Arrangement for network access via the telecommunication network by remote-controlled filter
Abstract
The invention relates to an arrangement to check/control access to IP-networks via the telecommunication network. A personal computer is connected via the telecommunication network to an interface pool which constitutes interface between the telecommunication network and the IP-network. According to the invention there is a remote-controlled filter which can be controlled to allow access to the IP-network. An access check/control server checks the authorization of the user of the personal computer and controls the remote-controlled filter depending on the authorization check. The remote-controlled filter initially only allows access to the access check/control server. The access check/control server further can attend to debiting of the user of the personal computer, and check different blocking functions for the access to the IP-network. <IMAGE>

Term
No projected expiry on record.
- Priority and filed
- Granted
- Today
10 claims: 6 independent, 4 dependent
- 1PATENTKRAV 1. Arrangemang för att kontrollera access till IP-nät via telenät, innefattande åtminstone en persondator ansluten via telenätet till en gränssnittspool, som bildar gränssnitt mellan telenätet och IP-nätet, kännetecknat av att åtminstone ett fjärrstyrt filter som kan styras för att medge access till IPnätet och en accesskontrollserver, som kan kontrollera persondatorns användares behörighet och styra det fjärrstyrda filtret i beroende av behörighetskontrollen.
- 2Arrangemang enligt krav 1, kännetecknat av att det fjärrstyrda filtret före behörighetskontrollen endast medger access till accesskontrollservern.
- 3Arrangemang enligt krav 2, kännetecknat av det fjärrstyrda filtrets normalläge efter avslutad access för persondatorns användare är att endast medge access till accesskontrollservern.
- 4Arrangemang enligt något av föregående krav, kännetecknat av att accesskontrollservern ombesörjer debitering av persondatorns användare.
- 5Arrangemang enligt något av föregående krav, kännetecknat av att gränssnittspoolen är en modempool.
- 6Arrangemang enligt något av föregående krav, kännetecknat av att accesskontrollservern som komplement eller alternativ till behörighetskontrollen och debiteringen är anordnad att ombesörja sändning av ett företrädesvis interaktivt reklambudskap till persondatorns användare.
- 7Arrangemang enligt något av föregående krav, kännetecknat av att accesskontrollservern spärrar access till vissa IP-nätadresser.
- 8Arrangemang enligt något av föregående krav, kännetecknat av att accesskontrollservern i beroende av för persondatorns användare individuella behörighetsprofiler spärrar access till vissa IPnätadresser .
- 9Arrangemang enligt krav 8, kännetecknat av att 504 546 6 individuella behörighetsprofiler är lagrade i accesskontrollservern.
- 10Arrangemang enligt krav 8, kännetecknat av fördefinierade behörighetsprofiler är lagrade i det 5 fjärrstyrda filtret, varvid behörighetskontrollen kan innebära att en behörighetsprofil knyts till persondatorns användare. 504 546 Persondator ansluten till modempolen t. ex. med FPP eller SLIP Filter Filter Filter Accesskontrollserver Programmodul (t.ex. ett skript) P-nat t.ex. Internet) 3. Filtret ar oppet för fullständig Internet-access för den uppringande datorns IP-nummer 2. Order om att öppna för fullständig Internetaccess efter kontroll. 1. Filtret tilläter endast access till accesskontrollservern.
Independent claims10
36 paragraphs in 7 sections, as filed
(54)
PATENT HOLDER Telia AB, 123 86 Farsta SE
INVENTOR'S OFFICE
NAME
Mattias Söderhielm, Nacka Strand SE Karlsson B
Arrangements for network access via the telecommunications network filter through remote control (56) (57)
CALLED PUBLICATIONS: - - SUMMARY:
The invention relates to an arrangement for controlling access to IP networks via the telecommunications network. A personal computer is connected via the telecommunications network to an interface pool which forms an interface between the telecommunications network and the IP network. According to the invention there is a remote-controlled filter which can be controlled to allow access to the IP network. An access control server checks the permissions of the personal computer user and controls the remote-controlled filter depending on the access control. Initially, the remote-controlled filter only allows access to the access control server. The access control server can further charge the personal computer users and control various blocking functions for access to the IP network.
<img file="SE504546C2_D0001.tif" />
The numbers mom parentheses indicate international identification code, INID code. Letters in clamps indicate international document code.
504 546
FIELD OF THE INVENTION
The present invention relates to an arrangement for network access, in particular access to TCP / IP networks, e.g. Internet. Access is controlled by a filter that can be remotely controlled by a special server that controls the user's authority and controls access to the IP network. The special access control server allows the access control to be moved from the interface between the telephone network and the IP network, which enables efficiency and extended functionality.
BACKGROUND OF THE ART
In today's system, a user's access rights are controlled and charge for modem pools is provided by a terminal server located at or in the modem pool. Each modem pool thus has its own server which controls the access. This means that the modem pools are unnecessarily burdened with technology and costs.
According to the present invention, a separate access control server is provided which may be located at any location in the system. This means more efficient utilization and also enables increased functionality in the server, as will be explained in more detail below.
SUMMARY OF THE INVENTION
Thus, the present invention provides an arrangement for controlling access to IP networks
504
546
<img file="SE504546C2_D0002.tif" />
over telecommunications networks. The arrangement includes a personal computer connected via the telecommunications network to an interface pool which is the interface between the telecommunications network and the IP network. According to the invention, the arrangement comprises a remote-controlled filter which can be controlled to allow access to the IP network and an access control server which can control the personal computer user's authority and control the remote-controlled filter depending on the access control.
