TWI225736B - Mobile network agent - Google Patents

Mobile network agent Download PDF

Info

Publication number
TWI225736B
TWI225736B TW92128761A TW92128761A TWI225736B TW I225736 B TWI225736 B TW I225736B TW 92128761 A TW92128761 A TW 92128761A TW 92128761 A TW92128761 A TW 92128761A TW I225736 B TWI225736 B TW I225736B
Authority
TW
Taiwan
Prior art keywords
mobile
network
agent
mobile device
network system
Prior art date
Application number
TW92128761A
Other languages
Chinese (zh)
Other versions
TW200515729A (en
Inventor
Jan-Ming Ho
Chun-Hsin Wu
An-Tzung Cheng
Chih-Chung Huang
Original Assignee
Academia Sinica
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Academia Sinica filed Critical Academia Sinica
Priority to TW92128761A priority Critical patent/TWI225736B/en
Application granted granted Critical
Publication of TWI225736B publication Critical patent/TWI225736B/en
Publication of TW200515729A publication Critical patent/TW200515729A/en

Links

Abstract

A mobile network agent is installed in any network system. The mobile network agent automatically obtains the identification information of a mobile device that requests to establish connection with the network system and authenticate the identity of the mobile device. The authentication information is notified to the network system and the home network or the virtual private network (VPN) server of the mobile device. Communication packages coming from the home network or the VPN are received by the mobile network agent directly and are transmitted to the mobile device. On the other hand, communications packages coming from the mobile device are transmitted to the home network or the VPN via the mobile network agent, to be processed by the latter. Under the present invention, even if the mobile device or its home network is not installed with the mobile network agent, a mobile device is allowed to roam from network to network via a network system installed with the mobile network agent of this invention.

Description

1225736 五、發明說明(1) 一、 【發明所屬技術領域】 種使 仍能維持良 本發明是關於一種行動網路代理器,特別是關於 行動裝置能在不同I P網段(s e g m e n t )間漫遊, 好通信品質的行動網路代理器。 二、 【先前技術】 由於網際網路及行動通信應用技術的發達,利用具 動運算能力的行動裝置(mob i 1 e d ev i ce )連結無線網路系行 統,進入網際網路存取所需資訊,已經成為日益重要的應、 用。各種提供可攜式裝置,例如筆記型電腦、個人數位助理 等在網路系統或I P網段間漫遊的技術,乃應運而生。國際間 也針對這種急迫的需求,制定各種規範及標準。例如I E E £ 8 〇 2 · 1 X標準等。 」 目前可見的行動裝置漫遊技術,主要是建立在所謂的 AAA 架構(Authentication, Authorization and Accounting infrastructure),來進行行動裝置所連結的 系統廠商(operator )間的漫遊資訊交換協定。在這種架構 之下,行動裝置與任一網路系統連線時,需進行連線,取得 認證與授權。而當離開該系統,進入另一網路系統之範圍 (即所謂之網段)時,則需與前系統中斷連線,再與次一系 、统進行連線’另外取得認證與授權,才能執行相同的網路資 机存取。此種斷線、連線過程,不但費時,且於斷線前所進 行之資訊存取,也可能因而中斷,無法回存(retrieve)或 回復(resume ),造成不便。 此外’習知技術之行動裝置在進行漫遊之前,需在其原1225736 V. Description of the invention (1) 1. [Technical field to which the invention belongs] This invention can still maintain the present invention. The present invention relates to a mobile network agent, and in particular, the mobile device can roam between different IP network segments. Mobile communication agent with good communication quality. 2. [Previous Technology] Due to the development of Internet and mobile communication application technologies, mobile computing devices (mob i 1 ed ev i ce) with mobile computing capabilities are used to connect to wireless network systems and enter Internet access stations. The need for information has become an increasingly important application. Various technologies have been developed to provide portable devices, such as laptops, personal digital assistants, to roam between network systems or IP network segments. In response to this urgent need, various regulations and standards have been developed internationally. For example, I E E £ 8 2 · 1 X standard and so on. The currently available mobile device roaming technology is mainly based on the so-called AAA architecture (Authentication, Authorization and Accounting infrastructure) to perform roaming information exchange protocols between system manufacturers (operators) connected to mobile devices. Under this architecture, when a mobile device connects to any network system, it needs to be connected to obtain authentication and authorization. When leaving the system and entering the scope of another network system (so-called network segment), you need to disconnect from the previous system and then connect with the next system and system. Perform the same network asset access. This disconnection and connection process is not only time-consuming, but the information access before the disconnection may also be interrupted, and it cannot be retrieved or resumed, causing inconvenience. In addition, the mobile device of the conventional technology must be

1225736 五、發明說明(2) 所屬網路系統(home network )經過認證與授權,才能在漫 遊時與外部系統(f 〇 r e i g η n e t w ◦ r k )進行連線。如果未取 得原網路系統所給予的I P位址,則無法連上提供漫遊服務之 網路系統,進行資訊之存取。 在網路系統存在防火牆(f i r e w a 1 1 )之情形下,因為漫 遊的結果,如果發生I P位址互相衝突(c ο 1 1 i s i ο η ),例如 二個以上使用相同I P位址,但源自不同原網路系統之行動裝 置同時連上一網路系統,則發生混淆,輕則發出警訊,重則 影響資訊存取的正確性。某些網路服務在發生I P位址衝突 時,即無法使用。 雖然有上述困難,但無論如何,使用習知之行動裝置’ 漫遊服務,均需在行動裝置上建置(1 ns ta 1 1 )身份認證裝 置或軟體,才能進行漫遊時的身份認證程序。對於行動裝置 漫遊應用,增加不便。 因此目前必須有一種新穎的行動網路代理器,該代理器 可裝置於網路系統端,以自動辯識行動裝置之身份,而提供 行動裝置漫遊服務。 同時也需有一種行動網路代理器,可以使得未建置網路 漫遊身份辯識工具之行動裝置,方便進行網路漫遊。 同時也有必要提供一種行動網路代理器,可以免除行動裝置 在網路間漫遊時一再認證、授權之手續。 同時也必須有一種行動網路代理器,可以避免行動裝置 在變更連結網路系統時,發生通信中斷之現象。 三、【發明内容】1225736 V. Description of the invention (2) The home network must be authenticated and authorized before it can connect with the external system (f 〇 r e i g η n e t w ◦ r k) while traveling. If the IP address given by the original network system is not obtained, the network system providing roaming service cannot be connected for information access. In the case of a firewall (firewa 1 1) in the network system, if the IP addresses conflict with each other (c ο 1 1 isi ο η) because of roaming results, for example, two or more use the same IP address, but originate from When mobile devices of different original network systems are connected to a network system at the same time, there will be confusion, a warning signal will be issued, and the accuracy of information access will be affected. Some Internet services are unavailable when IP address conflicts occur. In spite of the above difficulties, no matter how to use the conventional mobile device ’roaming service, an (1 ns ta 1 1) identity authentication device or software must be installed on the mobile device to perform the identity authentication process when roaming. For mobile device roaming applications, it is inconvenient. Therefore, there must be a novel mobile network agent that can be installed on the network system to automatically identify the identity of the mobile device and provide mobile device roaming services. At the same time, a mobile network agent is also needed to enable mobile devices without a network roaming identification tool to facilitate network roaming. At the same time, it is also necessary to provide a mobile network agent, which can eliminate the need for mobile devices to repeatedly authenticate and authorize when roaming between networks. At the same time, there must be a mobile network agent, which can avoid the communication interruption of mobile devices when changing the connection network system. Third, [invention content]

