Establishing dynamic tunnel access sessions in a communication network
Abstract
Method for dynamically creating a tunnel in a communications network with a view to providing the host of a subscriber access to a network service, comprising: storing a subscriber profile in a network database, in which the subscriber profile includes specific subscriber network service tunneling requirements for a plurality of network services (20¿, 20¿¿) that are available to the subscriber, including information to identify tunnel requirements for each of said services; establish a subscriber network session between a gateway device (12) and the subscriber's host; receiving on the gateway device (12) a first request for access to the service associated with a first network service (20¿), the first request for access to the service being received at any time during the current session of the network subscriber; identify the first request for access to the service as originating from the subscriber; access the subscriber profile in response to the receipt of the first request for access to the service; determine, based on the tunneling requirements of the subscriber-specific network service in the subscriber profile that has been accessed, if the first network service (20) presents a specific tunneling requirement of the subscriber, and create a first tunnel (32) if the determination is made that the subscriber profile requires the first tunnel, wherein the first tunnel (32) has a first endpoint in the gateway device and a second endpoint in the first network service, characterized in that the gateway device (12) deceives the first network service (20) by believing that the tunnel extends to an extreme point in the host of the subscriber (14) by changing the addresses of the source within the packages that come from from the subscriber host (14) and the destination addresses within the packets that come from the first network service (20¿).

Term
Term ended
Projected expiry passed 20 October 2020, 5.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
20 claims: 5 independent, 15 dependent
- 1ES 2 263 496 T3 REIVINDICACIONES 1. Método para crear dinámicamente un túnel en una red de comunicaciones con vistas a proporcionar al anfitrión de un abonado acceso a un servicio de red, que comprende:almacenar un perfil de abonado en una base de datos de la red, en el que el perfil de abonado incluye unos requisitos de tunelización del servicio de red específicos del abonado para una pluralidad de servicios de red (20', 20”) que están disponibles para el abonado, incluyendo información para identificar requisitos de los túneles para cada uno de dichos servicios;establecer una sesión de red de abonado entre un dispositivo de pasarela (12) y el anfitrión del abonado;recibir en el dispositivo de pasarela (12) una primera solicitud de acceso al servicio asociada a un primer servicio de red (20'), recibiéndose la primera solicitud de acceso al servicio en cualquier instante de tiempo durante la sesión en curso de la red de abonado;identificar la primera solicitud de acceso al servicio como originada en el abonado;acceder al perfil de abonado en respuesta a la recepción de la primera solicitud de acceso al servicio;determinar, basándose en los requisitos de tunelización del servicio de red específicos del abonado en el perfil de abonado al que se ha accedido, si el primer servicio de red (20') presenta un requisito de tunelización específico del abonado, y crear un primer túnel (32) si se toma la determinación de que el perfil de abonado requiere el primer túnel, en el que el primer túnel (32) tiene un primer punto extremo en el dispositivo de pasarela y un segundo punto extremo en el primer servicio de red, caracterizado porque el dispositivo de pasarela (12) engaña al primer servicio de red (20) haciéndole creer que el túnel se extiende hasta un punto extremo en el anfitrión del abonado (14) al cambiar las direcciones de la fuente dentro de los paquetes que provienen del anfitrión de abonado (14) y las direcciones de destino dentro de los paquetes que provienen del primer servicio de red (20').
- 2Método según la reivindicación 1, en el que el almacenamiento de un perfil de abonado comprende el almacenamiento de por lo menos un parámetro seleccionado de entre el grupo constituido por el identificador de acceso a la red, un nombre de usuario/abonado y una contraseña de usuario/abonado.
- 3Método según la reivindicación 1 o la reivindicación 2, que comprende además la determinación de si existe previamente un primer túnel entre el dispositivo de pasarela (12) y el primer servicio de red (20') antes de crear el túnel entre el dispositivo de pasarela (12) y el primer servicio de red (20').
- 4Método según cualquiera de las reivindicaciones anteriores, en el que más de un abonado que acceda a la red de comunicaciones a través del dispositivo de pasarela (12) puede transmitir simultáneamente paquetes de datos al primer servicio de red (20') a través del primer túnel (32).
- 5Método según cualquiera de las reivindicaciones anteriores, en el que el método comprende además:recibir en el dispositivo de pasarela (12) una segunda solicitud de acceso al servicio asociada a un segundo servicio de red (20”), recibiéndose la segunda solicitud de acceso al servicio en cualquier instante de tiempo durante una sesión en curso de la red de abonado;identificar la segunda solicitud de acceso al servicio como originada en el abonado (14);acceder al perfil de abonado en respuesta a la recepción de la segunda solicitud de acceso al servicio;determinar, basándose en los requisitos de tunelización del servicio de red específicos del abonado en el perfil de abonado al que se ha accedido, si el segundo servicio de red presenta un requisito de tunelización específico del abonado;y crear un segundo túnel si se toma la determinación de que el perfil de abonado requiere el segundo túnel, en el que el segundo túnel tiene un primer punto extremo en el dispositivo de pasarela (12) y un segundo punto extremo en el segundo servicio de red (20”).
