TWI415418B - A system that controls computers to access the Internet - Google Patents
A system that controls computers to access the Internet Download PDFInfo
- Publication number
- TWI415418B TWI415418B TW98132218A TW98132218A TWI415418B TW I415418 B TWI415418 B TW I415418B TW 98132218 A TW98132218 A TW 98132218A TW 98132218 A TW98132218 A TW 98132218A TW I415418 B TWI415418 B TW I415418B
- Authority
- TW
- Taiwan
- Prior art keywords
- mobile device
- connection
- computer
- user
- driver
- Prior art date
Links
- 238000001514 detection method Methods 0.000 claims description 27
- 238000000034 method Methods 0.000 abstract description 3
- 238000010586 diagram Methods 0.000 description 4
- 238000004891 communication Methods 0.000 description 2
- 238000007726 management method Methods 0.000 description 2
- 230000005540 biological transmission Effects 0.000 description 1
- 230000007423 decrease Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 230000007613 environmental effect Effects 0.000 description 1
- PCHJSUWPFVWCPO-UHFFFAOYSA-N gold Chemical compound [Au] PCHJSUWPFVWCPO-UHFFFAOYSA-N 0.000 description 1
- 239000010931 gold Substances 0.000 description 1
- 229910052737 gold Inorganic materials 0.000 description 1
Landscapes
- Telephonic Communication Services (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
本發明係關於一種控管電腦以行動裝置上網的系統,特別為一種利用控管電腦作業系統中的行動裝置驅動程式與連線程式,並運用控管政策派送伺服器,設定權限至須接受控管的電腦代理程式中,以達到可依使用者不同權限,加以控管該電腦可否經由行動裝置連接上網的目的。The invention relates to a system for controlling a computer to use a mobile device to access the Internet, in particular to a mobile device driver system and a threaded type in a control computer operating system, and using a control policy to dispatch a server, setting authority to be controlled In the computer agent program, the user can control whether the computer can be connected to the Internet via a mobile device according to different permissions of the user.
行動上網的時代來臨,行動上網裝置種類也越來越繁多,上網速度也越來越快,相對的用3G行動裝置中的數據通訊功能就可以滿足一般使用者能隨時隨地上網汲取資訊的需求。The era of mobile Internet access is coming, the types of mobile Internet devices are becoming more and more numerous, and the Internet speed is getting faster and faster. The relative data communication function in 3G mobile devices can meet the needs of ordinary users to access information online anytime and anywhere.
隨著各項3G行動裝置產品及寬頻價格下滑,企業資訊風險卻隨之升高。在當前企業中,過去大量機密性資料的外洩或遭竊取的新聞時有所聞,其中包括個人資料、客戶資料或是銀行交易紀錄等。因此企業開始重視資訊風險管理,並從使用環境管理、使用者的使用習慣、密碼控管著手。With the decline of various 3G mobile device products and broadband prices, corporate information risks have increased. In the current enterprise, news of the leakage or theft of a large amount of confidential information in the past has been known, including personal data, customer data or bank transaction records. Therefore, enterprises began to pay attention to information risk management, and began to use environmental management, user habits, and password control.
但是越來越多使用者在工作環境中使用3G行動裝置中的數據通訊功能,讓電腦同時介接企業內部網路並連線到外部網路。企業因此在不安全的環境下從事機密性文件的傳輸,而造成企業機密性文件被竊或是遺失。故企業的資訊部門也應著手針對3G行動裝置的上網功能進行控管。However, more and more users use the data communication function in the 3G mobile device in the work environment, so that the computer can simultaneously connect to the internal network of the enterprise and connect to the external network. Enterprises are therefore engaged in the transmission of confidential documents in an unsafe environment, resulting in the theft or loss of confidential documents. Therefore, the information department of the enterprise should also start to control the Internet access function of the 3G mobile device.
在實務上,目前3G行動裝置功能強大,種類也繁多。故必須深入的研究每種3G行動裝置上網的功能與連線模式,才能有效的控管使用者連線到企業外部網路所產生的資安風險。In practice, the current 3G mobile devices are powerful and diverse. Therefore, it is necessary to thoroughly study the functions and connection modes of each 3G mobile device to effectively control the security risks generated by users connecting to the external network of the enterprise.
