JP4538325B2 - 複数の管理対象エンティティーの安全な無線管理のためのプロキシ方法及びシステム - Google Patents
複数の管理対象エンティティーの安全な無線管理のためのプロキシ方法及びシステム Download PDFInfo
- Publication number
- JP4538325B2 JP4538325B2 JP2004560973A JP2004560973A JP4538325B2 JP 4538325 B2 JP4538325 B2 JP 4538325B2 JP 2004560973 A JP2004560973 A JP 2004560973A JP 2004560973 A JP2004560973 A JP 2004560973A JP 4538325 B2 JP4538325 B2 JP 4538325B2
- Authority
- JP
- Japan
- Prior art keywords
- message
- proxy
- wid
- operating system
- command
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
- 238000000034 method Methods 0.000 title claims abstract description 74
- 230000006854 communication Effects 0.000 claims description 54
- 238000004891 communication Methods 0.000 claims description 53
- 230000005540 biological transmission Effects 0.000 claims description 27
- 238000013475 authorization Methods 0.000 claims description 14
- 238000013507 mapping Methods 0.000 claims description 7
- 238000005516 engineering process Methods 0.000 abstract description 18
- 230000008569 process Effects 0.000 abstract description 16
- 238000004422 calculation algorithm Methods 0.000 abstract description 15
- 230000008901 benefit Effects 0.000 abstract description 4
- 238000007726 management method Methods 0.000 description 41
- 239000010410 layer Substances 0.000 description 24
- 230000004044 response Effects 0.000 description 21
- 239000003795 chemical substances by application Substances 0.000 description 16
- 230000009471 action Effects 0.000 description 15
- 238000012545 processing Methods 0.000 description 15
- 230000006870 function Effects 0.000 description 14
- 238000010586 diagram Methods 0.000 description 9
- 238000009434 installation Methods 0.000 description 6
- 238000012384 transportation and delivery Methods 0.000 description 5
- 238000012790 confirmation Methods 0.000 description 4
- 238000012546 transfer Methods 0.000 description 4
- 238000013459 approach Methods 0.000 description 3
- 230000004888 barrier function Effects 0.000 description 3
- 238000006243 chemical reaction Methods 0.000 description 3
- 229920001690 polydopamine Polymers 0.000 description 3
- 150000003839 salts Chemical class 0.000 description 3
- 239000000969 carrier Substances 0.000 description 2
- 238000013478 data encryption standard Methods 0.000 description 2
- 238000012217 deletion Methods 0.000 description 2
- 230000037430 deletion Effects 0.000 description 2
- 230000001419 dependent effect Effects 0.000 description 2
- 230000002829 reductive effect Effects 0.000 description 2
- 238000013515 script Methods 0.000 description 2
- 230000002123 temporal effect Effects 0.000 description 2
- 238000011282 treatment Methods 0.000 description 2
- 125000002066 L-histidyl group Chemical group [H]N1C([H])=NC(C([H])([H])[C@](C(=O)[*])([H])N([H])[H])=C1[H] 0.000 description 1
- 230000004075 alteration Effects 0.000 description 1
- 238000013474 audit trail Methods 0.000 description 1
- 230000001413 cellular effect Effects 0.000 description 1
- 230000001010 compromised effect Effects 0.000 description 1