第8頁 1225736Page 8 1225736

五、發明說明(3) 本發明之目的即在提供一種新穎 代理器可裝置於網路系統端,以^ : /動、、罔路代理器,該 而提供行動裝置漫遊服務。 力辯識行動裝置之身份’ 本發明之目的即在提供一種行動網路 哭 … 置網路漫遊身份辯識工具之行動壯 可以使付未建 同時也有必要提供一種行動、;路代進;網:J遊。 裝置在網路間漫遊時一再認證、授權之手二j可以免除仃動 本發明之目的即在提供一種行動網 行動更連結網路系統時,發生通】…= 統中,該網路代理器可以自動读;』各種網路系 份’自動將其I Ρ位址及該行動網理所:::土置之身 知該網路系統,及送至其所屬之;= 之網路位址通 = ”路(Virtua"⑽te Netw〇rk_vpN)飼 直接由,-:、原網路糸統或其VPN伺服器之通信封包,則 該行動Γ署丁!網路代理器接收,轉送至該行動裝置。同時, 回其原網路之通信封包,則透過該行動網路代理器送 明之行動細伺服器由後者進行必要之處理。本發 在該行代理器不需裝置在該行動裝置中,也不需建置 動網路代理:之原網路系統中。任何網路系統只需建置該行 事置, 為’即可使未裝置漫遊服務身份辯識工具之行動 ",進行網路漫遊。 、 參照ίΐϊ其他本發明之目的及優點,可由以下詳細說明並 口式而更形清楚。V. Description of the invention (3) The purpose of the present invention is to provide a novel agent that can be installed on the network system side to provide mobile device roaming services. The purpose of the present invention is to provide a mobile network to cry ... The action of setting up a network roaming identification tool can make Fu Weijian also need to provide an action; : J Tour. The device repeatedly authenticates and authorizes hands when roaming between networks. The purpose of the present invention is to provide a mobile network to connect to a network system, and communication occurs] ... = In the system, the network agent Can read automatically; "Various network components" automatically send its IP address and the mobile network office :: Tu Zhizhi knows the network system, and sends it to its own; = network address The communication path "Virtua " ⑽te Netw〇rk_vpN" feeds directly from,-:, the communication packet of the original network system or its VPN server, then the action is signed! The network agent receives and forwards it to the action At the same time, the communication packet back to the original network will be processed by the mobile detailed server sent by the mobile network agent. The latter does not need to be installed in the mobile device. There is also no need to set up a mobile network agent: in the original network system. Any network system only needs to set up this service device to perform the network operation of "the identification tool for roaming service without device installation". Roaming, refer to other objects of the present invention And advantages, may be the following detailed description and the bayonet even more apparent.

1225736 五、發明說明(4) 四、【實施方法】 以下依據圖式說明本發明之行動網路代理器。 第1圖顯示一個網路系統之示意圖。圖中,標為(1 0 ) 者為行動裝置(90)所屬之原網路系統(home network), 包括一虛擬私人網路(virtual private network, VPN )词 服器(1 1 )、一網路問道器(gate way ) ( 1 2 )、一行動代1225736 V. Description of the invention (4) 4. [Implementation method] The mobile network agent of the present invention will be described below with reference to the drawings. Figure 1 shows a schematic diagram of a network system. In the figure, the one marked with (1 0) is the home network system to which the mobile device (90) belongs, including a virtual private network (VPN) server (1 1), a network Gate way (1 2), one action generation

理器(13 )、多數之通信節點(correspondence node, CN )(1 4 )、一台印表機(1 5 ),尚可包括其他電腦、通信設 備,而形成一網路系統。該行動裝置(9 〇 )在其原網路系統 (1 0 )中有註冊之位址(帳號),而在該VPN伺服器(1 j ) 也註冊用戶編號;該Gate way ( 1 2 )及VPN伺服器(1 1 )則具 有網際網路之I P位址。 於第1圖中顯示,該行動裝置 ^ 一 > 、9 U )係原與第1外界網μ 系統(foreign network ) (20 )連線,而由該第丨外界網路 系統(2 0 )之連線狀態,轉而與第2外界網路系統(3 〇 )進 巧線二各外界網路系統(20) (3〇)均可能具有或不具有 理!!服裔(31 ) 、GateWay或路由器(22 ) ( 3 2 ),行動代 路t ⑶)及通信節點(24) (34)等。此夕卜,在網The processor (13), most of the communication nodes (CN) (1 4), and a printer (1 5) can also include other computers and communication equipment to form a network system. The mobile device (90) has a registered address (account number) in its original network system (10), and a user number is also registered in the VPN server (1j); the Gate way (1 2) and The VPN server (1 1) has the IP address of the Internet. It is shown in FIG. 1 that the mobile device ^ a >, 9 U) is originally connected to the first external network μ system (foreign network) (20), and the first external network system (20) The connection status, and then enter the second external network system (30) into the second line. Each external network system (20) (30) may or may not have reason! Servants (31), GateWay Or router (22) (3 2), mobile agent (t ⑶) and communication node (24) (34) and so on. Now, on the net

= =數ί其他通信節點⑷)。圖中閃電符號 )代表連線,前頭Α代表移轉連線。 本發明之行動網路代理哭r〇/ 該行動裝置(90 )漫遊之服務 (23 ) ( 3 3 )乃在提供 理器之系統圖。 乃。苐2圖即顯示本發明行動代 如第2圖所示,本發明之行動 、、同路代理器(5〇 )係介於行動= = Number ί other communication nodes ⑷). The lightning symbol) in the figure represents the connection, and the front A represents the transfer connection. The mobile network agent of the present invention is crying. The mobile device (90) roaming service (23) (33) is providing a system diagram of the processor. But. Figure 2 shows the action generation of the present invention. As shown in Figure 2, the action of the present invention and the same agent (50) are in the action.

1225736 五、發明說明(5) 裝置(40 )與一網路系統(6〇 )之 置辨識模組(51 ),用以在行動裝置、n /、有:一個行動裝 )請求建立連線時,掏取該行動筆^罔路系統(60 之VPN伺服器之認證資訊,而取得苴與其原網路系統 包傳輸模組(52),用以收、送行動:貝:;-個資訊封 系統(60 )與外界交換之資訊;一 :^40 )透過該網路 (…,用以在該行動裝】(40):==連線模組 動網路代理器時,與該行動網路代理路:統具有行 網段交替處理模組(54),用以在行;J =通^ -個 時’取得其原連線網路系統之位址、、,上2建立連線 戶Vi: 訊;及一個IP衝突處理模組(55),用以在 置之1?位址或帳號與其他電腦裝置或系統之 =立址相同日夺’進行資料流的分流。以下分別說明之。 仃動裝置辨識模組 本發明行動網路代理器之行動裝置辨識模組(51 )具有 自動取得行動裝置(9 0 )身份負訊的功能。在本發明之實例 中’行動網路代理器乃是在行動裝置(90 )與原網路系統 (1 0 )的V P N祠服器(11 )建立連線時,由行動裝置辨識模 組(5 1 )擷取其身份認證資訊。在作法上,可利用監聽網路 封包之方式,在行動裝置(9 0 )連線,請求其原網路系統 (1 〇 )之VPN伺服器(Π )認證其身份時,啟動行動網路代 理器(50 ),而進行網路封包之監聽。當VPN伺服器(1 2 ) 回覆行動裝置(9 0 ),送出認證結果封包時,即可取得認證 狀態資訊。例如在PPTP (P〇int-to-point Tunneling1225736 V. Description of the invention (5) The device (40) and an identification module (51) of a network system (60) are used when a mobile device, n /, and: a mobile device) requests to establish a connection , Obtain the authentication information of the mobile pen 罔 罔 路 system (60 VPN server, and get the original network system package transmission module (52), to receive and send the action: shell :;-an information cover The system (60) exchanges information with the outside world; one: ^ 40) through the network (..., used to install in the mobile) (40): == when the module is connected to the mobile network agent, and the mobile network Road agent road: It has a line network segment alternate processing module (54), which is used for travel; J = pass ^-each time 'to obtain the address of its original connected network system Vi: communication; and an IP conflict processing module (55), which is used to offload data streams when the address or account is set to the same address as other computer devices or systems.仃 Automatic device identification module The mobile device identification module (51) of the mobile network agent of the present invention has the ability to automatically obtain the identity of the mobile device (90). In the example of the present invention, the 'mobile network agent is a module identified by the mobile device when the mobile device (90) establishes a connection with the VPN server (11) of the original network system (1 0). The group (5 1) retrieves its identity authentication information. In practice, it can use the method of monitoring network packets to connect to the mobile device (90) and request the VPN server of its original network system (10). Π) When verifying its identity, start the mobile network proxy (50) and listen for network packets. When the VPN server (1 2) responds to the mobile device (90) and sends the authentication result packet, it can be obtained Authentication status information. For example, in PPTP (P〇int-to-point Tunneling

