首页> 外国专利> Computer equipment and software to provide IP mobility across borders continuous security.

Computer equipment and software to provide IP mobility across borders continuous security.

机译:提供跨境IP移动性的计算机设备和软件,持续安全。

摘要

An arrangement and a computer program product, for providing seamless IP mobility across a security boundary between two domains, secure domain (105) and insecure domain (107), is described. The invention comprises a novel architecture of known network infrastructure components, inner system home agent (130) and outer system home agent (102) along with enabling client software on the user device (103). The specific client software as well as the novel architecture represents the invention. Unlike state-of-art today, the method is based on the combined use of independent IP mobility systems in each of the two domains. The key to the invention is client software being able to operate with both mobility systems simultaneously. Moreover, communication takes place in such a way that the ordinary remote access security solution is in control of all access to the secure home domain of the user. The resulting method provides secure and seamless IP mobility in any domain with independent choice of mobility and security technologies. The invention does not require any significant changes (adaptations nor extensions) to any IP mobility or security technology beyond existing or upcoming standards. Nor does it require any significant changes to existing infrastructure components. The mobility client software is the only component that is affected, thus making the method client-centric, as opposed to a network-centric approach that is otherwise the alternative. The invention applies both for the current IPv4 family of standards as well as the forthcoming IPv6 family of standards. The invention applies in particular for the Mobile IP and IPSec VPN standards but is not restricted to these technologies. The invention is applicable for any IP mobility and IP security protocols as long as they are based on the same set of underlying principles. IMAGE
机译:描述了一种用于在安全域(105)和不安全域(107)这两个域之间的安全边界上提供无缝IP移动性的装置和计算机程序产品。本发明包括已知网络基础设施组件,内部系统归属代理(130)和外部系统归属代理(102)以及在用户设备(103)上启用客户端软件的新颖架构。特定的客户端软件以及新颖的体系结构代表了本发明。与当今的最新技术不同,该方法基于两个域中每个域中独立IP移动系统的组合使用。本发明的关键是能够同时与两个移动性系统一起操作的客户端软件。此外,通信以普通的远程访问安全解决方案控制对用户的安全本地域的所有访问的方式进行。所得方法通过独立选择移动性和安全性技术,可在任何域中提供安全无缝的IP移动性。本发明不需要对任何IP移动性或安全技术进行任何超出现有或即将来临的标准的重大改变(改编或扩展)。它也不需要对现有基础架构组件进行任何重大更改。移动客户端软件是受影响的唯一组件,因此使该方法以客户端为中心,而以网络为中心的方法则相反。本发明既适用于当前的IPv4标准族,也适用于即将推出的IPv6标准族。本发明尤其适用于移动IP和IPSec VPN标准,但不限于这些技术。本发明适用于任何IP移动性和IP安全协议,只要它们基于相同的基础原理集即可。 <图像>

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号