Method and system for carrying out transactions in network using network identifiers
Abstract
FIELD: physics; computer engineering. SUBSTANCE: invention relates to architecture for transactions through the internet. There is control of price and route for making payments with through processing of payments. In the proposed method payments are addressed without need for knowing bank account details of the receiver, which makes easier making payments and their clearing. The process of making payments is turned into a process of rendering communication services. Use of attribute certificates with a network identifier of the payer and corresponding identifiers of main clearing organisations prevents disclosure of confidential information by opening actual bank information to an unlimited circle of individuals. EFFECT: possibility of making transactions in which there is provision for conformity of a single telephone number of a subscriber to the position indicator of the subscriber, network identifier, as well as distribution of files of said numbers on a central communication switch and internet server. 6 cl, 24 dwg
Term
Term ended
Expired 23 October 2023, 2.9 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
6 claims: 1 independent, 5 dependent
- 1Способ проведения транзакций в сети, заключающийся в присвоении сетевого идентификатора, по меньшей мере, одному ресурсу сети, который является уникальным транзакционным идентификатором в использовании при адресации транзакций указанного идентификатора, при этом файлы телефонных номеров абонентов сети связи, включая телефонный номер центрального коммутатора, обеспечивающего услуги связи, размещают на центральном коммутаторе и в Файлах ресурсов на сервере Провайдера услуг проведения транзакций, обеспечивая взаимосвязь этих номеров с их сетевыми идентификаторами, проведение транзакций осуществляют посредством адресации сетевого вызова с использованием сетевого идентификатора ресурса, сетевой вызов для проведения транзакций осуществляют посредством транзакционной инструкции с сетевым идентификатором вызываемого ресурса, а при получении запроса на установление места сетевого ресурса, содержащего телефонный номер вызываемого ресурса, извлекают указанный сетевой идентификатор, взаимосвязанный с этим телефонным номером, и устанавливают связь, проводя транзакцию с указанным ресурсом сети.
- 2Способ по п.1, отличающийся тем, что нотация уникального транзакционного идентификатора ресурса сети содержит идентификаторы зон проведения транзакций и информацию об их иерархии, каждая из зон является сервером Провайдера услуг проведения транзакций для дочерних зон, а последняя в иерархии дочерняя зона, по умолчанию, является Провайдером услуг проведения транзакций для указанного ресурса сети.
- 3Способ по п.1 или 2, отличающийся тем, что в Файле ресурса размещают цифровой сертификат, содержащий, по меньшей мере, уникальный транзакционный идентификатор и открытый ключ ресурса сети.
- 4Способ по п.1, отличающийся тем, что для маршрутизации соединения из Файлов ресурсов сети извлекают уникальный транзакционный идентификатор вызывающего и вызываемого ресурсов, определяют идентификаторы и иерархию транзакционных зон для указанных ресурсов сети, определяют общую для вызывающего и вызываемого ресурсов зону, являющуюся Точкой Поворота Маршрута, в которой транзакция из восходящей в иерархии зон одного из ресурсов становится нисходящей в иерархии зон второго из ресурсов.
- 5Способ по п.1, отличающийся тем, что при выявлении нескольких Точек Поворота Маршрута через них прокладывают альтернативные маршруты с целью установления связи для проведения транзакции.
- 6Способ по п.1, отличающийся тем, что транзакционная инструкция является инструкцией выставления счета на оплату или инструкцией проведения платежа, или инструкцией трассировки, или инструкцией оценки продолжительности или стоимости проведения платежа.
Independent claims6
830 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
The present invention generally relates to data processing. More specifically, the present invention relates to a system and method of facilitating the exchange of information and communication between the various communication devices, using the phone number.
Description related technologies
US Patent №6151624 (hereinafter "patent b24") and author K.Teage other, which is included herein in its entirety, which is also regarded by the author as the closest prototype of the present application and describes a system and method that facilitate search and access to network resources such as a web page using their natural language names. In the case of Web pages, the system and method 624 patent link the natural language name (hereinafter, "name"), a so-called Uniform Resource Locator ("URL") in the metadata file that also contains additional descriptive information about the web page. After entering and confirming the natural language name in the line data entry web browser system and method for turning in the index database that contains metadata that allows you to find the appropriate URL, associated with the specified natural language name. The system and method patent 624 then sends the user to meet the demands of a Web page designated corresponding URL. Such a method frees the user from having to know the full URL of the desired web page to the user to get access to the web page.
Nevertheless, there are some flaws and limitations associated with the system and method described patent 624. As described in the patent 624, natural language names are not unique to any specific name, the user can correspond to more than one Web page, from which the user is forced to choose. Accordingly, the 624 patent provides additional data and network processing for resolving such conflicts.
Moreover, the names may be protected by copyright or trademark registration of the domain name, and therefore can not be permitted to use the Web site administrator who wants to call your own website so particular name, even if it is registered in the manner prescribed by law.
Moreover, the patent does not state 624 to communicate with other resources and communication methods, namely, e-mail, voice mail and PDA (personal digital assistant).
Therefore, those that did not suffice, and therefore was not available, are system and method that allows a user to use a unique descriptive information for the identification and implementation of access and interaction with Web sites or other network resources by using information that is unique and well known.
Encryption by public key enables secure communications using key pairs. Each key pair comprises public and private keys. The public key and private key are related so that data encrypted with one key pair can only be decrypted with another key of one pair, and identify the private key with the public key, it is practically impossible. The private key is typically created and kept secret the owner, while the public key is usually given to everyone. Secure communications between the parties may then be installed using a pair of keys belonging to the parties.
Using public key cryptography solves a lot of problems in open networks such as the Internet. Nevertheless remain two significant problems. First, the parties must have effective access to the public keys of others. Second, as in a variety of protocols the parties are identified with their public key is to be found a reliable way to test for these parties that the corresponding public key belongs to the person concerned.
The structure of the management of public keys (Public Key management Infrastructure-PKI) solves the two problems. In one approach, the PKI based on digital certificates that tie the public keys to appropriate individuals with a certain degree of integrity. PKI typically includes a database of digital certificates with the ability to conduct operations on them to handle such data and maintain the database. For example, processed requirements of the new digital certificate, revocation of existing certificates, checks the status of existing certificates.
Nearest prototypes and their differences
US Patent №6151624, issued RealNames, does not offer the possibility of linking between the networks of communications and the Internet; check on-line status; secure connection; Support communications standards 3rd generation, such as MMS / I-mode / FOMA and unified communications services and communications (unified communication and messaging).
US Patent №6324645, owned by VeriSign offers the use of digital certificates, but does not detail the use of certificates for device communications networks that are connected to the Internet; secure online shopping services and transactional services based on the verification of ETA and dynamic URL (Uniform Resource Locators).
US Patent №5793762, entitled "System and method for providing packet data and voice services to mobile subscribers", and US Patent №5457736, entitled "System and method for providing microcellular personal communications services (PCS) utilizing embedded switches". The main difference between these patents and the present invention is that besides the connection of the calls and a wired network, a mobile network, a mobile network, a wired network, a mobile network, a mobile network, the present invention also offers the possibility of browser-type compounds wired network brauzer- mobile network, the mobile network browser and a wired network browser, thus providing the possibility of the compounds (krosoperabelnost) not only between all of the mobile Internet, but also between mobile and wired networks and the Internet users, so that the user of any network or the Internet can make a call without having mobile subscribers.
US Patent №5732359, called "Mobile terminal apparatus and method having network inter-operability", offers krosoperabelnost between networks of mobile and satellite communications, but does not protect any krosoperabelnosti between the telephone network and the Internet.
US Patent №6353621, titled "Method to allow seamless service to mobile subscribers across various mobile switching centers supporting multiple intersystem standards", describes a method of telephone connections and krosoperabelnosti for mobile networks at the level of mounting a plurality of switches that support a variety of communication protocols (TCP / IP protocol for internet included). Nevertheless, said patent does not provide a connection for the exchange between the machine and the program or programs and hardware.
US Patent №5521962, entitled "Temporary storage of authentication information throughout a personal communication system", describes a method for managing authentication information for users of mobile networks, reducing the number of copies of this information posted in the infrastructure of a specific wireless network.
Known invention does not require the presence of a central repository of Internet Switch (Svicha) containing a database, the file number, providing krosoperabelnost between networks of mobile, wireless and Internet.
Limitations and disadvantages of the known systems and methods described herein may be removed and eliminated various embodiments of the present invention, in particular the proposed methods, systems and computer data streams, recording media business model, including among other things, the creation of the primary file rooms or SFI ( primary number file - PNF), containing a single telephone address of ETA, which has a telephone number belonging to a network resource.
One of the advantages of the invention is a method for creating a secondary file rooms or WPF (secondary number file), as well as the main file or Non-GFN (default number file), and WPF, and GFN are mirror copies of the ETT; GFN is placed on the central switch (a switch server) that provides a network connection device itself is a network resource, and WPF is placed on the server ISP.
Another particular offers the advantages of a method comprising the issue of a temporary digital certificate containing the ETA for the use of at least one, the subscriber - BA (Temporary Target - TT), the VA can act as a temporary subscriber recipient or initiator of calls in the network, while Digital Certification Administrator - ACS (preferably who is also a switch server) and the CA publishes ETA ETA (ETA digital certificate); places ETA and ETA at once in CA File number or sends them reseller (VAR); Reseller assigns ETA / CA specific time the Subscriber by posting them in the SFI of the Subscriber.
Another application of the invention is to encryption during the session exchange in which the subscribers use the shorter pair of keys for encryption acceleration video and audio in real time, each subscriber releases the short public and private keys; It places the private key in the internal protected memory of the Subscriber, and the private key is used only for one session; encrypts the new short public key using the original length of the private key or by using the public key of the long second party (second party in exchange); sends the encrypted message over the network to a second subscriber; second subscriber decrypts the received message containing the new short public key of the first party, and uses the resulting public key to encrypt the first subscriber and / or decryption of exchange with the first party.
The foregoing description of a lecture only some aspects of the most interesting applications of the invention. A detailed description of the various applications of the invention are described below, while the scope of the invention defined in the claims.
The aforementioned needs, and other needs and objects are realized by the present invention which, on the one hand, comprises a method for finding in a network (hereinafter, "localization") and establishing communication with network resources, using a telephone number and an identifier of places on the network and includes the steps of placing the first phone number in conjunction with the resource identifier in place of the network (the "Index places in the network" or the "Index") of that resource; receiving a request for the establishment of a network resource space containing the first telephone number; Removing the interconnected pointer to the first telephone number; and establishing communication with the resource using the resulting pointer.
One of the features of such a perspective involves placing at least a second telephone number for the same resource in conjunction with pointer; receiving a request for localization of a resource based on the first or second telephone number; extracting pointer interconnected with the first or second telephone number; and establishing communication with the resource using the resulting pointer. Another feature includes the steps of placing the first and second telephone number in conjunction with a pointer to the file number in the storage device interconnected with the resource.
Other features include steps to extract the file number containing the phone number and associated resources; Analysis of the file number; creating a record of the index, based on the values found in the file number; placing the index entries in the index, which is available separately from the storage device. And another feature includes the steps of transferring a file over the network to the client number associated with the resource; placing the file number on the storage device to the server associated with the client. Other features include periodic polling file number associated with the customer; checking for a match of one of the telephone numbers arranged in a third room containing a telephone number contained in the database index; updating the database index file numbers when changes are detected. Another feature is a step to synchronize the index database.
In accordance with another feature of the method includes the steps of receiving the client identifier, interconnected with the resource; generating a set of metadata describing the resource index and the client identifier; accommodation metadata set in persistent storage associated with the client. Another feature is the assignment of a randomly generated name of the metadata set. Another feature is instructing the client to place the metadata at the specified place in the persistent storage. Another feature is the registration of a set of metadata and randomly generated name in the database.
Previous is only a brief description of the various features of the invention. The invention determines many other aspects set forth in the claims.
BRIEF DESCRIPTION OF DRAWINGS
The present invention is illustrated as only examples and not as limitations of the application, the accompanying drawings, in which the numbers refer to similar elements including:
1 is a diagram of the file number.
1B is a diagram of embodiments of a system for navigation of network resources based on the metadata.
2A is a flowchart of the method for service registration in the system shown in Figure 1B.
2B is a flowchart for a method of enhancing the file numbers in the system shown in Figure 1B.
3 is a flowchart for a method of operation of the interrogation "spider" in the system shown in Figure 1B.
4 is a block diagram of a service index build in the system shown in Figure 1B.
5 is a flowchart for a method of operation in a system resolution services 1B.
6 is a flowchart for a method of operation of services
Search numbers in the system shown in Figure 1B.
7A is an example of the page statistical report generated by the system 1B.
7B is another example of the page statistical report generated by the system 1B.
8 is a block diagram of a computer system that may be used to implement the present invention.
9 is a simplified block diagram of the resolution and navigation systems.
Detailed description of embodiments
There mechanism described by linking a network resource with a phone number, as well as a location in the network and establish communication with network resources using the associated phone numbers. As used herein, for purposes of explanation, indicated some distinctive details to provide a thorough understanding of the invention. However, the experienced person will appreciate that the present invention may be practiced without these distinctive details. In other instances, well known constructions and devices are shown in the form of circuits or explained in another way, in a manner that avoids incoherence with respect to this invention.
File Format Rooms
In one embodiment of the present invention, the metadata linked with a network resource such as a Web page, a network computer, a Web-capable device, or other wireless communication device. In general, metadata is data that describes other data. Metadata which the present invention provide information that describes a Web page or other resource communication network in a manner similar to the manner in which the library card catalog describes a book. For example, the metadata includes information communication telephone number from a web page or other network resources, the description of the resource description language supported resource geographic allocation of resources, and other information related to the resource. Referring to the example given web page metadata determined by the administrator of the server containing the page, which is described in the metadata, and a copy of the metadata is available and is linked to the server so that the metadata is available via the Web. Using the program librarian, this copy of the metadata is recorded in the database of the connected, in turn, with the index. In this spirit, the web site can be called by the printing of the famous telephone number (it is placed in the metadata associated with the information) in the web browser. Then, the metadata information is used to enable telephone numbers to the addresses of websites associated with the telephone number in the metadata.
As stated, besides web pages metadata may associate other network resources to the telephone number. For example, metadata can be linked with a phone number means IM (instant messaging) user, the mobile telephone number (when the phone number, which is based on file metadata is the number of fixed phone) or even a means of Internet videoconferencing. In this spirit, telephone number and associated metadata can be used to detect the myriad of communications associated with the telephone number in addition to the web page.
While further description of various embodiments of the present invention generally relates to the resolution of resources such as a web page with a phone number, it is understood that the sophisticated technology people will be able to easily modify the proposed this concept to fulfill the resolution of other network resources by using a phone number as described below.
Preferably, the metadata is prepared and initially placed in the form of a file number 64, which is a text file with the grammar of the language Extensible Markup Language (XML). XML is a language detection, promoted of Microsoft® Corporation and Netscape® Communications Corporation. Further information about XML is provided in the document "XML: Principles, Tools, and Techniques," The World Wide Web Journal, vol.2, no.4 (Fall 1997) (Sebastopol, Calif .: O'Reilly & Assoc., Inc. ).
Previous respectfully text file number 64 is compatible with the formats Resource Definition Format ("RDF") and CC / PP (Composite Capabilities / Preference Profiles), RDF-based management information describing the device as well as with other initiatives XML descriptions VEB capable mobile devices and metadata. RDF is the syntax of XML, developed by a consortium of World Wide Web Consortium for expressing semantics. Text file metadata described herein also called file MLS. Example file MLS presented below in Figure 1A.
MLS file 900 is determined according to the grammar in which the elements are surrounded by accompanying tags. For example, "<resource>" and "</ resource>" tags are complementary. MLS file 900 has two main parts, namely the circuit section 902 and data section 904. The circuit section 902 and data section 904 are embedded in the accompanying tags ("<xml>, </ xml>"), which indicates that the file 900 utilizes MLS grammar of XML.
Section 902 scheme marked tags <schema> and </ schema>. Circuit section determines a circuit which is used to organize the data in the data section. On the example of Figure 1, the reference "href" in the circuit section refers to the file, "MLS-schema", posted on the Web server that contains the schema definition. Scheme named "MLS". Tags in the MLS file 900, which is part MLSschema, prefixed "MLS". Using this prefix, XML parser that reads the MLS file 900 may determine the tags, which are part of the MLS circuit.
The data section 904 is marked tags <xml: data> and </ xml: data>. The data section contains one or more MLS listings MLS 905. Each entry 905 is marked tags <assertions> and </ assertions>. Conceptually, each MLS entry 905 is a set of statements about the network resource that is specified in the tag <assertions>. In the example in Figure 1, one MLS entry 905 makes assertions about the network resource home.acme.com, which as an example is the home page of the Internet, a fictitious company Acme Corporation. Of course, in accordance with the present invention, the tag <assertions> can make assertions about a network resource, different from the web page. For example, the tag <assertions> User can define a nickname for instant messaging tools.
In further embodiments of the present invention, more than one type of resource may be associated with a phone number, and different resources may be available based on the availability of a particular resource. For example, a landline telephone number the user can be associated with the user nickname used for instant messaging, SMS-user ID with means for real-time video conferencing, such as for example Microsoft NetMeeting. File defines a list of the numbers of different resources hierarchical order, such as instant messaging, then video conferencing, and then the SMS is preferably updated depending on the availability of each resource in real time in accordance with known methods. Thus, when an attempt to make contact with the user, using his landline phone number, resource contributes to the establishment of such contact, as defined by the established hierarchy and the availability of a particular resource in real time for a variety of reported cases. Continuing with the above example, the connection is made through the medium of instant messaging, unless the user is available in real-time mode ("on-line" or "line") through its agent instant messaging, otherwise it will attempt to establish communication through videoconference. If the user is not available in the on-line via a videoconference, will attempt to establish communication via SMS. Other means of communication may also be offered, such as voice or video messages can be placed for subsequent delivery to the user.
The metadata file of the present invention provides a single addressing scheme based on the use of the telephone number. The metadata file in combination with a single addressing scheme makes it possible to establish communications between and among the various types of devices operating in different networks. In another example, the file metadata can be used to facilitate addressing between the posting on the Internet video conferencing system and a mobile phone equipped with video conferencing facilities, such as a mobile phone 3rd generation with the possibility of video conferencing. In this context, the establishment of communication can be initiated by the user of videoconferencing over the Internet by typing in the address bar of the Internet browser phone number that has been allowed to file metadata resource videophone.
Language RDF provides a general mechanism for describing many types of resources. RDF in nature does not provide tools for describing web pages. Accordingly, the file number 64 is expressed in the terminology of RDF, specific to a Web page that describes the main attributes of the web page. Attributes include a phone number associated with the Web page, and preferably also include a pointer or URL, description, language attribute, the attribute of the region and attribute the registry. Of course, a professional will appreciate the fact that the concept allows the use of other relevant attributes for resources that are not web pages.
Each MLS entry 905 has a set of metadata 906. In the case of the example of Figure 1, the metadata 906 contains a value that indicates the phone number associated with the resource. The value of the phone number "212-555-1234" is between the tags <telnumber> and <telnumber>. The metadata 906 also include a description value, the value of the language identifier and the identifier of the region. Couple tag identifies each entry. For example, Figure 1 is a description of the value of "Home Page of Acme Corporation," the value of the language - "English," and the value of the region is "Global." Value description provides a description of the network resource that is associated with a real phone number, which in this example may be the main corporate telephone corporation Acme Corporation. In accordance with the present invention may include the telephone number area code or country code, and may include digital or mixed alphabetic prefix or expansion, for example 1 -800-USA-RAIL, or any other type of characters that are commonly used with telephone numbers.
When multiple resources are defined in the MLS single file, preferably, for safety purposes, each network address, declared for the resource has been associated with the shortest network address contained in the MLS file each resource. In a preferred embodiment, each such network address must be a logical continuation or logical root network address in the file MLS, containing the smallest number of characters. For example, in the excerpt shown in Figure 1, relating to a Web page, all subsequent declaration of resources would be needed to identify the network addresses that describe the files placed in the directory tree, whose root is www.medialingua.com address. This relationship is tested using the Registration Services (Registration Service) 22 at the moment when he first created the file MLS.
Of course, as described above, can be described by MLS file any resource that is not a Web page, such as e-mail or "nickname" for the user instant messaging services ("buddy" identifier from an instant messaging buddy list).
Another key advantage of the described mechanism is that it can be used to provide access to network resources using mnozhetsvo telephone numbers. Create one or more files File number 64. 64 rooms contain many descriptions. Each description includes the phone number, interconnected with a certain one or more network resources associated with the field <telnumber>. However, each of the descriptions related to the same network resources associated with the tag <resource>.
For example, one or more files have 64 rooms descriptions which are contained the telephone number of the corporation Acme Corporation, such as the main number for the legal, marketing, technical department and sales department. Each description describes the same network share. Accordingly, these descriptions provide a plurality of telephone numbers, which indicate or be settled in the same network address. When certain third party wishes to obtain access to that described thus a network resource, such third party may use any of these telephone numbers of the network resource that is known for such third party. Resolver (Resolver) 40 would resolve a telephone number that is possible to find the network address of the network resource corresponding to the number, no matter what kind of phone number of this resource has been entered. Accordingly, the user can locate and access the network resource, using any of a variety of telephone numbers of the resource.
In an alternative embodiment, attributes and the attribute list highlighted tag <MLS: listings>. Attribute list is one or more key words or other values that describe other properties of the resource. For example, each resource has a property of the object, which indicates the general nature of the product, service or entity associated with the resource. It allows you to organize the database in a manner similar to that used directory "Yellow Pages". For example, the Acme Corporation Corporation has in its file number 64 line <MLS: listing> containing Anvils (anvil), Rockets (rocket), Slingshots (slingshot), which indicates that the corporation is a manufacturer of anvils, rockets and slingshots.
In an alternative embodiment, the resources described in the file numbers 64 are subjects rather than web pages. Resource type "subject" has metadata, including mailing address, email address and other personal information. In such an embodiment the system can be used as a search service entities and not for navigating web pages or other network resources.
For example, the resource search service entities may contain links to Web resources page where the user can send an e-mail the owner of the resource. Additionally or alternatively, the resource can contain links which allow for selection or send a SMS message, a pager, or otherwise pass the message owner resource. Moreover, ftp, or other links, or data associated with the owner of the resource can be placed on a web page. Thus, the telephone number in the <telnumber> File number 64 plays a role of "Personal Internet Addresses (Personal Internet Address)" or PIA (PIA), being a single personal identifier that can be used by others to connect, send and / or receive information a resource in many ways, namely call, send an e-mail, download, or "lose" files using ftp, exchange messages, participate in the chat, send the task assignment or a meeting, leave a voice message or a video message, or check on-line status of the owner PIA. Useful telephone numbers associated with the service of the search subjects increases when the phone number is also the number of fixed telephone and mobile, thus allowing to implement the service "one call (one call)" offered by different operators of the phone fixed and mobile communications, which allow you to automatically translate Up to a predefined mobile number if landline phone does not answer.
In case the resource has the means to send messages, the sender can be identified by extracting the data of the settings of his computer and the computer operating system. For example, when sending e-mail system can be provided to accompany him information identifying the sender retrieved from the settings of the operating system Window, located in the settings Start / Settings / Control Panel / Users / Properties. Thus, a resource that sent the message, the sender will receive an identifier, which can then be used to reply to the message sender.
In accordance with various designs of the present invention, the resources described in the file numbers 64 are wireless communication devices, web-adapted devices or other means of communication, different from the Web page or entities. For example, the resource-type "device" has metadata defining the device such as the size of its screen, the amount of memory, type of communication, postal address associated with the device, its e-mail request for replenishment, such as the requirement to replenish the paper in the network the printer, the printer detected that the paper runs out, and other information. In this embodiment, the system can be used to provide more services to find devices to determine their availability and becoming than to navigate Web pages or other network resources.
In another alternative embodiment File number 64 may contain other additional attributes. For example, other attributes include Organization (Organization), subject (Subject), abstract (Abstract), type (Type), Audience (Audience). Attribute Organization File number 64 may indicate the organization or company that owns or is associated with a network resource, such as, "Federated Stores Incorporated". The subject attribute File number 64 describes the network resource supplies to the domain, such as "dogs" (dogs). In Summary File attribute number 64 is located a short description of the network resource. The attribute type File number 64 contains information describing the type of network resources such as file "RealAudio file". The audience attribute File number 64 contains information about the intended audience of a network resource, such as "Women age 19-34" (women aged 19-34 years).
