CA2725720C

Systems and methods for providing dynamic network authorization, authentication and accounting

Abstract

Systems and methods for selectably controlling and customizing source access to a network, where the source is associated with a source computer, and wherein the source computer has transparent access to the network via a gateway device and no configuration software need be installed on the source computer to access the network. A user may be prevented access from a particular destination or site based upon the user's authorization while being permitted to access to other sites. The method and system can identify a source without that source's knowledge, and can access customizable access rights corresponding to that source in a source profile database which can be a remote authentication dial-in user service (RADIUS) or a lightweight directory access protocol (LDAP) database. Source profiles are used within the source profile database to dynamically authorize source access to networks and destination via networks. The gateway device includes the ability to recognize computer attempting to access a network, their location, the identity of users, etc.

CA2725720C, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 20 October 2020, 5.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

179 claims: 19 independent, 160 dependent

  1. 1
    CA 02725720 2016-03-22 The embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows:1. A method for controlling access to a network, comprising: receiving at a gateway device a packet comprising a request from a source computer for access to a computer network;identifying an attribute associated with the source computer based upon the packet;and determining access rights of the source computer based at least upon the identified attribute and further based upon data stored in a source profile database in communication with the gateway device, wherein the access rights define rights of the source computer to access the computer network, the access rights being determined without requiring interactive steps by a computer user.
  2. 11
    A system for controlling access to a network, comprising:a network management device configured to receive a packet comprising a request from a source computer for access to a computer network;the network management device further configured to identify an attribute associated with the source computer based upon the packet;and the network management device further configured to determine access rights of the source computer based at least upon the identified attribute and further based upon data stored in a source profile database in communication with the network management device, wherein the access rights define rights of the source computer to access the computer network, the access rights being determined without requiring interactive steps by a computer user.
  3. 21
    A method, executed at a network management system, of providing authenticated network access to a client computer in communication with the network management system wherein the client computer transmits to the network management system a packet, the method comprising:receiving, at the network management system, a request from the client computer to access a network content;determining the client computer's authorization rights using at least a portion of the request identifying the client computer, by accessing a user profile stored in a user profile database, wherein the user profile associates said portion of the request with the authorization rights;-23CA 02725720 2016-03-22 determining, based on the authorization rights, whether to allow the client computer to access the requested content or to redirect the client computer to network content different from the requested network content;and sending, to the client computer, a client computer response based on the determination of whether to allow the client computer to access the requested network content or to redirect the client computer to network content different from the requested network content.
  4. 28
    A system configured to provide network access to a client computer in communication with the system, wherein the client computer transmits to the system a packet, the system comprising:a communications port configured to receive a request from the client computer to access a network content;and a processor further configured to determine the client computer's authorization rights using a portion of the request identifying the client computer, by accessing a -24CA 02725720 2016-03-22 user profile stored in a user profile database, wherein the user profile associates said portion of the data with the authorization rights;the processor further configured to determine, based on the authorization rights, whether to allow the client computer to access the requested network content or to redirect the client computer to network content different from the requested network content;and the processor further configured to send, to the client computer, a client computer response based on the determination of whether to allow the client computer to access the requested network content or to redirect the client computer to network content different from the requested network content.
  5. 35
    A computer-implemented method to provide network access to a client computer, wherein the client computer generates a packet, the computer-implemented method comprising:-25CA 02725720 2016-03-22 receiving a- connection request for an external server from the client computer;determining the client computer's authorization rights based in part on the connection request, by accessing a user profile stored in a user profile database, wherein the user profile associates at least a portion of the connection request with the authorization rights;determining, based on the authorization rights, whether to provide the client computer with access to the external server or to redirect to an authentication system;and sending, to the client computer, a client computer response based on the said determination of authentication rights.
  6. 41
    A method for selectably controlling and customizing source access to a network, wherein the source is associated with a source computer having access to a network via a gateway device, characterized in that the method comprises the steps of:receiving at the gateway device a request from the source computer for access to the network;identifying an attribute associated with the source based upon a packet transmitted from the source computer and received by the gateway device;and -26CA 02725720 2016-03-22 accessing a source profile corresponding to the source and stored in a source profile database, wherein the source profile is accessed based upon the attribute, and wherein the source profile database is located external to the gateway device and in communication with the gateway device, wherein the source computer has transparent access to the network via the gateway device such that the packet transmitted from the source computer remains unaltered by said gateway device, and wherein no configuration software need be installed on the source computer to access the network,
  7. 50
    A system for selectably controlling and customizing access, to a network, by a source, where the source is associated with a source computer and accesses the network via a gateway device, characterized in that the system comprises;a gateway device, wherein the gateway device receives a request from the source for access to the network;a source profile database in communication with the gateway device and located external to the gateway device, wherein the source profile database stores access information identifiable by an attribute associated with the source, and wherein the attribute is identified based upon a data packet transmitted from the source computer and received by the gateway device;and an Authentication, Authorization and Accounting, AAA, server in communication with the gateway device and source profile database, wherein the AAA server determines if the source is entitled to access the network based upon the access information stored within the source profile database, and wherein the AAA server determines the access rights of the source, wherein access rights define the rights of the source to access destination sites via the network, wherein the source computer has transparent access to the network via the gateway device such that the data packet transmitted from the source computer remains unaltered by said gateway device, and wherein no configuration software need be installed on the source computer to access the network.