第11頁 1225736 五、發明說明(6)Page 11 1225736 V. Description of the invention (6)

Protocol )之VPN中,VPN伺月艮器會利用PPP (Point-to-point Protocol )來傳送認證資料與結果。因 此封包未加密,故可由行動裝置辨識模組(5 1 )取得其内 容,加以記錄,而利用此身份資料,進行其控制。 在本發明另一些實例中,行動裝置辨識模組(5 1 )係使用 SNMP (Simple Network Management Protocol ,簡單網路 管理協定)來查詢使用者認證狀態。在這種模式下,可使用 pol 1 ing或trap方式向VPN伺服器(1 1 )詢問。此外,也可以 在VPN伺服器(1 1 )中提供一介面,以供行動代理器之行動 裝置辨識模組(5 1 )查詢行動裝置(9 0 )認證狀態,或直接 在行動代理器中内建VPN伺服器。均可達到類似效果。 在應用之場合,行動裝置(9 0 )並非在原網路系統(1 0 )上進行連線,而是在第1外界網路系統(2 0 )上進行連 線。此外,行動裝置(9 0 )與第1外界網路系統(2 0 )是透 過一般網路系統之通信規約進行連線。 由於第1外部網路系統(2 0 )具有一行動網路代理器(2 3 ),該代理器(2 3 )之行動裝置辨識模組(5 1 )乃擷取行動 裝置(9 0 )與其所屬原網路系統(1 〇 )之VPN伺服器(1 2 ) 之網路封包,辯認其身份,予以記錄。在此情形下,行動網 路代理器(23)是利用 proxy ARP (Address resolution protocol )來導引行動裝置(90 )的通信封包。 資訊封包傳輸模組 本發明之資訊封包傳輸模組(5 2 )係用以代替行動裝置 (9 0 )傳送及接收資訊封包。In a Protocol (VPN) VPN, the VPN server uses Point-to-point Protocol (PPP) to send authentication data and results. Therefore, the packet is not encrypted, so the content can be obtained and recorded by the mobile device identification module (51), and the identity data is used for its control. In some other examples of the present invention, the mobile device identification module (51) uses SNMP (Simple Network Management Protocol, Simple Network Management Protocol) to query the user authentication status. In this mode, you can query the VPN server (1 1) using pol 1 ing or trap. In addition, an interface can also be provided in the VPN server (1 1) for the mobile device identification module (5 1) of the mobile agent to query the authentication status of the mobile device (9 0), or directly in the mobile agent. Build a VPN server. Can achieve similar results. In the application, the mobile device (90) does not connect on the original network system (10), but connects on the first external network system (20). In addition, the mobile device (90) and the first external network system (20) are connected through a communication protocol of a general network system. Since the first external network system (20) has a mobile network agent (2 3), the mobile device identification module (5 1) of the agent (2 3) captures the mobile device (9 0) and its The network packet of the VPN server (1 2) of the original network system (10) belongs to, identify its identity, and record it. In this case, the mobile network agent (23) uses a proxy ARP (Address resolution protocol) to guide the communication packet of the mobile device (90). Information packet transmission module The information packet transmission module (5 2) of the present invention is used to send and receive information packets instead of a mobile device (90).

第12頁 1225736 五、發明說明(7) 第3圖即顯示/種適用在本發明行動網路代理器之通信模式 示意圖。如第3圖所示,在行動裝置(9 0 )之原網路系統 (1 0 )及第1外界網路系統(2 0 )中,均設置有行動網路代 理器(13 )及(23 )。行動裝置(90 )與外界通信節點(44 )間之通信,是透過原網路系統(1 〇 )之VPN伺服器(11 ) 進行;所收送的資訊乃是解除封包(d e c a p s u 1 a t e d )的資 訊。 適用於本發明之外界通信節點(44 )包括任何Web server*、FTP server等。所接收來自行動裝置(90 )的封包 可以利用V P N伺服器(1 1 )指定給V P N用戶(c 1 i e n t )之I P位 址,識別身份。該I P位址可以在行動装置(9 0 )完成連線 後,由V P N祠服為(11 )指派。不過,此I p位址也可能經由 網路位址轉換(network address translation)轉換成其 他I P位址。 由外界通#郎點(4 4 )送給行動裝置(9 〇 )之封包,則 是根據一般I P繞路(I P rou t i ng )規則,傳遞到原網路系統 (1 0 )的行動代理器(1 3 ),之後再由原網路系統(1 〇 )將 封包轉送到第1外界網路系統(2 0 ),由其行動代理器(2 3 )之資訊封包傳輸模組送到行動裝置(9 〇 )。 在第3圖的實例中’行動裝置(90 )與VPN伺服器(丨丨)間的 通信,是透過外界行動代理器(23 ),經由原網路系統(i 〇 )之行動代理器(1 3 )進行。因此,在行動裝置(9 〇 )與原 網路系統(1 0 )之行動代理器(丨3 )間,是利用vpN穿隧 (VPN tunneling)為其通信通道。適用之方式包括ppTpPage 12 1225736 V. Description of the invention (7) Figure 3 shows a schematic diagram of the communication mode applicable to the mobile network agent of the present invention. As shown in FIG. 3, mobile network agents (13) and (23) are provided in the original network system (1 0) and the first external network system (20) of the mobile device (90). ). The communication between the mobile device (90) and the external communication node (44) is performed through the VPN server (11) of the original network system (10); the information received is decapsu 1 ated Information. The external communication nodes (44) applicable to the present invention include any Web server *, FTP server, and the like. The received packet from the mobile device (90) can be identified by using the IP address assigned by the VPN server (1 1) to the VPN user (c 1 i e n t). The IP address may be assigned by V P N Temple Service (11) after the mobile device (90) completes the connection. However, this IP address may also be converted into another IP address through network address translation. The packet sent by the external communication # Langdian (4 4) to the mobile device (90) is passed to the mobile agent of the original network system (10) according to the general IP routing rules. (1 3), and then the original network system (10) forwards the packet to the first external network system (20), and the information packet transmission module of its mobile agent (2 3) is sent to the mobile device (9 0). In the example in FIG. 3, the communication between the mobile device (90) and the VPN server (丨 丨) is through an external mobile agent (23) and a mobile agent (1) of the original network system (i). 3) Perform. Therefore, between the mobile device (90) and the mobile agent (3) of the original network system (10), vpN tunneling (VPN tunneling) is used as its communication channel. Applicable methods include pptp