Defining the metadata for a network resource, linking the metadata with network resources and placing copies of metadata on the server that contains the network resource, implementation of the proposed manner provides significant advantages. For example, metadata support convenient. Since a copy of the metadata is available locally on the server that contains the network resource, the metadata can be updated at any time without having to contact the main service. As described below, the mechanism bypassing the metadata (metadata crawler mechanism) periodic visits to a server in order to monitor changes in the metadata. If the file number 64 changed after the changes are automatically propagated to the database and index.
In addition, the combined file number 64 operates as a distributed database metadata. Support distributed database scaling increases as modification of metadata is not dependent on the availability of a single central database. Further, placing the metadata files linked to the device server that hosts the network share itself, improves data integrity. Only a user who has received the authorization to place the files on the server can create relationships between metadata and corresponding reference network resources on that server.
Of course, one skilled in the technology properly appreciate the fact that metadata may alternatively or additionally be placed in a central database. The central database can be periodically updated various relevant network server that contains the resources or resource information, or can be manually updated central administrator.
Another advantage is the multilingual compatibility. XML is the standard symbol table supports UNICODE. As a result, the attributes placed in the file number 64, can be expressed in any natural national language.
System Phone Number
Using metadata stored in the file number 64, in combination with the detection of network resources, the network resource attributes can be used to detect and connect to a network resource. For example, as described above, the attribute of "telephone number" File number 64 can be used to detect a web page. 1B is a block diagram of the execution of network discovery, which consists of Registry (Registry) 10, Librarian (Librarian) 20 Index (Index) of 30 and a resolver (Resolver) 40. Sophisticated technology specialist will assess the fact that the variation of execution provided by the detection system allows network resources to implement the system resources different from the Web page.
It is understood that as illustrated above and hereafter, the term "network address" generally means the unequivocal identifier of the location of the resource on the network, one example of a network address URL.
Registry database 10 comprises 12 in the form of a commercial system database such as SQL Server or another database. Registry 10 provides a centralized repository for linking telephone numbers to network addresses or URL, and the attribute information associated with the telephone numbers. By definition, each telephone number is unique throughout the Internet or other communication network and therefore is unique within the Registry 10. Registry 10 functions as a centralized, highly productive, scalable, continuously running store all metadata. The Registry 10 also includes statistics related to the use of metadata in the context of the various services that are built on top of the Registry, such as a car navigation system GO, described herein.
Telephone numbers, network addresses, and descriptive information are loaded into the Registry 10c via Librarian 20. In the preferred embodiment, Librarian Index 20 and 30 are exchanged with the database 12 using interface ODBC. In a preferred embodiment, database 12 has a capacity of the order of several hundred million records. Registry database 10 and 12 help to ensure the appropriate structure and vocabulary for the Web sites or other resources used.
Librarian 20 has service registration (Registration Service) 22 and Spider (Crawler) 24, each of which is connected to a database 12 and a network such as the Internet 50 or other network communications. Registration Service received 22 new links phone numbers to network addresses, as well as descriptive information and downloads ("logs") in their Registry 10. Registration Service 22 receives a communication from the client 70 via the Internet 50. Crawler 24 is moved over the Internet 50 (touches the Internet) periodically communicating with registered resources, which are connected to the Internet, to detect changes in links located or associated with such web servers.
The system of telephone numbers is reacted with one or more web servers or other resources, which are connected to the Internet 50. As an example, a web server 60 is shown in Figure 1B, but any number of Web servers can be used in this embodiment. The local database 62 is connected to the web server 60 so that the web server can retrieve values from the local database for use in a Web application running on a web server.
File number 64 is placed in connection with the Web server 60 so that the web server can retrieve the file number and send the content to the Internet 50 in response to requests. In the preferred embodiment, the file number 64 places the description of one or more phone numbers. Each description includes the phone number phone number resource Web server 60, resource description, network address, or other identifier of the resource space on the network, as well as other information about the resource, such as the language used by them and intended use of the geographic region. Preferably, the file number 64 also accommodates a grammar identifier, which is used to format the other information in the file room. Thus, the information in the file room is self-sufficient in terms of description and language independent.
As indicated by path 29, Crawler 24 can communicate with the Web server to retrieve the values of 60 and placed in the file number 64, using a connection through the Internet 50. As indicated in the path 28, Crawler 24 may notify the Index 30 that the index files should be 34 updated to reflect changes in the information contained in File Number File 64 rooms.
Index 30 is connected with the Register 10. Index 30 includes builder index Index Builder 32, and one or more of the index files 34 Index Files that contain an index of all the phone numbers, records of phone numbers and resources known to the system. For example, the index file Index Files 34 are index entries for the values placed in the file number 64. Index Files 34 is built, administered and updated builder index Index Builder 32.
In general, in a preferred embodiment, the files Index Files 34 are more compact than the index, supported by conventional search engines, since the amount of information provided in all the files of 64 rooms is significantly lower content of all network resources available on the Internet. This compact size is an advantage, providing greater scalability and sensitivity than conventional search engines. In addition, the compact size of the files index Index Files 34 30 allows the Index to be replicated in a number of different geographic locations.
Resolver (Resolver) 40 includes one or more processes permit (resolver processes) R1, R2, Rn, each of which is associated respectively with the service (Service) 42, 44, 46. Each resolver process R1, R2, Rn binds to its corresponding service 42, 44, 46 for queries containing the telephone number, converting or permit the telephone number in the network address associated with the phone number and send addresses and other information associated with the telephone number, the requested service.
Client 70 is connected to the Internet 50. The client is a computer, a server, a web-capable device or wireless communication device, or a network in which the program is executed web browser 74 operating system 72. An example of a Web browser 74 is Netscape Communicator. (3TM)., As an example of the operating system 72 is Microsoft Windows 95. (3TM). Services of telephone numbers available to the client 70 via the internet 50 using a browser 74 according to standard protocols of telecommunications or the Internet / Web.
For example, under control of the browser 74 and the client 72 operating system 70 may establish an HTTP connection with the Service Registration 22 via the Internet 50. The browser 74 extracts pages or forms of Registration Service 22, which are prepared in a format of markup language HTML. The browser 74 displays the page or form. The user of the client 70 reads a page or enter information into the form and sends the completed forms back to the Registration Service 22. In this case, the client 70 and 22 perform Registration Service dialog that the user of the client 70 can perform the functions offered by the system.
Preferably, the Registration Service 22, spider 24, the Index Builder 32, and Resolver 40 are one or more computer programs with functions and procedures described herein. In one embodiment, each registration services 22, spider 24, the index builder Resolver 32 and 40 is an independent process, one or more instructions each of these processes can be activated and executed at every predetermined time. In a preferred embodiment, the computer programs developed using object-oriented programming language and programming language such as Java.
Service Registration (Registration Service) 22 Spider (Crawler) 24 Builder Index (Index Builder) 32 and the Resolver (Resolver) 40 is preferably performed in one or more components sservernyh computers that can quickly access, manage and update the database 12 and index files 34. These elements may be distributed or separated. For example, it provided that the Resolver 40 and its processes Rl, R2, Rn are performed on a single server computer, and Service Registry 22, spider 24, and Builder Index 32 operate on the same computer or on a cluster of computers that are separate from the server that hosts the Resolver 40 . In this configuration, the Resolver 40 can quickly receive and respond to customer requests for access to network resources that are located in the index index file (Index Files) 34, without interfering with or affecting the operation of other elements and their functions.
In one embodiment, the Librarian (Librarian) 20, and other system functions may be available to the client 70 by establishing a connection with one or more administrative Web pages (Web pages) 80 which provide functions using an HTTP connection. Administrative Web pages (Web pages) 80 placed on the web server and generated by the program that is installed on the server, which can communicate with other elements of the system. This program sends the page to the top-level client 70. The browser 74 of the client displays the top-level page, which is a menu of options for working with the system. For example, the preferred option menu shown in Table 1.
TABLE 1 OPTIONS top-level menu FILE MLS Create (Create) Activate (Activate) Modify (Modify) Delete (Delete) STATISTICS AND PAYMENT OF ACCOUNTS Statistics (Stats) Payment of invoices (Billing) CUSTOMER New Customer (New Customer) Edit profile (Modify Profile) Change contacts (Change Contacts) Exit (Logout)
Each of the top-level menu options can be selected by moving the cursor, which is generated by the client 70, the name of the required menu option using the input device and "click" them on the option selected. Functions executed when selecting each of the menu options are presented below in terms of the functioning of the module executing this function.
In the foregoing discussion of the elements of the system have been described in relation to the Internet 50 as a connecting element. However, the Internet is just one example of a coupling element, which can be used for establishing communication between system elements. Other elements, such as a local area network, regional network, other wired or wireless networks, Intranets and Extranets, may also be used. At the same time, the protocol relating to the Internet, such as the Transmission Control Protocol and Internet Protocol, also not mandatory, other protocols may be used instead.
In such a configuration, the system has advantages over other approaches. For example, the web sites of the customer 60 are isolated from the database 12. The files of the index 34 are separated from the database 12 and the index files are only available Resolver (Resolver) 40. This reduces database load and increases the ability to respond, and provides scaling. This architecture corresponds well to the concept of a distributed file replication index.
Features Customer Profile
In one embodiment, the system provides the customer information management functions that allow you to post, track, update customer information in the system. The information managed for each client, called Customer Profile. Customer profiles stored in the database 12.
When the option Customer / new customer, the system generates one or more Web pages that contain forms that allow the user to enter a new profile. The form has a field to record the name, address, telephone number, contact person, and the method of payment, such Web pages and forms are sent to the client 70, and shown in the browser. User client 70 enters the appropriate information in the field of records and "clicks" on the "Accept" button, located on the Web page. In response, the client system 70 returns the completed form by HTTP. The system extracts the information entered from the fields and places it in the database table 12.
In a preferred embodiment, the process of registering the Customer / New Customer initiated using a Web page generated by the system in the form shown in Table 2.
TABLE 2GLAVNAYA registration page Welcome to the site of the registration phone number. Before you submit for the consideration of your phone number, you should provide us with some information about you and the organization you can think of. To initiate the registration process, you first need to enter your email address as your name (login name), and choose a password. You also need to remember that the username and password as system phone number is used by them to provide you with access privileges. Username Password [BACK] [NEXT]
Table 2 notation [BACK] and [NEXT] means the function buttons. The user enters the user's email address in the Name field, and the user's favorite password in the Password field. When a user (clicks) NEXT softkey name and password stored in the database 12 in association with each other.
Preferably, the system then displays a Web page that contains a form that allows the system to obtain further information about the user. The form may have fields for a username, address, city, state, zip code, state, and phone number, ID or nickname from the list of instant messaging, e-mail, mobile operator or wired communications, equipment type and model number. The user enters the required information and presses the button NEXT. Alternatively, or in addition, certain information may be retrieved from information already available on the user's computer, such as setting the preferred language or country and area code contained in the Web browser of the user or in Windows® user. The system checks each entry to ensure that the format of the value meets the requirements for each of the fields. The values stored in the database 12 in association with a user name and email address. All together, this information is the profile of the customer. When the customer profile is created, the user can create a record such as "phone number" and place them in one or more files 64 rooms.
Selecting menu Customers / Edit Profile causes the system to generate a Web page containing a form that allows the user to change a previously created user profile. To protect the IP address of the user operation is extracted from the HTTP exchanges, during which the user has used the option Customer / edit profile. The user is allowed to view and change only the profile that matches the previously creates files that are hosted on a server that has the same IP address as the user. Based on the IP address of the user, the system scans the corresponding profile in the database 12 and extracts the content of the profile. The content of the profile is shown in the web-village.
The user can then move the cursor, generated by the client 70 to any other value shown on the web page, and modify the values. When the user selects or clicks "Accept" filled with the values contained in the web page is transmitted to the system over HTTP. The system updates a database 12 using these values.
Selecting a menu option CUSTOMER / Change contacts allows the user to change the contact for payment associated with the registered file number. Selecting Customers / out allows the user to complete the current session, or log in under a different name of the customer. These functions are provided in the Web program that receives and loads the appropriate values in the register (Registry).
Service Registration
2A shows a diagram of a preferred method of execution of the operation of the Service Registry (Registration Service) 22 Librarian (Librarian) 20.
Preferably, Registration Service 22 has a web interface, through which one or more clients 70 may use the functions offered by the Service Registry by selecting the function buttons placed on the web page to activate the function.
The primary function of the Service Registry is 22, the registration of new telephone numbers in the Register 10. In one embodiment, the registration service 22 caused by the use of options on the page Create a top-level menu. As shown in Scheme 200, the external user or "client" of the system identifies itself to the system so that the information entered later may be associated with the customer. This information includes customer e-mail, which can be sent to the customer registration service posts 22 through the Internet 50. In this context, the terms "client" and "user" refers to the operator of a computer to remotely connect to the system, for example, to the client 70.
As indicated in Figure 202, then provides the customer information registration service 22, which identifies the network resource web server 60 for its location, phone number, descriptive information about a network share. For example, a customer enters a phone number "212 555 3000" (it is the default number of the name XYZ Sorr), http://www.xyzcorp.com in the URL, and description of the resource. Preferably, this information is entered into the fields of the web page that is designed for receiving such information in the form shown in Table 3.
TABLE 3 pages of telephone recording Telephone number: 212-555-3000 URL: http://www.xyzcorp.com. Type: Language: English Region: North America Description: This is the home page of the manufacturer devices, XYZ Corp. [BACK] [NEXT]
When the user has entered all the information to continue processing the file number 64, the user presses a function key NEXT, placed at the bottom of the page.
In response, in step 203, the system initiates a review of the service, which is available at the price described resolution service. For example, it can be set to hold at a fixed price based on the expected number of transitions per month for a specific resource. Expected number of permits for any specific site can be based on the available history of this site is still active. For example, MSN provides services to document the number of conversions per month on various Web sites. Referring to the database, the system can determine how many transitions are expected on the Web site to identify the user and the system will set an appropriate price for the user to pay in advance or upon execution.
In step 203A, the user is informed about the payment for services rendered and it permits or denies payment, and exits the program, or accept the terms of payment and proceeds to step 204.
In step 204, registration service 22 64 Non-creates the file based on the information entered by the customer. Thus, the file number 64 is located on a server accessible to the registration service 22. However. File number 64 is not placed in connection with the Web server 60.
At block 205, registration service 22 randomly generates a filename for the file number 64. A random file name is used to prevent unauthorized access to the programs, processes, or users to identify or change the file number 64 when it is placed in association with the Web server 60. If you have used the same name on any web server registered by the Register 10, an authorized user can modify a record made in the File Room 64, referring to another network resource. As a result, as will be shown below, the spider 24 would detect the change and posted a phone number in the Register 10. Accordingly, it is desirable to hide the name of the file number 64 from unauthorized users.
In block 206, the file number 64 is sent to the customer as a file attachment to an email. Object 206 comprises a step of receiving emails from the user. In the preferred embodiment, the system displays a Web page having a field to enter an e-mail, in the form shown in Table 4.
TABLE 4 Page Entries EMAIL Enter your email address where we can send you the file is a phone number that you just created. joe @ xyzcorp. corn [BACK] [NEXT]
After sending the file to the user rooms 64 email system displays a confirmation page on the client 70. In a preferred embodiment, the confirmation page has the shape shown in Table 5.
TABLE 5 CONFIRMATION PAGE file your phone number has been sent to the address joe@xyzcorp.com. Now you should save the file on your web site in accordance with the instructions in the message you receive. After the execution of this step, the file must be activated through the service activation File phone number. (Just follow the previous link or contact customer support, contact the item Activation of category file MLS.). [END]
In step 208, the customer sets the file number 64 on the Web server 60 or in a manner accessible to the web server. Preferably, the file number 64 is placed in a location on the web server 60, which is described registration service 22. For example, the email message describes what file number 64 must be installed in the root directory of the network share, which is named in the file number 64. This is done, to ensure that the customer receives is authentic; Registration Service 22 suggests that the only authentic representative of the customer can have access to the root directory of the web server, which is called the network share. The root directory is also indicated for the convenience of the customer. When the file number 64 is located in the root directory of the web server, the customer can change or reorganize the web server without affecting the file number. Conversely, if the file number 64 would be placed in a subordinate directory of the Web server, then he could be a risk of tripping File number if you accidentally delete the directory in which the file is kept.
In block 210, the customer confirms the registration service 22 that the file number 64 was placed by the customer in the described location. Confirmation of the Customer may be granted in the form of a message email, directed to the service desk 22, or by introducing the appropriate command from the Web interface of the Service Registry 22.
Then, the user is required to activate file number. Activation is the process of verifying that the file number is placed in the right place and the authorized user. Optionally, the activation process may also include payment for the privilege of holding for the file number to be registered and recognized by the system. One embodiment of the method of activation is shown in Figure 2B.
In a preferred embodiment, the user activates the file number upon its creation by selecting menu FILE MLS / Activation from the options menu of the upper level. In response, as shown in 212, the system creates a page in which the user is asked to enter the activation type, and sends the page to the client, which displays it. For example, the system shows the page of the form shown in Table 6.
TABLE 6 Type page ACTIVATION Please select a service: (*) Live update previously recorded files rooms. (*) Date of the new file number on your web site. [BACK] [NEXT]
Preferably the characters you see in the form of "(*)" in Table 6 above shows the display as "radio buttons", or other graphic elements that can be done by choice. When the user selects the first option ("Live update previously recorded files Numbers"), as shown in the 214-216, the system activates the Spider (Crawler), which finds the file number of the user on the Internet, updates the database 12, as described below. Thus, the "Live Update" allows the user to force the system to find changed files and update the rooms with new information. Alternatively, as described below in connection with Spider (Crawler), the user can simply wait and Spider (Crawler) eventually find the modified file, and update the database.
When the user selects the second option ("Registering new file number on your web site"), as shown in 220-222, in response, the system generates and sends to the client 70 Web page from which the user can enter billing information related to the user and its file number in accordance with the counted amount and the actions taken in steps 203 and 203A. Steps payment process activation are entirely optional part of the process, and other embodiments do not imply any mechanism of payment, including those relating to steps 203 and 203A. In the embodiments that use payment mechanisms, the web page contains fields for entering information relating to the payment. For example, a field recording the credit card type, card number, expiry date of the card and the cardholder's name. The system receives the values of the fields on the payment information in the block 224.
In block 226 the system prompts the user to enter the network address of the file number to activate it, and a description of the file number.
In block 228 registration service 22 creates an HTTP connection with the web server 60, requests a copy of the file and loads Rooms 64. This step is performed in order to verify that the file is valid for 64 rooms and is located in the right place. In block 230 File number 64 is analyzed and extracted from it the values that identify the network share. In block 232, the system creates a web page that reflects the values identified in the analysis of the current file number 64, and sends the page to the client 70. On the Web page, the system displays the following message:
"The file number that we have downloaded from your site contains the following entries. Please check these records. Click NEXT to continue.
[BACK] [NEXT] "
As shown in block 234, the user is viewing records, checking their accuracy, and click on the NEXT button. If some of the values are not correct, the user presses the back, which activates Sorry described herein.
In a preferred embodiment, the system then displays a Web page that contains a written legal agreement, providing for the payment of the registration fee, as well as the resolution of disputes, including legal, as shown in blocks 236-238. Agreement "signed" by pressing the "accept" or "reject." To accept the agreement and proceed, the user presses the button to accept. To reject the terms of the agreement and the termination of the registration process, the user clicks rejected. Using a legal agreement is completely optional, and the execution of which does not use such an agreement is also seen here and is the subject of the present invention.
The system then places the values extracted from the analysis file number 64 in the database 12 of the Register 10, as shown in block 240.
For security purposes, the network address or URL File number 64 should match the root directory of the web server 60. This prevents redirection to unauthorized phone numbers other network addresses. It also prevents the owners of the web server 60 of the redirection to the web server of any other phone numbers that the owner of the server is not.
In block 242 registration service 22 notifies the Index Builder 32, which created a new record in the database 12. The route 26 1B is such notification. The notification shall include information sufficient to identify a new record in the database 12, for example, the identifier string ("rowid") table, which posted a new record. In response, the Index Builder 32 performs a live update of the index file 34, as explained below.
Thus, the file number 64, created by the user is activated and becomes available for use by the resolver 40.
In a preferred embodiment, database 12 may receive requests from registered members of the system. As a result, the registered member can submit requests to the database 12, which drives the database show the current registered information about network resources or Web pages, or other structures. Accordingly, if another registered user is able to register the information that misrepresents the contents of the user network resource, the distortion can be detected and reported it to the Register for corrective actions. Thus, the registration procedure and open an opportunity to query the database 12 allows the system in question to avoid scams is possible with the unintended use of meta tags.
Changing or deleting the file information Rooms
After creating the file number, having one or more entries, the records can be edited or deleted using the File functions MLS / Change and files MLS / Remove shown in the list of top-level menu.
When the user selects the file functions MLS / Change, the system reads the MLS file from the server associated with the user, and displays the contents of the file on a web page, in the form shown in Table 7.
TABLE 7 FORM "FILE MLS / Edit Page" Current list of entries MLS, contained in your file MLS, below. To edit an entry, select the appropriate word and click Edit. To delete an entry, select the appropriate word and click Remove. To add a new MLS listings, click ADD. Click NEXT when finished editing the file MLS. [Back] [EDIT] [DELETE] [add] [next] Telephone Number: 212-555-3000 URL: http://www.xyzcorp.com Type: Language: English Region: North America Description: Home Appliances manufacturer , XYZ Corp. Joined: Phone Number: 212-555-1234 URL: http://www.acme.com Type: Language: English Region: Global Description: Home Acme Corp Joined:
The page consists of sections of text instructions, set function keys and editing the list of entries, now found in file rooms. Text instructions explain the functions executable function buttons. In a preferred embodiment, the function buttons on a page are all records the file number and not on a field basis. For example, to edit an entry the user selects the appropriate phone number, such as "212-555-1235" and click the Edit button. In response, the system displays the edit page of the record, which contains the selected entry. The user can enter the modified text in the field recording to editing page.
Similarly, to delete a record, the user selects the appropriate word and click the Remove button. In response, the system creates a new file number, which contains all previous records, except for the recording you want to delete.
To add a new record to show the file number, the user clicks on the Add button. In response, the system displays the page in the form of Table 3, discussed above in connection with the creation of a new file number.
To activate the changes made by the operations to edit, delete and add the user presses the button NEXT. Pressing NEXT forces the system to create a new file number, preferably in the above format XML. The system sends an email the new file number of the user in the appropriate explanatory message. For security purposes, the user is required to place a new file in a directory Non-prescribed system, as in the case of creating a new file.
Spider (Crawler)
The graph 3 shows the flowchart of the method is preferably used Spider 24. In the preferred embodiment, the system includes a process planner which initiates activation and operation spider 24. For example, the scheduler allocates event schedule. Event states that Spider 24 must be performed every twenty four hours. After the scheduled event scheduler launches Spider 24.
In block 302, Spider 24 reads the database 12 from the register 10, and retrieves one or more rows or records that identify network resources, zaindeksirovannye in the index file 34. A method for selecting rows or records is not critical and therefore can be used several different schemes. For example, the spider 24 can select all the rows or records that have not been updated since the last time the inclusion of the Spider. Or Spider 24 can select all the rows or records that have been created for a certain period of time or who are older than a certain number of days. Or Spider 24 selects a list of recently updated records. In a preferred embodiment, the system also establishes the link between numbers and file names MLS and placements, called a table of information about the files (File Info table). Spider compares the selected rows to Table information about files and sets the network address, or URL location of the file number associated with each phone number, string, or recording.
For each of the selected rows or records in the block 304 Spider 24 polls Web site of the customer, which is represented by a row or record of trying to find updates to the file number 64, which is arranged in connection with the Web site. The survey includes the steps to open an HTTP connection with the web site, request and receive a copy of the file number. Spider 24 analyzes the file number using XML parser to find record of the telephone number, as well as the values within each record telephone number that contains a phone number, network address, as well as descriptive information about the network share. XML parser exists and can be purchased from the Corporation Microsoft® Corporation.
