Location-based identification for use in a communications network
Abstract
A network device capable of providing location-based identification to network subscribers, comprising: a processor (58, 96, 124) that communicates with an access hub (56, 92, 122) to determine the connection ports (54) of the data packets generated on the server (86, 116), and a base of data that stores the associated connection ports, characterized in that the processor (58, 96, 124) determines the respective identifiers assigned to the respective connection ports (54) based on the location of the connection ports, The database stores the identifiers, and the processor (58, 96, 124) identifies the connection ports (54) within a network that has been guaranteed network authorization based on the respective identifiers.

Term
Term ended
Projected expiry passed 20 October 2020, 5.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
24 claims: 8 independent, 16 dependent
- 1ES 2 221 868 T3 REIVINDICACIONES 1. Un dispositivo de red capaz de proporcionar identificación basada en la localización a los abonados de red, comprendiendo:un procesador (58, 96, 124) que comunica con un concentrador de acceso (56, 92, 122) para determinar los puertos de conexión (54) de los paquetes de datos generados en el servidor (86, 116), y una base de datos que almacena los puertos de conexión asociados, caracterizado porque el procesador (58, 96, 124) determina los identificadores respectivos asignados a los respectivos puertos de conexión (54) en base a la localización de los puertos de conexión, la base de datos almacena los identificadores, y el procesador (58, 96, 124) identifica los puertos de conexión (54) dentro de una red a la que se le haya garantizado la autorización de red en base a los identificadores respectivos.
- 2Un dispositivo de red según la reivindicación 1, en el que el procesador (58, 96, 124) lee un identificador dentro de una parte etiquetada del paquete de datos (88) para determinar los puertos de conexión (54) de los paquetes de datos generados en servidor (86, 116).
- 3Un dispositivo de red según la reivindicación 1 o en la reivindicación 2, en el que el procesador (58, 96) usa protocolo VLAN como enlace de comunicaciones entre el procesador y el concentrador de acceso (56, 92).
- 4Un dispositivo de red según la reivindicación 1, en el que el procesador incluye un agente de preguntas capaz de solicitar los datos de identificación relativos al puerto de conexión (54) de los paquetes de datos generados en servidor (116).
- 5Un dispositivo de red según la reivindicación 4, en el que el agente de preguntas usa Protocolo de gestión de Red Simple (SNMP) como enlace de comunicaciones entre el dispositivo de red y el concentrador de acceso (122).
- 6Un dispositivo de red según la reivindicación 4 o la reivindicación 5, en el que el agente de preguntas usa Lenguaje de Marcas Ampliable (XML) como el enlace de comunicaciones entre el dispositivo de red y el concentrador de acceso (122).
- 7Un dispositivo de red según cualquiera de las reivindicaciones anteriores, en el que el procesador (58, 96, 124) determina el identificador asignado a un puerto de conexión específico (54) en respuesta a una transmisión inicial de paquetes de datos (86,116) desde el puerto de conexión.
- 8Un dispositivo de red según cualquiera de las reivindicaciones anteriores, en el que el procesador (58, 96, 124) accede a la base de datos junto con una aplicación de sistema de red para proporcionar información de facturación de abonado de red.
- 9Un dispositivo de red según cualquiera de las reivindicaciones anteriores, en el que el procesador (58, 96, 124) accede a la base de datos junto con una aplicación de sistema de red para proporcionar a los abonados opciones de facturación.
- 10Un procedimiento para implementar la identificación basada en la localización en una red de comunicaciones, que comprende los pasos de:establecer una conexión de red entre un servidor (52, 82, 112) y una red;transmitir paquetes de datos (86,116) desde el ser vidor a través de un puerto de conexión específico de la localización (54);caracterizado por los pasos de identificar el puerto de conexión específico de la localización en un concentrador de acceso (56, 92, 122) en forma de un identificador de puerto en base a la localización del puerto de conexión;comunicar el identificador de puerto a un dispositivo de red (58, 96, 124);almacenar el identificador de puerto en una base de datos en comunicación con el dispositivo de red;y identificar los puertos de conexión (54) a los que se les haya garantizado la autorización de red en base a los identificadores de puerto respectivos.
- 11Un procedimiento según la reivindicación 10, en el que la identificación de un puerto de conexión específico de la localización (54) en un concentrador de acceso (56, 92, 122) incluye el etiquetado de los paquetes de datos (86) con un identificador de puerto en el concentrador de acceso.
- 12Un procedimiento según la reivindicación 11, en el que la comunicación del identificador de puerto a un dispositivo de red (58, 96, 124) incluye la transmisión de los paquetes de datos etiquetados (94) al dispositivo de red.
- 13Un procedimiento según la reivindicación 11 o la reivindicación 12, en el que el etiquetado de los paquetes de datos (86) con un identificador de puerto incluye el etiquetado de los paquetes con un identificador de puerto que corresponde a una dirección de control de acceso al medio (MAC).
- 14Un procedimiento según la reivindicación 11, 12 ó 13, en el que el etiquetado de los paquetes de datos (86) con un identificador de puerto incluye la implementación del uso de protocolo VLAN.
- 15Un procedimiento según cualquiera de las reivindicaciones anteriores de la 10 a la 14, en el que el concentrador de acceso (56, 92, 122) comprende un elemento de red que comprende un módulo de acceso de línea de abonado digital (DSLAM), un punto de acceso sin hilos (WAP), un sistema de terminación cable módem (CMTS) o un dispositivo de conmutación.