- 6Método según la reivindicación 5, que comprende además la determinación de si existe previamente un segundo túnel entre el dispositivo de pasarela (12) y el segundo servicio de red (20”) antes de crear el túnel (36) entre el dispositivo de pasarela (12) y el segundo servicio de red (20”).
- 7Método según la reivindicación 5 o la reivindicación 6, en el que el segundo túnel (36) es funcional de forma simultánea con el funcionamiento del primer túnel (32).
- 8Método según la reivindicación 5, en el que más de un abonado que acceda a la red de comunicaciones a través del dispositivo de pasarela (12) puede transmitir simultáneamente paquetes de datos hacia el primer servicio de red (20') a través del primer túnel (32) y hacia el segundo servicio de red (20”) a través del segundo túnel (36).
- 9Sistema para crear dinámicamente un túnel en una red de comunicaciones con vistas a proporcionar al anfitrión de un abonado acceso a una red de destino, que comprende:un dispositivo de almacenamiento que almacena un perfil de abonado, en el que el perfil de abonado incluye requisitos de tunelización del servicio de red específicos del abonado para una pluralidad de servicios de red que están disponibles para el abonado, incluyendo información para identificar requisitos de los túneles para cada uno de dichos servicios;unos medios para establecer una sesión de red de abonado entre un dispositivo de pasarela (12) y el anfitrión del abonado (14);unos medios para recibir en el dispositivo de pasarela (12) una primera solicitud de acceso al servicio asociada a un primer servicio de red (20') en cualquier instante de tiempo durante una sesión en curso de la red de abonado;unos medios para identificar la primera solicitud de acceso al servicio como originada en el abonado;unos medios para acceder al perfil de abonado en respuesta a la recepción de la primera solicitud de acceso al servicio;unos medios para determinar, basándose en los requisitos de tunelización del servicio de red específicos del abonado en el perfil de abonado al que se ha accedido, si el primer servicio de red (20') presenta un requisito de tunelización específico del abonado;y unos medios para crear un primer túnel (32) si se toma la determinación de que el perfil de abonado requiere el primer túnel, en el que el primer túnel tiene un primer punto extremo en el dispositivo de pasarela y un segundo punto extremo en el primer servicio de red (20'), ES 2 263 496 T3 caracterizado porque el dispositivo de pasarela (12) se puede hacer funcionar de manera que engaña al primer servicio de red (20) haciéndole creer que el túnel se extiende hasta un punto extremo en el anfitrión del abonado (14) al cambiar las direcciones de la fuente dentro de los paquetes que provienen del abonado (14) y las direcciones de destino dentro de los paquetes que provienen del primer servicio de red (20).
- 10Sistema según la reivindicación 9, que comprende además unos medios para determinar si existe previamente un primer túnel (32) entre el dispositivo de pasarela (12) y el primer servicio de red (20') antes de crear el túnel (32) entre el dispositivo de pasarela (12) y el primer servicio de red (20').
- 11Sistema según la reivindicación 9, que comprende además:unos medios para recibir en el dispositivo de pasarela (12) una segunda solicitud de acceso al servicio asociada a un segundo servicio de red (20”), recibiéndose la segunda solicitud de acceso al servicio del abonado en cualquier instante de tiempo durante una sesión en curso de la red de abonado;unos medios para identificar la segunda solicitud de acceso al servicio como originada en el abonado;unos medios para acceder al perfil de abonado en respuesta a la recepción de la segunda solicitud de acceso al servicio;unos medios para determinar, basándose en los requisitos de tunelización del servicio de red específicos del abonado en el perfil de abonado al que se ha accedido, si el segundo servicio de red presenta un requisito de tunelización específico del abonado;y unos medios para crear un segundo túnel (36) si se toma la determinación de que el perfil de abonado requiere el segundo túnel, en el que el segundo túnel (36) tiene un primer punto extremo en el dispositivo de pasarela (12) y un segundo punto extremo en el segundo servicio de red (20”).
- 12Dispositivo de pasarela (12) que crea dinámicamente un túnel en una red de comunicaciones para proporcionar a un anfitrión de un abonado acceso a una red de destino, que comprende:unos medios para establecer una sesión de red de abonado entre el dispositivo de pasarela (12) y el anfitrión del abonado (14);un procesador que recibe de un abonado, en cualquier instante de tiempo durante una sesión en curso de la red de abonado, una solicitud de acceso a un servicio asociada a un servicio de red (20) e identifica la solicitud de acceso al servicio como originada en el abonado (14);una base de datos a la que accede el procesador, que almacena un perfil de abonado que incluye requisitos de tunelización del servicio de red específicos del abonado para una pluralidad de servicios de red que están disponibles para el abonado, incluyendo información para identificar requisitos de los túneles para cada uno de dichos servicios;y un módulo de gestión de túneles implementado por el procesador que se comunica con la base de datos, durante la sesión en curso de la red de abonado, para determinar si el abonado requiere un túnel (32) para acceder al servicio de red solicitado y, si se toma una determinación de que se requiere el túnel, el módulo de gestión de túneles crea una sesión de acceso al servicio entre el dispositivo de red y el servicio de red, caracterizado porque el dispositivo de pasarela se puede hacer funcionar de manera que engaña al primer servicio de red (20) haciéndole creer que el túnel se extiende hasta un punto extremo en el anfitrión del abonado (14) al cambiar las direcciones de la fuente con paquetes que provienen del anfitrión del abonado (14) y las direcciones de destino con paquetes que provienen del primer servicio de red (20).