For each record in the file room, as shown in block 306, the spider 24 checks whether a record with a string or record in the database 12. Thus Spider 24 determines whether the content is different from the file number of records in the database 12. If so as shown in block 308, the spider 24 updates a database 12, and requests the builder of the index (Index Builder) to rebuild the index entry related to the updated row or record in the database 12.
In this way the spider 24 polls the Web sites on the Internet 50, to detect sites of customers undergoing renewal. Since the rooms are scattered files on the network by a large number of customer sites, each customer is free to change its file room at any time. The customer does not have to tell the system about this phone number as Spider 24 eventually finds every change and update the database 12, respectively. Thus, the Librarian 20 automatically monitors changes to the file number allocated to the network and periodically updates the register 10 in response to changes. Advantageously, the customers and end users involved in the process of updating the database 12.
Spider 24 updates the database automatically.
In a preferred embodiment, the customer may instruct the Librarian immediately execute the program 20 24 Spider on a particular Web site. In this case, a specific file number changes instantly detected and loaded into the database. The customer activates the instant execution Spider 24 by selecting the Live Updates from the top menu. In a preferred embodiment, the system also carries out, once a week, a full update of the index file 34 based on the contents of the database 12. In this way, at least on a weekly basis, the index file 34 are rebuilt based on the current contents of the database 12.
In an alternative embodiment Spider 24 also confirms the validity of each location of network resources that are identified by each of the file number. For example, 24 spider trying to connect to and download each resource that is identified in the file record numbers. If an error occurs, a corresponding Email-message is sent to the contact person and organization that has registered the file number. This message informs the contact person in the file number wrong location specified network resource.
Builder Index (Index Builder)
The index contains 30 Index Builder 32, and the index file 34 32 Index Builder is a program or process that operates in two modes. In the first mode process Reconstructive Index Builder 32 periodically interrogates the database 12, detects changes in the database and index the changed records of phone numbers in the index file 34. In the second mode, the Index Builder 32 updates the index file 34 in real-time, turn fulfilling instructions index update. 4 is a block diagram of a preferred embodiment Builder Index 32. Computer certain GO Machines 100, 102, 104, each executable program Builder Index 32. Each of the machines GO Machine 100, 102, 104 associated with the processes of the network interface M1, M2, Mn Agent queues (Queue Agent) 92a. Agent queues 92a is connected to a network 106, such as a local area network and receives requests to build the index entries from the Librarian 20. Agent queues 92a distributes each request a copy of one of the network interfaces M1, M2, Mn, which, in turn, transmits a request associated GO car with him 100, 102, or 104. This architecture responds well to external requests, and is resistant to errors.
Within each GO machine. Index Builder 32 is connected with a pair of queues 90a, 90b and a pair of indices 34a, 34b. Hour GO 42 can have access to any of the indexes 34a, 34b, but at any given time is associated with only one of them. Resolver 40 is absent in Figure 4 for purity, but it should be understood that the service GO 42 accesses each index 34a, 34b by means of the resolver 40.
For the GO Service 42 important to maintain constant contact with one or another index. Accordingly, using the architecture shown in Figure 4, the index builder builds using the following codes protsess.Sluzhba GO 34b associated with an index and has instructions to send requests for permission to telephone numbers only index 34b. As soon as the request for the construction of the index comes from the queues 92a Agent Builder Index 32 32 Index Builder adds requests to both queues 90a and 90b. When one of the queues becomes sufficiently full, for example turn 90a, the Index Builder 32 sequentially removes records from a queue in the order of "first-in-first-came out" (FIFO), and updates Ying index 34a records of each queue. At the same time, if you received are any new requirements to build an index, they are sent to both the queue. When the queue was empty 90a and 34a of the index is completely updated, the Index Builder 32 instructs the GO Service 42 pass the requirement to allow a telephone number only index 34a. Index Builder 32 then deletes the records from the queue only 90b and 34b only updates the index from the queue. Thus, the index builder 32 may add index entries to one of the queues 90a, 90b, but always only one index is updated per unit time, using the contents of only one queue at a time. The queue to which the Index Builder 32 communicates is always the opposite, or complementary to the index 34a, 34b, with which the GO Service 42 is related to the current time. Therefore GO service 42 maintains constant contact with the index, and the index builder 32 may update the index in real time, without interrupting the process of resolving the telephone number.
Preferably, the requests include the construction of an identifier called "Fileld", the file or the terms, which is linked to a table of information, or TIF File (File Info table), above. Builder 32 Index ETF seeks to FileID and extracts all database records, data coincide with FileID. Each database entry includes a unique identifier, which is described in the database record. These unique identifiers are generated using a sequence generator database server. Using a unique ID database entry that matches FileID, Builder Index retrieves coincident index entry. Recording index information is compared with information contained in the request for the construction. If the information in the request to build different, record index is updated. If the information in the request for construction shows that the associated network resource is no longer active or available on the network, the index entry is removed.
To ensure the scalability, reliability and fast response of each GO machines 100, 102, 104 has a similar configuration and operates in parallel with the others. Although in Figure 4 is for illustration only three GO 100.102 machine 104, the system may use any number of machines. In the preferred embodiment, the scheduler determines when to begin the performance of the Index Builder 32.
Resolver (Resolver)
In general Resolver 40 functions as an interface to query the metadata stored in the Register 10. Resolver 40 operates, get a phone number as the requests from the service 42, 44, 46, 30 requests the index to determine network addresses corresponding to predetermined telephone address, and responds services passing Point network addresses. Resolver 40 is structured to respond quickly to the search operation and serve millions of requests per day. To minimize response time and ensure scalability, responding to requests Resolver 40 has no direct access to the database Register 12 10. Instead Resolver communicates with the index of 34, which is located in the fast main memory.
In the preferred embodiment Resolver 40 operates on any number of a plurality of processes R1, R2, Rn, each of which is associated with the service 42, 44, 46, which generates requests to resolvers. Services 42, 44, 46 communicate with the processes of R1, R2, Rn resolver using the compound HTTP. It is also preferred that the computer running the program resolver 40, had a triple-redundant configuration. This configuration provides a rapid response to requests for services 42, 44, 46, and ensures reliability. Each of the processes, R1, R2, Rn is executed in a web application that takes the Resolver. Services 42, 44, 46 communicate with the processes of R1, R2, Rn resolver using an HTTP connection.
In one embodiment, the process of the resolver 40 is designed as a dynamic library links (dynamically linked library, or DLL), which is integrated into the services 42, 44, 46. In the preferred embodiment, each of the processes 40 Resolver is a separate process or program that operates in accordance with The method shown in Figure 5. Resolver 40 filled with one or more API (application interface creating application programming interface), which allows to develop services that use the Resolver, such as "Yellow Pages" and search services.
As shown in blocks 502-504, the outer web client, server or browser, such as client 70 accesses the resolver 40. In one embodiment, the client 70 establishes a connection to the resolver 40 by using an HTTP connection. In block 502, the client 70 creates an HTTP connection to the resolver 40. In block 504, the client 70 provides Resolver URL, requesting thereby return the network address corresponding to a particular telephone number. For example, URL is in the form http://www.resolver.com/resolve? tn = TELRPHONE NUMBER. In such a form of a URL string "http: //" specifies the URL as an HTTP request, "www.resolver.com" is the domain server, a "resolve" is the name of the program executed on the server of the specified domain, which actually is a resolver. The expression "tn = TELEPHONE NUMBER" sends the value "TELEPHONE NUMBER" parameter "mm", which is recognized by the resolver. In cases where the phone number is posted along with the city and the country code, the browser client is preferably programmed to add country and city codes to the telephone number, which is entered by the user without one or both codes. Such information may be obtained from a secondary operating system settings Window user.
In another embodiment, the client 70 establishes a connection with one of the services 42, 44, 46 associated with the processes of the resolver 40. Services 42, 44, 46, 70 communicate with the client by requesting and receiving a phone number.
For example, in one case, the Resolver 40 receives the telephone number requested by the client 70. In response, the Resolver 40 to build object-specifier (Qualifier object) in the main memory, which contains the phone number. In block 506, Resolver communicates with the index 30 and makes a request to grant him a network address, or URL, which corresponds to the telephone number to the client's request 70. In a preferred embodiment is carried out by sending a request accommodation facilities Index (Index Store object) message containing Object- specifier. Accommodation Index summarizes and provides a brief explanation of the Index 30. Accommodation index queries the index.
In block 508 Resolver 40 receives a response from the Index 30 that contains the network address, or URL, which corresponds to the telephone number to the client's request 70. In the preferred embodiment Accommodation index returns a set of object records (Entry Set object) resolver 40. The object contains a set of records, or mentions a set of one or more entries from the index 30, which correspond to the requested phone number. Preferably recordset object formed so as to provide a location or URL of the network resource that is described in the object entry.
Using Object recording lets you set the system to operate when only part of a phone number. This is particularly useful when the user knows the proposed system only a part of the telephone number on which to search for information. As an example, a user who knows only the last four digits of the telephone number may enter "3421". Object record set will contain all records of telephone numbers ending in "3421", that is, for example, the number "212-324-3421", "213-247-3421" and "702-397-3421" and the user can then select the number or the relevant resource which in his view is the desired resource.
Accommodation Index also contains logic to sort records in a recordset object, based on the function of excessive use. If the object is a set of records has only one record, ordering is required. If the object is a set of records has more than one entry, the entries may use any method of the preferred ordering.
In block 510 Resolver 40 generates an outgoing message on the basis of the response index. In the preferred embodiment, the Resolver 40 creates an XML file that contains information from the response index 30. In the preferred embodiment, each of the services 42, 44, 46 is provided with the parser XML, which can convert an XML file created by the resolver 40, in the text or other information in the format used Client 70. In the preferred embodiment, each record referred to in the recordset object also contains a value that represents the number of times the record has been allowed (searched for or). The number of use may be used to rank the entries in the time to display or use other methods of one of the services 42-46.
Preferably, after the resolution of each telephone number Resolver 40 did logging (log file) 84, which include the phone number, the total number of permits in the past, including the current resolution, IP address and domain name of the client or server that has requested the current resolution and a time in which there is a solution.
In the preferred embodiment, the index 30 and 40 Resolver physically run on the same computer, and the index file 34 are located in the main memory of the computer. This configuration improves the response time of the resolver 40 by providing quick access to the Index 30. It is understood that the Resolver 40 responds to tens of millions of requirements to resolve the telephone number on the day. In the preferred embodiment, the index 30 and 40 Resolver also in the form of a plurality of software COM objects (Component Object Model, or COM) to communicate with the runtime library AltaVista, using API AltaVista. Licenses for runtime libraries AltaVista sold by Digital Equipment Corporation in the form of SDK AltaVista (Software Development Kit or SDK).
In an alternative embodiment Resolver 40 is able to distinguish the address relating to the Internet, local area network or "Intranet", and accessible from outside the local business network "Extranet." The intranet version Resolver 40 goes to register 10, which is available within the organization that owns and manages the resolver. Register 10 contains information that describes resources intranet. In particular, this applies to organizations that have based PBX telephone system uses an internal four- or pyatitsifirnye expansion of internal phones. Resolver 40 converts the telephone number or extension entered by the user in the address of the intranet resources and navigates users to these resources.
Services (Services)
Services 42, 44, 46 may be provided in several embodiments. In one embodiment, the GO service 42 is a computer program installed or attached to the browser 74 of the client 70. For example, GO service 42 installed on the client as a plug 70 (plug-in) to the browser 74. The user downloads the GO service 42 from a central distribution site and places service to the client 70. The user installs a program that sets the service to the browser 74. After setting the GO service 42 intercepts telephone numbers entered by the user in the browser 74, and allows the telephone addresses into network addresses used by the browser 74.
6 shows a block diagram of a method for operating a service GO 42 in the above configuration. In block 600, the user causes the execution of the browser 74.
The browser 74 has a field of administration of the URL in which the user at will print the network address of the document to extract it and display in the browser. In block 602, the user enters a phone number in the administration of the network address. In block 604, service GO 42 captures keystrokes made by the user when typing in the field of administration of network addresses of the browser 74, and thus obtains the telephone number entered by the user.
Next, control is passed to block 609. At block 609 service requests 42 Resolver 40 allow the phone number from a browser to a network address. For example, service 42 creates a URL that refers to a predetermined place in the system where the Resolver 40. This URL contains as a parameter passed resolver 40 phone number from a browser. Service 42 opens an HTTP connection from the client 70 to 40 Resolver using this URL, containing the phone number. Resolver 40 retrieves the telephone number of a URL and performs a resolution as described above. Resolver 40 then returns the address of the network resource HTTP messages 74 browser.
If the corresponding network resource address value obtained by the resolvers 40, at block 610, service GO 42 74 redirects the browser to the network address found resolver 40. For example, service 42 retrieves the address of the network resource from the HTTP messages, received from the resolver 40, and transmits it browser functions 74 that may download and display Web pages. The browser 74 then loads and displays the file or page, located at a network address in the usual manner. Alternatively, if more than one network resource location values from the resolver 40 in response to a resolver 40 only part of the phone number, at block 610, the service shows the list of values placements (addresses) of network resources. The results are displayed in order from more important to less important permissions based on the values of permits, processed and kept in the Statistical service (Statistics Service) 82. In another embodiment, the service returns to the client response 70 HTTP, contains the XML that contains the results of a query.
In an alternative embodiment GO Service 42 is designed as a web application running on a dedicated web server. To find a network resource client 70 establishes a connection with a Web server GO, using a predefined address or URL. In response, the Web application service GO 42 shows a Web page containing a form with a field of data entry. The user types the phone number of the network resource in the field of data entry. GO server 42 detects the network resource, as described above.
In another alternative embodiment GO service 42 is associated with a button or panel, built-in web page of the external web server. The button or panel is fixed network address or URL, which causes GO service 42 when the button or panel selected by the user, view the external web server. This configuration provides the ability to enter phone numbers that do not require the use of a browser.
In another alternative embodiment GO service 42 includes a mechanism for detecting and responding to the language used by the client 70, which binds to and makes a request to the GO, the country code identifying this way. Assume that the computer on which the service of GO 42, operates using a set of UTF-8 characters and English, while the customer uses 70 Japanese language and encoding of a different character set. When the GO Service 42 sends to the client 70 Web page containing a form to enter phone number, web page includes a hidden field with the deployment of a predetermined text string. Client 70 receives a Web page, and his browser or operating system converts a Web page into a set of characters that he uses. User client 70 enters a phone number in a web page and sends it to the Customer Service GO GO 42. 42 receives a Web page, extracts the value of the hidden field and compares it to the hidden meaning of the table compares the values or hidden field with different sets of character sets and languages. GO Service 42 determines the appropriate character set and language. Using the language (country code), GO service 42 selects a resource that has to match the value of the language in section 906, metadata resource. Thus, the system determines the language of the client that sent the request, and provides it with the resources corresponding to the language.
In another alternative embodiment Service GO 42 and 40 use the Resolver values Metadata File number 64 associated with the resources to respond to the extended requests. For example, suppose that the airline United Airlines registers the file number 64, which describes the resources in several different languages, such as English, French and Japanese. The user finds a Web site belonging to United Airlines, which is produced in France or in French. The user enters within GO Service 42 phone number of reservations United Airlines in the United States with the addition thereto word "France" like this: "1-800-241-6522 France". Resolver 40 compares with the record metadata fields 906 Description section, region and language associated with the file number 64 of United Airlines.
Resolver 40 and Go service 42 redirects the user's browser to the site of United Airlines, made in French.
In an alternative embodiment, when the GO service 42 is designed as a plug-in to the browser installed on the client 70, GO, the service provides information on character encoding resolver 40. To obtain the character encoding used by the client at the moment 70, GO, 42 service calls a function of the operating system that runs on the client 70. GO service 42 adds information about the character encoding used by the client to the URL, the user's request to transfer to the Resolver 40. In this case, Resolver receives information defining the language and character encoding used by the client is currently 70, and may be return address network resource corresponding to a given language.
In an alternative embodiment the computer system further comprises a microphone coupled to an analog-digital converter (ADC). This ADC is connected through an appropriate interface to a computer system bus. Under the control of system driver program or other appropriate program of the ADC receives an analog audio signal from a microphone and converts it into a digital signal. The driver or other program receives the digital signal and converts it into a phoneme string of words, the keyword or command to GO service 42. The converted signal is used GO service 42 as the input signal, it replaces the keyboard input or mouse. Thus, the user can view the user interface 1000 and slander the word into the microphone, giving the GO command service 42 to search for specific network resources. Thus, the user uses the navigation VEB using the word (s) of spoken language.
Another alternative embodiment is shown in Figure 9. A service is arranged in the form of a web server or web server middleware application 60a. Web application server 60a communicates with the client 70 using HTTP messages through the Internet 50. The Web application server 60a includes a script processor interface Common Gateway Interface (CGI), the application server, such as server Netscape Kiva, Microsoft Active Server, or Apple WebObjects (ZTM). The software application running on a Web application server 60a communicates with the resolver 40 via the Internet 50 via the path 40a, 40b using a CGI script to generate the HTTP requests and responses. Web application server 60a uses function calls resolver 40 provides an API for communication via the path 40a, 40b. Using this scheme Web application server 60a produces a query containing requests resolver 40. Resolver 40 evaluates the response requests and 30 requests the index creates a set of metadata for all index entries reflecting Web pages that match the query. Metadata Set is packaged in an XML file and is delivered to the resolver 40 Web application server 60a. Web application server 60a has an XML parser (analyzer) that can analyze XML code from an XML file. Using analyzed code XML, Web application server 60a creates one or more HTML documents and delivers them to the client 70. The client 70 displays an HTML document to the end user.
Service Statistics (Statistics Service)
As described above with respect to the resolver 40, each time the Resolver resolution produces a phone number, he puts a note of this in the log (log file). The system has 82 Statistics Service, which is responsible for reading the magazine and loading the log information in the index file 34.
In a preferred embodiment Statistics Service 82 operates periodically on a scheduled basis. Statistical Service 82 reads each log entry and creates an index object based on the information contained in the magazine. Then the statistics service 82 sends a message to the Index Builder 32, which asks Builder Index values reside in the index file 34. In response, the Index Builder 32 places the value in the index file 34.
Page top-level menu system has hyperlinks that allow the user to access the functions of statistics and pay bills.
When the option STATISTICS AND PAYMENT OF ACCOUNTS / Statistics, the system generates a Web page 700 in the form shown in Figure 7. Web page 700 has a list of options 702 top-level set of function buttons 704 allow the user to create other global functions, such as address resolution, the introduction of new information about the customer, receive services and enhanced customer support information on the system of telephone numbers.
The function keys 706 reports allow the user to access the reporting functions of the system. This performance reporting buttons 706 include buttons select records 712 714 Timing Report to Records 716 718 Facilities Report.
Button Record Selection 712 is used to determine the list of entries in the file room, which must be generated reports. When a user uses the Select button 712 entries, the system reads the file from the server room, which has an IP address that matches the IP address of the current user's domain. The system analyzes the file number and displays a list of all the phone numbers on the new web page, which is sent to the client 70. This page displays a selection means - the so-called radio button, adjacent to each of the telephone numbers on the list. The selection is made by clicking with radio button, then the web page is sent to the system, the system provides statistical information for all the selected telephone number in all reports to be generated later.
Selecting the button 714 is used to set the time period for which you want to generate statistical reports. When a user uses the button timing 714, the system generates a new Web page and sends it to the client 70. This Web page includes a form in which the user enters the start date and end date of the report. When the user sends the completed page to the system, the system receives and places the resulting value dates. Later, when the report is generated, it will contain statistical information for the phone number of permits that have occurred between those dates.
Entries for the Report button 716 is used to generate reports and graphs showing the resolution of all the phone numbers that have happened to write each number as described in the current file number. When the button is used to report 716 records, the system reads the statistical information, which is available in the statistical database tables for each of the 12 phone numbers that are defined in the current file number. The system generates charts and graphs of statistical reports and generate a Web page that contains the graphs and charts.
7A shows an example web page generated thereby. Graph 708 includes an exemplary histogram. Each bar in the histogram represents the telephone number defined in the current file number. The vertical axis 720 indicates the number of permits (in thousands) for each telephone number. The horizontal axis 722 shows each number, for which the statistics in the report. Statistical square 710 has a column 730 description taken from the Description field of the file number to the column number of permits 732 percent and the column 734. The column 730 lists the description of each phone number and its description, as defined in the current file number. Column number of permits 732 gives the number of permits telephone number that occurred during this particular period of time. Column 734 percent of each number indicates the percentage of authorizations attributable to the resolution of the telephone number.
7B shows an example of another type of graphics generated service statistics. The vertical axis 720 is the number of permits each telephone number. The horizontal axis 722 comprises a plurality of columns 738, each of which is associated with the telephone number. The bar represents the number of permits this phone number. The second vertical axis 736 shows the percentage of all permits manufactured system in respect of telephone numbers listed on the horizontal axis 722.
In this version of the owner of the phone numbers is paid by the end users, who registered phone numbers in the Register 10. The Librarian 20 creates a demand for payment to the account of each user when the system is put a new record through the Service Registry (Registration Service) 22. In another embodiment, end users and clients from among those who register phone numbers in the Register 10, pay a fee owner of the phone numbers for each resolution produced by the resolver 40 in response to the third parties. Resolver 40 creates a demand for payment to the account of each user, after the end of each resolution. This performance information retention fees from customers' accounts are documented and collected in a database table 12. Periodically external accounting program reads the table of accounts and payments from the database 12 and generates an invoice that is sent to users. STATISTICS menu option and pay bills / Statistics from the menu list 702 allows users to observe and research in real-time balances and the current pay users registered entries of phone numbers, as well as take into account the amount of payment for services permission. When the function is selected pay the bills, the system reads the table and pay bills from the database 12 and generates web-page report summarizing for the services of the customer. This web page is sent to the client 70 and displayed it.
Browse Equipment
Figure 8 is a block diagram illustrating a computer system 800 upon which can be accomplished pursuant to the invention. The system of Figure 8 is intended to implement the above-described uses for permitting web pages using telephone numbers. Sophisticated skilled in the art will appreciate the fact that the system of Figure 8 may be modified so as to utilize known methods and components for permitting execution resources different from those described above, such as mobile phones, PDA, and so on.
Computer system 800 includes bus 802 or other mechanism for transferring information, and a processor 804 connected to bus 802 for processing information. Computer system 800 also includes main memory 806, such as RAM (random access memory or RAM) or other storage device connected to the bus 802 for placing information and instructions designed for execution on the processor 804. Main memory 806 also may be used to accommodate temporary variables or other intermediate information during execution of instructions to be executed by processor 804. Computer system 800 further includes a read only memory (read only memory or ROM) 808 or other persistent storage associated with the bus 802 for placing the static information and instructions for processor 804. A storage device 810, such as a magnetic disk or optical disk, is also present and is connected to the bus 802 for placing information and instructions.
Computer system 800 may be coupled via bus 802 to a display 812, such as a cathode ray tube (CRT), for displaying information to a computer user. The input device 814, including alphanumeric and other keys, is coupled to bus 802 for the exchange of information and commands to the processor 804. Another type of input device is cursor control 816, such as a mouse, trackball or the cursor keys to guide the transfer of information and command selections processor 804 and for controlling cursor movement on display 812. This input device typically has two degrees of freedom in two axes, a first axis (x) and the second axis (y), which allow the device to be positioned in the plane.
The invention relates to the use of computer system 800 for implementing the system of detection of network resources in their telephone numbers. In accordance with one embodiment of the invention, the detection of a network resource is provided by the computer system 800 in response to processor 804 for execution by one or more of the sequences of instructions contained in main memory 806. Such instructions may be read into main memory 806 from another computer information carrier (computer- readable medium), such as storage device 810. Execution of sequences of instructions contained in main memory 806 causes processor 804 to perform the process steps described herein. In alternate designs may be used instead of another circuit assembly or in combination with software instructions to implement the invention. Thus, application of the invention is not limited to any specific combination of hardware circuitry and software.