- 230000003111 delayed effect Effects 0.000 description 1
- 238000013461 design Methods 0.000 description 1
- 238000001514 detection method Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 238000011982 device technology Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 230000002708 enhancing effect Effects 0.000 description 1
- 239000012530 fluid Substances 0.000 description 1
- 230000003100 immobilizing effect Effects 0.000 description 1
- 230000002452 interceptive effect Effects 0.000 description 1
- 238000002955 isolation Methods 0.000 description 1
- 239000002346 layers by function Substances 0.000 description 1
- 230000000670 limiting effect Effects 0.000 description 1
- 230000001343 mnemonic effect Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000002360 preparation method Methods 0.000 description 1
- 238000012857 repacking Methods 0.000 description 1
- 230000002441 reversible effect Effects 0.000 description 1
- 238000012216 screening Methods 0.000 description 1
- 238000010187 selection method Methods 0.000 description 1
- 230000035945 sensitivity Effects 0.000 description 1
- 101150062870 ssl3 gene Proteins 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0435—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply symmetric encryption, i.e. same key used for encryption and decryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0464—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload using hop-by-hop encryption, i.e. wherein an intermediate entity decrypts the information and re-encrypts it before forwarding it
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/061—Network architectures or network communication protocols for network security for supporting key management in a packet data network for key exchange, e.g. in peer-to-peer networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/101—Access control lists [ACL]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/04—Protocols specially adapted for terminals or networks with limited capabilities; specially adapted for terminal portability
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/08—Protocols specially adapted for terminal emulation, e.g. Telnet
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0838—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
- H04L9/0841—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
- H04L9/0844—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0863—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving passwords or one-time passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0866—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/76—Proxy, i.e. using intermediary entity to perform cryptographic operations
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/30—Definitions, standards or architectural aspects of layered protocol stacks
- H04L69/32—Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
- H04L69/322—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
- H04L69/329—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the application layer [OSI layer 7]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Small-Scale Networks (AREA)