  8. 54
    The system of clai m 50, wherein the source profile database includes a plurality of source profiles, wherein each respective source profile of the plurality of source profiles contains access information.
  9. 57
    A method for redirecting a source attempting to access a destination through a gateway device, wherein source is associated with a source computer, characterized in that the method comprises the steps of:receiving at the gateway device a request from the source to access the network;identifying the source based upon an attribute associated with the source;accessing a source profile database located external to the gateway device, the source profile database storing access rights of the source;and determining the access rights of the source based upon the identification of the source, wherein the access rights define the rights of the source to access destination sites via the network, wherein the source computer has transparent access to the network via the gateway device such that packets transmitted from the source computer remain unaltered by said gateway device, and wherein no configuration software need be installed on the source computer to access the network.
  10. 66
    A system for enabling communication between a computer and a service provider network, characterized in that the system comprises:a computer;-30CA 02725720 2016-03-22 a network gateway device in communication with the computer for connecting the computer to a computer network, wherein the network gateway device receives source data that represents a user attempting to access the computer network;and a service provider network in communication with the network gateway device, comprising an authentication server located external to the network gateway device and in communication with the network gateway device and having therein a source profile database comprising source profiles that represent users authorized to access the computer network, wherein the authentication server compares the source data to the source profiles to determine if the user attempting to access the computer network can access the computer network, wherein the computer has transparent access to the network via the network gateway device such that packets transmitted from the computer remain unaltered by said network gateway device, and wherein no configuration software need be installed on the source computer to access the network.
  11. 73
    A method of authorizing a portable communication device to access a network resource, the method being performed at a network management system in communication with the portable communication device via a network, the method comprising:receiving, from a portable communication device via a network, a request to access a network resource;determining, on a processor, whether the portable communication device is authorized to access the requested network resource, the determination being based on a unique identifying attribute associated with the portable communication device without the unique identifying attribute being predefined in a user profile database and without querying the portable communication device or its user for information;if the portable communication device is authorized, allowing the portable communication device to access the network resource;and if the portable communication device is not authorized, redirecting the portable communication device to an authentication system where the portable communication device is configured to submit authentication-related information wherein the portable communication device can be authorized to access the requested network resource, wherein redirecting the portable communication device comprises sending transmission control protocol handshake completion data to the portable communication device in response to the request to access the network resource, the transmission control protocol handshake completion data configured to appear to be from the network resource, wherein the network management system need not communicate with the network resource if the portable communication device is not authorized.
  12. 84
    85. A computer implemented network management system configured to authorize a portable communication device to access a network resource, the system comprising:a first network interface configured to receive, from a portable communication device via a network, a request to access a network resource;a first software module that, when implemented on one or more processors, is configured to determine whether the portable communication device is authorized to access the requested network resource, the determination being based on a unique identifying attribute associated with the portable communication device without the unique identifying attribute being predefined in a user profile database and without querying the portable communication device or its user for information;a second software module that, when implemented on one or more processors, is configured to allow the portable communication device to access the requested network resource if the portable communication device is authorized;a third software module that, when implemented on one or more processors, is configured to redirect the portable communication device to an authentication system where the portable communication device is configured to submit authenticationrelated information wherein the portable communicarion device can be authorized to access the requested network resource if the portable communication device is not authorized, the third software module configured to redirect the portable communication device by sending connection handshake completion data to the portable communication device in response to the request to access the network resource, the connection handshake completion data configured to appear to be from the network resource, wherein the network management system need not communicate with the network resource if the portable communication device is not authorized;and one or more processors configured to implement the first, second and third software modules.
  13. 85
    86. A computer implemented network management system configured to authorize a portable communication device to access a network resource, the system comprising:a first network interface configured to receive, from a portable communication device via a network, a request to access a network resource;and -34CA 02725720 2016-03-22 one or more processors configured to: determine whether the portable communication device is authorized to access the requested network resource, the determination being based on a unique identifying attribute associated with the portable communication device without the unique identifying attribute being predefined in a user profile database and without querying the portable communication device or its user for information;allow the portable communication device to access the requested network resource if the portable communication device is authorized;and redirect the portable communication device to an authentication system where the portable communication device is configured to submit authentication-related information wherein the portable communication device can be authorized to access the requested network resource if the portable communication device is not authorized, by at least sending connection handshake completion data to the portable communication device in response to the request to access the network resource, the connection handshake completion data configured to appear to be from the network resource, wherein the network management system need not communicate with the network resource if the portable communication device is not authorized.
  14. 92