- 13Dispositivo de pasarela según la reivindicación 12, que comprende además un módulo de gestión de sesiones implementado por el procesador que se comunica con la base de datos para gestionar la sesión de acceso a la red proporcionada por el dispositivo de red.
- 14Dispositivo de pasarela según la reivindicación 12, en el que el módulo de gestión de túneles determina si existe previamente un túnel entre el dispositivo de pasarela y el servicio de red antes de crear el túnel entre el dispositivo de pasarela y el servicio de red.
- 15Dispositivo de pasarela según la reivindicación 12, en el que el módulo de gestión de túneles es capaz de crear más de una sesión de acceso a la red para el acceso simultáneo de abonados a más de un servicio de red.
- 16Dispositivo de pasarela según la reivindicación 12, en el que el módulo de gestión de túneles es capaz de proporcionar un acceso simultáneo a la sesión de acceso a la red a más de un abonado que acceda a la red de comunicaciones a través del dispositivo de pasarela (12).
- 17Dispositivo de pasarela según la reivindicación 16, que comprende además un módulo de gestión de sesiones implementado por el procesador que se comunica con la base de datos para gestionar la sesión de acceso simultáneo a la red proporcionada a más de un abonado que accede a la red de comunicaciones a través del dispositivo de pasarela.
- 18Dispositivo de pasarela según la reivindicación 16, en el que el perfil de abonado define requisitos de tunelización del servicio de red específicos del abonado para una pluralidad de servicios de red a los que se le ha autorizado a acceder al abonado.
- 19Dispositivo de pasarela según la reivindicación 18, en el que los requisitos de tunelización del servicio de red específicos del abonado están predefinidos por el abonado.
- 20Dispositivo de pasarela según la reivindicación 18, en el que los requisitos de tunelización del servicio de red específicos del abonado están predefinidos por el administrador del dispositivo de pasarela.
Independent claims20
39 paragraphs in 2 sections, as filed
ES 2 263 496 T3
DESCRIPTION
Establishment of dynamic access sessions through tunnels in a communications network.
Field of the invention
The present invention relates generally to the management of a communication network and, more particularly, to methods and apparatus for dynamically establishing tunnel access sessions in a network device within a communication network. Background of the invention
Although desktop computers generally remain as part of the same network for a substantial period of time, portable computers or other such computers are specifically designed to be portable. As such, notebook computers connect to different networks at different times depending on the location of the computer. In one of the common examples, in which the laptop acts as a worker's desktop computer, the laptop is configured to communicate with your company network, ie the company network. However, when the worker travels, the laptop can be connected to different networks that communicate in different ways. In connection with this, the worker can connect the laptop to the network maintained by an airport or a hotel to access the company network, the Internet or some other online service. However, since these other networks are configured somewhat differently, the notebook must also be reconfigured to communicate properly with these other networks. Typically, this configuration is performed by the user / subscriber each time the laptop connects to a different network. As will become apparent, this repeated reconfiguration of the laptop is not only time consuming, but also prone to errors. In addition, the user / subscriber is often required to have specific software running on the laptop to communicate with the company network, although such communications may conflict with the network through which the laptop must transfer. data to reach the company network.
A gateway device acts as an interface that connects the user / subscriber to a number of networks or other online services. For example, the gateway device can act as a gateway to the Internet, the corporate network, or other networks and / or online services. In addition to acting as a gateway, the gateway device automatically adapts to the host's protocols and other parameters so that it can communicate with the new network in a way that is transparent to both the user / subscriber and the new network. Once the gateway device has adapted properly to the user's host, the host can communicate properly over the new network, for example, a hotel, home, airport, or other location network. , to access other networks, such as the company network, or other online services, such as the Internet.
The user / subscriber, and more specifically the remote user or laptop user, benefits from being able to access a multitude of networks without having to go through the time-consuming and all too often daunting task of reconfiguring their host based on specific network settings. In this way, the gateway device is able to provide more efficient access to the network for the user / subscriber. A gateway device also contributes by providing the user / subscriber with broadband network access that can be customized according to the needs of the user / subscriber. In many cases, the remote user / subscriber is concerned about having network access to their home or business networks, which are typically protected by a firewall. The firewall prevents unauthorized access to the company network through a general Internet connection, for example through an Internet service provider. Although it is possible to have some access from outside the firewall, for example incoming e-mail, in general access to business resources such as network databases and application programs is not accessible to hosts located outside the firewall unless be that the user / subscriber has an active account with a valid username and password combination.
