IP Library Patent Application 16354990
Patent Application
App. No. 16/354,990

Methods and Apparatus for Controlling Application-Specific Access to a Secure Network

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/354,990
Abstract

The present disclosure relates to methods and apparatuses for controlling application specific access to a secure network (SN). An example method of controlling application-specific access to a secure network (SN) arranged within a communication environment (CE) includes receiving a first request at the secure gateway device (SGD) from a requesting client application (CA) external to the secure network (SN), checking whether the first request includes information trustworthily identifying the requesting client application (CA), granting access to the secure network (SN) in response to verifying that the requesting client application (CA) is the authorized client application (CA), verifying, based on the access control data, whether the requesting client application (CA) is the client application (CA) authorized to access the requested service, and granting access to the requested service in response to verifying that the requesting client application (CA) is the client application (CA) authorized to access the requested service.

Claims (74)

1 . A method of controlling application-specific access to a secure network arranged within a communication environment, the method comprising:

providing access control data that identifies an authorized client application being authorized to access at least one service provided by the secure network and further identifies at least one service provided by the secure network to which service the authorized client application is authorized to access,

receiving a first request at a secure gateway device from a requesting client application external to the secure network, the first request being an access request to access to the secure network,

checking, by the secure gateway device, whether the first request includes information trustworthily identifying the requesting client application, wherein when the checking indicates that the first request includes information trustworthily identifying the requesting client application, verifying, by the secure gateway device, on a basis of access control data and the information trustworthily, whether the requesting client application is the authorized client application being authorized to access the at least one service provided by the secure network;

granting, by the secure gateway device, access to the secure network in response to verifying that the requesting client application is the authorized client application;

receiving, at the secure gateway device, a second request from the requesting client application to access a requested service provided by the secure network;

verifying, by the secure gateway device, based on the access control data, whether the requesting client application is the client application authorized to access the requested service; and

granting, by the secure gateway device, access to the requested service in response to verifying that the requesting client application is the client application authorized to access the requested service.

2 . The method of claim 1 , wherein the secure network comprises the secure gateway device providing access to the secure network for client applications external to the secure network;

3 . The method of claim 1 , further comprising at least one of the following:

denying, by the secure gateway device, access to the secure network, when the checking indicates that the first request does not include information trustworthily identifying the requesting client application;

denying, by the secure gateway device, access to the secure network in response to verifying that the requesting client application is not the authorized client application; and

denying, by the secure gateway device, access to the requested service in response to verifying that the requesting client application is not the client application authorized to access the requested service.

4 . The method of claim 1 , wherein the communication environment includes an access control server, which maintains the access control data, and wherein the access control data is provided from the access control server to the secure gateway device.

5 . The method of claim 1 , wherein an access control server is either integrated into the secure network or external to the secure network.

6 . The method of claim 1 , wherein the information trustworthily identifying the application is a Transport Layer Security certificate.

7 . The method of claim 1 , wherein verifying that the requesting client application is the client application authorized to access the requested service comprises analyzing a public key included in the information trustworthily identifying the application; and further comprising at least one of:

verifying that the requesting client application is the client application authorized to access the requested service comprises comparing information derived from the public key with the access control data; and

analyzing the public key comprises hashing the public key and verifying that the requesting client application is the client application authorized to access the requested service is based on the hash value of the public key.

8 . The method of claim 1 , wherein the at least one service provided by the secure network is hosted by at least one node in the secure network, and wherein the second request includes an indication of one the at least one nodes hosting the requested service.

9 . The method of claim 1 , wherein the second request includes an indication identifying a connection to the requested service.

10 . The method of claim 1 , wherein verifying that the requesting client application is the client application authorized to access the requested service comprises comparing the information trustworthily identifying the requesting client application with the access control data.

11 . The method of claim 1 , further comprising:

establishing, prior to receiving the first request, a position of trust between the application installed on the client device and the secure network yielding trustworthy identity information of the application and wherein the access control data is obtained from the trustworthy identity information.