- 16Un procedimiento según la reivindicación 10, en el que la identificación del puerto de conexión específico de la localización (54) en un concentrador de acceso (56, 92, 122) incluye:transmitir una pregunta de petición de puerto desde el dispositivo de red (124) a un concentrador de acceso (122), y transmitir una respuesta de identificación de puerto desde el concentrador de acceso al dispositivo de red.
- 17Un procedimiento según la reivindicación 16, en el que la transmisión de una pregunta de solicitud de puerto desde el dispositivo de red (124) incluye la transmisión de una pregunta SNMP (Protocolo de Gestión de Red Simple).
- 18Un procedimiento según la reivindicación 16 o la reivindicación 17, en el que la transmisión de una pregunta de solicitud de puerto desde el dispositivo de red (124) incluye la transmisión de una pregunta XML (Lenguaje de Marcas Ampliable).
- 19Un procedimiento según la reivindicación 16, 17 ó 18, en el que la transmisión de una respuesta de identificación de puerto incluye la transmisión de un identificador de puerto que corresponde con una dirección de control de acceso al medio (MAC).
- 20Un procedimiento según cualquiera de las rei ES 2 221 868 T3 vindicaciones anteriores de la 10 a la 19, en el que el dispositivo de red (58, 96, 124) incluye un dispositivo de puerta (124) que proporciona acceso de red a los abonados.
- 21Un procedimiento según cualquiera de las reivindicaciones anteriores de la 10 a la 20, en el que la identificación del puerto de conexión específico de la localización (54) comprende la asignación de un identificador de puerto a un respectivo puerto de conexión en respuesta a una transmisión inicial de paquete de datos (86, 116) desde el puerto de conexión.
- 22Un procedimiento según cualquiera de las reivindicaciones anteriores de la 10 a la 21, que incluye el acceso a la base de datos junto con una aplicación de sistema de red para proporcionar información de facturación de abonado de red.
- 23Un procedimiento según cualquiera de las reivindicaciones anteriores de la 10 a la 22, que incluye el acceso a la base de datos junto con una aplicación de red para proporcionar a los abonados de la red opciones de facturación.
- 24Un procedimiento según cualquiera de las reivindicaciones anteriores de la 10 a la 23, que incluye el desmontaje del identificador de puerto de los paquetes de datos generados en servidor (86, 116) originados desde un puerto de conexión respectivo (54) antes de la transmisión de los paquetes de datos a través de la red.
Independent claims24
66 paragraphs in 2 sections, as filed
ES 2 221 868 T3
DESCRIPTION
Location-based identification for use on a communications network.
Field of the invention
The present invention relates generally to an identification process within a communication network, and more particularly to a method and apparatus for implementing location-based identification in a communication network.
Background of the invention
While desktop computers are generally part of the same network for a substantial period of time, notebook computers, handsets, and personal digital assistants (PDAs), cell phones, or other portable computers (collectively they are all referred to as such as “laptops”) are specifically designed to be portable. As such, laptop computers are connected to different networks at different points in time depending on the location of the computer. In a common example where the laptop serves as an employee's desktop computer, the laptop is configured to communicate with its employee network, that is, the company network. When the employee travels, however, the laptop can be connected to different networks that communicate in different ways. In this regard, the employee can connect the laptop to a network maintained by an airport, a hotel, a mobile phone operator or any other setting in order to access the company network, the Internet or some other service in line. The laptop is also commonly brought into the employee's home where it is used to access various networks, such as the company network, a home network, the Internet, and the like. As these other networks are otherwise configured differently, however, the laptop must also be reconfigured in order to communicate properly with these other networks. Typically, this configuration is performed by the user each time the laptop is connected to a different network. As will be apparent, this repeated laptop setup is not only time consuming, it is also error prone. The reconfiguration procedure may even be beyond the capabilities of many users or violate the IT policy of your employees.
A universal subscriber gate device has been developed by Nomadix, LLC of Westlake Village, California and is described in detail in United States Patent Application No. 08 / 816,174 entitled "Nomadic Router", dated March 12, 1997, in the name of the inventors Short et al .; 09 / 458,602 entitled "Systems and Methods for Authorizing, Authenticating and Accounting Users Having Transparent Computer Access to a Network Using a Gateway Device", dated December 8, 1999, in the name of the inventors Pagan et al; and 09 / 458,569 entitled "Systems and Methods for Redirecting Users Having Transparent Computer Access to a Network Using a Gateway Device Having Redirection Capability" dated December 8, 1999 in the name of the inventors Short et al. These applications have been assigned to the same recipient of the rights as that of the present invention.
The gateway device serves as an interface that connects the user or subscriber to a number of networks or other online services. For example, the gateway device can serve as a gateway to the Internet, the company network, or other networks and / or online services. In addition to serving as a gate, the gate device automatically adapts to the protocols and other parameters of the server in order to be able to communicate with the new network in a way that is transparent to both the user / subscriber and the new one. net. Once the door device has been properly adapted to the user's server, the server can communicate appropriately over the new network, such as a hotel network, home network, at an airport or in any other location in order to access other networks, such as the company network, or other online services, such as the Internet.
The laptop user / subscriber, and more specifically the laptop or remote user, benefits from being able to access a myriad of communication networks without having to suffer the time consuming and daunting task of all too much. often to reconfigure your server according to specific network configurations. From another perspective, the network service provider benefits from avoiding "on-site" visits and / or technical support calls from the user who is unable to properly reconfigure the laptop. In this way, the gate device is able to provide more efficient network access and network maintenance to the user / subscriber and the network operator.
