US2007005765A1PendingUtilityA1

Network access control using network address translation

Assignee: MICROSOFT CORPPriority: Jan 24, 2000Filed: Jun 30, 2006Published: Jan 4, 2007
Est. expiryJan 24, 2020(expired)· nominal 20-yr term from priority
H04L 61/2591H04L 67/56H04L 67/563H04L 67/564H04L 63/10H04L 63/0227H04L 63/0281
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An improved network content filtering system and method utilize the network address translation functionality of a shared network connection to redirect outgoing packets from a client intended for a destination web server to an access controlling web server instead. Before a session to the destination web server is established, the access controlling web server either approves or refuses the connection, providing a content filtering mechanism. If the connection is refused, the access controlling web server may substitute other content for a filtered URL. In order to identify the client, the shared connection may additionally embed an identifier token in the redirected traffic, so as to customize the filtering action or to facilitate billing functions.

Claims

exact text as granted — not AI-modified
1 - 32 . (canceled)  
   
   
       33 . A computer-implemented system that controls access to remote resources comprising the following computer-executable components: 
 a client component that transmits a packet comprising connection setup information and a destination address, the destination address is an Internet Protocol (IP) address corresponding to an intended destination server;    a gateway component that receives the packet, rewrites the destination address, and redirects the packet; and    an access control component that receives the redirected packet and determines whether the client component is granted access to the intended destination server.    
   
   
       34 . The system of  claim 33 , the gateway component redirects the entirety of the packet.  
   
   
       35 . The system of  claim 33 , the packet transmitted by the client comprises a request for a resource from the intended destination server.  
   
   
       36 . The system of  claim 35 , the resource is at least one of an audible resource, a readable resource, a viewable resource, and an Universal Resource Locator (URL) resource.  
   
   
       37 . The system of  claim 33 , the gateway component receives access information from the access control component.  
   
   
       38 . The system of  claim 33 , the gateway component forbids client component access to the intended destination server if the access control component determines access is not granted.  
   
   
       39 . The system of  claim 38 , the gateway component establishes a connection session between the client component and the access control component.  
   
   
       40 . The system of  claim 33 , the gateway component establishes a connection session between the client component and the intended destination server if the access control component determines access is granted.  
   
   
       41 . The system of  claim 40 , the connection session is transparent with respect to the client component.  
   
   
       42 . The system of  claim 40 , the gateway component monitors subsequent packets on the fly to determine when the client component attempts to establish a connection with a different destination.  
   
   
       43 . The system of  claim 33 , the gateway component is remote from the client component, the gateway component is coupled to the client component by way of a first network.  
   
   
       44 . The system of  claim 43 , the gateway component is remote from the intended destination server and the access control component, the gateway component is coupled to the intended destination server and the access control component by way of a second network.  
   
   
       45 . The system of  claim 33 , the access control component is an RSACi Web Server.  
   
   
       46 . The system of  claim 33 , the access control component determines whether the client component is granted access to the intended destination server based at least in part upon a resource requested from the intended destination server.  
   
   
       47 . The system of  claim 33 , the access control component determines whether the client component is granted access to the intended destination server based at least in part upon an identity of the client component.  
   
   
       48 . The system of  claim 33 , the access control component determines whether the client component is granted access to the intended destination server based at least in part upon an URL of the intended destination server.  
   
   
       49 . The system of  claim 33 , the access control component embeds in a packet an identity token that uniquely identifies the client component.  
   
   
       50 . In a computer network environment comprising a client, a hosting server, an access controlling server, and a gateway interposed between the client and both the hosting server and the access controlling server, a method for controlling access of the client to a desired resource hosted on the hosting server, comprising: 
 receiving at the gateway a request packet from the client for the desired resource;    redirecting the entire request packet to the access controlling server;    receiving at the gateway a permission notification from the access controlling server in response to the redirected request packet; and    choosing to either grant or deny access of the client machine to the desired resource based at least in part upon the permission notification.    
   
   
       51 . The method of  claim 50 , further comprising establishing a connection session between the client and at least one of the hosting server and the access controlling server based at least in part upon whether access was granted or denied.  
   
   
       52 . A computer-implemented system for controlling access to remote resources comprising: 
 a computer-implemented means for rewriting a destination address of a packet to a new destination address and redirecting the entirety of the packet to the new destination address;    a computer-implemented means for determining at the new destination address if access to the destination address should be allowed; and    a computer-implemented means for creating a connection to at least one of the destination address and the new destination address based upon the access determination.

Join the waitlist — get patent alerts

Track US2007005765A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.