1. An asset management system for managing a network asset communicably connectable to a computer network, said asset management system comprising:
storage means for storing management information of the network asset communicably connectable to the computer network, including network asset identifying information identifying the network asset and computer network node identifying information of the network asset identifying the network asset on the computer network to which the network asset is communicably connected;
determining means for determining sender and destination network address of information circulating over the computer network and for determining whether said information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being managed;
gathering means for gathering network asset management information, including network asset identifying information identifying the network asset being managed and computer network node identifying information of the network asset based upon the information circulating over the computer network, when determined by said determining means that the information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being managed; and
updating means for comparing the gathered network asset management information with the stored network asset management information and when the gathered network asset management information and the stored network asset management information are not same, updating the stored network asset management information with the gathered network asset management information.
2. An asset management system according to claim 1, wherein said management information includes information on a software asset executed by the asset.
3. An asset management system according to claim 1, wherein said management information includes information on a hardware asset constituting the asset.
4. An asset management system according to claim 2, wherein said management information includes information on a hardware asset constituting the asset.
5. An asset management system according to claim 1, wherein said management information includes information on classification as to whether the asset is a leased asset or not and, if it is, information on a lease expiration date of the asset, further comprising;
means for comparing a current date and the lease expiration date of the asset, and
means for providing a notification that the lease has expired when it is detected that the lease has expired as a result of the comparison by the comparing means.
6. An asset management system according to claim 2, wherein said management information includes information on classification as to whether the asset is a leased asset or not and information on a lease expiration date of the asset, further comprising:
means for comparing a current date and the lease expiration date of the asset, and
means for providing a notification that the lease has expired when it is detected that the lease has expired as a result of the comparison by the comparing means.
7. An asset management system according to claim 3, wherein said management information includes information on classification as to whether the asset is a leased asset or not and if it is, information on a lease expiration date of the asset, further comprising:
means for comparing a current date and the lease expiration date of the asset, and
means for providing a notification that the lease has expired when it is detected that the lease has expired as a result of the comparison by the comparing means.
8. An asset management system according to claim 4, wherein said management information includes information on classification as to whether the asset is a leased asset or not and information on a lease expiration date of the asset, further comprising:
means for comparing a current date and the lease expiration date of the asset, and
means for providing a notification that the lease has expired when it is detected that the lease has expired as a result of the comparison by the comparing means.
9. An asset management system according to claim 1, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
10. An asset management system according to claim 2, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
11. An asset management system according to claim 3, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
12. An asset management system according to claim 4, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
13. An asset management system according to claim 5, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
14. An asset management system according to claim 6, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
15. An asset management system according to claim 7, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
16. An asset management system according to claim 8, wherein said management information includes information on an amount of stock, a lower limit of amount of stock and an amount of replenishment at one time of a consumable item consumed by the asset, said gathering means is provided with means for gathering information on the asset being out of a consumable item, and said updating means is provided with: means for, when it is detected that the asset is out of a consumable item, determining whether the amount of stock becomes less than the lower limit after replenishment of the consumable item or not; and means for providing a notification that the consumable item is short of stock when the amount of stock becomes less than the lower limit.
17. The asset management system according to claim 1, further comprising:
an asset management client connected at a position through which information circulating via the computer network passes; and
means for detecting that an asset not being managed is connected to the network and activating an alarm notification upon such detection.
18. An asset management system according to claim 1, further comprising:
a communication log of each section storing data items including sender and destination addresses of information circulating over the network; and
means for detecting whether the addresses are those of an asset being managed and when an asset not being managed is detected alerting an administrator.
19. An asset management system according to claim 18, further comprising:
means for determining whether an asset has been transferred, automatically updating the contents of the asset registration and producing an alarm notification when the contents of the registration of the asset manager register master have been automatically updated.
20. An asset management system according to claim 1, further comprising:
a softwarehardware log connected at a position through which information circulating via the network passes; and
means for analyzing the log and automatically updating the content of the asset management register using the log.
21. An asset management system according to claim 1, further comprising:
a section asset master storing asset licenses; and
means for checking the licenses when it is determined that the software asset is one being managed.
22. An asset management system for managing a network asset communicably connectable to a computer network, said asset management system comprising:
a storage medium storing management information of the network asset communicably connectable to the computer network, including network asset information identifying the network asset and computer network node identifying information of the network asset to identify the network asset on a computer network to which the network asset is communicably connected;
a controller in communication with said storage medium, and performing processes comprising:
(i) determining sender and destination network address of information circulating over the computer network and determining whether said information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being managed;
(ii) gathering network asset management information, including network asset identifying information identifying the network asset being managed and computer network node identifying information of the network asset, based upon the information circulating over the computer network, when determined by said determining that the information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being manage; and
(iii) comparing the gathered network asset management information with the stored network asset management information and when the gathered network asset management information and the stored network asset management information are not same, updating the stored network asset management information with the gathered network asset management information.