- Computer And Data Communications (AREA)
Description
なお、本出願に対応する外国の特許出願においては下記の文献が発見または提出されている。
(メッセージ送信プロトコル)
(セキュリティ)
(プロキシ処理)
(ファイアウォールの背後への複数の安全なTELNETサービスの配達)
(プロキシ処理)
(メッセージ送信プロトコル)
(セキュリティ)
WIDが下記を作って送信すると仮定する:
<H>2.7^3^!@#$%^&*^(*$&@</H>*^%$#@!)%$(%1+!#$%^&*()%$*$#%%#$%%##%#EOT
これは下記のように分解する:
ヘッダ=<H>2.7^3^!@#$%^&*^(*$&@</H>
クライアント・バージョン 2.7
暗号化タイプ 3
WID ID !@#$%^&*^(*$&@ 秘密キー603で暗号化されている
メッセージ・ペイロード=*^%$#@!)%$(%1+!#$%^&*()%$*$#%%#$%%##%#EOT
*^%$#!)%$(%1+!#$%^&*()%$*$#%%#$%%##%#は下記のように解読される:
R 要求
9000 ゲット・キー
0 トークン
12−06−2002 日付
14:50:23 時刻
2.7 ソフトウェア・バージョン
105 ソフトウェア改訂番号
1 WIDタイプ
58745875 完全性検査エレメント(ICE)
その後、プロキシは、通信キーで暗号化された自分の応答を提供することができ、その応答でプロキシはWIDのために自分が行おうと意図していることの確認を1つのトークン及び1つのセッション・キーと共に供給し、その応答は例えば:
!$#@!%&*(&)*^)SDGA#Q%#!%^%*$^(*%HWG@$%TVR#!%EOT
であり、これをWIDは(通信キーを使って)次のように解読する:
A 応答
9000 キーを得る(GetKey)
9175F1764A54Ec3B トークン
2.7 ソフトウェア・バージョン
!%EP*)$&!$!@%&^*a((&b@%!$$@SDHW$^@!$!@$ セッション・キー
FalJTH(*&^^^%#jaAFei8jh031−84!@#$%^&*()*^&%$@@!!@#$%^EOT
であってよくて、これをプロキシは次のように解読する:
R 要求
9001 ログオン・ユーザー(Logon User)
9175F1764A54Ec3B トークン(再生を妨げる)
KEVINSRIMDEVICE WID ID
12−06−2002 日付
14:51:0 時刻
Kevin ユーザーID (許可を可能にする)
1056789039281 ユーザーIDE及びパスワードのハッシュされた値
&b(*&%^$#!@!〜!HARQERafa#$3453466$@$!%^&&EOT
これをWIDは下記のように解読する:
A 応答
A 応答
9001 ログオン・ユーザー
AB45C7990E2213D 新しいトークン
2.7 ソフトウェア・バージョン
F 認証
モード
ABCコミュニケーションズLtd:に認可されている ライセンス・メッセージ
例えば、セッション・キーで暗号化されていて最後の有効なトークンを含んでいる下記のメッセージがWIDからプロキシへ送られ得る:
*#&#%&*^&*Aqtwetyu#$&$HAqWRTY%@^@&*##EOT
これをプロキシは次のように解読する:
R 要求
6000 複数のサーバー/複数の処置
AB45C7990E2213D トークン
KEVINSRIMDEVICE WID ID
12−06−2002 日付
14:52:15 時刻
2.7バージョン ソフトウェア・バージョン
^*(%$)(*%%$jaeiBE45234626&*(%&$#(&(*_)*)_^*%$%^*(%$)(*%%$jaeiBE45234626&*(%&$#(&(*_)*)_^*%&%^*(%$)(*%%$jaeiBE45234626&*(%&$#(&(*_)*)_^*%&%^*(%$)(*%%$jaeiBE45234626&*(%&$#(&(*_)*)_^*%&%^*(%$)(*%%$jaeiBE45234626&*(%&$#(&(*_)*)_^*%&%EOB
これに対してWIDは次のように応答し:
ACKEOT
この確認を受信すると、プロキシは下記を送ることによってメッセージを完了させる:
*#&#%&*^&*Aqtwetyu#$&$HAqWRTY%@^@&*##*#&#%&*^&*Aqtwetyu#$&$HAqWRTY%@^@&*##*#&#%&*^&*Aqtwetyu#$&$HAqWRTY%@^@&*##Aqtwetyu#$&$HAqWRTY%@^@&*##*#&#%EOT
前述の例では、WIDは許可情報を下記のように解読することができる:
A 応答
6000 複数のサーバー/複数の処置
146745C79902213D 新しいトークン
2.7 ソフトウェア・バージョン
Domain A ドメインA
Server1 サーバー1(例えば管理対象エンティティー1)
TFTTFFFFFFFFFFF ドメインA/サーバー1で許される複数の処置
Domain A ドメインA
Server2 サーバー2(例えば管理対象エンティティー14)
TFTTFFTFFFTFFTT ドメインA/サーバー2で許される複数の処置
Domain B ドメインB
Server X サーバーX(例えば管理対象エンティティー36)
TTTTTTTTTTTTTTT ドメインB/サーバーXで許される複数の処置
(ファイアウォールの背後へのテルネット・サービスの安全な配達)
Claims (27)
- 複数の管理対象コンピュータを、前記複数の管理対象コンピュータにより信頼されているプロキシサーバを介して、無線で管理する方法であって、
前記管理対象コンピュータのための1以上のオペレーティングシステム・コマンドに対応し、前記1以上のオペレーティングシステム・コマンドそのものとは異なる少なくとも1つのコマンドを含み、符号化されたメッセージを、無線装置から送信するステップと、
前記プロキシサーバにおいて、前記メッセージを受信して復号し、前記無線装置を認証して、前記メッセージに含まれる前記少なくとも1つのコマンドに対応する前記1以上のオペレーティングシステム・コマンドを前記管理対象コンピュータ上で実行することが前記無線装置のユーザーに対して許可されている場合に、前記メッセージに含まれる前記少なくとも1つのコマンドを許可するステップと、
前記メッセージに含まれる前記少なくとも1つのコマンドに対応する前記1以上のオペレーティングシステム・コマンドを前記管理対象コンピュータ上で実行することが前記無線装置のユーザーに対して許可されている場合に、前記少なくとも1つのコマンドに対応する前記1以上のオペレーティングシステム・コマンドを、前記プロキシサーバから前記管理対象コンピュータへ送るステップと、
を含む方法。 - 前記複数の管理対象コンピュータは、LANに接続されたサーバーを含む、