目前市面上3G行動裝置中的開放性作業系統包含:Symbian、Windows Mobile、MAC OSX、黑莓機、Andorid與Linux等。這些行動裝置的作業系統皆經由四種硬體介面與電腦連線,分別為:Universal Serial Bus(USB)、藍芽、紅外線與WiFi無線網路;此四種硬體在電腦上安裝後會分成兩類裝置,一為網卡,二為數據機。其中網卡又可區分為:有線網卡、無線網卡與虛擬網卡三種,3G行動裝置通常係以後兩者為驅動方式。因為此兩類裝置類別本就屬於連接網路之實體層,故控制驅動程式即為控管網路連接。The open operating system in the current 3G mobile device on the market includes: Symbian, Windows Mobile, MAC OSX, BlackBerry, Andorid and Linux. The operating systems of these mobile devices are connected to the computer via four hardware interfaces: Universal Serial Bus (USB), Bluetooth, infrared and WiFi wireless networks; these four hardwares are divided into two parts after being installed on the computer. Two types of devices, one for the network card and two for the data machine. The network card can be divided into three types: a wired network card, a wireless network card and a virtual network card. The 3G mobile device is usually driven by the latter two. Because these two types of devices are inherently connected to the physical layer of the network, the control driver is the control network connection.
使用者必須在電腦上安裝該行動裝置的作業系統所需的連線程式,例如:Windows Mobile需安裝ActiveSync,Symbian需安裝PC Suite,以及MAC OSX需安裝iTunes等;這些連線程式將會經由網卡或數據機的驅動程式連接上3G行動裝置。連線成功後,使用者就可以用3G行動裝置讓電腦連到外部網路。故本發明只需對使用者的網卡或數據機驅動程式加以控制,即可達到控管的目的。The user must install the threaded system required for the operating system of the mobile device on the computer, for example: Windows Mobile needs to install ActiveSync, Symbian needs to install PC Suite, and MAC OSX needs to install iTunes; these threads will pass through the network card. Or the driver of the data machine is connected to the 3G mobile device. After the connection is successful, the user can connect the computer to the external network with a 3G mobile device. Therefore, the present invention only needs to control the user's network card or data machine driver to achieve the purpose of control.
本案發明人鑑於上述所衍生的各項問題,經苦心孤詣潛心研究後,研發完成本件發明,將可解決企業所將面臨重大的資安問題。In view of the above-mentioned problems arising from the above-mentioned problems, the inventors of this case have researched and developed the inventions after painstaking research, which will solve the major capital security problems that enterprises will face.
本發明之目的即在於提供一種控管電腦以行動裝置上網的系統,以提供企業內部的使用者進行行動裝置上網行為的控管。The object of the present invention is to provide a system for controlling a computer to use a mobile device to access the Internet, so as to provide a user inside the enterprise to control the online behavior of the mobile device.
達成上述發明目的之控管電腦以行動裝置上網的系統,係由裝置行動裝置上網控管代理模組之電腦,可透過企業內部網路連接至後端的企業控管政策之伺服器,取得行動裝置上網控管政策之設定。其設定方式是經由企業內部的行動裝置控管政策伺服器將權限分派至每個使用者電腦中的行動裝置上網控管代理模組,進行行動裝置上網行為的控管。 企業內部的行動裝置控管政策伺服器將權限分派至每個使用者電腦中的行動裝置上網控管代理模組,進行行動裝置上網行為的控管。The system for controlling the computer to achieve the above-mentioned invention is a mobile device that is connected to the computer of the agent module of the mobile device, and can be connected to the server of the enterprise control policy of the back end through the internal network of the enterprise to obtain the mobile device. The setting of the online control policy. The setting method is to distribute the authority to the mobile device control agent module of the mobile device in each user computer through the mobile device control policy server in the enterprise, and control the online behavior of the mobile device. The mobile device control policy server in the enterprise assigns the authority to the mobile device control agent module of the mobile device in each user's computer, and controls the online behavior of the mobile device.
