CN1784673A - Secure web browser based system administration for embedded platforms. - Google Patents

Secure web browser based system administration for embedded platforms. Download PDF

Info

Publication number
CN1784673A
CN1784673A CNA2004800118811A CN200480011881A CN1784673A CN 1784673 A CN1784673 A CN 1784673A CN A2004800118811 A CNA2004800118811 A CN A2004800118811A CN 200480011881 A CN200480011881 A CN 200480011881A CN 1784673 A CN1784673 A CN 1784673A
Authority
CN
China
Prior art keywords
parameter
client terminal
access point
wlan
administration
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CNA2004800118811A
Other languages
Chinese (zh)
Inventor
张俊彪
萨钦·莫迪
索拉布·马瑟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Thomson Licensing SAS
Original Assignee
Thomson Licensing SAS
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Thomson Licensing SAS filed Critical Thomson Licensing SAS
Publication of CN1784673A publication Critical patent/CN1784673A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F15/00Digital computers in general; Data processing equipment in general
    • G06F15/16Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L1/00Arrangements for detecting or preventing errors in the information received
    • H04L1/20Arrangements for detecting or preventing errors in the information received using signal quality detector
    • H04L1/205Arrangements for detecting or preventing errors in the information received using signal quality detector jitter monitoring
    • HELECTRICITY
    • H03ELECTRONIC CIRCUITRY
    • H03MCODING; DECODING; CODE CONVERSION IN GENERAL
    • H03M7/00Conversion of a code where information is represented by a given sequence or number of digits to a code where the same, similar or subset of information is represented by a different sequence or number of digits
    • H03M7/30Compression; Expansion; Suppression of unnecessary data, e.g. redundancy reduction
    • H03M7/46Conversion to or from run-length codes, i.e. by representing the number of consecutive digits, or groups of digits, of the same kind by a code word and a digit indicative of that kind
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L7/00Arrangements for synchronising receiver with transmitter
    • H04L7/0054Detection of the synchronisation error by features other than the received signal transition
    • H04L7/0066Detection of the synchronisation error by features other than the received signal transition detection of error based on transmission code rule

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Quality & Reliability (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Small-Scale Networks (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)
  • Storage Device Security (AREA)

Abstract

The invention provides a method for a web browser based remote administration system to maintain its security by utilizing an ActiveX control or a plug-in, without relying on HTTPS protection to transact management information. The invention does not burden the embedded system and thus is ideally suited for the remote administration of embedded systems. The invention provides a method to calculate a security code base upon identical algorithms in the administrative system having the browser and the embedded system. When the browser-based administrator submits the management information, an operator packages the control information as a string and invokes the security function in the plug-in with the string as a parameter. After the security function returns the result, the operator sends the form data together with a coded digest to the remote system. The digest may be embedded in the form data, for example, as a hidden field.