請求項1に記載の方法。 - 前記無線装置は、無線ネットワークを通じてインターネットへアクセスする携帯用ディジタル計算装置を含む、
請求項2に記載の方法。 - 前記メッセージの送信は、無線又はインターネット手段を介しての送信、または、無線およびインターネット手段の組み合わせを介しての送信である、
請求項1から請求項3までの何れか一項に記載の方法。 - 前記メッセージは、前記少なくとも1つのコマンドのグループの記号表示を使用することによって符号化される、
請求項1から請求項4までの何れか一項に記載の方法。 - 前記メッセージは暗号化されており、
前記復号は、前記メッセージを解読し、解釈し、拡張して、前記プロキシサーバから前記管理対象コンピュータへ送信するのに適する前記1以上のオペレーティングシステム・コマンドを得ることを含む、
請求項1から請求項5までの何れか一項に記載の方法。 - 前記1以上のオペレーティングシステム・コマンドの少なくとも1つは、少なくとも1つのパラメータを要求し、
前記メッセージは、前記少なくとも1つのパラメータを更に含み、
前記拡張は、前記少なくとも1つのパラメータと前記1以上のオペレーティングシステム・コマンドの少なくとも1つとを結びつける、
請求項6に記載の方法。 - 前記認証および許可は、前記複数の管理対象コンピュータのためのプロキシとして動作する前記プロキシサーバによって実行される、
請求項1から請求項7までの何れか一項に記載の方法。 - 前記認証は、前記無線装置が前記プロキシサーバに登録されていること、または前記無線装置のユーザーが前記プロキシサーバに登録されていることを確かめることを含む、
請求項1から請求項8までの何れか一項に記載の方法。 - 前記認証は、前記無線装置が前記プロキシサーバに登録されていること、および前記無線装置のユーザーが前記プロキシサーバに登録されていることを確かめることを含む、
請求項1から請求項9までの何れか一項に記載の方法。 - 前記許可は、前記1以上のオペレーティングシステム・コマンドを実行するように前記管理対象コンピュータに要求することを前記無線装置のユーザーが許されていることを確かめることを含む、
請求項1から請求項10までの何れか一項に記載の方法。 - 前記1以上のオペレーティングシステム・コマンドの前記プロキシサーバから前記管理対象コンピュータへの前記送信は、前記無線装置と前記管理対象コンピュータとの接続無しで実行される、
請求項1から請求項11までの何れか一項に記載の方法。 - 前記無線装置のユーザーにより選択されたユーザーパスワードとは別の、装置パスフレーズが前記無線装置に割り当てられ、
前記復号は、前記装置パスフレーズに基づいて通信キーを生成し、前記メッセージを復号することを含む、
請求項1から請求項12までの何れか一項に記載の方法。 - 前記メッセージは、テルネット・サービスをファイアウォールの背後に配達するために使われる、
請求項1から請求項13までの何れか一項に記載の方法。 - 前記少なくとも1つのコマンドは、2以上のコマンドからなるシーケンスを含み、
前記メッセージは、前記シーケンスを前記シーケンスの記号表示にマッピングすることで、符号化される、
請求項1から請求項14までの何れか一項に記載の方法。 - 前記記号表示の少なくとも一部は、前記2以上のコマンドの暗号化に基づく、
請求項15に記載の方法。 - 前記1以上のオペレーティングシステム・コマンドは、マイクロソフト(登録商標)ウインドウズ(登録商標)のコマンドおよびUNIX(登録商標)のコマンドから選択される、
請求項1から請求項16までの何れか一項に記載の方法。 - ユーザーが複数の管理対象コンピュータを無線で管理するためのシステムであって、
前記管理対象コンピュータのための1以上のオペレーティングシステム・コマンドに対応し、前記1以上のオペレーティングシステム・コマンドとは異なる少なくとも1つのコマンドを含み、符号化されたメッセージを作成し、送信するように構成された無線装置と、
前記複数の管理対象コンピュータにより信頼されており、前記メッセージを受信して復号し、前記無線装置を認証して、前記メッセージに含まれる前記少なくとも1つのコマンドに対応する前記1以上のオペレーティングシステム・コマンドを前記管理対象コンピュータ上で実行することが前記無線装置のユーザーに対して許可されている場合に、前記少なくとも1つのコマンドを許可し、前記少なくとも1つのコマンドに対応する前記1以上のオペレーティングシステム・コマンドを、前記管理対象コンピュータへ送る、プロキシメッセージ・プロセッサと、
を含むシステム。 - 前記無線装置は、更に、無線ネットワーク作動可能にされる送信装置において動作するように構築され、セル電話機又はポケットベル(登録商標)を包含し、インターネットへアクセスする、
請求項18に記載のシステム。 - 前記プロキシメッセージ・プロセッサは、前記プロキシメッセージ・プロセッサにより使用されるようになっているインターネットへの接続部を含む、
請求項18または請求項19に記載のシステム。 - 前記プロキシメッセージ・プロセッサは、ポート80を開かせないけれども、インターネットに、また、前記複数の管理対象コンピュータがその上で動作するところのネットワークに接続するようになっていると共に適切な複数のアクセス権が認められているサーバーを含む、
請求項18から請求項20までの何れか一項に記載のシステム。 - 前記1以上のオペレーティングシステム・コマンドは、マイクロソフト(登録商標)ウインドウズ(登録商標)のコマンドおよびUNIX(登録商標)のコマンドから選択される、
請求項18から請求項21までの何れか一項に記載のシステム。 - 複数の管理対象コンピュータを、前記複数の管理対象コンピュータにより信頼されているプロキシサーバを介して、無線で管理する方法であって、
前記管理対象コンピュータのための1以上のオペレーティングシステム・コマンドのシーケンスに対応し、前記シーケンスそのものとは異なる少なくとも1つのコマンドを含み、符号化されたメッセージを、無線装置から送信するステップと、
前記プロキシサーバにおいて、前記メッセージを受信して復号し、前記無線装置を認証して、前記メッセージに含まれる前記少なくとも1つのコマンドに対応する前記1以上のオペレーティングシステム・コマンドの前記シーケンスを前記管理対象コンピュータ上で実行することが前記無線装置のユーザーに対して許可されている場合に、前記メッセージに含まれる前記少なくとも1つのコマンドを許可するステップと、
前記メッセージに含まれる前記少なくとも1つのコマンドに対応する前記1以上のオペレーティングシステム・コマンドの前記シーケンスを前記管理対象コンピュータ上で実行することが前記無線装置のユーザーに対して許可されている場合に、前記少なくとも1つのコマンドを、前記1以上のオペレーティングシステム・コマンドの前記シーケンスに拡張するステップと、
前記1以上のオペレーティングシステム・コマンドの前記シーケンスを、前記プロキシサーバから前記管理対象コンピュータへ送るステップと、