使用者電腦若使用行動裝置上網行為時,行動裝置上網控管代理模組將依照權限設定,檢查該電腦是否允許連線至行動裝置;若不允許時,行動裝置上網控管代理模組中的驅動程式控制模組將關閉該行動裝置連線程式或是該行動裝置驅動程式。If the user's computer uses the mobile device to access the Internet, the mobile device control agent module of the mobile device will check whether the computer is allowed to connect to the mobile device according to the authority; if not, the mobile device controls the proxy module in the Internet. The driver control module will close the mobile device with the thread or the mobile device driver.
請參閱圖一,為本發明控管電腦以行動裝置上網的系統之實施架構示意圖,由圖中可知,其中分為上下兩部分:上半部份為本發明之功能方塊圖,可包含行動裝置控管政策伺服器1和行動裝置上網控管代理模組2;下半部份為一般使用者用行動裝置讓電腦連到外部網路之示意圖。Please refer to FIG. 1 , which is a schematic diagram of an implementation structure of a system for controlling a computer to access a mobile device according to the present invention. It can be seen from the figure that the upper and lower parts are divided into two parts: the upper part is a functional block diagram of the present invention, and may include a mobile device. The control policy server 1 and the mobile device control the proxy module 2; the lower part is a schematic diagram of the general user using the mobile device to connect the computer to the external network.
前述所稱之行動裝置控管政策伺服器1可透過行動裝置上網控管代理模組2提供設定使用者是否可以使用行動裝置上網,並且可即時更新、記錄使用者電腦的行動裝置使用狀態。另外本發明之核心為行動裝置上網控管代理模組2,其包含行動裝置上網控管政策模組21、行動裝置上網連線記錄模組22、網卡連線偵測模組23、數據機撥號連線偵測模組24、網卡驅動程式控制模組25及數據機驅動程式控制模組26等6個模組,各模組之詳細之功能、動作流程與關係如下列所述:行動裝置上網控管政策模組21,主要為接受行動裝置控管政策伺服器1之控管政策派送介面11所傳送的命令,取得該使用者之控管權限的連線設定參數,再經由偵測參數設定介面211將行動裝置上網連線設定參數傳送給網卡連線偵測模組23或數據機撥號連線偵測模組24。若使用者電腦使 用的連線裝置為網卡驅動程式時,網卡連線偵測模組23會偵測到網卡連線狀態,再藉由連線狀態偵測回傳介面221將該網卡連線狀態傳回至行動裝置上網連線記錄模組22記錄下來。另外可再經由網卡連線設定介面231將連線設定參數傳送至網卡驅動程式控制模組25中,其中參數定義設定為可將網卡驅動程式設定為啟用或停用。當網卡驅動程式控制模組25接受到網卡連線偵測模組23之網卡連線設定介面231中的連線設定參數後,若此參數定義為要將網卡驅動程式關閉時,將由網卡驅動程式設定介面251直接控制停用使用者電腦之作業系統中所對應的裝置驅動程式,以求達到控管該網卡連線之目的。The aforementioned mobile device control policy server 1 can provide a setting for the user to use the mobile device to access the Internet through the mobile device control agent module 2, and can instantly update and record the mobile device usage status of the user's computer. In addition, the core of the present invention is a mobile device control module 2 for mobile devices, which includes a mobile device control policy module 21, a mobile device connection recording module 22, a network card connection detection module 23, and a data machine dialing. 6 modules, such as the connection detection module 24, the network card driver control module 25 and the data machine driver control module 26, the detailed functions, operation processes and relationships of the modules are as follows: The control policy module 21 mainly receives the command transmitted by the control policy delivery interface 11 of the mobile device control policy server 1, obtains the connection setting parameter of the user's control authority, and then sets the detection parameter through the detection parameter. The interface 211 transmits the mobile device connection setting parameter to the network card connection detection module 23 or the data machine dial connection detection module 24. If the user makes a computer When the connection device is the network card driver, the network card connection detection module 23 detects the connection status of the network card, and then transmits the connection status of the network card back to the action through the connection status detection back interface 221. The device Internet connection recording module 22 records. In addition, the connection setting parameter can be transmitted to the network card driver control module 25 via the network card connection setting interface 231, wherein the parameter definition is set to enable or disable the network card driver. After the network card driver control module 25 receives the connection setting parameter in the network card connection setting interface 231 of the network card connection detection module 23, if the parameter is defined as the network card driver is to be turned off, the network card driver is used. The setting interface 251 directly controls the device driver corresponding to the operating system of the disabled user computer, so as to achieve the purpose of controlling the connection of the network card.
