CA2388628C

Systems and methods for providing dynamic network authorization, authentication and accounting

Abstract

Systems and methods for selectably controlling and customizing source access to a network, where the source isassociated with a source computer, which has transparent access to the network via a gateway device and no configuration softwareneed be installed on the source computer to access the network. A user may be prevented access from a particular destination orsite based upon the user's authorization while being permitted to access to other sites. The method and system can identify a sourcewithout that source's knowledge, and can access customizable access rights corresponding to that source in a source profile database,which can be a remote authentication dial-in user service (RADIUS) or a lightweight directory access protocol (LDAP) database.Source profiles are used within the source profile database to dynamically authorize source access to networks and destination vianetworks. The gateway device includes the ability to recognize computer attempting to access a network, their location, the identityof users, etc.

CA2388628C, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Expired 20 October 2020, 5.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

31 claims: 4 independent, 27 dependent

  1. 1
    CA 02388628 2009-04-15 THE EMBODIMENTS OF THE INVENTION IN WHICH AN EXCLUSIVE PROPERTY OR PRIVILEGE IS CLAIMED ARE DEFINED AS FOLLOWS:1. A method for controlling access to a network, comprising: receiving at a gateway device (12) a request from a source computer (14) for access to a computer network (20);enabling, via the gateway device (12), the source computer (14) to access the computer network (20) regardless of a network configuration of the source computer (14) and no configuration software need be installed on the source computer (14) to access the computer network (20);identifying an attribute associated with the source computer (14) based upon a packet transmitted from the source computer (14) and received by the gateway device (12);accessing a source profile corresponding to the source computer (14) and stored in a source profile database, wherein the source profile is accessed based upon the attribute, and wherein the source profile database is in communication with the gateway device (12);and determining access rights of the source computer (14) based upon the source profile, wherein the access rights define rights of the source computer (14) to access a requested network destination on the computer network (14).
  2. 9
    A system for controlling access to a network comprising:a gateway device (12), wherein the gateway device (12) receives a request from a_source computer (14) for access to a computer network (20);a source profile database in communication with the gateway device (12), wherein the source profile database stores access information identifiable by an attribute associated with the source computer (14), and wherein the attribute is identified based upon a data packet transmitted from the source computer (14) and received by the gateway device (12);and an Authentication, Authorization and Accounting, AAA, server (30) in communication with the gateway device (12) and the source profile database, wherein the AAA server (30) determines if the source computer (14) is entitled to access the computer network (20) based upon the access information stored within the source profile database, and wherein the AAA server (30) determines access rights of the source computer (14), wherein the access rights define rights of the source computer (14) to access destination sites via the computer network (20) wherein the source computer (14) is enabled to have access to the computer network (20), via the gateway device (12), regardless of a network configuration of the source computer (14) and no configuration software need be installed on the source computer (14) to access the computer network (20).
  3. 16
    A method for redirecting a source attempting to access a destination, comprising:receiving at a gateway device (12) a request from a source computer (14) to access a computer network (20);enabling, via the gateway device (12), the source computer (14) to access the computer network (20) regardless of a network configuration of the source computer (14) and no configuration software need be installed on the source computer (14) to access the computer network (20);identifying the source computer (14) based upon an attribute associated with the source computer (14);accessing a source profile database that stores access rights of the source computer (14);and determining the access rights of the source computer (14) based upon the identification of the source computer (14), wherein the access rights define rights of the source computer (14) to access destination sites via the computer network (20). CA 02388628 2009-04-15
  4. 25
    A system for enabling communication between a computer and a service provider network, comprising:a source computer (14);a network gateway device (12) in communication with the source computer (14) for connecting the source computer (14) to a computer network (20), wherein the network gateway device (12) receives source data that represents a user attempting to access the computer network (20);and a service provider network in communication with the network gateway device (12), comprising: an authentication server in communication with the network gateway device (12) and having therein a source profile database comprising source profiles that represent users authorized to access the computer network (20), wherein the authentication server compares the source data to the source profiles to determine if the user attempting to access the computer network (20) can access the computer network (20), wherein the source computer (14) is enabled to have access to the computer network (20) via the network gateway device (12), regardless of a network configuration of the source computer (14) and no configuration software need be installed on the source computer (14) to access the network (20).