Gate devices are typically used to provide network access to the user of the remote laptop, such as users in hotels, airports, and other locations where the remote laptop may be located. Additionally, door devices have found widespread use in multi-tenant homes as a means of providing residents with an intranet that connects residents, broadband Internet access capabilities, and the ability to adapt to multiple residents. the variances of the individual business network needs of the residents. With the advent of even smaller portable computing devices, such as handsets, PDAs, and the like, the locations where these users can reside are becoming almost limitless. One day we may envision a wireless communications technology that provides the ability to network all forms of passengers by land or air. Gateway devices will also provide the impetus to guarantee remote network access to all remote users communicating over wireless links and other predictable means of communication.
US-A5,946,308 describes a network in which a gateway device assigns end systems to a broadcast group based on destination. The results of this assignment are then used to assign the access ports to those end systems that are within the broadcast group. The double assignment is then employed for the purpose of stable
ES 2 221 868 T3 cer restricted groups within a network. The network request allows the identification of the broadcast packets and that they are only routed through the network so that the transmission is limited only to those users or ports defined for a particular VLAN-ID.
In most remote user applications and multi-tenant dwelling applications, the door manager (ie network service provider) is not overly concerned with “who” the user / subscriber is, but rather where the user resides or is located. Location-based information is imperative for the network service provider who wants to manage subscriber bills based on where they are physically located rather than who they are or what they may choose to use. For example, in the hotel scenario, the network service provider is more concerned with knowing that room 301 has a seven-day network subscription than with who the individual users residing in room 301 are. In this manner, the network administrator is able to provide room 301, unlike individual residents of room 301, with a location identifier. The gate manager or network provider relies on this information to ensure accurate billing to the subscriber.
Additionally, the gate manager can benefit from location-based identification in the network management area. For example, through classification within network databases according to location, the gateway device is able to provide network options to subscribers based on where they are located. By way of example, if the network device has "learned" through location identification that room 301 is a suite, thereby providing its clients with additional service privileges, the door device can provide these privileges. additional services without the need to ask the user / subscriber regarding the status of the suite. The same type of location classification may be beneficial in the multi-resident dwelling example (i.e. a specially classified building or wing), in the airport example (i.e. a specially designated network port area for travelers from first class) or in any other network application that uses a gateway device to provide network access and network adaptation.
Summary of the invention
According to one aspect, the present invention consists of a network device capable of providing location-based identification to network subscribers, comprising a processor that communicates with an access concentrator to determine the connection ports of the generated data packets. on the server, and a database that stores the associated connection ports, characterized in that the processor determines the respective identifiers assigned to the respective connection ports based on the locations of the connection ports, the database stores the identifiers, and the processor identifies the connection ports within a network that are has granted network authorization based on their respective identifiers.
According to another aspect, the present invention consists of a method for implementing location-based identification in a communication network, comprising the steps of establishing a network connection between a server and a network, transmitting data packets from the server through a location-specific connection port, characterized by the steps of identifying the location-specific connection port in an access concentrator in the form of a port identifier based on the location of the connection port, communicating the port identifier to a network device, storing the identifier of port on a database in communication with the network device, and identify the connection ports to which network authorization has been granted based on the respective port identifiers.
The network device is typically a gateway device.
In one embodiment of the invention, the network device, eg, a gateway device, is capable of communicating with an access concentrator to determine the identity of the port corresponding to the received MAC address. The gateway device is then able to use the location-based identities to structure billing schemes and manage the entire network that the service provider has established.
In one embodiment of the procedure for implementing location-based identification, the process of identifying the port at an access concentrator includes tagging network packets at the access concentrator with a port identifier that corresponds to a control address. media access (MAC). The access concentrator and the network device will tag and communicate the port numbers by assigning VLAN (virtual local area network) identifiers to the ports.
In another embodiment of the method for implementing location-based identification, the port identification process at an access concentrator includes transmitting a port identification query from a network device, typically a gateway device, to a hub. access and sending a port identification response from the access concentrator to the network device. The network device and the access concentrator have the corresponding agents configured to send and answer questions. For example, the door device and the access concentrator can incorporate an SNMP agent or an XML agent to communicate through queries.
In yet another embodiment of the method for implementing location-based identification in a communication system, the network device, typically a gateway device, accesses a database to determine the identification status of the connection ports within of a communications network. The status of the connection ports identification is then used to run a network system application such as billing, authentication or any other network management application.
Brief description of the drawings
Figure 1 is a block diagram of a communication system that includes a door device for the automatic configuration of one or more
ES 2 221 868 T3 servers to communicate through the gateway device with other networks or other online services.
Figure 2 is a block diagram of a simplified communication network configured to allow location-based identification, in accordance with one embodiment of the present invention.
Figure 3 is a block diagram of a communication network using DSL as the communication medium and implementing VLAN tagging to incorporate location-based identification, in accordance with one embodiment of the present invention.
Figure 4 is a block diagram of a communication network highlighting the unique VLAN identification feature of VLAN tagging, in accordance with one embodiment of the present invention.
Figure 5 is a block diagram of a communication network using DSL as the communication medium and implementing the SNMP query to incorporate location-based identification, in accordance with one embodiment of the present invention.
Figure 6 is a flow chart of a general procedure for location-based identification in a communication network, in accordance with one embodiment of the present invention.