第13頁 1225736 五、發明說明(8) tunneling等。這層tunneling是由行動裝置(90)與行動代 理器(2 3 ) ( 1 3 )進行包裝及解包裝。 此外,由於行動裝置(90 )與原網路系統(1 0 )之VPN 伺服器(Π )間之通信,乃是透過外界行動代理器(2 3 )與 原系統行動代理器(1 3 )為之,在兩行動代理器(2 3 ) (13 )間,可使用行動IP穿隧(mobile IP tunneling)技術進 行。適用之方式包括IP-in- IP tunneling 或 GRE (Generic Routing Encapsulation ) tunneling 等。此層之tunneling 是由雙方之行動代理器(2 3 ) ( 1 3 )負責包裝。 利用上述設計,當行動裝置(9 0 )透過第1外界網路系 統(20 )與其原網路系統(1 〇 )之vpn伺服器(1 1 )進行連 線時,雙方之行動網路代理器(2 3 ) ( 1 3 )均可自動偵測在 此請求,而加以接管。行動代理器(2 3 ) ( 1 3 )透過監聽其 連線封包而得知認證資訊,進而建立連線。行動裝置(9 〇 ) 與其原系統之VPN伺服器(1 1 ),甚至外界通信節點(44 ) 之通信,均通過行動代理器(2 3 ) ( 1 3 )之資訊封包傳輸模 組(5 2 )進行。 行動代理器連線模組 本發明之行動網路代理器,提供一個行動代理器連線模 組(5 3 )以在原網路系統(丨〇 )亦具有行動代理器(1 3 ) 時’建立其直接之通信通道。 兩行動代理器(23 ) ( 1 3 )間建立連線時,適用之作法 包括:由外界行動代理器(2 3 )直接以行動裝置(9 0 )之原 網路系統(1 0 )之IP位址為目的地,送出l〇cat i〇n updatePage 13 1225736 V. Description of the invention (8) Tunneling and so on. This layer of tunneling is packed and unpacked by the mobile device (90) and the mobile agent (2 3) (1 3). In addition, since the communication between the mobile device (90) and the VPN server (Π) of the original network system (1 0) is through the external action agent (2 3) and the original system action agent (1 3), In other words, between two mobile agents (23) (13), mobile IP tunneling (mobile IP tunneling) technology can be used. Applicable methods include IP-in-IP tunneling or GRE (Generic Routing Encapsulation) tunneling. The tunneling of this layer is packaged by the mobile agents (2 3) (1 3) of both parties. With the above design, when the mobile device (90) is connected to the vpn server (11) of the original network system (10) through the first external network system (20), the mobile network agents of both parties (2 3) (1 3) can automatically detect this request and take over. The mobile agent (2 3) (1 3) learns the authentication information by monitoring its connection packet, and then establishes a connection. The communication between the mobile device (9) and its original system's VPN server (1 1), and even the external communication node (44), is through the information packet transmission module (5 2 of the mobile agent (2 3) (1 3)) )get on. Mobile agent connection module The mobile network agent of the present invention provides a mobile agent connection module (5 3) to be established when the original network system (丨 〇) also has a mobile agent (1 3). Its direct communication channel. When establishing a connection between the two mobile agents (23) (1 3), the applicable methods include: the external mobile agent (2 3) directly uses the IP of the original network system (1 0) of the mobile device (9 0) Address is the destination, send l〇cat i〇n update

第14頁 1225736 五、發明說明(9) 的控制信息。根據I p路由(r ou t i n g )規則,該控制信息將 傳送給原網路系統(1 〇 )。而原網路系統(1 q )上的行動代 理器(1 3 )則利用相同的監聽方式,例如pr〇Xy ARp,來截 收控制信息。兩者即可建立連線,而行動裝置則不需提供任 何額外信息給外界行動代理器(2 3 )。 網段交替處理模組 網段交替處理模組(5 4 )之功用在執行網段交替作業。 在第1圖中,亦顯示行動裝置(9 〇 )自第1外界網路系統 (2 0 )解除連線,而與第2外界網路系統(3 〇 )進行連線。 如果行動裝置(90)係使用DHCP (dynamic host con f i gurat i on pro toco 1,動態主機架構規約)來取得原網 路系統(1 0 )的I P位址,則每次發生網段域交替(hand 〇 f f )時,行動裝置(90 )可能會送出DHCP請求或DHCP discover (服務搜尋信息)來取得新的動態ip指定 (dynamic IP assignment)。在本發明中,該行動代理器 (33 )可利用其網路系統(30 )中之DHCP伺服器(未圖示) 或其内建之DHCP伺服器,進行網段交替處理,以使行動裝置 (9 0 )保持取得及使用相同的動態I p位址。 利用其他方式,使行動裝置(9 0 )保持使用原動態I p位 址之狀態,而不致於斷線,亦屬可行。 如果第2外界網路(3 0 )之行動代理器(3 3 )可由行動裝置 之DHCP請求中得知其原連線之第1外界網路系統(20 )之 DHCP IP位址,則將此DHCP請求或DHCP discover送至原連線 之苐1外界網路糸統(2 0 ) D H C P伺服器。如果第2外界網路Page 14 1225736 V. Control information of invention description (9). According to the I p routing (rou ti n g) rule, the control information will be transmitted to the original network system (10). The mobile agent (1 3) on the original network system (1 q) uses the same monitoring method, such as prOxy ARp, to intercept the control information. The two can establish a connection, and the mobile device does not need to provide any additional information to the external action agent (2 3). Network segment processing module The function of the network segment processing module (5 4) is to perform the network segment replacement operation. In the first figure, the mobile device (90) is also shown to be disconnected from the first external network system (20) and connected to the second external network system (30). If the mobile device (90) uses DHCP (dynamic host configuration on pro toco 1) to obtain the IP address of the original network system (1 0), each time the network segment domain alternates ( hand 〇ff), the mobile device (90) may send a DHCP request or DHCP discover (service search information) to obtain a new dynamic IP assignment. In the present invention, the mobile agent (33) may use a DHCP server (not shown) in its network system (30) or its built-in DHCP server to perform network segment alternate processing to make the mobile device (90) Keep acquiring and using the same dynamic IP address. It is also feasible to use other methods to keep the mobile device (90) using the original dynamic IP address without disconnection. If the mobile agent (33) of the second external network (30) can learn the DHCP IP address of the first external network system (20) from the DHCP request of the mobile device, then The DHCP request or DHCP discover is sent to the external network system (2 0) of the original connection to the DHCP server. If the 2nd external network

1225736 發明說明(ίο) (30 )之行動代理器(33 )已存有該行動裝置(9〇 )之原連 線DHCP飼服器之資訊,例如,該行動裝f ( 9〇 )曾經由此第 2外界、”罔路(3 0 )之連線’移動至其他外界網路系統,而與 ,仃動代理器進行連線,則第2外界網路(3 〇 )之行動代理 器(33 )也可透過其他行動代理器查詢得知,而將其DHCP請 求或DHCP discover傳送給原連線之DHCP伺服器。當然,行 動代理器(33)轉送DHCP request及discover回第1外界網 路(20 )之動作,也可能予以省略。1225736 Invention description (ίο) (30) The mobile agent (33) has stored the information of the original connected DHCP feeder of the mobile device (90). For example, the mobile device f (90) has been The second external, "Broadway (30) connection" is moved to another external network system, and the connection with the automatic agent, the mobile agent (33) of the second external network (30) ) Can also be known through other mobile agent queries, and send its DHCP request or DHCP discover to the original connected DHCP server. Of course, the mobile agent (33) forwards the DHCP request and discovers back to the first external network ( 20) may also be omitted.