を含む方法。 - 前記1以上のオペレーティングシステム・コマンドの少なくとも1つは、少なくとも1つのパラメータを要求し、
前記メッセージは、前記少なくとも1つのパラメータを更に含み、
前記拡張するステップは、前記少なくとも1つのパラメータと前記1以上のオペレーティングシステム・コマンドの少なくとも1つとを結びつける、
請求項23に記載の方法。 - 複数の管理対象コンピュータを無線で管理するためのシステムであって、
複数の管理対象コンピュータにより信頼されており、
(a)無線装置から発生しており、前記管理対象コンピュータのための1以上のオペレーティングシステム・コマンドのシーケンスに対応し、前記シーケンスそのものとは異なる少なくとも1つのコマンドを含み、符号化されたメッセージを受信し、
(b)前記メッセージを復号し、
(c)前記無線装置を認証し、
(d)前記メッセージに含まれる前記少なくとも1つのコマンドに対応する前記1以上のオペレーティングシステム・コマンドのシーケンスを前記管理対象コンピュータ上で実行することが前記無線装置のユーザーに対して許可されている場合に、前記少なくとも1つのコマンドを許可し、
(e)前記少なくとも1つのコマンドを、前記1以上のオペレーティングシステム・コマンドの前記シーケンスに拡張するステップと、
(f)前記メッセージに含まれる前記少なくとも1つのコマンドに対応する前記1以上のオペレーティングシステム・コマンドのシーケンスを前記管理対象コンピュータ上で実行することが前記無線装置のユーザーに対して許可されている場合に、前記1以上のオペレーティングシステム・コマンドの前記シーケンスを、前記管理対象コンピュータへ送る、
ように構成されたプロキシメッセージ・プロセッサを含むシステム。 - 前記1以上のオペレーティングシステム・コマンドの少なくとも1つは、少なくとも1つのパラメータを要求し、
前記メッセージは、前記少なくとも1つのパラメータを更に含み、
前記プロキシメッセージ・プロセッサは、前記少なくとも1つのパラメータと前記1以上のオペレーティングシステム・コマンドの少なくとも1つとを結びつける、
請求項25に記載のシステム。 - 前記複数の管理対象コンピュータは、少なくとも2つの異なるドメインにまとめられている、
請求項25または請求項26に記載のシステム。
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US10/326,226 US7454785B2 (en) | 2002-12-19 | 2002-12-19 | Proxy method and system for secure wireless administration of managed entities |
| CA002414830A CA2414830C (en) | 2002-12-19 | 2002-12-19 | Proxy method and system for secure wireless administration of managed entities |
| PCT/CA2003/002036 WO2004057823A2 (en) | 2002-12-19 | 2003-12-19 | Proxy method and system for secure wireless administration of managed entities |
Publications (3)
| Publication Number | Publication Date |
|---|---|
| JP2006512806A JP2006512806A (ja) | 2006-04-13 |
| JP2006512806A5 JP2006512806A5 (ja) | 2006-12-14 |
| JP4538325B2 true JP4538325B2 (ja) | 2010-09-08 |
Family
ID=32683244
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP2004560973A Expired - Fee Related JP4538325B2 (ja) | 2002-12-19 | 2003-12-19 | 複数の管理対象エンティティーの安全な無線管理のためのプロキシ方法及びシステム |
Country Status (4)
| Country | Link |
|---|---|
| EP (1) | EP1576783A2 (ja) |
| JP (1) | JP4538325B2 (ja) |
| AU (1) | AU2003289796A1 (ja) |
| WO (1) | WO2004057823A2 (ja) |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20090279477A1 (en) * | 2005-08-30 | 2009-11-12 | Ntt Docomo, Inc. | Mobile station, wireless access network apparatus, and mobile communication system |
| GB2436417B (en) * | 2006-03-22 | 2008-02-20 | Nec Technologies | Radio access bearer transfer |
| CN106789615A (zh) * | 2017-02-04 | 2017-05-31 | 重庆优启科技有限公司 | 一种提高web处理并发请求的方法及使用其的服务站 |
| CN111193586B (zh) * | 2018-11-14 | 2023-01-13 | 中国移动通信有限公司研究院 | 一种信息处理方法、分组传送网设备及量子密钥设备 |
Family Cites Families (14)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5892905A (en) * | 1996-12-23 | 1999-04-06 | International Business Machines Corporation | Computer apparatus and method for providing a common user interface for software applications accessed via the world-wide web |
| US6119228A (en) * | 1997-08-22 | 2000-09-12 | Compaq Computer Corporation | Method for securely communicating remote control commands in a computer network |
| JP3929186B2 (ja) * | 1998-09-18 | 2007-06-13 | 三菱電機株式会社 | クライアント/サーバシステム |