Description

Be used to embed platform, based on the system management of secure web browser
The cross reference of related application
The application requires in the U.S. Provisional Patent Application No.60/454 of submission on March 14th, 2003, and 582 rights and interests merge its whole contents at this by reference.
Technical field
The present invention relates to a kind of method that configuration variation is provided at Network Access Point; specifically; the invention provides the method in a kind of WLAN environment; wherein during telemanagement and management processing, access point is with the stationary computer that has web browser or portable terminal uses ActiveX control or plug-in unit to strengthen security function and do not rely on HTTPS to protect.
Background technology
The field of the invention be about, by comprise the WLAN (wireless local area network) of using IEEE 802.1x framework or (WLAN), have and be provided to other networks (LAN (Local Area Network) or the World Wide Web that connect such as rigid line, as the Internet) access give other networks of the access point of stationary computer or mobile terminal device, insert network safely such as WWW.Produced in rest station, coffee-house, library and wireless telecommunications (" focus ") that similarly the common implementing place can public access in the progress of WLAN technical elements.Now, public WLAN is provided to the private data network such as company intranet, or gives the mobile communication equipment user such as the access of the public data network of the Internet, reciprocity communication and real-time radio TV broadcasting.The relatively low expense of implementing and operating public WLAN, and obtainable high bandwidth (surpassing 10 mbit/usually) makes public WLAN become desirable access mechanism, the mobile radio communication equipment user by it can with the external entity exchange data packets.But as what be discussed below, such public use may damage security, unless be used to the appropriate device discerning and authenticate in existence between common communication period and in processing remote management and management function.
In the authentication method of browser Network Based, stationary computer or portable terminal use the web browser with hypertext transfer protocol secure socket (HTTPS) protocol operation, and certificate server carries out communication and all can not invade or steal secret user profile thereon to guarantee on the path between portable terminal and the certificate server anyone.
Remote system administration/administration is the key request of the computer system of relevant any kind.Use web browser (http protocol) just becoming basic management characteristic as the interface that is used for telemanagement.For the safety long-distance management based on browser is provided, HTTPS is the selection of nature.But, very huge for embedded system to the resource requirement of HTTPS such as the WLAN access point, a large amount of storage spaces be consume and corresponding expense support and CPU ability required.In fact, these restrictions have hindered the development that is used for based on the actual solution of the security management mechanism of browser historically.For example, most of today, commercially available WAP did not protect the telemanagement between browser and the access point to exchange.The hacker can obtain administrator password like a cork and damage access point.
HTTPS is designed to communications protocol, though browser or the webserver does not all have pre-established authentication codes wherein, as the secret password word of only knowing by client terminal and certificate server.This hypothesis of secret is absolute necessary in network application, and several ten million browsers may be visited millions of servers and do not had prior trusting relationship in network application.Therefore, a large amount of uses of HTTPS need be at the certificate on the server being provided at the security negotiation between browser and the server, and set up the shared security code that is used for HTTP communication subsequently.In remote system administration case, manager and remote equipment can be shared security code in advance, therefore remove a source of the expense related with the HTTPS communication.But, owing to web browser does not provide based on so necessary secure communication mechanism of shared security code, so processor need have the characteristics that security is provided by the plug-in unit that uses ActiveX control or equivalent function.
Summary of the invention
Here the invention provides a kind of method, be used for improving security during the exchange telemanagement between the access point of customer equipment that uses browser and network.Specifically, the invention provides a kind of method, be used between the access point of customer equipment and wireless network (WLAN) exchange of management change request safely.WLAN can comprise the network that meets IEEE 802.11 standards.Administration change relates to parameter to be used, and guarantees that the management information that is received is to receive from suitable client terminal.Usually, when receiving to such as the request of the administration management document of Webpage the time, the access point of network also produces and sends first parameter (for example random number) to client terminal.Can produce first parameter in response to the inquiry after the request of administration management document.
