Communication system, network for qualification screening/setting, communication device, and network connection method

Information

  • Patent Application
  • 20070174381
  • Publication Number
    20070174381
  • Date Filed
    January 09, 2007
    18 years ago
  • Date Published
    July 26, 2007
    18 years ago
Abstract
The present invention provides a network connection method which prevents connection by virus-infected communication devices or communication devices intended for unauthorized access to a network, and enables connection to the network in a simple manner. A user of a requestor communication device connects to a main network by inserting a cable of the communication device to a port of a network device. When the requestor communication device is connected one-on-one to a reception box by a check-in network inside the network device, check-in is performed using the reception box. When the reception box determines through check-in processing that the requestor communication device satisfies connection qualifications, the reception box switches the network, to which the requestor communication device will be connected, from the check-in network to the main network. The requestor communication device then makes a transition to actual use of the main network.
Description

BRIEF DESCRIPTION OF THE DRAWINGS


FIG. 1 is a flowchart showing operations of a communication system according to an embodiment of the present invention;



FIG. 2 is a block diagram showing a configuration of a communication system according to a first example of the present invention;



FIG. 3 is a block diagram showing a connection status of a reception box and a communication device shown in FIG. 2;



FIG. 4 is a block diagram showing a configuration of the reception box shown in FIG. 2;



FIG. 5 is a block diagram showing a configuration of the communication device shown in FIG. 2;



FIG. 6 is a sequence chart showing network connection processing in the communication system according to the first example of the present invention;



FIG. 7 is a sequence chart showing network connection processing in the communication system according to the first example of the present invention;



FIG. 8 is a sequence chart showing quarantine processing in the communication system according to the first example of the present invention;



FIG. 9 is a sequence chart showing quarantine processing in the communication system according to the first example of the present invention;



FIG. 10 is a flowchart showing processing of a check-in tool used in the communication system according to the first example of the present invention;



FIG. 11 is a flowchart showing processing of confirming a plug-in destination network in the communication system according to the first example of the present invention;



FIG. 12 is a sequence chart showing operations during plug-out in the communication system according to the first example of the present invention;



FIG. 13 is a block diagram showing a configuration of a communication system according to a second example of the present invention;



FIG. 14 is a flowchart showing operations of a communication device in the communication system according to the second example of the present invention;



FIG. 15 is a block diagram showing a configuration of a communication system according to a third example of the present invention;



FIG. 16 is a block diagram showing a connection status of a reception box and peripheral device in a communication system according to the third example of the present invention;



FIG. 17 is a sequence chart showing network connection processing in the communication system according to the third example of the present invention;



FIG. 18 is a sequence chart showing network connection processing in the communication system according to a fourth example of the present invention;



FIG. 19 is a sequence chart showing network connection processing in the communication system according to the fourth example of the present invention; and



FIG. 20 is a block diagram showing a connection status of a reception box and a communication device according to a fifth example of the present invention.