12 . A computer program product for controlling application-specific access to a secure network arranged within a communication environment, wherein

the computer program product comprises computer code configured to, when executed by at least one computer device, cause the at least one computer device to:

provide access control data that identifies an authorized client application being authorized to access at least one service provided by a secure network and further identifies at least one service provided by the secure network to which service the authorized client application is authorized to access,

receive a first request at a secure gateway device from a requesting client application external to the secure network, the first request being an access request to access to the secure network,

check, by the secure gateway device, whether the first request includes information trustworthily identifying the requesting client application, wherein when the checking indicates that the first request includes information trustworthily identifying the requesting client application, verifying, by the secure gateway device, on a basis of access control data and the information trustworthily, whether the requesting client application is the authorized client application being authorized to access the at least one service provided by the secure network;

grant, by the secure gateway device, access to the secure network in response to verifying that the requesting client application is the authorized client application;

receive, at the secure gateway device, a second request from the requesting client application to access a requested service provided by the secure network;

verify, by the secure gateway device, based on the access control data, whether the requesting client application is the client application authorized to access the requested service; and

grant, by the secure gateway device, access to the requested service in response to verifying that the requesting client application is the client application authorized to access the requested service.

13 . A method of controlling application-specific access to a secure network arranged within a communication environment performed by a requesting client application external to the secure network, the method comprising:

transmitting a first request to a secure gateway device, the first request being an access request to access to the secure network and including information trustworthily identifying the requesting client application, the secure network comprising the secure gateway device to provide access to the secure network for client applications external to the secure network;

transmitting a second request to the secure gateway device, when access to the secure network is granted and in response to verifying, by the secure gateway device on the basis of the information trustworthily identifying the requesting client application and the control access data identifying the authorized client application being authorized to access at least one service provided by the secure network, that the requesting client application is the authorized client application, wherein the second request is a request to access a requested service provided by secure network; and

accessing the requested service, when access to the requested service is granted and in response to verifying, by the secure gateway device based on the control access data further identifying at least one service provided by the secure network to which the authorized client application is authorized to access, that the requesting client application is the client application authorized to access the requested service.

14 . The method of claim 13 , wherein the communication environment includes an access control server, which maintains the access control data, and wherein the access control data is provided from the access control server to the secure gateway device.

15 . The method of claim 13 , wherein an access control server is either integrated into the secure network or external to the secure network.

16 . The method of claim 13 , wherein the information trustworthily identifying the application is a Transport Layer Security certificate.

17 . The method of claim 13 , wherein verifying that the requesting client application is the client application authorized to access the requested service comprises analyzing a public key included in the information trustworthily identifying the application; and further comprising at least one of:

verifying that the requesting client application is the client application authorized to access the requested service comprises comparing information derived from the public key with the access control data; and

analyzing the public key comprises hashing the public key and verifying that the requesting client application is the client application authorized to access the requested service is based on the hash value of the public key.

18 . The method of claim 13 , wherein the at least one service provided by the secure network is hosted by at least one node in the secure network, and wherein the second request includes an indication of one the at least one nodes hosting the requested service.

19 . The method of claim 13 , wherein the second request includes an indication identifying a connection to the requested service.

20 . The method of claim 13 , wherein verifying that the requesting client application is the client application authorized to access the requested service comprises comparing the information trustworthily identifying the requesting client application with the access control data.

21 . The method of claim 13 , further comprising:

establishing, prior to receiving the first request, a position of trust between the application installed on the client device and the secure network yielding trustworthy identity information of the application and wherein the access control data is obtained from the trustworthy identity information.