On the other hand, as those of ordinary skill in the art will observe, different network protocols can be used within the Internet infrastructure and within enterprise networks, posing potential access problems for the remote user. For example, at the network protocol level an Internet Protocol (IP) is typically used to send data over the Internet. On the other hand, a business network can use any one of a variety of network protocols including IP, IPX, Appletalk, and so on. If the IP protocol and the company network protocol are incompatible, then the remote user may be prevented from accessing resources on the company network. Additionally, when a remote user attempts to access the corporate network over the Internet, typically through an Internet service provider, the remote user is dynamically assigned an IP address. This IP address identifies the user / subscriber of the host and allows the correct routing of IP packets to and from the host. However, the remote user may be denied access by the corporate network firewall because the IP address assigned by the Internet service provider is not one of the authorized addresses on the corporate network.
In response to these and other problems associated with granting remote access to a company network over the Internet, several techniques have been developed to create virtual private networks (VPNs), in which a remote node on a single network is interconnected using a publicly accessible means of communication. For example, there are a number of systems that allow users / subscribers to create virtual networks using the Internet as a medium to transport data between the company network and a remote user. These systems often include encryption and other security mechanisms to ensure that only authorized users can access the virtual network, and that data cannot be intercepted.
The most common technique for building a VPN is by implementing tunneling. Tunneling works by encapsulating or wrapping a pa2
ES 2 263 496 T3 quete or a message from one protocol of one network into the protocol of another. The encapsulated packet is transmitted over the network through the wrap around network protocol. This method of packet transmission avoids the limitations of protocols, and allows remote users to have uninterrupted access to your company network without any apparent effect of accessing your company network through another network that has a different protocol. Several relatively well-known tunneling protocols include Microsoft's PPTP, Cisco's Layer Two Forwarding (L2F) protocol, and IETF's L2TP which is a hybrid of L2F and PPTP. Another technique that tunneling uses is the encapsulation of the point-to-point protocol that is described in EP 0.917.318. In the article "Dial-In Virtual Private Networks Using Layer 3 Tunnably" by Gay Scott Malkin, IEEE 1997, November, yet another tunneling technique is described. Although these and other tunneling techniques have certain advantages, not a single tunneling protocol provides automated setup without the need for special software on the client side (ie, on the remote computer).
For this reason, there is an unmet need in the industry for a system and method that dynamically create subscriber tunnels automatically and without the need for a pre-established relationship between an Internet access point and a remote company network.
Summary of the invention
The present invention comprises a method and apparatus for implementing dynamic tunnel access sessions in a network device within a communication network. Various aspects are defined in the independent claims. Some preferred features are defined in the dependent claims. Tunnel access sessions are created between a network device, typically a gateway device, and a network service, such as the Internet or a corporate intranet, and provide transparent tunnel access sessions for users / subscribers accessing the communication network through the network device. The present invention does not require any special client-side software to be loaded on the subscriber's remote host, and it does not require any manual configuration of the remote host. Instead, the gateway device establishes a tunnel, whereby the gateway device functions as one endpoint and the corporate network functions as the other endpoint. Instead of configuring and reconfiguring the remote host each time a tunneling session is created, the remote host provides the gateway device with the appropriate subscriber profile information necessary to establish a tunneling session with a service. specific network. Thereafter, the gateway device accesses the subscriber profile information each time a tunnel access session is guaranteed for said subscriber to access the network service. Essentially, the gateway device takes over the role of the remote host as the tunnel endpoint, fooling the network service. The tunnel access session that is established from the gateway device to the network service is such that the network service sees the gateway device as if it were the remote host. By allowing the gateway device to function as the endpoint of the tunnel, the remote host is not limited to a single tunnel per session, but can have multiple access sessions per tunnel, established simultaneously during a single logging session on the system.
Brief description of the drawings
Figure 1 is a block diagram of a communication network providing dynamic tunneling for communication between a remote host and a network service, in accordance with an embodiment of the present invention.
Figure 2 is a block diagram of a communication network that provides the dynamic establishment of two simultaneous sessions by tunnels, according to an embodiment of the present invention.
Figure 3 is a flow chart of a method for creating and managing tunnels in a communication network, according to an embodiment of the present invention.
Detailed description of the preferred embodiments
The present invention will now be more fully described with reference to the accompanying drawings, in which preferred embodiments of the invention are shown. However, the present invention can be practiced in many different ways and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that the present description will be thorough and complete, and will fully communicate the scope of the invention to those skilled in the art. Throughout memory, like numbers refer to the same items.
