide a part of the tree DIT, which concerns only data subscriber server HSS, or even only part of the data used by one subscriber server HSS multiple HSS servers in a large system of mobile telecommunication.
[0206] the Directory 1500 keeps a record for subscribers in a telecommunication network, such as, for example, the telecommunications network 200 according to the embodiment of the invention. In the Directory 1500, the subscriber identification may be numerous partitions on the person's name 1503a - 1503d. To reflect the data associated with HSS server 301, there can be at least four specific domain entries: IMSI Domain (IMSID), the name of the MSISDN (MSISDN), Name Personal ID (privateD), and the Name
Public ID (publicD). Name these are represented by an alias record, such as, for example, the Alias MSISDN 1505, the entry the Alias IMSI 1507, entry 1509 Alias PublicId and PrivateId Alias entry 1511. For example, so that the record Alias IMSI 1507 allows you to access subscriptions, such as the Subscription entry 1517, via the MSISDN 325, and through a unique ID, such as supply record Domain 1503c. Also record the Alias IMSI 1507 allows you to access the subscription record, such as the Subscription entry 1517, using the IMSI 323, and a unique ID. The same recording Alias PrivateId 1511 allows you to access the subscription record, such as the Subscription entry 1517, with the key PrivateID 327, as well as through a unique identifier ID. Recording Alias
55P31384PL00
EP 2 156 649 B1
PublicId 1509 allows you to access the subscription record, such as the Subscription entry 1513 with a key PublicID 329, and through a unique ID.
[0207] the Subscription Entry 1513 represents the level of the top (or root) data of the subscriber. The Subscription entry 1513 represents the root of the subscriber data prowizjonowania for services, such as services associated with the server HSS whether the register HLR. In accordance with what is said, data services HSS, HLR services, and other services, they are kept as a record of children record 1513 Subscription. For example, the entries may contain an entry hssService 1515, hlrService entry 1517, and other services 1519. In the example of the invention a globally unique IDENTIFIER, in accordance with what is shown through the Domain 1503c, identificeret the Subscription entry 1513 from the point of view of diagnosis, through a defined standard, such as, for example, Rozróżniona Name (DN) of X. 500. The Subscription entry 1513 may also be from using the identity of the alias, such as, for example, the IMSI 323, the MSISDN 325 room, the key PublicId 327 and key PrivateId 329, in accordance with what is discussed here. [0208] FIG. 15B shows a block diagram depicting a server architecture of HSS, such as, for example, the server HSS 301 main communication network CN 206, shown in FIG. 3, according to the embodiment of the invention.
[0209] the Server HSS 301 may include multiple servers, each of which includes an application server HSS 1521 is integrated with the platform Directory Server (DS) 1523 according to the embodiment of the invention. Platform 1523 Directory Server contains at least one agent agent DSA and DUA, such as the DS platform shown in FIG. 7A. of course, the DS platform 1523 may contain more or fewer agents DSA than shown in FIG. 7A and FIG. 7B. Server HSS 301 may include a TCP/IP interface to search for and update data on the DS platform 1523 using standard protocols such as DAP and LDAP. TCP/IP interface can also be used, for example, to provide the database when a new subscriber joins the IMS domain 214. Platform 1523 Directory Server for tasks
55P31384PL00
EP 2 156 649 B1 such as duplication, data synchronization, data backup, providing automatic error detection and recovery after the accident.
[0210] the HSS Application 1521 facilitates transaction processing subscriber and traffic signals from the various domains in the backbone Network, such as IMS Domain 214. In the example embodiment of the invention the HSS application 1521 typically takes the message from the domain, formatted according to a diagnosis Protocol, such as, for example, a message formatted according to the Diameter Protocol from the IMS Domain 214. The Diameter message may, for example, require data storage on the Server, article 1523 for data related to a particular subscriber.
[0211] the Server HSS 301 typically maintains and uses two basic data type. First, the HSS server 301 contains data prowizjonowania data relating to subscribers and available services. The data is stored prowizjonowania itself, as a rule, ordinary subscriber data such as identity, function, CSCF 321 in the IMS domain 214, where was your subscription current status of the exception calls (barring), as well as profile data services. Secondly, the server HSS 301 includes configuration and control data on a shared services HSS 301 and the HSS server system 301. Server configuration data to the HSS 301 stored on the Server, article 1523 contain the following elements: as a Rule, Remote IMS (Remote Entity Rules), the Possibilities for the target Servers (Required Server Capabilities) and the Permissions AS (AS Permissions).
[0212] in Accordance with what was said of the example of implementation of the invention provides an improved server HSS, which contributes to the CRYPTOGRAPHIC service providers to implement flexible network infrastructure that can implement technologies such as IMS, Nielicencjonowany Mobile Access (Unlicensed Mobile Access (UMA)) and other IP services. Some examples of the invention, the improved HSS is compatible with server platforms HLR other manufacturers, is configured to minimize the gap of the network, provides support for the many ways parallel
55P31384PL00
EP 2 156 649 B1 network access, and also provides the flexibility of linking services to a larger number of subscribers. In addition, the advanced server allows HSS suppliers
CSP is easy to introduce new services, consolidation and improving business processes and reducing operating expenses.
