IP Library Granted Patent US 8,966,270
Granted Patent B2
US 8,966,270 · App. 11/647,274 · Granted Feb 24, 2015

Methods and systems for providing controlled access to the internet

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,966,270
App. No.
11/647,274
Granted
Feb 24, 2015
Kind
B2
Abstract

Novel, Internet-related architectures, methods and devices are proposed that are based on a fundamentally different philosophy: hosts (e.g., source and destination nodes) are given the ability to specify their access control policies to the network they are a part of, and the network enforces these policies. The architecture proposed is mobility friendly to the ever increasing number of mobile hosts and is scalable as well.

Claims (27)

1. A method for controlling access to nodes in a network comprising:

generating an authorization request message (AUTHREQ) that includes a source access certificate (SAC) for authorizing one or more destination nodes to send data packets to a source node;

forwarding the (AUTHREQ) with its SAC to one or more intermediate control nodes via a first pathway, the pathway comprising a signaling and control pathway; and

receiving a valid authorization reply message (AUTHREP) that includes a destination access certificate (DAC) that includes consent and binding, identity-based signatures from one of the one or more destination nodes via a second pathway that is distinct from the first pathway, wherein the (AUTHREP) authorizes the source node to send data packets to the destination node associated with the (AUTHREP).

2. The method as in claim 1 further comprising exchanging data packets between the source and destination nodes, wherein each data packet sent from the source node includes the DAC and each data packet sent from the destination node includes the SAC.

3. The method as in claim 2 further comprising verifying that each data packet sent from a node includes a valid access certificate.

4. The method as in claim 3 wherein the verification step comprises:

verifying that a DAC of each data packet includes valid consent and binding, identity-based signatures.

5. A method for controlling access to nodes in a network comprising:

receiving at least one valid authorization request message (AUTHREQ) that includes a source access certificate (SAC) from an intermediate control node via a first pathway, the SAC authorizing at least one destination node to send data packets to a source node associated with the SAC, and wherein the first pathway comprises a signaling and control pathway;

generating an authorization reply message (AUTHREP) that includes a destination access certificate (DAC) that includes consent and binding, identity-based signatures; and

forwarding the (AUTHREP) to the source node associated with the valid (AUTHREQ) via a second pathway that is distinct from the first pathway, the (AUTHREP) authorizing the source node to send data packets to the destination node.

6. The method as in claim 5 further comprising exchanging data packets between the source and destination nodes over the second pathway, wherein each data packet sent from the source node and destination node includes a valid access certificate.

7. A system for controlling access to nodes in a network, the system comprising:

at least one hardware source node configured to:

generate an authorization request message (AUTHREQ) that includes a source access certificate (SAC) for authorizing one or more destination nodes to send data packets to a hardware source node;

forward the (AUTHREQ) with its SAC to one or more intermediate control nodes via a first pathway, the pathway comprising a signaling and control pathway; and

receive a valid authorization reply message (AUTHREP) that includes a destination access certificate (DAC) that includes consent and binding, identity-based signatures from one of the one or more destination nodes via a second pathway that is distinct from the first pathway, wherein the (AUTHREP) authorizes the hardware source node to send data packets to the destination node associated with the (AUTHREP).

8. The system as in claim 7 , further comprising at least one destination node, wherein the hardware source and the destination node exchange data packets, each data packet sent from the hardware source node includes a DAC and each data packet sent from the destination node includes an SAC.

9. The system as in claim 8 further comprising one or more routers operable to verify that each data packet sent from a node includes a valid access certificate.

10. The system as in claim 9 wherein the one or more routers is operable to verify that a DAC of each data packet includes valid consent and binding, identity-based signatures.

11. A system for controlling access to nodes in a network, the system comprising:

at least one hardware destination node configured to:

receive at least one valid authorization request message (AUTHREQ) that includes a source access certificate (SAC) from an intermediate control node via a first pathway, the SAC authorizing at least one hardware destination node to send data packets to a source node associated with the SAC, and wherein the first pathway comprises a signaling and control pathway;

generate an authorization reply message (AUTHREP) that includes a destination access certificate DAC that includes consent and binding, identity-based signatures; and

forward the (AUTHREP) to the source node associated with the valid (AUTHREQ) via a second pathway that is distinct from the first pathway, the (AUTHREP) authorizing the source node to send data packets to the hardware destination node.

12. The system as in claim 11 , wherein the hardware destination node is further configured to exchange data packets with the source node over the second pathway, wherein each data packet sent from the source and the hardware destination node includes a valid access certificate.

Assignments (13)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED AT REEL: 019123 FRAME: 0971. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jul 15, 2015
From: BU, TIAN; LI, LI; RAMJEE, RAMACHANDRAN
To: LUCENT TECHNOLOGIES INC.
Reel/Frame 036104/0298 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2015
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 034769/0361 →
MERGER AND CHANGE OF NAME Recorded Jan 14, 2015
From: LUCENT TECHNOLOGIES INC.; ALCATEL USA MARKETING, INC.; ALCATEL USA SOURCING, INC.; LUCENT TECHNOLOGIES INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 034706/0080 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2014
From: CREDIT SUISSE AG
To: ALCATEL LUCENT
Reel/Frame 033868/0555 →
SECURITY AGREEMENT Recorded Jan 30, 2013
From: ALCATEL LUCENT
To: CREDIT SUISSE AG
Reel/Frame 029821/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2007
From: BU, TIAN; LI, LI; RAMJEE, RAMACHANDRAN
To: ALCATEL-LUCENT TECHNOLOGIES INC.
Reel/Frame 019123/0971 →