System for managing sessions and connections in a network
Abstract
A modular architecture for use in a network device such as a Remote Authentication Server (RAS) includes a number of interconnected objects associated with processes, services, access protocols and other functionality provided on the device. Objects may also be associated with users, sessions or other data structures that may be accessed by any of the functional objects in the device. Additional services and updates may easily be implemented into this architecture without disrupting user connections. Redundant copies of the objects may be maintained in memory to facilitate the provision of carrier grade performance by swapping out failed components m the event of a fault.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A connection management system, comprising:
a plurality of session managers, each session manager for controlling access by users to resources of a system; a shared repository of data and processes; and an aggregation controller, for controlling communication between the plurality of session managers and the shared repository of data and processes.
2 . The connection management system of claim 1 , wherein the resources of the system include applications available in the system, and wherein access to the applications is restricted to a subset of the plurality of session managers.
3 . The connection management system of claim 1 , wherein the aggregation controller controls distribution of addresses from a pool of addresses among the plurality of session managers.
4 . The connection management system of claim 1 , wherein the session managers are distributed on physical devices in a network.
5 . The connection manager of claim 1 , wherein at least two of the plurality of session managers execute on a common device.
6 . The connection management system of claim 1 , further comprising an object-oriented library of available applications, and wherein each of the plurality of session managers maintains a relational database for at least one session, the relational database including:
at least one application object instance, the application object instance being derived from the library of available applications responsive to a request for the application by a user; and at least one user record, associated with the user, and including configuration information linking the user to the at least one application object instance.
7 . The connection management system of claim 1 , wherein each session manager comprises:
a plurality of handler objects, each of the handler objects including pointers to program code associated with a function of the handler object; an event dispatcher, disposed to receiving event indicators and to forward the event indicators to at least one of the handler objects; and a relational database for storing information linking the user to at least one of the handler objects.
8 . A method of managing a plurality of connections, comprising:
providing a plurality of session managers, each session manager for controlling access by users to resources of a system; providing a shared repository of data and processes; providing an aggregation controller; and operating the aggregation controller to control communication between the plurality of session managers and the shared repository of data and processes.
9 . The method of claim 8 , wherein the resources of the system include applications available in the system, and wherein access to the applications is restricted to a subset of the plurality of session managers.
10 . The method of claim 8 , wherein the aggregation controller controls distribution of addresses from a pool of addresses among the plurality of session managers.
11 . The method of claim 8 , wherein the session managers are distributed on physical devices in a network.
12 . The method of claim 8 , wherein at least two of the plurality of session managers execute on a common device.
13 . The method of claim 8 , further comprising:
providing an object-oriented library of available applications; and maintaining, by each of the plurality of session managers, a relational database for at least one session, the relational database including:
at least one application object instance, the application object instance being derived from the library of available applications responsive to a request for a respective application by a user; and
at least one user record, associated with the user, and including configuration information linking the user to the at least one application object instance.
14 . The method of claim 8 , wherein each session manager comprises:
a plurality of handler objects, each of the handler objects including pointers to program code associated with a function of the respective handler object; an event dispatcher, disposed to receiving event indicators and to forward the event indicators to at least one of the handler objects; and a relational database for storing information linking a user to at least one of the handler objects.
15 . The method of claim 8 , comprising storing a user record for each active connection, the user record comprising an object having a plurality of attributes and indicating at least one service associated with the user connection.
16 . The method of claim 15 , comprising generating the user record by using an existing template associated with a respective user to define the attributes of the user connection.
17 . The method of claim 15 , wherein the attributes of the user connection include access properties of the user connection.
18 . The method of claim 15 , wherein the attributes of the user connection include tunneling properties of the user connection.
19 . The method of claim 15 , wherein the attributes of the user connection include routing properties associated with the user connection.
20 . The method of claim 15 , wherein the attributes of the user connection include traffic management services associated with the user connection.
21 . The method of claim 15 , wherein the attributes of the user connection include user properties associated with the user connection.
22 . The method of claim 15 , comprising authenticating user connections to a device.
23 . The method of claim 22 , wherein authenticating user connections comprises:
determining, for each user connection request received at an interface of the device, whether a domain of the request is available on the interface; and responsive to the domain being available on the interface, generating the user record for the user connection, the user record storing the attributes of the user connection.Join the waitlist — get patent alerts
Track US2013254410A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.