Współhostowane HSS/HLR and co-invested HSS/HLR [0213] FIG. 16A and FIG. 16B depict a flowchart representing respectively współhostowany system 1600 and współlokowany system 1620 for the HSS 301 and the server registry HLR 307, according to the embodiment of the invention. As in the case of współhostowanego system 1600, as współlokowanego system 1620, the HLR 307 and registry server HSS 301 and use the Directory 1605 located on a server in the back (backend) 1603. The directory 1605 comprises a directory implemented in one or more of the agents DSA, such as, for example, the agent DSA 702 shown in FIG. 7B, according to example of the invention.
[0214] the Examples of the invention can offer a single logical server HSS and the HLR registry. Server HSS 301 and the HLR 307 register shown in FIG. 16A and FIG. 16B effectively, give a combination of one logical HSS and HLR register, as will be discussed. When a CSP making a combination of new services and use komutowanie IP register HLR 307 can become a focal point for future extensions to the network CSP. In addition, the HSS server 301 can propel providers CSP to improve their relationships with their subscribers. As a result, one logical server HSS and the HLR registry can lead the improvement of conventional networks.
[0215] When the server HSS 301 and the HLR 307 are installed a registry on the same computer as the server, this setting is defined as "współhostowana installation HSS/HLR". In accordance with that shown in FIG.
16A, the server HSS 301 and the HLR 307 are registry on the server front
55P31384PL00
EP 2 156 649 B1 the end of 1601. Server HSS 301 and the HLR 307 using registry Directory 1605 installed in the back end server 1603.
[0216] In the example embodiment of the invention, the front end server 1601 can have a distributed architecture, such as server HSS 301 and the HLR 307 registry that are located on multiple servers, 1609, 1611, which form a logical server front end 1613. In accordance with that shown in FIG. 16B, when the server HSS 301 and the HLR 307 are installed a registry on a separate front end servers 1609, 1611 but share a common Directory 1605 installed in the back end server 1603, the installation is defined as "współlokowana installation HSS/HLR". In this regard, the server HSS 301 and the HLR 307 using registry Directory 1605 installed in the back end server 1603.
[0217] If the server HSS 301 does not share Directory 1605 register HLR 307, this setting is defined as "a separate server HSS". In such systems, HLR registry data are typically stored on the remote repository HLR data. A separate server HSS is not illustrated here, but this kind of architecture is known in the art.
[0218] the name of the mobile Subscriber that has the HLR data or współhostowanym system 1600 or współlokowanym system 1620 is called the "subscriber home." Caller name mobile that has the HLR data on a remote HLR data repository, called a "subscriber niemacierzystym".
Mode UMS [0219] the Server HSS 301 interacts with the register HLR 307 to provide various services for subscribers in the UMS Domain 214, the PS domain 212, and the CS domain 210, in accordance with what was discussed earlier. This is called server HSS 301 in the Server Mode of User Mobility (User Mobility Server (UMS) Mode).
[0220] Mode UMS ensures smooth operation of the server HSS for współhostowanych system 1600, and 1620 współlokowanych systems, as
55P31384PL00
EP 2 156 649 B1 for a separate server HSS. Mode UMS also allows smoother operation if some subscribers on współhostowanym system 1600 or 1620 współlokowanym system for some reason are subscribers niemacierzystymi. Whether the subscriber is "native" or not, is defined using what data is available to the HLR of the subscriber in the directory 1605 in the back end of 1603, according to the embodiment of the invention. In other words, the typical process is to try and read the data of the HLR. If such a reading is completed, press "parent". Otherwise, the subscriber niemacierzysty.
[0221] In mode UMS server HSS 301 operates in three scenarios. In the Case of the server HSS 301 interacts with a remote HLR 307 registry, which is a regime, in General, well-adjusted via conventional approaches. In Case II server HSS 301 interacts with data obtained from the register HLR 307 in współhostowanym system 1600. In the Case of III server HSS 301 interacts with data obtained from the register HLR 307 in współlokowanym system 1620.
[0222] Interface Mobile Application Part (Mobile Application Part (MAP)) between the register HLR 307 and HSS 301 server enables UMS. The interface CARD facilitates data recovery, such as, for example, vectors of authentication resynchronizacyjne number of consecutive authentication (authentication resynchronizing the sequence numbers) and/or restore of user data and location information in the CS domain 210 and the PS domain 212. [0223] the MAP Interface, which is known in the art, provides communication between the HSS server and the remote register HLR. In this regard, the remote registry is kontaktowany HLR HSS server when required, using the MAP interface 1609. For example, in this kind of config.cjach server HSS performs the operation of sending login information MAPS (MAP Send Authentication Info (SAI)) remote registry HLR to restore the vectors for authentication and resynchronizacyjnych serial numbers. In this kind of config.cjach server HSS performs a MAP Any Time Interrogation (ATI) on the remote register HLR for information about the status and location of the user CS domain/a PS name.
55P31384PL00
EP 2 156 649 B1 [0224] a Message CARD from the server HSS are conditionally cable for remote registry HLR using the IMSI number or the MSISDN of the subscriber. Key PrivateID niemacierzystego subscriber with the corresponding number
IMSI is stored in the HSS data. The IMSI number is used to contact the remote registry HLR after receiving the message Cx-MAR. For the Public key ID of the parent or niemacierzystego subscriber corresponding to the MSISDN number stored in the HSS data. The same number MSISDN is used to contact the remote registry HLR after receiving the message Sh-UDR. According to the example of the invention possible to perform the mapping between the key PrivateID subscriber number IMSI. Mapping this allows you to effectively number the IMSI execution of transactions in the register HLR 301 and 307, the HSS server.