Referring now to Figure 1, the communication network 10 including a gateway device 12 is depicted as a block diagram. Typically, the network system includes a plurality of user / subscriber hosts 14 that access the network to gain access to other networks or other online services. For example, hosts can be in communication with ports that are located in different rooms of a hotel, a multi-family residence, or an office building. Alternatively, the hosts can be in communication with ports of an airport, a stadium or the like. The communications network also includes a gateway device that provides an interface between the plurality of hosts and the various networks or other online services. Most of the time the gateway device is located near the hosts in a relatively low position in the fabric of the network as a whole (that is, the gateway will be located in the hotel, the multi-family residence, the airport, etc.). However, the gateway device may be located higher in the overall network fabric, such as at a Network Operations Center (NOC) Point of Presence (PoP), if desired. Although the gateway device can be physically implemented in many different ways, the gateway device typically includes a controller and a memory device in which software is stored that defines the operational characteristics of the gateway device.
ES 2 263 496 T3 gateway. Alternatively, the gateway device can be incorporated into another network device, such as the gatekeeper or router, or the software that defines the operation of the gateway device can be stored on a PCMCIA card that can be inserted into the host to automatically reconfigure the host in order to communicate than with a different communication network.
Typically, the network system 10 also includes a gatekeeper 16 positioned between the hosts 14 and the gateway device 12 to multiplex the signals received from the plurality of hosts over a link to the gateway device. Depending on the medium through which the hosts connect to the gatekeeper, the gatekeeper can be configured in different ways. For example, the gatekeeper can be a digital subscriber line access module (DSLAM) for signals transmitted over regular telephone lines, a cable modem termination system (CMTS) for signals transmitted over coaxial cables. / fiber optic, a wireless access point (WAP) for signals transmitted over a wireless network, a switch, or the like. As also shown in Figure 1, the network system typically includes one or more routers 18 and / or servers (not shown in Figure 1) in communication with a plurality of networks 20 or other online services 22. Although the communication network is represented as having a single router, the communication network can have a plurality of routers, switches, bridges, or the like, which are arranged in some hierarchical configuration to adequately route traffic to and from the various networks or other online services. In this connection, typically the gateway device establishes a link with one or more routers. In turn, the routers establish links to the servers of other networks or other online service providers, such as Internet service providers, based on subscriber selection.
The gateway device 12 is specifically designed to configure hosts 14 that register with the network 10 in a way that is transparent to the subscriber. In the typical network using a Dynamic Host Configuration Protocol (DHCP) service, the DHCP server 24 will initially assign an IP address to a host that is registering with the network through communication with the gateway device. Although illustrated as a separate device with respect to the gateway device 12, the DhCp server 24 may be incorporated into the physical embodiment that houses the gateway device. When opening your web browser or alternatively when attempting to access an online service, the gateway device will typically instruct the subscriber to enter the ID and password corresponding to the desired online service that the subscriber is attempting to access. The gateway device then determines whether the subscriber is authorized to access the service, the level of access and / or the type of service to which the subscriber is authorized according to an Authentication, Authorization and Accounting (AAA).
An AAA server, which is a subscriber record database, may be remote from the gateway device or the AAA database may be embedded in the physical embodiment hosting the gateway device. Assuming that the subscriber has been authenticated and has authorization, typically the gateway device presents new subscribers with a home page or control panel that identifies, among other things, online services or other networks that are accessible through the gateway device. Additionally, the home page displayed by the gateway device may provide information regarding current settings or settings that will govern the access provided to the specific subscriber. As such, the gateway administrator can easily modify parameters or other settings to customize the service for their specific application. Typically, changes to parameters or other settings that potentially use additional network system resources will incur a higher cost, such that the gateway administrator will charge the subscriber a higher fee for their service (for example, an increase in bandwidth).
The home page also allows the subscriber to select the network 20 or other online service 22 that the subscriber wishes to access. For example, the subscriber can access the network of the company in which the host is habitually residing. Alternatively, the subscriber can access the Internet or other online services. Once the subscriber chooses to access a network or other online service, the gateway device establishes a suitable link or tunnel to the desired network or online service, as described in detail below.
After this, the subscriber can freely communicate with the desired network 20 or other online service 22. To support this communication, the gateway device 12 generally performs a packet translation function that is transparent to the user / subscriber. In connection with this, for outgoing traffic from host 14 to the network or other online service, the gateway device changes attributes within the packet coming from the user / subscriber, such as the source address, the checksum , and application-specific parameters, to meet the criteria of the network to which the user / subscriber has accessed. Additionally, the outgoing packet includes an attribute that will tell all incoming packets from the accessed network to be routed through the gateway device. In contrast, inbound traffic, from the network or other online service, that is routed through the gateway device undergoes a translation function in the gateway device so that packets are formatted appropriately for the host. user / subscriber. In this way, the packet translation process that takes place at the gateway device is transparent to the host, which apparently sends and receives data directly from the accessed network. By implementing the gateway device as an interface between the user / subscriber and the network or other online service, the user / subscriber will eliminate the need to reconfigure their host 14 when accessing successive networks.
