System and method to support networking functions for mobile hosts that access multiple networks
    3.
    发明授权
    System and method to support networking functions for mobile hosts that access multiple networks 失效
    支持访问多个网络的移动主机的网络功能的系统和方法

    公开(公告)号:US07929528B2

    公开(公告)日:2011-04-19

    申请号:US12242771

    申请日:2008-09-30

    IPC分类号: H04L12/28 H04W4/00

    摘要: An IP-based corporate network architecture and method for providing seamless secure mobile networking across office WLAN, home WLAN, public WLAN, and 2.5 G/3 G cellular networks for corporate wireless data users. The system includes Internet roaming clients (IRCs), a secure mobility gateway (SMG), optional secure IP access (SIA) gateways, and a virtual single account (VSA) server. The IRC is a special client tool installed on a mobile computer (laptop or PDA) equipped with a WLAN adaptor and a cellular modem. It is responsible for establishing and maintaining a mobile IPsec tunnel between the mobile computer and a corporate intranet. The SMG is a mobile IPsec gateway installed between the corporate intranet and the Internet. It works in conjunction with the IRC to maintain the mobile IPsec tunnel when the mobile computer is connected on the Internet via a home WLAN, a public WLAN, or a cellular network. The SIA gateway is a special IPsec gateway installed in the middle of the wired corporate intranet and an office WLAN. It works with the IRC to ensure data security and efficient use of corporate IP addresses when the mobile computer is connected to the office WLAN. The VSA server manages authentication credentials for every corporate user based on a virtual single account concept. The Internet Roaming system can provide secure, always-on office network connectivity for corporate users no matter where they are located using best available wireless networks.

    摘要翻译: 一种基于IP的企业网络架构和方法,用于为企业无线数据用户提供跨办公室WLAN,家庭WLAN,公共WLAN和2.5 G / 3G蜂窝网络的无缝安全移动网络。 该系统包括互联网漫游客户端(IRC),安全移动网关(SMG),可选的安全IP接入(SIA)网关和虚拟单一帐户(VSA)服务器。 IRC是安装在配有WLAN适配器和蜂窝调制解调器的移动计算机(笔记本电脑或PDA)上的特殊客户端工具。 它负责在移动计算机和公司内部网之间建立和维护移动IPsec隧道。 SMG是安装在企业内部网和互联网之间的移动IPsec网关。 它与IRC一起工作,以便在移动计算机通过家庭WLAN,公共WLAN或蜂窝网络在因特网上连接时维护移动IPsec隧道。 SIA网关是安装在有线企业内部网和办公室WLAN中间的专用IPsec网关。 它与IRC一起工作,以确保在移动计算机连接到办公室WLAN时数据安全并有效利用公司IP地址。 VSA服务器根据虚拟单一帐户概念管理每个公司用户的身份验证凭据。 互联网漫游系统可以为企业用户提供安全,永远在线的办公网络连接,无论他们所在的地方使用最佳可用无线网络。

    SYSTEM AND METHOD TO SUPPORT NETWORKING FUNCTIONS FOR MOBILE HOSTS THAT ACCESS MULTIPLE NETWORKS
    4.
    发明申请
    SYSTEM AND METHOD TO SUPPORT NETWORKING FUNCTIONS FOR MOBILE HOSTS THAT ACCESS MULTIPLE NETWORKS 失效
    用于支持接入多个网络的移动网络的网络功能的系统和方法

    公开(公告)号:US20090022152A1

    公开(公告)日:2009-01-22

    申请号:US12242771

    申请日:2008-09-30

    IPC分类号: H04L12/56 H04L9/00

    摘要: An IP-based corporate network architecture and method for providing seamless secure mobile networking across office WLAN, home WLAN, public WLAN, and 2.5 G/3 G cellular networks for corporate wireless data users. The system includes Internet roaming clients (IRCs), a secure mobility gateway (SMG), optional secure IP access (SIA) gateways, and a virtual single account (VSA) server. The IRC is a special client tool installed on a mobile computer (laptop or PDA) equipped with a WLAN adaptor and a cellular modem. It is responsible for establishing and maintaining a mobile IPsec tunnel between the mobile computer and a corporate intranet. The SMG is a mobile IPsec gateway installed between the corporate intranet and the Internet. It works in conjunction with the IRC to maintain the mobile IPsec tunnel when the mobile computer is connected on the Internet via a home WLAN, a public WLAN, or a cellular network. The SIA gateway is a special IPsec gateway installed in the middle of the wired corporate intranet and an office WLAN. It works with the IRC to ensure data security and efficient use of corporate IP addresses when the mobile computer is connected to the office WLAN. The VSA server manages authentication credentials for every corporate user based on a virtual single account concept. The Internet Roaming system can provide secure, always-on office network connectivity for corporate users no matter where they are located using best available wireless networks.

