IP Library Granted Patent US 7,114,083
Granted Patent B2
US 7,114,083 · App. 10/409,375 · Granted Sep 26, 2006

Secure server architecture for web based data management

Assignee: MCI, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,114,083
App. No.
10/409,375
Granted
Sep 26, 2006
Kind
B2
Abstract

A double firewalled system is disclosed for protecting remote enterprise servers that provide communication services to telecommunication network customers from unauthorized third parties. A first router directs all connection requests to one or more secure web servers, which may utilize a load balancer to efficiently distribute the session connection load among a high number of authorized client users. On the network side of the web servers, a second router directs all connection requests to a dispatcher server, which routes application server calls to a proxy server for the application requested. A plurality of data security protocols are also employed. The protocols provide for an identification of the user, and an authentication of the user to ensure the user is who he/she claims to be and a determination of entitlements that the user may avail themselves of within the enterprise system. Session security is described, particularly as to the differences between a remote user's copper wire connection to a legacy system and a user's remote connection to the enterprise system over a “stateless” public Internet, where each session is a single transmission, rather than an interval of time between logon and logoff, as is customary in legacy systems.

Claims (10)

1. A system for securing an enterprise communications network, comprising:

a first firewall for accepting a service request from a client and permitting access to one or more first preselected addresses in compliance with a first set of filtering rules;

a secure web server, located at one of the first preselected addresses, for establishing a session with the client and receiving the service request via the first firewall, wherein said session is associated with a session identifier encapsulated in a cookie that is generated from a separate server;

a second firewall in communication with the secure web server for accepting the service request from the secure web server and permitting access to one or more second preselected addresses in compliance with a second set of filtering rules; and

a dispatcher server, located at one of the second preselected addresses, for receiving the secure request via the second firewall and, in response, dispatching the service request to a proxy service for applying system resources of the enterprise communication network responsive to the service request.

2. The system for securing an enterprise communications network as claimed in claim 1 wherein said secure web server is further configured for wrapping and unwrapping the cookie at each service request to verify said client to said dispatcher server at each transmission of a service request in said session.

3. A method for securing an enterprise communications network, comprising:

establishing a session with a client in response to receiving a service request from the client via a first firewall permitting access in compliance with a first set of filtering rules, wherein said session is associated with a session identifier encapsulated in a cookie that is generated from a separate server; and

dispatching the service request to a proxy service for applying system resources of the enterprise communication network in response to receiving to the service request via a second firewall permitting access in compliance with a second set of filtering rules.

4. The method for securing an enterprise communications network as claimed in claim 3 further comprising wrapping and unwrapping the cookie at each service request to verify said client for said dispatching at each transmission of a service request in said session.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 032734 FRAME: 0502. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: VERIZON BUSINESS GLOBAL LLC
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 044626/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2014
From: VERIZON BUSINESS GLOBAL LLC
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 032734/0502 →
CHANGE OF NAME Recorded May 14, 2013
From: MCI WORLDCOM, INC.
To: WORLDCOM, INC.
Reel/Frame 030411/0278 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2013
From: DEVINE, CAROL Y.; SHIFRIN, GERALD A.; SHOULBERG, RICHARD W.
To: MCI WORLDCOM, INC.
Reel/Frame 030410/0670 →
CHANGE OF NAME Recorded May 14, 2013
From: MCI, LLC
To: VERIZON BUSINESS GLOBAL LLC
Reel/Frame 030411/0328 →
MERGER Recorded May 14, 2013
From: MCI, INC.
To: MCI, LLC
Reel/Frame 030411/0027 →
CHANGE OF NAME Recorded Apr 29, 2004
From: WORLDCOM, INC.
To: MCI, INC.
Reel/Frame 014576/0287 →
Continuity (3)
Continuation 0915940600 · Sep 24, 1998
Provisional Application 6006065500 · Sep 26, 1997
Related Publication 20030191970A1 · Oct 9, 2003