反之’如果第2外界網路(3 〇 )之行動代理器(3 3 )無 =得知,連線之DHCP伺服器的資訊。但可取得該行動裝置先 則所取得的動態I P位址,例如行動裝置(9 〇 )所送出之训Cp 明求中τ有所睛求I P之選項(〇pt丨〇n )時,則該網路代理器 (33)可以代替原先之⑽⑶伺服器繼續分派(assign)所請 求之I P位址給該行動裝置(9 〇 )。否則,該網路代理器(3 3 )亦可重新分派一個新的丨p位址給行動裝置(9 〇 )。這時該 行動裝置的V P N連線及授權中斷,必須重新連線。 當第1外界網路系統(20 )之DHCP伺服器接收到第2外界 網路系統(30 )的DHCP所傳來之DHCP請求或discover時,即 可依一般適用之規則,延長行動裝置(9 〇 )所使用丨p位址之 租用期間。 在本發明另一實例中,行動裝置(9 0 )所屬之原網路系 統(1 〇 ),並沒有建置行動代理器(1 3 )。這時,當行動裝 置(9 0 )與第1外界網路系統(2 〇 )進行連線時,其行動代 理器(2 3 )之行動裝置辨識模組(5 1 )在偵測此現象時,可On the contrary, if the mobile agent (33) of the second external network (30) does not know, the information of the connected DHCP server. However, the dynamic IP address obtained by the mobile device first can be obtained, for example, when the training Cp sent by the mobile device (9 〇) clearly seeks the option of τ to obtain the IP intently, then the The network proxy (33) may continue to assign the requested IP address to the mobile device (90) instead of the original ⑽CD server. Otherwise, the network agent (33) can also re-assign a new IP address to the mobile device (90). At this time, the VPN connection and authorization of the mobile device are interrupted, and the connection must be reconnected. When the DHCP server of the first external network system (20) receives the DHCP request or discover from the DHCP of the second external network system (30), it can extend the mobile device (9 〇) The lease period of the p address used. In another example of the present invention, the original network system (10) to which the mobile device (90) belongs does not have a mobile agent (13). At this time, when the mobile device (90) is connected to the first external network system (20), when the mobile device identification module (51) of its mobile agent (23) detects this phenomenon, can

第16頁 1225736 、發明說明(Η) 動向行動裝置(9 0 )所屬的原網路彳% f 9 裝置(9〇)之授權資訊’並利用所取 發明之漫遊服務。在此設計下,行動裝置(9〇)、可以= 第i外界網路系統(20 )額外註冊或提供帳 而在 原網路系統(1 〇 )中之帳號,並在第丨外^ 而可使用其 上取得授權,使用網路資源。第1外界網路系統(2〇) 然1由於原、、:路(1 0 )上沒有行動代理器能夠 m〇blle IP tunnell、ng,為了讓行動裝置(90)在移動到第2 外界網路系統後’能可保持通訊, 】第2 (23)必須扮演行動裝置(90)的暫時原網路代理器,;;有 =裝置⑼j的通訊封包將經由行動代 動代理器(33)之間,透過„oblle Ip tunneHng來傳送。-如果行動裝置(90)係使用原網路的1[5位址, =路系統(2〇)上的IP位址,此時,行動代理器(23)可 ,用NAT (網路位址轉換協定)讓行動裝置⑼)能夠與 原網路的VPN伺服器(1 1 )正常連線。 :亍動凌置(9 0 )也可以使用第!外界網路系統(2 〇 )上的j p 立=,例如透過DHCP從第1外界網路系統(2〇 )上的㈣⑶伺 服為’得到一個I P位址。 不娜哪種情況’行動裝置(9 〇 )與原網路的v p N伺服器 1 )通訊將經由行動代理器(2 3 )來轉送。 1 P衝突處理模組 本發明之行動網路代理器具有一 I p衝突處理模組(5 5 用以在4行動裝置之I p位址或其他帳號、代號與其他電Page 16 1225736, description of the invention (Η) The original network of the mobile device (90) belongs to the% f9 device (90) 's authorization information' and uses the obtained invention's roaming service. Under this design, the mobile device (90) can use the i-th external network system (20) to additionally register or provide an account in the original network system (10), and can be used outside the Authorized to use network resources. The first external network system (20). However, because there is no mobile agent on the original,:, and (1 0), m0blle IP tunnell, ng, so that the mobile device (90) is moving to the second external network. The communication system can maintain communication after the network system.] The second (23) must act as the temporary original network agent of the mobile device (90); the communication packet with the device ⑼j will pass through the mobile agent (33). Transmission via „oblle Ip tunneHng.” If the mobile device (90) uses the 1 [5 address of the original network, = IP address on the road system (20), at this time, the mobile agent (23 ) Yes, use NAT (Network Address Translation Protocol) to allow mobile devices ⑼) to connect to the VPN server (1 1) of the original network normally.: 亍 动 凌 置 (9 0) can also be used! Jp on the network system (20) = for example, via DHCP from the ㈣CD server on the first external network system (20) to 'get an IP address. No matter what's the case' mobile device (9 〇 ) Communication with vp N server 1) of the original network will be forwarded via mobile agent (2 3). 1 P conflict processing module Action of the invention Road agent having a conflict management module I p (I p 55 to address 4 at the mobile device, or other accounts, and other electrical code

第17頁 1225736 五、發明說明(12) 腦裝置之I P位址、帳號、代號發生重複時,解決其衝突。 由於行動裝置(9 0 )係使用其所屬原網路系統(2 0 )所 給予之I P位址’因此,當兩個不同的行動裝置同時與一外界 網路系統進行連線時,可能發生丨p衝突(c〇丨H s i 〇11 )之現 象。本發明之行動代理器利用分流(traf f ic separati〇n ) 之方式’將兩個行動裝置之資訊流(t r a f f i c )分隔,來解 決I P衝突之現象。此種分流技術可以利用任何已知之方式為 之’例如VLAN (Virtual Local Area Network,如 IEEE802. 1 Q )技術。其他能產生行動裝置身分代碼之方法,也可適用 於本發明。說明如下: 在向外傳送資訊時,從行動裝置(9 0 )送出的資訊封 包,包括layer 2的圖框(frame ),如ARP (位址詢問規 約,Access Resolution Protocol )信息,都會自動被加上 VLAN標示,或其他身分碼,並一路送到行動代理器,行動代 理杰可以根據VLAN標示來決定封包是由哪個行動裝置所送出 的。 、 如果有其他行Page 17 1225736 V. Description of the invention (12) When the IP address, account number, and code of the brain device are duplicated, resolve the conflict. Because the mobile device (90) uses the IP address given by its original network system (20), therefore, when two different mobile devices are connected to an external network system at the same time, it may happen 丨The phenomenon of p conflict (c〇 丨 H si 〇11). The mobile agent of the present invention uses the method traf f ic separation to separate the information flow (t r a f f i c) of two mobile devices to resolve the IP conflict phenomenon. This shunting technology can be used in any known way, such as VLAN (Virtual Local Area Network, such as IEEE 802.1Q) technology. Other methods capable of generating an identity code for a mobile device are also applicable to the present invention. The description is as follows: When sending information outward, the information packet sent from the mobile device (90), including the frame of layer 2, such as ARP (Address Inquiry Protocol, Access Resolution Protocol) information, will be automatically added. Put the VLAN tag, or other identification code, and send it to the mobile agent all the way. The mobile agent can determine which mobile device sends the packet according to the VLAN tag. If there are other lines