Use produces new argument such as the predetermined algorithm of MD5 hash function from some parameter.Parameter can comprise first parameter, and it can be the random number that is produced by access point.For better security, can produce new argument from the Several Parameters of the string argument that comprises the password related, first parameter and for example can from new administration information, produce with client terminal.New argument can be sent to access point from client terminal, it uses the parameter of being used by client terminal to produce corresponding new argument then.If parameter matching, then access point is accepted new administration information and is implemented them.By this way, the certificate parameter that has new administration information by use provides better security, and using client terminal and access point is that known parameter produces described certificate parameter.
In an embodiment of the present invention, manager uses browser to be usually designed to the supervising the network page form of HTML(Hypertext Markup Language) form from the remote computer request such as local web-server, and it comprises that manager can be used to provide and the territory (field) that obtains with the relevant information of the safety communication of network.Web page form comprises filling management information, its when finishing by by calling such as may being submitted to remote computer, being character string with information package by the true-time operation device that the Javascript code provides.The true-time operation device calls has the plug-in security function of book character string as a parameter; The prompting safe function with the remote system communication.
In case producing random number and store this number, reception form data, remote system be used for reference in the future.It also sends to manager with this number.Administrator security function is connected random number, administrator password (before being stored in the plug-in unit) with string argument.Afterwards, for producing such as the summary of message 5 summaries (MD5) and with it, the result who connects returns to safe function.This process comprises the true-time operation device of use such as Javascript so that will be embedded in the form that comprises management information from the result that safe function is come then, and this form is sent to remote computer, thereby finishes submission.Remote computer uses random number, password of storing and the data that received to produce MD5 digest.If this digests match is in the summary that is received, then agree the management of being asked and update system suitably.In communication subsequently, from manager management information is sent to remote computer, remote computer at first produces random number, and this random number is used in message 5 summaries (MD5) by manager afterwards.In each case, remote system digest can compare with the summary that is received subsequently, if this digests match, is then agreed the management request asked and update system correspondingly in the summary that is received.
Description of drawings
To from following detailed description, better understand the present invention when reading in conjunction with the accompanying drawings.But do not point out the various features of accompanying drawing.On the contrary, for clear, can at random expand or reduce various features.Comprise in the accompanying drawings have below each figure:
Fig. 1 shows the block diagram of the communication system of implementing method of the present invention;
Fig. 2 shows the process flow diagram that is used to protect the embodiments of the invention that communication inserts;
Fig. 3 a shows the process flow diagram that is used to protect the embodiments of the invention that communication inserts; With
Fig. 3 b shows the process flow diagram that is used to protect the embodiments of the invention that communication inserts.
Embodiment
In each figure that will discuss, circuit, the piece that is associated and arrow are represented the function of treatment in accordance with the present invention process, and it can be realized with the circuit of transmission of electric signals and lead or the data bus that is associated.Perhaps, the arrow of one or more associations can be illustrated in the communication (for example, data stream) between the software routines, especially when the inventive method or equipment of the present invention are implemented as the digital processing process.
The invention provides a kind of method, the long-distance management system that is used for browser Network Based is kept its security by using ActiveX control or plug-in unit, and does not rely on the HTTPS protection of handling management information.The present invention does not increase the burden of embedded system, thereby is fit to very much the telemanagement of embedded system.The present invention also provides a kind of method, and it comes the computationally secure code according to the identical algorithms in management system with browser and embedded system.When submitting management information to based on the manager of browser, manipulater is packaged as character string with control information and calls to have this character string and makes safe function in the plug-in unit of parameter.After the safe function return results, manipulater sends to remote system together with the summary of list data and coding.For example summary can be embedded among the list data as implicit territory.