Claims
  • 1. A communication system, including a main network which provides various services, a network for qualification screening/setting provided independently from the main network, a reception control section connected to the main network and the network for qualification screening/setting, the communication system further comprising: means of performing quarantine connection of a communication device to the reception control section via the network for qualification screening/setting when the communication device requests connection to the main network;means of performing qualification screening, provided at the reception control section, which acquires status information of the quarantine-connected communication device to determine whether the status satisfies preset qualification requirements; andmeans of connecting the network, to which the communication device is connected, to the main network when it is determined that the qualification requirements are satisfied.
  • 2. A communication system, including a plurality of main networks which provide various services, a network for qualification screening/setting provided independently from the plurality of main networks, a reception control section connected to the main networks and the network for qualification screening/setting, the communication system further comprising: means of performing quarantine connection of a communication device to the reception control section via the network for qualification screening/setting when the communication device requests connection to the main networks;means of performing qualification screening, provided at the reception control section, which acquires status information of the quarantine-connected communication device to determine whether the status satisfies preset qualification requirements; andmeans of selectively connecting the network, to which the communication device is connected, to any one of the plurality of main networks according to the qualification requirements when it is determined that the qualification requirements are satisfied.
  • 3. The communication system according to claim 1, wherein the reception control section provides in advance the quarantine-connected communication device with key information for verifying, using an electronic signature function, whether information to be acquired from the main network is proper information.
  • 4. The communication system according to claim 1, wherein the communication device provides in advance the quarantine-connected reception control section with key information for verifying, using an electronic signature function, whether information to be transmitted from the device itself to the main network is proper information.
  • 5. The communication system according to claim 1, wherein the communication device confirms connection destination in the network for qualification screening/setting when connection to the network for qualification screening/setting connection is detected, triggered by connection of the device itself to the network for qualification screening/setting connection, and performs automatic discovery configuration of required information to the reception control section of the confirmed connection destination.
  • 6. The communication system according to claim 1, wherein the reception control section returns the communication device to a quarantine-connection setting when the communication device is disconnected from the main network.
  • 7. The communication system according to claim 1, wherein, when the communication device connects to the network for qualification screening/setting without being loaded with a tool for qualification screening, the reception control section guides Web access from the communication device to a download site of the tool for qualification screening, and the communication device downloads and installs the tool for qualification screening from the download site.
  • 8. The communication system according to claim 7, wherein, in the event that a new tool for qualification screening exists on the download site when connecting to the network for qualification screening/setting, the communication device downloads and executes the new tool for qualification screening.
  • 9. The communication system according to claim 7, wherein the tool for qualification screening confirms existence of updated information on the download site when the communication device connects to the network for qualification screening/setting, and downloads the updated information if such information exists.
  • 10. The communication system according to claim 1, wherein the reception control section connects all communication devices to the network for qualification screening/setting when events regarding the main network match requirements set in advance from the outside.
  • 11. The communication system according to claim 7, wherein the communication device is a communication device which may be loaded with the tool for qualification screening.
  • 12. The communication system according to claim 1, wherein the reception control section comprises means of confirming the type of communication device when such device is incapable of being loaded with the tool for qualification screening, and means of setting information at the communication device according to confirmation results.
  • 13. The communication system according to claim 12, wherein the information to be set at the communication device is information for enabling the communication device to operate on the main network.
  • 14. The communication system according to claim 1, wherein the main network and the network for qualification screening/setting are respectively at least either a VLAN (Virtual LAN [Local Area Network]) or a VPN (Virtual Private Network).
  • 15. A network for qualification screening/setting, provided independently from a main network which provides various services and connected to a reception control section together with the main network, the network for qualification screening/setting comprising: means of performing quarantine connection of a communication device to the reception control section when the communication device requests connection to the main network; andmeans of connecting the communication device, quarantine-connected to the reception control section, to the main network when it is determined that the status information of the communication device satisfies preset qualification requirements.
  • 16. A network for qualification screening/setting, provided independently from a plurality of main networks which provide various services and connected to a reception control section together with the main networks, the network for qualification screening/setting comprising: means of performing quarantine connection of a communication device to the reception control section when the communication device requests connection to the main networks; andmeans of selectively connecting the communication device, quarantine-connected to the reception control section, to one of the plurality of main networks according to the qualification requirements when it is determined that the status information of the communication device satisfies preset qualification requirements.
  • 17. The network for qualification screening/setting according to claim 15, wherein the reception control section provides in advance a quarantine-connected communication device with key information for verifying, using an electronic signature function, whether information to be acquired from the main network is proper information.
  • 18. The network for qualification screening/setting according to claim 15, wherein the communication device provides in advance the quarantine-connected reception control section with key information for verifying, using an electronic signature function, whether information to be transmitted from the communication device to the main network is proper information.
  • 19. The network for qualification screening/setting according to claim 15, wherein the reception control section returns the communication device to a quarantine-connection setting when the communication device is disconnected from the main network.