(媒體存取控制,Media Address Control )位址,這此A 請求並不會直接送到這兩個行動裝置,而由 二(Media Access Control, Media Address Control) address, this A request will not be sent directly to the two mobile devices, but by the two

這些ARP請求。 乃代理為回 在接收外來資訊時,由於行動裝置對外的資料流^ 此由原網路系統轉送來的VpN資料漭,—e ,士 V P Μ 仞犯怒让 Τ η · . _ ' /;,L 5 由VPN連線,因〜一 π…忖埯來的vnN資料法卜 代理器都很容易由VPN㈤服器的Ιρ位址來區別、^ ’仃 位址的行動裝置。這是因為兩個行動裝置通 :These ARP requests. It is because the agent responds to the external data flow of the mobile device when receiving the external information ^ This VpN data transferred by the original network system, —e, VP VP 仞 angered T η ·. _ '/; ,, L 5 is connected by VPN, because the vnN data proxy agents from ~~ ... are easily distinguished by the VPN server's Ip address, and the mobile device with the address of ^ '. This is because the two mobile devices communicate:

^25736 五、發明說明(13) ' ---一^ "一^ 個VPN肖服态。所以—個行動裝置的識別方式宜α「原網路 ί統VPN伺服器ΙΡ位址」加上「原網路系統!"立址」,而不 早純只含原網路系統丨ρ位址。 如果行動裝置的原網路系統I ρ位址與其他行動裝置的 >NS*(網域名稱,D〇main Name System)或 gateway 發生 IP =丁突時’例如某個行動裝置的丨p位址恰好是另一個行動裝 、士,DNS的IP位址。此時,同樣可以利用似n的方式來分流 化皂產生I P衝突的行動裝置的資訊流。 搜叫^ ,如果订動装置的原網路系統1 P位址剛好是行動代 叙:荽a ^址^,則行動代理器必須利用VLAN來獨立出此行 P ^ t貝吼流。當行動裝置送出ARP請求來偵測此I P是否 匕有人使用時,行重Λ抑甲 要—4 丁助代理杰不應該回覆訊息。針對此行動裝 直,订勤代理器必須值驻广^ 25736 V. Description of the invention (13) '--- ^ " One ^ VPN service status. Therefore, the identification method of a mobile device should be α “the original network and the IP address of the VPN server” plus “the original network system!” And not just the original network system. site. If the original network system I ρ address of the mobile device and the other mobile device's NS * (domain name, Domain Name System) or gateway IP = Ding Su ', such as the bit position of a mobile device The address is exactly the IP address of another mobile device, DNS, DNS. At this time, the information flow of mobile devices that cause IP conflicts can also be shunted in an n-like manner. Search for ^, if the original network system 1 P address of the subscription device happens to be mobile agent: 荽 a ^ address ^, then the mobile agent must use VLAN to make this trip independently. When the mobile device sends an ARP request to detect whether this IP is used by someone, it should be repeated to suppress the request.—4 The assistant agent should not reply to the message. For this action, the booking agent must be based in Guangzhou.

△ ” 叩乂眉捣4 (maSquerade )成其他不衝突& IP 上圖顯_示本發明行動網路代理器處理1]?衝突流程圖。 (2日:所:’於(4 〇 1 )第1行動裝置首先進入外界網路 p〇int ) 尚未^成網路授權前,無線網路進出點(Access 置的網路^包路交換器會使用預設’UN 〇來傳送第1行動裝 位置更新與上路尸)權後外,”外罔路代理為與原網路代理器完成 以VLAN丨來傳送第丨:動裝: = 包進出點或交換器將 當於U04)使用相_位址的第2行動裝置也進入此外△ ”" MaSquerade "into other non-conflicting & IP The above figure shows the mobile network agent processing 1] of the present invention? Conflict flow chart. (2nd: All: 'Yu (4 〇1) The first mobile device first enters the external network (pint). Before the network authorization is established, the wireless network access point (the network set by the Access ^ packet switch will use the default 'UN 〇' to send the first mobile device). After the location update and on-the-road corps) rights, the "outer route agent" will complete the transmission with the VLAN of the original network agent. 丨: Dynamic equipment: = The packet entry / exit point or switch will be used as U04). The second mobile device at the address also entered

第19頁 1225736 五、發明說明(14) 界網路後,相同地,在未完成網路授權前,第2行動裝置的 網路封包會使用VLAN 0。此時雖然兩個行動裝置使用相同的 I p位址,但因為所處的VLAN不同,因此彼此的網路通訊不會 互相干擾。 於(4 0 5 )第2行動裝置也完成了位置更新與網路授權, 外界網路將於(4 0 6 )分派一個不會發生丨p衝突的VUN給第2 行動裝置。以本圖為例,因為外界網路知道第丨行動裝置在 VLAN 1,因此分派VLAN 2給第2行動裝置。 VLAN ( IEEE 8 0 2· 1Q )的用途主要用來讓一個實體的區域網 路能夠被分隔成多個虛擬的區域網路。雖然兩行動裝置處在 相同的實體網路中,作VI A Μ从处m , V LAN的使用可以分流這兩個行動裝置 的網路封包,並將之分陪太 1网在不同的區域網路,以避免互相干 根據 IEEE 802. 1 Q, 一個行動代理器而言, 的行動裝置。 由於VLAN tag最大到40 96,因此對 最多可以允許4 0 9 6個使用相同I P位址 五、【發明之效果】 利用本發明之行曹ΛPage 19 1225736 V. Description of the invention (14) After the network is bound, similarly, before the network authorization is completed, the network packet of the second mobile device will use VLAN 0. At this time, although the two mobile devices use the same IP address, they will not interfere with each other's network communication because they are in different VLANs. At (405) the second mobile device also completed the location update and network authorization. The external network will (4) assign a VUN that will not conflict with the second mobile device. Take this figure as an example, because the external network knows that the second mobile device is in VLAN 1, it assigns VLAN 2 to the second mobile device. The purpose of VLAN (IEEE 802 · 1Q) is mainly to enable a physical area network to be divided into multiple virtual area networks. Although the two mobile devices are in the same physical network, as VI A Μ from the source m, the use of V LAN can offload the network packets of these two mobile devices and accompany them to the same network in different regional networks. In order to avoid interfering with each other according to IEEE 802.1 Q, a mobile agent is a mobile device. Since the maximum VLAN tag is 40 96, the same IP address can be used for a maximum of 4 0 6 5. [Effect of the invention] Utilizing the trip of the present invention Cao Λ