[0225] However, the subscribers are effectively subscribers of stem cells in współhostowanym the system 1600, as współlokowanym system 1620. In connection with this transaction, SAI and ATI are not required for współhostowanego system 1600 or współlokowanego system 1620, and there is no need to duplicate the data used by the server HSS 301 and the HLR 307 registry. As for współhostowanego system 1600, and 1620 współlokowanego system authentication data 1607 are stored in the Directory 1605 in such a way that they can be used as a server HSS 301, and the register HLR 307. Consequently, the authentication data 1607 shall not be reproduced to deal with each of these applications. In other words, the processes of the SAI and ATI should not be performed in the system configured in accordance with that shown in FIG.ch 16A and 16B. In accordance with the statement of the General operation of the telecommunication network can be obtained by simply disabling the UMS mode. In this regard, the authentication data 1607 may be shared between the server and the HSS 301 and the HLR 307 registry, according to the embodiment of the invention.
[0226] In the example embodiment of the invention, the network management system, such as, for example, Network Management System 412 may determine the Mode of the UMS server HSS 301 so that it worked in mode is Enabled (ON) or in mode
55P31384PL00
EP 2 156 649 B1
Off (OFF) for this combination of HSS and HLR. UMS mode can be switched on or off, e.g. by setting the label "only your data" to TRUE (it means "no HLR") or FALSE (it means "HLR"). If the UMS Mode - OFF, the transactions SAI and ATI, for example, will not be used by the server HSS 301 connection register HLR 307. In the case of setting the value "OFF", the authentication state may be available for the server HSS 301 and the HLR 307 using registry simple access to the Directory 1605.
[0227] FIG. 16C illustrates a front end 1601 that has been configured to hold service data 1619 for applications such as server HSS 301 and the HLR 307 registry, according to the embodiment of the invention. [0228] the Data stored in the directory, e.g. the directory 1605, contain usually a mixture of data and provides subscriber data 1619. These services, 1619, such as, for example, are not typical for the subscriber's authentication data 1607 and the marker in UMS Mode, can be separated from the data of the subscriber and number of applications (e.g., server, HSS 301 and HLR 307 registry), which often use such data, according to the embodiment of the invention. By shifting these services 1619 to the Front End 1601, access is not typical for the subscriber authentication data 1607 and the UMS Mode label applications such as server HSS 301 and the HLR 307 registry almost instantaneous, according to the embodiment of the invention.
[0229] the Data provides 1619 usually contain items such as a marker in UMS mode and an authentication scheme. According to the embodiment of the invention, the authentication scheme may lead alias for other authentication schemes. In this regard, this approach may use a pseudonym, supported inside the server HSS 301, according to the embodiment of the invention. The mapping discussed above for the key PrivateID and the IMSI can also be done when the services in 1619, was moved in front of 1601, according to the embodiment of the invention.
55P31384PL00
EP 2 156 649 B1 [0230] the Agent DSA the Rear End, otherwise it works like the Rear End of 1603 shown in FIG. 16A as an agent of the DSA 702 shown in FIG. 7A, according to the embodiment of the invention. Also, the DS server 1625a - 1625c DS work similarly to the DS server
706 shown in FIG. 7A. Agent DUA 1627 operates similarly for agent DUA 704 shown in FIG. 7A, according to the embodiment of the invention.
Static Entries for Methods Intermediate [0231] FIG. 17 shows a block diagram showing a data hierarchy stored in a Directory 1700 facilitating static access to entries, according to the embodiment of the invention. The directory 1700 may be stored on one or more directory servers 1721, configured as server the DS 706, shown in FIG. 7A. The DS server 1721 can work within the DSA agent, such as, for example, the agent DSA 702 shown in FIG. 7A. The same operation, in the Directory 1700 may be received and processed via the application catalog server 1723, everything works the same as the software catalog server
707 shown in FIG. 7A. components running on the Directory 1700 sprzęgają computer components inside the server directory to handle the updates, e.g. using the CPU. [0232] that Require a unit (for example, applications such as server HSS 301 or the HLR 307 registry), invokes one or more methods of entry 1703 - 1715, are present in the Directory 1700 to perform various functions. The requesting unit may present each unit able to execute the query to the directory 1700, such as a client application or end user. These methods hide application knowledge, on the mutual relations of data within the schema of the Directory 1700 and provide simple interfaces, such as, for example, prowizjonowania. Public ways can be a means for: adding a subscriber adding a subscriber, for example, the service server HSS for an existing subscriber
55P31384PL00
EP 2 156 649 B1 and/or change the service settings of the subscriber, such as, for example, to change the settings of call forwarding.
[0233] Using the call intermediate methods, such as records of 1703 - 715, an external application can operate on data in the directory 1700 without having specific knowledge of the directory structure. This can be particularly useful in directories where the scheme they are subject to frequent change and/or genetic programs that were designed to work with a particular schema. Despite the fact that the examples here are related to the system of telecommunications services, this approach can be applied in various systems, which I'm sure the application must perform tasks in a certain directory but not know or may not know the actual directory structure according to the embodiment of the invention.
