Providing secure internet access to a client device in a remote location
A system for providing a client device in a remote location secure access to the internet via a satellite connection is provided includes: a client device: a satellite system configured to provide the client device with access to the internet; and an internet service provider (ISP), wherein, during a registration process: the satellite system is configured to receive a first blockchain state signal which encodes information about a first state of a blockchain, and to generate and transmit a first RF broadcast signal encoding the information about the first state of the blockchain: the client device is configured to receive the first RF broadcast signal, to generate a registration request based on the information about the state of the blockchain, the registration request including a public key ID associated with the client device, and to be transmitted to an electronic address corresponding to a blockchain associated with the ISP, and to transmit the registration request to the satellite system: the satellite system is configured to receive the registration request, and to transmit it to the electronic address associated with the ISP; the ISP is configured to determine whether the registration request is a valid request, and if the registration request is a valid request, to add the public key ID to an authorized list, wherein when a public key ID is on the authorized list, the client device or user thereof is permitted to access the internet via the satellite system. Similar methods and systems relation to connection requests are also provided.
1 . A system for providing a client device in a remote location secure access to the internet via a satellite connection is provided, the system including:
a client device;
a satellite system configured to provide the client device with access to the internet; and
an internet service provider (ISP), wherein the ISP or the satellite system comprises an authorization module,
wherein, during a registration process:
the satellite system is configured to receive a first blockchain state signal which encodes information about a first state of a blockchain, and to generate and transmit a first RF broadcast signal encoding the information about the first state of the blockchain;
the client device is configured to receive the first RF broadcast signal, to generate a registration request, the registration request including a public key ID associated with the client device and a deterministic transformation of contents of at least a portion of a previous block of the blockchain, and to be transmitted to an electronic address corresponding to a blockchain associated with the ISP, and to transmit the registration request to the satellite system;
the satellite system is configured to receive the registration request, and to transmit the registration request to the electronic address associated with the ISP;
the ISP is configured to determine whether the registration requestis a valid request, and based on the registration request being a valid request, to add the public key ID to an authorized list, wherein public key IDs on the authorized list indicate client devices that are permitted to access the internet via the satellite system; and
the authorization module is configured to grant the client device access to the internet by encrypting a connection session key with a public encryption key associated with the client device, to generate an encrypted connection session key, and sending the encrypted connection session key to the client device, the encrypted connection session key being decryptable by using a private decryption key which is complementary to the public encryption key, and the decrypted connection session key being usable to access the internet.
2 . The system of claim 1 , wherein:
the electronic address is an electronic address of a blockchain wallet associated with the ISP;
the registration request includes authentication data comprising a signature generated using a private signature key of the client device from which the registration request is received; and
the public key ID is a public verification key which corresponds to the private signature key used to generate the signature.
3 . The system of claim 1 , wherein:
the ISP or the satellite system includes, or has associated therewith, an access management system to manage access, via the satellite system, to the internet, the access management system comprising a request management system configured to:
receive the registration request from the satellite system or a satellite of the satellite system; and
determine whether the registration request received at the electronic address meets a validation criterion, wherein:
in response to the request management system determining that the registration request received at the electronic address meets the validation criterion, the request management system is configured to determine that the registration request is a valid request; and
in response to the request management system determining that the registration request received at the electronic address does not meet the validation criterion, the request management system is configured to determine that the registration request is not a valid request.
4 . The system of claim 1 , wherein:
the satellite system is configured to transmit an i th RF broadcast signal at a time t i,0 , and re-transmit the i th RF broadcast signal a plurality N times, where a j th re-transmission takes place at t i,j .
5 . The system of claim 4 , wherein:
after missing a transmission of the i th RF broadcast signal at a time t i,0 , the client device is configured to:
receive a retransmitted version of the i th RF broadcast signal from a subsequent history H m at a time t i,m where m>0, the retransmitted version of the i th RF broadcast signal encoding information about an i th state of the blockchain; and
store the information about the i th state of the blockchain in a memory of the client device.
6 . The system of claim 1 , wherein:
the registration request comprises a public encryption key associated with the client device.