The term "computer storage medium information" ("computer-readable medium") is used to refer to any medium that participates in providing instructions to the execution processor 804. Such a storage medium, including but not limited to, may be nonvolatile, volatile carrier transmission carrier. Non-volatile media include, for example, optical or magnetic disks, such as storage device 810. Volatile media include dynamic memory, such as main memory 806. Transmission media include coaxial cables, copper wire and fiber optics, including the wires that make up the bus 802. Transmission media They may also take the form of acoustic or light / radio waves, such as generated in the process of data exchange in a radio or infrared wavelength range data.
The general form of the carrier computer information includes, for example, a floppy disk, a flexible disk, hard disk, magnetic tape or any other magnetic medium, a CD or any other optical medium, punch cards, punched tape, any other physical medium with drawing holes, a RAM, PROM and EPROM, flash memory, any other memory chip or cartridge, a carrier wave as described hereinafter, or any other medium which can be read by a computer.
Various forms of computer information carriers can be used for carrying one or more sequences of one or more instructions to processor 804 for execution. For example, the instructions may initially be recorded on a magnetic disk of a remote computer. The remote computer can load the instructions into a dynamic memory and send the instructions over a telephone line using a modem. Modem disposed adjacent to the computer system 800 can receive the data on the telephone line and use an infrared transmitter to convert the data to an infrared signal. Infrared receiver coupled to bus 802 can receive the data borne infrared signal and transmit data to the bus 802. Bus 802 carries the data to main memory 806, from which processor 804 retrieves and executes the instructions. Instructions received main memory 806 may optionally be placed on storage device 810 either before or after the execution of the processor 804.
Computer system 800 also includes a communication interface 818 coupled to bus 802. Communication interface 818 provides a two-way communication connected to a network link 820 that is connected to a local network 822. For example, communication interface 818 may be a card or a modem digital integrated services networks ( integrated services digital network or ISDN) to provide a data communication connection to a corresponding type of telephone line. Another example of a communication interface 818 may be a network interface card LAN (local area network or LAN) provides a connection to communicate with a compatible LAN. Wireless links may also be used. In this embodiment each communication interface 818 sends and receives electrical, electromagnetic or optical signals that carry digital data streams representing various types of information.
Network link 820 typically provides data communication through one or more networks or other data devices. For example, network link 820 may provide a connection through local network 822 to a host computer 824 or the equipment. Internet service provider (Internet Service Provider, or ISP) 826. ISP 826 in response provide data services through a worldwide network of packet data is now often referred to as the Internet 828. Local network 822 and Internet 828 both use electrical, electromagnetic or optical signals that carry streams data. Signals in different networks, the signals in network communication signals 820 and 818 in the communication interface carrying the digital data to and from computer system 800, are exemplary forms of carrier waves transmitting information.
The computer network 800 can send and receive data, including program code, through the network (s), network link 820 and communication interface 818. In the example of the Internet, the server 830 may transmit a requested code for an application program through Internet 828, ISP 826, local network 822 and communication interface 818. In accordance with the invention, one such downloaded application provides a program for language-naming system network, as described herein.
The resulting code can be executed on the CPU 804 upon receipt, and / or stored for later execution on the storage device 810, or other storage device with the nonvolatile memory when power is off. Described way computer system 800 can receive program code in the form of a carrier wave.
Options; advantages
In the following specification the invention has been described with respect to specific embodiments. Nevertheless, it is apparent that it is susceptible to various modifications and alterations without departing from the basic idea of the invention throughout its breadth and depth. For the invention, therefore, the specification and drawings have illustrative rather than a limiting value.
Description Application
Definitions
A layer of secure protocols (Secure layer protocols): Secure Sockets Layer (SSL); Microsoft® Passport single sign-in (SSI); other similar.
URL. URL (Uniform Resource Locator) - a unique identifier, such as an IP address. Keyword, phone number or DNS name, as well as any others that uniquely identifies network resources.
IP address. IP (Internet Protocol) address is a numerical URL and represents a layer addressing addressing system DNS; IP addresses are unique by definition; The IP address can have their DNS names assigned to them. Keyword or DNS name can not be used unless they are mapped IP address.
ETA - Single Phone Address (UTA -Uniform Telephone Address). ETA is the phone number assigned to the network subscribers, user or resource (with customers). Each subscriber has only one assigned by ETA and ETA because each uniquely identifies a specific subscriber. Each ETA has at least one file number assigned to this ETA and its associated. Addressing ETA is a unique layer address (URL) on top of telephone numbers, and IP addresses of the DNS name. ETA is compatible with the company's name Keyword RealNames (note: RealNames company ceased to exist in summer 2002). ETA can be assigned to any network subscribers, including Internet resources, as well as phones with a wired or wireless (mobile, satellite and other) line.
ETA subscriber. The subscriber has the ability to work in the "World Wide Web" or web is a network entity of any kind, the device (such as a computer device, a data carrier chip or processor), software (such as a web browser, instant messenger, a program to work with e-mail and other ), data (such as Web sites or pages, etc.), frequency of the wave and its modulation, or the division or the composition (eg, a particular station). The subscriber is able to require the network to give it a URL. There is only one unique ETA assigned to the Subscriber.
IP address determines the exact location of the Subscriber to the Internet, called the primary IP address and SFI belongs to subscribers and is available on the network is uniquely determined by the primary IP address. All subscribers have the tools to work with web, such as web server, web browser, and other hardware and software that allows subscribers to manage data SFI, to carry out the connection, communication, and sharing over the Internet. For each primary file numbers must be created preferably two mirrored SFI called primary and secondary Fal rooms; SFI these copies are placed and available in real time on a switch, server and Internet Provider (ISP), respectively.
Dynamic and Static IP address (URL) and "traveling" cell identifier (ID). Each subscriber can be accessed on the network using its URL. The Internet subscribers typically have static IP addresses assigned to them using the dedicated line Internet, (such as DSL, T1, etc.); the so-called dial-up (Internet access with "dial-up") or mobile (traveling) Subscribers are usually temporary dynamic IP address assigned to them via DHCP (Dynamic Host Configuration Protocol) and is valid during the time that the Subscriber is connected to a specific ISP or cell for the mobile network. During the trip, number of mobile devices are remembered as the devices themselves are serviced using standards such mobile roaming (traveling) as an ANSI-41 and GSM-MAP.
ANSI-41
ANSI-41 provides support for travelers who visit your service area, as well as your customers when they are traveling outside your service. When the traveler is recorded in your service area by
Use MIN / ESN traveler, your mobile switching center (mobile switching center - MSC) and register visitors area (visiting location register - VLR) determine the appropriate home location register MSC area Traveler (HLR) for routing.
Your MSC forwards the message through the SS7 network and, if required, via a gateway access to other SS7 network for transmission to the MSC / HLR home zone for checking.
MSC / HLR caller traveler checks and sends the response, allowing the caller to the requested connection.
When your customer is traveling outside your service area, the process is repeated, but the messages are sent over the network to your MSC / HLR.
GSM-Map
Just as ANSI-41, GSM-MAP can transmit important information about the MSC / HLR / VLR register and imperceptible movement between you and the network your roaming partner, and the message protocol provides instant access to improved capabilities SS7, for example the possibility save the number (Number Portability).
One feature where transport GSM-MAP is different from an ANSI-41 - is the administration of the traveler. GSM-MAP network used International Mobile Station Identifier (IMSI), whereas the ANSI-41 uses the Mobile ID Number (MIN).
IMSI is an identifier of 15 digits, which is based on the mobile country code (Mobile Country Code -MCC), representing the country of origin of the traveler, the mobile network code (Mobile Network Code -MNC) defining native network (origin) of the user, and finally identification number of the mobile station (Mobile Station Identification Number -MSIN), which identifies the particular mobile node.
When the traveler is recorded in your service area by:
Phone traveler was included in your service area; VLR launches your registration request to HLR traveler. Each HLR is identified by a mobile country code (Mobile Country Code) and mobile network code (Mobile Network Code).
HLR responds maintain your VLR, and your VLR, in response, transmits the data to the MSC traveling user.
Thus, the traveler is now registered in your service area.
When your customer is traveling outside your service, but is in the coverage area of your partner via GSM roaming process is repeated exactly the opposite, and messages are sent in the opposite direction to the MSC / HLR your network.
ETA chief, primary and secondary URL. Primary URL ETA - a URL,
determining the location of the primary file Non ETA placed on the property of the subscriber to the Internet. Secondary URL ETA - a URL, determines the location of the secondary file Non-ETA (mirror copy of the primary file number) associated with the ISP. Secondary File Non mainly located at the location of the ISP Internet. ETA chief URL specifies the location of the master file Non ETA Switch on server on the Internet. The main URL and secondary URL is used mainly as Subscriber is not available in real-time (stored in the offline mode - off-line), that is, when the subscriber is not available for its primary URL, and is used for the purposes of inspection and verification.
File Non ETA. Non-file described in detail in U.S. Patent Application №10 / 085,717, which is the parent to the present its continuation in part (CIP). This file number is assigned to a specific number of ETA, designating subscribers.
Chief, Primary and Secondary Files Non ETA. Non-File contains metadata associated with ETA. File Room is predominantly a data file in the format RDF, XML-based and CC / PP. Main File Room is located on the Main Svich- URL to the server, as described above. Primary File Room is located on the property of the subscriber - device available on the network on Primary URL, a secondary file rooms available at URL to secondary ISP. There may also tertiary, quaternary, etc. URL, providing different or distributed Internet services and telecommunications; respectively may exist Tertiary, quaternary, etc. File number. SFI mainly contains three URL, you have a main, primary and secondary URLs. The main URL is always the same as the Primary URL Switch server. The secondary URL is always the same as the Primary URL Internet Provider (ISP) of the Subscriber. Both primary and secondary URL provided to subscribers when they subscribe to the service, both URL stored in the primary file rooms during commissioning or dynamically allocated network and written to the ETT when subscriber is connected to the network. Both primary and secondary Files rooms are mirror copies of the primary file rooms.
Content Metadata File Non ETA: mostly use XML metadata and compatible RDF and CC / PP, as well as other formats, and can include the following information relating to the Subscriber:
Phone Number (ETA).
Primary URL. Primary URL determined if the caller is available in real time (lo-line), and determined if the subscriber is not available ("off-line").
Secondary URL
Primary URL
Primary URL authorization center
Primary URL Administrator Digital Certification (if it does not coincide with that of a switch server)
Primary URL Network Security
Number ETA authorization center
Number ETA Certification Administrator Digital
Number ETA Network Security
Initial Public Key (public key server, a switch)
Secondary Public Key (public key of native ISP subscriber)
The public key of the Authorization
Public Key Administrator Digital Certification (if different from that of a switch server)
Public Key Network Security
On-line status. On-line status is derived from the Primary URL.
The current status of available and additional resources needed Subscriber (devices)
The acquired resources and the current status of the purchase (delivery / payment, etc.)
The data relating to network security policy to contain the financial and banking data, electronic purse, resolution (proxies), access rights, data sets for the identification and authentication, biometrics, and so on.
User Preferences (conventional communication services, such as a service subscriber identity, procedure and conditions for switching to order services such as instant messaging, text mode, SMS mode, etc.).
Methods and protocols for verification and authorization for access.
Other metadata is disclosed in parent application to the present a continuation.
Other data provided by third parties, such as Microsoft Passport or VeriSign and other certificates.
Digital certificates Digital Certificates Administrator (Svicha) (preferably comprises all of the primary file rooms with unchanged values).
Authorized privileges for public key encryption method (preferably a part of the digital certificate).
Metadata, located in a protected segment of the internal memory of the Subscriber:
** 3apis Credit Card **
** ** Bank Account Information
** Private key file encryption by public key **
** Password for a single phone **
Check availability of the Subscriber to communicate in real-time (Online status check): Description of the "ping" command to check the IP address.
"Ping" command or other similar checks the availability of a particular user on the network in real-time by its IP address or DNS name. Execution team possible in manual mode in Windows using the path Start - Programs - Accessories - Command Prompt. To check a particular IP address or URL command line should be a way of life:
ping <here it is necessary to specify the IP address>
or
ping <specify a DNS name here>
The following is a specific example of command execution ping:
A Microsoft Windows 2000 [Version 5.00.2195]
(C) Copyright 1985-2000 Microsoft Corp.
C: \> ping www.names.ru Pinging www.names.ru [212.24.32.169] with 32 bytes of data:
Reply from 212.24.32.169: bytes = 32 time <10ms TTL = 121
Reply from 212.24.32.169: bytes = 32 time = 10ms TTL = 121
Reply from 212.24.32.169: bytes-32 time = 10ms TTL = 121
Reply from 212.24.32.169: bytes = 32 time <10ms TTL = 121
Ping statistics for 212.24.32.169:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 10ms, Average = 5ms
C: \>
Web server (Web server). This network device or program is installed on a particular network subscribers; usually web server provides the connection to the Internet, and data processing scripts and stuff. Web server supports SSL (Secure Layer protocol) and therefore supports public key infrastructure PKI and its procedures, it can create a request for issue of a certificate (Certificate Signature Request -CSR), to create public and private keys, locate, retrieve, receive and place in storage of digital certificates issued by the CA administrator. It can also act within the PKI as a calling or receiving party infrastructure. Web server may be a device - just a chip, such as ASE1101 MT8 or PIC12C509A / SN fhttp: //world.std.com/~fwhite/ace/) or program. Web server is always a part of the Subscriber, but the subscriber may not have their own Web server (web server).
Web browser (Web browser). This network device or program. Web browser can provide a different set, but must have at least the following:
processing of addresses and find them subscribers to the Internet and compatible with Web communications networks; Connect to selected subscribers; Online visualization of static content (HTML, XML, etc.); visualization of dynamic content Internet audioobmena and video in real time using image transfer techniques and voice over IP connection (dynamic markup language data, streaming data, VoIP, and so on). Web browser supports SSL (Secure Layer protocol) and therefore supports public key infrastructure PKI and its procedures, it can create a request for issue of a certificate (Certificate Signature Request -CSR), to create public and private keys, locate, retrieve, receive and place in memory Digital certificates issued by the CA administrator. It can also act within the PKI as a calling or receiving party infrastructure.
Addresses ETA Administrator (AA). AA is a central administrator that contains a central repository of data ETA, ETA applicants providing registration services, management and resolution addressing ETA ETA addresses the network and the associated file number ETA. Switch Server is a central software and hardware complex data management placed the Administrator address.
Administrator Digital Certification (ACS). ACS is a central administrator PKI, providing a digital certificate for the file number ETA and services related to SSL. Preferably, the ACS is both the Administrator address (AA).
Switch server (Switch server). Switch is an Internet server, providing the switching service for subscribers that have addresses and ETA do not have those. Switch is the central subscriber (the switch), and contains the main file Room ETA, providing main URL for each of them. Sam, being the Subscriber Network, Switch server has its own chief, Primary and Secondary Files rooms.
File system security. Switch server and ISP can establish and enforce network security policy for selected or all IP connections, exchanges, phone calls and transactions. Information These policies are in the file system security, available on Switch server, and the ISP, arranged respectively at the primary and secondary files safely. File Security can have its own number of ETA and therefore can be accessed on the network using a number of ETA Security. This ETA Security Number may be widely known number, such as 911, used in the United States, or numbers 01, 02 and 03 are used in Russia, and so on.
On-line (On-line) status.Eto status is available to subscribers to communicate in real time. For the purposes of the present application, the concept of "on-line status" is understood as the availability of a particular user through Web on its primary URL (extension states "on-line"), and the concept of "off-line status" is understood as the lack of access to the subscriber on its primary URL (status Subscriber "off-line").
"Challenging" and "responsible" subscribers. Calling called subscriber initiates a call through an IP of another - meets the Subscriber using the last number of ETA. Calls can be implemented as a machine-to-machine, machine-to-program-to-program the machine and program-to-program, IP calls. The caller can provide your ETA Responder Subscriber number and other metadata from the primary file number of the caller. The caller can also be an anonymous person.
IP call. IP call is an Internet connection between the calling and answering callers, established to exchange data, visual and audible exchange point-to-point with the use of the Internet and protocol TCP / IP, technology transfer images and sound over IP (voice & video over IP technology), others appropriate means of working with the Web. It can be implemented as a wired network calls like - a mobile network, the mobile network - the wired network, the mobile network - the mobile network, the present invention also offers the possibility of browser-type compounds of a wired network, a browser, a mobile network, a mobile network-browser and a wired network -browser, and a mobile network as a mobile cellular understood as satellite, or any other wireless communication. In protected mode, IP call can use any of the known algorithms and encryption techniques such as RSA, Diffie-Hellman, and other, SSL, PKI, and SSI MS.
Telecom operator - ISP (Service Provider). Under the telecommunications operator or ISP in the application refers to companies providing communication services with access to the Internet. As a Subscriber, each ISP may have its main, primary and secondary file rooms.
Point of sales and services (Point Of Sales -POS). POS terminals - a network node number endowed with ETA, providing data services, sales support and conduct transactions. Each POS can be endowed with a number of ETA and therefore can be a subscriber networks, providing access to the Internet.
Realization
Using the preferred standard methods of authentication (authentication). The recommendations of the standard H.501 (H.501 recommendations).
X.509 directory services (X.509 directory services); Directory services H.519 protocol (H.519 directory services protocol); The preferred use of the IETF Kerberos (http: // www. Ietf. Org / html. Charters / krb-wg-charter.html): Syntax encrypted messages (Cryptographic Message Syntax -CMS); more.
Digital certificates, encryption issues: Internet X.509 PKI certificates can be used in accordance with the specification IETF "Use of ECC Algorithms in CMS", located on the Internet http://search.ietf.org/intemet-drafts/draft-ietf -smime-ecc-06.txt for distribution of public keys. Using ECC algorithms and keys within X.509 certificates is described in the papers:
- L.Bassham, R.Housley and W.Polk, "Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and CRL profile", PKIX Working Group Internet-Draft, November 2000.
- FIPS 186-2, "Digital Signature Standard", National Institute of Standards and Technology, February 15, 2000.
- SECG, "Elliptic Curve Cryptography", Standards for Efficient Cryptography Group, 2000. The document is available at www.secg.org/collateral/secl.pdf.
Financial services and conducting transactions: Preferably use standard ANSI X9.62-1998, "Public Key Cryptography For The Financial Services Industry:
The Elliptic Curve Digital Signature Algorithm (ECDSA) ", American National Standards Institute, 1999; Markup Language electronic business documents (Electronic Commerce Markup Language - ECML)
Creating the Primary File number (Primary Number File -PNF). When you first become a client services based on the use of numbers of ETA, it provides the Administrator and the Administrator Addresses Digital Certificates with all necessary information, including the number of ETA and on the basis of this information formed the primary file number (SFI). To use the SFI for transactions and services SSL, Digital Certificates Administrator - ACS publishes digital certificate authority (CA) that allows the use of SSL and PKI. The public part of the information for PKI located in ETA SFI and is available to other users PKI, and closed part is placed in the protected memory segment Subscriber. CA private key is signed by ACS and comprises at least a number of the ETA, and public key of the Subscriber. CA follows the format of X.509; ETA number contained in the X.509 - expansion.
Provision of primary URL and synchronization with the primary file Rooms: Each time the user enters the network, the network of its registers and assigns primary URL; After vesting Primary URL this URL is preferably transmitted subscribers and is located in the metadata primary file number; Primary URL value is then preferably pa zmeschaetsya secondary file Room (ISP) and the main file room (on the Switch server). During registration on the network, preferably authenticates Switch (authenticates) the Subscriber using the Subscriber CA; Then Subscriber synchronizes field ETT with the relevant fields of primary and secondary file number. The subscriber retrieves the fields primary and secondary URL from SFI and, using them, establishes a connection with the main and secondary file rooms, respectively; When the connection is established subscriber starts synchronization metadata. For authorization and verification of the Subscriber and to prevent access nominees (imposters) to network resources, Switch server, ISP or any other subscriber or a visitor to the network using the procedures SSL can extract the CA from SFI, decrypt it using the public key of ACS, and get at least a number of the ETA, and public key belonging to the Subscriber; then, at exchanging SSL, checking person can make sure that the subscriber does not play the role of real subscribers and is such and has the appropriate privileges.
Updating the secondary and the main file rooms: ISP constantly and promptly update the Secondary File Non establishing a connection to the primary and / or master file rooms. Is available to subscribers in real numbers (status - "on-line") can also be installed by conventional means through the operators of telecommunications services and then the file format is available in the rooms and the secondary file rooms.
Updating the master file Rooms:
Method 1: Switch server continuously and promptly update the master file rooms, extracting data (Switch - pool method) or receiving data (ISP push method) from the secondary file number of the subscriber; If the network received Your Calls, Switch server retrieves the primary URL of the Subscriber from the Main File number and if Primary URL is defined, the Switch sets up a connection with him; If the connection fails, Switch disconnects and assigns Primary URL rooms in the main file to "zero" and the value of the status is set to "off-line". In another case, "on-line status of" Subscriber can be obtained using other ISP own capabilities, and then recovered and placed on the ISP Server Switch for each subscriber. Alternatively, the Switch server can constantly check a command like "ping" all subscribers using their primary checking the URL and thus their "on-line status of" permanently. Whenever finishes checking on-line status, the Switch updated the status field in the master file number of each subscriber / ETA.
Method 2: Getting in the zone of the network, each subscriber establishes a connection with the Switch server and synchronizes its primary file metadata rooms with the main file rooms. Switch consistently and promptly connected to each subscriber and updates the values of the fields of the Main File number data taken (Switch-pull method) or received (Subscriber push method) of the primary file number of the subscriber; When a call is received from the network to a particular subscriber, the server retrieves Svich- Primary URL Subscriber from the Main File number and, if the primary URL is not zero, Switch connects to it. If it is zero or a connection can not be established, Switch disconnects and sets the value of "zero" in the Primary URL subscribers, and in the status field value of "off-line".
Making outgoing IP call when the address bar of the Internet browser or another program of work with the Internet introduced ETA number of the caller, the caller establishes a connection and communicates with the Switch server, as described in the parent application for the present a continuation and receives metadata meet Subscriber of its main file number; if ETA Primary URL Responding Subscriber is not zero, then the caller is trying to establish a connection to the responsible Subscriber using his ETA Primary URL, taken from the main file room will meet the Subscriber; Primary URL is valid if the (actual) and the subscriber answers, the caller and respond provide each other with their CA, and make checks in accordance with the existing network security policy; depending on the policy caller can access the primary file and back rooms meet Responder can verify the primary file number of the calling; The calling and answering process data security, following established procedures, security policy, accessing data and sharing data with the responding user if you do enable privileges. This protocol is used mainly started the session IETF (IETF Session Initiation Protocol) or similar to them to be exchanged between the calling and answering subscriber.
When Primary URL Responding Subscriber valid and the caller joined to the responsible party, but the latter did not respond ("does not answer"), the caller tries to leave a message in the memory device responds to the Subscriber;
When Primary URL is not valid or is zero, the browser retrieves the Secondary URL and attempts to detect the network secondary file number and so on, and when found another URL, which said web browser allows you to create and leave a message there of any kind.
Answering incoming IP call when receive an IP call, to answer subscriber automatically switches to the appropriate mode "answer" / "refuse to answer" or another mode, calls or other means lets you know of an incoming connection (call);
The responding subscriber is trying to retrieve a number of ETA and the CA primary file number of the caller; Responder subscriber can verify the validity of the ETA, and the CA, as well as the privileges of the caller using PKI. After checking Responder subscriber decides to grant or to refuse to connect the caller in accordance with the security policy and implementation challenges, privileges and preferences of both parties, as defined in the metadata of the file number and the CA. If required to establish a secure connection, both sides begin encrypted communication using SSL and PKI, as well as its public and private keys. Secured Communication Mode allows the purchase, pay and use other services and transactions in a secure way. When checking, verification, authentication is complete, the parties to the protocol used primarily by "IETF Session Initiation Protocol" or a similar option for the exchange between the parties.
Enabling or disabling the lists of subscribers. Each subscriber has a list of other network subscribers, anyway related to that specific user (ie the list of phone numbers of friends, partners, relatives, etc.). The list can be divided into at least primarily on the following parts: those subscribers who are not allowed to see the on-line status of a specific subscriber; those subscribers who are allowed to see the on-line status of a specific subscriber; those callers who are not allowed to connect to that particular subscriber; those callers who are allowed to connect with this particular user, etc. Therefore, each caller can check and receive "on-line status" only for those subscribers a network that allowed the caller to check it. Before making the connection to a particular party by the caller can check if it's available (on-line) Answerer (called) on the network, and if they meet the subscriber on the network is not available (off-line), the caller may abandon the attempt to establish a connection and save time in this way.
