IP Library Granted Patent US 10,999,360
Granted Patent B2
US 10,999,360 · App. 16/228,003 · Granted May 4, 2021

Method of processing requests, and a proxy server

Inventors: Sylvain Desbureaux (Lannion, FR); Regis Frechin (Louannec, FR); Jean-Marc Duro (Lannion, FR)
Assignee: ORANGE
H04L67/1021H04L61/1511H04L61/2007H04L63/00H04L63/10H04L63/102H04L67/28H04L67/32H04W8/082H04L63/0272H04L63/0281H04L63/08H04L63/20H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,999,360
App. No.
16/228,003
Granted
May 4, 2021
Kind
B2
Abstract

A method of processing requests, which is implemented by a proxy server of resolution of domain names of a first communications network. The first communications network is accessible by a user terminal via a communications tunnel set up over a second communications network. The processing method includes, on receiving a domain name resolution request coming from the terminal and sent via the communications tunnel: obtaining an identifier of the user from information contained in a field of the request; using the identifier of the user to determine whether the user is or is not authorized to access the domain name; if the user is authorized to access the domain name, sending an IP address to the terminal via the communications tunnel, the IP address corresponding to the domain name and being accessible to the terminal via the second communications network; else, rejecting the request from the terminal.

Claims (37)

1. A processing method comprising:

processing requests, which is implemented by a proxy server of resolution of domain names of a first communications network, said first communications network being accessible by a user terminal via a communications tunnel set up over a second communications network, said proxy server being comprised in said first communications network, and said processing by the proxy server comprising, on receiving a domain name resolution request coming from the terminal and sent via the communications tunnel:

an obtaining act of obtaining an identifier of the user from information contained in a field of the request, wherein the identifier of the user is obtained by the proxy server from an IP address of the user terminal contained in the request and was allocated to the user terminal while the communications tunnel was being set up;

a determination act of using said identifier of the user to determine whether the user is or is not authorized to access said domain name;

if the user is authorized to access the domain name, a send act of sending an IP address to the terminal via the communications tunnel, the IP address corresponding to the domain name and being accessible to the terminal via said second communications network;

else, a rejection act of rejecting the request from the terminal.

2. The processing method according to claim 1 , wherein the determination act comprises interrogating at least one domain name resolution server forming part of the first network or of a third network distinct from the first network.

3. The processing method according to claim 1 , wherein, if the user is authorized to access the domain name, the method further comprises an act of causing the terminal to be configured by an equipment of the first network so as to allow the terminal to transmit at least one data stream to said IP address of the domain name without passing via said communications tunnel.

4. A non-transitory computer-readable data medium storing a computer program having instructions, which when executed by a processor of a proxy server configure the proxy server to perform a method of processing requests, the proxy server being a server of resolution of domain names of a first communications network and comprised in said first communications network, said first communications network being accessible by a user terminal via a communications tunnel set up over a second communications network, said processing comprising, on receiving a domain name resolution request coming from the terminal and sent via the communications tunnel:

an obtaining act of obtaining an identifier of the user from information contained in a field of the request, wherein the identifier of the user is obtained by the proxy server from an IP address of the user terminal contained in the request and was allocated to the user terminal while the communications tunnel was being set up;

a determination act of using said identifier of the user to determine whether the user is or is not authorized to access said domain name;

if the user is authorized to access the domain name, a send act of sending an IP address to the terminal via the communications tunnel, the IP address corresponding to the domain name and being accessible to the terminal via said second communications network;

else, a rejection act of rejecting the request from the terminal.

5. A proxy server of domain name resolution forming part of a first communications network accessible by a user terminal via a communications tunnel set up over a second communications network, said proxy server comprising:

a processor; and

a non-transitory computer-readable medium comprising instructions stored thereon which when executed by the processor configure the proxy server to perform the following acts on receiving a domain name resolution request coming from the terminal and sent via the communications tunnel:

obtaining an identifier of the user from information contained in a field of the request, wherein the identifier of the user is obtained by the proxy server from an IP address of the user terminal contained in the request and was allocated to the user terminal while the communications tunnel was being set up;

using said identifier of the user to determine whether the user is or is not authorized to access said domain name;

if the user is authorized to access the domain name, sending an IP address to the terminal via the communications tunnel, the IP address corresponding to the domain name and being accessible to the terminal via said second communications network; and

else rejecting the request from the terminal.

6. A communications system comprising:

a user terminal configured to set up a communications tunnel with a first communications network over a second communications network; and

a proxy server of resolution of domain names of the first communications network accessible by the user terminal via the communications tunnel set up over the second communications network, said proxy server being comprised in the first communications network and comprising:

a processor; and

a non-transitory computer-readable medium comprising instructions stored thereon which when executed by the processor configure the proxy server to perform the following acts on receiving a domain name resolution request coming from the terminal and sent via the communications tunnel:

obtaining an identifier of the user from information contained in a field of the request, wherein the identifier of the user is obtained by the proxy server from an IP address of the user terminal contained in the request and was allocated to the user terminal while the communications tunnel was being set up;

using said identifier of the user to determine whether the user is or is not authorized to access said domain name;

if the user is authorized to access the domain name, sending an IP address to the terminal via the communications tunnel, the IP address corresponding to the domain name and being accessible to the terminal via said second communications network; and

else rejecting the request from the terminal;

said terminal also being configured:

to send to the proxy server, via the communications tunnel, all of its domain name resolution requests; and

on receiving the IP address of the domain name from the proxy server in response to the domain name resolution request, to transmit at least one data stream to said IP address of the domain name without passing via said communications tunnel.

7. The communications system according to claim 6 further comprising an equipment forming part of the first communications network, which equipment is activated when the user is authorized to access the domain name, and is set to configure the terminal to enable the terminal to transmit a data stream to said IP address of the domain name without passing via said communications tunnel.

8. The communications system according to claim 6 further comprising an equipment forming part of the first communications network, which equipment is set to configure the terminal:

to enable the terminal to transmit at least one data stream without passing via communications tunnel when said data stream satisfies at least one predetermined first criterion;

and/or to enforce the terminal to transmit at least one data stream via said communications tunnel when said data stream satisfies at least one predetermined second criterion.

9. The communications system according to claim 6 , wherein the communications tunnel is secure.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2019
From: DESBUREAUX, SYLVAIN; FRECHIN, REGIS; DURO, JEAN-MARC
To: ORANGE
Reel/Frame 048137/0057 →
Priority Claims (1)
FR 1762837 · Dec 21, 2017 · national
Continuity (1)
Related Publication 20190199822A1 · Jun 27, 2019