Method, apparatus, article and system for network communications
40 claims: 6 independent, 34 dependent
- 1NYA PATENTKRAV 1. Ett förfarande som innefattar:att vid en anordning (110) upprätta (312) en första förbindelse (114, 116, 118, 120) till en server (160);att etablera (320) ett informationsutbytesprotokoll för kommunicering via den första förbindelsen (114, 116, 118, 120);att vid anordningen öppna (342) en andra förbindelse (114, 116, 118, 120) till servern;att välja (360), från förbindelser som innefattar den första och andra förbindelsen, att en förbindelse ska vara aktiv;och att kommunicera (350) information som är konfigurerad för informationsutbytesprotokollet genom användande av den aktiva förbindelsen.
- 2Förfarandet i enlighet med krav 1, vilket ytterligare innefattar kommunikationsinformation konfigurerad för informationsutbytesprotokollet genom användande av den första förbindelsen (114, 116, 118, 120) som den aktiva förbindelsen, innan val av den andra förbindelsen (114, 116, 118, 120) som den aktiva förbindelsen sker.
- 3Förfarandet i enlighet med krav 1, i vilket den, andra förbindelsen (114, 116, 118, 120) öppnas innan etablering (320) av informationsutbytesprotokollet.
- 4Förfarandet i enlighet med krav 1, i vilket en enda av förbindelserna (114, 116, 118, 120) väljs som den aktiva förbindelsen.
- 5Förfarandet i enlighet med krav 1, i vilket två eller flera av förbindelserna (114, 116, 118, 120) väljs som den aktiva förbindelsen. 526 563 II
- 6Förfarandet i enlighet med krav 1, i vilket den andra förbindelsen (114, 116, 118, 120) innefattar en trådlös förbindelse.
- 7Förfarandet i enlighet med krav 1, ytterligare innefattande att välja (360), från förbindelserna (114, 116, 118, 120), att en förbindelse ska vara passiv.
- 8Förfarandet i enlighet med krav-7, ytterligare innefattande att bibehålla den passiva förbindelsen (230) medan åtminstone en del information kommuniceras genom användande av den aktiva förbindelsen (240) .
- 9Förfarandet i enlighet med krav 1, 6, 7 eller 8, ytterligare innefattande att övervaka (340) förbindelserna (114, 116, 118, 120) för en parameter som väljs från gruppen som består av signalstyrka, överföringstakt, latenstid, överföringskostnad och förbindelseintegritet;och att återvälja (360) den aktiva förbindelsen för att optimera parametern.
- 10Förfarandet i enlighet med krav 1, i vilket informationen kommuniceras i paket som innefattar sammansatt information för mer än en applikation.
- 11Förfarandet i enlighet med 1, 4, 6, 7 eller 8, i vilket informationen innefattar en instruktion som utförs av en modul på servern.
- 12Förfarandet i enlighet med krav 1, i vilket informationen innefattar en sammansättning av information från applikationer, varvid omfattningen för varje applikations sammansättning är beroende av en prioritetsindi526 563 kator för informationsutbyte som förknippas med varje applikation.
- 13Förfarandet i enlighet med krav 11, i vilket instruktionen åstadkommer servern (160) att kontakta ett fjärrbeläget system, ta emot ett svar från det fjärrbelägna systemet och utföra en respons utan att sända svaret till anordningen (110).
- 14Ett förfarande som innefattar:att vid en server (160) acceptera (312, 342) förbindelser (114, 116, 118, 120) från en anordning (110) för kommunikation av information som konfigureras av ett informationsutbytesprotokoll;att detektera (340) eller välja (360) en eller flera av förbindelserna som en aktiv förbindelse;att kommunicera (350) information som konfigurerats av informationsutbytesprotokollet genom användande av den aktiva förbindelsen.
- 15Förfarandet i enlighet med krav 14, i vilket en enda av förbindelserna (114, 116, 118, 120) väljs som den aktiva förbindelsen.
- 16Förfarandet i enlighet med krav 14, i vilket informationen kommuniceras (350) i paket, varvid vart och ett av åtminstone några av paketen innefattar sammansatt information för olika applikationer på anordningen (110).
- 17Förfarandet i enlighet med krav 14, i vilket informationen innefattar en instruktion för en modul.
- 18Förfarandet i enlighet med krav 17, vilket ytterligare innefattar utförande av instruktionen.
- 19Förfarandet i enlighet med krav 18, i vilket modulen påverkar instruktionen genom kontakt med en fjärr- *· * «« ···· • · · · ··· ··«· 526 563 li belägen server, tar emot ett svar från den fjärrbelägna servern och åstadkommer en respons utan att sända svaret till anordningen.
- 20Förfarandet i enlighet med krav 14, 15 eller 19, i vilka informationen är en sammanslagning av information för applikationer, varvid sammanslagningens omfång för varje applikation är beroende av en prioritetsindikator för informationsutbyte som förknippas med varje applikation.
