IP Library Granted Patent US 9,531,717
Granted Patent B2
US 9,531,717 · App. 13/635,187 · Granted Dec 27, 2016

Method of securing access to data or services that are accessible via a device implementing the method and corresponding device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,531,717
App. No.
13/635,187
Granted
Dec 27, 2016
Kind
B2
Abstract

The invention allows to secure access to data or services that are available for devices and applications via a device implementing the method. In order to secure the access to data or to one or more services that is/are accessed via a network device, the invention proposes a method that among others avoids unauthorized access to a data or one or more services and a device implementing the method.

Claims (24)

1. A method of securing access to data and services that are accessed via a network device implementing the method, said method being implemented by said network device, wherein the method comprises:

receiving a request for accessing data or at least one service, the request comprising a source identifier identifying a source of the request;

if the request does not comprise a session identifier, and if a stored source identifier group exists in memory for the source identifier, generating a session identifier for subsequently accessing data or at least one service from sources having source identifiers that are in the source identifier group existing in memory for the source identifier, storing in memory information associating said generated session identifier with said stored source identifier group for the source identifier, granting the request, and transmission of the generated session identifier to the source of the request; and

if the request comprises a session identifier, and if a stored source identifier group exists in memory for the session identifier comprised in the request, comparing source identifiers associated with the source identifier group existing in memory for the session identifier comprised in the request to said source identifier comprised in said request, and granting the request if the source identifier comprised in said request is comprised in said source identifiers associated with the stored source identifier group for the session identifier comprised in the request.

2. The method according to claim 1 , wherein the source identifier comprised in the request identifies a source of transmission of the request.

3. The method according to claim 1 , wherein the source identifier comprised in the request identifies a source of reception of the request.

4. The method according to claim 1 , wherein the source identifier comprised in the request designates a number of a physical connector.

5. The method according to claim 1 , wherein the source identifier comprised in the request designates a number of a network interface.

6. The method according to claim 1 , wherein the source identifier comprised in the request designates a network interface address.

7. The method according to claim 1 , wherein the source identifier comprised in the request designates an identifier of a software application.

8. The method according to claim 1 , wherein the method is active on an application layer of an Internet Protocol suite.

9. The method according to claim 8 , wherein the method is implemented in a web application.

10. A network device for securing access to data and services that are accessed via the device, wherein the device comprises:

a network interface configured to receive a request for accessing data or at least one service, the request comprising a source identifier identifying a source of the request;

if the request does not comprise a session identifier, and if a stored source identifier group exists in memory for the source identifier, a processor configured to generate a session identifier for subsequently accessing data or at least one service from sources having source identifiers that are in the source identifier group existing in memory for the source identifier, said processor being further configured to store in memory information associating said generated session identifier with said stored source identifier group for the source identifier, and said processor being further configured to grant the request, and the network interface being further configured to transmit the generated session identifier to the source of a first request; and

if the request comprises a session identifier, and if a stored source identifier group exists in memory for the session identifier comprised in the request, said processor being configured to compare source identifiers associated with the source identifier group existing in memory for the session identifier comprised in the request to said source identifier comprised in said request, and processor being configured to grant the request if the source identifier comprised in said request is comprised in said source identifiers associated with the stored source identifier group for the session identifier comprised in the request.

11. The network device according to claim 10 , wherein the source identifier comprised in the request identifies a source of transmission of the request.

12. The network device according to claim 10 , wherein the source identifier comprised in the request identifies a source of reception of the request.

13. The network device according to claim 10 , wherein the source identifier comprised in the request designates a number of a physical connector.

14. The network device according to claim 10 , wherein the source identifier comprised in the request designates a number of a network interface.

15. The network device according to claim 10 , wherein the source identifier comprised in the request designates a network interface address.

16. The network device according to claim 10 , wherein the source identifier comprised in the request designates an identifier of a software application.

17. The network device according to claim 10 , wherein the processor is configured to execute operations in accordance with an application layer of an Internet Protocol suite.

18. The network device according to claim 10 , wherein the processor is configured to implement a web application.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME FROM INTERDIGITAL CE PATENT HOLDINGS TO INTERDIGITAL CE PATENT HOLDINGS, SAS. PREVIOUSLY RECORDED AT REEL: 47332 FRAME: 511. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 28, 2024
From: THOMSON LICENSING
To: INTERDIGITAL CE PATENT HOLDINGS, SAS
Reel/Frame 066703/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2018
From: THOMSON LICENSING
To: INTERDIGITAL CE PATENT HOLDINGS
Reel/Frame 047332/0511 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2013
From: FEYTONS, DIRK
To: THOMSON LICENSING
Reel/Frame 029717/0617 →