Issue of digital certificates (CA) to the ETA / Subscriber. When the administrator creates Addresses ETA and ETA register number associated with certain numbers and create a primary file Non-Subscriber Administrator Digital Certification (ACS), in turn, creates a digital certificate authority (CA); CA to create a subscriber must be able to support and work over SSL
user fills in all required fields primary file number (preferably all of the ETT with unchanged values), and then generates a file Requirements Signing Certificate (Certificate Signature Request -CSR), as well as private and public keys; The private key is stored in the protected memory segment Subscriber.
The subscriber provides a CSR and public key for the signature of ACS.
Public key file and the primary file Non ETA is encrypted (signed) ACS private key, and the encrypted file is a digital certificate ETA.
ACS signs the CSR and returns it to the Subscriber as a Digital Subscriber Certificate Authority (CA). CA includes ETA ACS and signed digitally.
Subscriber puts CA in a primary file numbers of subscribers and makes it available for treatments SSL.
Verification and Authentication are used to prevent access to network resources impostors or specific subscriber and implemented using SFI particular subscriber with Digital Certificate Manager, switches or subscriber:
Simple Authentication in an unprotected mode (SSL not used):
ETA is derived from the primary file number of the caller; extracted main, primary and secondary files ETA number of the caller;
ETA checked, the caller's number by comparing the key data, taken from the secondary and the main file with the relevant Non-taken from the primary file number; If the data match, the test (verification) is completed successfully and the caller is authorized to use the requested service, and they provided the Subscriber verification Svicha.
Strong authentication in secure mode (SSL used) here Subscriber A (A) authenticates subscribers in (B):
B:
The data is encrypted using the private key, creating data B1, create a test message containing the CA B and B1 data, the transmitting A verification message, and
A:
Retrieves CA B and B1 data of the test message
Decrypts the CA in using the public key of ACS
The extracted data and public keys of the CA in the decrypted
Decrypts the data B1, using the public key B and forming data A
A comparison of data from the data and if data are identical to the data in A, then A concludes that B owns the right and ACS certified private key, and verified data, so authentic.
The data here are preferably a part of the CA in the ETA and B; or other fields in the CA, or some or all of the fields in the CA; or full CA B.
Other similar relevant authentication procedure may be set based on the use of a particular method of cryptography.
Verification, authentication and authorization In responding Subscriber. For authorization and verification of the caller and to prevent unauthorized access to the resources of the Subscriber impostors using fake Primary File Non ETA caller specific subscriber via SSL
It retrieves the digital certificate of the primary file number of the caller; decrypts the CA's public key to the ACS (Svicha); checks the validity of the CA; authenticates the caller; The caller provides the connection to the responsible Subscriber given privileges of the caller if he was tested successfully, and refuses to connect, check if it has not passed.
Verification, authentication and authorization of the caller. In order to check that the compound was present, and not fake In responding subscribers and to prevent unauthorized access to the resources of the pretenders to the caller using its SFI, in the process of establishing a connection to the responsible party by the caller retrieves the CA is responsible Subscriber of his ETT; CA decrypts the data using the public key of ACS (Svicha); verifies number ETA Responding Subscriber and verify its privileges.
Service transactions over a secure connection between subscribers representing buyers and sellers.
Services of transactions over the IP connection can be provided on the basis of the relevant Security Policy Network (Network Security policy) and user privileges using layer Secure Socket Layer (SSL), PKI infrastructure and services ACS numbers ETA. The method of public key encryption allows you to check the numbers ETA through Infrastructure Public Key encryption method - PKI (Public key cryptography infrastructure). Layer SSL (secure socket layer) allows the use of PKI for secure transactions and e-commerce, banking services, services of data exchange and exchange in real time. All are based on the use and maintenance of CA certificates. Payments between buyers and sellers can be performed using procedures similar to the implementation of the authorization of payment by credit card, as described below:
Report Buyer
"The message of the Buyer" is a message created by the Subscriber Buyer. "The message of the Buyer" preferably comprises:
CA Seller
Seller Primary URL (optional)
These purchase (currency and amount of purchase, time of purchase, the number of purchase / transaction and other necessary information about the purchase).
"The message of the Buyer" is a purchase contract, a certified digital signature, that is encrypted using the Private Key Subscriber - Buyer.
Message to the seller
"Message to Seller" is a message created by the Subscriber - Seller. "Message to Seller" preferably comprises:
CA Buyer
Buyer Primary URL (optional)
"The message of the Buyer", signed using the private key of the Buyer. These purchase (currency and amount of purchase, time of purchase, the number of purchase / transaction and other necessary information about the purchase).
"Message to Seller" is a contract of sale, a certified digital signature, that is encrypted using the Private Key Subscriber - Seller.
Authorization
"Authorization" is a message composed authorization center. "Authorization" preferably comprises:
CA Buyer
Buyer Primary URL (optional)
"The message of the Buyer", signed by the private key of the Buyer.
These purchase (currency and amount of purchase, time of purchase, the number of purchase / transaction and other necessary information about the purchase).
"Authorization" authorization is signed digitally, that is encrypted using the private key authorization center.
Authentication method "Payment"
It contains steps:
Set a wired or wireless connection between buyers and sellers.
The user is shown on the display, or otherwise communicated the name of the purchase, its price and other data on the purchase / transaction.
The subscriber unit waits for permission (authorization) Buyer's making a purchase, and if the resolution obtained by:
Preferably the strict mutual authentication Buyer / Seller in protected mode connection
If Seller and Buyer are authentic. Buyer:
Makes "Message Purchaser"
It establishes a connection to the authorization center, using the Primary URL
Authorization center
The strict mutual authentication with the authorization center in a secure communication mode, if required
Sends "Message Purchaser" in the authorization center
Authorization Center:
Decodes "Message buyer", using the public key of the Buyer, the Buyer is taken from the CA in the authentication process and
Authorization center
Makes a message "Authorization"
It sends a message "Authorization" Buyer
The buyer sends "Authorization message" to the Seller
Seller decrypts the message "Authorization" using the public key of the authorization
Or authorization center:
Enables (search queries) through the Switch server Primary URL of the Seller, the Seller using the number ETA taken from CA Seller; OR takes Primary URL sellers from "Communications of the Buyer '
Establishes a connection with the Seller, the Seller using Primary URL
Authenticates the Seller and if the Seller is authentic:
Checks (verifies) parties to the transaction and data on purchase
Makes a message "Authorization"
It sends a message "Authorization" the Seller
Seller decrypts the message "Authorization" using the public key of the authorization
Seller authorizes the sale (transfer to the buyer of goods / services) if the payment is authorized authorization center
The method of authentication "Hold"
It includes steps:
Set wired or wireless connection between Buyer and Seller
The user is shown on the display, or otherwise communicated the name of the purchase, its price and other data purchase / transaction
The subscriber unit waits for permission (authorization) Buyer's making a purchase, and if permission is obtained:
Preferably the strict mutual authentication Buyer / Seller in protected mode connection
If Seller and Buyer are authentic. Buyer:
Makes "Message buyer"
Sends "Message Purchaser" Vendor; and Seller:
Decrypts the "Message of the Buyer", using the public key of the Buyer, the Buyer is taken from the CA, and verifies the data on purchase, if it is prescribed policies used, and if the data is correct purchase, then
Makes "Message to Seller"
It establishes a connection to the authorization center, using the Primary URL authorization center
The strict mutual authentication with the authorization center in protected mode, if it requires a security policy and if the authenticity of the parties is established:
Pass the "Message to Seller" in the authorization center; and authorization center:
Decrypts the "Message to Seller", using the public key of the Seller, extracts and decodes "Message Purchaser" using the public key of the Buyer, taken from the CA Buyer
Verifies the parties to the transaction and data
Makes a message "Authorization"
It sends a message "Authorization" the Seller
Seller decrypts the message "Authorization" using the public key of the authorization
Seller authorizes the sale, if authorization of payment received
Record credit card. Record credit card (CCZ) is a typical entry posted on the credit card. CCZ is usually recorded on the magnetic stripe of a credit card or the internal memory contains a smart card or in another memory of the credit card.
Method of payment authorization from your credit card. In order to use a credit card for transactions in real time, the CCZ is to be read from the credit card and the metadata recorded in the protected area of memory of the Subscriber. Then CCZ may be used, as described in the authentication method. If a particular system of credit cards (such as VISA, MasterCard or other) requires a change in the CCZ in the process of authorization of a particular transaction, changes in the credit system of the CCZ is returned to the Subscriber encrypted with the public key of the Subscriber, and then obtained CCZ stands for Subscriber with his private key and placed in the metadata of protected memory Subscriber for further usage.
The method of writing off funds from a bank account. Write off from the account in the bank can be achieved by a similar method described in the section of payment authorization from your credit card.
Time ETA. To reduce the cost of calls and increase the flexibility and accessibility of telecommunications services, ACS (Switch) may issue interim CA, with numbers of ETA, the latter are used for disposable handsets with the possibility of communication via the Internet, as well as Internet browsers and other network objects / subscribers who collectively they called the time extension (VA); they can establish the connection to the caller, or respond to subscribers in the network. ACS (Switch) and the CA publishes ETA ETA; ETA places and CC directly to the file number or the VA sends them to resellers, who are assigned the ETA / CA BA particular by placing them in the primary file Non-VA.
Such disposable tubes can be used in transactions, to exchange text, voice, images via IP connection, they can be sold and activated for use with or without assigning assigning a permanent number setefogo ETA. When the tube is acquired for the first time enabled by the user, it prompts the user to manually type or select a specific preset number ETA, or select a network automatically offered temporary accommodation ETA.
Mode pseudostatical ETA: If the user wants to use a specific number of ETA, the tube is preferably required to enter the "Password for temporary accommodation ETA" to check the user's rights to use ETA (similar to a password for use with a personal identification number for the SIM card GSM handsets); When the password is entered, the handset establishes a connection with the Administration Server that issued the number of the ETA (AA Switch server, ISP, VAR) through a layer of SSL and check the "Password for temporary ETA rooms" or compares the password with an encrypted password on the secure storage tube; If the test is successful (the password is correct), the user is granted access to network resources using the selected ETA, and the user recognizes the legitimate owner of the ETA; if the test is successful, the tube could be denied access to network resources or it can be declared stolen, depending on what is provided for network security policy, or
A specific ETA number and the CA for it may be granted and be valid for a standard set period of time, set the number of connections / transactions for the handset / program and, if assigned, a number of the ETA must be entered (can be programmed so that the ETA itself will appear in user interface immediately after the tube / program) and its use is confirmed user command.
ETA Dynamic mode: When the user after purchase of the tube includes it in the first time, the handset establishes a connection with the Switch server via the Internet; Switch server registers the handset to the network and assigns it a number of ETA and dynamic master file number; The main file is a copy of Non-primary file Non-ETA; Dynamic ETA may be used only during a particular connection if the user does not require it to consolidate the number of ETA to a standard period of time, or other standard conditions of use. Dynamic ETA withdrawn after the connection, the subscriber is assigned or the standard period of time at the request of the user. To keep the number of Dynamic ETA on standard tube must be able to update your primary file Non-specific dynamic ETA and ACS needs to let the CA containing the ETA, and assign CA tube, as described above.
Using the ETT as these digital credentials.
SFI can be used as a digital ID card, including all identifying information required for the specific purposes of verification, authentication, and authorization of transactions.
Encryption using the shortened sessions of key pairs. For
encryption acceleration streaming sound and image in real time, subscribers can use short session key pair. For this purpose each subscriber:
- Generates a new pair of short keys (indoor and outdoor)
- The private key is stored in a secure partition the internal memory of the Subscriber and is used only for a single communication session
- Each subscriber encrypts new short public key using the original private key, sends the Subscriber or by the Original Public Key, the receiving subscriber, and transmits encrypted so short public key to the receiving Subscriber
- The receiving subscriber decrypts the message containing the public key of the opposite short Subscriber, and uses it to encrypt / de encrypt data interchange (streaming data) is sent to the Subscriber.
Or alternatively:
Each of the subscribers to create a couple of new short keys in such a way that short the public key of each Subscriber is an easy number to some of the bank nearest to the lack or excess to the number of the ETA (or number is calculated on the basis of the ETA established network method), and the proximity to the number of ETA determined by the current network security policy, and short covering key Each subscriber is selected so as to be practically very difficult calculated.
Thus, using the current network security policy and ETA number subscribers, the network can be calculated as their own short public key and a public key of the opposite short Subscriber without the need to exchange public keys with each other.
Thus, each subscriber has a short public key
Subscriber opposite and uses it to encrypt / decrypt data exchange (streaming data) from the opposite Subscriber.
It is clear that the PKI Subscribers can encrypt messages (streams) in two ways:
175 using the private key sends the Subscriber to obtain a subscriber decrypts it sends the public key of the Subscriber. The encrypted message in this case can be decrypted by any subscribers with the public key is sent Subscriber, and privacy of correspondence is not guaranteed
176 using the public key of the receiving of the Subscriber to obtain a subscriber decodes the message using its private key. The encrypted message in this case can not be deciphered by anyone other than the receiving subscriber and privacy of correspondence GUARANTEE
Business Model 1: ETA sales rooms, which are valid for a certain period of time or the number of services provided or to a certain amount of money and so on.
Business Model 2: Sales of digital certificates, where the number of verifiable ETA is the main part of the certificate, the privileges include the conditions of use, which are valid for a certain period of time or the number of services provided, or for a certain amount of money and so on.
Business Model 3: Sale of SFI with a constant number ETA to the subscriber or permanent without permanent ETA non Interim subscribers.
Business Model 4: Sale of media carriers (SIM card for GSM and later standards 3rd generation connection (3G standards), CD, DVD, or other media carriers) to SFI files written to media.
Business Model 5: Sales of recordable memory chips or processors SFI files recorded in the memory.
Business Model 6: Sales of SFI as a digital identity card.
Business Model 7: For Sale "permissions" ETA rooms and / or file number (transaction search Primary URL of a known ETA number / file number) with payment for each "permission".
Business Model 8: Selling Rooms ETA and / or data file number to third parties for the provision of pay-per-ETA and / or data file number.
Business Model 9: Sale of Services authentication numbers ETA and / or file data Non-pay-per-authentication.
Business model 10: Selling Services Authorization of payment by number of ETA and / or the data of the file number to the pay-per-authorization.
11 Business model: selling development tools (Software Development Kit-SDK), implements the functionality specified in the use of ETA application methods.
Learned and professionals will appreciate the possibility of using records Credit card (CCZ) or bank account records, encrypted using a private key authorization center. This implementation provides the ability to limit to one the number of parties that can read the CCZ, and this is the only party authorization center. Because of this, this implementation provides a robust security when carrying out transactions, and protection against theft with the highest level of security. Another feature is that this implementation allows existing conventional device authorization of payments with the use of the main types of credit cards and so does the implementation of the claimed method is a very inexpensive authorization. Encrypted ETA-CCZ (3 ETA-CCZ) makes the authentication twice more robust, allowing to compare ETA extracted from the 3-ETA-CCZ with ETA extracted from the CA.
Learned and professionals will appreciate the possibility of using Encrypted billing records (ZZS) obtained by encrypting the billing records (AP) using the public key of the authorization. This implementation allows you to limit to one the number of parties that can read the AP, and this point is the authorization center. Because of this, this implementation provides a robust security when carrying out transactions, and protection against theft with the highest level of security. Using a public key to encrypt the authorization center ZZS and CCZ also allows any third party to encrypt or ZZS CCZ and thus allows an unlimited number of sides safely and reliably protect the records of customer accounts and join the use of the authorization center services in this way.
Learned and professionals will appreciate the fact that thanks to the release of the Digital Certificate Account (SSC) containing ETA (Single Transactional Address) of the network resource, and public key resource and ZZS resource CA / CA (authorization center, and he's Certification Authority - before and Administrator called Digital Certification - ACS) is the possibility of "on the fly" to authenticate a particular network resource, and check the right of this resource on the use of specific ZZS, safe and reliable comparing ZZS such resources for the provision of services to secure transactions. This, in turn, allows the CA / CA to avoid the creation, management and security content of the database, which establishes the correspondence between the ZZS / CCZ and ETA specific network resource, and the latter circumstance, as a result, allows the CA / CA to avoid the costs associated with the presence of such Database. On the other hand, the lack of a database allows CA / CA rid of possible errors security content of financial and personal data database.
Another feature is that ZZS allows the use of conventional existing infrastructure authorization of the main systems of credit cards, and so does the claimed method is very inexpensive to implement, virtually bringing the needs of CA / CA to the presence of a single POS (point-of-sales) terminals and use a single account Seller (merchant account) of receiving and processing credit card payments.
Using ZZS along with CA allows to share the responsibility in providing certificates and authorization, as well as creating conditions for the distribution of various ulsug without compromising security during transactions.
The independence of the technology of ZZS from the domain of the data type and origin of the account (bank, account service provider, credit card bill, and so on) makes the process unique universal for the accounts of any nature, including but not limited to, bank accounts, credit card systems, accounts Customer service providers, biometric accounts and any other accounts.
Another feature is the ability to encrypt the PIN (personal indentification code) code or the password of the resource, using the public key from this resource that allows resource independently create, modify and manage passwords as a means of protection against theft, protecting the resource when it is used to carry out transactions.
The infrastructure of the transaction
The infrastructure of the transaction as an example is shown in Figure 10 and contains the network resources in 1000, each of which is assigned an identifier ETA (Single Transactional address), network of financial institutions 1001 and 1002, each of which is assigned to the identifier of the ETA and infrastructure authorization and clearing 1003. Each network resource is a payer or payee and financial institutions are the providers of financial accounts (banks is preferable) for the specified payee and the payer, and the infrastructure is a system of authorization and clearing of transactions, which is in accordance with the illustration of a settlement (clearing) the financial institution providing clearing accounts given to 10 other financial institutions.
Specified financial institutions assigned Shuttle ETA (META). Each ID is a common META specific ETA or ETA. META available are assigned, are arranged and indexed in the database server Switch (core switch).
The described method involves the creation of specific "zero-based" META system identifiers. This method allows to assign zone "zero" country code comprising 100 billion available numbers, in particular, the number of "full ground" + 0-000-000-0000; and a "zero zone", such as + 7-000-000-0000, containing up to 1 million rooms available for each country; and the "zero-based" array of numbers in every region of each country, which up to 1 million additional ETA numbers for each area code, such as an array from + 7-095-000-0000 7-095-099-9999 to + specifically for the purpose authorization in the region of Moscow, Russia. For example, in a Global IDs Registry ETA or Global Clearing House transaction and Authorization 1101, as shown in Figure 11, can be assigned from among the identifiers ETA "full ground" and to the local node authorization may be used such as ETA zero of the country, region or number, starting from scratch, such as for example the 000-oooh.
Similar to the banking system of the ETA financial account specific resource for global addressing and availability of the ETA should include both the resource itself and META number of financial institution in the network and therefore the global routing number will be META / ETA format. For example recording + 7-095-000-0000 / + 7-095-123-4567 might mean that resources related to Russia and the region 095 of Moscow, has an assigned identifier ETA + 7-095-123-4567, served financial institution, located in Russia, in Moscow and the region 095 having an assigned route ID META + 7-095-000-0000.
In the same manner it may be referred to correspondent relationships between banks, forming a "complex" META, META containing sequence numbers corresponding to banks. For example, as shown in Figure 10, META2 / META1 / ETA will mean that a particular resource ETA is a client of a particular bank META1, and the bank has a correspondent META1 bank account META2. It allows you to organize a very simple route system addressing by placing appropriate route META information in the resource file. It also allows you to create an infrastructure in which regardless of its location or resource bank each specific resource can choose any particular bank to service their own accounts, and use a variety of bank accounts and credit card accounts.
In each area code of a specific country financial institutions can be indexed using conventional ETA, although the system META identifier is preferred and allows sequential numbering, in which the first assigned META within a particular area code is "0" as the value of the rightmost digit, the next " 1, "the next" 2 "and so on, the number is completed before the size of the full telephone number by adding zeros on the left. Last ETA in this array began to "0", meaning only the numbers continue to "9". Therefore, for example, the first META assigned to Russia in the region 095 in Moscow, would have been + 7-095-000-0000, and Second + 7-095-000-0001, + 7-095-000-0002 and following the last 7 + 095-099-9999.
The above "zero" method of assigning numbers META allows "zero" for the number of services of transaction and to create a database META rooms with sequential numbering. This array of available rooms starts from 000-0000 to 099-9999 for a 7-digit telephone numbering and providing up to 1 million available routing number within each area code of each country.
The invention makes it possible to address a simple payment, in which the payer or the payee only need to know the appropriate number ETA to provide simple routing transaction or payment between the recipient's bank account and Payer. The invention provides a universal approach in which financial institutions are network resources with IDs ETA assigned to them, the financial institutions may receive payment orders signed by the participants of the transaction to authenticate the payer using ETA particular resource, and make payments from a bank account belonging to the ETA specific resource Payer.
All financial institutions must have a META numbers and comply with the requirements of the transaction locks to ensure the flow of transactions through the infrastructure of ETA / META conduct transactions. Gateway also must provide the ability to compare real-time extensions of the accounts with the relevant identifiers ETA their respective owners or internal numbering system should be built based on the numbering of ETA, which will use authentication ETA as the main part of the payment authorization process.
As shown, the invention can be used as identifiers ETA and for routing purposes. ETA is a higher identification layer disposed over the traditional routing systems to the Internet and communication networks and for the financial infrastructure. Therefore ETA layer expands, unites and unifies addressing in the Internet and telecommunications networks, and addressing financial exchange and routing, it also creates a universal transport layer ISO / OSI for the network resources of any nature.
The infrastructure of clearing and authorization
After making the payment from the bank account of a particular Payer Payer's bank shall transfer the funds to the payee. Therefore, between financial institutions there should be a settlement center (clearing center) conducting inter-bank settlements.
In one embodiment, shown in Figure 12, the system can utilize existing infrastructure, such as based on the numbering SWIFT or national numbering, such as for example the numbering of American Bank Association (ABA) FedWire system in the USA, or numbering, based on Bank Identification Codes (BIC) in Russia or other numbering systems intended for inter-bank clearing and exchange. This performance of ETA IDs can be mapped to existing IDs SWIFT, ABA, or numbers, or numbers BIC or other routing IDs and corresponding substantive information.
Alternatively, the system of authorization and clearing can be created as an independent Chamber of clearing and authorization (PCD), which uses unified ETA procedure for authentication between the payer and the recipient banks using their respective META number of banks as the main part of the auditee.
Another implementation might not include RCA and on the other hand could be built through bilateral agreements on authorization and clearing between banks, in which the payer's bank can directly connect to the beneficiary's bank, and after mutual authentication to transmit a signed payment order to the payee and to carry out clearing operations described herein.
Digital agreement on the transaction
Any agreement may be concluded between the resources by digitally signing the relevant content. To the Agreement are and payment orders, invoices and other documents, the authenticity of the signature of the creator by which is verifiable. Digital agreements signed using a digital certificate ETA, are preferred in the framework of the described method.
Online Services of transactions - are those during which the payer and the recipient are available in real time.
Online Services conducting transactions using PKI and digital signature to authenticate the transaction.
Using META identifiers can be realized by placing META rooms along with the encrypted billing records (ZZS) or without placing the last attribute in the CA or CA (ACS). Multiple accounts can be "allowed" (meaning technique permits the network names / addresses / identifiers) and operated, using the infrastructure of ETA called for each network resource. To create the possibility of managing multiple accounts corresponding to a particular resource META number of specific financial institutions should be placed in the CA or the ACS resource. Therefore, at least ETA particular resource identifier, its public key along with the identifier META financial institution servicing the account of a particular resource should be placed in a digital certificate, or the CA attribute, creating the possibility of incoming and outgoing payments for specific accounts such resource.
We distinguish three types of agreements signed digitally:
Agreement on Transaction
SS contains digital certificates and / or ACS both sides of the transaction and the agreement itself buy digitally signed an agreement to sell Buyer and digitally signed the Seller and the amount / currency transactions.