Figure 7 is a flow diagram of a method for location-based identification in a communication network that implements VLAN tagging, in accordance with one embodiment of the present invention.
FIG. 8 is a flow diagram of a method for location-based identification in a communication network that implements the SNMP query in accordance with one embodiment of the present invention.
Detailed description of the preferred embodiments
The present invention will now be described more fully hereinafter with reference to the accompanying drawings, in which preferred embodiments of the invention are shown. This invention, however, can be practiced in many different ways and should not be construed as limited to the embodiments stated herein; Rather, these embodiments are provided so that this description will be straightforward and complete and fully expresses the scope of the invention to those skilled in the art. Numbers refer to items with the same number throughout the document.
Referring now to Figure 1, a network system 10 that includes a gateway device 12. The network system typically includes a plurality of computers / servers 14 accessing the system in order to access the system in block diagram form. gain access to networks or other online services. For example, servers can be in communication with ports that are located in different rooms of a hotel in a multi-resident dwelling. Alternatively, the servers can be in communication with the ports at an airport, in a public space or the like. The network system also includes a gateway device that provides an interface between the plurality of servers and the various networks or other online services. Most commonly, the gate device is located close to the servers and in a relatively low position in the structure of the entire network system (i.e. the gate device will be located within the hotel, multi-unit residence, airport, etc. .). However, the gate device can be located higher in the global network system such as a Point of Presence (PoP) or a Network Operation Center (NOC), if so desired.
Although the gate device can be physically realized in many different ways, the gate device typically includes a controller and a memory device in which commands are stored that define the operational characteristics of the gate device. Alternatively, the door device can be realized within another network device, such as an access concentrator or a router, or the commands that define the functionality of the door device can be stored on a PCMCIA card so that they are can be run by one or more servers in order to automatically reconfigure the server or servers to communicate with a different network.
The network system 10 also typically includes an access concentrator 16 located between the servers 14 and the gateway device 12 to multiplex the received signals from the plurality of communications over a link to the gateway device. Depending on the medium through which the servers are connected to the access concentrator, the access concentrator can be configured in different ways. For example, the gatekeeper can be a digital subscriber line access module (DSLAM) for signals transmitted over normal telephone lines, a cable modem termination system (CMTS) for signals transmitted over coaxial cables, a wireless access point (WAP) for signals transmitted over a wireless network, a switch, or the like. As can be seen in Figure 1, the network system typically includes one or more routers 18 and / or servers (not shown in Figure 1) in communication with a plurality of networks 20 or other online services 22. While the network system is described to have a single router, the network system will typically have a plurality of routers, switches or bridges or the like that will be arranged in some hierarchical manner in order to appropriately route traffic to and from. different networks or other online services. In this regard, the gateway device will typically establish a link with one or more routers. The routers, in turn, establish links to the servers of other networks or other online service providers, such as Internet service providers, based on subscriber selection.
The gate device 12 is specifically designed to tailor the configuration of each of the servers 14 that register with the network system 10 in a way that is transparent to the subscriber and to the network. In the typical network system employing the Dynamic Server Configuration Protocol (DHCP) service, an IP address is assigned to the server that is registering on the network through communication with the gateway device. The DHCP service can be provided by an external DHCP server 24 or it can be provided by an internal DHCP server located within the door device. When opening your web browser
ES 2 221 868 T3 or otherwise, when trying to access an online service, the door device will direct the subscriber to enter some form of identifier such as his ID and password. In an alternative embodiment of the device, it is anticipated that the gate device will be able to automatically detect this information upon the server's connection to the network or any attempt to log in. The gateway device then determines whether the subscriber has rights to access the communication system, the level of access and / or the type of services to which the subscriber is entitled according to an Authentication, Authorization and Account (AAA) procedure. which is described in United States Patent Application Nos. 08 / 816,174.09 / 458,602 and 09 / 458,569. An AAA service, which is subscriber registration, may be a remote AAA server to the gate device or the AAA service may comprise a database embedded within the physical embodiment that houses the gate device.
Assuming the subscriber has been authenticated and authorized, the gate device typically presents subscribers with a home page or control panel that identifies, among other things, online services or other communication networks that are in operation. accessible through the door device. In addition, the home page presented by the gate device may provide information regarding current parameters or settings that will govern the access provided to the particular subscriber. As such, the door manager can quickly alter parameters or other settings in order to tailor the service according to his particular application. Typically, changes to parameters or other configurations that will potentially use additional network system resources will come at a cost, such that the gate manager will charge the subscriber a higher fee for their service. For example, a user may choose to increase the transfer rate at which signals are transmitted over the communication network and pay a correspondingly higher price for the service provided.
The home page also allows the subscriber to select the network 20 or other online services 22 that the subscriber wishes to access. For example, the subscriber can access the company network on which the server is typically resident. Alternatively, the subscriber can access the Internet or other online services. Once the subscriber chooses to access the network or another online service, the gateway device establishes the appropriate links through one or more routers 18 to the desired network or desired online service.