    摘要翻译: 一种基于IP的企业网络架构和方法,用于为企业无线数据用户提供跨办公室WLAN,家庭WLAN,公共WLAN和2.5 G / 3G蜂窝网络的无缝安全移动网络。 该系统包括互联网漫游客户端(IRC),安全移动网关(SMG),可选的安全IP接入(SIA)网关和虚拟单一帐户(VSA)服务器。 IRC是安装在配有WLAN适配器和蜂窝调制解调器的移动计算机(笔记本电脑或PDA)上的特殊客户端工具。 它负责在移动计算机和公司内部网之间建立和维护移动IPsec隧道。 SMG是安装在企业内部网和互联网之间的移动IPsec网关。 它与IRC一起工作,以便在移动计算机通过家庭WLAN,公共WLAN或蜂窝网络在因特网上连接时维护移动IPsec隧道。 SIA网关是安装在有线企业内部网和办公室WLAN中间的专用IPsec网关。 它与IRC一起工作,以确保在移动计算机连接到办公室WLAN时数据安全并有效利用公司IP地址。 VSA服务器根据虚拟单一帐户概念管理每个公司用户的身份验证凭据。 互联网漫游系统可以为企业用户提供安全,永远在线的办公网络连接,无论他们所在的地方使用最佳可用无线网络。

    System and method to support networking functions for mobile hosts that access multiple networks
    5.
    发明授权
    System and method to support networking functions for mobile hosts that access multiple networks 失效
    支持访问多个网络的移动主机的网络功能的系统和方法

    公开(公告)号:US07441043B1

    公开(公告)日:2008-10-21

    申请号:US10334628

    申请日:2002-12-31

    IPC分类号: G06F15/173 G06F15/16

    摘要: An IP-based corporate network architecture and method for providing seamless secure mobile networking across office WLAN, home WLAN, public WLAN, and 2.5G/3G cellular networks for corporate wireless data users. The system includes Internet roaming clients (IRCs), a secure mobility gateway (SMG), optional secure IP access (SIA) gateways, and a virtual single account (VSA) server. The IRC is a special client tool installed on a mobile computer (laptop or PDA) equipped with a WLAN adaptor and a cellular modem. It is responsible for establishing and maintaining a mobile IPsec tunnel between the mobile computer and a corporate intranet. The SMG is a mobile IPsec gateway installed between the corporate intranet and the Internet. It works in conjunction with the IRC to maintain the mobile IPsec tunnel when the mobile computer is connected on the Internet via a home WLAN, a public WLAN, or a cellular network. The SIA gateway is a special IPsec gateway installed in the middle of the wired corporate intranet and an office WLAN. It works with the IRC to ensure data security and efficient use of corporate IP addresses when the mobile computer is connected to the office WLAN. The VSA server manages authentication credentials for every corporate user based on a virtual single account concept. The Internet Roaming system can provide secure, always-on office network connectivity for corporate users no matter where they are located using best available wireless networks.

    摘要翻译: 一种基于IP的企业网络架构和方法,用于为企业无线数据用户提供跨办公室WLAN,家庭WLAN,公共WLAN和2.5G / 3G蜂窝网络的无缝安全移动网络。 该系统包括互联网漫游客户端(IRC),安全移动网关(SMG),可选的安全IP接入(SIA)网关和虚拟单一帐户(VSA)服务器。 IRC是安装在配有WLAN适配器和蜂窝调制解调器的移动计算机(笔记本电脑或PDA)上的特殊客户端工具。 它负责在移动计算机和公司内部网之间建立和维护移动IPsec隧道。 SMG是安装在企业内部网和互联网之间的移动IPsec网关。 它与IRC一起工作,以便在移动计算机通过家庭WLAN,公共WLAN或蜂窝网络在因特网上连接时维护移动IPsec隧道。 SIA网关是安装在有线企业内部网和办公室WLAN中间的专用IPsec网关。 它与IRC一起工作,以确保在移动计算机连接到办公室WLAN时数据安全并有效利用公司IP地址。 VSA服务器根据虚拟单一帐户概念管理每个公司用户的身份验证凭据。 互联网漫游系统可以为企业用户提供安全,永远在线的办公网络连接,无论他们所在的地方使用最佳可用无线网络。

    Secure IP access protocol framework and supporting network architecture
    6.
    发明授权
    Secure IP access protocol framework and supporting network architecture 有权
    安全的IP接入协议框架和支持网络架构

    公开(公告)号:US08046577B2

    公开(公告)日:2011-10-25

    申请号:US10317694

    申请日:2002-12-12

    IPC分类号: H04L29/06

    摘要: A protocol framework for a Secure IP Access (SIA) method, and supporting components deployed on IP hosts and IP networks. Using this method, an IP host can establish a secure data channel within an IP network over an insecure shared link while requesting IP address and networking configuration parameters from the IP network. A system administrator can implement strong access control against various attacks that an edge IP network may have to face, such as a denial-of-service attack that exhausts assignable IP addresses. This is a lightweight, scalable, and backward-compatible solution that can improve security performance for public and corporate LANs having open access such as wireless access points and Ethernet jacks.