| JP2000236348A (ja) * | 1999-02-16 | 2000-08-29 | Telecommunication Advancement Organization Of Japan | インターネットプロトコルを用いた遠隔機器の管理システム |
| JP2000285061A (ja) * | 1999-03-31 | 2000-10-13 | Nec Corp | プロキシアクセス制御システム |
| US6349336B1 (en) * | 1999-04-26 | 2002-02-19 | Hewlett-Packard Company | Agent/proxy connection control across a firewall |
| AU2001263240A1 (en) * | 2000-05-19 | 2001-12-03 | Ztango, Inc. | A system and user interface for managing users and services over a wireless communications network |
| JP2002094573A (ja) * | 2000-09-14 | 2002-03-29 | Shikoku Electric Power Co Inc | 機器の運用・管理システム |
| US6748215B1 (en) * | 2000-09-29 | 2004-06-08 | Qualcomm, Incorporated | Method and apparatus for performing a candidate frequency search in a wireless communication system |
| GB2367709B (en) * | 2000-10-07 | 2003-05-21 | Complementary Tech Ltd | Improvements in or relating to communications |
| US8812666B2 (en) * | 2001-01-29 | 2014-08-19 | Da Capital Fund Limited Liability Company | Remote proxy server agent |
| CA2342540A1 (en) * | 2001-03-29 | 2002-09-29 | Govindan Ravindran | System and method for management of remote devices in a network |
| JP2002312311A (ja) * | 2001-04-11 | 2002-10-25 | Hitachi Ltd | サービス連携システム |
| US20020193131A1 (en) * | 2001-06-18 | 2002-12-19 | International Business Machines Corporation | Mobile wireless management of servers and other resources |
-
2003
- 2003-12-19 EP EP03782045A patent/EP1576783A2/en not_active Withdrawn
- 2003-12-19 AU AU2003289796A patent/AU2003289796A1/en not_active Abandoned
- 2003-12-19 JP JP2004560973A patent/JP4538325B2/ja not_active Expired - Fee Related
- 2003-12-19 WO PCT/CA2003/002036 patent/WO2004057823A2/en not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| JP2006512806A (ja) | 2006-04-13 |
| EP1576783A2 (en) | 2005-09-21 |
| WO2004057823A2 (en) | 2004-07-08 |
| AU2003289796A1 (en) | 2004-07-14 |
| WO2004057823A3 (en) | 2004-09-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US7421735B2 (en) | Proxy method and system for secure wireless administration of managed entities | |
| US7814208B2 (en) | System and method for projecting content beyond firewalls | |
| US8332464B2 (en) | System and method for remote network access | |
| US7702901B2 (en) | Secure communications between internet and remote client | |
| US7660980B2 (en) | Establishing secure TCP/IP communications using embedded IDs | |
| US6529513B1 (en) | Method of using static maps in a virtual private network | |
| US7039713B1 (en) | System and method of user authentication for network communication through a policy agent | |
| US20030229786A1 (en) | System and Method for Application-Level Virtual Private Network | |
| US20040088539A1 (en) | System and method for securing digital messages | |
| WO2004107646A1 (en) | System and method for application-level virtual private network | |
| EP1384370B1 (en) | Method and system for authenticating a personal security device vis-a-vis at least one remote computer system | |
| US20050060534A1 (en) | Using a random host to tunnel to a remote application | |
