IP Library Granted Patent US 11,271,777
Granted Patent B2
US 11,271,777 · App. 17/359,800 · Granted Mar 8, 2022

System for controlling network access of terminal based on tunnel and method thereof

Inventors: Young Rang Kim (Seoul, KR); Min Jae Lee (Seoul, KR); Pil Ho Song (Seoul, KR); Joo Tae Kim (Seoul, KR)
Assignee: PRIBIT Technology, Inc.
H04L12/4633H04L12/4666H04L12/66H04L63/10H04L12/4625
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,271,777
App. No.
17/359,800
Granted
Mar 8, 2022
Kind
B2
Abstract

A node includes: a communication circuit; a processor operatively connected to the communication circuit; and a memory operatively connected to the processor and storing a target application and an access control application, wherein the memory stores instructions that when executed by the processor, cause the node to: detect a network access event of the target application to a destination network through the access control application, identify whether a tunnel corresponding to identification information of the target application and the destination network and authorized by an external server exists, transmit a data packet of the target application through the authorized tunnel using the communication circuit, when the authorized tunnel exists, and drop the data packet of the target application, when the authorized tunnel does not exist.

Claims (48)

1. A node comprising:

a communication circuit;

a processor operatively connected to the communication circuit; and

a memory operatively connected to the processor and storing a target application and an access control application,

wherein the memory stores instructions that when executed by the processor, cause the node to:

detect, through the access control application, a network access event of the target application to a destination network,

identify, through the access control application, whether a tunnel exists between the node and a gateway,

identify, through the access control application, whether the target application is accessible to the destination network, based on data flow information received from an external server, wherein the data flow information is based on the target application and the destination network,

in response to determining that the tunnel exists and the target application is accessible to the destination network, transmit, through the access control application, a data packet of the target application via the tunnel, and

in response to determining that the tunnel does not exist or the target application is not accessible to the destination network, drop, through the access control application, the data packet of the target application.

2. The node according to claim 1 , wherein the instructions cause the node to:

before detecting the network access event, request, through the access control application, controller access to the external server,

receive, from the external server, a first response comprising control flow information corresponding to the access control application and the external server.

3. The node according to claim 1 , wherein the instructions cause the node to:

in response to detecting the network access event, request, through the access control application, network access to the external server,

receive, from the external server, a second response comprising the data flow information.

4. The node according to claim 3 , wherein the instructions cause the node to:

before requesting the network access, perform, through the access control application, a validity check of the target application based on an access policy database received from the external server, and

drop the data packet of the target application, when the validity check of the target application fails.

5. The node according to claim 3 , wherein the data flow information further comprises information for generating the tunnel, and

wherein the instructions cause the node to:

in response to determining that the tunnel does not exist, generate the tunnel with the gateway based on the data flow information, and

when generating the tunnel is completed, transmit the data packet of the target application via the tunnel.

6. The node according to claim 1 , further comprising a display, and

wherein the instructions cause the node to:

output a screen provided from the destination network through the display when the data packet is transmitted, and

output a user interface screen indicating that access to the destination network is not allowed through the display when the data packet is dropped.

7. The node according to claim 1 , wherein the instructions cause the node to:

receive a user input requesting user authentication,

request user authentication to the external server, the user authentication request including information corresponding to the user input,

receive, from the external server, a third response indicating whether the user authentication is completed or not.

8. A method of a node in which a target application and an access control application are installed, comprising:

detecting, by the access control application, a network access event of the target application to a destination network;

identifying, by the access control application, whether a tunnel exists between the node and a gateway;

identifying, through the access control application, whether the target application is accessible to the destination network, based on data flow information received from an external server, wherein the data flow information is based on the target application and the destination network;

in response to determining that the tunnel exists and the target application is accessible to the destination network, transmitting, by the access control application, a data packet of the target application via the tunnel; and

in response to determining that the tunnel does not exist or the target application is not accessible to the destination network, dropping, by the access control application, the data packet of the target application.

9. A method of a sever comprising:

receiving, from an access control application of a node, a network access request of a target application of the node to a destination network;

identifying whether the target application is accessible to the destination network based on identification information of the target application and address information of the destination network; and

in response to determining that the target application is accessible to the destination network, transmitting data flow information which is based on the target application and the address information of the destination network.

10. A method of a gateway comprising:

receiving, from an external server, information required to generate a tunnel, wherein the information is based on a target application and a destination network;

generating the tunnel between the gateway and a node which stores the target application based on the information;

receiving a data packet;

identifying whether the received data packet is received through the tunnel;

in response to determining that the data packet is received through the tunnel, forwarding the data packet to the destination network; and

in response to determining that the data packet is not received through the tunnel, dropping the data packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2021
From: KIM, YOUNG RANG; LEE, MIN JAE; SONG, PIL HO; KIM, JOO TAE
To: PRIBIT TECHNOLOGY, INC.
Reel/Frame 057023/0489 →
Priority Claims (1)
KR 10-2020-0030721 · Mar 12, 2020 · national
Continuity (4)
Continuation 17030918 · Sep 24, 2020
Continuation In Part 16580866 · Sep 24, 2019
Continuation In Part 16580974 · Sep 24, 2019
Related Publication 20210328830A1 · Oct 21, 2021
Cited By (4)
US 12,267,304 US 12,348,494 US 12,381,890 US 12,519,754