The subscriber can then freely communicate with the desired network 20 or other online service 22. In order to support this communication, the gateway device 12 generally performs a packet translation function that is transparent to the user / subscriber and for the network. In this regard, for out-of-bounds traffic from the server 12 to the communication network or other online service, the gateway device changes the attributes within the packet coming from the user / subscriber, such as the source address, the checksum and application-specific parameters to meet the criteria of the network that the user / subscriber has accessed. In addition, the outgoing packet includes an attribute that will direct all incoming packets from the accessed network to be routed through the gate device. In contrast, in-boundary traffic from the accessed network or other online services that is routed through the gate device, undergoes a translation function in the gate device so that packets are formatted. appropriately for the user / subscriber server. In this way, the packet translation process that takes place at the gateway device is transparent to the server, which appears to send and receive data directly from the communications network that has been accessed. Additional information regarding the translation function is provided in US Patent Application No. 08 / 816,714. By implementing the gateway device as an interface between the user / subscriber and the communication network or other online services, however, the user / subscriber will eliminate the need to reconfigure their server 12 when accessing subsequent networks.
In one embodiment of the present invention, the door device implements location-based identification. In accordance with the present invention, the location-based identification may also be embedded within another network device, such as an access concentrator or a router, or the commands that define the location-based identification may be stored in a PCMCIA card that can be run by one or more servers in order to identify the ports from which the server accesses the network system. Location-based identification allows the network system to grant network access to a specific location (for example, a hotel room, a specific apartment address, etc.) rather than to a specific user or server residing in the location. location. Basing identification on location, rather than user or server basis, allows the gate manager (i.e. network service provider) to manage the network system according to user locations and provide a scheme of billing according to the user's locations.
In one embodiment of the present invention, the gateway device includes a processor that communicates with an access concentrator to determine the connection ports of the data packets generated at the server. Once the connection ports have been determined, they are stored within a database, such as a connection table, which is in communication with the gate device processor. In a typical gateway device, the processor will employ the use of VLAN protocol as the communication link between the gateway device and the access concentrator. While VLAN is by definition Virtual Local Area Network, in the context in which we are with VLAN, it is the standard IEEE 802.1 Q protocol used to implement VLAN. VLAN technology is well known in the art and has been used to create virtual networks by employing VLAN processors between network interfaces to logically bridge networks together. VLAN works on the concept of port tracking by tagging the IP packet with an identifier. Using VLAN technology , the gateway device can provide the subscriber
ES 2 221 868 T3 network access on a localized port basis. For example, in the multi-resident housing environment, a network service provider may wish to provide provision of Internet access to individual units or individual apartments; Each unit is assigned a VLAN ID (a port location tag). In this example, a resident within the unit may choose to subscribe to the service and the door device will then allow Internet access from the resident's unit, regardless of which server or user is within the unit. Typically, network access to servers is guaranteed via MAC (Media Access Control) address that connects the device to a shared network media. Using VLAN tagging bypasses the MAC address identification process.
VLAN ports can be “tagged” at any level, for example, a tag can be assigned to a specific room in a hotel or apartment building, or a floor within a building, a wing within a building, or the building itself. building, they can be assigned an individual tag. Alternatively, multiple ports can be tagged to a single room. The gate device uses a port location authorization table to manage assigned ports and to ensure accurate billing for services used by a particular port.
Figure 2 illustrates a simplified network system 50 configured to allow location-based identification supported by VLAN tagging. A series of portable computers / servers 52 are located within separate entities. Separate entities may include apartment units, hotel rooms, airport kiosks, shops, or the like. The user (not shown in Figure 2) connects to the network service provider through a port 54 in the room. Communication between the server and the port can be physical; such as a cable to a connector, or the communication can be wireless. A modem (not shown in figure 1), either internal within the servers or external, may be required to provide access to the network service provider. The means used to establish the connection may include standard dial-up, cable, CAT5 high-quality cable, DSL (Digital Subscriber Line), wireless communication, or any other applicable means of connection.
After the server establishes connections, it begins sending standard Internet Protocol (IP) packets. An access concentrator 56 initially receives the IP packets. The access concentrator serves as a switch that multiplexes the signals received from numerous ports and sends them out through an output port. Depending on the means by which the servers are networked to the access concentrator, the access concentrator can be configured in different ways. For example, the access concentrator may be a digital subscriber line access module (DSLAM) for signals transmitted over normal telephone lines, a cable modem termination system (CMTS) for signals transmitted over cables. coaxial, a wireless access point (WAP) for signals transmitted over a wireless network, a switch or the like. In order to implement VLAN tagging, the access concentrator must be able to support VLAN technology. If the access concentrator does not support VLAN tagging or a similar tagging means, then location-based identification can be implemented by means of the SNMP (Simple Network Management Protocol) alternate query embodiment of this invention that is detailed in a later discussion in this document. Access concentrators are well known to those of general skill in the art and most DSLAMs or other access concentrators will support VLAN technology.
In performing the VLAN tagging of the present invention, once the access concentrator receives the IP packet, it knows which server to send it to (from the MAC address header), but it does not know where the server is located. The access concentrator through the use of a VLAN processor has the ability to “know” from which port each packet arrived. It then reconfigures the packet by adding a header, typically between the Ethernet and IP parts of the packet according to the IEEE 802.1Q VLAN protocol, identifying the port number and the server. These packets are then forwarded through a simple output to the gate device 58. The gate device removes the port information and records the data in a database, such as a connection table. A typical connection table maps a port identifier to a MAC address for all incoming packets routed from the access concentrator. The dynamic nature of the table would allow the subscriber to change locations and access the network system through an alternate port that has been identified and authorized for use. Once the port number has been registered, the VLAN portion is stripped from the packet header and the packet is forwarded to a router 60 and subsequently to the Internet 62 or another network in the system. The VLAN header can be repositioned on a packet that is being communicated from the network to the server so that the access concentrator knows where the packet is going to be sent. Additionally, the tagging packets coming from the network back to the subscriber provide that the gateway device is interoperable with most access concentrators that are in VLAN tagging mode. This allows access concentrators that comprise a composite communication network to communicate in a "trunked" manner.