[0234] the Application, such as server HSS 301 or the HLR registry is causing the image associated with the item, such as the entry 1703, using rozróżnionej name (DN) of the entry. The name reflects the actual DN or adapted tree records, ancestors who creates records, which are available this way. For example, the DN of the entry 1707 is "Root.You can send commands with.EntryB”, because the Root (Root) Entry 1701 and 1703 are the ancestors of the entry 1707 in the Directory 1700. Thus is now defined as "a Way True". The application of the Methods in the Actual directory structures is known in the art.
[0235] due to the fact that the name reflects the actual DN or adapted the name of an element tree, consisting of various ancestors, the DN can be a problem when the schema of the Directory 1700 is changed for some reason. Such changes can affect the naming of the record and, therefore, can change the record name, which should work ways prowizjonowania. This affects the system prowizjonowania, due to the forced changes to the software to change the names of schemes. For example, assume that the scheme is changing so that the record 1709 is added to the Directory 1700 between the entry 1707 and the entry 1711, and in addition, assume that the connection between the entry 1707 and the entry 1711 - removed.
55P31384PL00
EP 2 156 649 B1
Name the DN of the entry 1711 changes, so "Root.You can send commands with. EntryB.EntryB.2" by "Root.You can send commands with.EntryB. EntryB 1.EntryB2”.
[0236] According to the example embodiment of the invention Method, the Actual can be the Deputy of the "Method Niebezpośrednim". Method the indirect method is applied to the recording system, such as a Root 1701. Recording system common to all applications and requires no changes when changes occur in the schema. Therefore, the " entry system "static" and the Image is applied indirectly can be caused by using a static element of the system. In the example implementation of the invention, the indirect Method is applied is at the point where the application connects with the Directory 1700. For example, entry 1705 represents a "Static Entry C. 2". In this regard, the application can use the appropriate Protocol (for example, extended operations, LDAP) to display the record 1705 (that is, the way the submitted entry 1705) to call the method represented by entry 1715 regardless of schema changes, which could change the name of the DN of the entry 1715. In other words, the app sends the recording method 1715. An application that needs to call a method of a static entry (e.g., entry 1715) needs to know the DN of this record. In this regard, the name of the entry (e.g., its DN) should be the name you will not have to change.
[0237] the indirect Method is applied comes through the API with some information, RDN, such as, for example, the identity of the subscriber and includes the second part of the design information of the DN in its internal implementation. This allows you to reconstruct how to apply indirect DN of the entry where the visitor should be Way Real. This functionality can be implemented in two ways:
• reconstruction of DN can be "encoded firmly," that is, the character of DN is implemented in logic, software recording static, such as Static Entries C. 2 1705 and/or • reconstruction of the DN mobile "int soft", for example, using a template DN stored in the custom data services, for which specific information
55P31384PL00
EP 2 156 649 B1
RDN supplied through the API podstawiana via a static entry, such as Static Entries C. 2 1705. These customized data services will tend to be stored inside the directory itself, the same way you keep the directory schema.
[0238] In this regard, to apply the indirect Method includes information to identify the DN of the entry on which Actual should be named - but the indirect Method is applied to hides from external applications to interface changes caused to the schema of the Directory 1700.
[0239] According to the example embodiment of the invention, when the directory schema is changed so that affects location records in which it is located, the Real Method, the indirect Method is applied must be updated to reflect this. If the applied indirect Method is implemented in the encoding method soft, as described above, then all you need is to define a new template DN. In some cases it is desirable (for example, to transfer the data in mode on-line) Method is applied indirectly supported the two forms of DN, at least for the duration of the migration.
[0240] due to the fact that the indirect Method is applied is at the point where applications connect to the Directory Server (for example, a Static entry C2 705), no need for more communication between the agents DSA for access path between the application and the Way Niebezpośrednim, according to the embodiment of the invention. Despite the fact that often the most elegant approach is a single entry for the program with many application-specific ways, it is possible to use a static element with numerous applications. This means that the connection point can be located exactly in the DSA agent, such as, for example, the agent DSA 702 shown in FIG. 7A, which are connected to external applications that use this method. In accordance with what has been said, covers the performance, therefore, minimal. External applications, even down to the way Niebezpośrednich would have to connect with the primary (root and root) agent DSA.
55P31384PL00
EP 2 156 649 B1 [0241] the Indirect Methods present an interface for the application that contains sufficient information to allow you to get through the indirect Method is applied name of the current element, which should work the way real. In this regard, to avoid cheating the system associated with the restructuring of schemes, by applying Methods Niebezpośrednich.
[0242] the static Entries that perform the indirect methods, such as a Static entry C2 1705, can be created at almost any time in the Directory 1700 using a Static entry Master of 1720 according to the embodiment of the invention. of course, the creation of these records and how the task is typically during system installation/upgrade software. The job is usually associated with the installation of the extended schema that defines the new or changed object class and define the methods together with the installation of public libraries, which contain code of the method. The job is so important activity of the software installation and can be carried out using standard methods of software installation (for example, using a UNIX system, the file package or rpm or contained shell scripts, config files.cyjnymi, files download databases with binary and so on). Master Entry 1720 Static can build a static entry, associate it with a Directory 17, as well as equip a static entry for the reconstruction of the DN of the entry where the guest can be a Real Image using the approach with the coding hard or soft, as described above. Master Record Static 1720 may also include an operator interface that simplifies the task of creating static entries.
