WO0235797A2

Systems and methods for providing dynamic network authorization, authentication and accounting

Abstract

Systems and methods for selectably controlling and customizing source access to a network, where the source is associated with a source computer, and wherein the source computer has transparent access to the network via a gateway device and no configuration software need be installed on the source computer to access the network. A user may be prevented access from a particular destination or site based upon the user's authorization while being permitted to access to other sites that the method and system deems accessible. The method and system can identify a source without that source's knowledge, and can access customizable access rights corresponding to that source in a source profile database. The source profile database can be a remote authentication dial-in user service (RADIUS) or a lightweight directory access protocol (LDAP) database. The method and system use source profiles within the source profile database to dynamically authorize source access to networks and destinations via networks.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

32 claims: 4 independent, 28 dependent

  1. 1
    THAT WHICH IS CLAIMED:1. A method for selectably controlling and customizing source access to a network, wherein the source is associated with a source computer, and wherein the source computer has transparent access to the network via a gateway device and no configuration software need be installed on the source computer to access the network, comprising: receiving at the gateway device a request from the source computer for access to the network;identifying an attribute associated with the source based upon a packet transmitted from the source computer and received by the gateway device;accessing a source profile corresponding to the source and stored in a source profile database, wherein the source profile is accessed based upon the attribute, and wherein the source profile database is located external to the gateway device and in communication with the gateway device, and determining the access rights of the source based upon the source profile, wherein access rights define the rights of the source to access the network.
  2. 10
    A system for selectably controlling and customizing access, to a network, by a source, where the source is associated with a source computer, and wherein the source computer has transparent access to the network via a gateway device and no configuration software need be installed on the source computer to access the network, comprising:a gateway device, wherein the gateway device receives a request from the source for access to the network;a source profile database in communication with the gateway device and located external to the gateway device, wherein the source profile database stores access information identifiable by an attribute associated with the source, and wherein the attribute is identified based upon a data packet transmitted from the source computer and received by the gateway device, and an Authentication, Authorization and Accounting (AAA) server in communication with the gateway device and source profile database, wherein the AAA server determines if the source is entitled to access the network based upon the access information stored within the source profile database, and wherein the AAA server determines the access rights of the source, wherein access rights define the rights of the source to access destination sites via the network.
  3. 17
    A method for redirecting a source attempting to access a destination through a gateway device, wherein source is associated with a source computer, and wherein the gateway device enables the source to communicate with a network without requiring the source computer to include network software configured for the network, comprising:receiving at the gateway device a request from the source to access the network;identifying the source based upon an attribute associated with the source;accessing a source profile database located external to the gateway device, the source profile database storing access rights of the source;determining the access rights of the source based upon the identification of the source, wherein the access rights define the rights of the source to access destination sites via the network.
  4. 26
    A system for enabling transparent communication between a computer and a service provider network, comprising:a computer;a network gateway device in communication with the computer for connecting the computer to a computer network, wherein the network gateway device receives source data that represents a user attempting to access the computer network;and a service provider network in communication with the network gateway device, comprising an authentication server located external to the network gateway device and in communication with the network gateway device and having therein a source profile database comprising source profiles that represent users authorized to access the computer network, wherein the authentication server compares the source data to the source profiles to determine if the user attempting to access the computer network can access the computer network.