  • 20. The network for qualification screening/setting according to claim 15, wherein, when the communication device is quarantine-connected to the network for qualification screening/setting without being loaded with a tool for qualification screening, the reception control section guides Web access from the communication device to a download site of the tool for qualification screening, and the communication device downloads and installs the tool for qualification screening from the download site.
  • 21. The network for qualification screening/setting according to claim 20, wherein, in the event that a new tool for qualification screening exists on the download site when the communication device is quarantine-connected to the reception control section, the communication device downloads and executes the new tool for qualification screening.
  • 22. The network for qualification screening/setting according to claim 20, wherein the tool for qualification screening causes the communication device to confirm existence of updated information on the download site when connecting to the network itself, and causes the communication device to download the updated information if such information exists.
  • 23. The network for qualification screening/setting according to claim 15, wherein the reception control section causes all communication devices to connect to the network itself when events regarding the main network match requirements set in advance from the outside.
  • 24. The network for qualification screening/setting according to claim 20, wherein the communication device is a communication device which may be loaded with the tool.
  • 25. The network for qualification screening/setting according to claim 15, wherein the reception control section confirms the type of communication device when such device is incapable of being loaded with the tool for qualification screening, and sets information at the communication device according to confirmation results.
  • 26. The network for qualification screening/setting according to claim 25, wherein the information to be set at the communication device is information for enabling the communication device to operate on the main network.
  • 27. The network for qualification screening/setting according to claim 15, wherein the main network is at least either a VLAN (Virtual LAN [Local Area Network]) or a VPN (Virtual Private Network).
  • 28. The network for qualification screening/setting according to claim 27, wherein the network itself is at least either a VLAN (Virtual LAN [Local Area Network]) or a VPN (Virtual Private Network).
  • 29. A communication device that requests connection to a main network in a communication system comprising the main network which provides various services, a network for qualification screening/setting provided independently from the main network, and a reception control section connected to the main network and the network for qualification screening/setting, wherein the device itself is quarantine-connected via the network for qualification screening/setting to the reception control section in order to perform qualification screening on whether the device itself satisfies preset qualification requirements, and when it is determined that the qualification requirements are satisfied, the network to which the device itself is connected will be connected to the main network.
  • 30. A communication device that requests connection to a plurality of main networks in a communication system comprising the main networks which provide various services, a network for qualification screening/setting provided independently from the main networks, and a reception control section connected to the main networks and the network for qualification screening/setting, wherein the device itself is quarantine-connected via the network for qualification screening/setting to the reception control section in order to perform qualification screening on whether the device itself satisfies preset qualification requirements, and when it is determined that the qualification requirements are satisfied, the network to which the device itself is connected will be selectively connected to one of the plurality of main networks according to the qualification requirements.
  • 31. The communication device according to claim 29, wherein, in a state of quarantine-connection to the reception control section via the network for qualification screening/setting, key information for verifying, using an electronic signature function, whether information to be acquired from the main network is proper information, is provided in advance from the reception control section.
  • 32. The communication device according to claim 29, wherein the device itself provides in advance the reception control section with key information for verifying, using an electronic signature function, whether information to be transmitted from the device itself to the main network is proper information.
  • 33. The communication device according to claim 29, wherein the device itself confirms connection destination in the network for qualification screening/setting when connection to the network for qualification screening/setting connection is detected, triggered by connection of the device itself to the network for qualification screening/setting connection, and performs automatic discovery configuration of required information to the reception control section of the confirmed connection destination.
  • 34. The communication device according to claim 29, wherein, when the device itself connects to the network for qualification screening/setting without being loaded with a tool for qualification screening, Web access from the device itself is guided by the reception control section to a download site of the tool for qualification screening, and the device itself downloads and installs the tool for qualification screening from the download site.
  • 35. The communication system according to claim 34, wherein, in the event that a new tool for qualification screening exists on the download site when connecting to the network for qualification screening/setting, the device itself downloads and executes the new tool for qualification screening.
  • 36. The communication device according to claim 34, wherein the tool for qualification screening confirms existence of updated information on the download site when the device itself connects to the network for qualification screening/setting, and downloads the updated information if such information exists.
  • 37. The communication device according to claim 34, wherein the device itself is a device which may be loaded with the tool.
  • 38. The communication device according to claim 29, wherein, in the event that the device itself is incapable of being loaded with the tool for qualification screening, the reception control section confirms the type of the device itself and sets information at the device itself according to confirmation results.
  • 39. The communication device according to claim 38, wherein the information to be set at the device itself is information for enabling the device itself to operate on the main network.
  • 40. The communication device according to claim 29, wherein the main network and the network for qualification screening/setting are respectively at least either a VLAN (Virtual LAN [Local Area Network]) or a VPN (Virtual Private Network).
  • 41. A network connection method used in a communication system which includes a main network which provides various services, a network for qualification screening/setting provided independently from the main network, a reception control section connected to the main network and the network for qualification screening/setting, the method comprising the steps of: performing quarantine connection of a communication device to the reception control section via the network for qualification screening/setting when the communication device requests connection to the main network;having the reception control section acquire status information of the quarantine-connected communication device to perform qualification screening in order to determine whether the status satisfies preset qualification requirements; andconnecting the network, to which the communication device is connected, to the main network when it is determined that the qualification requirements are satisfied.