The clock mechanism [0243] Improved clock mechanism, can be applied in different situations, such as in the case when the events concerning the establishment, change, or delete hours can be obtained through various
55P31384PL00
EP 2 156 649 B1 units and/or when the validity period of the hours is so important that it should be a highly available event (e.g., more available than is typically possible in an individual node of the transmitter).
[0244] in Accordance with what was said example of the invention provides a highly efficient warehouse duplicated data, configured to store the time, so that they can be potentially divided in various ways, for example through time or through an Application ID. Of course, this example of execution of the clock mechanism can provide access to hours only in one direction, for example, by the expiration date hours. In accordance with what has been said, examples of manufacturing allow for processing request units (e.g., applications) that are located on multiple nodes, events that require the creation, modification or deletion of hours to do it using a mechanism such as the Application ID. In accordance with what was said, requiring unit can be any unit, for example, a client application or end user, who need hours for this event. [0245] Using the duplicated data warehouse allows zegarom to maintain, even if the individual nodes that process fail, according to the embodiment of the invention. In addition, the clock can be divided by time, according to the embodiment of the invention, so that the processing loss can be performed by any available processing node that may have access to store duplicated data.
[0246] high-performance database and the mechanism of duplication in real time, given only the limits of the possible implementations for the example of the invention, capable of handling large amounts of events for a second time. In this regard, the clock mechanism can be used to implement complex or simple.
[0247] FIG. 18A illustrates a communications network 1800 using a access point high speed (HSAP), which can enjoy the benefits of an improved clock mechanism according to the embodiment of the invention. The clock mechanism is a leak here can be used in
55P31384PL00
EP 2 156 649 B1 different environments, and communications network, 1800 described here is just one such medium that can be used by advanced clockwork.
[0248] In the network 1800, when it can be a subscriber moves 1810, responsibility for maintaining his connection is, in the end, from the base station 1812a to the base station 1812b. The base station 1812a - 1812d communicate various subscriber information and services via an access point high speed (HSAP) 1814. The network 1800 may be configured to support, for example, base stations 1812a - 1812d from various manufacturers in a small office, to provide wireless network function of mobile roaming.
[0249] Point HSAP 1814 may communicate with base stations 1812a - 1812d using the AAA Protocol, such as the Cx Protocol, which is used in IMS networks, compatible with 3GPP, to communicate between I-CSCF and S-CSCF and HSS server, such as the CSCF 321 and the server HSS 301 shown in FIG. 3. These protocols are known in the art and certain standards, such as RFC 3588, 3GPP TS 29.228 and 3GPP TS 29.229. [0250] In the configuration shown in FIG. 18A, the dot effectively HSAP 1814 located on the banks of a network frame 1812 and contains a Node SGSN (SGSN Emulated) 1816, emulator for node SGSN 317 shown in FIG. 3. In this regard, the point of the HSAP 1814 and the Node SGSN 1816 can effectively help to ensure that the entire network of 1,800 will act and behave as a normal home " network. In this regard, the network 1800 operates in a similar manner to the mobile network 204 shown in FIG. 2.
[0251] the Point HSAP 1814 can use the Node SGSN 1816 to communicate with the register HLR 307 using regular MAP interface. The interface CARD provides the application layer for various nodes in the backbone Network connection, 1822 for mutual communication in order to provide services to mobile subscribers. Backbone network 1812 may include more than one registry HLR, and to Emulate
55P31384PL00
EP 2 156 649 B1
The SGSN node can be configured to communicate with the HLR logs the network frame 1812.
[0252] the Point of the HSAP 1814 using the Node SGSN 1816 may also include the Function of Data Loads (Charging Data Function (CDF), which collects events load reported via base stations (BS 1812) to Write Data Loads (Charging Data Records (CDR) and forwards them to the System Alcohol 1818, according to the embodiment of the invention. A CDR record is a formatted collection of information about obciążanym events (e.g., making connections, duration of connection, amount of data transferred, etc.) for use in billing and accounting. If the CSP supplies the subscribers in specified accounts, CDR records are used to construct line items on the subscriber's account.
[0253] In this custom network settings it is possible to point HSAP 1814 may not supply the System Loads 1818 important events related to the CDR record, like "event "end call" and "event" communication". Both of these events, which are known in the art, are useful in determining loads appropriate number, especially in the case where the subscriber pays on the basis of and at least partially based on the duration of the call.
[0254] FIG. 18B depicts the physical communication network 1800 shown in FIG. 18A, which can use the advanced clock mechanism according to the embodiment of the invention. In accordance with what was said above, the network 1800 can be configured to support a wireless LAN, which provides the function of roaming mobile device. Assume that base station, such as BS 1812a and 1812b BS have been configured to support communications Protocol High-Speed Downlink Packet Access (HSDPA). The Protocol HSDPA, sometimes referred to as High-Speed Downlink Access Protocol, is a Protocol of mobile telephony of the third generation 3G HSPA family and provides a large data transfer rate. The Protocol HSDPA achieves the increase in data transmission speed by determining
55P31384PL00
EP 2 156 649 B1 of the new channel W-CDMA or TD-CDMA, a common communication channel down at a high speed (HS-DSCH), which is used to communicate the link down to the mobile station. The HSDPA Protocol known in the art.