若使用者電腦使用的連線裝置為數據機驅動時,數據機撥號連線偵測模組24會偵測到數據機連線狀態,再藉由連線狀態偵測回傳介面221將該數據機連線狀態傳回至行動裝置上網連線記錄模組22記錄下來,另外可再經由數據機連線設定介面241將連線設定參數傳送至數據機驅動程式控制模組26中,其中參數定義設定為可將數據機驅動程式設定為啟用或停用。當數據機驅動程式控制模組26接受到數據機連線偵測模組24之數據機連線設定介面241中的連線設定參數後,若此參數定義為要將數據機驅動程式關閉時,將由數據機驅動程式設定介面261直接控制停用使用者電腦之作業系統中所對應的裝置驅動程式,以求達到控管該數據機連線之目的。If the connection device used by the user's computer is a data machine driver, the data dialing connection detection module 24 detects the connection status of the data machine, and then detects the data through the connection status detection interface 221 The connection status of the machine is transmitted back to the mobile device connection record recording module 22, and the connection setting parameter is transmitted to the data machine driver control module 26 via the data connection setting interface 241, wherein the parameter definition is Set to enable the modem driver to be enabled or disabled. After the data driver driver control module 26 receives the connection setting parameter in the data connection setting interface 241 of the data connection detection module 24, if the parameter is defined to be to turn off the data driver, The data driver driver setting interface 261 directly controls the device driver corresponding to the operating system of the deactivated user computer, so as to control the connection of the data machine.
行動裝置上網連線記錄模組22,主要是由偵測參數設定介面211與連線狀態偵測回傳介面221,接收該使用者之網卡或數據機連線狀態,再由連線記錄回傳介面12傳回給行動裝置控管政策伺服器1,回報使用者電腦之行動裝置上網連線是否合乎政策。The mobile device connection recording module 22 is mainly configured by the detection parameter setting interface 211 and the connection state detection back interface 221, and receives the connection state of the user's network card or the data machine, and then returns the connection record. The interface 12 is transmitted back to the mobile device control policy server 1 to report whether the mobile device connection of the user's computer is in compliance with the policy.
本發明所提供之控管電腦以行動裝置上網的系統,與其他習用技術相互比較時,更具備下列優點:The system for controlling the computer connected to the mobile device provided by the invention has the following advantages when compared with other conventional technologies:
1.本發明提供之系統,無論使用者的行動裝置是何種作業系統,皆可控管與偵測記錄該上網連線行為,可解決金業所將面臨的重大資安問題。1. The system provided by the present invention can control and detect the online connection behavior regardless of the operating system of the user's mobile device, and can solve the major security problems that the gold industry will face.
2.無論行動裝置的作業系統為何種,所提供之網卡與數據機驅動程式控制模組直接控制該裝置之驅動程式,不會影響行動裝置網路連線程式,相容性高。2. Regardless of the operating system of the mobile device, the provided network card and the data machine driver control module directly control the driver of the device, and the network of the mobile device is not threaded, and the compatibility is high.
3.提供控管政策伺服器,可由派送介面傳送命令,設定該使用者之控管權限。並可由上網連線偵測回報該使用者之連線狀態是否合乎政策。3. Provide a control policy server, which can be sent by the dispatch interface to set the user's control authority. It can be detected by the Internet connection to report whether the connection status of the user is in compliance with the policy.
4.舉凡有關控管電腦由行動裝置上網之模組或是系統,皆可使用本發明。4. The present invention can be used in any module or system for controlling a computer to be accessed by a mobile device.