  • 42. A network connection method used in a communication system which includes a plurality of main networks which provide various services, a network for qualification screening/setting provided independently from the main networks, a reception control section connected to the main networks and the network for qualification screening/setting, the method comprising the steps of: performing quarantine connection of a communication device to the reception control section via the network for qualification screening/setting when the communication device requests connection to the main network;having the reception control section acquire status information of the quarantine-connected communication device to perform qualification screening in order to determine whether the status satisfies preset qualification requirements; andselectively connecting the network, to which the communication device is connected, to one of the main networks according to the qualification requirements when it is determined that the qualification requirements are satisfied.
  • 43. The network connection method according to claim 41, wherein the reception control section provides in advance the quarantine-connected communication device with key information for verifying, using an electronic signature function, whether information to be acquired from the main network is proper information.
  • 44. The network connection method according to claim 41, wherein the communication device provides in advance the quarantine-connected reception control section with key information for verifying, using an electronic signature function, whether information to be transmitted from the device itself to the main network is proper information.
  • 45. The network connection method according to claim 41, wherein the communication device confirms connection destination in the network for qualification screening/setting when connection to the network for qualification screening/setting connection is detected, triggered by connection of the device itself to the network for qualification screening/setting connection, and performs automatic discovery configuration of required information to the reception control section of the confirmed connection destination.
  • 46. The network connection method according to claim 41, wherein the reception control section returns the communication device to a quarantine-connection setting when the communication device is disconnected from the main network.
  • 47. The network connection method according to claim 41, wherein, when the communication device connects to the network for qualification screening/setting without being loaded with a tool for qualification screening, the reception control section guides Web access from the communication device to a download site of the tool for qualification screening, and the communication device downloads and installs the tool for qualification screening from the download site.
  • 48. The network connection method according to claim 47, wherein, in the event that a new tool for qualification screening exists on the download site when connecting to the network for qualification screening/setting, the communication device downloads and executes the new tool for qualification screening.
  • 49. The network connection method according to claim 47, wherein the tool for qualification screening confirms existence of updated information on the download site when the communication device connects to the network for qualification screening/setting, and downloads the updated information if such information exists.
  • 50. The network connection method according to claim 41, wherein the reception control section connects all communication devices to the network for qualification screening/setting when events regarding the main network match requirements set in advance from the outside.
  • 51. The network connection method according to claim 41, wherein the communication device is a communication device which may be loaded with the tool.
  • 52. The network connection method according to claim 41, wherein the reception control section confirms the type of communication device when such device is incapable of being loaded with the tool for qualification screening, and sets information at the communication device according to confirmation results.
  • 53. The network connection method according to claim 52, wherein the information to be set at the communication device is information for enabling the communication device to operate on the main network.
  • 54. The network connection method according to claim 41, wherein the main network and the network for qualification screening/setting are respectively at least either a VLAN (Virtual LAN [Local Area Network]) or a VPN (Virtual Private Network).
  • 55. A program for a network connection method, used in a communication system which includes a main network which provides various services, a network for qualification screening/setting provided independently from the main network, a reception control section connected to the main network and the network for qualification screening/setting, the program comprising: performing quarantine connection of a communication device to the reception control section via the network for qualification screening/setting when the communication device requests connection to the main network; andhaving a computer of the reception control section acquire status information of the quarantine-connected communication device to perform qualification screening in order to determine whether the status satisfies preset qualification requirements, and connect the network, to which the communication device is connected, to the main network when it is determined that the qualification requirements are satisfied.
  • 56. A program for a network connection method, used in a communication system which includes a plurality of main networks which provide various services, a network for qualification screening/setting provided independently from the main networks, a reception control section connected to the main networks and the network for qualification screening/setting, the program comprising: performing quarantine connection of a communication device to the reception control section via the network for qualification screening/setting when the communication device requests connection to the main networks; andhaving a computer of the reception control section acquire status information of the quarantine-connected communication device to perform qualification screening in order to determine whether the status satisfies preset qualification requirements, and selectively connect the network, to which the communication device is connected, to one of the main networks according to the qualification requirements when it is determined that the qualification requirements are satisfied.
  • 57. A qualification screening tool program, used in a communication system which includes a main network which provides various services, a network for qualification screening/setting provided independently from the main network, and a reception control section connected to the main network and the network for qualification screening/setting in order to perform qualification screening on whether a communication device requesting connection to the main network satisfies preset qualification requirements, wherein the qualification screening tool program causes a computer of the communication device to perform the processing of: confirming a link status when the communication device is quarantine-connected to the reception control section via the network for qualification screening/setting; confirming the network for qualification screening/setting; and acquiring qualification screening information for qualification screening from the communication device and transmitting the information to the reception control section.
  • 58. The qualification screening tool program according to claim 57, which causes a computer of the communication device, when the computer is connected to the network for qualification screening/setting, to confirm existence of updated information on the download site and download the updated information if such information exists.
Priority Claims (1)
Number Date Country Kind
2006-015749 Jan 2006 JP national