IP Library › Granted Patent US 7,174,458
Granted Patent B2
US 7,174,458 · App. 10/218,618 · Granted Feb 6, 2007

Method of and apparatus for authenticating client terminal by making use of port access

Assignee: Kabushiki Kaisha Toshiba
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,174,458
App. No.
10/218,618
Granted
Feb 6, 2007
Kind
B2
Abstract

Each time one of a predetermined n number of authentication ports is accessed by a client terminal, a server checks to see if all of the n number of authentication ports have been accessed. If all of the n number of authentication ports have been accessed, the server determines that it has succeeded in authenticating the client terminal, opens its communications port to the terminal, and gives right of access to the client terminal.

Claims (40)

1. In a communications system comprising a server that includes a port allocated as a communications port and a plurality of ports allocated as authentication ports not known to a third party, a method of authenticating a client terminal by making use of port access to said server from said client terminal, said client terminal being connected to said server via a network, said method comprising:

monitoring the accessing by said client terminal to any one of said plurality of authentication ports;

detecting on the basis of the result of the monitoring of said accessing that all of said plurality of authentication ports have been accessed by said client terminal; and

opening said communications port to said client terminal, when it is detected that all of said plurality of authentication ports have been accessed by said client terminal and all of said plurality of authentication ports have successfully authenticated said client terminal.

2. A method according to claim 1 , further comprising detecting that the order in which said plurality of authentication ports are accessed coincides with a predetermined order, wherein

all of said plurality of authentication ports have successfully authenticated said client terminal when all of said plurality of authentication ports have been accessed by said client terminal and the order in which they have been accessed coincides with said predetermined order.

3. A method according to claim 1 , further comprising:

measuring the access time required for all of said plurality of authentication ports to be accessed by said client terminal; and

detecting that said measured access time is within a predetermined time, wherein

all of said plurality of authentication ports have successfully authenticated said client terminal when all of said plurality of authentication ports are accessed by said client terminal within said predetermined time.

4. A method according to claim 1 , further comprising:

performing authentication by a password via the communications port after said communications port is opened; and

giving said client terminal a right of access to said server, when said authentication by a password is successful.

5. A method according to claim 1 , further comprising changing the number of said authentication ports and the port numbers of them each time said communications port is opened.

6. A method according to claim 1 , further comprising changing said predetermined order of access each time said communications port is opened.

7. A method according to claim 1 , further comprising:

measuring the time interval between accesses to said plurality of authentication ports; and

detecting that said measured access time interval is within a predetermined time interval, wherein

all of said plurality of authentication ports have successfully authenticated said client terminal when all of said plurality of authentication ports are accessed by said client terminal and each time interval between accesses to said plurality of authentication ports is within said predetermined time interval.

8. In a communications system comprising at least one communications server that includes a port allocated as a communications port and an authentication server that includes a plurality of ports allocated as authentication ports not known to a third party, a method of authenticating a client terminal by making use of port access to said authentication server from said terminal, said client terminal, said at least one communications server, and said authentication server being connected via a network, said method comprising:

monitoring the accessing by said client terminal to any one of said plurality of authentication ports of said authentication server;

detecting on the basis of the result of the monitoring of said accessing that all of said plurality of authentication ports of said authentication server have been accessed by said client terminal; and

causing said authentication server to request said communications server to open said communications port of said communications server to said terminal, when it is detected that all of said plurality of authentication ports of said authentication server have been accessed by said client terminal all of said plurality of authentication ports have successfully authenticated said client terminal.

9. A method according to claim 8 , further comprising notifying said terminal of the address of said communications server and the port number of said communications port when said authentication server requests said communications server to open said communications port to said client terminal.

10. A method according to claim 8 , wherein

said communications system has a plurality of communications servers one of which is said at least one communications server and each of which has a port allocated as said communications port, and

the method further comprises selecting any one of said plurality of communications servers as a communications server whose communications port is to be opened and with which said client terminal can communicate, when it is detected that all of said plurality of authentication ports of said authentication server have been accessed by said client terminal all of said plurality of authentication ports have successfully authenticated said client terminal.

11. A method according to claim 10 , further comprising measuring the loads on said plurality of communications servers, wherein a communications server having the lightest load is selected, when loads on said plurality of communications servers are measured.

12. In a communications system comprising a communications server that includes a port allocated as a communications port, a plurality of authentication servers that includes at least one port allocated as an authentication port not known by a third party, and a management server, a method of authenticating a client terminal by making use of port access to said plurality of authentication servers from said terminal, said client terminal, said communications server, said plurality of authentication servers, and said management server being connected via a network, said method comprising:

detecting the accessing of said client terminal to the authentication ports of said plurality of authentication servers for each of said plurality of authentication servers;

causing said authentication server to notify said management server of success in authentication, when the accessing of said client terminal to said authentication port of said authentication server is detected; and

causing said management server to request said communications server to open said communications port of said communications server to said client terminal, when all of said plurality of authentication servers notify said management server of success in authentication all of said plurality of authentication ports have successfully authenticated said client terminal.

13. An article of manufacture comprising a computer-usable medium having computer-readable program code means embodied therein, the computer-readable program code means in said article of manufacture comprising:

computer-readable program code means for causing a server computer to monitor the accessing of a client terminal to any one of a plurality of authentication ports of the server computer, the server computer including a port allocated as a communications port and the plurality of ports allocated as authentication ports not known by a third party, and said terminal being connected to the server computer via a network;

computer-readable program code means for causing said server computer to detect on the basis of the result of the monitoring of said accessing that all of said plurality of authentication ports have been accessed by said client terminal; and

computer-readable program code means for causing said server computer to open said communications port to said client terminal, when it is detected that all of said plurality of authentication ports have been accessed by said client terminal all of said plurality of authentication ports have successfully authenticated said client terminal.

14. A server which includes a port allocated as a communications port and a plurality of ports allocated as authentication ports not known by a third party and which authenticates a client terminal connected to the server via a network by making use of port access from said terminal, said server comprising:

means for monitoring the accessing by said client terminal to any one of said plurality of authentication ports;

means for detecting that all of said plurality of authentication ports have been accessed by said client terminal, on the basis of the result of the monitoring of said accessing; and

means for opening said communications port to said client terminal, when said detecting means detects that all of said plurality of authentication ports have been accessed by said client terminal all of said plurality of authentication ports have successfully authenticated said client terminal.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2002
From: ARAKI, MOTOHISA; MURAI, TOSHIO
To: KABUSHIKI KAISHA TOSHIBA
Reel/Frame 013200/0452 →
Priority Claims (1)
JP 2001-280783 · Sep 14, 2001 · national
Continuity (1)
Related Publication 20030056097A1 · Mar 20, 2003