According to an embodiment of the present invention, the schematic diagram of Fig. 2 represents the dynamic establishment and management of
ES 2 263 496 T3 transparent tunnels for the subscriber in a communication system 10. As illustrated in Fig. 2, a gateway device 12 provides automatic tunnel configuration without the need for specialized client-side software in the host 14 '. In this way, the establishment of the tunnels in the network device is transparent to the subscriber. The tunnel can be implemented simultaneously by multiple subscribers who communicate with the gateway device and who are able to access the network or online service with which the tunnel communicates. Furthermore, the gateway device 12 allows a single user / subscriber to establish two or more tunnels simultaneously since the tunnels do not depend on a specific configuration in the host of the user / subscriber 14 '.
A user / subscriber initially establishes an account with the gateway device 12 through a web browser interface, in which the user / subscriber enters various user-unique data, including those that are necessary to establish connections to the networks and / or or online services to which the user / subscriber wishes to gain access. Typically, for each network the user / subscriber wishes to access, a request will be forwarded to the user / subscriber asking them to enter authorization information (such as a username, a network access identifier, and a password). The information entered by the user / subscriber will be used to create a profile that will be stored in the authorization file in the AAA module 30 of the gateway device 12. These user-specific profiles will then be used, in turn, by the network device, in determining whether to create a tunnel when a user / subscriber requests access. The user / subscriber will be provided the ability to add, delete and / or modify their profile, including information to establish tunnels. Additionally, the administrator of the network device can provide a tunnelled connection for a user / subscriber by modifying the user / subscriber profile in the AAA module. Typically, a group of users / subscribers are provided tunnelled connections by modifying a group profile in a database table that can be internal or external to the network device. The network device administrator can use Lightweight Directory Access Protocol (LDAP) or a similar communication link to implement the modifications to the group profiles.
Although the AAA module 30 is illustrated as an integral component of the gateway device 12, it should be noted that the AAA module 30 can be arranged in a remote location, serves as a hub for and is accessible by a plurality of network devices that implement establishing transparent tunneling for the subscriber. For example, a regional or national chain of hotels that provides seamless network access to occupants of various hotel rooms may use a plurality of network devices.
At the start of a new network access session by the user / subscriber, the user / subscriber registers in the gateway device 12 by entering the username and password of his account. The user / subscriber can then select access to one or more of the networks and / or online services available through the gateway device 12. For example, as illustrated in Fig. 2, the host user / subscriber 14 'has simultaneously established access to three independent networks, two of which are being accessed through dedicated tunnels. A first tunnel 32 provides access to network 20 ', tunnel 32 was established when the user / subscriber requested access to network service 20', typically from a web browser interface, which caused a notification packet to be sent setup from the user / subscriber host 14 'to the gateway device 12. Network device 12 identifies the packet as originating from the user / subscriber by cross-referencing a specific subscriber identifier, typically the packet's MAC address, IP address, or originating port identifier with the corresponding authorization table in the AAA 30 module. By relating the subscriber identifier on the packet to the user / subscriber profile (in which the user / subscriber provided a list of networks to access via a tunnel), the gateway device 12 can determine if a tunnel is needed to providing the user / subscriber access to the network service 20 '. If no tunnel is required, then the user / subscriber is provided with standard network access. However, if a tunnel is required, the tunnel management module 44 of the gateway device 12 determines whether a tunnel to the network service 20 'has already been established, and if so, places the packet in the existing tunnel. If no tunnel exists, then the tunnel management module 44 establishes a tunnel using the profile information provided by the user / subscriber during account creation and / or subsequent modification. If the user / subscriber did not provide all the information necessary to establish the tunnel connection due to, for example, doubts regarding the security of the information, the user / subscriber is presented with a request for additional information via a page web or through an information and control console panel on the host that requests the missing information.
Tunnel management module 44 contacts network service 20 'to establish tunnel access to network service 20', typically through a firewall 34 or other secure access server. Using the authorization information provided when the user / subscriber initially establishes their account (for example, a username, a network access identifier, and a password), the gateway device 12 is given access to the network service. 20 ', assuming that the network service 20' authenticates and accepts the connection. The resulting tunnel established by the tunnel management module 44 occurs between the gateway device 12 and the network service 20 'and can be implemented by means of any suitable tunneling protocol supported by the network service 20', such as L2TP, PPTP or PPPoE. From the perspective of the server side of the network service 20 ', the fact that the tunnel ends at the gateway device 12 instead of the user / subscriber host 14' cannot be detected. Essentially, the gateway device 12 tricks the network service 20 'into believing that the tunnel extends entirely to an end point at the user / subscriber host 14'. However, since the extreme point is at the
ES 2 263 496 T3 gateway device 12 instead of on user / subscriber host 14 ', multiple tunnels can be established simultaneously during a single session because the tunnels do not depend on the specific software configuration on the user host / subscriber 14 '. Additionally, the tunnel management module 44 of the gateway device 12 can dynamically create a tunnel on behalf of a user / subscriber using the network registration information provided by the user / subscriber. The session management module 42 manages the access sessions of each subscriber accessing the communications network through the network device, recording information about the sessions as desired. The session management module provides tables of routes and services available to one or more subscribers in the communication network. The tables provide the means to compare the authorized services / networks of a given subscriber with those that require tunnelled communication.