According to Fig. 1, by 140 1To 140 nOne or more portable terminals of expression are via wireless medium 124 and access point 130 n, be associated with fire wall 122 and such as certificate server 150 nOne or more virtual manipulators 150 1-n Local computer 120 carry out communication.From terminal 140 1-nThe communication that comes need utilize the Internet 110 to visit safe data station or other resources with related communication path 154 and 152 usually, and described communication path 154 and 152 need prevent such as the tight security that may be hacker's unauthorized entity.
As in Fig. 1, further illustrating, IEEE 802.1x framework comprise carry out interactive station mobility is offered pellucidly the several assemblies and the service of the higher level in the network stack.IEEE 802.1x network has defined such as access point 130 1-nAP station and fixing or portable terminal 140 1-n, being connected to wireless medium and comprising the function of IEEE 802.1x agreement as assembly, it is MAC (medium access control) 138 1-nWith PHY (Physical layer) (not shown) of correspondence, and be connected 127 to wireless medium.Usually, in the software and hardware of radio modem or network insertion or interface card, realize IEEE 802.1x function.The present invention proposes a kind of method, be used for being implemented in client terminal 140 at wireless medium 124 n, access point 130 n, the secure communication means between home server 120 and the certificate server 150.
According to the present invention, insert 160 and allow each to fix or portable terminal 140 1-nInsert WLAN 155 safely by authentication, and provide subsequently a kind of install come by as gateway 121, fire wall 122 create the management table of the safety service stream of guaranteeing between terminal and its communication system assembly, described gateway 121, fire wall 122 can be as the communication path 152 of representing HTTP and non-HTTP communication route and 154 and exist than the part of macroreticular.Can understand the 160 this modes that allow this safety to insert that insert best by reference Fig. 1.
Under the convention of IEEE 802.1x agreement, illustrated at fixing or wireless telecommunications system (as terminal 140 n), between public WLAN 115, local web-server 120 and the certificate server 150 in time and the sequential process of the interaction that takes place, the wherein access point 130 of Fig. 1 nKeep controlled ports and uncontrolled port, by its access point and terminal 140 1-nExchange message.By access point 130 nThe controlled ports that keeps is as the inlet passage such as the non-authentication information of data service, to pass through WLAN 115 and terminal 140 1-nUsually, access point 130 1-nKeep each controlled ports to close according to IEEE 802.1x agreement, up to relevant terminal 140 1-nAuthentication carry out till the communication.Access point 130 1-nTotal each uncontrolled port that keeps is opened to allow portable terminal 140 1-nWith certificate server 150 exchange verify datas.
More particularly, with reference to Fig. 2 and Fig. 3 a, in the method according to the invention, manager uses terminal 140 1-nCome from the remote computer 150 requests 210 supervising the network page forms that are designed usually as the HTML(Hypertext Markup Language) form with browser, it comprises that wherein manager can provide and the territory that obtains with the relevant information of the safety communication of network.In case received form 215, web page form will be filled with the management information of request, the management information of request can be submitted to 225 to remote computer 150 by the true-time operation device that the JavaScript code provides by for example calling when finishing 220, being character string with information package 230.The true-time operation device calls has the plug-in security function 235 of book character string as a parameter; Point out 240 safe function and remote system 150 to carry out communication 250.
In case receive 320 form data, remote system 150 produces random number 330 and stores 335 these numbers and is used for reference in the future.It also should be counted and send 340 to manager 140 1-nManager 140 1-nSafe function is connected 260 with this random number, administrator password (being stored in the plug-in unit) before with string argument.Afterwards, for producing 270, the result who connects returns to safe function such as the summary of message 5 summaries (MD5) and with it.This process comprises: use true-time operation device such as Javascript so that will be embedded in the form that comprises management information from the result of safe function then, and this form is sent 275 to remote computer 150, thereby finish submission.Remote computer uses random number, password of storing and the data that received to produce 350 1 MD5 digests.If this digests match 355, is then agreed 360 management of being asked and update system suitably in the summary that is received.If do not match then refuse 356 the visit.In communication subsequently, from manager management information is sent to remote computer 150, remote computer 150 at first produces random number, and this random number is used in message 5 summaries (MD5) by manager afterwards.In each case, remote system digest compares with the summary that is received subsequently, if this digests match, is then agreed the management request asked and update system correspondingly in the summary that is received
Form of the present invention shown in should be appreciated that only is a preferred embodiment.Can in function and arrangements of components, carry out various changes; To shown in and described device can replace with the device of equivalence; And can be independent of other features and use some feature, only otherwise depart from the scope and spirit of the present invention that in claims, define.