It should be noted that while other devices that are in the network system can communicate in VLAN protocol, in this embodiment the only two devices that require communication by VLAN protocol are the access concentrator and the gateway device. Server devices are generally unable to communicate in VLANs, and downstream network components (routers, switches, bridges, etc.) are inconsistent in this regard.
Figure 3 is a block diagram illustrating a network configuration using DSL as the communication medium and VLAN tagging as the means of incorporating location-based identification. This networking configuration is shown by way of example, and other communication media, such as cable, comunica
ES 2 221 868 T3 wireless network or the like, to configure a network that uses VLAN tagging to incorporate location-based identification. Network system 80 includes servers 82, typically laptop computers and in this illustration conventional laptop computers. The servers in this example are located in individual hotel rooms, however, the servers could have been located in other entities, such as apartment units, office rooms, airport kiosks, or the like. The servers access the network through a digital subscriber line (DSL) modem 84. Once a communications link has been established, the servers send standard IP packets 86 to communicate data within the network. In the DSL modem a DSL header is attached to the packets, resulting in the DSL / Ethernet / IP packet 88. The DSL header serves to identify the DSL modem on the port. The packets are then routed through a connection point, shown in this example as download block 90, before an access concentrator 92 receives them.
In this embodiment, the access concentrator is a DSLAM that is capable of communicating in the VLAN protocol (IEEE 802.1Q). The access concentrator determines the port from which the packets were sent and assigns an appropriate VLAN identification number to the packet based on the port from which it was sent. As shown in figure 4, each port, in this example each hotel room has a unique VLAN ID. For example, hotel room 3210 may be assigned VLAN ID 3210 and hotel room 1001 may be assigned VLAN ID 1001. A table within the access concentrator assigns the VLAN IDs to the associated room number, kiosk number, etc. A VLAN header is added to the packet, resulting in the Ethernet over VLAN over IP packet 94 shown in Figure 4. These packets are then communicated to the gate device 96 where the VLAN portion of the header is removed and the VLAN ID is referenced to a specific port within a communication table database associated with the gate device. In turn, the door device may use location-based identification for billing purposes, such as the Hotel PMS system 98 shown in Figure 4, network authorization, or other network purposes. After the port device has registered the port information, the packets are forwarded to other networks, such as the Internet 100. In this example, the packets are communicated as standard IP packets 102.
It should be noted that the door device or any other network device that performs location-based identification will require configuration upon initial installation to accommodate location-based identification. If VLAN tagging is to be the basis for location-based identification, the gateway device or a similar network device must be configured to allow this communication to occur. A door manager will need to configure the door so that VLAN IDs are assigned to particular entities or ports (ie, room numbers, apartment units, etc.). Port location assignments can be added, updated or deleted, according to the door manager's commands. Adding a port assignment to the door device database may involve assigning a port number, assigning a location to the port number, and a conditional status for this port location. Conditional statuses can be associated with billing schemes. For example, port locations can be assigned a “no charge” status, a “usage charges” status, or any other status can be assigned.
In another embodiment of the present invention, location-based identification is implemented by means of the processor inside a gate device using a query agent that is capable of requesting the identification data related to the connection port of the packets. of data generated on the server. A typical gate processor will implement the SNMP (Simple Network Management Protocol) query or a similar query agent can be implemented. SNMP query completion is generally used if the access concentrator does not support the VLAN protocol. Figure 5 is a block diagram illustrating a network configuration using DSL as the communication medium and SNMP queries as the means of incorporating location-based identification. This networking configuration is shown by way of example, other communication means such as cable, wireless communication or the like can also be used to configure a network using SNMP queries to incorporate location-based identification. Network 110 includes servers 112, typically laptop computers and in this illustration conventional laptop computers. The servers in this example are located in individual hotel rooms, however, the servers could be located in other entities, such as apartment units, office rooms, airport kiosks, or the like. The servers access the network through a digital subscriber line (DSL) modem 114. Once a communication link is established, the servers send out standard IP data packets 116 to communicate data within the network. In the DSL modem a DSL header is appended to the packets, resulting in the DSL / Ethernet / IP packet 118. The packets are then routed through a connection point, shown in this example as download block 120, before they are received by an access concentrator 122.
In this application, as the access concentrator does not implement VLAN tagging, the packets communicated between the access concentrator and the gateway device 124 are standard IP packets 126. The IP packets that are received by the gateway device are devoid of any information regarding the location (ie ports). As shown in figure 5, the gate device must be configured to send SNMP 128 query packets back to the access concentrator asking the concentrator which port this packet came from (ie this MAC address). The access concentrator that is in communication with a database that links the MAC addresses with the ports, is then able to answer the question with an answer to the SNMP 136 question that links the MAC address of the packet with a number of port. The access concentrator responds
ES 2 221 868 T3 by sending an IP packet back to the gate device identifying the port number. The gate device removes the port number and associated MAC address from the SNMP header and formats the information into an appropriate communication table database associated with the gate device in a table format. In turn, the door device may use location-based identification for billing purposes, such as the hotel PMS system 130 shown in Figures 5 and 6, network authorization, or any other purpose. Once the database has the appropriate port number for MAC address assignment for any specific location, the gate device will no longer be required to send SNMP queries to the access concentrator. In this way the SNMP query procedure is typically only required to be performed once for any given port. After the gateway device has registered the information regarding the port in the database, the packets are forwarded to other networks, such as the Internet 132. In this case, the packets are communicated as IP packets 134.