23. An asset management system in which clients of network sections and a server are in communication by a computer network, the system comprising:
an asset management client in each network section to gather network asset management information of network assets communicably connectable to and belonging to each corresponding network section and
an asset management server in communication with each asset management client by the computer network to analyze the network asset management information gathered by each asset management client of each network section and to manage network assets of all the network sections wherein:
said asset management server comprises a storage medium for storing a master file registering network asset management information of the network assets, said network asset management information including network section identifying information identifying each network section, network asset identifying information identifying the network asset belonging to each network section and network section node identifying information identifying a connection node capable of connecting the asset at each section to the the network asset on the network section to which the network asset belongs,
said asset management client comprises a storage medium for storing, based upon sender and destination network address of information circulating over the computer network, in association with network section information identifying a belonging network section of said network asset management client, network asset management information of the network asset including network asset identifying information identifying the network asset belonging to the network section of said asset management client and network section node identifying information identifying the network asset on the network section to which the network asset belongs,
said asset management client further comprises a controller to perform a process comprising:
gathering, from the information circulating over the computer network, the network asset management information of each network asset belonging to each network section of each asset management client, network asset management information including information identifying the network asset, being managed, of the network section of said asset management client and network section node identifying information identifying a the network asset on the network section to which the network asset belongs, when determined that the information circulating over the computer network is information sent from the network asset, being managed, of the network section of said asset management client or information addressed to the network asset,
said asset management server further comprises a controller to perform a process comprising:
comparing the network asset management information of each network asset belonging to each network section gathered by the asset management client of each network section with the master file network asset management information, and
when the gathered network asset management information and the master file network asset management information are not same according to the comparing, updating the master file network asset management information with the gathered management information.
24. An asset management system for managing a network asset communicably connectable to a computer network, said asset management system comprising:
a storage unit to store management information of the network asset communicably connectable to the computer network, including network asset identifying information identifying the network asset and computer network node identifying information to identify the network asset on the computer network to which the network asset is communicably connected;
a determining unit sender and destination network address of information circulating over the computer network and for determining whether said information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being managed;
a gathering unit gathering network asset management information, including network asset identifying information identifying the network asset being managed and computer network node identifying information identifying of the network asset, based upon the information circulating over the computer network, when determined by said determining that the information circulating over the computer network is information sent from the network asset being managed or information addressed to the network asset being managed; and
an updating unit to compare the gathered network asset management information with the stored network asset management information and to update the stored network asset management information according to the comparison.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.
1. A computing method, comprising:
running on a user computer a first operating environment for performing general-purpose operations and a second operating environment, which is configured exclusively for interacting with multiple servers in respective secure communication sessions and is separate from the first operating environment, wherein the second operating environment is isolated from the first operating environment and the first operating environment does not interact with the multiple servers in the secure communication sessions, the first operating environment including an operating system and second operating environment including an operating system separate from the operating system of the first operating environment, wherein in the protected communication session the second operating environment exchanges transaction data with a server via a security protocol, wherein general-purpose operations performed in the first operating environment do not affect operation of the second operating environment, and wherein running the second operating environment comprises verifying a trustworthiness of the second operating environment by communication between the second operating environment and a Central Management System (CMS) that is external to the user computer;
storing in the second operating environment multiple different server-specific credentials, each corresponding to one of the multiple servers, for authenticating a user of the user computer to each respective server, and a single set of master credentials for authenticating the user to the second operating environment; and
establishing a secure communication session between the user computer and at least one of the multiple servers under control of a program running in the second operating environment, by authenticating the user to the second operating environment using the master credentials and, responsively to successfully authenticating the user in the second operating environment, automatically selecting one of the server-specific credentials in the second operating environment corresponding to the one of the multiple servers and the second operating environment authenticating the user to the one server using the selected server-specific credentials.
2. The method according to claim 1, and comprising conducting the secure communication session with the given server responsively to successfully authenticating the user computer to the given server.
3. The method according to claim 1, wherein establishing the secure communication session comprises authenticating the user to the given server using the selected server-specific credentials only upon successfully verifying the trustworthiness of the second operating environment by the CMS.
4. The method according to claim 1, wherein storing the server-specific credentials comprises providing at least one of the server-specific credentials to the CMS, and sending at least one of the server-specific credentials from the CMS to the user computer for storage in the second operating environment.
5. The method according to claim 4, wherein providing at least one of the server-specific credentials further comprises providing a security policy of at least one of the servers to the CMS, and enforcing the security policy with respect to the second operating environment by the CMS.
6. The method according to claim 1, wherein storing the server-specific credentials comprises providing at least one of the server-specific credentials to the user computer independently of the CMS.
7. The method according to claim 1, wherein the master credentials are uniquely associated with the user computer, and wherein authenticating the user using the master credentials comprises verifying that the user computer matches the master credentials.
8. The method according to claim 1, wherein storing the server-specific credentials comprises encrypting the server-specific credentials, and wherein authenticating the user to the given server using the selected server-specific credentials comprises decrypting the selected credentials.
9. The method according to claim 1, wherein storing the master credentials comprises encrypting the master credentials, and wherein authenticating the user using the master credentials comprises decrypting the master credentials.