- 21Förfarandet i enlighet med krav 14, ytterligare innefattande att detektera (340) eller välja (360), från förbindelserna (114, 116, 118, 120), att en förbindelse ska vara passiv.
- 22Förfarandet i enlighet med krav 21, ytterligare innefattande att bibehålla någon annan av förbindelserna (114, 116, 118, 120) som en passiv förbindelse medan åtminstöne en del information kommuniceras (350) genom användande av den aktiva förbindelsen.
- 23En anordning (110) som innefattar en processor (413) och mjukvara konfigurerad för att åstadkomma processorn att öppna (312) en första förbindelse (114, 116, 118, 120) till en server (160);att upprätta (320) ett informationsutbytesprotokoll;att öppna (342) en andra förbindelse (114, 116, 118, 120) till en server;att välja (360), från förbindelser som innefattar den första och andra förbindelsen, att en förbindelse ska vara aktiv;och 526 563 att kommunicera (350) information som konfigurerats för informationsutbytesprotokollet genom användande av den aktiva förbindelsen.
- 24Anordningen (110) i enlighet med krav 23, i vilken processorn (413) dessutom är konfigurerad att övervaka (340) förbindelserna (114, 116, 118, 120) för en parameter som valts från gruppen som består av signalstyrka, överföringstakt, latenstid, överföringskostnad och förbindelseintegritet;och att återvälja (360) den aktiva förbindelsen för att optimera parametern.
- 25Anordningen (110) i enlighet med krav 23, i vilken informationen kommuniceras i paket, varvid åtminstone några av paketen innefattar sammansatt information för olika lokal applikationer.
- 26Anordningen (110) i enlighet med krav 23, i vilken informationen innefattar instruktioner som utförs av en modul på servern (160) .
- 27Anordningen (110) i enlighet med krav 23, i vilken mjukvara åstadkommer processorn (413) att välja, från förbindelserna (114, 116, 118, 120), att en förbindelse ska vara passiv.
- 28Anordningen (110) i enlighet med krav 27, i vilken mjukvaran åstadkommer processorn (413) att bibehålla den passiva förbindelsen (114, 116, 118, 120) medan åtminstone en del av informationen kommuniceras (350) genom användande av den aktiva förbindelsen.
- 29Ett organ (110) som innefattar ett maskinläsbart media som lagrar maskinexekverbara instruktioner som åstadkommer maskinen (413) ···· 526 563 att öppna (312) en första förbindelse (114, 116, 118, 120) till servern (160);att etablera (320) ett informationsutbytesprotokoll;att öppna (342) en andra förbindelse (114, 116, 118, 120) till en server;att välja (360), från förbindelserna, att en förbindelse ska vara aktiv;och att kommunicera (350) information som konfigurerats för informationsutbytesprotokollet genom användande av den aktiva förbindelsen.
- 30Organet (110) i enlighet med krav 29, i vilket en enda av förbindelserna (114, 116, 118, 120) väljs som den aktiva förbindelsen.
- 31Organet (110) i enlighet med krav 29, i vilket instruktionerna dessutom åstadkommer maskinen (413) att övervaka (340) förbindelserna (114, 116, 118, 120) för en parameter vald från gruppen som består av signalstyrka, överföringstakt, latenstid, överföringskostnad och förbindelseintegritet;och att återvälja (360) den aktiva förbindelsen för att optimera parametern.
- 32Organet (110) i enlighet med krav 29, i vilket informationen kommuniceras i paket, varvid vart och ett av åtminstone några av paketen innefattar sammansatt information för olika lokala applikationer.
- 33Organet (110) i enlighet med krav 29, i vilket informationen innefattar instruktioner som utförs av en modul i servern (160).
- 34Organet (110) i enlighet med krav 29, i vilket instruktionerna åstadkommer maskinen att välja (340), från förbindelserna (114, 116, 118, 120), att en förbindelse ska vara passiv. 526 563
- 35Organet (110) i enlighet med krav 34, i vilket instruktionerna åstadkommer maskinen (413) att bibehålla den passiva förbindelsen medan åtminstone en del av informationen kommuniceras (350) genom användande av den aktiva anslutningen.
- 36Ett system innefattande en anordning (110), en server (160) och kommunikationslänkar, i vilket anordningen är konfigurerad att öppna (312) en första förbindelse (114, 116, 118, 120) till servern genom användande av en av kommunikations län karna ;att etablera (320) ett informationsutbytesprotokoll;att öppna (342) en andra förbindelse (114, 116, 118, 120) till servern genom användande av en annan av kommunikationslänkarna;att välja (360), från förbindelser som innefattar den första och andra förbindelsen, att en förbindelse ska vara aktiv;att kommunicera (350) information som är konfigure rad för informationsutbytesprotokollet genom användande av den aktiva förbindelsen.
- 37Systemet i enlighet med krav 36, i vilket åtminstone kommunikationslänkarna innefattar en trådlös kommunikationslänk.