Payment Agreement (SS)
PS is an agreement to pay, digitally signed Payer; PS comprises at least CA Payer, ID ETA, and the sum value and the currency of payment. PS can be absolute or contain details of payment.
Electronic Payment Agreement
This agreement is issued and signed by the financial institution for the interbank exchange and comprising at least an agreement SS or SS, signed by the client of the financial institution, the CA of the financial institution and the sum / the currency of payment and other necessary information.
The proposed method comprises providing at least three types of services:
- Agreement on Transaction - is when both parties to the agreement have to sign an agreement to conduct a transaction that reflects their counter-agreement to buy and sell;
- Payment agreements - this is when any network resource can accept unconditionally or caused by something the decision to hold the payment in favor of another particular network resource;
- Electronic Payment Agreement - an agreement between the two financial institutions, allowing them to conduct counter payments and make them cleared.
Transaction Agreement is used for both B2C and B2B for the types of transactions between individuals.
For example, for e-commerce in the Internet, for ordinary shopping in a supermarket, petrol stations and wherever the cashier gets the money entering the ETA customer ID as a payer into the POS terminal and the customer will receive a bill for its network device and authorizes payment through the introduction of authorization password in your network device. Agreement on the deal could significantly simplify the payment for telecommunication services, when the service provider initiates the payment by invoice (the requirement of the payment) directly to the network device of the client and end user devices simply authorizes payment by entering a password authorization.
Agreement on the deal could serve for B2B, providing services to conduct transactions in real time to network devices of different companies scattered around the world.
Agreement on the deal could also simplify the transactions between individuals, related network and located in different parts of the world at the time of the transaction.
Generally. Agreement on the Transaction during the transaction allows the payer and the recipient to sign a binding agreement by the parties for the supply of goods, services or information for payment, creating a legal basis for the transaction and, therefore, each party receives the necessary legal protection.
Payment Agreement is used for transactions in which the payer may be caused by something or unconditional intention to transfer the funds to the recipient's account. PS is used when the end user needs to transfer funds to someone else. This service can serve as a replacement line, such as services provided by the offices and representatives of the company "Western Union".
Using the "ETA CCZ"
In order to make payments with a credit card the described method involves the use of ETA identifiers for credit cards and other media containing readable identifier ETA used to record credit card bills. Payment may be made if into the POS terminal has been entered and confirmed by a secret PIN, the appropriate identifier ETA particular resource - Payer.
Example ETA payment at the supermarket.
When a buyer purchases a basket full of coming to the store cashier, the cashier said the value of purchases by reading bar codes with purchases or by hand or by other means, and receives the full value of purchases.
Then, if the customer prefers ETA method of payment, the cashier enters or ETA customer number into the POS terminal manually or reads barcode ETA disposed on the surface of the buyer's mobile phone or credit card of the buyer, or the buyer on the business cards and so on. Mobile phone buyer may be able to display the barcode ETA on the display. Barcode ETA numbers read conventional bar code reader, POS terminal seller store.
Then the cashier confirms ETA, and then enter:
Real-time mode:
POS terminal sends a message asking you to pay for a purchase on a mobile phone buyer, the phone receives a message and shows the authenticated identity of the Seller, the payment amount and the question "accept" or "reject" a payment.
The buyer chooses the "accept" and enter your secret password to confirm the payment.
The cashier and the buyer gets the message - proof of payment of the authorization center to the POS terminal, respectively, of the seller and the buyer on the mobile phone.
Confirmation is saved and the transaction is completed.
In this example, the phone may be able to receive from the POS terminal and also a shopping list, including their cost, barcodes purchases goods image, weight, price per kilogram, and other characteristics of each of the goods purchased. The phone may also be able to save the resulting data to be used next time a customer wants to repeat a package in respect of selected items from a list of them.
The phone can also be able to manage multiple bank accounts and credit card accounts, allowing the user to select one of the accounts for the particular transaction. The procedure for using the default accounts can be such that there will always be used by a particular one, and every next be used only when the previous one may provide for payment.
Off-line mode
When the mobile phone buyer can not be used to carry out transactions in real time (for example, the battery is low, or the buyer forgot your phone at home) after ETA buyer introduced as ETA payer memory POS terminal to conduct transactions in off-line mode The terminal offers customers to make entering a secret password by ETA. Optionally, the cashier, POS terminal can send to the network core switch ETA number, get the show on the display and POS terminal ETA personal data of the owner of the hotel, including its photo, name and other descriptive information. Then the cashier can require the buyer to present a document proving his right to use ETA identifier.
The customer enters a secret code and confirms its ETA. Password Check is carried out through the described authentication system, and if the password is correct, and authorization is obtained, the POS terminal receives the authorization message and displays it on the screen to the cashier and the customer. The same authorization message is sent to the phone buyer, upon ETA number for future reference.
Confirmation of the transaction is stored and the transaction is completed.
An example of using payment services ETA payer
Payer chooses the payment transaction in the interface of the phone. The payer enters ETA Payee in the appropriate field on the display.
The payer selects currency and enters the value of the transaction amount and purpose of the transaction, if necessary.
Payer confirms the payment.
Payer enters the secret password to confirm the transaction.
Payment is carried out after checking the password and if the password is correct.
The payer receives authorization from the network, and this message is displayed on the display to confirm the completion of the transaction.
The recipient receives an authorization from the network as a notification informing that his account has been credited, and also contains the authenticated number ETA payer and purpose of the payment, if any.
Confirmation is saved and the transaction is completed.
The procedure for clearing and authorization
Assume that the financial institutions are banks.
When the payment order is made and sealed with a digital signature of the sender, the message is sent by the payer to the payer's bank META. However, it may also be a bill. This message (invoice, payment order) may be sent instead to the payee or the payer or the payer's bank and the beneficiary, without making significant changes in the procedure for authorization and clearing transactions. The payer's bank authenticates the digital signature of the payer and, if it is authentic, it extracts the transaction amount and methane / ETA number of the recipient, or at least ETA recipient's number, which is then "allowed" full number of META / ETA through a central switch (Switch-server) , the transaction is completed in keeping the bank at the expense of the recipient ETA described above.
Using the existing clearing system
Upon receipt of the Payment Order the payer's bank may allow the META through Central Switch (CC) in, for example, SWIFT number or other identifier of the routing of the beneficiary bank, and then make a payment using the relevant international or domestic means of routing and clearing agents or third parties. This method allows you to use the existing infrastructure of clearing and routing and provides a very low-cost implementation of the method of META / ETA payments as described.
If you are using the existing clearing SWIFT system or the other, in the file META appropriate financial institution must be paid corresponding to the address information of SWIFT or other routing and clearing. During the transaction sender and recipient of payment instructions are exchanged META data, taken from your own files ETA or its CA or SSC. Next payer gives his bank META / ETA route recipient and the bank authorizes META through the Central Committee, the Central Committee of getting ordinary SWIFT number or other identifier of the routing defined for the beneficiary's bank. This allows the bank to the payer's bank to complete the transaction with the recipient in the usual way. In this case, a preferred embodiment of the system assumes that each file ETA and its copies, CA or SSC should include methane as the sole information to route payments to the Central Committee could not take a commission for conducting transactions, since the lack of conventional bank details in File recipient will force Bank Payer apply them to the Central Committee to allow methane to the recipient's account details. In that case, the Central Committee could take a commission for permission to META rates and may require each bank of the payer to provide information on the Central Committee of the transaction and its amount, to set the commission based on the amount of the transaction.
Using the clearing system META rooms
When the payer's bank receives the payment order, the bank creates its own bank payment order, which signed its digital signature. Preparation includes at least sum and META / ETA routes payer and payee ETA or their number. After that, the payer's bank is permitted in the CC META number of the beneficiary bank in the URL of the beneficiary bank. Then the payer's bank creates and signs a payment order of sender establishes a connection with META RCA and the beneficiary's bank. Parties mutually authenticate each other and to the payer's bank sends the payment order to the PCA.
PKA authorizes or rejects the payment order authorization form signed by a digital signature PCD. If the balance of the clearing account of the bank sender allows you to carry out the operation, the PCA credits the beneficiary's bank and debits the sender's bank account in the amount of the transaction and clearing fees for transactions. Authorization PAC sent to the addresses of the beneficiary bank, and the bank of the sender. If the authorization is granted and authenticity, then credits the recipient's bank account, as the bank debits the sender by the sender in the amount of the transaction and the corresponding commission.
The implementation of the ATM
Methane can be assigned to the ATM and the team "request cash x" may come from the ATM user to write off the money from any other network resource that is also assigned to the ETA, and after authorization of the transaction by the user ETA cash resources will be provided to the user of the ATM. In accordance with the foregoing POS terminal may be configured as described ATM.
An example of an ATM cash withdrawal according to the invention can be the following:
The user selects an ATM cash withdrawal with the use of the ETA;
ETA Introduces Keyboard ETA or enters a plastic card in the ATM receptacle for reading data ETA; ATM asks the user to enter a password and, if authorization is received, the ATM dispenses cash.
Machine can be equipped with a telephone or videophone, allowing 'live' authentication voice and image, where the payer (the responder) can see and talk with the recipient (the connection initiator) during payment authorization, after which the recipient receives the money from the ATM, if the payer I have authorized such issuance. The recipient and payer are different people or one person.
Business model
In the above cases, the authorization center can act as RTA for the registered banks, and may also have a database "resolution" is set appropriately for each specific META relevant detail specific routing and clearing fees and information about the balance of the clearing account of the bank.
Reception fee produces META number of banks and other financial institutions, and takes a commission of the Central Committee resolution service META rooms in the routing information, authorization and clearing.
The Commission for the conduct of the transaction may have an interest or a fixed amount, or have an interest and fixed components at the same time charged for clearing transactions (commission per transaction, and the Commission, depending on the transaction amount).
The Commission for the conduct of the transaction may also depend on the distance between the payer and the payee by analogy with the board for long-distance and near telephone.
The invention comprises a method of creating, issuing and management of digital certificate authorities (CAs), providing a multi-level model of distribution and access to many accounts, based on the use of CA and public key infrastructure (hereinafter PKI - Public Key Infrastructure). Different embodiments, described below, but they are not given as limitations of applicability of the invention, but merely to illustrate it.
The distributed architecture of the distribution of identity services. Certifying services (services CA), based on the use of CA and PKI, widely available and companies like VeriSign and others. Typically, these providers of services do not recognize the identity CA issued its competitors. This leads to undue market segmentation and lack of interoperability of identity services on a global scale. The latter circumstance prevents the use of identity services and users as a result of the business of certifying centers (TC) is suffering from a lack of penetration in the focal market.
The invention provides a method of distribution through a network identity services, which Certifying Center "Tier One" is a proxy for all of the lower levels, and the lower levels are a "reinsurance" to the upper levels, with which they are associated. At 16, the lowest level of Certifying Center "Tier END" sign digital certificates DCEND for its users and addresses the certifying center of higher level "Tier (END-1)" for the exchange of CA issued a new one. CA "Tier (END-1)" uses DCEND, signed by the CA "Tier END" as a request for the release of the Digital Certificate (the Certificate Signature Request or CSR), and CA "Tier (END -1)" retrieves data from CA and sign DCEND it using his Private Key (END-1), releasing thereby the digital certificate DC (END-1), which is then transmitted to the CA "Tier (END-2)" and there processed in the same manner as described above, and so on up the chain of CA when the CA will be achieved "Tier One" and the latest digital certificate DCTierOne be released. Issued CA "DCTierOne" then returned to the user through a chain of participating CAs or directly on the device and placed the user on his card or otherwise placed in the memory chip or processor, or a printing method is applied on the surface or written to media by other means.
This distribution model is based on a legally registered relationship of trust between the upper and lower levels of TC, creating the conditions for receiving the certifying center of the upper level of the CA issued by the CA of the lower level, with each CA issued by the CA of the lower level, it is perceived by each CA top level as a CSR for the issuance of the CA more high level. This model allows you to delegate responsibility for inappropriate content CA those issued CSR, on the basis of which was released on the relevant CA, that is, to delegate responsibility to the upper levels of the hierarchy of CAs, starting with "Tier One", on the lower levels up to "Tier End", who is responsible to the upper levels of the verification of user rights to use specific resource identifier (IR), a billing record (AP) and encrypted billing records (ZZS) in the application by CSR. This extension provides the necessary protection for the upper levels, protecting them from error and fraud, negligence or deliberate actions of the lower levels when checking the user rights to use specific R & D, ES and ZZS.
Propagation model provides the opportunity to participate in the issuance of an unlimited number of CA CA different levels, while allowing different CAs each level to compete with each other. The model also provides the possibility of replacing the CA issued by any of the authorized CA on the CA, the CA issued the first level "Tier One", thus ensuring scalable and globally interoperable, based on the recognition of the CA, the CA issued a single top-level "Tier One".
This architecture also makes it possible to replace the CA when a new provider of low-level Tier END (N) can add a field to its services in the existing CS user, and to request the replacement of the old CA to the new matter to which of the CA that user applied for CA release first or immediately before.
Contents of CA
Each CA includes subject areas, and each area contains certain fields. CA preferably uses an XML format and subject dialects. Subject segments can be connected to communication services, personal data, financial, social, biometric, security, services of credit rating and other subject areas. Specialization can also be only one.
Each region preferably comprises one of the fields: Resource Identifier (MI), or billing records (AP) or encrypted billing records (ZZS), or their composition, wherein:
- AP is the account or the name or identifier or recording of any kind, meaningful for the specific purpose of using the service provider. AP is not encrypted. In one of the preferred embodiments of the AP is the credit rating of the user, which is based on the use of the financial area CA of AP. In another embodiment, the AP is the name or other identification of the user. In another preferred embodiment, the AP may or route identifier and / or the account identifier, which is a full record of the financial account; or a key word or code that is meaningful to a specific service provider.
- IR is a unique alphanumeric identifier that matches the specific telephone number or ENUM (http://www.ietf.org/html.charters/enum-charter.html), or ETA (single telephone address), or to the DNS name, or other well-known network ID, provides network interoperability and global access to network devices of any type. IR is a subspecies of the AP, it is not encrypted, and used for telecommunication purposes and authentication. IR may contain additional information attached in the form of the AP or ZZS. IR field can be combined "difficult" TS1 / TS2 / NIHD, thus reflecting such correspondent relationships between banks. In one embodiment, TS is a route identifier and / or account identifier, which together form a complete record of the financial account, wherein one or both of these identifiers can be ETA.
- ZZS is the AP, which has been encrypted using the public key belonging to a specific service authorization center service providers, who created the CA or the CA service record containing ZZS. Therefore ZZS can be encrypted unlimited number of entities and decrypted only one authorization center having private key is a pair to the specified public key.
The preferred embodiment assumes that each CA is structured as shown in Figure 17.
In this design, each corresponding to a resource can be authenticated headed Title CAs. Title is a user ID.
The preferred embodiment involves the use of or just field values IR, or AP, or ZZS, and / or composition thereof for the title and CA areas.
LC and ZZS preferably used without IR, if the field or AP ZZS are some favorites provider IR device that is accessible by other means. Usually it is a local or global service provider with a local, global or standard means of access.
If AP or ZZS used service provider who does not know the default, then the IR service provider must be specified in the IR in order to provide access to its services. In the latter case, the complete filling of the area will require (up + AP) or (up + ZZS) or (up + FB + ZZS).
In the preferred embodiment the value of the R & D is used as the access address to the gateway service provider, the service provider is able to identify incoming calls by comparing the value of the header causes the resource to CA through internal accounting system provider. As the IR service provider may be used by the routing number of the bank (for example, methane or other address), as Header CA is the account number (ETA user number or a different address), which must be matched identifier bank account at the time when the user installs Connect to the gateway of the bank using the IR address of the bank.
ZZS is preferably used when the AP includes personal or other information that you want to protect, such as for example credit card information or other sensitive information that is not intended for public distribution. Assuming that ZZS is recording credit card (CCZ), the address of IR would be a network identifier Gateway Center Authorisation of payments using credit cards or bank that issued the card, or gateway address other related organizations. ZZS can also be a bank account, and R & D in this case may be the address of the gateway access to the bank. Otherwise ZZS can encode fingerprints or other sensitive information.
In another embodiment, a record of each service provider is located in a separate CA, all CA issued for a particular resource, have the same meaning Header CA and contain the same public key from this resource. Therefore, each of these CAs alone may serve as a means of authentication resources on the network and serve as a highly directional purposes for which a particular CA has been released. These CAs may be placed in the subject areas of memory devices and are available on the domain name that they serve. For example, subject folder Bank can contain all CA-related banking services, folders BANKJNAMED - with the names of the banks, and the folder CARD card can contain folders CARD_NAMED with the names of specific cards, which, in turn, kept the CA issued by various banks and Card service centers.
<img file="00000001.tif" he="40" wi="65" img-format="tif" img-content="undefined" />
This design avoids the replacement of previously issued CA with the addition of a new service provider and thus makes PKI easier to implement and manage. It also allows service providers to exercise better control over their services and account information, which is part of the CA entries in its production and distribution. It also allows you to control access to each specific CA relating to the particular domain at the level of storage management of a particular resource.
Implementation of smart cards and network devices.
In this case, the performance provides a multi-level distribution of the CA, as described above, and can be used as smart cards, and network devices, providing unified access to distributed services of the transaction, the service provided by a plurality of nodes of different service providers. In such an embodiment, each smart card and network device endowed CA using the architecture described distribution of identity services. The data of each CA are segmented as described above, and include fields for addressing and identification, facilitating a connection, authentication, and access to services of the transaction, provided by various banks and organizations engaged in cash management, credit card system, credit rating agencies and other organizations. Facilities using smart cards provide the ability to secure access to all financial accounts and cash management tools, whose field records are included in the financial area of the CA. Therefore, these services are independent of vendor services and universal. The owner of the smart card can carry out transactions with each or simultaneously with all their accounts, included in the CA through ATMs around the world, if the ATM support working through PKI and telecommunication channels, and / or use for their transaction network device for this purpose. Preferably, the smart cards are cards ETA, and R & D in the field of the CA is methane address a specific service provider. Smart cards can be cards with a magnetic strip or in any other medium, or memory chip, or processor, or network device, comprising CA.
This design provides simultaneous access to multiple accounts contained in the CA, through any terminal capable of using PKI. This allows the use of smart cards with ATM and allows the use of personal communication devices as a means to universal access to all existing user accounts. With regard to financial accounts, it allows you to upload and manage financial data account from any ATM using a smart card, and from any communication device, if the ATM and device support working through PKI. Using multiple accounts with authentication service allows you to organize the global credit rating, which collects statistics and data on the use of accounts and provides credit ratings for the respective service users. The invention allows the use of smart cards to control immigration. Examples of the use of smart cards:
Example 1: Assume that the value of the financial field 1 (up + ZZS) is (www.authorizationcenter.com/FREEDOM/gateway.htm + ZZKK VISA). Assume also ZZS encrypted public key specific authorization center payments by credit card VISA. When the smart card is inserted into the card slot of the ATM, the ATM removes CA of smart cards using and checking underneath the signature and using the Open klyuchTier One. ATM then retrieves and uses the network address www.authorization_center.com/FREEDOM/gateway.htm, to connect to the gateway authorization center, which belongs to the address. If the connection is successful, the parties make mutual authentication by providing their CC. The exchange value of the field becomes available ZZS authorization center (CA), ZZS stands authorization center, using the private key of Central Asia, and as a result CA has decoded Record Credit card VISA. Then the transaction is completed by withholding the payment amount from the account of VISA credit cards in the usual way via the infrastructure of the payment authorization VISA International.
Example 2: Assume the financial value of the field 1 (up + AP) is (ABA 021000089+ "Name"). In this case AVA021000089 (the numbering of the American Bankers Association American Bank Association) is the routing number of the bank Citibank in a federal system of payments FedWire. Therefore, the operation of a particular account may be after the connection to the ABA 021000089, mutual authentication and the search account with the name "Name" in the internal system of the bank accounts of CitiBank. If the appropriate internal account is found, the user smart card will be granted access to the account.
Example 3: Suppose the financial value of the field 1 (TS) is an ETA (+ 1-212-123-4567), which is a phone gateway bank. When the smart card is inserted into the card slot of the ATM and the IR address removed an ATM from a CA card, ATM accesses the bank, establishing the connection to the specified phone number, and after the mutual authentication of the parties between the smart card and the bank last extracts subject CA and looking for his correspondence in the internal System of Accounts. If the relevant headings by a CA is found, the bank provides access to the account found.
Example 4: Suppose that the owner of the card is drawn to the bank for loans; Assume also that the financial value of the field 1 (IR) is the ETA (+ 1-212-123-4567), belonging to the telephone gateway credit rating agencies (CRAs). When the smart card is inserted into the card slot smart card reader and address of TS read from the CA, the reader communicates with the CRA using the number of ETA, and after mutual authentication between the smart card and the AKP recent extracts from the CA card subject CA and looking for the appropriate headings through the internal system Accounts acre. If the appropriate account is found, the CRA provides a data card reader found the credit rating of the account; a credit rating takes into account the bank loans and on the basis of the obtained values of the credit rating of the smart card decision on lending to the owner or the refusal to grant the loan.
Example 5: Assume that the value of the financial field 1 (IR) is the ETA (+ 1-212-123-4567), which is the phone number of the Department gateway entry visas. When the smart card is inserted into the card slot reader Border Guard passport and visa controls and the value of the gateway address read from the IR Department field CA reader connects to the gateway of the Department, using the number + 1-212-123-4567, and after mutual authentication between the card and the Department He retrieves the last subject CA and looking for it in compliance with the internal database of the Department of visa and if the cardholder has a valid and unexpired visa, the card holder is given the opportunity to cross the border and enter the country.
Example 6: Assume the financial value of the field 1 is ETA (+ 1-212-123-4567), the financial value of the field is 2 (+ 1-303-123-4567), and the financial value of the field .... N is a (+ ZZS + 1-512-123-4567), and field 1 and field 2 contains the access numbers to gateways banks and field N is a telephone number to access the gateway authorization center payments on credit cards VISA, and ZZS in the N is encrypted storage of Credit Card VISA. When the smart card is inserted into the card slot of the ATM, the ATM R & D addresses are retrieved from the fields 1, 2, ... N digital certificate and then establishes a connection to the ATM gateways banks and CA VISA, using the appropriate address of IR access gateways. After mutual authentication with each of the banks and the Central Asian VISA each bank is looking for the appropriate headings in the internal systems of the CA accounts of banks and CA VISA ZZS decrypts using its own private key, and thus receives the relevant credit card account VISA. If you found the account, the relevant headings CA, and CCZ VISA exists and is valid, then ATM displays to the user smart card on display carrying information for each bank account and bank card VISA and allows a transaction through any of the accounts in accordance with the regulations of the Bank and the privileges of the card holder.
The use of network devices
Procedures for access, authentication and authorization of network devices using a similar procedure with the use of smart cards and ATM or smart card reader, perform the role of a network device in the above examples. Thus, instead of a CA card can be used by the CA network device (a network share), and instead of an ATM or card reader used alone network device or resource, which also connects to the gateways of banks and authorization centers using these identifiers TS Gateway.
Business model
The business model involves the sale of the CA and the services of its release. The model also involves the sale of the replacement CA.
In the context of the above, the present invention provides an architecture of the calculations performed via the Internet (priori), which can be performed as described below.
The architecture of the calculations performed via the Internet (priori)
Payment Units (PU). Payment nodes are nodes (management) network, the network address (identifier) of each PU is used as an identifier for the account corresponding to the UE. In respect of each payment or UE can be one of the open sites payer or intermediary node or nodes - the payee. Each UE has a unique network address associated with the UE; network address may have a phone number format and be ETA or ENUM, or be a www or e-mail address (e-mail), or any other appropriate network address that can be resolved by means of resolving network addresses to the appropriate network address of the primary clearing organizations or DSO (ie, clearing organizations, which is the default). Each PU can be both challenging resource and responsible resource in the process of execution of payment, and the caller node is both payer and Responder node is the Recipient during the atomically payments. The calling UE can be both the Payer and facilitator of "End-to-End" payments (hereinafter UMA), and recipient can act as a mediator or Recipient UMB.