10. The method according to claim 1, wherein storing the server-specific credentials comprises storing a self-contained data element comprising one of the server-specific credentials and a software application that is to run in the second operating environment for communicating with a respective one of the servers.
11. The method according to claim 10, wherein the self-contained data element further comprises attributes of the software application.
12. The method according to claim 10, wherein the self-contained data element comprises the master credentials, the multiple server-specific credentials and respective multiple software applications for communicating with the servers.
13. The method according to claim 1, wherein establishing the secure communication session comprises, in response to successfully authenticating the user to the given server, causing a packet filter of the given server to allow packets arriving from the user computer to reach the given server.
14. A user computer, comprising:
an network interface device, which is operative to communicate with multiple servers over a communication network; and
a hardware processor, which is coupled to run a first operating environment, which is configured to perform general-purpose operations, and a second operating environment, which is configured exclusively for interacting with the multiple servers in respective protected communication sessions and is separate from the first operating environment,
wherein the second operating environment is isolated from the first operating environment and the first operating environment does not interact with the multiple servers in the secure communication sessions, the first operating environment including an operating system and second operating environment including an operating system separate from the operating system of the first operating environment,
wherein in the protected communication session the second operating environment exchanges transaction data with a server via a security protocol,
wherein general-purpose operations performed in the first operating environment do not affect operation of the second operating environment, and
wherein running the second operating environment comprises verifying a trustworthiness of the second operating environment by communication between the second operating environment and a Central Management System (CMS) that is external to the user computer,
the hardware processor configured to store in the second operating environment multiple different server-specific credentials, each corresponding to one of the multiple servers, for authenticating a user of the user computer to each respective server and a single set of master credentials for authenticating the user to the second operating environment, and
the hardware processor configured to establish a secure communication session between the user computer and at least one of the multiple servers under control of a program running in the second operating environment, by authenticating the user to the second operating environment using the master credentials and, responsively to successfully authenticating the user in the second operating environment, automatically selecting, one of the server-specific credentials in the second operating environment corresponding to the one of the multiple servers and the second operating environment authenticating the user to the one server using the selected server-specific credentials.
15. The user computer according to claim 14, wherein the processor is coupled to conduct the secure communication session with the given server responsively to successfully authenticating the user computer to the given server.
16. The user computer according to claim 14, wherein the processor is coupled to authenticate the user to the given server using the selected server-specific credentials only when the trustworthiness of the second operating environment is successfully verified by the CMS.
17. The user computer according to claim 14, wherein the processor is coupled to receive at least one of the server-specific credentials from the CMS, and to store received at least one of the server-specific credentials in the second operating environment.
18. The user computer according to claim 14, wherein the processor is coupled to store at least one of the server-specific credentials independently of the CMS.
19. The user computer according to claim 14, wherein the master credentials are uniquely associated with the user computer, and wherein the processor is coupled to authenticate the user using the master credentials by verifying that the user computer matches the master credentials.
20. The user computer according to claim 14, wherein the processor is coupled to encrypt the stored server-specific credentials, and to decrypt the selected credentials so as to authenticate the user to the given server.
21. The user computer according to claim 14, wherein the processor is coupled to encrypt the stored master credentials, and to decrypt the master credentials so as to authenticate the user.
22. The user computer according to claim 14, wherein the processor is coupled to store a self-contained data element comprising one of the server-specific credentials and a software application that is to run in the second operating environment for communicating with a respective one of the servers.
23. The user computer according to claim 22, wherein the self-contained data element further comprises attributes of the software application.
24. The user computer according to claim 22, wherein the self-contained data element comprises the master credentials, the multiple server-specific credentials and respective multiple software applications for communicating with the servers.
25. A computer software product for use in a user computer, the computer software product comprising a non-transitory computer-readable storage medium, storing executable instructions, which instructions, when executed by the user computer, cause the user computer to perform operations including,
communicating with multiple servers over a communication network, to run a first operating environment for performing general-purpose operations and a second operating environment, which is configured exclusively for interacting with the multiple servers in respective secure communication sessions and is separate from the first operating environment,
wherein where the second operating environment is isolated from the first operating environment and the first operating environment does not interact with the multiple servers in the secure communication sessions, the first operating environment including an operating system and second operating environment including an operating system separate from the operating system of the first operating environment,
wherein in the protected communication session the second operating environment exchanges transaction data with a server via a security protocol,
wherein general-purpose operations performed in the first operating environment do not affect operation of the second operating environment, and
wherein running the second operating environment comprises verifying a trustworthiness of the second operating environment by communication between the second operating environment and a Central Management System (CMS) that is external to the user computer,
storing in the second operating environment multiple different server-specific credentials, each corresponding to one of the multiple servers, for authenticating a user of the user computer to each respective server and a single set of master credentials for authenticating the user to the second operating environment, and
establishing a secure communication session between the user computer and at least one of the multiple servers under control of a program running in the second operating environment, by authenticating the user to the second operating environment using the master credentials and, responsively to successfully authenticating the user in the second operating environment, automatically selecting one of the server-specific credentials in the second operating environment corresponding to the one of the multiple servers and the second operating environment authenticating the user to the one server using the selected server-specific credentials.