- 38Systemet i enlighet med krav 36 eller 37, i vilket anordningen (110) dessutom är konfigurerad för att övervaka (340) förbindelserna (114, 116, 118, 120) för en parameter som är vald från gruppen som består av signalstyrka, överföringstakt, latenstid, överföringskostnad och förbindelseintegritet;och att återvälja (360) den aktiva förbindelsen för att optimera parametern. 526 563 zr • · • · · • ···· * · ·· ·· ·♦·· • ·
- 39Systemet i enlighet med krav 36, i vilket anordningen (110) vidare är konfigurerad att välja (360), från förbindelserna (114, 116, 118, 120), att en förbindelse ska vara passiv.
- 40Systemet i enlighet med krav 39, i vilket den passiva anslutningen (114, 116, 118, 120) bibehålls medan åtminstone en del av informationen kommuniceras (350) genom användande av den aktiva förbindelsen (114, 116, 118, 10 120) .
Independent claims40
130 paragraphs in 4 sections, as filed
BACKGROUND
This invention relates to network communication.
Mobile devices, such as laptops, mobile phones and handheld digital aids, communicate via wireless networks to enable their users to work in multiple locations and while traveling, such as at home, at airports, aircraft and public spaces. The mobile devices typically run applications that retrieve data from a server on the Internet through communication where a single connection is used.
DESCRIPTION OF DRAWINGS
Fig. 1 shows a block diagram of network connections between a mobile client and a home agent.
Fig. 2 shows a channel state machine.
Fig. 3 shows a flow chart of a process for connecting a mobile client.
Fig. 4 shows a block diagram of a mobile device.
Fig. 5 shows a block diagram of a stack for providing information to an application.
Figs. 6A & 6B show a block diagram of information processing units realized by a mobile client.
Figs. 7A, 7B & 7C show a block diagram of information processing units realized by a home agent or a server.
··· • · • · ···
526 E63
<img file="SE526563C2_D0001.tif" />
<img file="SE526563C2_D0002.tif" />
DETAILED DESCRIPTION
A flexible and robust information exchange protocol for connecting a device to a secure network may include two or more open connections. The connections can be wireless and can be selectively and efficiently selected to improve information transfer speed and reliability.
Referring to the example shown in Fig. 1, a mobile (or immobile) device 110 establishes four ex10 amplifying connections or channels with a home agent 160. Examples of mobile devices include laptops, handheld computers (e.g., PalmPilots ™, handheld digital aids, keypads, pagers, mobile phones (for example, phones that allow the use of
WAP, Wireless Application Protocol), MP3 players and gaming and / or entertainment stations. Examples of immobile devices include desktops, large devices and factory machines.
The terms connection and channel refer to a route for transmitting and / or receiving information.
Information refers to both data (eg text, numeric data, Boolean data, addresses, graphic content and the like) and instructions (eg requests, instructions, queries and the like). The home agent can be a computer system (such as a desktop computer, a server, a server park, or a mainframe).
Connection 114 is a cordless telephone link (e.g.
· '··. third-generation wireless networks (3G), wireless networks • «: two-and-a-half-generation (2.5G) networks, GPRS (General: 30 Packet Radio Service), i-mode NT (NTT DoCoMo, Japan), GSM j?. * (Global System for Mobile Communications), CDMA (Code • · * * Division Multiple Access) or Wireless TDMA (Time Di • · · vision Multiple Access) / D-AMPS (Digital Advanced Mobi • · · '· ”Le Phone Service). This connection can be a modem ···
· ... · 35 connection that is diverted to an Internet service ·· · • '. · Provider that connects the mobile client 110 to the Internet 140.
···
22 '/? ··'. '. I ··:' t · 2 '· .. ίο / 7/1 // /.ICHAROSC ?;
; 2Λ2ΈΝ2:? / ?? jrii /<sub>:</sub> \ 5ΕΛ 2005675/210026 7 5 Appl lelir · 'rucl or 2E7 7 0 0 2 · i 1 - 1 i
526 563
<img file="SE526563C2_D0003.tif" />
Connection 116 is a wireless connection to a local area network (LAN) 130 (eg a wireless network as provided by wireless Ethernet, BlueTooth, the Institute of Electrical and Electronics Engineering (IEEE) standard 802.11a or 802.11b (IEEE std.). 802.111999, published 1999) or CDPD connections (Cellular Digital Packet Data). Information from this connection can optionally be transmitted via a translator of foreign network addresses (NAT) / proxy 132 for connection from the intranet 130 to the Internet 140.
Connection 118 is a wired network connection,
e.g. to a company intranet 130. Information from this connection is transmitted via a foreign NAT / proxy 132 for connection to the Internet 140.
