AU779137B2

Systems and methods for providing dynamic network authorization, authentication and accounting

Abstract

This record has no abstract on file.

AU779137B2, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Expired 20 October 2020, 5.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

9 claims: 1 independent, 8 dependent

  1. 1
    THE CLAIMS DEFINING THE INVENTION ARE AS FOLLOWS:1. A method for selectably controlling and customizing source access to a network, wherein the source is associated with a source computer having access to a network via a 5 gateway device, characterized in that the method comprises the steps of: receiving at the gateway device a request from the source computer for access to the network;identifying an attribute associated with the source based upon a packet transmitted from the source computer and received by the gateway device;10 accessing a source profile corresponding to the source and stored in a source profile database, wherein the source profile is accessed based upon the attribute, and wherein the source profile database is located external to the gateway device and in communication with the gateway device;and determining the access rights of the source based upon the source profile, wherein 15 access rights define the rights of the source to access the networks;wherein the source computer has transparent access to the network via the gateway device such that the packet transmitted from the source computer remains unaltered by said gateway device, and wherein no configuration software need be installed on the source computer to access the network.
  2. 9
    10. A system for selectably controlling and customizing access, to a network, by a source, where the source is associated with a source computer and accesses the network via 25 a gateway device, characterized in that the system comprises:a gateway device, wherein the gateway device receives a request from the source for access to the network;a source profile database in communication with the gateway device and located external to the gateway device, wherein the source profile database stores access 30 information identifiable by an attribute associated with the source, and wherein the POPER\RAB\12243-Olrapoo>e-doc-04/11ΛΜ P \OPER\RABM22<)X)lr«panjeda-O4/l 1XM -2516. The system of claim 10, wherein the source profile database is located within the AAA server. • · *· 17. A method for redirecting a source attempting to access a destination through a 5 gateway device, wherein source is associated with a source computer, characterized in that the method comprises the steps of: receiving at the gateway device a request from the source to access the network;identifying the source based upon an attribute associated with the source;accessing a source profile database located external to the gateway device, the 10 source profile database storing access rights of the source;determining the access rights of the source based upon the identification of the source, wherein the access rights define the rights of the source to access destination sites via the network;wherein the source computer has transparent access to the network via the gateway 15 device such that packets transmitted from the source computer remain unaltered by said gateway device, and wherein no configuration software need be installed on the source computer to access the network. 18. The method of claim 17, wherein accessing a source profile database comprises • · ...... 20 accessing a source profile database comprising a remote authentication dial-in user service (RADIUS). 19. The method of claim 17, wherein accessing a source profile database comprises accessing a source profile database comprising a lightweight directory access protocol 25 (LDAP) database. 20. The method of claim 17, further comprising assigning a location identifier to the location from which requests for access to the network are transmitted, and wherein the location identifier is the attribute associated with the source. P:\OPER\RAB\l224W31rapcnje doc-04/l I AM -2621. The method of claim 17, further comprising updating the source profile database when a new source accesses the network. 22. The method of claim 17, further comprising maintaining in an accounting database 5 a historical log of the source's access to the network, wherein the accounting database is in communication with the source profile database. 23. The method of claim 17, wherein receiving at the gateway device a request from a source for access comprises the step of receiving a destination address from the source. 24. The method of claim 19, wherein determining if the source computer is entitled to • · · ϊ ·* access the destination address further comprises denying the source computer access where ···· • •ji the source profile indicates that the source computer is denied access. • · · • · · • · • · · • · · *· · 15 25. The method of claim 17, wherein determining if the source is entitled to access the network further comprises directing the source to a login page when the source profile is . not located within the source profile database. ·«·· 26. A system for enabling communication between a computer and a service provider 20 network, characterized in that the system comprises: a computer;a network gateway device in communication with the computer for connecting the computer to a computer network, wherein the network gateway device receives source data that represents a user attempting to access the computer network;and 25 a service provider network in communication with the network gateway device, comprising an authentication server located external to the network gateway device and in communication with the network gateway device and having therein a source profile database comprising source profiles that represent users authorized to access 30 the computer network, wherein the authentication server compares the source data P \OPER\RAB\1 2243-Olraponje doc-04/l ΙΛΜ -27to the source profiles to determine if the user attempting to access the computer network can access the computer network, wherein the computer has transparent access to the network via the network gateway device such that packets transmitted from the computer remain unaltered by said 5 network gateway device, and wherein no configuration software need be installed on the source computer to access the network. 27. The system of claim 26, further comprising an accounting system for maintaining historical data concerning use of the service provider network. 28. The system of claim 26, wherein the authentication server comprises a remote J ·' authentication dial-in user service (RADIUS). • · ·· • · · · • · · • · · ··. *· 29. The system of claim 26, wherein the authentication server comprises a lightweight • · · *· *· 15 directory access protocol (LDAP) database. 30. The system of claim 26, wherein the source profile database includes a plurality of source profiles, wherein each respective source profile of the plurality of source profiles contains access information. 31. The system of claim 26, wherein the source data comprises an attribute associated with the computer and transmitted from the computer to the gateway device. 32. The system of claim 26, wherein the source data comprises login information 25 associated with a respective user. 33. A system for selectably controlling and customizing access, to a network, substantially as hereinbefore described with reference to the accompanying drawings. 30 34. A method for selectably controlling and customizing access, to a network, substantially as hereinbefore described with reference to the accompanying drawings. P:\OPER\RABM 220-0lrapoo«.ctoc-04/l I KM -2835. A method for redirecting a source attempting to access a destination through a gateway device, substantially as hereinbefore described with reference to the accompanying drawings. 36. A system for enabling communication between a computer and a service provider network, substantially as hereinbefore described with reference to the accompanying drawings. **·* 9999 99 9 • · * 9 9 9