Ip suhnpt # ^ π 、、同路代理器,不論行動裝置跑到那布 A f s u b n e t,都能夠保拉社 取網路資訊。行動裝置、i使用屬於原網路系統的1P位址來术 的通訊並不會因此^ ^不同的外界網路系統間移動,原琴 訊的通信節點都不需^需重新連線,所有正與行動裝置3 動裝詈力丁门认从田、仃動裝置已經不在原網路系統。个 & 1隹不同的外界網敗 $有的VPN連線不需要斷線再重連,Ip suhnpt # ^ π, the same agent, no matter the mobile device goes to that cloth A f s u b n e t, can be Paula network information. The mobile device and i use the 1P address belonging to the original network system for communication. This does not mean that ^ ^ different external network systems move between the original network communication nodes do not need to reconnect, all With the mobile device 3, the mobile device is not able to recognize the subordinates, and the mobile device is no longer on the original network system. &Amp; 1 隹 Different external networks fail $ Some VPN connections do not need to be disconnected and reconnected,

段改#,伯"如壯$ 崎糸統間移動後,雖然外在的IP網 人夂’但灯動裝置上 第20頁 1225736 五、發明說明(15) -" "-- 而且能夠快速地完成網路交替動作,保持連線狀態。 適用於本發明之行動裝置可以是一般行動裝置平台,。 要能支援IP網路協定以及VPN應用協定,就可以使用本發明、 之行動網路代理器,不需要更新軟體功能,或仰賴支援特殊 通訊協定。以PC、筆記型電腦為例,Mlcr〇s〇ft Wind〇ws、 UNIX-like OS、MAC 〇S 等都能使用。以PDA 為例,pALM 〇s、 Microsoft WlnCE以及Llnux等都可使用。以行動電話裝置 吕,只要能存取IP網路及VPN連線,都可以使用。 本發明之^亍動代王军哭、Γ 分,除了建立卿連\二可以自動識別並確認使用者的身 身分認證程序。使用7者過沾程外,使用者不需另外進行或提供< 動裝置已經建立與片::通訊也可以獲得加密保護。-旦行 動到不同的網路或進=系統的VPN連線,無論行動裂置移 會自動識別並確認使用丁:線細胞(cen )交替,行動代理器 提供身分認證程序。 的身分,使用者不需要另外進行或 【元件符號表】 10 原網路系統 11 虛擬私人網路伺服器 12 網路閘道器段 改 # , 伯 " After moving between rugged and rugged systems, although the external IP network is stunned, but on the moving device, page 20 1225736 V. Invention description (15)-" "-and It can quickly complete the network alternate action and keep the connection status. The mobile device applicable to the present invention may be a general mobile device platform. In order to support the IP network protocol and VPN application protocol, the mobile network agent of the present invention can be used without updating software functions or relying on supporting special communication protocols. Taking PC and notebook as examples, Mcr0s〇ft Wind 0ws, UNIX-like OS, MAC 0S, etc. can be used. Taking PDA as an example, pALM 0s, Microsoft WlnCE, and Llnux can be used. With a mobile phone device, you can use it as long as you can access the IP network and VPN connection. According to the present invention, in addition to crying for Wang Jun and Γ points, in addition to establishing a clear link, the user can automatically identify and confirm the user's identity authentication procedure. In addition to the use of 7 users, users do not need to perform additional or provide a mobile device: and communication: communication can also be encrypted. -Once you move to a different network or a VPN connection to the system, regardless of the mobile splitting, it will automatically identify and confirm the use of Ding: Line Cell (cen) alternately, and the mobile agent provides the identity authentication process. User ’s identity, users do n’t need to do it separately or [component symbol table] 10 original network system 11 virtual private network server 12 network gateway

13 行動網路代理哭 14 通信節點 15 印表機 2 0 第1外界網路系統13 Mobile network agent crying 14 Communication node 15 Printer 2 0 1st external network system

第21頁Page 21

1225736 五、發明說明(16) 22 網 路 閘 道 器 或 路 由 器 23 行 動 網 路 代 理 器 24 通 信 々斤 即 點 30 第2外界網路系統 31 伺 服 器 32 網 路 閘 道 器 或 路 由 器 33 行 動 網 路 代 理 器 34 通 信 即 點 40 行 動 裝 置 44 其 他 通 信 khz 即 點 50 行 動 網 路 代 理 器 51 行 動 裝 置 辨 識 模 組 52 資 訊 封 包 傳 輸 模 組 53 行 動 代 理 器 連 線 模 組 54 網 段 交 替 處 理 模 組 55 IP 衝 突 處 理 模 組 60 網 路 系 統 90 行 動 裝 置 99 連 線1225736 V. Description of the invention (16) 22 Network gateway or router 23 Mobile network agent 24 Communication jack 30. Second external network system 31 Server 32 Network gateway or router 33 Mobile network Agent 34 communication point 40 mobile device 44 other communication khz point 50 mobile network agent 51 mobile device identification module 52 information packet transmission module 53 mobile agent connection module 54 network segment processing module 55 IP Conflict Resolution Module 60 Network System 90 Mobile Device 99 Connection

第22頁 1225736 圖式簡單說明 第1圖顯示一個網路系統之示意圖。 第2圖顯示本發明行動網路代理器之系統圖。 第3圖即顯示一種適用在本發明行動網路代理器之通信 模式示意圖。 第4圖顯示本發明行動網路代理器處理I P衝突流程圖。Page 22 1225736 Schematic description Figure 1 shows a schematic diagram of a network system. Figure 2 shows a system diagram of the mobile network agent of the present invention. Fig. 3 is a schematic diagram showing a communication mode applicable to the mobile network agent of the present invention. FIG. 4 shows a flowchart of handling IP conflicts by the mobile network agent of the present invention.

第23頁Page 23

Claims (1)