上列詳細說明係針對本發明之一可行實施例之具體說明,惟該實施例並非用以限制本發明之專利範圍,凡未脫離本發明技藝精神所為之等效實施或變更,均應包含於本案之專利範圍中。The detailed description of the preferred embodiments of the present invention is intended to be limited to the scope of the invention, and is not intended to limit the scope of the invention. The patent scope of this case.
綜上所述,本案不但在技術思想上確屬創新,並能較習用物品增進上述多項功效,應以充分符合新穎性及進步性之法定發明專利要件,爰依法提出申請,懇請 貴局核准本件發明專利申請案,以勵發明,至感德便。To sum up, this case is not only innovative in terms of technical thinking, but also able to enhance the above-mentioned multiple functions compared with conventional articles. It should be submitted in accordance with the law in accordance with the statutory invention patents that fully meet the novelty and progressiveness, and you are requested to approve this article. Invention patent application, in order to invent invention, to the sense of virtue.
1‧‧‧行動裝置控管政策伺服器1‧‧‧Mobile device control policy server
11‧‧‧控管政策派送介面11‧‧‧Control Policy Delivery Interface
12‧‧‧連線記錄回傳介面12‧‧‧Connection record back interface
2‧‧‧行動裝置上網控管代理程式2‧‧‧Mobile device Internet control agent
21‧‧‧行動裝置上網控管政策設定模組21‧‧‧Mobile device Internet control policy setting module
211‧‧‧偵測參數設定介面211‧‧‧Detection parameter setting interface
22‧‧‧行動裝置上網連線記錄模組22‧‧‧Mobile device Internet connection recording module
221‧‧‧連線狀態偵測回傳介面221‧‧‧Connection status detection backhaul interface
23‧‧‧網卡連線偵測模組23‧‧‧Network card connection detection module
231‧‧‧網卡連線設定介面231‧‧‧Network card connection setting interface
24‧‧‧數據機撥號連線偵測模組24‧‧‧Data machine dial-up connection detection module
241‧‧‧數據機連線設定介面241‧‧‧Data machine connection setting interface
25‧‧‧網卡驅動程式控制模組25‧‧‧Network Card Driver Control Module
251‧‧‧網卡驅動程式設定介面251‧‧‧Network card driver setting interface
26‧‧‧數據機驅動程式控制模組26‧‧‧Data machine driver control module
261‧‧‧數據機驅動程式設定介面261‧‧‧Data machine driver setting interface
圖一為本發明控管電腦以行動裝置上網的系統之實施架構示意圖。FIG. 1 is a schematic diagram of an implementation architecture of a system for controlling a computer to access a mobile device by using a mobile device.
1...行動裝置控管政策伺服器1. . . Mobile device control policy server
11...控管政策派送介面11. . . Control policy delivery interface
12...連線記錄回傳介面12. . . Connection record backhaul interface
2...行動裝置上網控管代理程式2. . . Mobile device web control agent
21...行動裝置上網控管政策設定模組twenty one. . . Mobile device Internet control policy setting module
211...偵測參數設定介面211. . . Detection parameter setting interface
22...行動裝置上網連線記錄模組twenty two. . . Mobile device Internet connection recording module
221...連線狀態偵測回傳介面221. . . Connection status detection backhaul interface
23...網卡連線偵測模組twenty three. . . NIC connection detection module
231...網卡連線設定介面231. . . NIC connection setting interface
24...數據機撥號連線偵測模組twenty four. . . Data dialing connection detection module
241...數據機連線設定介面241. . . Data connection setting interface
25...網卡驅動程式控制模組25. . . NIC driver control module
251...網卡驅動程式設定介面251. . . NIC driver setting interface
26...數據機驅動程式控制模組26. . . Data machine driver control module
261...數據機驅動程式設定介面261. . . Data machine driver setting interface
Claims (9)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| TW98132218A TWI415418B (en) | 2009-09-24 | 2009-09-24 | A system that controls computers to access the Internet |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| TW98132218A TWI415418B (en) | 2009-09-24 | 2009-09-24 | A system that controls computers to access the Internet |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| TW201112676A TW201112676A (en) | 2011-04-01 |
| TWI415418B true TWI415418B (en) | 2013-11-11 |
Family
ID=44909332
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| TW98132218A TWI415418B (en) | 2009-09-24 | 2009-09-24 | A system that controls computers to access the Internet |
Country Status (1)
| Country | Link |
|---|---|
| TW (1) | TWI415418B (en) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| TW200527215A (en) * | 2003-12-18 | 2005-08-16 | Red Hat Inc | Rights management system |