It should be noted that when asking SNMP queries, the gate device and access concentrator must be SNMP compliant. Both the door device and the access concentrator must be configured with the SNMP agent to receive, send, and act upon receipt of SNMP queries. If other inquiry agents are used to implement location-based identification then both the door device or similar network device and the access concentrator must be configured with the chosen inquiry agent.
In accordance with one embodiment of the present invention, a method for implementing location-based identification in a communication network is shown in the flow chart of Fig. 6. In step 150, a network connection is established between a server and a network. The communication medium that can be used to establish the connection includes telephone line, DSL, conventional cable, CAT5 cable, wireless communication, and the like. In step 160, data packets, typically IP data packets, are transmitted from the server to the network through a location-specific connection port. The location-specific connection port is typically located in a hotel room, airport kiosk, apartment building, or similar remote location. In step 170, the location-specific connection port is identified at an access concentrator. The identification process that occurs at the access concentrator may include VLAN tagging of data packets, responses to SNMP questions, or similar identification processes. Once the application-specific connection port has been identified in the form of a port identifier, it is then, in step 180, communicated to a network device, typically a gateway device. The network device will comprise or be in communication with a database which, in step 190, stores the port identifiers in order to identify the ports that have been authorized to access the network.
In accordance with another embodiment of the present invention, a method for location-based identification that implements VLAN tagging in a communication network is shown in the flow chart of Figure 7. In step 200, a network connection is established between a server and a network. The communication medium that can be used to establish the connection includes telephone line, DSL, conventional cable, CAT5 cable, wireless communication, and the like. In step 210, the server sends network data packets to the network through a connection port, and in step 220 the network data packets are received at an access concentrator. The access concentrator may comprise a digital subscriber line access module (DSLAM) for signals transmitted over normal telephone lines, a cable modem termination system (CMTS) for signals transmitted over coaxial cables, a point Wireless Access (WAP) for signals transmitted over a wireless network, switch, or the like. The access concentrator will be configured with an agent that allows port identification. For example, an access concentrator can be configured with a VLAN agent that provides VLAN tagging of packets transmitted from a location-specific connection port.
In step 230, the access concentrator labels the network data packets with a port identifier that corresponds to the media access control (MAC) address. Tagging of the network data packet is typically performed using VLAN technology. Each port in the network service provider entity is configured as a virtual LAN and therefore each port has its own VLAN identifier. In step 240, the tagged data packet is received at a network device, typically a gateway device, where the port identification information is stripped from the packet header. In step 250 the port identifier is incorporated into a database that is in communication with the network device. Once the location-based data, in this example the port identifier, is incorporated into the database, it can be called up for billing scheme purposes, authentication purposes or for any other use in global management systems. network.
According to another embodiment of the present invention, a method for location-based identification that implements the query in a communication network is shown in the flow chart of Fig. 8. In step 300, a network connection is established between a server and a network. The communication medium that can be used to establish the connection includes telephone line, DSL, conventional cable, CAT5 cable, wireless system, and the like. In step 310, the server sends network data packets to the network through a connection port and in step 320 the network packets are received at the network device, typically a gateway device.
The network device is typically configured with an agent that is capable of generating queries to other network devices. For example, the network interface device can be configured with an SNMP agent that is capable of generating SNMP queries or another similar agent can be used, such as XML. In step 330, the network device sends a port identification query to a concen
ES 2 221 868 T3 gatekeeper, in response to receipt of network data packets. The access concentrator may comprise a digital subscriber line access module (DSLAM) for signals transmitted over normal telephone lines, a cable modem termination system (CMTS) for signals transmitted over coaxial cables, a point Wireless Access (WAP) for signals transmitted over a wireless network, switch, or the like. Typically, the access concentrator will have an agent capable of answering questions sent by the network interface device. For example, the access concentrator can be configured with an SNMP agent that is capable of generating SNMP responses, or another similar agent can be used, such as XML corresponding to the agent used in the network interface device. Additionally, the access concentrator is configured to track the identity of the port against the MAC address of incoming packet traffic.
In step 340, the access concentrator sends a port identification response back to the network device and in step 350, the network identifier is incorporated into the database that is in communication with the network device. Once the location-based data, in this example the port identifier, is incorporated into the database, it can be called up for billing schemes, authorization or for use in any other global network management system.
The method and apparatus of the present invention provide identification based on subscriber location rather than identification of subscribers based on user or device. In this way, the network system can manage network management and billing schemes (ie, quality of service, billing maintenance, authorization, etc.) based on the physical entity; the hotel room, apartment unit, airport kiosk, etc., in which the user is located. This provides more options to the network service provider in terms of billing and network management.
Many modifications and other embodiments of the invention will come to the mind of one of ordinary skill in the art to which this invention pertains having the benefit of the teachings presented in the preceding descriptions and associated drawings. Therefore, it will be understood that the invention is not limited to the specific embodiments described and that modifications and other embodiments are intended to be included within the scope of the appended claims. Although specific terms are used herein, they are used only in a generic and descriptive sense and not for purposes of limiting the scope of the present invention in any way.