As illustrated in Fig. 2, a second tunnel 36 is established on behalf of the user / subscriber to provide access to the network service 20 "through the firewall 38. The tunnel 36 can be established in substantially the same manner as the described above in relation to tunnel 32. Additionally, the user / subscriber may be granted access to other networks and / or online services that do not require a tunnel connection, such as the global multimedia mesh portion of the Internet 40.
As mentioned above, the user / subscriber host 14 'does not require any specific client-side software to access the network services 20', 20 ", but only requires a standard communication protocol to communicate with the host. gateway device 12, for example, TCP / IP. Once established, tunnels 32, 36 can receive data packets from individual networks in virtually any protocol. This situation is made possible by the network device that decapsulates data packets as they exit a tunnel in preparation for transmission to the subscriber host. The tunnels can be terminated by means of an explicit command from the network service 20 ', 20 "or the user / subscriber host 14'. Alternatively, the tunnels can be interrupted if they are not used within a certain predetermined period of time.
Referring to Fig. 3, a flow chart of a tunnel management methodology in accordance with the environment of the present invention is illustrated. In block 50, the network device receives a packet destined for a tunnelled service or an explicit request for access to the network from a user / subscriber. The request for access to the network may come from an entry of access request data (i.e. username, password, etc.) by a user / subscriber or the information may be stored in memory on the user's host / subscriber, automatically generating the access request. Once the packet or request has been received at the network device, the user / subscriber is then authorized to access the network using a subscriber identifier in the header of the network access request packets to search the user / subscriber profile in the AAA module, as indicated by means of block 52. In block 54, within the tunnel management module of the network device, a determination is made to find out if the destination IP address of the packet that is being sent from the user / subscriber is associated with a network service that requires a tunnel for access. If the destination IP address does not require any tunnel for access, then the user / subscriber is provided with standard network access, as indicated by block 56.
If the tunnel management module determines that the destination IP address is associated with a network service that requires tunneling for that particular subscriber, then at block 58, it is determined whether a tunnel has already been established. If a tunnel has been established, then at block 60, the packet is encapsulated using the tunneling protocol appropriate for that network service, and any other translation or routing instructions are carried out that are relevant to the packet. data. Once the encapsulation / translation of the packet is complete, it is placed in the tunnel to be delivered to the network service.
If in block 58, the tunnel management module determines that no tunnel has yet been established for the requested network, in that case, in block 62, it is determined if additional subscriber data not provided in the profile is required. subscriber of the AAA module, to register with the network service in order to establish a tunnel between the network service and the gateway device. If additional subscriber data is required, then at block 64, a subscriber data request packet is sent from the gateway device to the user / subscriber. The data request may take the form of an information and control panel presented at the user / subscriber host, or the user / subscriber may be directed to a web page or a similar data request method may be used.
If no additional subscriber data is necessary or once the subscriber data has been obtained, then a tunnel is created with the destination network using, if necessary, the registration information in the subscriber's network. The tunnel is created with the gateway device as one endpoint, and the destination network as the other endpoint as indicated by block 66. Once the tunnel has been created, the packets that are received from the user / subscriber and destined for the destination network will be encapsulated with the tunneling protocol and placed in the tunnel. The existence of the tunnel ensures that packets coming from the network service are routed through the gateway device before being delivered to the user / subscriber. The gateway device will decapsulate the packets coming through the tunnel from the network service before transmitting the packets to the user / subscriber.