| TW200820026A (en) * | 2006-10-17 | 2008-05-01 | Jiunn-Sheng Yan | Information security monitor and control method and the device thereof |
| TWM336634U (en) * | 2007-11-07 | 2008-07-11 | Handlink Technologies Inc | Internet access apparatus |
| TW200833007A (en) * | 2007-01-19 | 2008-08-01 | Plantynet Taiwan Co Ltd | Management method for network connection time and system thereof |
| TW200904067A (en) * | 2007-07-04 | 2009-01-16 | Asustek Comp Inc | Method and system for connecting network using communication apparatus |
-
2009
- 2009-09-24 TW TW98132218A patent/TWI415418B/en not_active IP Right Cessation
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| TW200527215A (en) * | 2003-12-18 | 2005-08-16 | Red Hat Inc | Rights management system |
| TW200820026A (en) * | 2006-10-17 | 2008-05-01 | Jiunn-Sheng Yan | Information security monitor and control method and the device thereof |
| TW200833007A (en) * | 2007-01-19 | 2008-08-01 | Plantynet Taiwan Co Ltd | Management method for network connection time and system thereof |
| TW200904067A (en) * | 2007-07-04 | 2009-01-16 | Asustek Comp Inc | Method and system for connecting network using communication apparatus |
| TWM336634U (en) * | 2007-11-07 | 2008-07-11 | Handlink Technologies Inc | Internet access apparatus |
Also Published As
| Publication number | Publication date |
|---|---|
| TW201112676A (en) | 2011-04-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9699216B2 (en) | System and method for remotely managing security and configuration of compute devices | |
| CN101266590B (en) | Method and system for dynamically switching device configuration | |
| TWI451266B (en) | A system and method for enabling cloud computing services based on user location | |
| US8122172B2 (en) | Portable information security device | |
| TWI606352B (en) | Computer unit, server and related computer program product and method | |
| CN105247531A (en) | Providing managed browser | |
| CN101308475A (en) | Safe mobile storage system and usage method thereof | |
| CN102148841B (en) | Method for remotely monitoring multiple operating systems | |
| CN111158857B (en) | Data encryption method, device, equipment and storage medium | |
| CN104216761B (en) | It is a kind of that the method for sharing equipment is used in the device that can run two kinds of operating system | |
| WO2005101205A1 (en) | Computer system | |
| CN104268484A (en) | Cloud environment data leakage prevention method based on virtual isolation mechanism | |
| CN108537072A (en) | A kind of USB interface-based security system | |
| US20030217278A1 (en) | Computer, hard disk device, disk device sharing system composed of the plural said computers and shared hard disk device, and sharing method applied to the said sharing system | |
| CN102194079A (en) | File access filtering method | |
| TWI415418B (en) | A system that controls computers to access the Internet | |
| CN103795726A (en) | Depth protection method for virtual data safety access | |
| CN105872096B (en) | A kind of distal end shared system of external equipment | |
| TW201524156A (en) | Real-time network monitoring system | |
| CN202512605U (en) | Multifunctional secure digital (SD) card | |
| CN101374048A (en) | Mandatory terminal monitoring system based on fine-grained centralized strategy in mobile office | |
| CN104135366A (en) | Data authentication system and data authentication method | |
| JP4908367B2 (en) | Information processing device | |
| CN112399414B (en) | Network connection method, device, electronic device and storage medium | |
| KR101260633B1 (en) | Personal information auto-saving security system and drive method of the same |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| MM4A | Annulment or lapse of patent due to non-payment of fees |