IP Library Granted Patent US 8,910,300
Granted Patent B2
US 8,910,300 · App. 13/339,807 · Granted Dec 9, 2014

Secure tunneling platform system and method

Inventors: Martin Varsavsky Waisman-Diamond (Madrid, ES); Gonzalo Julián Bécares Fernández (Madrid, ES); Xabier Iurgi Arginzoniz Cebreiro (Madrid, ES); Juan Manuel Muñoz Castro (Madrid, ES); Pablo Martin Medrano (Madrid, ES)
Assignee: Fon Wireless Limited
H04L63/083H04L29/12367H04L61/2514H04L63/1425H04L63/30H04W12/06H04L63/162
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,910,300
App. No.
13/339,807
Granted
Dec 9, 2014
Kind
B2
Abstract

Disclosed is a system and method for receiving, by a wireless gateway device from a user computing device, a request for network access. In an embodiment, the request is formatted to comply with a different communication protocol, and transmitted to a authentication computing device. The gateway device receives a reply from the authentication computing device that grants the request. The reply is transmitted by the wireless gateway device and to the user computing device. A first communication pathway is established between the authentication computing device and the user computing device, and a request for access to at least one other computing device is received by the authentication device. The request is forwarded, and a reply granting the request is received and forwarded to the user computing device.

Claims (50)

1. A method of providing internet access for a first user computing device, the method comprising:

receiving, by a wireless gateway device, from the first user computing device, a request for the internet access;

transmitting via the internet, by the wireless gateway device, to a second computing device remote from the wireless gateway device, a request to authenticate the first user computing device;

only after receiving, by the wireless gateway device, a reply that authenticates the first user device, establishing a communication tunnel between the wireless gateway device and the second computing device,

wherein the reply that authenticates is received from a remote authenticating computing device different and remote from the second computing device, and different and remote from the wireless gateway device;

wherein after the communication tunnel is established, the method further comprises:

receiving, by the wireless gateway device, data packets, and encapsulating each data packet; and

providing, by the wireless gateway device, the internet access for the first user computing device by transmitting, through the communication tunnel, data received from the user computing device; and

assigning, by the wireless gateway device, an internet protocol address for a communication session of the first user computing device.

2. The method of claim 1 , wherein the first user device and the wireless gateway device communicate using HTTP.

3. The method of claim 1 , wherein the first user device and the wireless gateway device communicate using EAP.

4. The method of claim 1 , wherein the second computing device includes a layer 2 tunneling protocol network server (“LNS”).

5. The method of claim 4 , further comprising:

reformatting, by the LNS, each encapsulated data packet; and

transmitting via the internet, by the LNS, to a remote network platform device the reformatted data packet.

6. The method of claim 1 , wherein the second computing device requests the authentication using RADIUS protocol.

7. The method of claim 1 , wherein the second computing device is a RADIUS server.

8. The method of claim 1 , wherein each encapsulated data packet is transmitted by the wireless gateway device using point-to-point protocol.

9. The method of claim 1 , further comprising logging, by the second, device credentials and a session address.

10. The method of claim 1 , further comprising:

receiving, by the wireless gateway device, from a second user computing device different from the first user computing device, a request for the internet access;

transmitting via the internet, by the wireless gateway device, to the second computing device, the request to authenticate the second user computing device;

only after receiving, by the wireless gateway device, a reply that authenticates the second user device, establishing a communication session between the wireless gateway device and the second computing device,

wherein the reply that authenticates is received from the remote authenticating computing device;

wherein after the communication session is established, the method further comprises:

providing, by the wireless gateway device, the internet access for the second user computing device by transmitting, through the communication tunnel in the communication session, data received from the second user computing device; and

assigning, by the wireless gateway device, an internet protocol address for a communication session of the second user computing device so as to enable unambiguous discrimination of the second user computing device from the first user computing device.

11. The method of claim 1 , wherein the wireless gateway device assigns, using Network Address Translation, a single internet protocol address to communications of the first user computing device and to communications of a second computing device different from the first user computing device,

wherein the second user computing device requests internet access via the wireless gateway device.

12. The device of claim 1 , wherein the fourth module is configured to assign, using Network Address Translation, a single internet protocol address to communications of the first user computing device and to communications of a second computing device different from the first user computing device,

wherein the second user computing device requests interne access via the wireless gateway device.

13. A wireless gateway device that provides internet access for a first user computing device, the device comprising:

a first module configured to receive from the first user computing device, a request for the internet access;

a second module configured to transmit, to a second computing device remote from the wireless gateway device and connected to the wireless gateway device via the internet, a request to authenticate the first user computing device;

a third module configured to establish, only after receiving, by the wireless gateway device, a reply that authenticates the first user device, a communication tunnel between the wireless gateway device and the second computing device,

wherein the reply that authenticates is received from a remote authenticating computing device different and remote from the second computing device, and different and remote from the wireless gateway device;

a fourth module configured to receive, only after the communication tunnel is established, data packets, and encapsulating each data packet; and

the fourth module configured to provide the internet access for the first user computing device by transmitting, through the communication tunnel, data received from the user computing device; and

the fourth module configured to assign, by the wireless gateway device, an internet protocol address for a communication session of the first user computing device.

14. The device of claim 13 , wherein the wireless gateway device communicates with the first user device using HTTP.

15. The device of claim 13 , wherein the wireless gateway device communicates with the first user device using EAP.

16. The device of claim 13 , wherein the each encapsulated data packet is transmitted using point-to-point protocol.

17. The device of claim 13 , wherein the at least one second computing device includes a layer 2 tunneling protocol network server.

18. The device of claim 13 , wherein:

the first module is configured to receive from a second user computing device different from the first user computing device, a request for the internet access;

the second module is configured to transmit via the Internet to the second computing device, the request to authenticate the second user computing device;

the third module is configured to establish, only after receiving a reply that authenticates the second user device, a communication session between the wireless gateway device and the second computing device,

wherein the reply that authenticates is received from the remote authenticating computing device;

the fourth module is configured to provide, only after the communication session is established, the internet access for the second user computing device by transmitting, through the communication tunnel in the communication session, data received from the second user computing device; and

the fourth module is configured to assign an internet protocol address for a communication session of the second user computing device so as to enable unambiguous discrimination of the second user computing device from the first user computing device.

Assignments (3)
SECURITY AGREEMENT Recorded Dec 30, 2014
From: FON WIRELESS LIMITED
To: SILICON VALLEY BANK
Reel/Frame 034715/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2014
From: FON TECHNOLOGY, SL
To: FON WIRELESS LIMITED
Reel/Frame 033157/0453 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2012
From: WAISMAN-DIAMOND, MARTIN VARSAVSKY; BECARES FERNANDEZ, GONZALO JULIAN; ARGINZONIZ CEBREIRO, XABIER IURGI; MUNOZ CASTRO, JUAN MANUEL; MEDRANO, PABLO MARTIN
To: FON TECHNOLOGY, SL
Reel/Frame 028099/0795 →
Continuity (3)
Provisional Application 61428620 · Dec 30, 2010
Provisional Application 61559460 · Nov 14, 2011
Related Publication 20120204241A1 · Aug 9, 2012