Contents2
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
179 members in 13 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 16109399 | United States of America | P | |
| 19990161093P | United States of America | – |
Members179
| Document | Office | Kind | |
|---|---|---|---|
| CA2388601A1 | Canada | A1 | |
| CA2388623A1 | Canada | A1 | |
| CA2388628A1 | Canada | A1 | |
| CA2698604A1 | Canada | A1 | |
| CA2725720A1 | Canada | A1 | |
| CA2737890A1 | Canada | A1 | |
| WO0131843A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0131855A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0131861A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO0131883A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0131885A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0131886A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0131889A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU1088501A | Australia | A | |
| AU1098301A | Australia | A | |
| AU1224101A | Australia | A | |
| AU1224201A | Australia | A | |
| AU1224301A | Australia | A | |
| AU1340401A | Australia | A | |
| AU2297601A | Australia | A | |
| WO0133808A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2614401A | Australia | A | |
| WO0131886A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0133808A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0131885A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0131843A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0131855A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0131889A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0235797A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU1336702A | Australia | A | |
| WO0131855A9 | World Intellectual Property Organization (WIPO) | A9 | |
| WO0131883A3 | World Intellectual Property Organization (WIPO) | A3 | |
| KR20020059640A | Republic of Korea | A | |
| EP1222775A2 | European Patent Office (EPO) | A2 | |
| EP1222791A2 | European Patent Office (EPO) | A2 | |
| EP1224788A2 | European Patent Office (EPO) | A2 | |
| EP1226687A2 | European Patent Office (EPO) | A2 | |
| WO0133808A9 | World Intellectual Property Organization (WIPO) | A9 | |
| EP1232610A1 | European Patent Office (EPO) | A1 | |
| EP1234425A2 | European Patent Office (EPO) | A2 | |
| KR20020070268A | Republic of Korea | A | |
| KR20020075365A | Republic of Korea | A | |
| WO0235797A3 | World Intellectual Property Organization (WIPO) | A3 | |
| IL149188D0 | Israel | D0 | |
| IL149223D0 | Israel | D0 | |
| IL149227D0 | Israel | D0 | |
| WO0131861A9 | World Intellectual Property Organization (WIPO) | A9 | |
| CN1391754A | China | A | |
| CN1408169A | China | A | |
| JP2003513514A | Japan | A | |
| JP2003513522A | Japan | A | |
| JP2003513524A | Japan | A | |
| WO0235797A9 | World Intellectual Property Organization (WIPO) | A9 | |
| CN1433622A | China | A | |
| US6636894B1 | United States of America | B1 | |
| WO0133808A8 | World Intellectual Property Organization (WIPO) | A8 | |
| EP1224788B1 | European Patent Office (EPO) | B1 | |
| AT270014T | Austria | T | |
| ATE270014T1 | Austria | T1 | |
| DE60011799D1 | Germany | D1 | |
| US6789110B1 | United States of America | B1 | |
| CN1178446C | China | C | |
| AU779137B2 | Australia | B2 | |
| ES2221868T3This record | Spain | T3 | |
| US6868399B1 | United States of America | B1 | |
| EP1222791B1 | European Patent Office (EPO) | B1 | |
| AT297095T | Austria | T | |
| ATE297095T1 | Austria | T1 | |
| DE60020588D1 | Germany | D1 | |
| DE60011799T2 | Germany | T2 | |
| ES2243319T3 | Spain | T3 | |
| CN1233129C | China | C | |
| KR100559357B1 | Republic of Korea | B1 | |
| DE60020588T2 | Germany | T2 | |
| EP1226687B1 | European Patent Office (EPO) | B1 | |
| AT327618T | Austria | T | |
| ATE327618T1 | Austria | T1 | |
| DE60028229D1 | Germany | D1 | |
| EP1234425B1 | European Patent Office (EPO) | B1 | |
| AT335340T | Austria | T | |
| ATE335340T1 | Austria | T1 | |
| DE60029819D1 | Germany | D1 | |
| AU2006207853A1 | Australia | A1 | |
| US7117526B1 | United States of America | B1 | |
| US2006239254A1 | United States of America | A1 | |
| ES2263496T3 | Spain | T3 | |
| JP3880856B2 | Japan | B2 | |
| KR100687837B1 | Republic of Korea | B1 | |
| DE60029819T2 | Germany | T2 | |
| DE60028229T2 | Germany | T2 | |
| US7194554B1 | United States of America | B1 | |
| US7197556B1 | United States of America | B1 | |
| ES2269195T3 | Spain | T3 | |
| CN1314253C | China | C | |
| KR100734965B1 | Republic of Korea | B1 | |
| EP1819108A2 | European Patent Office (EPO) | A2 | |
| AU2006207853B2 | Australia | B2 | |
| EP1855429A2 | European Patent Office (EPO) | A2 | |
| IL149188A | Israel | A | |
| IL149227A | Israel | A |
Numbers
- Publication
- 2221868
- Application
- 989664
Titles2
- Spanish
- IDENTIFICACION BASADA EN LA LOCALIZACION PARA SU USO EN UNA RED DE COMUNICACIONES.
- English
- IDENTIFICATION BASED ON THE LOCATION FOR USE IN A COMMUNICATIONS NETWORK.
Classification
- CPC, 12
- H04L63/0236
- H04L12/14
- H04L12/1403
- H04L12/1439
- H04L12/289
- H04L12/4645
- H04L41/0266
- H04L67/306
- H04L67/12
- H04L67/02
- H04L69/329
- H04L61/5084
- IPC, 6
- H04L12 14
- H04L12 24
- H04L12 28
- H04L29 06
- H04L29 08
- H04L29 12