IP Library Granted Patent US 7,712,128
Granted Patent B2
US 7,712,128 · App. 10/483,984 · Granted May 4, 2010

Wireless access system, method, signal, and computer program product

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,712,128
App. No.
10/483,984
Granted
May 4, 2010
Kind
B2
Abstract

A system, method, signal, and computer program product for providing secure wireless access to private databases and applications without requiring a separate wireless client-server internetworking security protocol infrastructure. The wireless device ( 201 ) communicates with the wireless access service provider ( 205 ) via hypertext transfer protocol (HTTP) messages, and the wireless access service provider ( 205 ) and the secure network ( 204 ) perform a RADIUS authentification for the wireless device ( 201 ).

Claims (90)

1. A method for providing a user of a wireless device access to a secure application via a client-server internetworking security protocol configured to at least one of control authentication, perform accounting, and provide access-control in a networked, multiuser environment, comprising steps of:

receiving an authentication request message requesting access to said secure application from said wireless device at a wireless access service mechanism configured to process said authentication request message, said authentication request message being in accordance with a wireless message protocol and including an IP address of said wireless device and an access credential of the user of said wireless device;

producing, by the wireless access service mechanism, a client-server internetworking security protocol authentication request message based on said authentication request message by reformatting a portion of said authentication request message in accordance with said client-server internetworking security protocol and including information of said IP address of said wireless device and/or said access credential;

transmitting said client-server internetworking security protocol authentication request message from said wireless access service mechanism to a client-server internetworking security protocol authentication device configured to perform client-server internetworking security protocol authentication, wherein said client-server internetworking security protocol authentication device authenticates said user for access to said secure application based on said IP address of said wireless device and/or said access credential;

receiving a client-server internetworking security protocol authentication accept message and/or a client-server internetworking security protocol authentication reject message from said client-server internetworking security protocol authentication device

processing said client-server internetworking security protocol authentication accept message at said wireless access service mechanism to convert said client-server internetworking security protocol accept message to a wireless authentication accept message according to said wireless message protocol;

transmitting a client-server internetworking security protocol access message from said wireless access service mechanism to said client-server internetworking security protocol authentication device;

transmitting a session start message from said wireless access service mechanism to a wireless gateway device;

transmitting said wireless authentication accept message from said wireless access service mechanism to said wireless device, wherein said user is authorized to access said secure application upon receipt of said wireless authentication accept message;

timing a connection time between said wireless device and said wireless gateway device so as to produce a wireless timing parameter at said wireless access service mechanism;

transmitting a session end notification message from said wireless access service mechanism to said wireless device in response to determining that said wireless timing parameter exceeds a predetermined timing value.

2. The method of claim 1 , wherein said client-server internetworking security protocol comprises RADIUS.

3. The method of claim 1 , further comprising:

processing said client-server internetworking security protocol authentication request message by said client-server internetworking security protocol authentication device; and

transmitting said client-server internetworking security protocol authentication accept message and/or said client-server internetworking security protocol authentication reject message from said client-server internetworking security protocol authentication device to said wireless access service mechanism via a direct connection and/or a local network.

4. The method of claim 1 , further comprising:

transmitting a client-server internetworking security protocol access authentication Accounting-End Message from said wireless access service mechanism to said client-server internetworking security protocol authentication device via a direct connection and/or a local network.

5. The method of claim 1 , further comprising:

transmitting a client-server internetworking security protocol access authentication Accounting-End Message from said wireless access service mechanism to said client-server internetworking security protocol authentication device via a direct connection and/or a local network.

6. The method of claim 1 , further comprising:

processing said client-server internetworking security protocol authentication reject message at said wireless access service mechanism to convert said client-server internetworking security protocol reject message to a wireless authentication reject message according to said wireless message protocol; and

transmitting said wireless authentication rejection message from said wireless access service mechanism to said wireless device.

7. The method of claim 2 , wherein said step of transmitting said client-server internetworking security protocol authentication request message includes transmitting via a global network.

8. The method of claim 7 , further comprising:

transmitting said session start message from said wireless access service mechanism to a wireless gateway device via said global network.

9. The method of claim 8 , further comprising:

transmitting said session end notification from said wireless access service mechanism to said wireless gateway device and/or said wireless device via said global network if said wireless timing parameter exceeds said predetermined timing value.

10. The method of claim 8 , further comprising:

transmitting said client-server internetworking security protocol access authentication Accounting-End Message from said wireless access service mechanism to said client-server internetworking security protocol authentication device via said global network.

11. The method of claim 9 , further comprising:

transmitting said client-server internetworking security protocol access authentication Accounting-End Message from said wireless access service mechanism to said client-server internetworking security protocol authentication device via said global network.

12. The method of claim 7 , further comprising:

processing said client-server internetworking security protocol authentication reject message at said wireless access service mechanism to convert said client-server internetworking security protocol reject message to a wireless authentication reject message according to said wireless message protocol; and

transmitting said wireless authentication reject message from said wireless access service mechanism to said wireless device.