[0255] Assume that the base station BS 1812a - 1812b communicate with the agent DSA 1831. Agent DSA 1831 can be formed in the same way as the agent of the DSA 702 shown in FIG. 7A. Agent DSA 1831 may operate on data associated with an HSDPA node 1834a in conjunction a DS node 1836a. A DS node 1836a may operate as a server DS 706a, shown in FIG. 7A. The HSDPA node 1834a and the DS node 1836a form so once the physical layer for the tasks performed through the logical layer shown in FIG. 18A, according to the embodiment of the invention. [0256] in Accordance with what is shown, the agent DSA 1831 may also be formed from multiple HSDPA nodes 1834a -1834c, with each HSDPA node 1834a - 1834c has an associated DS node 1836a - 1836c. Agent DSA 1831 may contain more or fewer HSDPA nodes and DS nodes than shown. In addition, the HSDPA nodes and DS do not necessarily have to be pair with him, although in many networks this type of pairing would be desirable.
[0257] the Network may include more base stations than just the base station BS 1812a - 1812b. Each base station communicates with a primary HSDPA node and, if necessary, support node HSDPA. For example, in accordance with the as shown, the base station BS 1812a has the HSDPA node 1834a as its primary HSDPA node and HSDPA 1834b as its node the secondary node for HSDPA, in accordance with what is shown by continuous lines and doted.
[0258] In this network configuration, a base station, such as base station BS 1812a, as a rule, will work in constant contact Diameter in the order of proper maintenance records, such as CDR records. It is not surprising that sometimes it can be difficult maintaining a continuous, Diameter-session. As a result, there are problems in maintaining a consistent set of CDR records.
55P31384PL00
100
EP 2 156 649 B1 [0259] When the mobile station MS moves 1810, not all base stations 1812a, 1812b in the network can share the same HSDPA node. In this regard, the network includes a handover between base stations, which allows you to continue uninterrupted connections.
[0260] However, events are load affiliated with connection can be presented for various nodes HSDPA depending on whether the mobile station MS 1810 is at base station 1812a or 1812b. The solution to this problem is to store events encumbrances in respect of the subscriber in a common subscriber database accessible to all nodes HSDPA. She can either create the part agent the DSA 1831, or may be enclosed within one or more individual agents DSA the rear end.
[0261] Unfortunately, even this solution of the problem, because the Deputy Director of these agencies watch for this connection on the DS server may not receive "event end", for different reasons. These institutions watch the usual timer that is used in telephony to upewniania that the events of alcohol associated with a specific connection is not lost over the network. It is also possible for some key events, such as, for example, the events of the end connections, vision loss connections, that could look as if this connection has never been located, or that the connection is continued, substantially less or more than the actual duration of the call. For example, "event" end of call" represents the completion of the call (when one party hangs up), which can be important information in the CDR records, because a lot of stressful calls to vendors CSP based on the duration of calls and/or total duration, the subscriber's connection in the specified time period, e.g. a month. In this regard, there is a need to transmit the clock along with other information about the connection between the nodes HSDPA or ensure that this information is provided for the corresponding procedure of the rear end.
[0262] therefore, the embodiment of the invention includes a distributed clock mechanism, which can be used as a watch
55P31384PL00
101
EP 2 156 649 B1 of these institutions to network, such as described herein. Examples of the performance of these watches do not necessarily require high accuracy, and in some embodiments these institutions may be configurable, for example, from 10 to 60 seconds.
[0263] FIG. 18C shows a Subscriber entry 1841 from a directory, such as directory agent retained by the DSA 1831, according to the embodiment of the invention. The entry 1841 Subscriber contains an entry Load of 1843. Entry Load 1843 contains records of Event, Load, 1845, and records of these institutions Watch, 1847.
[0264] for Example, in the example of the invention applied to telecommunication network supported data servers DS 1836 in agent DSA 1831 represent the HSDPA node for each cycle of the timer pseudo dozorującego hours. Also, the data representing each "event" means of communication" for the HSDPA node for the subscriber and its branch "session, media". The event connection tool is, as a rule, the requirement of standards of weights to ensure that regular entries are maintained in the records CDR for the current call. Event center connection and do not necessarily reflect the state change in combination, at least. The events of the mid connection is typically generated fairly often, and can help in assigning the call is completed, if the event end of the connection is not registered. As a consequence, event, means of communication, can contribute to the billing system to correct voltage długotrwających connections that extend over multiple periods of the load. The call event, e.g., events, communications, and events of the end of the connection must be taken regularly for the HSDPA node 1814 in accordance with the standards of the telecommunications and therefore, the HSDPA node 1814 to run these institutions the clock to ensure that they will actually be received correctly.
[0265] FIG. 18D represents 1850 Hours, having a Watch entry 1851 in a directory excess agent DSA 1831, according to the embodiment of the invention. The entry of these institutions Watch, 1847, is shown in FIG. 18C supplies
55P31384PL00
102
EP 2 156 649 B1 which can be used to "transfer" the entry of these institutions Clocks Load Data Subscriber (Subscriber CD Guard Timer 1848a-d associated with the Data entry Burden 1843 by "quantum" pseudo hours, Hours held 1851. In this regard, the record Watch 1851 provides dynamic clock tree, according to the embodiment of the invention. [0266] Watch Entry 1851 maintains a set of records "ticks" clock 1855a 1855d. These recording cycles represent different times within Hours 1851. Events connect and can be in hours from the start time ("now" + XX) until the end ("now"). In this regard, these institutions Clocks Load Data Subscriber 1848d can first be associated with a maximum duration dozorującego hours, the entry at the Moment + XX 1855d.
