US2015067814A1PendingUtilityA1

Methods And Systems For Providing Controlled Access To The Internet

Assignee: ALCATEL LUCENT USA INCPriority: Dec 29, 2006Filed: Nov 6, 2014Published: Mar 5, 2015
Est. expiryDec 29, 2026(~0.4 yrs left)· nominal 20-yr term from priority
H04L 63/0823H04L 63/101H04L 63/10H04L 63/123
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Novel, Internet-related architectures, methods and devices are proposed that are based on a fundamentally different philosophy: hosts (e.g., source and destination nodes) are given the ability to specify their access control policies to the network they are a part of, and the network enforces these policies. The architecture proposed is mobility friendly to the ever increasing number of mobile hosts and is scalable as well.

Claims

exact text as granted — not AI-modified
1 - 4 . (canceled) 
     
     
         5 . A method for controlling access to nodes in a network comprising:
 receiving an authorization request message (AUTHREQ) from a source node, the (AUTHREQ) including a source access certificate (SAC), via a signaling and control pathway;   comparing the SAC to stored access and denial values associated with at least one destination node;   forwarding the (AUTHREQ) to the at least one destination node as a high priority request via the signaling and control pathway when the comparison indicates the SAC matches an access value;   forwarding the (AUTHREQ) to the at least one destination node as a low priority request via the signaling and control pathway when the comparison indicates the SAC does not match an access or denial value; and   declining to forward the (AUTHREQ) to the at least one destination node when the comparison indicates the SAC matches a denial value.   
     
     
         6 . The method as in  claim 5  further comprising storing access and denial values for a plurality of destination nodes,
 wherein the access values for each corresponding destination node indicate those sources that are authorized to send data packets to the corresponding destination node and the denial values for each corresponding destination node indicate those sources that are not authorized to send data packets to the corresponding destination node. 
 
     
     
         7 - 12 . (canceled) 
     
     
         13 . A system for controlling access to nodes in a network, the system comprising one or more distributed hash table (DHT) servers operable to:
 receive an authorization request message (AUTHREQ) from a source node, the (AUTHREQ) including a source access certificate (SAC), via a signaling and control pathway;   compare the SAC to stored access and denial values associated with at least one destination node;   forward the (AUTHREQ) to the at least one destination node as a high priority request via the signaling and control pathway when the comparison indicates the SAC matches an access value;   forward the (AUTHREQ) to the at least one destination node as a low priority request via the signaling and control pathway when the comparison indicates the SAC does not match an access or denial value; and   decline to forward the (AUTHREQ) to the at least one destination node when the comparison indicates the SAC matches a denial value.   
     
     
         14 . The system as in  claim 13 , wherein one or more of the DHT servers is further operable to store access and denial values for a plurality of destination nodes,
 wherein the access values for each corresponding destination node indicate those sources that are authorized to send data packets to the corresponding destination node and the denial values for each corresponding destination node indicate those sources that are not authorized to send data packets to the corresponding destination node.   
     
     
         15 - 16 . (canceled)

Join the waitlist — get patent alerts

Track US2015067814A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.