1225736 六、申請專利範圍 1. 一種行動網路代理器,用以使一行動裝置透過一外界 網路與其原屬網路系統建立連線,該外界網路與該原屬網路 可建立連線,該行動網路代理器具有: 一個行動裝置辨識模組,用以擷取該行動裝置與其原 屬網路系統之認證資訊,而取得其身份資訊; 一個資訊封包傳輸模組,用以收、送行動裝置透過該 外界網路系統與外界交換之資訊封包;1225736 VI. Scope of patent application 1. A mobile network agent that enables a mobile device to establish a connection with its original network system through an external network, and the external network can establish a connection with the original network The mobile network agent has: a mobile device identification module for capturing authentication information of the mobile device and its original network system to obtain its identity information; an information packet transmission module for receiving, Sending information packets that the mobile device exchanges with the outside world through the outside network system; 一個行動代理器連線模組,用以在該行動裝置之原屬 網路系統具有行動網路代理器時,與該行動網路代理器建立 通信通道; 一個網段交替處理模組,用以在行動裝置建立連線 時,取得其原連線網路系統之位址資訊,並向該原連線網路 系統送出更新資訊;及 一個I P衝突處理模組,用以在所連線之行動裝置之I P 位址或帳號與其他電腦裝置或系統之I P位址相同時,進行資 料流的分流。 2. 如申請專利範圍第1項之行動網路代理器,其中該行 動裝置辨識模組,是在該行動裝置向該外界網路系統請求建 立連線時,加以啟動。A mobile agent connection module for establishing a communication channel with the mobile network agent when the original network system of the mobile device has a mobile network agent; a network segment processing module for When the mobile device establishes a connection, it obtains the address information of its original connected network system, and sends updated information to the original connected network system; and an IP conflict processing module for the connected operation When the IP address or account of the device is the same as the IP address of another computer device or system, the data flow is divided. 2. If the mobile network agent of item 1 of the patent application scope, the mobile device identification module is activated when the mobile device requests the external network system to establish a connection. 3. 如申請專利範圍第1項之行動網路代理器,其中該行 動裝置辨識模組,是在該行動裝置與該外界網路系統之VPN 伺服器建立連線時,取得其認證資料。 4. 如申請專利範圍第1項之行動網路代理器,其中該行 動裝置辨識模組,是向該原屬網路系統請求,而取得該行動3. For example, the mobile network proxy of the scope of patent application, wherein the mobile device identification module obtains authentication information when the mobile device establishes a connection with the VPN server of the external network system. 4. If the mobile network agent of item 1 of the patent application scope, wherein the mobile device identification module requests the original network system and obtains the action 第24頁 ^5736 *讀專利範圍 I置之身分資訊。 ^ 5 ·如申請專利範圍第1項之行動網路代理器,其中該資 δί1封包是在該行動代理器與設置在該原屬網路系統之另_'一 動代理器間傳輸。 仃 6 ·如申請專利範圍第1項之行動網路代理器,其中該資 封包是在該行動代理器與設置在該原屬網路系統之另"一^ 一 動代理器間,透過行動I Ρ穿隧傳輸。 4于 7 ·如申請專利範圍第1項之行動網路代理器,苴 :父替處理模組,是在該行動装置發出DHCP請求或DHcp服 臾尋信號時,加以啟動。 務 8 ·如申請專利範圍第7項之行動網路代理器,复中 =交替處理模組將該DHCP請求或DHCp服務搜尋信號、,:、、.罔 係、讀行動裝置建立連線之其他網路系統,以延長‘,,一 吏用該其他網路系統所授權j p位址之期間。 ^ 丁動羞置 9.如申請專利範圍第1項之行動網路朴神的 τ突處理模組可產生不同辨η # 代里态,其中該I ρ 同IP位址之不同行動裝ΐ將不同辨識碼加給具有相 行資訊分流。 …仃動裝置與其他電腦裝置,:Ϊ 1 0.如申請專利範圍第1項之 硪碼為VLAN標示。 、 動網路代理器,其中該辨 1 1 .如申請專利笳圊筮〗 識碼係加於該彳干固弟1項之行動網路代理哭# ^ 4仃動裝置所產生代理為,其中該辨 1 Z ·如申請直 〈貝Λ封包。 識碼係力U於# 1範圍第1項之行動_路# @ 万、迗給該行動裝 T A、、同路代理器,其中該辨 刀我置之貧訊封包。Page 24 ^ 5736 * Read the scope of the patent I. Identity information. ^ 5 If the mobile network agent of item 1 of the scope of patent application, the packet of δί1 is transmitted between the mobile agent and another mobile agent provided in the original network system.仃 6. If the mobile network agent in item 1 of the patent application scope, the packet is between the mobile agent and another mobile agent installed in the original network system. P tunneled transmission. 4 to 7 · If the mobile network agent in item 1 of the patent application scope, 苴: the parent processing module is activated when the mobile device sends a DHCP request or a DHcp server search signal. Task 8 · If the mobile network agent in item 7 of the scope of patent application is applied, the re-entry = alternate processing module, the DHCP request or the DHCp service search signal,: ,,,,,,,,,, etc., read the mobile device to establish a connection to the other Network system to extend the period of time that a person uses the jp address authorized by the other network system. ^ Ding Shame 9. If the mobile network Pu Shen's τ burst processing module of the first patent application scope can generate different identification η # generation state, where the different mobile devices with I ρ and IP address will Different identification codes are added to the stream with phase information. … Automatic devices and other computer devices: Ϊ 1 0. If the 硪 code in item 1 of the scope of patent application is VLAN identification. 1. Move the network agent, where the identification 1 1. If you apply for a patent, the identification code is added to the action of the mobile network agent 1 # ^ 4 The agent generated by the mobile device is, where The discrimination 1 Z · If the application is directed to a packet. The identification code is the action # 1 in # 1 range_ 路 # @ 万 、 迗 Install the agent T A, and the same agent in the action, and the discriminator should be a poor packet.
TW92128761A 2003-10-16 2003-10-16 Mobile network agent TWI225736B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW92128761A TWI225736B (en) 2003-10-16 2003-10-16 Mobile network agent

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW92128761A TWI225736B (en) 2003-10-16 2003-10-16 Mobile network agent

Publications (2)

Publication Number Publication Date
TWI225736B true TWI225736B (en) 2004-12-21
TW200515729A TW200515729A (en) 2005-05-01

Family

ID=34588322

Family Applications (1)

Application Number Title Priority Date Filing Date
TW92128761A TWI225736B (en) 2003-10-16 2003-10-16 Mobile network agent

Country Status (1)

Country Link
TW (1) TWI225736B (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8626172B2 (en) 2005-08-10 2014-01-07 Qualcomm Incorporated Method and apparatus for simultaneous communication utilizing multiple wireless communication systems
TWI497945B (en) * 2004-03-24 2015-08-21 皇家飛利浦電子股份有限公司 Distributed beaconing periods for ad-hoc networks
TWI514824B (en) * 2013-05-23 2015-12-21 Mitsubishi Electric Corp A relay device and a communication method selection method and a program product

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI497945B (en) * 2004-03-24 2015-08-21 皇家飛利浦電子股份有限公司 Distributed beaconing periods for ad-hoc networks
US8626172B2 (en) 2005-08-10 2014-01-07 Qualcomm Incorporated Method and apparatus for simultaneous communication utilizing multiple wireless communication systems
TWI514824B (en) * 2013-05-23 2015-12-21 Mitsubishi Electric Corp A relay device and a communication method selection method and a program product

Also Published As

Publication number Publication date
TW200515729A (en) 2005-05-01

Similar Documents

Publication Publication Date Title
JP4616732B2 (en) Packet transfer device
JP5497901B2 (en) Anonymous communication method, registration method, message sending / receiving method and system
JP4270888B2 (en) Service and address management method in WLAN interconnection
US20090073995A1 (en) Devices and methods for local breakout in a gateway of an access service network
US9203694B2 (en) Network assisted UPnP remote access
JP5987122B2 (en) Network address translated device identification for device specific traffic flow steering
KR101678720B1 (en) Broadband network system and implementation method thereof
KR101640209B1 (en) Apparatus and method for supporting portable mobile VPN service
EP2702785B1 (en) Local access point name for use in accessing packet data networks
WO2011044808A1 (en) Method and system for tracing anonymous communication
WO2009143729A1 (en) Method, system and apparatus for realizing dhcp user service wholesale
KR20140099598A (en) Method for providing service of mobile vpn
KR101901341B1 (en) Method and apparatus for supporting mobility of user equipment
WO2011035667A1 (en) Methods and systems for implementing inter-network roam, querying and attaching network
WO2014101755A1 (en) Service data shunting method and system
WO2013178160A1 (en) Wireless data terminal and ipv4/ipv6 dual stack support method therefor
JP2008066907A (en) Packet communication device
JP5872066B2 (en) Method, apparatus and system for accessing core network by non-3GPP
US20050083883A1 (en) Mobile network agent
CN114125995B (en) Data transmission method and device
WO2007128239A1 (en) System for implementing mobile ipv6 and method for establishing user link in the system
TWI225736B (en) Mobile network agent
JP4344336B2 (en) Multihoming authentication communication system, multihoming authentication communication method, and management server
WO2014107969A1 (en) Method and system for user address allocation in wireless local area network/fixed network interaction
WO2012089030A1 (en) Method, access device and authentication device for network access by multiple access methods

Legal Events

Date Code Title Description
MM4A Annulment or lapse of patent due to non-payment of fees