ETA.
In the context of ETA priori understood as Single Transactional address. ETA is a unique identifier of the resource. ETA coincides with one of the network identifiers, such as a telephone number, www address, e-mail, IP, or other unique network address, or the name of a natural language. ETA or the same transaction identifier associated with the resources.
Atomic Payment (AP). Atomic payments are executed as a telecommunication connection point-to-point, then there is a transactional connection (hereinafter referred to as transactional call or t-call). T-call is a point-to-point at which the transactional instruction is created causing a resource in the form of a network connection, using parametric line notation namespace (namespace string), that is, the line containing the address of ETA Responding resource and a payment instruction containing specific parameters payment and digital signature Calling resource. For definiteness we will talk about the transaction as payment, although it can be any other kind of transaction. For simplicity, we also become assumed that a payment instruction is part of the namespace URN (eg, namespace ETA), and the payment instruction is for a question mark - "?" a URN Namespace notation (discussed in the example below). Preferred format line T-sa11 in the case described using the format described as a URN Syntax in RFC 2141 and RFC 2396, and can follow the approach outlined in the "Resolution of URIs Using the DNS" (RFC 2168), "Architectural Principles of Uniform Resource Name Resolution "(RFC 2276)," DDDS and Namespace Definition Mechanisms implementations "(RFC 3401, 3402, 3403, 3404, 3405, 3406). However, in spite of the requirements laid down in these RFC, mentioned above, for simplicity, in the examples below, we do not follow the requirements of the syntax URL Syntax requirements. We also will not indicate the ports, thereby simplifying the syntax namespace although various ports can be used to separate network connections transmitted in order to transmit the payment instructions from, for example, network calls transmitted purpose of browsing the Internet, as the use of the same namespace but different ports facilitates the separation of data streams for payment applications and applications that provide navigation to the Internet, but in this case is difficult to understand the meaning of the present invention. For vending machines (vending machine) the use of ports in the notation would be to use the same DNS address and port 80 for example to access the Internet server of the vending machine to view buying drinks available, such as port 88 for payment of the bought drinks with the vending machine under consideration.
With respect to the namespace and its administrative domain (referring to authoritative domains, that is, the domain that has administrative rights over a set of domain names its own area of ownership), using an analogy with the DNS, Atomic payment may be either upward to the root domain (TLD ) or downward to the host (the lower level domains) within the area of ownership (authority zone) of the current domain.
For payment transactions connection parameters can be the sum of the value of the currency of payment, the purpose of payment and so on. The parameters may also comprise a method of clearing the identifier (such as, for example clearing a real-time or offline) Caller preferences and other resources in the form namespace:
PAYEE_UTA? PAR_1 = VAL1 & PAR_2 = VAL2 & ...... / PAYER_UTA / PAYER_DIG_SIGNATURE.
The contents of the payment, for example, to foreign recipients can also be defined and the method of payment, such as the use of SWIFT instead of the local clearing bank or a clearing house.
For example:
THE DEFAULT CLEARING.com?payee.com/credit/USD/1000/ON/payer.com/Kjnkethab kjdlkcmncv
In this example:
THE DEFAULT CLEARING.com is an identifier of the JCE
payee. com is ETA identifier of the recipient (both the network address and account ID)
Credit - means an operation crediting the account of the Recipient
US - means the payment currency (US Dollars)
1000 - is the sum of payment
ON - means a requirement to conduct clearing operations in real time
payer.com - ETA is the identifier of the payer (both the network address and account ID)
Kjnkethabkjdikcmncv - is alleged the digital signature of the payer.
Another example:
credit.THE DEFAULT CLEARING.com?+l-('212H23-4567/USD/1000/+l-(202H23-4567/Kj nkethabkj dikcmncv
in him:
+ 1- (212) -123-4567 ETA is a recipient ID (phone number or ENUM) and
+ 1 (202) is -123-45b7 ETA Payer ID (phone number or ENUM).
In the future, we will call the "t-call string" notation following payment instructions:
credit.THE DEFAULT CLEARING.com?payee.com/USD/1000/ON/payer.com/Kjnkethabkjdl kcmncv.
End-to-End Payment (UMB). UMB is a payment, starting on the payer and the ending resource in the resource Recipient. UMB can be atomic delivery, but is generally understood as a chain of successive payments involving resources payer, recipient and intermediary. UMB flows skoz chain resources intermediary from the payer to the recipient in the form of a sequence of atomic charges, implemented as a series of t-call point-to-point. For every payment of atomic both resources (nodes) that are parties to the payment, the architecture should support trust relationships (ie use of PKI), to enable mutual authentication of the parties atomically payment.
Client. The resource (node) Client is a resource, which is the lowest level of the hierarchy in a tiered infrastructure clearing and therefore has only one customer relationship with maternal levels of clearing and has no child relationships. Because the client does not manage its own domain clearing the permission of the client database does not contain any client identifiers ETA and ETA contains only identifiers of parent clearing domains. Therefore, all of ETA referred to in connection t-call customer always displayed in the ID ETA owned by OKO ETA for any particular expense of the resource ID, and then the client sets the t-call connection using the appropriate ETA identifier belonging to the JCE.
Clearing organizations (FBOs). Clearing organizations are clearing organizations and routing of payments. KO usually serve as an intermediary during the UMB, but can also act as a client, as a resource payer or payee UMB. In terms of providing transactional communication services (meaning the area of transactional telecommunications) each CO is understood as a switch - the domain namespace, which contains a database of address identifiers ETA owned subsidiary CA and client resources (hosts in a similar DNS), for which the current CO OKO is. Similarly to the distributed architecture of DNS servers provides DNS resolution of names to IP addresses, at which the parent DNS servers (authoritative DNS server) holds address information for resources registered in the area of responsibility (meaning "zone of authority") of the DNS servers.
Each OKO may be a child QoS resources for its respective parent KO top level, such as the settlement and clearing of the House, correspondent banks, and so the case, as a subsidiary of CA, as a customer for the parent CA should use the parent CA, and maintain methods of communication and clearing specific for this JCE.
Mokoena. Each KO low-level defaults can use the services of a certain CO top level, which is why a parent OKO (Moco).
EYE. Each client resource utilizes at least one basic QoS (JCE), however, the customer can be account holder (host) simultaneously for several OKO (domain namespace).
Infrastructure clearing.
18 illustrates a multi-layered structure of relations between the parties to the clearing operations, and name resolution clearing where
⇒ Client # 1 is the owner of the account in one bank CF # 1, located in the US; CF # 1 is a client OKO (COCO) for the Client # 1.
⇒ Client # 2 is the owner of a bank account CF # 3, located in Russia; CF # 3 is KOKO client Client # 2.
⇒ Client # 3 is the owner of a bank account CF # 4, located in Russia; CF # 4 and # 5 are CF KOKO client Client # 3.
⇒ CF # 1 is a bank located in the United States; SWIFT and the American Bank Association (ABA) is Moko for CF # 1 and have different ways of clearing.
⇒ CF # 2 is an international clearing network SWIFT; CF # 1, # 3 and CF CF # 5 are subsidiaries KO for SWIFT, a SWIFT, in turn, is Moko for each of them.
⇒ CF # 3 is a Russian bank; SWIFT is Mokoena for CF # 3.
⇒ CF # 4 is a Russian bank; CF # 3 is Moko (correspondent bank) for CF # 4.
=> CF # 5 is a Russian bank; SWIFT and CF # 7 are Mokoena for CF # 5.
⇒ CF # 6 is the clearing house of the American Bankers Association ABA; CF # 1 and 7 CF # are children clearing domain ABA.
⇒ CF # 7 a bank located in the United States; ABA is Mokoena for CF # 7.
18 shows that the Client # 1 can transfer money (to make a payment) to the client Client # 2 using only one route:
(Client # 1 → CF # 1 → CF # 2 → CF # 3 → Client # 2).
If the Client # 1 would like to transfer the money to the client Client # 3, he could use one of the alternative routes:
(Client # 1 → CF # 1 → CF # 2 → CF # 3 → CF # 4 → Client # 3) or
(Client # → CF # 1 → CF # 2 → CF # 5 → Client # 3) or
(Client # 1 → CF # 1 → CF # 6 → CF # 7 → CF # 5 → Client # 3).
In carrying out operations in accordance with the present invention can support a priori, for example, the principles set out in the "Architectural Principles of Uniform Resource Name Resolution" (RFC in 2276), or the like, and the network addresses may match the account identifiers.
Clearing Cycle. The cycle is a clearing procedure for the payment of atomic, performed a KO. Each DA settles atomically payments under certain of their agreements, such as the requirement of a positive balance or requirement on the amount of customer account balances or other rules of the clearing. Clearing the cycle as a step cycle includes address resolution, which is an important part of the cycle of clearing. During Clearing Cycle CO:
⇒ receives a call t-call from the calling of resources (from their own customers or subsidiaries KOs)
⇒ Authenticates calling resource by its ID ETA and digital signatures,
⇒ Verifies compliance with the applicable requirements of payment options payment syntax and other conditions, and if the requirements of the regulations made produce
○ Cycle permission. QoS allows the Recipient ID ETA ETA identifier of the next KO (RMS), which is either the JCE for the recipient, or for the current CO Mokoena.
⇒ debits the customer's account and credited to the RMS current in a clearing of the domain.
⇒ string Creates for t-call call, such as for example credit-NEXT_DEFAULT_CLEARING.com7pavee.com/USD/1000/ON/paver.com, wherein NEXT_DEFAULT_CLEARING.com a location for establishing a network connection, and the remainder is a copy of line t-call starting compound without a digital signature.
⇒ Signs own digital signature string parameter t-call call credit.NEXT_DEFAULT_CLEARING.com7pavee.com/USD/1000/ON/paver.com/digital_signature_of_CURRENT_CF.
⇒ Set the connection to the JCE, created using line t-call call.
The next cycle of clearing again uses the rules of clearing and creates the following t-call line, as described above, and so on, until the payment does not fall on the payee's bank account.
Database TO cycles for name resolution. Each DA is a Domain Administrator account (by analogy with the Administrator of the DNS domain name), and maintains a database permit the namespace in the "zone management" ('zone of authority ") of its Clearing domain. For example, each bank is clearing domain namespace for the accounts of their own customers (similar to the host for the DNS system), as well as to other banks (similar to the sub domain namespace servers in a similar DNS), which use the reporting bank as a correspondent bank to obtain access to maternal clearing organization under review the bank. In the latter case, the Russian bank may have correspondent account in US banks to gain access to the payments system FedWire payment clearing banks in the American Bankers Association (American Bank Association).
Database domain specific "zone management" sets the correspondence between ETA IDs registered in the region caused by methane resources KO identifiers. Database "area management" permits ETA caller ID resource identifiers corresponding META OKO that are in the "zone administration," or permits in the meta IDs subsidiary or parent OKO similarly to how organized IN-ADDR.ARPA Internet domain (see . RFC 1033) and search for matches in its database reverse addressing (see. RFC 1034 "Algorithm Names Server" as an example of execution). If called ETA can not be resolved within the current clearing domain identifier OKO (that is an outcome of the search corresponding identifier OKO negative), the ETA caller ID resource should be allowed by default ETA ID Mokoena (root namespace server) of the current DA, respectively, with certain the parent domain for the payment method. Table 8 shows a simplified example of a database table, resolves <Called ETA + method> → <OKO ETA>.
Each CA must include resolving the database in which each client identifier ETA mapped to the set of his ETA OKO different clearing method used and all the ETA, not belonging to customers will be allowed to ETA Mokoena, using the specified method of clearing. The method of clearing a parameter in a line of T-sa11, providing resolution, the result of which is a unique identifier of the JCE or ETA Mokoena for each unique pair of "unique ETA + unique method." The database is used by default only one method, each unique ETA will have a single unique OKO ETA as a result of authorization if ETA called the resource is contained in zone administirovaniya current domain, or be allowed to Moko ETA current domain if ETA calling resource is not a match in the database resolution.
Table 8 shows the table clearing resolution database where ETA each called a resource is permitted for children KO and customers in the JCE based method of clearing and for all ETA resources that are not clients of the current CO ETA resources will be allowed in a particular ETA Mokoena current CO with specified method of clearing. A variety of methods of clearing can be maintained, for example as it is used to address family identifier (Address-family identifiers - AFI) for RIP-2 (RFC 1723), or by using other known techniques.
Table 8ZaprosVyzyvaemyyETA1Vyzyvaemy ETA2Vyzyvaemy ETA3 ... Called ETANLyuboy ETA, that is not a client or domain subsidiary KOMetod1273 ... NL123 ... KOtvetOKO ETA1OKO ETA2OKO ETA7OKO ETA3 ... OKO ETANOKO BTALMOKO ETA1MOKO ETA2MOKO ETA3 ... Moko etak
Using the previous example of a Russian, an American bank and the ABA, the Russian bank will only allow ETA IDs only their customers, and American Bank allows both ETA IDs of their clients and customers of the Russian bank, and clearing the database ABA should be to allow the ETA all customers both Russian and the American banks. An example of this resolution is to a certain extent artificial and the real world are hierarchical namespace and use the country and area codes for telephone numbers and notations domains for the Internet domain name space for unique routing connections.
Since a significant number of the URL in the internet and the telephone number is busy and not available for use by a new registrant, it is difficult to construct a hierarchical namespace for clearing infrastructure using the existing global Internet domains, as well as existing codes of countries and regions for telephone numbers. Therefore, it is useful to create a new infrastructure for clearing namespace URN: <NID> <NSS>, described in RFC 2276 and RFC 3401-3406, or a new global Internet domains, such as, for example-PAY, and "Zero" ETA (NETA) Room Telephony:
NETA: +0 (123) -123 4567 or + 7- (000) -123-4567, or + 7- (095) -0123456 DNS: 70950123456.PAY
Another version for the Internet can be a transformation of identity NETA in notation URN, what notation URN: <NID> <NSS> alleged domain "PAY" should be the value of the field NID (namespace ID), and the identifier NETA together and payment instruction shall be meaning NSS (Namespace Specific String) notation URN.
EXAMPLE clearing hierarchical infrastructure based on NETA, is shown in Figure 19.
For the conversion (for later resolution) NETA hierarchy in the DNS hierarchy can be applied algorithm described in RFC 3402, and other known or new equipment. As an illustration, a distributed below are some types of changes in phone numbers notation names DNS, ENUM or other URN:
+ 7- (095) -123-4567 → 70951234567.pay
+ 7- (095) -123-4567 → 7095234567.us.pav
+ 7- (095) -123-4567 → 1234567.washington.us.pav
+ 7- (095) -123-4567 → 1234567.095.7.rau
+ 7- (095) -123-4567 → 4567.AT & T.washmgton.us.pav
+ 7- (095) -123-4567 → 7.6.5.4.3.2.1.0.9.5.7.ABCD.arpa
+ 7- (095) -123-4567 → tel: +70951234567
+ 7- (095) -123-4567 → 70951234567.UTAresolution.com
+ 7- (095) -123-4567 → UTAresolution.com? 70,951,234,567
Other transformation in the DNS names might look like this:
+ 7- (095) -123-4567 → 70951234567.12020000001.10000000001.00000000001.com.
+ 7- (095) -123-4567 → 70,951,234,567 (a.bank.clearmghouse.com
and so on.
Figure 20 shows the same clearing infrastructure, and 19, where it is assumed that NETA are converted into the DNS name in the intended domain. RAU the DNS subdomain where there are also the US and RU, referring to the US and Russia and resolve descending order in the proposed domain. PAY.
Another technique would use a new protocol, such as a fictional protocol HTTPSP - "hyper text transfer secure payment protocol", which could be based on a standard HTTPS protocol and adapted to transmit payment instructions, clearing and name resolution.
Another approach would be to use a standard Internet transport (IP) along with the special allocation of the domain, using the technology of DNS and PKI, in which all domain owners have been clearing organizations (FBOs), and system domains would contain a conversion table is not DNS → IP, and conversion of NETA → → DNS IP or IP, or e-mail → IP, or "natural language name" → IP and so on. As a separate system based on the technology of DNS and PKI, the latest decision may be the least expensive to implement and most secure.
To resolve identifiers ETA division, depending on the method of clearing the database permissions can be executed as a DDDS DNS database as defined in RFC 3403, using the field ORDER and PREF to determine the method of clearing method of prioritizing clearing. Database KO in this case can be used DDDS algorithm described in RFC 3402, in which the first known rules (translation of the title "First Well Known Rule") could be a rule of processing line "t-call" call, and Clearing and name resolution can be performed using the rules database DDDS and operated "key" (called "keys"), as described in RFC 3402, wherein the "key" can indulge in a row parameter values t-call call.
Notwithstanding the foregoing, a more practical way would be to use the existing space of DNS names as clearing, with such Client # 3 (see Figure 18) could have 3 DNS name, defining 3 alternative route clearing. Assuming that the CF # 6 is the domain # 6.som CF, a CF # 5 is the domain CF5.com and CF # 2 is the domain CF2.com, klirinovy route could be written in the notation of DNS names as follows:
Client3.CF4.CF3.CF2.com for (Client # l → CF # 1 → CF # 2 → CF # 3 → CF # 4 → Client # 3)
Client3.CF5.CF2.com for (Client # l → CF # 1 → CF # 2 → CF # 5 → Client # 3)
Client3.CF5.CF7.CF6.com for (Client # l → CF # 1 → CF # 6 → CF # 7 → CF # 5 → Client # 3).
In the latter example, the ETA customer ID Client # 3 corresponds to three the URL Client3.CF4.CF3.CF2.com. Client3.CF5.CF2.com and Client3.CF5.CF7.CF6.com inside CF2.com, and CF6.com clearing domains.
Cycle permission. Cycle permit a search operation in the DNS database, which implements routing atomic payment.
The service authorization. The service authorization applies only to the routing of payments and the UMB is implemented as a chain of consecutive "cycles permit" - search the database domain name system of the clearing organization, as described in RFC 1035, 1034 and 3403 network address identifier corresponding ETA atomic Recipient payment. Similarly, the implementation of the DNS domain of each credit institution becomes its "management area" for all its customers and subsidiaries KO.
Each receiver identifier may be allowed in the network ID of its JCE, the JCE is "area management" domain identifier of the recipient, which is why the subdomain is an identifier or a host identifier in this case. For example, the identifier of the recipient = + 1 (212) -123-45b7 may correspond to the identifier of its OKO = 12121234567.citibank.com, and Citibank-com is a parent domain for the recipient. This method allows the user to seamlessly route calls t-call of the transaction through a chain of OKO connecting the calling and answering resources. Each of the JCE can be a bank or a Processing Center for processing payments by credit card or by the Calculation center or other clearing organization.
Provision of search KO. For the detection and study of the route clearing transactions can be used by RIP-2 protocol (Routing Information Protocol), defined in RFC 1723 or any other similar technique.
As a team the route search command can be used "Tracert", described in the protocol TCP / IP, or equivalent command can be used for wired and wireless networks.
The following example shows the output of the command "tracert":
C: \> tracert www.multilex.ru
Tracing route to multilex.ru [212.24.32.169]
over a maximum of 30 hops:
1 <1 ms <1 ms <1 ms gate.medialingua.ru [192.168.1.3]
2 1ms 1ms lms62.118.27.65
3 20ms 21ms 21 ms 10.4.255.100
4 123ms 211ms 131 ms spd-gw-GE-0-l-20.mtu.ru [195.34.53.97]
5 22ms 21ms 25 ms PTT-Pex.core.mtu.ru [195.34.53.65]
6 22ms 23ms 23ms Pex-M9.core.mtu.ru [195.34.53.10]
7 44ms 43ms 42 ms s-b3-pos0-2.telia.net [213.248.101.57]
8 45ms 45ms 45 ms teliasonera-01843-s-b3.c.telia.net [213.248.78.250]
9 68ms 73ms 75 ms mowl-000.sonera.ru [217.74.128.122]
10 75ms 73ms 74ms vlan30-ge5-l.m9-3.caravan.ru [217.74.128.126]
11 77ms 71ms 77ms vlan615-ge0-0-10.office-l.caravan.ru [217.23.151.78]
..........................................
C: \>
As can be seen from this example, the command "tracert" allows you to find the physical path that connects the calling and answering units (resources) of the network, including all intermediary resources. The use of this communication method of searching for the Architecture of the calculations performed via the Internet (priori) allows for payment ulsugi search route.
Search clearing organization and search for a route to the optimization of the cost of clearing the UMB considered in the example "Route optimization of the cost of clearing." section "Examples of Use" below.
Certifying services. To establish a relationship of trust between nodes priori can be used PKI. Each resource can be provided with a digital certificate authority (CA), containing at least the payment of the resource attributes, as described in RFC 3281. The payment attributes should include at least two -ETA, ie Certified ID ETA and ETA resource identifier main Clearing organizitsii specified resource. This method of digital certification provides routing information to the routing information in the routing to accommodate Database Clearing Organization.
Illustrating the contents of the CA, again using the DNS analogs such certified payment attributes could include information the entire set of resource records DNS (DNS Resource Record), which are contained in the master file name server DNS, or some kind of an important part of the range of the display (see. RFC 1034). Being then extracted from the CA, and placed in the master zone file DNS, certified information resource records will allow to provide reliable DNS service permits. Reduction of Digital Certificates to the DNS system, such as suggested in RFC 2538 "Storing Certificates in the Domain Name System (DNS)" and can be used to create certified DNS database when creating a priori. This RFC also provides the ability to access the public key of the resource, creating the necessary conditions for the use of digital signatures and encryption string t-call.
The network can use a single root Certification Authority (CA) or multiple root CAs whose identity services can be mutually recognized as valid due to reach an agreement, aimed at support of the cross-transactions. Although considered architecture allows you to use a lot of root CAs, some resources, such as mobile phones and other small devices, may not have enough space to store multiple CA or may not support work with several root CAs, because these nodes can use the services of only one root CA. whose services are recognized by all the other CA under the agreement on counter-trust. Nevertheless, in some cases, the number of useful trusted CAs can be limited to one TC.
Aspects of confidentiality. Keeping secrets is solved using PKI for Clearing the network for secure communications network electronic money transfer (Electronic Funds Transfer, or EFT) and distributed in a secure network Clearing the database described herein. Each Clearing database is protected by a network database, accessible only to the clearing participants. Digital certificates and PKI can be used as a source of reliable information displaying a plurality of ETA caller ID resource to a plurality of routing information to their accounts, creating an environment of trust and security when granting authorization and clearing services.
Examples of using
An example of the implementation of the database authorizes DNS.
Case 1
Detached priori can be performed using existing software implementations of DNS resolvers and DNS name servers, as well as using existing protocols, including UDP and TCP / IP. This DNS software would display and to resolve not only the DNS addresses, and any other network address in the IP address, providing a variety of services, as proposed in RFC 3403. Because of this, each ETA called a resource identifier can be resolved in the corresponding IP address of the JCE and for non-clients of ETA identifiers can be resolved in the DNS name server Parent KO, while the DNS system can use the Almaty domain JCE as "root" domain and allow all non-client identifiers ETA through it or by using a multi-level model resolution.
RFC 1034, 1035 and 1183 in some parts may be used for such an execution. Resolution ETA identifier in the domain name (see. "An example of lending transactions," explains resolution payer.com → payer.payerbank.com) may then be performed using domain INN-ADDR.ARPA to search by IP address or by using the DDDS to search ETA other types of identifiers.
In the case of the execution result of DDDS resolution ETA identifier "rauee.som" might look like this:
rauee.som.
;; order pref flags service regexp replacement
INNAPTR100 50 "a" "httpsp + N2T" "" rayee.som
INNAPTR100 50 "a" "https + N2R" "" payee.payeebank.clearing.com.
INNAPTR100 60 "a" "https + N2R" "" payee.payeebankl.clearing 1.com.
INNAPTR100 70 "a" "https + N2R" "" oayee.payeebank2.clearing2.clearing3.com.
INNAPTR100 70 "a" "http + N2B" "" billing.payee.com.