22 . A computer program product for controlling application-specific access to a secure network arranged within a communication environment, wherein the computer program product comprises computer code configured to, when executed by at least one computer device, cause the at least one computer device to:

transmit a first request to a secure gateway device, the first request being an access request to access to a secure network and including information trustworthily identifying a requesting client application, the secure network comprising the secure gateway device to provide access to the secure network for client applications external to the secure network;

transmit a second request to the secure gateway device, when access to the secure network is granted and in response to verifying, by the secure gateway device on the basis of the information trustworthily identifying the requesting client application and the control access data identifying the authorized client application being authorized to access at least one service provided by the secure network, that the requesting client application is the authorized client application, wherein the second request is a request to access a requested service provided by secure network; and

access the requested service, when access to the requested service is granted and in response to verifying, by the secure gateway device based on the control access data further identifying at least one service provided by the secure network to which the authorized client application is authorized to access, that the requesting client application is the client application authorized to access the requested service.

23 . A secure gateway device for application-specific access control to a secure network arranged within a communication environment, the secure gateway device adapted to:

check whether a first request, being transmitted to the secure gateway device from a requesting client application external to the secure network and being an access request to access to the secure network, includes information trustworthily identifying the requesting client application, the secure network comprises a secure gateway device providing access to the secure network for client applications external to the secure network;

verify, when the check of the first request indicates that the first request includes information trustworthily identifying the requesting client application, on a basis of access control data identifying an authorized client application being authorized to access at least one service provided by the secure network and the information trustworthily, whether the requesting client application is the authorized client application;

grant access to the secure network in response to verifying that the requesting client application is the authorized client application;

in response to a second request from the requesting client application to access a requested service provided by secure network, verify, based on the access control data further identifying at least one service provided by the secure network to which service the authorized client application is authorized to access, whether the requesting client application is the client application authorized to access the requested service; and

grant access to the requested service in response to verifying that the requesting client application is the client application authorized to access the requested service.

24 . The secure gateway device of claim 23 , wherein the communication environment includes an access control server, which maintains the access control data, the secure gateway device being further adapted to:

request the access control data from the access control server prior to the receiving of the first request from the client application;

request the access control data from the access control server upon the receiving of the first request from the client application; and

request the access control data from the access control server in response to an update process to update the access control data.

25 . The secure gateway device of claim 23 , being further adapted to:

deny access to the secure network when checking indicates that the first request does not include information trustworthily identifying the requesting client application;

deny access to the secure network in response to verifying that the requesting client application is not the authorized client application; and

deny access to the requested service in response to verifying that the requesting client application is not the client application authorized to access the requested service.

26 . The secure gateway device of claim 25 , wherein the communication environment includes an access control server, which maintains the access control data, the secure gateway device being further adapted to:

request the access control data from the access control server prior to the receiving of the first request from the client application;

request the access control data from the access control server upon the receiving of the first request from the client application; and

request the access control data from the access control server in response to an update process to update the access control data.

27 . A client application external to a secure network for controlling application-specific access to the secure network arranged within a communication environment including an access control server, the client application adapted to:

transmit a first request to the secure gateway device, the first request being an access request to access to the secure network and including information trustworthily identifying the requesting client application, the secure network comprises a secure gateway device providing access to the secure network for client applications external to the secure network;

transmit a second request to the secure gateway device, when access to the secure network is granted and in response to verifying, by the secure gateway device on the basis of the information trustworthily identifying the requesting client application and control access data identifying an authorized client application being authorized to access at least one service provided by the secure network, that the requesting client application is the authorized client application, wherein the second request is a request to access a requested service provided by secure network; and

access the requested service when access to the requested service is granted and in response to verifying, by the secure gateway device based on the access control data further identifying at least one service provided by the secure network to which service the authorized client application is authorized to access, that the requesting client application is the client application authorized to access the requested service.

Assignments (2)
CHANGE OF NAME Recorded Dec 14, 2022
From: VIRTUAL SOLUTION AG
To: MATERNA VIRTUAL SOLUTION GMBH
Reel/Frame 062321/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2019
From: VON SPRETI, CHRISTIAN; MIHATSCH, OLIVER; JAKOBI, THOMAS
To: VIRTUAL SOLUTION AG
Reel/Frame 049689/0721 →