For example, 1855s can represent 60 seconds from now, and could be called "in the Moment + 60".
[0267] these institutions the timer represents the maximum time during which the delay may be the event of the joint means or the end event of the connection before deciding to become a corrective action, for example, create abnormal CDR records.
[0268] If the client application receives the correct response (e.g., event, means of communication), then the client application can remove a permanent clock and , if necessary, start another timer. In other words, ever adopted by a new event, the means of communication specified institutions Data Clock Load of the Subscriber 1848a - d should be deleted and replaced by the new timer at the moment "is currently + 60". When any event is received, the end of the connection, the current of these institutions Clocks Load Data of the Subscriber needs to simply be deleted.
[0269] until the moment when it will be received the event mid-connection or event end of the connection, the extension of these institutions Clocks Load Data Subscriber 1848a - d passes through the watch, in the end, reaching to record the Moment, 1855a, according to the embodiment of the invention. When a client application przepytuje record at the Moment, 1855a, a client application can find all of the records, such as, for example, these agencies Watch
55P31384PL00
103
EP 2 156 649 B1
The data Load of the Subscriber 1848a, which were prohibited without obtaining the events of the mid connection or events connection end. A client application can then perform the appropriate corrective action in accordance with the standards of the load.
[0270] to permit the successful implementation of all these actions, the example of the invention you should apply the following naming rules entry:
• Watch 1851: called by the agent DSA in which he resides, and the subscriber 1841.
• These institutions Clocks Load Data Subscriber 1848a - d: called in accordance with the identity of the caller and ID of the record in the Data Load 1843 • these institutions Watch 1847: called to match the Clock and the 1851 entry at the Moment+XX 1855a - d, which is at the present time these institutions Clocks Load Data Subscriber 1848a - d.
[0271] In the example embodiment of the invention shown in FIG. 18D, watch 1851 was installed with ziarnistością 10 seconds, which is the reason why the entry names of the bars are moved in increments of 10, such as, for example, stroke is currently+10 1855b. However, the graininess of the recording cycles can be set at a different level of time, such as 1 second or 20 seconds, depending on the requirements of the time. To stop the timer 1851 (for example, the duration of time represented by the clock) can be almost any length, with less accurate results (for example, more than sometimes) oznaczającymi shorter periods of service for the CSP, this means the clock granularity of 10 seconds and a duration of 2 minutes is less accurate than the clock granularity 1 second and a duration of 30 seconds. The entry arrows, 1851 can be configured for larger or smaller size, the presence of a greater or lesser number of entries for different times, according to the embodiment of the invention.
[0272] In connection with this application, such as, for example, the main HSDPA node 1834a, should periodically contact their slits belt
55P31384PL00
104
EP 2 156 649 B1 "in the moment", which must contain only records Dozorujących Hours that should appear. Perhaps the clock mechanism can be designed to alert applications about the job in the time interval "present". All events are located in time at the moment 1855a represent the hours that have elapsed, and therefore require appropriate processing (for example, by adding the abnormal events of the mid connection to CDR records) when you retire. In other words, the application, such as application for HSDPA node 1834a trying to collect the events of the loads that lost oversight.
[0273] the processing of Events such as the events of mid-connection or events connection end, as a rule, require the release and possible re-posting of watch. If the naming rules set out above continue, the application must not scan all devices that are still in use, but may be search for them through n azwy when coming events, communications, and events of the end of the connection. Other operations, such as, for example, checking whether the connection is still connected, and can be supported by simple mechanisms of rejection and possible re-posting of watch and/or share the events of the end of the connection to connect to the loading system 1818.
[0274] 1851 Watch, can realize the flow of events relating to the individual subscriber, group of subscribers or a separate set of servers, subscription. If for some reason the regular flow of events is interrupted, then the clock 1851 may help you in determining what happened to the interruption and to assist in the launch of a special processing that needs to happen according to the embodiment of the invention.
[0275] FIG. 18E illustrates to escape the clock mechanism is implemented on the agent DSA 1831, shown in FIG. 18B according to the embodiment of the invention. As mentioned above, to escape the clock mechanism can be applied for synchronization of each event, and not necessarily limited to clock events related to the telecommunications systems.
55P31384PL00
105
EP 2 156 649 B1 [0276] the Agent DSA 1831 reminds the agent of the DSA 702 shown in FIG. 7A. Also, the server DS 1836 resembles the DS 706, the server agent and the DUA 1864 operates as an agent DUA 704 shown in FIG. 7A. The client application 1866 could be any application that uses or another sought-after unit, but in the mechanism with the clock mechanism described herein for mobile telecommunications is most likely that this will be the unit responsible for maintaining time events, such as an application associated with the node HSDPA 1814, according to the embodiment of the invention.