    93. A method of managing access to network resources, the method being performed by a network management system in communication with a portable communication device, the method comprising:receiving, at a communications port of a wireless access point of the network management system from a portable communication device, a connection request for an exremal server, the connection request comprising one or more network packets;transmitting the connection request from the wireless access point to a controller of the network management system;determining, using the controller, whether to provide the portable communication device with access to the external server, the determination being based at least in part on comparing an attribute included in the connection request to a user profile database;and upon determining that the portable communication device is not at that time permitted with access to the external server, redirecting the portable communication device to an authentication system, the redirection including: sending transmission control protocol handshake completion data from the communications port of the wireless access point to the portable communication device in response, to the connection request, said transmission control protocol handshake completion data configured to indicate that it was sent by the external server;receiving at the controller via the wireless access point a request from the portable communication device for a network resource of the external server;receiving, at the wireless access point from the controller, the redirection data comprising resource identification data that identifies the authentication system, the -36CA 02725720 2016-03-22 redirection data configured to cause the portable communication device to be redirected to the authentication system;and sending, from the communications port of the wireless access point to the portable communication device, a browser redirect message based upon the redirection data;whereby the portable communication device provides authentication-related information wherein the portable communication system can be provided access to the network resource, wherein the network management system need not communicate with the external server to redirect the portable communication device,
  15. 96
    97. The method of'claim 93, wherein determining whether to provide the portable communication device with access to the network resource further comprises denying the portable communication device access where the user profile database indicates that the portable communication device may not access the network resource.
  16. 111
    112. A network management system configured to manage access to a network resource, the system comprising:a wireless access point configured to receive, from a portable communication device, a connection request for an external server, the connection request comprising one or more network packets;and a controller configured to receive the connection request from the wireless access point and determine whether to allow the portable communication device to access the external server, the determination being based at least in part on comparing one or more attributes included in the connection request to a user profile database;the network management system further configured to redirect the portable communication device to an authentication system, upon determining not to allow the portable communication device to access the external server at that time, the redirect including: sending transmission control protocol handshake completion data from the communications port of the wireless access point to the portable communication device in response to the connection request, said transmission control protocol handshake completion data configured to indicate that it was sent by the external server;-39CA 02725720 2016-03-22 receiving at the controller via the wireless access point a request from the portable communication device for a network resource of the external server;receiving, at the wireless access point from the controller, redirection data comprising resource identification data that identifies the authentication system, the redirection data configured to cause the portable communication device to be redirected to the authentication system;and sending, from the communications port of the wireless access point to the portable communication device, a browser redirect message based upon the redirection data;whereby the portable communication device submits authentication-related information wherein the portable communication system can be allowed to access the network resource, wherein the network management system need not communicate with the external server to redirect the portable communication device.
  17. 127
    128. A method of accessing a network resource of an external server by a portable communication device, the method performed by a network management system in communication with the portable communication device, the method comprising:receiving, at a communications port of a wireless access point of the network management system from a portable communication device, a connection request for an external server, the connection request comprising one or more network packets;transmitting the connection request from the wireless access point to a controller of the network management system;determining, using the controller, whether to provide the portable communication device with access to the external server, the determination being based at least in part on comparing one or more attributes included in the connection request to a user profile database;sending transmission control protocol handshake completion data from the communications port of the wireless access point to the portable communication device in response to the connection request, said transmission control protocol handshake completion data configured to indicate that it was sent by the external server;-42CA 02725720 2016-03-22 receiving, at the wireless access point from the controller, redirection data comprising resource identification data that identifies an authentication system, the redirection data configured to cause the portable communication device to be redirected to the authentication system;and sending, from the communications port of the wireless access point to the portable communication device, a browser redirect message based upon the redirection data, the browser redirect message being sent upon a determination not to provide the portable communication device with access to the external server at that time;whereby the portable communication device transmits authentication-related information wherein the portable communication system can be provided access to a network resource of the external server, wherein the network management system need not communicate with the external server to redirect the portable communication device.
  18. 153
    154. A network management system configured to manage access of a portable communication device to a network resource of an external server, the system comprising:a wireless access point configured to receive, from a portable communication device, a connection request for an external server, the connection request comprising one or more network packets;and a controller configured to receive the connection request from the wireless access point and determine whether to allow the portable communication device to access the external server, lite determination being based at least in part on comparing an attribute included in the connection request to a user profile database;the network management system further configured to redirect the portable communication device to an authentication system, by performing operations comprising;sending transmission control protocol handshake completion data from the communications port of the wireless access point to the portable communication device in response to the connection request, said transmission control protocol handshake completion data configured to indicate that ή was sent by the external server;receiving, at the wireless access point from the controller, redirection data comprising resource identification data that identifies the authentication system, the -46CA 02725720 2016-03-22 redirection data configured to cause the portable communication device to be redirected to the authentication system;and sending, from the communications port of the wireless access point to the portable communication device, a browser redirect message based upon the redirection data, the browser redirect message being sent as a result of the determination not to allow the portable communication device to access the network resource;whereby the portable communication device transmits authentication-related information wherein the portable communication system can be allowed to access a network resource of the external server, wherein the network management system need not communicate with the external server to redirect the portable communication device.
  19. 172
    173. The network management system of daim 154, wherein the controller is further configured-to redirect upon determining that the portable communication device is not authorized to access the requested network resource.
Independent claims19