    摘要翻译: 用于安全IP接入(SIA)方法的协议框架,以及部署在IP主机和IP网络上的支持组件。 使用这种方法,IP主机可以通过不安全的共享链路在IP网络内建立安全数据通道,同时从IP网络请求IP地址和网络配置参数。 系统管理员可以对边缘IP网络可能必须面对的各种攻击实施强大的访问控制,例如耗尽可分配IP地址的拒绝服务攻击。 这是一个轻量级的,可扩展的和向后兼容的解决方案,可以提高具有开放访问权限的公共和公司LAN(如无线接入点和以太网插孔)的安全性能。

    Layer-2 IP networking method and apparatus for mobile hosts
    7.
    发明授权
    Layer-2 IP networking method and apparatus for mobile hosts 有权
    移动主机的二层IP组网方法和设备

    公开(公告)号:US07768980B1

    公开(公告)日:2010-08-03

    申请号:US11403767

    申请日:2006-04-13

    IPC分类号: H04L12/66 H04Q7/24 G06F15/173

    摘要: A method and apparatus to enable IP networking for mobile hosts without requiring changes to be made to the TCP/IP stack in the operating system installed on the mobile hosts. The apparatus is an “intelligent device” that can be installed on or connected to a mobile host, and may comprise a software-only logical module, physical hardware, or a combination of both. To a mobile host, the intelligent device emulates a network interface such as an Ethernet card or a telephone modem. The intelligent device appears to an access network just like any regular IP host connected to the access network through a physical network interface device. The intelligent device handles all mobile networking functions for the mobile host, and may control multiple different physical network interface devices to enable a connection to the “best” access network available to the mobile user at his location.

    摘要翻译: 一种用于为移动主机启用IP网络的方法和装置,而不需要对安装在移动主机上的操作系统中的TCP / IP栈进行更改。 该装置是可以安装在移动主机上或连接到移动主机的“智能设备”,并且可以包括仅软件逻辑模块,物理硬件或两者的组合。 对于移动主机,智能设备模拟诸如以太网卡或电话调制解调器之类的网络接口。 就像通过物理网络接口设备连接到接入网的任何常规IP主机一样,智能设备就像接入网络一样出现。 智能设备处理移动主机的所有移动网络功能,并且可以控制多个不同的物理网络接口设备,以便连接到他所在位置的移动用户可用的“最佳”接入网络。

    Mobile device having network interface selection
    8.
    发明授权
    Mobile device having network interface selection 失效
    具有网络接口选择的移动设备

    公开(公告)号:US07180876B1

    公开(公告)日:2007-02-20

    申请号:US10145973

    申请日:2002-05-14

    IPC分类号: H04Q7/20

    CPC分类号: H04W48/18 H04W88/06

    摘要: An access interface module includes a first network interface module for interfacing with a first access network and a second network interface module for interfacing with a second access network of a type that is different from the first network. The access module can further include a processor coupled to the first and second network interface modules and a device interface module coupled to the processor for interfacing with a host device.

    摘要翻译: 访问接口模块包括用于与第一接入网络接口的第一网络接口模块和用于与不同于第一网络的类型的第二接入网络进行接口的第二网络接口模块。 访问模块还可以包括耦合到第一和第二网络接口模块的处理器和耦合到处理器的与主机设备接口的设备接口模块。

    Layer-2 IP networking method and apparatus for mobile hosts
    9.
    发明授权
    Layer-2 IP networking method and apparatus for mobile hosts 有权
    移动主机的二层IP组网方法和设备

    公开(公告)号:US08462748B2

    公开(公告)日:2013-06-11

    申请号:US12829360

    申请日:2010-07-01

    IPC分类号: H04W4/00 H04L12/28 G06F15/173

    摘要: A method and apparatus to enable IP networking for mobile hosts without requiring changes to be made to the TCP/IP stack in the operating system installed on the mobile hosts. The apparatus is an “intelligent device” that can be installed on or connected to a mobile host, and may comprise a software-only logical module, physical hardware, or a combination of both. To a mobile host, the intelligent device emulates a network interface such as an Ethernet card or a telephone modem. The intelligent device appears to an access network just like any regular IP host connected to the access network through a physical network interface device. The intelligent device handles all mobile networking functions for the mobile host, and may control multiple different physical network interface devices to enable a connection to the “best” access network available to the mobile user at his location.

    摘要翻译: 一种用于为移动主机启用IP网络的方法和装置,而不需要对安装在移动主机上的操作系统中的TCP / IP栈进行更改。 该装置是可以安装在移动主机上或连接到移动主机的“智能设备”,并且可以包括仅软件逻辑模块,物理硬件或两者的组合。 对于移动主机,智能设备模拟诸如以太网卡或电话调制解调器之类的网络接口。 就像通过物理网络接口设备连接到接入网的任何常规IP主机一样,智能设备就像接入网络一样出现。 智能设备处理移动主机的所有移动网络功能,并且可以控制多个不同的物理网络接口设备,以便连接到他所在位置的移动用户可用的“最佳”接入网络。