IP Library Granted Patent US 9,008,056
Granted Patent B2
US 9,008,056 · App. 13/001,407 · Granted Apr 14, 2015

Remote network access via a visited network

Inventors: Erwan Le Ber (Lannion, FR); Philippe Hemon (Tregastel, FR)
Assignee: Orange
H04L63/101H04L29/12066H04L29/12594H04L29/12839H04L61/1511H04L61/304H04L61/6022H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,008,056
App. No.
13/001,407
Granted
Apr 14, 2015
Kind
B2
Abstract

Remote access for a terminal to a first network via a second network is managed; the first network being linked to the second network via a network apparatus. At the level of the network apparatus, there is received, from the terminal via the second network, a request for remote access to the first network indicating access information comprising a first parameter corresponding to a physical address of the terminal and a second parameter corresponding to a secret key of the gateway. The network apparatus thereafter decides whether the terminal is authorized to remotely access the first network on the basis of said access information. This network apparatus subsequently emits, bound for the terminal via the second network, a message indicating whether the terminal is authorized to remotely access the first network.

Claims (52)

1. A remote access management method for managing remote access for a terminal to a first network via a second network; said first network being connected to the second network via a network equipment functioning as a gateway, said network equipment managing a list linking respective items of access information to each registered terminal;

said method comprising the following steps applied at the network equipment:

receiving, from the terminal via the second network, a request for remote access to the first network indicating access information;

deciding that the terminal is authorized to remotely access the first network when the access information indicated in the remote access request corresponds to the access information associated with said terminal in said list; and

transmitting, to the terminal via the second network, a message indicating whether the terminal is authorized to remotely access the first network, wherein said access information comprises a first parameter corresponding to a Media Access Control (MAC) address of the terminal and a second parameter corresponding to a secret key of the network equipment, and

wherein the network equipment registers with a Domain Name System (DNS) server by transmitting a registration request indicating a MAC address of the network equipment.

2. The remote access management method as claimed in claim 1 , wherein the network equipment provides a service in the first network, and provides said service via the second network to the terminal authorized to remotely access the first network.

3. A remote access management method for managing remote access for a terminal to a first network via a second network; said first network being connected to the second network via a network equipment functioning as a gateway, said network equipment managing a list linking respective items of access information to each registered terminal, wherein the terminal has a Media Access Control (MAC) address of the network equipment;

said method comprising the following steps applied at the terminal:

transmitting to a Domain Name System (DNS) platform an address request indicating the MAC address of the network equipment;

receiving a response indicating an IP address of the network equipment;

transmitting, to the network equipment via the second network, a remote access request indicating access information; and

receiving, from the network equipment via the second network, a message indicating whether the terminal is authorized to remotely access the first network, the network equipment deciding that the terminal is authorized to access the first network when the access information indicated in the remote access request corresponds to the access information associated with said terminal in said list;

wherein said access information includes a first parameter corresponding to a MAC address of the terminal and a second parameter corresponding to a secret key of the network equipment.

4. A network equipment functioning as a gateway in a system for managing remote access for a terminal to a first network via a second network;

said network equipment connecting said first network to the second network;

said network equipment comprising:

a manager for managing a list linking respective items of access information to each registered terminal;

a registration unit suitable for registering a Media Access Control (MAC) address of the terminal when said terminal is in the first network and for registering with a Domain Name System (DNS) server by transmitting a registration request indicating a MAC address of the network equipment;

a reception unit that receives, from said terminal via the second network, an access request indicating access information;

a decision unit decides that the terminal is authorized to access the first network when the items of access information indicated in the remote access request correspond to the items of access information associated with said terminal in said list; and

a transmission unit that transmits, to the terminal via the second network, a message indicating whether the terminal is authorized to access the first network,

wherein said access information includes a first parameter corresponding to said MAC address of the terminal and a second parameter corresponding to a secret key of the network equipment.

5. A terminal in a system for managing remote access to a first network via a second network;

said first network being connected to the second network via a network equipment functioning as a gateway, said network equipment managing a list linking respective items of access information to each registered terminal,

wherein the terminal has a Media Access Control (MAC) address of the network equipment;

the terminal comprising:

a registration unit that registers the terminal with the network equipment when the terminal is in the first network, and provides said network equipment with a MAC address of the terminal;

a first transmission unit that transmits to a Domain Name System (DNS) platform an address request indicating the MAC address of the network equipment;

a first reception unit that receives a response indicating an IP address of the network equipment;

a second transmission unit that transmits, to the network equipment via the second network, a remote access request indicating access information; and

a second reception unit that receives, from the network equipment via the second network, a message indicating whether the terminal is authorized to access the first network remotely, the network equipment deciding that the terminal is authorized to access the first network when the access information indicated in the remote access request corresponds to the access information associated with said terminal in said list;

wherein said access information includes a first parameter corresponding to said MAC address of the terminal and a second parameter corresponding to a secret key of the gateway.

6. A system for managing remote access to a first network via a second network for a terminal, the system comprising:

the terminal; and

a network equipment that functions as a gateway and manages a list that links respective items of access information to each registered terminal;

said first network being connected to the second network via the network equipment;

said network equipment comprising:

a registration unit suitable for registering a physical address of the terminal when said terminal is in the first network;

a reception unit that receives, from said terminal via the second network, an access request indicating access information;

a decision unit that decides whether the terminal is authorized to access the first network on the basis of said access information; and

a transmission unit that transmits, to the terminal via the second network, a message indicating whether the terminal is authorized to access the first network,

wherein said access information includes a first parameter corresponding to said physical address of the terminal and a second parameter corresponding to a secret key of the network equipment;

wherein the terminal has a Media Access Control (MAC) address of the network equipment, the terminal comprising:

a registration unit that registers the terminal with the network equipment when the terminal is in the first network, and provides said network equipment with a MAC address of the terminal;

a first transmission unit that transmits to a Domain Name System (DNS) platform an address request indicating the MAC address of the network equipment;

a first reception unit that receives a response indicating an IP address of the network equipment;

a second transmission unit that transmits, to the network equipment via the second network, a remote access request indicating access information; and

a second reception unit that receives, from the network equipment via the second network, a message indicating whether the terminal is authorized to access the first network remotely, the network equipment deciding that the terminal is authorized to access the first network when the access information indicated in the remote access request corresponds to the access information associated with said terminal in said list;

wherein said access information includes a first parameter corresponding to said MAC address of the terminal and a second parameter corresponding to a secret key of the gateway.

7. A non-transitory computer readable storage medium, storing computer instructions to perform the remote access management method of claim 1 .

8. A non-transitory computer readable storage medium, storing computer instructions to perform the remote access management method of claim 3 .

Assignments (2)
CHANGE OF NAME Recorded Mar 10, 2015
From: FRANCE TELECOM
To: ORANGE
Reel/Frame 035125/0598 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2011
From: LE BER, ERWAN; HEMON, PHILIPPE
To: FRANCE TELECOM
Reel/Frame 026201/0741 →
Priority Claims (1)
FR 08 54186 · Jun 24, 2008 · national
Continuity (1)
Related Publication 20110208863A1 · Aug 25, 2011