INNAPTR100 50 "a" "wap + N2V" "" wap.payee.com
IN NAPTR 100 80 "a" "sip + N2V" "" payee.com (% sip. Someservice.com
INNAPTR100 80 "a" "http + N2IP" "" 213.248.101.57,
where the service is "https + N2T" means "name-to-trace" the valuation of the route payment using alleged HTTPSP protocol; and three services "https + N2R" means "name-to-route" to provide alternative clearing domains ranks of preference (preference) 50, 60 and 70 for the routing of payment; and last service "http + N2V", to view the content of WAP server Payee describing services or consumer products.
Using DDDS becomes possible to produce a trace route, using a query each of the identifiers ETA payer and the recipient for the search service "https + N2R" routing in the DNS database and comparing the results to find them overlapping domains DA, and when the same domains KO found , it is possible to request their cost and duration of the clearing transactions for the purpose of optimization of the transaction.
Case 2
Assume that the database uses the DDDS DNS resource records NAPRT, allowing payments to resolve the address of each node in the corresponding address of the JCE. We also assume that some recipients "Payee" (payee.corn) has a bank account "PayeeBank" (PEBank.com) and some Payer "Payer" (payer.com), has a bank account "PayerBank" (PRBank.com) .
Let us also assume that the call t-call contains the string "? Payee.com/credit/USD/1000/PayerDigSign". Suppose that described in RFC 3402 Unique Line Applications (Application Unique String, or "AUS") received an application in the processing of t-call by removing the text that appears between the sign '?' and the first character '/' (the first known rule, as described in RFC 3402), and a database query DNS DDDS performed using the extracted text. In this case, the request will be substring "rauee.som."
The result permits DDDS line "Rauee.som" could be:
Rauee.som
;; order pref flags service regexp replacement IN NAPRT 100 10 "" X2Y "" PEBank.com
Now the application changes the value of the former AUS, adding value "payee" to the result of the search, and rewrites a string to a string AUS Payee.PEBank.com, and the application makes to the database search for the string "Payee.PEBank.com", which allowed the database to record :
Payee.PEBank.com
;; order pref flags service regexp replacement
INNAPRT10010 "p" X2Y "" payee.PEbank.DCFl.com
This implementation allows you to consistently resolve the identifier "payer.com" in route "payer.PRBank.com" and later in "payer.PRBank.DCFl.com", and getting DNS name "payee.PEbank.DCFl.com" is the end (of the This is evidenced by the flag "P") and ends the application name resolution "rauee.sot", returning the string "payee.PEBank.DCFl.com" as a full route clearing payment to the Receiver. Domen.SOM clearing is not in this example.
The same authorization identifier Payer would give consistent results:
Payer.com
;; order pref flags service regexp replacement INNAPRT10010 "" X2Y "" payer.PRBank.com
payer.PRBank.com
;; order pref flags service regexp replacement INNAPRT10010 "p" X2Y "" payer.PRBank.DCFl.com.
The application compares the final clearing routes for the Receiver Rauee.som → PEBank.com; Payee.com → PEBank.com → DCFl.com and Payer Payer, com → PRBank. com; Payer.com → PRBank.com → DCF1.corn in order to find the turning point routes (SST), that is, first left the domain name contained in the routes and coincides Recipient and payer, and so is clearing DCF1 domain in our case. Both the end of the route are compared to find a matching link and this link is considered to be the turning point route where the route becomes of rising Clearing downward clearing. Obviously, clearing the route given payment payer-recipient will Payer.com → PRBank.com → DCFl.com → PEBank.com → Payee.com, and is a turning point DCF1 route.
There may be more than one point turn in a route for each pair payer and the recipient.
Case Service Search route
Assume that the identifiers "Payer" Payer and "Payee" recipients may be allowed in the ETA identifiers clearing routes:
Payer
;; order pref flags service regexp replacement
IN NAPTR 100 50 "a" "http + N2T" "" paver.com
INNAPTR100 60 "a" "https + N2R" "" Daver.FOObank.ROOclearing.com.
IN NAPTR 100 50 "a" "https + N2R" "" pavee.GObank.REclearing.com.
and
Payee
;; order pref flags service regexp replacement
INNAPTR100 50 "a" "http + N2T" "" pavee.com
INNAPTR100 50 "a" "https + N2R" "" pavee.ZOObank.ROOclearing.com.
INNAPTR100 60 "a" "https + N2R" "" pavee.GObank.TOclearing.com.
Comparing the results of the permission identifiers "Payee" and "Payer" for services N2R (Name-to-Route), we find that the payment m ozhet be conducted using one of two independent routes, namely through the bank "GObank", which are account and payer and the recipient or through a clearing organization "ROOclearing", which has a correspondent bank account of the Beneficiary "ZOObank" and correspondent bank account of the Payer "FOObank".
Payer → GObank → Payee Payer → FOObank → ROOclearing → ZOObank → Payee
If the Payer wishes to make a payment from your bank account FOObank (this matter has a higher priority in the field of "pref" recording NAPTR record), then he must use a second route through the clearing ROOclering:
Payer → FOObank → ROOclearmg → ZOObank → Payee.
At the same time to select the optimal route clearing could be used given in the example below machinery "Optimization of the route clearing cost", which allows real-time assess the cost / duration of the payment, taking into account the preferences of taxpayers.
Example lending transactions.
Let's infrastructure includes a priori Recipient, Recipient Bank, the payer, the payer's bank and the Automated Clearing House (AKP) "www.CHIPS.com", shown in Figure 18. Both the bank and the AKP are clearing organizations for their own customers, with each bank is routed and Clearing Organization to its end customers, and the AKP is the Clearing Organization and routes for both banks that are members (customers) automatic transmission. Assume also that the resolution service provided by DNS database in which ETA called a resource is displayed in the main clearing organization ETA called a resource. ETA can be a phone number, so DNS name or IP address, or any other network address or name.
Imagine that the payer is a web site that has an address www.payer.com, and the recipient is a user of the mobile phone in the US, having room + 1- (212) -123-4567, having a bank account www.TargetBank.com.
As shown in Figure 21, the task is to transfer funds from the account of the payment on the account www.payer.com + 1 (212) in the bank -123-45b7 www.TargetBank.com;
The procedure of payment:
1. payer.com creates t-call 1: credit.PayerBank.com?paver.com/USD/1000/CHIPS/+l-(212)-123-4567/DigitalSignatureOFwww.payer.com;
2. www.payer.com establish a network connection using a string t-call 1 formatted in accordance with the rules of the network, for example by following the syntax of RFC 2396, RFC 3406.
3. www.payerbank.com receives a call t-call 1 and applies to a line call first known rules, then the payer's bank executes clearing, search and permit the Recipient ID, using the parameters taken from the string t-call 1 as a "key" algorithm described in RFC 3402. Because the Beneficiary's account + 1 (212) is located outside the clearing -123-45b7 domain www.payerbank.com, the result will be empty resolution (DNS error resolution), so the result of the search of the clearing organization shall be the value of primary clearing organizations top-level designated as "THE_UPPER_TIER_DEFAULD_CLEARING_FACILITY" or short "UTDCF", which may be one of the clearing houses SWIFT, ABA, or CHIPS, used by the bank as the parent www.payerbank.com OKO. Among these must be chosen Chamber CHIPS, because the name "CHIPS" was indicated as a parameter in a line t-call I.
4. Bank www.payerbank.com creates a string t-call in the form of 2 credit.chips.com?paverbank.com/payer.com/USD/1000/ON/+1 - (212) -123-4567 / DigitalSignatureOFwww.payerbank .com. It is appropriate to note that the notation www.payer.com itself can be solved inversely, using the operation INN-ADDR in payer.paverbank.com inside www.paverbank.com as www.paver.com, is clearing the host within the domain www. payerbank.com payer's bank.
5. The Bank Payer www.payerbank.com establish a network connection using the line calling t-call 2 formatted in accordance with the rules of the network, such as the syntax of RFC 2396 and RFC 3406 for example.
6. ACP www.CHIPS.com receives a call t-call 2 and applies to line procedure call parameter extraction, retrieval, and name resolution. As a result, the ID + 1 (212) -123-45b7 permitted identifier 12121234567.TargetBank.chips.com, as the Bank Recipient is a subdomain within the ACP CHIPS, and he is the recipient of a host within a domain's bank. The parameter "ON" stands for real-time performance of clearing and notification of the transaction.
7. ACP www.CHIPS.com call creates a string t-call 5 format and establishes a network connection to complete the loan. It is appropriate to note that the notation identifier Payer www.payer.com itself can be inversely solved using INN-ADDR operation in the name of the payer, payerbank. chips.corn inside www.chips.com, www.payer.com as a host in the domain of clearing www.payerbank.com, and www.payerbank.com is a sub domain within www.chips.com Zone Administration AKP CHIPS.
8. www.CHIPS.com call creates a string t-call in the form of three and establishes a network connection to complete the debit.
9. www.payerbank.com call creates a string t-call 4 in the form of debit.paverbank.com?paver.com/USD/1000/ON/+1-(212)-123-4567/DigitalSignatureOFwww.payerbank.com.
10. Bank www.TargetBank.com call creates a string t-call credit. and establishes a network connection to complete the loan recipient.
Although there are considered only the case of crediting the account of the Recipient, or any subsequent professional can easily applying the technique to be used for debit, billing and other transactions.
Obviously, the advanced technology and DDDS NAPTR RR, proposed in RFC 2916, 3401-3406, can be used for the execution of the described examples. In this case, a resolution can be obtained in the form of a NAPTR:
rauee.sot
IN NAPTR 100 80 "a" "pay + N2C" "" pavee.com@credit.payeebank.clearing.com. IN NAPTR 100 80 "a" "pay + N2D" "" Davee.com @ .dedit.paveebankl.clearingi.corn, IN NAPTR 100 80 "a" "pay + N2B" "" pavee.com @, billmg.paveebank2. clearmg2.com.
In the latter case, each transaction type uses the default URL for individual clearing accounts and debit billing for a conditional payment service.
Route optimization clearing cost.
It is well known that electronic payments have a cost, and the cost can vary depending on the method of payment (by ABA, SWIFT or via a credit card), while the payer payment amount and recipient are the same. 18 illustrates a different chain of payment, including a different number of members, and this number may also affect the value of the transaction, as well as during it.
Suppose that there is a priori infrastructure and implements certain command "cost", it is also assumed that this team is "cost" is similar to an existing Internet command "tracert", but additionally returns the value of the payment of the atomic point to point, and other characteristics as a result parameter. Such a team could be performed using the service route search, as shown in the example of "The Case of the route search services" above. Assuming this infrastructure, as shown in Figure 18, the conditional command "cost", applied to a client Client # 3, would detect the clearing route (Client # l # l → CF CF → # 2 → # 3 → CF Client # 2) returning the following result:
C: \> cost'Client # 2 '.
Tracing route cost to 'Client # 2' [212.24.32.169] over a maximum of 30 hops:
Route 1
1 10ms 10 ms 10 ms USD 0,32 CF # 1 [192.168.1.3]
2 10ms 10 ms 10 ms USD 0,0 CF # 2 [62.118.27.65]
3 10ms 10 ms 10 ms USD 0,5 CF # 3 [10.4.255.100]
4 10ms 10 ms 10 ms USD 0,0 Client # 2 [10.4.255.101]
Route 1 statistics:
Number of CF Nodes = 3 Approximate payment cost USD 0,82 Approximate payment time of 30 ms
C: \>
Now assume that the client Client # 1 would like to transfer the money to the client Client # 3. For this, he can use one of the alternative routes Clearing:
(Client # 1 → CF # 1 → CF # 2 → CF # 3 → CF # 4 → Client # 3) or
(Client # 1 → CF # 1 → CF # 2 → CF # 5 → Client # 3) or
(Client # 1 → CF # 1 → CF # 6 → CF # 7 → CF # 5 → Client # 3).
Therefore testing of the team 'cost' in relation to the payment (Client # 1 → Client # 3) would give a result of:
C: \> cost 'Client # 3'.
Tracing route cost to 'Slient # 3' [212.24.32.169] over a maximum of 30 hops:
Route 1
1 10 ms 10 ms 10 ms USD 0,32 CF # 1 [192.168.1.3]
2 10 ms 10 ms 10 ms USD 0,0 CF # 2 [62.118.27.65]
3 10 ms 10 ms 10 ms USD 0,5 CF # 3 [10.4.255.100]
4 10 ms 10 ms 10 ms USD 0.5 CF # 4 [10.4.255.101]
May 10 ms 10 ms 10 ms USD 0,5 CF # 3 [10.4.255.102]
Route 2
1 10 ms 10 ms 10 ms USD 0,32 CF # 1 [192.168.1.3]
2 1 day 1 day 1 day USD 0,0 CF # 2 [62.118.27.65]
October 3 ms 10 ms 10 ms USD 0,5 CF # 5 [10.4.255.103]
4 10 ms 10 ms 10 ms USD 0,0 Client # 3 [10.4.255.105]
Route 3
1 10 ms 10 ms 10 ms USD 0,32 CF # 1 [192.168.1.3]
2 10 ms 10 ms 10 ms USDO, 2 CF # 6 [62.118.27.65]
October 3 ms 10 ms 10 ms USD 0,5 CF # 7 [10.4.255.106]
October 3 ms 10 ms 10 ms USD 0,5 CF # 5 [10.4.255.107]
4 10 ms 10 ms 10 ms USD 0,0 Client # 3 [10.4.255.108]
Route 1 statistics:
Number of CF Nodes = 4
Approximate payment cost USD 1,32
Approximate payment time of 50 milliseconds Route 2 statistics:
Number of CF Nodes = 3
Approximate payment cost USD 0,82
Approximate payment time 1 day and 30 milliseconds Route 3 statistics:
Number of CFNodes-4
Approximate payment cost USD 1,52
Approximate payment time of 50 milliseconds
C: \>
It is obvious that the route "Route 2" has the lowest total cost of $ 0.82 UMB US dollars, but at the same time has the greatest length of the clearing, of 1 day to 50 milliseconds for the route "Route 1" and "Route 3". Engineering teams 'cost' is a computer and allows you to control the amount and timing of payments in real time.
The above technique provides a unique implementation priori ranking route clearing using the "cost" for payments to the UMB. This ranking, in turn, allows you to control the clearing routes, taking into account users' preferences in relation to the cost and timing of the transaction, and therefore the invention provides a practicable solution for financial institutions and their respective clearing, using the command "cost" trace value.
Use of payment preferences in the last example team "cost" can afford to implement various clearing scenario, so if the first preference of the user is cleared in real time and a second preference of minimizing costs, the result management clearing will route "Route 1" price cost USD and 1.32 times of 10 milliseconds as the cheapest way to clearing a route in real-time; and if the first user preference is the minimum price and the second - the date of clearing, clearing control result will be the choice of the route "Route 2" with the price of USD 0.82, and the time of 1 day.
As shown in the application, is it possible to use the existing Internet technology and its transportation equipment authorization and routing, as well as the use of a mature PKI technology for the purpose of clearing payments, providing real-time multi-level and multipath clearing infrastructure and services of the payments, make it simple to manage cost and routes of payments, creating conditions for a through PROCESSING (Straight Through Processing, or STP) of payments UMB. Cost Management ARPI payments infrastructure can significantly reduce or even avoid the cost of clearing, allowing account holders to manage and control the cost in terms of their payments.
Specific for different network identifiers (such as ETA, methane and others) and are typical of network software and user interfaces (telephone user interface that focuses on using only the numeric keypad) can be used to navigate and ARPI, allowing convenient to address payments and automate their clearing.
ARPI allows users to address the payments without the need to know the payee's bank account details and methods of clearing providing at the same time the possibility of UMB authorization and details of the beneficiary's account through payment processing and clearing.
The invention ARPI completely changes the nature of the payments translating their area of particular solutions of the clearing and the provision of banking services in the area of standardized technological solutions; from the field work with tedious bank details to work with having something meaningful and easy-to-use network IDs and names of the ETA; the need for knowledge of the details of bank accounts to permit free use of services accounts; the impossibility of making payments using a digital phone keypad to addressing freedom of payments, using existing phone contact lists; of paper-20th century in digital technology works in real-time and full automation.
Active use of identity PKI services solves the problem of confidence in these accounts, allowing to provide a secure environment, and clearing of payments. Using an attribute certificate containing only the network address of the payer and the corresponding network addresses OKO, it can fill the DNS database addressing system certified information and avoid unnecessary disclosure of confidential banking information.
Using existing technology DNS to resolve in making sure the set display enables transparent to the user to obtain the necessary reliable banking information, creating conditions for the provision of straight-through processing in real time.
ARPI is widely based on the use of the existing infrastructure of the Internet and its technologies, its protocols, for providing a unique built-in cheap through processing of payments and automatic control, resolution, routing, and conduct final settlement. The invention opens the door models SID (Shared Information and Data) for ARPI providing Technology Neutral Architecture (TNA) for the implementation of the Forum TM Forum's (www. Tmforum.org) to implement the business model, called New Generation Operations Systems and Software (NGOSS).
While in the application how to create a new architecture of the calculations performed via the Internet, and describes the various ways to create, issue and manage digital certificates, with the possibility of multi-level dissemination of CA and access to multiple accounts using the specified CA and PKI, based on the described any expert is able to offer Various embodiments of methods and their implementation in the framework outlined in the application approach. Therefore the depth of the invention is defined by the following claims.
Contents5
Every citation, both waysCites: the store holds 5 of 6
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11710120B2 | Cited by | United States of America | Applicant |
| US10887096B2 | Cited by | United States of America | Applicant |
| RU2615333C2 | Cited by | Russian Federation | Search report |
| US11138644B2 | Cited by | United States of America | Applicant |
| RU2721235C2 | Cited by | Russian Federation | Search report |
| RU2625949C2 | Cited by | Russian Federation | Search report |
| RU2684503C2 | Cited by | Russian Federation | Search report |
| US11475150B2 | Cited by | United States of America | Applicant |
| RU2644128C2 | Cited by | Russian Federation | Search report |
| US10908982B2 | Cited by | United States of America | Applicant |
| US11010090B2 | Cited by | United States of America | Applicant |
| US11048547B2 | Cited by | United States of America | Applicant |
| US11449376B2 | Cited by | United States of America | Applicant |
| RU2705775C1 | Cited by | Russian Federation | Search report |
| US11537593B2 | Cited by | United States of America | Applicant |
| US11055694B2 | Cited by | United States of America | Applicant |
| US10607212B2 | Cited by | United States of America | Applicant |
| RU2666312C2 | Cited by | Russian Federation | Search report |
| US10460366B2 | Cited by | United States of America | Applicant |
| US11288254B2 | Cited by | United States of America | Applicant |
| RU2708945C2 | Cited by | Russian Federation | Search report |
| US10996986B2 | Cited by | United States of America | Applicant |
| US11003600B2 | Cited by | United States of America | Applicant |
| RU2509360C1 | Cited by | Russian Federation | Search report |
| RU2672132C2 | Cited by | Russian Federation | Search report |
| US10817875B2 | Cited by | United States of America | Applicant |
| US10990698B2 | Cited by | United States of America | Applicant |
| RU2677669C2 | Cited by | Russian Federation | Search report |
| US11797502B2 | Cited by | United States of America | Applicant |
| RU2710289C2 | Cited by | Russian Federation | Search report |
| RU2709673C2 | Cited by | Russian Federation | Search report |
| US11256823B2 | Cited by | United States of America | Applicant |
| US11184745B2 | Cited by | United States of America | Applicant |
| RU2677669C2 | Cited by | Russian Federation | Search report |
| US11188901B2 | Cited by | United States of America | Applicant |
| WO2014031032A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US11657036B2 | Cited by | United States of America | Applicant |
| US10621572B2 | Cited by | United States of America | Applicant |
| US11061720B2 | Cited by | United States of America | Applicant |
| RU2673098C1 | Cited by | Russian Federation | Search report |
| RU2715796C1 | Cited by | Russian Federation | Search report |
| US9928538B2 | Cited by | United States of America | Applicant |
| US11681821B2 | Cited by | United States of America | Applicant |
| US10705761B2 | Cited by | United States of America | Applicant |
| US11062306B2 | Cited by | United States of America | Applicant |
| US11055694B2 | Cited by | United States of America | Applicant |
| US11710120B2 | Cited by | United States of America | Applicant |
| US11055160B2 | Cited by | United States of America | Applicant |
| US12112316B2 | Cited by | United States of America | Applicant |
| RU2612645C2 | Cited by | Russian Federation | Search report |
| RU2707152C2 | Cited by | Russian Federation | Search report |
| US11776027B2 | Cited by | United States of America | Applicant |
| US11776028B2 | Cited by | United States of America | Applicant |
| RU2674329C2 | Cited by | Russian Federation | Search report |
| US11734260B2 | Cited by | United States of America | Applicant |
| US11677550B2 | Cited by | United States of America | Applicant |
| RU2173028C1 | Cites | Russian Federation | – |
| US5617540A | Cites | United States of America | – |
| EP1195707A1 | Cites | European Patent Office (EPO) | – |
| WO9953713A1 | Cites | World Intellectual Property Organization (WIPO) | – |
| US6332165A | Cites | United States of America | – |
| JP 2002175274, 21.06.2002. Норенков И.П. и др. Телекоммуникационные технологии и сети. - М.: МГТУ имени Н.Э.Баумана, 1998, с.83, 85-88. | Non-patent | – | – |
30 members in 6 offices
Priority claims11
| Document | Office | Kind | Date |
|---|---|---|---|
| 0200462 | Russian Federation | W | |
| PCTRU0200462 | Russian Federation | – | |
| 0300634 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| PCTIB0300634 | International Bureau of the World Intellectual Property Organization (WIPO) | – | |
| PCTIB0302045 | International Bureau of the World Intellectual Property Organization (WIPO) | – | |
| 2005115454 | Russian Federation | A | |
| PCTIB0300634 | – | – | – |
| PCTRU0200462 | – | – | – |
| RU20050115454 | – | – | – |
| WO2002RU00462 | – | – | – |
| WO2003IB00634 | – | – | – |
Members30
| Document | Office | Kind | |
|---|---|---|---|
| US2003078987A1 | United States of America | A1 | |
| US2003079124A1 | United States of America | A1 | |
| WO03036412A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2002348547A1 | Australia | A1 | |
| WO03036412A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO03073337A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003248364A1 | Australia | A1 | |
| WO03036412A9 | World Intellectual Property Organization (WIPO) | A9 | |
| WO2004023709A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003230133A1 | Australia | A1 | |
| WO2004038528A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003280125A1 | Australia | A1 | |
| AU2003280125A8 | Australia | A8 | |
| WO2004038528A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1459496A2 | European Patent Office (EPO) | A2 | |
| US2005114367A1 | United States of America | A1 | |
| CN1631023A | China | A | |
| AU2002348547A8 | Australia | A8 | |
| RU2004115751A | Russian Federation | A | |
| RU2005115454A | Russian Federation | A | |
| RU2273107C2 | Russian Federation | C2 | |
| RU2376635C2This record | Russian Federation | C2 | |
| RU2009124069A | Russian Federation | A | |
| RU2011111138A | Russian Federation | A | |
| RU2464637C1 | Russian Federation | C1 | |
| US8868467B2 | United States of America | B2 | |
| US2015052056A1 | United States of America | A1 | |
| US9043246B2 | United States of America | B2 | |
| US2015227933A1 | United States of America | A1 | |
| US11341497B2 | United States of America | B2 |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| The patent is invalid due to non-payment of feesMM4A | MM4A | |
| Application not withdrawn (correction of the notice of withdrawal)WithdrawnFZ9A | FZ9A | |
| Acknowledgement of application withdrawn (lack of supplementary materials submitted)WithdrawnFA92 | FA92 |
Numbers
- Publication
- 2376635
- Publication, DOCDB
- 2376635
- Publication, EPODOC
- RU2376635
- Application
- 200511545409
- Application, DOCDB
- 2005115454
- Application, EPODOC
- RU20050115454
Titles2
- English
- METHOD AND SYSTEM FOR CARRYING OUT TRANSACTIONS IN NETWORK USING NETWORK IDENTIFIERS
- Russian
- СПОСОБ И СИСТЕМА ПРОВЕДЕНИЯ ТРАНЗАКЦИЙ В СЕТИ С ИСПОЛЬЗОВАНИЕМ СЕТЕВЫХ ИДЕНТИФИКАТОРОВ
Classification
- IPC, 4
- G06Q20 16
- G06Q20 40
- H04L9 32
- G06Q30 00