Connection 120 is a direct connection to the Internet 140, e.g. a DSL (Digital Subscriber Line, digital subscriber line), ISDN (Integrated Service Digital Network) or cable modem connection, Internet 140 directs the connections to the home agent 160 which is connected to
Internet via a corporate firewall 152. The home agent 160 may also be connected to a second intranet 150.
The mobile client 110 may be designed to flexibly use a number of communication protocols (eg TCP (Transmission Control Protocol) / TCP / IP (In25 ternet Protocol), UDP (User Datagram Protocol), HTTP (Hypertext Transfer Protocol), SMTP (Simple Mail Transfer Protocol), POP3 (Post Office Protocol 3) or other Internet Protocols) for the purpose of communicating with the Home Agent 160, e.g. via Internet 150. In some examples, the mobile client 110 has been assigned an IP address in the secure intranet 150. Applications running on the mobile client 110 issue network calls using the assigned IP address, typically using a proxy module on the home agent 160. However, for the connections between the mobile client 110 and the home agent
160 require a different set of addresses. For example, the mobile client 110 may be a guest system having an il lit.
526 563
<img file="SE526563C2_D0004.tif" />
IP address of guests in a second intranet 130 or be connected to the Internet 140 by using a temporary IP address, e.g. via a third-party service provider. Addresses, such as the IP guest address and the temporary one
The IP address is invisible to the applications running on the mobile client 110, but is used, for example, by the network interfaces or operating system, for connection to the home agent 160.
The communication connections can use network 10 address translation (NAT). NAT enables machines in a secure intranet to use a set of assigned IP addresses. NAT translates these assigned IP addresses into external IP addresses for communication with devices outside the intranet. This protocol improves network security and allows more efficient assignment of IP addresses in an intranet. In general, the mobile client 110 will establish connections with the home agent via NAT, e.g. said foreign NAT / proxy 132. NAT 132 forwards information, for example over a public or unsecured network, to the home agent 160 which is securely behind a firewall 152. The home agent 160 processes the information from the mobile client 110, for example by decompressing and decrypting the information, to allow the mobile client 110 to operate securely with the benefits of a direct connection to an intranet or virtual private network (VPN) 150.
Referring to Fig. 2, each connection operates as a finite state machine. The connection can be disconnected 210, connected 220, passivated 230 or activated 240. A connection sends information to, and receives information from, a server in the active state. An active connection 240 is switched to being passive 230 under certain conditions, for example if another connection is more efficient, more secure or more economical. A user or system administrator can define parameters for such a switch. The system can monitor the active connection 240 and / or the passive connections526 563 • ··· · · · ···· ····
<img file="SE526563C2_D0005.tif" />
230 for one or more of the following parameters: signal strength, transmission rate, latency, transmission cost and connection integrity. Monitoring and switching of connections can be performed without the user's knowledge5.
An active connection 240 is switched to the disconnected state 210, for example in case of loss of connection integrity (eg an abrupt interruption or a security breach). A disconnected connection 210 is switched to be connected 220 when deemed appropriate.
A connected connection 220 is switched to passive 230 once it has been established and initialized correctly. A passive connection 230 is generally not used to transmit or receive information except when it is necessary to monitor or maintain its integrity. In particular, a passive connection 230 is not used to send or receive application information. The passive connection 230 can be used to send instructions for its own activation. For example, if there is an abrupt interruption in the active connection 240, then either one, or both, of the server 160 and the mobile client 110 may issue instructions on a passive connection 230 to indicate that it is to be activated.
More than one connection can be activated at a given time. Information is shared between such active connections 240, for example in relation to the transmission rate of the given connection, its latency, its reliability and so on. The use of several connections at the same time increases the overall information transfer rate.
Referring to Fig. 3, the mobile client 110 reads 310 available network interfaces to search for those that allow connection to the home agent 160. The connection process includes initiating communication protocols 320. The steps involved in process 320 are typically required only for the initiation connection 312. the addition of additional liabilities ·· ····
526 563 connections 230 and switching between active connections 240 quickly and efficiently.
To initiate a connection 320, a network addressing 322 is initiated. For example, the mobile client 110 receives a Dynamic Host Configuration Protocol (DHCP) address from the home agent 160 or from another server. The mobile client 110 can also detect the presence of a proxy module on the home agent 160. Security protocols are established and authenticated 324 as is usually done with compression protocols 326. Examples of security protocols include TLS (transport layer security), SSL (secure sockets layers, secure port layers) and wireless TLS (WTLS). Non-limiting examples of a compression protocol include: Lossless
Compression (LZS®) and Microcom Networking Protocol-5 (MNP5). Optionally, the mobile client 110 and the home agent 160 may exchange secondary authentication information, such as authenticated names, digital certificates and cookies.
Once a protocol has been initialized for a session, initiating additional connections (e.g., at least one second connection) to the home agent 160 requires only authentication 314 to verify that a new connection exists between a mobile client 110 and / or a home agent. 160 who are already a party to a session. The same network25 plant, security, and compression protocols and parameters are used for information exchange as for the initial connection. For example, the common parameters for multiple sessions may include cryptographic keys, network address assignments, and compression formats (t.
ex. compression reference books). Accordingly, in such examples, all passive 230 and active connections 240 use the same level of security. The exact level can be determined by a system administrator or user.
