IP Library Granted Patent US 7,512,784
Granted Patent B2
US 7,512,784 · App. 11/514,852 · Granted Mar 31, 2009

Distributed subscriber management system

Assignee: Alcatel-Lucent Canada Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,512,784
App. No.
11/514,852
Granted
Mar 31, 2009
Kind
B2
Abstract

A distributed subscriber management system and method that controls access to a network preventing unauthorized traffic through the access network and providing centralized access control between user networks. The system and method provide controlled access through the use of one of several technologies including user authentication, using PAP, CHAP, RADIUS, TACACS+, or other standard authentication means. The method includes the steps of receiving a connection request from a user located on one of the User Networks; interrogating the user for userid and password information; encrypting the userid and password information; transmitting the encrypted information, via the access network, to an authentication server attached to one of a plurality of external networks; decrypting the information at the authentication server; and transmitting an authentication message from the authentication server of the external network to the access control node via the access network. The preferred method includes the additional step of challenging all data leaving the access control node.

Claims (32)

1. A distributed subscriber management system comprising:

a plurality of user networks, each user network connecting a respective group of users;

an integrated access device interposed between said plurality of user networks and an access network, said integrated access device comprising means for controlling admission to each of said user networks of users while connected to each other user network of said plurality of user networks; and

a plurality of external networks connected to said access network, each said external network having an authentication server;

wherein said integrated access device comprises a set of at least two authentication clients shared by said plurality of user networks and operable to authenticate and authorize data units received from users belonging to any of said user networks and destined to any of said external networks.

2. The distributed subscriber management system of claim 1 further including means for centralized access control between said user networks.

3. The distributed subscriber management system of claim 1 further comprising a secure data-unit labeling system associated with said integrated access device for marking data units received from said user networks to produce marked data units so that each said marked data unit destined to a specific external network from among said plurality of external networks becomes illegible to any other of said external networks.

4. The distributed subscriber management system of claim 1 wherein said set of at least two authentication clients uses a Remote Authentication, Dial-in User Service (RADIUS) protocol.

5. The distributed subscriber management system of claim 1 further including, in said integrated access device, means for:

receiving a data unit from a user located on one of said plurality of user networks;

interrogating said user for access information;

encrypting said access information prior to transmitting the

access information to an authentication server; and

wherein the encrypted access information is decrypted at the authentication server.

6. The distributed subscriber management system of claim 1 wherein said plurality of user networks includes a first number of user networks, said set of at least two authentication clients includes a second number of authentication clients, and said first number is unequal to said second number.

7. An integrated access device comprising:

a user-network interface connecting to a plurality of user networks to receive data units from said plurality of user networks;

at least two authentication clients operatively connected to said user network interface for authenticating and authorizing data units received from said plurality of user networks;

an external-network interface operatively connected to said at least two authentication clients and to an access network, said external-network interface operable to forward a data unit authorized by any of said at least two authentication clients to an external network from among a plurality of external networks connected to said access network; and

means for controlling admission to each of said user networks of users while connected to each other user network of said plurality of user networks.

8. The integrated access device of claim 7 further comprising means for allocating discrete bandwidth levels to at least one of said user networks.

9. The integrated access device of claim 7 further comprising:

means for service-level enforcing;

means for network-resource management;

means for collecting usage statistical usage; and

means for alarm monitoring.

10. The integrated access device of claim 7 , further comprising at least one of the following:

a password authentication protocol client;

a challenge handshake authentication protocol client;

a terminal-access controller-access control system client; and

a remote authentication dial-in user service protocol client.

11. The integrated access device of claim 7 wherein the user network interface includes a plurality of ingress cards and the external network interface includes an egress card.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2008
From: TROPIC NETWORKS INC.
To: 6467253 CANADA INC.
Reel/Frame 020997/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2008
From: TROPIC NETWORKS INC.
To: ALCATEL-LUCENT CANADA INC.
Reel/Frame 020997/0960 →
CHANGE OF NAME Recorded May 25, 2008
From: 6467253 CANADA INC.
To: TROPIC NETWORKS INC.
Reel/Frame 020998/0011 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2007
From: SKEMER, TERRY
To: SEDONA NETWORKS CORPORATION
Reel/Frame 019403/0969 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2007
From: ERNST&YOUNG INC., TRUSTEE IN BUNKRUPTCY OF SEDONA NETWORKS CORP.
To: TROPIC NETWORKS INC.
Reel/Frame 019404/0165 →
Priority Claims (2)
CA 2293989 · Jan 7, 2000 · national
CA 2296213 · Jan 14, 2000 · national
Continuity (2)
Continuation 0975503700 · Jan 8, 2001
Related Publication 20070005954A1 · Jan 4, 2007