13. A system configured to interface a wireless device to a secure application via a client-server internetworking security protocol configured to control authentication, perform accounting, and/or provide access-control in a networked, multiuser environment comprising:

said wireless device connected to a wireless service provider via a wireless connection medium;

a wireless access service mechanism connected to said wireless service provider via a global telecommunications network, said wireless access service mechanism being configured to:

receive an authentication request message from a user of said wireless device requesting access to said secure application, said authentication request message being in accordance with a wireless message protocol and including an IP address of said wireless device and an access credential of a user of said wireless device;

convert said authentication request message to a client-server internetworking security protocol authentication request message by reformatting a portion of said authentication request message in accordance with an internetworking security protocol and including information of at least one of said IP address of said wireless device and said access credential;

transmit said client-server internetworking security protocol authentication request message from said wireless access service mechanism to a client-server internetworking security protocol authentication device configured to perform client-server internetworking security protocol authentication, wherein said client-server internetworking security protocol authentication device authenticates said user for access to said secure application based on said IP address of said wireless device and/or said access credential;

receive a client-server internetworking security protocol authentication accept message and/or a client-server internetworking security protocol authentication reject message from said client-server internetworking security protocol authentication device

process said client-server internetworking security protocol authentication accept message at said wireless access service mechanism to convert said client-server internetworking security protocol accept message to a wireless authentication accept message according to said wireless message protocol;

transmit a client-server internetworking security protocol access message from said wireless access service mechanism to said client-server internetworking security protocol authentication device;

transmit a session start message from said wireless access service mechanism to a wireless gateway device;

transmit said wireless authentication accept message from said wireless access service mechanism to said wireless device, wherein said user is authorized to access said secure application upon receipt of said wireless authentication accept message;

time a connection time between said wireless device and said wireless gateway device so as to produce a wireless timing parameter at said wireless access service mechanism;

transmit a session end notification message from said wireless access service mechanism to said wireless device in response to determining that said wireless timing parameter exceeds a predetermined timing value; and

a client-server internetworking security protocol authentication device connected to said wireless access service mechanism, wherein said client-server internetworking security protocol authentication device authenticates said user for access to said secure application based on said IP address of said wireless device and/or said access credential.

14. The system of claim 13 , wherein said client-server internetworking security protocol comprises RADIUS.

15. The system of claim 14 , further comprising:

said wireless gateway device connected to said wireless access service mechanism; and

said secure application connected to said wireless gateway device.

16. The system of claim 14 , wherein said wireless access service mechanism and said client-server internetworking security protocol authentication device are connected by a direct connection and/or a local network.

17. The system of claim 14 , wherein said wireless access service mechanism and said client-server internetworking security protocol authentication device are connected by a global network.

18. The system of claim 15 , wherein said wireless access service mechanism and said wireless gateway device are connected by a direct connection and/or a local network.

19. The system of claim 15 , wherein said wireless access service mechanism and said wireless gateway device are connected by a global network.

20. An apparatus configured to interface at least one wireless client application to at least one secure application via a client-server internetworking security protocol configured control authentication, perform accounting, and/or provide access-control in a networked, multi-user environment, comprising:

a wireless access service mechanism configured to:

receive an authentication request message from said at least one wireless client application requesting access to said at least one secure application, said authentication request message being in accordance with a wireless message protocol and including an IP address of said wireless device and an access credential of a user of said wireless device,

convert said authentication request message to a client-server internetworking security protocol authentication request message by reformatting a portion of said authentication request message from said wireless message protocol to a client-server internetworking protocol;

forward said client-server internetworking security protocol authentication request message to a client-server internetworking security protocol authentication device for authentication of said at least one wireless client application for access to said at least one secure application, said client-server internetworking security protocol authentication request message being in accordance with a client-server internetworking security protocol and including information of said IP address of said wireless device and/or said access credential;

receive a client-server internetworking security protocol authentication accept message and/or a client-server internetworking security protocol authentication reject message from said client-server internetworking security protocol authentication device

process said client-server internetworking security protocol authentication accept message at said wireless access service mechanism to convert said client-server internetworking security protocol accept message to a wireless authentication accept message according to said wireless message protocol;

transmit a client-server internetworking security protocol access message from said wireless access service mechanism to said client-server internetworking security protocol authentication device;

transmit a session start message from said wireless access service mechanism to a wireless gateway device;

transmit said wireless authentication accept message from said wireless access service mechanism to said wireless device, wherein said user is authorized to access said secure application upon receipt of said wireless authentication accept message;

time a connection time between said wireless device and said wireless gateway device so as to produce a wireless timing parameter at said wireless access service mechanism; and

transmit a session end notification message from said wireless access service mechanism to said wireless device in response to determining that said wireless timing parameter exceeds a predetermined timing value.