In other examples, the system uses other security protocols and / or compression levels for the various connections. The home agent 160 and the mobile device
110 establishes different safety procedures for each connectionH
526 563
<img file="SE526563C2_D0006.tif" />
·· ·· «· · •« · «· • · · t« · · · · • <· · · «·· ··· delse, e.g. each passive or active channel, depending on the connection type. Thus, a connection that requires passage through a firewall, e.g. a mobile phone link to the Internet, requires a higher level of security, while a wired Ethernet connection to a LAN does not require such a high level of security.
The mobile client 110 and / or the home agent 160 can be programmed to decide whether additional connections should be opened 342. For example, parameters can be set for opening connections, e.g. based on the charge charged for using a particular connection, the connection speed, power consumption (eg the required battery capacity) and safety. The system can read available passive connections 230 and active connections
240 according to a variety of criteria. For example, the mobile client 110 may determine the number of current connections (eg, active or passive connections), their signal strength, and connection speed. The mobile client 110 may also detect its own geographical location to determine if it is in motion or leaving the effective range of a current connection, e.g. by using GPS (Global Positioning System). Such parameters can be used to determine whether additional connections should be established 342, whether active connections 240 should be switched 344 and whether existing connections should be closed.
Similarly, the mobile agent 110 and / or the home agent 160 can be programmed to determine whether the active connection 240 should be switched 360. Parameters for the decision may include the relative signal strength, latency, transfer rate, security, cost (e.g., billing per minute). or switching), power consumption and reliability of the various connections. The process of switching 360 one connection from active 240 to pass 230 siv 230 and another from passive 230 to active 240 is called handoff. The use of common information exchange protocols for all connections can
526 563
<img file="SE526563C2_D0007.tif" />
.: .: .: ···: .:. .:. * .:. :
facilitate transfer. For example, TCP timers, packet size, and windows do not need to be reconfigured for handover. This is important for abrupt connections when the active connection 240 is unexpectedly lost and a passive connection 230 must be made active 240.
Referring to Fig. 4, an exemplary device 110 is equipped with a memory 412 and a processor 413 for executing instructions. The device 110 also has a console 414 (e.g., including a keyboard and a screen) for transmitting results to the user and for receiving user instructions. The device 410 includes a circuit set 420 or other interface for connecting the subsystem of the device.
The circuitry 420 includes an I / O interface 430 such as an I / O control hub (ICH) or a basic I / O system (BIOS). For example, the ICH may be an Intel® 82801 type ICH. The I / O interface is connected to two or more I / O devices 432 and 434. These I / O devices
432 and 434 are used to establish communication channels with the home agent 160. For example, the I / O devices may include a modem (eg a modem connected to an internal or external mobile phone, a cable modem) an IRport, a network card, BlueTooth, a packet cellular com25 a communicator, a satellite connection or a wireless interface (for example, a CDPD wireless interface,
GPRS, GSM, 802.11a, 802.11b or BlueTooth).
Referring to Fig. 5, information is mapped from an application 510 running on a mobile client 110 to an application 560 running on a destination server 170 (ie, a server other than the home agent 160). The mobile client 110 is connected to the destination server 170 via the home agent 160. The information is sent through a rate limiter 520 which monitors information transfer rates and the service quality parameters of the application.
In some examples, the rate limiter 520 implements the desired quality of service policy so that some applications '· / ··' · Ά 2 ΡΛί RiCHARDSON
ΚΑΡΑΪΕΝ; \ IRr-i'-: ir / .i. L \ · tF p. '. Ct. 75121085/75 χμΐ - Rp ·., 7 011 11-11
526 563 · ·: ··: ·· Γ :? ·: ·· ·: “ϊ: ··: ··. : ·::
• · · · «· ·· ··· ··· ··· · : .· • · · • · · ··· · ·· · • · · • * • · ·· · ···· .·. :
data data is given priority over bandwidth over other application data. The rate limiter 520 also protects the mobile client 110 from sending data to the home agent 160 at a rate that is faster than the home agent can forward said data to its final destination, e.g. a destination server 170. The home agent 160 may instruct the rate limiter 520 on the client to slow down data transfer or to stop the transfer altogether for a specific destination (e.g. the destination server 170) when the home page 160 buffers an unreasonably large amount of data. This situation can occur, for example, when the mobile agent 160 sends data to a system with a slower wireless connection (eg, when the mobile client 160 sends information to another mobile client via the home agent
160) ,
The flow indexer 521 monitors outbound and inbound requests and information for the application. The flow indexer 521 can also merge information from the application with information for other applications. The mo20s buffer 522 stores outgoing information (e.g. as a packet) until an acknowledgment of its receipt is received from the home agent 160. If acknowledgment is not received after an interval, then the active connection 240 can be exchanged and the information (e.g. information packets) can be returned. Similarly, the mobility buffer 522 issues acknowledgments for information received from the home agent 160. The acknowledgments may be sent from time to time, e.g. together with outgoing data, to clear the other side's mobility buffer. The confirmation may be time insensitive. For example, the other side's mobility buffer may send additional information before acknowledgments are received. The number of confirmations sent can be tailored to reflect the capacity of the other side's mobility buffer. The sizes of the mobility buffers can be negotiated when the first connection is opened between the client and the home agent.