[0277] Each DS server keeps a copy of the 1836 1850 hours is shown in FIG. 18D. Therefore, any of DS servers can achieve processing of incoming events. Generally, any of the servers DS 1836 may achieve the processing of reading/searching with one main server, DS (e.g., DS server 1836a) responsible for adding/removing to/from 1850 Hours. The main server DS 1836 may also be responsible for communicating with a client application that 1866 (for example, when the record reaches the position of the "in the Moment" without the processing of a new event), according to the embodiment of the invention. In this regard, module, 1861 timer can be configured to communicate time events and relevant information for other modules, 1861 time on other servers DS. For example, only one module, a timer, 1861 must relate to the overclocking results for the sender unit (e.g., client application), although all the warehouses in slow motion, can be available for the sender unit according to the embodiment of the invention. In this regard, the disparate modules waiting to happen," 1861 may be configured so that only one module, the timer shall notify the requiring unit of the desired event if the event occurs temporary, according to the embodiment of the invention.
[0278] According to the embodiment of the invention, each server DS 1836 may include a module, a timer, 1861 to facilitate the processing of 1850 hours. Module, timer, 1861, may contribute, for example, make sure that the records are delayed-action being updated. Module, timer
55P31384PL00
106
EP 2 156 649 B1
1861 can also help in the treatment of actual breaks Hours 1850 by examining the legacy of the records and directing the testimony of overdue hours for the client application 1866 for the implementation of appropriate treatment observation, according to the embodiment of the invention. Module, 1861 timer may also delete the expired records in slow motion" watch 1850.
[0279] of Course, the use of event streams relating to hours, you can use more than one agent DSA 1831. For some applications, can you wish to every application had its flows, supported by local agent DSA, for example, the case point of the HSAP 1814 located in Japan might want it to be the local agent the DSA already, and teeth the same watch, support remote agent (DSA is, for example, in the UK), according to the embodiment of the invention. In addition, you may want to divide the group of subscribers so that he was the agent of the DSA assigned to a particular group of subscribers. In such embodiment, the primary DS 1836 server effectively maintains a watch for calls relating to this user group.
[0280] as Well as discussion of the DSA agents, if any particular server DS 1836 loses connection or becomes otherwise unavailable, other servers in DS agent DSA can continue processing with a clock. Due to the fact that the clock mechanism can be fully trusted. Enable and reset the Clock to 1850 can be played automatically between multiple servers DS 1836 using two-phase locking mechanism (two-phase commit mechanism), according to the embodiment of the invention.
[0281] examples of the performance of the clock mechanism can be used for many distributed applications, where you cannot guarantee that external events come to a single local host. In addition, in accordance with what was said, record, Watch, 1851 may reside in multiple data stores, so that in the event of a failure of one particular data store, such as magazine stored
55P31384PL00
107
EP 2 156 649 B1 on server DS 1836a, accurate time can still be continued using the data warehouse, brought from another device, such as a directory stored on the DS server 1836b.
[0282] In the example embodiment of the invention components of the invention include software based on a collection of tasks written in the programming language "C". This software can be however written in many other programming languages. Tasks within the program communicate with each other using a combination of queues and shared memory. For example, the directory server 706a to communicate with other directory servers 706b and 706c to the agent DSA 702, as well as other directory servers in the remote DSA agents through a TCP/IP connection according to the example of the invention. components of the invention may also be based on a hardware platform and/or combinations of hardware and software.
[0283] Despite the fact that has been illustrated and described specific embodiments of the invention, it is understood that the invention is not limited to only these embodiments. For connoisseurs are visible numerous modifications, changes, variations, substitutions and equivalents, without deviation d of the scope of the invention described in the objection. In General, the following objections to the terms used should not be construed as limiting the invention to the specific embodiments disclosed in the description, but it should be understood that include all subsystems and methods, which operate under the following reservations. In this regard, the invention is ultimately to include modifications and changes as are within the attached objections and their analogues.
Apertio Limited
Power of attorney:
55P31384PL00
108
EP 2 156 649 B1
Contents134
13 members in 8 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 0706904 | United Kingdom | A | |
| 78358607 | United States of America | A | |
| 08735970 | European Patent Office (EPO) | A | |
| 2008054244 | European Patent Office (EPO) | W | |
| EP20080735970 | – | – | – |
| GB20070006904 | – | – | – |
| US20070783586 | – | – | – |
| WO2008EP54244 | – | – | – |
Members13
| Document | Office | Kind | |
|---|---|---|---|
| GB0706904D0 | United Kingdom | D0 | |
| CA2683402A1 | Canada | A1 | |
| US2008256083A1 | United States of America | A1 | |
| WO2008122642A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2008122642A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP2156649A2 | European Patent Office (EPO) | A2 | |
| CN101711475A | China | A | |
| ZA200906905B | South Africa | B | |
| EP2156649B1 | European Patent Office (EPO) | B1 | |
| PL2156649T3This record | Poland | T3 | |
| CN101711475B | China | B | |
| CA2683402C | Canada | C | |
| US9112873B2 | United States of America | B2 |
Numbers
- Publication, DOCDB
- 2156649
- Publication, EPODOC
- PL2156649T
- Application
- 735970
- Application, DOCDB
- 08735970
- Application, EPODOC
- PL20080735970T
Titles2
- English
- ALIAS HIDING IN NETWORK DATA REPOSITORIES
- Polish
- Ukrywanie aliasu w repozytoriach danych sieci
Classification
- IPC, 2
- H04L29 12
- G06F17 30