21. The apparatus of claim 20 , wherein said client-server internetworking security protocol comprises RADIUS.

22. A computer program product including a computer storage medium, said computer storage medium comprising volatile media and/or non-volatile media, and a computer program code mechanism embedded in the computer storage medium, for providing a user of a wireless device access to a secure application via a client-server internetworking security protocol configured to control authentication, perform accounting, and/or provide access-control in a networked, multi-user environment, the computer code mechanism comprising:

at least one of unit of software and a unit of firmware configured to:

convert a wireless authentication message requesting access to said secure application to a client-server internetworking security protocol authentication request message by reformatting a portion of said wireless authentication message and to exchange said client-server internetworking security protocol authentication request message with a client-server internetworking security protocol device, said wireless authentication message being in accordance with a wireless message protocol and including an IP address of said wireless device and an access credential of a user of said wireless device, and said client-server internetworking security protocol message being in accordance with a client-server internetworking security protocol and including information of said IP address of said wireless device and/or said access credential;

receive a client-server internetworking security protocol authentication accept message and/or a client-server internetworking security protocol authentication reject message from said client-server internetworking security protocol authentication device

process said client-server internetworking security protocol authentication accept message at said wireless access service mechanism to convert said client-server internetworking security protocol accept message to a wireless authentication accept message according to said wireless message protocol;

transmit a client-server internetworking security protocol access message from said wireless access service mechanism to said client-server internetworking security protocol authentication device;

transmit a session start message from said wireless access service mechanism to a wireless gateway device;

transmit said wireless authentication accept message from said wireless access service mechanism to said wireless device, wherein said user is authorized to access said secure application upon receipt of said wireless authentication accept message;

time a connection time between said wireless device and said wireless gateway device so as to produce a wireless timing parameter at said wireless access service mechanism;

transmit a session end notification message from said wireless access service mechanism to said wireless device in response to determining that said wireless timing parameter exceeds a predetermined timing value; and

transmit a session end notification message from a wireless access service mechanism to said wireless device in response to determining that a wireless timing parameter exceeds a predetermined timing value;

wherein said user is authenticated for access to said secure application based on said IP address of said wireless device and/or said access credential.

23. The computer program product of claim 22 , wherein said client-server internetworking security protocol comprises RADIUS.

24. The method of claim 1 , wherein said access credential includes a user identification and/or a password associated with a user of the wireless device.

25. The system of claim 13 , wherein said access credential includes a user identification and/or a password associated with a user of the wireless device.

26. The apparatus of claim 20 , wherein said access credential includes a user identification and/or a password associated with a user of the wireless device.

27. The computer program product of claim 22 , wherein said access credential includes a user identification and/or a password associated with a user of the wireless device.

28. The method of claim 1 , wherein said wireless message protocol comprises HTTP and said client-server internetworking security protocol comprises RADIUS.

29. The system of claim 13 , wherein said wireless message protocol comprises HTTP and said client-server internetworking security protocol comprises RADIUS.

30. The apparatus of claim 20 , wherein said wireless message protocol comprises HTTP and said client-server internetworking security protocol comprises RADIUS.

31. The computer program product of claim 22 , wherein said wireless message protocol comprises HTTP and said client-server internetworking security protocol comprises RADIUS.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2016
From: FIBERLINK COMMUNICATIONS CORPORATION
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 039001/0462 →
RELEASE OF SECURITY INTEREST Recorded Dec 17, 2013
From: HORIZON TECHNOLOGY FINANCE CORPORATION
To: FIBERLINK COMMUNICATIONS CORPORATION
Reel/Frame 031802/0411 →
RELEASE OF SECURITY INTEREST Recorded Dec 17, 2013
From: SILICON VALLEY BANK
To: FIBERLINK COMMUNICATIONS CORPORATION
Reel/Frame 031802/0482 →
SECURITY INTEREST Recorded Dec 26, 2012
From: FIBERLINK COMMUNICATIONS CORPORATION
To: HORIZON TECHNOLOGY FINANCE CORPORATION
Reel/Frame 029666/0685 →
SECURITY AGREEMENT Recorded Feb 23, 2011
From: FIBERLINK COMMUNICATIONS CORPORATION
To: SILICON VALLEY BANK
Reel/Frame 025833/0509 →
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2010
From: WACHOVIA BANK, NATIONAL ASSOCIATION
To: FIBERLINK COMMUNICATIONS CORPORATION
Reel/Frame 024588/0384 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2004
From: POROZNI, BARRY; NICODEMUS, BLAIR GAVOR; SCHILLE, GLENN ALAN
To: FIBERLINK COMMUNICATIONS CORPORATION
Reel/Frame 016055/0587 →
SECURITY AGREEMENT Recorded Oct 8, 2004
From: FIBERLINK COMMUNICATIONS CORPORATION
To: WACHOVIA BANK, NATIONAL ASSOCIATION
Reel/Frame 015240/0919 →