? · '; · ΡΛAc-.6- = 71.:, 1' = 5 '· 1 6.Γ: Aat <. ί: .Η · ίcnL · / ·,
526 563
<img file="SE526563C2_D0008.tif" />
The information is then transmitted through a firewall 523. This process may include compression or decompression and / or encryption and decryption. Thereafter, the information is sent to a transmission port 524 of the active connection 240.
The information is transmitted via the active connection 240 from the transfer port 524 of the mobile device 110 to the transfer port 534 of the home agent 160. The home agent 160 processes the information in a corresponding manner with a firewall passage 533, mobility buffering and acknowledgment 532, application port control 531, similarly concealing information. and directing said data to its final destination in the network (e.g. an intranet or Internet) and mobility rate control 530. These processes map incoming information to an application port 540 on the home agent 160. This port can in turn be linked to an application port 550 on a destination server 170 which is connected to the same network as the home agent 160 via a VPN 150 . Although the processes described above relate to information transmitted from the mobile device 110 to the home agent 160, the same processes can be executed for information flowing from the home agent 160 to the mobile device 110.
Application-specific information can be routed into the active connection 240 in many different ways. Applications can be individually informed about the active connection 240 and can themselves route information over the active connection 240. In other examples, all application-specific information is routed to a network referrer which routes the information to the active connection 240. For example, applications' network calls and data can be captured directly from the applications and forwarded to the home agent 160. In other examples, applications use local proxy servers, e.g. proxy servers running on the mobile client 110 to send traffic to the active connection 240.
526 563
<img file="SE526563C2_D0009.tif" />
In some examples, ports (sockets) are created as software objects that connect an incoming / outgoing application stream to a network interface. Proxy servers are also used to process information from other applications.
Referring to Figs. 6A & 6B in the right-to-left direction, the mobile device 110 runs applications using three application ports 610, 611 and 612. An application requiring a network connection may utilize one or more of said application ports 610, 611. 612. Information exchange to and from a port is monitored by the flow indexer 616 and by port control 620.
Outgoing information is processed by the flow indexer
616 and the rate limiter 622. The rate limiter 622 provides quality of service and protects against the overflow of the home agent 160 buffer; the home agent 160 provides the rate limiter 622 with flow control notifications. Flow control systems (eg XON / XOFF or rate-based flow control systems) monitor information transfer rates, buffer load and acknowledgment acknowledgments. Flow control can be implemented on application and transport ports on both the mobile client 110 and the home agent 160. For example, if the home agent 160 is unable to send information to a third destination 170 at the same rate as it receives it from the mobile client 110, then a spill port is notified to the mobile client 110. Such actions may prevent the home agent 160 from buffering too much data.
Outgoing information from several application ports is packaged, compressed, encrypted and merged by units comprising the upper encoder 624 and the lower encoder 630 via the mobility buffer 626. The mobility buffer 626 retains a copy of said outgoing data until reception has been confirmed. If the active connection is broken and re-established (possibly on another network interface), the mobility buffer 626 may contain
<img file="SE526563C2_D0010.tif" />
526 563
<img file="SE526563C2_D0011.tif" />
may be returned immediately, or the computer (home agent or client) may wait for a mobility buffer acknowledgment (sent when a connection becomes active) before returning the exact amount of data requested by the other party from the mobility buffer. The decision to send or wait before sending can be made based on the amount of data in the mobility buffer, the estimated bit rate of the active interface, the cost of the interface and other care.
Router 640 routes traffic from the lower encoder
630 to the active transfer port (for example, one of 660, 670 or 680). The active transfer port is a dedicated information flow portal to the active connection 240. Information from said transfer port to the application ports is bidirectional. Information is secured using TLS or SSL protocol 666. The information is transmitted through the network firewall by the firewall passage 664. Abundant information is buffered by the mobile client 110 using the outgoing spill buffer 662. This information is stored until the home agent 160 confirms receipt of the content, e.g. each segment of the content.
Each transmission port 660, 670 and 680 is also monitored by a transmission monitor 661, 671 and 681. The general transmission protocol 692 is monitored by the mobility controller 642. General information flows are also monitored by the statistics collector 646.