Preferably, the filter's normal mode is to allow access to the access control server only.
The access control server may also provide charging and various blocking functions in accordance with preferred embodiments of the invention.
The invention is defined in detail in the appended claims.
BRIEF DESCRIPTION OF THE DRAWINGS
The invention will be described in detail below with reference to the drawing, the only figure of which is a combined block and flow diagram of a preferred embodiment of the present invention.
DETAILED DESCRIPTION OF PREFERRED EMBODIMENTS The present invention therefore relates to an access control arrangement by means of a server connected at any location on a TCP / IP network, e.g. Internet. The arrangement allows the charge to be handled by the server. The invention also enables advertising financing of the access, ie that you cannot access the network until you have taken part in an advertising message.
The figure shows how a user's personal computer via the telephone network and a modem pool and filter are connected to an IP network. An access control server controls the user's authority and controls a remote-controlled filter to control access. Arrows 1, 2 and 3 describe the steps to open access to the IP network.
A user connects to one via the telephone network <sub>3</sub> 504 546 modem pool or interface pool. By interface pool is here meant any form of equipment that allows a user to disconnect from the telecommunications network to a TCP / IP network. (Transmission Control Protocol / Internet Protocol is an international standard.) In the simplest case, the interface pool consists of a number of modems connected to a terminal server.
The functionality can be combined in one and the same equipment. Furthermore, it does not have to be a modem, it can also e.g. be about ATM or ISDN adapters or cards. The protocol used for communication is typically Point-to-Point Protocol (PPP) or Serial Line Internet Protocol (SLIP). The user either does not need to log into the modem pool or the login identity and password are the same for all users. The user is assigned by the modem pool a (dynamically allocated) IP number, ie an IP address.
A filter (a router connected to a computer or firewall) is connected between the modem pool and the IP network. This filter initially allows the calling user to only access the server where the access control takes place. This can be eg be a World Wide Web server. This is why no special user identification is needed in the modem pool.
After checking the user's authorization and any charges, a program module is activated in the server. This program module now sends a (appropriately encrypted) message to the filter that it should open to that particular user's IP address, so that the user can access more servers (eg all servers) on the IP network. The filter stays in the open position until the user disconnects. Then a message from the modem pool is sent to the filter requesting that the user's IP number be blocked, ie that access should only be allowed to the access control server again. Alternatively, this message can be sent the next time a connected user is assigned the same IP number.
Instead of access control and debiting
504
546
<img file="SE504546C2_D0003.tif" />
takes place in the access control server or in addition to this, the IP network access can be financed advertising. This is done by the user having to take part in an advertising message. When this happens, the application module that opens for the IP network access is activated. In order to ensure that the user has taken part in the advertising message, a number of questions can be asked in connection with it. Only after these have been satisfactorily answered will the IP network access be opened.
The above system can be used to block certain servers in the Internet or other IP networks. This is done by sending messages to all filters about which addresses to block. The filters then block these addresses even after they have been opened for full access by a user.
The above system can also be used to give some users limited access to the IP network. By setting up specific profiles (lists) of which IP network addresses are allowed or not allowed, the filter can be set selectively for a particular user when it opens for IP network access in the access control server. The profiles can be located in the access control server and sent to the filter via the opening. Alternatively, profiles can be predefined in the filter and the only thing sent from the access control server is the message which profile to use.
This functionality can e.g. is used to prevent certain users from accessing certain pornography-related servers.
Thus, the arrangement of the present invention means that the access control is moved out of the interface pool to any location in the system. This means that the number of access control servers required can be reduced and each access control server can thus be made more efficient and offer increased functionality. The hardware and software required to realize the invention are readily apparent to one of ordinary skill in the art. The invention is limited only by the following claims.
504 546
Contents7
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
16 members in 7 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 9502925 | Sweden | A | |
| SE19950002925 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| SE9502925D0 | Sweden | D0 | |
| NO963382D0 | Norway | D0 | |
| FI963200A0 | Finland | A0 | |
| FI963200A | Finland | A | |
| SE9502925L | Sweden | L | |
| NO963382L | Norway | L | |
| SE504546C2This record | Sweden | C2 | |
| EP0762707A2 | European Patent Office (EPO) | A2 | |
| EP0762707A3 | European Patent Office (EPO) | A3 | |
| FI114516B | Finland | B | |
| NO319380B1 | Norway | B1 | |
| EP0762707B1 | European Patent Office (EPO) | B1 | |
| DE69636945D1 | Germany | D1 | |
| DK0762707T3 | Denmark | T3 | |
| ES2284166T3 | Spain | T3 | |
| DE69636945T2 | Germany | T2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Patent has lapsedLapsedNUG | NUG |
Numbers
- Publication, DOCDB
- 504546
- Publication, EPODOC
- SE504546
- Application
- 9502925
- Application, DOCDB
- 9502925
- Application, EPODOC
- SE19950002925
Titles2
- Swedish
- Arrangemang för nätaccess via telenätet genom fjärrstyrt filter
- English
- Arrangement for network access via the telecommunications network through a remote controlled filter
Classification
- CPC, 4
- H04L63/0236
- H04L12/2856
- H04L12/2898
- H04L63/102
- IPC, 2
- H04L12 28
- H04L29 06