Claims (22)

1. one kind is used for exchanging the method for administering management information with the client terminal of wireless network, comprises step:
Receive administering the request of management document from client terminal;
To administer management document and send to client terminal;
Produce and send first parameter to client terminal;
Receive the new administration information and second parameter from client terminal;
Use predetermined algorithm and first parameter generating the 3rd parameter;
The 3rd parameter is compared to second parameter; With
Implement new administration information in response to described comparison step.
2. method according to claim 1, wherein said wireless network are the WLAN (wireless local area network) WLAN according to IEEE 802.11 standards, and described client terminal is the portable terminal in the coverage of WLAN, and described administration management document comprises the supervising the network page.
3. method according to claim 2, wherein said first parameter is a random number.
4. method according to claim 3, the step of wherein said generation the 3rd parameter comprise uses hash function and first parameter generating the 3rd parameter.
5. method according to claim 3, the step of wherein said generation the 3rd parameter comprise uses hash function, first parameter, password and string argument to produce the 3rd parameter.
6. method according to claim 5, wherein said string argument is corresponding with new administration information.
7. method according to claim 2, wherein forwarding step comprises that the transmission supervising the network page and ActiveX control are to client terminal.
8. access point in wireless network comprises:
Transceiver is used for and the client terminal communication;
Be coupled to the device of transceiver, be used to make that transceiver sends the administration management document in response to the request that comes from client terminal;
Be used to produce first parameter and make transceiver send the device of first parameter to client terminal, this transceiver receives the new administration information and second parameter from client terminal;
Be used for producing the 3rd parameter and the 3rd parameter be compared to the device of second parameter in response to first parameter; With
Be used for implementing the device of new administration information in response to described comparison.
9. access point according to claim 8, wherein said wireless network is the wireless lan (wlan) according to IEEE 802.11 standards, described client terminal is the portable terminal in the coverage of WLAN, and described administration management document comprises the supervising the network page.
10. access point according to claim 9, wherein said first parameter is a random number, and the described device that is used to produce the 3rd parameter comprises and is used to use hash function, random number, password and string argument to produce the device of the 3rd parameter.
11. access point according to claim 10, wherein said string argument is corresponding to new administration information.
12. a method of using the access point exchange administration management information in client terminal and the wireless network comprises step:
To send to access point to the request of administration management document;
Receive the administration management document from access point;
Receive first parameter from access point;
Import the generation new administration information in response to the user;
Use predetermined algorithm and first parameter generating, second parameter;
Second parameter and new administration information are sent to access point.
13. method according to claim 12, wherein said wireless network is the WLAN (wireless local area network) WLAN according to IEEE 802.11 standards, described client terminal is the portable terminal that meets IEEE 802.11 standards, and described administration management document comprises the supervising the network page.
14. method according to claim 13, the step of wherein said receiving management Webpage comprises receiving management Webpage and ActiveX control.
15. comprising, method according to claim 13, the step of wherein said generation second parameter use the hash function and first parameter to produce second parameter.
16. comprising, method according to claim 13, the step of wherein said generation second parameter use hash function, first parameter, password and string argument to produce second parameter.
17. method according to claim 16 wherein produces described string argument from new administration information.
18. one kind is used for the client terminal that carries out communication with the access point that is associated with wireless network, comprises:
Transceiver is used for and the access point communication;
Be coupled to the device of transceiver, be used to make transceiver to send to access point, and receive the administration management document, and be used for receiving first parameter from this access point from this access point for the request of administration management document;
Be used for producing the device of new administration information in response to user's input;
Be used to use the predetermined algorithm and first parameter to produce the device of second parameter;
Be used to make that transceiver sends to second parameter and new administration information in the device of access point.
19. client terminal according to claim 18, wherein said wireless network is the WLAN (wireless local area network) WLAN according to the IEEE802.11 standard, described client terminal is the portable terminal that meets IEEE 802.11 standards, and described administration management document comprises the supervising the network page.
21. client terminal according to claim 19 wherein uses described second parameter of the hash function and first parameter generating.
22. client terminal according to claim 19 wherein uses hash function, first parameter, password and string argument to produce described second parameter.
23. client terminal according to claim 22 wherein produces described string argument from new administration information.
CNA2004800118811A 2003-03-14 2004-03-11 Secure web browser based system administration for embedded platforms. Pending CN1784673A (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US45458203P 2003-03-14 2003-03-14
US60/454,582 2003-03-14

Publications (1)

Publication Number Publication Date
CN1784673A true CN1784673A (en) 2006-06-07

Family

ID=33029898

Family Applications (1)

Application Number Title Priority Date Filing Date
CNA2004800118811A Pending CN1784673A (en) 2003-03-14 2004-03-11 Secure web browser based system administration for embedded platforms.