Incoming information is processed to pass through the firewall 664 and then verified and decrypted by the TLS / SSL unit 666. Once the information has been processed, it is sent via unit 640 to the lower decoder 636, the lower sender 638 and the upper decoder 634 and the upper the sender 632. These devices can perform several information processing steps, e.g. removal of aggregated information and decompression and decryption of the information stream or packet. For example
MM; P<sub>+</sub> .- :. 2 '7 M i,
MP -ΆΪΡΡ '\ -MPaM v \' 00 7 :? \ 21 00So »5 Mpp. n-, i:? / ·>. il;) Pnei · '·:! 'P>. 2 3 2 2 l ·. cc ;.
526 563 ····
<img file="SE526563C2_D0012.tif" />
·· · »* ♦ ·· ···» controls the port controller 620 information packets to the appropriate application port 610, 611 and 612.
The flow indexer 622 determines the information transfer rate of the transfer port and buffers and / or conveniently compresses the information. For example, for a slow connection, information is compressed to minimize the information size, e.g. the number of bytes, despite administration surcharges in the calculation time for processing the information. In contrast, for fast connections, e.g. when the transfer rate is not limiting, information is compressed using fast algorithms that achieve a more modest reduction in the information size, or no compression occurs at all.
Information transfer rates can also be monitored by applications to indicate the capacity of the active connection 240. For example, if the capacity is available, applications can process low-level network jobs in the background, such as backing up and updating files. If capacity is limited, applications can reduce their communication burden, e.g. by requesting text or WAP pages instead of graphics.
Referring to Figs. 7A, 7B and 7C in the right-to-left direction, the home agent 160 has a process configuration similar to that of the mobile client 110. Information from connections is mapped to transfer ports 760 and 770. The information is transmitted for passages 764 and 774. through the firewall and then for security verification and decryption 766 and 776. A router 740 di30 rigs incoming information to the lower decoder 736. Outgoing information is also routed to the router 740 toward the transfer ports 760 and 770 by outputting the contents of the spill buffers 762 and 772.
The mobility controller 742 monitors the overflow of information in these buffers 762 and 772, and can suitably control the output information through the rate limiter 772, the router 740 and the lower encoder 730.
526 563 :::
ί LM
<img file="SE526563C2_D0013.tif" />
Incoming information is processed by the lower decoder 736 and the upper decoder 734. These decoders are connected to the lower transmitter 738 which can issue channel or connection specific instructions, and the upper transmitter 732 which can issue application specific instructions. The decoded information can be hidden in individual records and then distributed to the correct application ports 710, 711 and 712 on the home agent 160. Thus, information from the application ports is mapped
610, 611 and 612 running on the home agent 160 on the corresponding application ports 710, 711 and 712 on the home agent 160. As described above, these application ports also generate outgoing information for delivery to the mobile device 110.
The information can be sent via the active connection
240 by means of a number of different methods, for example in packages or as a continuous stream.
The information sent as a packet can be merged. The information from different application ports can be combined so that individual instructions and data records from different applications are included in a single information package. This packet is encrypted and compressed as a single entity using the previously initiated protocols, thus obviating the need to include authentication, cryptography, and compression headers. The package is combined with a minimum of key information, such as a checksum and a package identifier. Upon receipt of the package, a confirmation is issued for the entire package, e.g. an identifier and / or checksum for the information received. The merging of data is in contrast to systems that send individual data packets for each network call made or data mail sent by individual applications. In addition to reducing administration allowances, merging a number of items enables larger individual information packages, which may include related items. By joint placement of related items, the latency time can be reduced, which depends
21138 ·· II - K 1.5: 1 ». Ν ΝαΟ, ι gili Mt ici ·: HKli 5 liiiARD.SOS
11: 861: 1616141: 6 = :::: 1515 :: 25 211016 7511 :). 1011: 55 Appl iciic i ™! L: »: x :. ”»: I rs κί: ru »: l:.: R MEM llll- t: -. .ÖG
PhV 03 · ii · i?
526 563 on misalignment of packets that occurs when conventional packets arrive in disarray.
Optionally, the protocol includes the reduction of information exchanges that take place back and forth. When desired, this function determines whether multiple information exchanges between the mobile device and a destination system 170 can be emulated by a proxy module running on the home agent 160. The proxy module interacts with the destination system 170 (i.e., a system other than the home agent 160) on behalf of the mobile client 110 without having to exchange information with the mobile client 110. The use of the proxy module reduces network traffic and overcomes inefficiencies due to the latency of some wireless connections. Proxy modules can be general, e.g. capable of supporting15 yes more than one application, or they may be dedicated, e.g. application specific.
For example, the use of a web browser requires at least three transfers of information back and forth, which can be avoided by using a proxymo20 dul. When a user enters a uniform resource locator (URL) for a website, the browser on the mobile client 110 normally first sends a request to a domain name's server to obtain the actual IP address of said URL. The mobile client 110 then initiates a TCP connection to the web server at the IP address. Only after confirmation does the mobile client 110 send an http request to the web server and then receive the hypertext content.