| US7363486B2 (en) | Method and system for authentication through a communications pipe | |
| Bellovin et al. | Security mechanisms for the Internet | |
| JP4538325B2 (ja) | 複数の管理対象エンティティーの安全な無線管理のためのプロキシ方法及びシステム | |
| CA2414830C (en) | Proxy method and system for secure wireless administration of managed entities | |
| Bonachea et al. | SafeTP: Transparently securing FTP network services | |
| JP4866150B2 (ja) | Ftp通信システム、ftp通信プログラム、ftpクライアント装置及びftpサーバ装置 | |
| Mahmood | Transport layer security protocol in Telnet | |
| Bonachea et al. | SafeTP: Secure, Transparent, Interoperable FTP | |
| Gin | Building a Secure Short Duration Transaction Network | |
| WO2001035569A1 (en) | Method and system for data encryption and filtering | |
| Dalwadi | Network And Data Security | |
| JP2007324726A (ja) | ファイル共有サーバ装置、クライアント装置、印刷装置、ファイル共有システム、ファイル共有プログラム | |
| CA2260709A1 (en) | Method of using static maps in a virtual private network |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20060602 |
|
| A621 | Written request for application examination |
Free format text: JAPANESE INTERMEDIATE CODE: A621 Effective date: 20060927 |
|
| A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20061025 |
|
| A977 | Report on retrieval |
Free format text: JAPANESE INTERMEDIATE CODE: A971007 Effective date: 20090410 |
|
| A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20090428 |
|
| A601 | Written request for extension of time |
Free format text: JAPANESE INTERMEDIATE CODE: A601 Effective date: 20090724 |
|
| A602 | Written permission of extension of time |
Free format text: JAPANESE INTERMEDIATE CODE: A602 Effective date: 20090731 |
|
| A601 | Written request for extension of time |
Free format text: JAPANESE INTERMEDIATE CODE: A601 Effective date: 20090925 |
|
| A602 | Written permission of extension of time |
Free format text: JAPANESE INTERMEDIATE CODE: A602 Effective date: 20091002 |
|
| A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20091027 |
|
| A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20091222 |
|
| A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20100212 |
|
| TRDD | Decision of grant or rejection written | ||
| A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 Effective date: 20100615 |
|
| A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 |
|
| A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20100621 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20130625 Year of fee payment: 3 |
|
| R150 | Certificate of patent or registration of utility model |
Free format text: JAPANESE INTERMEDIATE CODE: R150 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20130625 Year of fee payment: 3 |
|
| S111 | Request for change of ownership or part of ownership |
Free format text: JAPANESE INTERMEDIATE CODE: R313113 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20130625 Year of fee payment: 3 |
|
| R350 | Written notification of registration of transfer |
Free format text: JAPANESE INTERMEDIATE CODE: R350 |
|
| LAPS | Cancellation because of no payment of annual fees |