Country Status (6)

Country Link
EP (1) EP1604294A2 (en)
JP (1) JP2006520501A (en)
KR (1) KR20050119119A (en)
CN (1) CN1784673A (en)
MX (1) MXPA05009878A (en)
WO (1) WO2004084019A2 (en)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101150577B (en) * 2007-11-02 2010-10-20 珠海金山软件有限公司 A system and method for secure Internet local function call
CN105262605A (en) * 2014-07-17 2016-01-20 阿里巴巴集团控股有限公司 Method, apparatus and system for obtaining local information

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20030235305A1 (en) * 2002-06-20 2003-12-25 Hsu Raymond T. Key generation in a communication system

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101150577B (en) * 2007-11-02 2010-10-20 珠海金山软件有限公司 A system and method for secure Internet local function call
CN105262605A (en) * 2014-07-17 2016-01-20 阿里巴巴集团控股有限公司 Method, apparatus and system for obtaining local information
CN105262605B (en) * 2014-07-17 2018-09-25 阿里巴巴集团控股有限公司 A kind of method, apparatus and system obtaining local information
US11240210B2 (en) 2014-07-17 2022-02-01 Advanced New Technologies Co., Ltd. Methods, apparatuses, and systems for acquiring local information

Also Published As

Publication number Publication date
WO2004084019A2 (en) 2004-09-30
EP1604294A2 (en) 2005-12-14
JP2006520501A (en) 2006-09-07
MXPA05009878A (en) 2006-03-13
WO2004084019A3 (en) 2004-12-02
KR20050119119A (en) 2005-12-20

Similar Documents

Publication Publication Date Title
US7142851B2 (en) Technique for secure wireless LAN access
Groß Security analysis of the SAML single sign-on browser/artifact profile
US6694431B1 (en) Piggy-backed key exchange protocol for providing secure, low-overhead browser connections when a server will not use a message encoding scheme proposed by a client
EP3008935B1 (en) Mobile device authentication in heterogeneous communication networks scenario
Lloyd et al. PPP authentication protocols
US6775772B1 (en) Piggy-backed key exchange protocol for providing secure low-overhead browser connections from a client to a server using a trusted third party
US8589675B2 (en) WLAN authentication method by a subscriber identifier sent by a WLAN terminal
FI115098B (en) Authentication in data communication
CN1711740B (en) Lightweight extensible authentication protocol password preprocessing
US7039946B1 (en) Piggy-backed key exchange protocol for providing secure, low-overhead browser connections when a client requests a server to propose a message encoding scheme
CN107579991B (en) Method for performing cloud protection authentication on client, server and client
CN1830190A (en) Controlling access to a network using redirection
US6751731B1 (en) Piggy-backed key exchange protocol for providing secure, low-overhead browser connections to a server with which a client shares a message encoding scheme
US20090113522A1 (en) Method for Translating an Authentication Protocol
CN1759558A (en) An identity mapping mechanism in wlan access control with public authentication servers
CN114978773A (en) Single package authentication method and system
EP1639782B1 (en) Method for distributing passwords
KR100819024B1 (en) Method for authenticating user using ID/password
CN1784673A (en) Secure web browser based system administration for embedded platforms.
US20060173981A1 (en) Secure web browser based system administration for embedded platforms
CN1567859A (en) A method of access authentication for WLAN
Lloyd et al. RFC1334: PPP Authentication Protocols
KR100406292B1 (en) Password Transmission system and method in Terminal Communications
Ahn et al. Improved Security Mechanism over Mobile WIMAX Initial Networks
CN116488853A (en) Trusted authentication method for mobile office scene

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
AD01 Patent right deemed abandoned

Effective date of abandoning: 20110629

C20 Patent right or utility model deemed to be abandoned or is abandoned