The use of a proxy module for the browser instead replaces the three return transmissions of information with a single exchange between the home agent 160 and the mobile client 110, thus reducing the information traffic on the active connection 240. When a user enters a URL for a website, this is sent
URL request via an active connection 240 to a proxy module on the home agent 160 or on a destination server 170. The proxy module requests the domain name server, initiates TCP li. : 3 0 V; \ t iöl. \ F3 3H P. 7 C ΟΑΓo .-- C · -, · ö / .Pani 2 .3 0 2 * 2 π) 050 '5 ΛρρΙ ica «: ioal <?, <.!. Te · rxut tacöör MET- '2003 2.3-3'.
526 563 · «···· • · • · · • · · ··· · connection and sends http request. These steps are performed without contacting the mobile client 110. When the proxy module receives the hypertext content, it directs the content back over the active connection 240 to the mobile client 110.
Another method of reducing network traffic involves the use of application-specific content reformatting. This property reformats information, in particular content. Irrelevant content can be removed to reduce the amount of data. For example, data by the home agent 160 is translated from HTML (hypertext markup language) and graphics format into i-mod or WAP compatible information.
The client 110 and / or the server 160 often have more than one application that sends information along a single active connection. Service quality protocols are used to determine which application has priority for information communication. Service quality parameters can be realized at many levels, for example at the level of the upper encoder 624 and the lower encoder 630, which combine network calls and data for different applications. The relative content of each merged data packet can be varied according to quality of service parameters.
In addition, the home agent 160, as well as the mobile client 110, can determine service quality. The quality of service may be asymmetric so that an application may have a high priority on the home agent 160 to send data to the mobile device 110, but may have a low priority on the mobile device 110 for sending data to the home agent.
160. A service quality parameter indicating priority for information exchange may be transmitted from the home agent 160 to the mobile device 110 or from the mobile device 110 to the home agent 160.
Other realizations are within the scope of the requirements.
For example, the techniques described herein are not limited to any particular hardware or software configuration; they can find applications in which computer35
526 563 or any treatment environment. The techniques can be realized in hardware, software or a combination of the two. The techniques can be realized in programs executing on programmable machines such as mobile or desktop computers, personal digital aids and similar devices each comprising a processor, a storage media readable by the processor (including volatile and non-volatile memories and / or storage elements), at least one input device and one or more output devices.
Each program can be implemented in a procedure-oriented or object-oriented high-level programming language for communicating with a machine system. However, the programs can be realized in assembler or machine language, if desired. In any case, the language can be a compiled or interpreted language.
Each such program can be stored on a storage media or device, e.g. CD-ROM, hard disk, magnetic disk or similar media or device, which is readable by a general or special programmable machine for configuring and handling the machine when the storage medium or device is read by the computer to perform the procedures described in this document. The system can also be realized as a machine-readable storage medium, configured with a program, where the storage medium configured in such a manner causes the machine to operate in a special and predefined manner.
The processes described here can be executed by an embedded system.
Contents4
22 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22
16 members in 7 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 81116101 | United States of America | A | |
| 81116101 | United States of America | A | |
| 0208355 | United States of America | W | |
| 0208355 | United States of America | W | |
| 811161 | – | – | – |
| PCTUS0208355 | – | – | – |
| US20010811161 | – | – | – |
| WO2002US08355 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| US2002133598A1 | United States of America | A1 | |
| WO02076063A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002248651A1 | Australia | A1 | |
| WO02076063A8 | World Intellectual Property Organization (WIPO) | A8 | |
| SE0302435D0 | Sweden | D0 | |
| FI20031292A | Finland | A | |
| SE0302435L | Sweden | L | |
| GB2389497A | United Kingdom | A | |
| GB2389497A8 | United Kingdom | A8 | |
| CN1498489A | China | A | |
| GB2389497B | United Kingdom | B | |
| SE526563C2This record | Sweden | C2 | |
| FI120073B | Finland | B | |
| CN1498489B | China | B | |
| US2011096741A1 | United States of America | A1 | |
| US9282011B2 | United States of America | B2 |
Numbers
- Publication, DOCDB
- 526563
- Publication, EPODOC
- SE526563
- Application
- 302435
- Application, DOCDB
- 0302435
- Application, EPODOC
- SE20030002435
Titles2
- Swedish
- Förfarande, anordning, organ och system för att bringa mobila anordningar i kontakt med servrar genom användandet av övervakade förbindelser
- English
- Method, apparatus, organs and systems to bring mobile devices into contact with the servers through the use of supervised connections
Classification
- CPC, 10
- H04L43/00
- H04L43/0811
- H04L43/0852
- H04L43/0894
- H04L67/14
- H04L67/04
- H04L69/329
- H04L67/62
- H04L9/40
- H04L67/01
- IPC, 4
- H04W72 54
- H04L12 26
- H04L29 06
- H04L29 08