Contents2
3 sheets
Sheet 1 Sheet 2 Sheet 3
179 members in 13 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 16089099 | United States of America | P | |
| 16089099 | United States of America | P | |
| 19990160890P | United States of America | – | |
| 160890P00972302 | – | – | – |
| US19990160890P | – | – | – |
Members179
| Document | Office | Kind | |
|---|---|---|---|
| CA2388601A1 | Canada | A1 | |
| CA2388623A1 | Canada | A1 | |
| CA2388628A1 | Canada | A1 | |
| CA2698604A1 | Canada | A1 | |
| CA2725720A1 | Canada | A1 | |
| CA2737890A1 | Canada | A1 | |
| WO0131843A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0131855A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0131861A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO0131883A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0131885A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0131886A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO0131889A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU1088501A | Australia | A | |
| AU1098301A | Australia | A | |
| AU1224101A | Australia | A | |
| AU1224201A | Australia | A | |
| AU1224301A | Australia | A | |
| AU1340401A | Australia | A | |
| AU2297601A | Australia | A | |
| WO0133808A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2614401A | Australia | A | |
| WO0131886A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0133808A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0131885A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0131843A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0131855A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0131889A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO0235797A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU1336702A | Australia | A | |
| WO0131855A9 | World Intellectual Property Organization (WIPO) | A9 | |
| WO0131883A3 | World Intellectual Property Organization (WIPO) | A3 | |
| KR20020059640A | Republic of Korea | A | |
| EP1222775A2 | European Patent Office (EPO) | A2 | |
| EP1222791A2 | European Patent Office (EPO) | A2 | |
| EP1224788A2 | European Patent Office (EPO) | A2 | |
| EP1226687A2 | European Patent Office (EPO) | A2 | |
| WO0133808A9 | World Intellectual Property Organization (WIPO) | A9 | |
| EP1232610A1 | European Patent Office (EPO) | A1 | |
| EP1234425A2 | European Patent Office (EPO) | A2 | |
| KR20020070268A | Republic of Korea | A | |
| KR20020075365A | Republic of Korea | A | |
| WO0235797A3 | World Intellectual Property Organization (WIPO) | A3 | |
| IL149188D0 | Israel | D0 | |
| IL149223D0 | Israel | D0 | |
| IL149227D0 | Israel | D0 | |
| WO0131861A9 | World Intellectual Property Organization (WIPO) | A9 | |
| CN1391754A | China | A | |
| CN1408169A | China | A | |
| JP2003513514A | Japan | A | |
| JP2003513522A | Japan | A | |
| JP2003513524A | Japan | A | |
| WO0235797A9 | World Intellectual Property Organization (WIPO) | A9 | |
| CN1433622A | China | A | |
| US6636894B1 | United States of America | B1 | |
| WO0133808A8 | World Intellectual Property Organization (WIPO) | A8 | |
| EP1224788B1 | European Patent Office (EPO) | B1 | |
| AT270014T | Austria | T | |
| ATE270014T1 | Austria | T1 | |
| DE60011799D1 | Germany | D1 | |
| US6789110B1 | United States of America | B1 | |
| CN1178446C | China | C | |
| AU779137B2 | Australia | B2 | |
| ES2221868T3 | Spain | T3 | |
| US6868399B1 | United States of America | B1 | |
| EP1222791B1 | European Patent Office (EPO) | B1 | |
| AT297095T | Austria | T | |
| ATE297095T1 | Austria | T1 | |
| DE60020588D1 | Germany | D1 | |
| DE60011799T2 | Germany | T2 | |
| ES2243319T3 | Spain | T3 | |
| CN1233129C | China | C | |
| KR100559357B1 | Republic of Korea | B1 | |
| DE60020588T2 | Germany | T2 | |
| EP1226687B1 | European Patent Office (EPO) | B1 | |
| AT327618T | Austria | T | |
| ATE327618T1 | Austria | T1 | |
| DE60028229D1 | Germany | D1 | |
| EP1234425B1 | European Patent Office (EPO) | B1 | |
| AT335340T | Austria | T | |
| ATE335340T1 | Austria | T1 | |
| DE60029819D1 | Germany | D1 | |
| AU2006207853A1 | Australia | A1 | |
| US7117526B1 | United States of America | B1 | |
| US2006239254A1 | United States of America | A1 | |
| ES2263496T3This record | Spain | T3 | |
| JP3880856B2 | Japan | B2 | |
| KR100687837B1 | Republic of Korea | B1 | |
| DE60029819T2 | Germany | T2 | |
| DE60028229T2 | Germany | T2 | |
| US7194554B1 | United States of America | B1 | |
| US7197556B1 | United States of America | B1 | |
| ES2269195T3 | Spain | T3 | |
| CN1314253C | China | C | |
| KR100734965B1 | Republic of Korea | B1 | |
| EP1819108A2 | European Patent Office (EPO) | A2 | |
| AU2006207853B2 | Australia | B2 | |
| EP1855429A2 | European Patent Office (EPO) | A2 | |
| IL149188A | Israel | A | |
| IL149227A | Israel | A |
Numbers
- Publication
- 2263496
- Publication, DOCDB
- 2263496
- Publication, EPODOC
- ES2263496T
- Application
- 972302
- Application, DOCDB
- 00972302
- Application, EPODOC
- ES20000972302T
Titles2
- Spanish
- ESTABLECIMIENTO DE SESIONES DE ACCESO DINAMICO POR TUNELES EN UNA RED DE COMUNICACIONES.
- English
- ESTABLISHMENT OF DYNAMIC ACCESS SESSIONS BY TUNNELS IN A COMMUNICATIONS NETWORK.
Classification
- CPC, 8
- H04L63/0272
- H04L12/2872
- H04L12/2876
- H04L12/4633
- H04L63/083
- H04L63/102
- H04L67/30
- H04L69/329
- IPC, 4
- H04L12 46
- H04L12 28
- H04L29 06
- H04L29 08