7 . A system for providing a client device in a remote location secure access to the internet via a satellite connection, the system including:
a client device;
a satellite system configured to provide the client device with access to the internet; and
an internet service provider (ISP), wherein the ISP or the satellite system comprises an authorization module,
wherein, during a connection process:
the client device is configured to generate a connection request including a public key ID associated with that client device, and to transmit the connection request to the satellite system via an RF signal;
in response to receiving the connection request, the satellite system is configured to transmit the connection request to the ISP, and the ISP is configured to determine whether the public key ID is on an authorized list;
in response to determining that the public key ID is on the authorized list, the satellite system is configured to grant access to the internet via an internet access broadcast signal and forward data between the client device and a remote computing system; and
the authorization module is configured to grant the client device access to the internet by encrypting a connection session key with a public encryption key associated with the client device, to generate an encrypted connection session key, and sending the encrypted connection session key to the client device, the encrypted connection session key being decryptable by using a private decryption key which is complementary to the public encryption key, and the decrypted connection session key being usable to access the internet.
8 . The system of claim 7 , wherein:
the connection session key is a rotating session key.
9 . The system of claim 7 , wherein:
the connection request comprises the public encryption key associated with the client device.
10 . The system of claim 7 , wherein:
the satellite system comprises a Geosynchronous or Mid-Earth Orbit satellite.
11 . A method of providing a client device in a remote location secure access to the internet via a satellite connection, the method comprising:
at a satellite system: receiving a first blockchain state signal which encodes information about a first state of a blockchain; and generating and transmitting a first RF broadcast signal encoding information about the first state of the blockchain;
at a client device: receiving the first RF broadcast signal; generating a registration request including a public key ID associated with the client device and a deterministic transformation of contents of atleast a portion of a previous block of the blockchain; and transmitting the registration request to the satellite system;
at the satellite system: receiving the registration request; and transmitting the registration request to an electronic address corresponding to a blockchain associated with an internet service provider (ISP);
at the ISP: determining whether the registration request is a valid registration request, and based on the registration request being a valid request, adding the public key ID to an authorized list, wherein public key IDs on the authorized list indicate client devices that are permitted to access the internet via the satellite system; and
at an authorization module that is included in the ISP or the satellite system, granting the client device access to the internet by encrypting a connection session key with a public encryption key associated with the client device, to generate an encrypted connection session key, and sending the encrypted connection session key to the client device, the encrypted connection session key being decryptable by using a private decryption key which is complementary to the public encryption key, and the decrypted connection session key being usable to access the internet.
12 . The method of claim 11 , wherein:
the electronic address is an electronic address of a blockchain wallet associated with the ISP;
the registration request includes authentication data comprising one or more of:
a deterministic transformation of contents of a previous block of the blockchain, or a portion thereof; and
a signature generated using a private signature key of the client device from which the registration request is received; and
the public key ID is public verification key which corresponds to the private signature key used to generate the signature.
13 . The method of claim 11 , wherein:
the ISP or the satellite system includes, or has associated therewith, an access management system to manage access, via the satellite system, to the internet, the access management system comprising a request management system configured to:
receive the registration request from the satellite system or a satellite of the satellite system; and
determine whether the registration request received at the electronic address meets a validation criterion, wherein:
in response to the request management system determining that the request received at the electronic address meets the validation criterion, the request management system is configured to determine that the registration request is a valid request; and
in response to the request management system determining that the request received at the electronic address does not meet the validation criterion, the request management system is configured to determine that the registration request is not a valid request.
14 . The method of claim 11 , wherein:
the satellite system is configured to transmit an i th RF broadcast signal at a time t i,0 , and re-transmit the i th RF broadcast signal a plurality N times, where a j th re-transmission takes place at t i,j .
15 . The method of claim 14 , wherein:
after missing a transmission of the i th RF broadcast signal at a time t i,0 , the client device is configured to:
receive a retransmitted version of the RF broadcast signal from a subsequent history H m at a time t i,m where m>0, the retransmitted version of the RF broadcast signal encoding information about an i th state of the blockchain; and
store the information about the i th state of the blockchain in a memory of the client device.
16 . The method of claim 11 , wherein:
the registration request comprises a public encryption key associated with the client device.