CA2275561A1 - Communication system and method increasing security - Google Patents

Communication system and method increasing security Download PDF

Info

Publication number
CA2275561A1
CA2275561A1 CA002275561A CA2275561A CA2275561A1 CA 2275561 A1 CA2275561 A1 CA 2275561A1 CA 002275561 A CA002275561 A CA 002275561A CA 2275561 A CA2275561 A CA 2275561A CA 2275561 A1 CA2275561 A1 CA 2275561A1
Authority
CA
Canada
Prior art keywords
dial
access route
server
user terminal
information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Abandoned
Application number
CA002275561A
Other languages
French (fr)
Inventor
Kazuhiko Harasaki
Hideyuki Hirata
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
NEC Corp
Original Assignee
NEC Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by NEC Corp filed Critical NEC Corp
Publication of CA2275561A1 publication Critical patent/CA2275561A1/en
Abandoned legal-status Critical Current

Links

Abstract

A communication method for increasing security for information communicating between a user terminal and a service provider via a PPP (point-to-point protocol) server is disclosed.
A dial-up connection is set up between the user terminal and the PPP server via a public network and an Internet access route is set up between the PPP server and the WWW server through the Internet. When card ID information is transferred between the user terminal and the service provider, a dial-up access route is set up between the PPP server and the dial-up server through the public network. The Internet access route is changed to the dial-up access route to transmit the card ID information through the dial-up access route. When processing of the card ID
information has been completed, the dial-up access route is disconnected and changed back to the Internet access route.

Description

COMMUNICATION SYSTEM AND METHOD INCREASING SECURITY
BACKGROUND OF THE INVENTION
1. Field of the invention The present invention generally relates to data communications system and in particular to a system and method for increasing security for personal information and secret information such as the identification number of a credit card.
2. Description of the Related Art In on-line shopping through the Internet using a credit card, it is necessary to send the personal information and the card identification number to the service provider for settlement of accounts. However, the Internet has the possibility of data leakage, causing a security problem. To increase security for such important information, several methods and systems have been proposed.
In Japanese Patent Unexamined Publication No. 9-305682, a user PC (personal computer) is connected to a service provider via a public network (PSTN/ISDN) and the service provider is connected to an information provider server via the Internet . The user PC is also connected to the information provider server via the public network. In this system, secret information such as the user's card id is transferred through PSTN/ISDN and the FQ5-373 , information other than the secret information is transferred through the Internet. Similar system and method are disclosed in Japanese Patent Unexamined Publication No.8-340332.
According to the conventional system, a user PC needs two communication devices for data communication and security communication. In other words, when doing settlement of accounts in on-line shopping via the Internet, the user PC needs to disconnect the Internet access route before setting up the dial-up access route.
SUMMARY OF THE INVENTION
An object of the present invention is to provide communications system and method which can achieve enhanced security for important information without a user terminal switching the route.
According to an aspect of the present invention, a communication method for increasing security for information communicating between a user terminal and a service providing site via a PPP (point-to-point protocol) server, includes the following steps . A dial-up connection is set up between the user terminal and the PPP server via a public network and an Internet access route is set up between the PPP server and the service providing site through the Internet to allow communication between the user terminal and the service provider. Thereafter, when important information is transferred between the user terminal and the service providing site, a dial-up access route is set up between the PPP server and the service providing site through the public network, changing from the Internet access route to the dial-s up access route to transmit the important information through the dial-up access route. When processing of the important information has been completed, the dial-up access route is disconnected and switched back to the Internet access route.
According to another aspect of the present invention, the PPP server transmits dial-up information and PPP user information identifying the user terminal within the PPP server to the service providing site through an Internet access route. The service providing site sets up a dial-up connection to the PPP server using the dial-up information and transmits the user information to the PPP server. The PPP server connects the user terminal to the service providing site through the dial-up connection to produce a dial-up access route depending on the user information received from the service providing site through the dial-up connection, wherein secret information is transferred from the user terminal to the service providing site through the dial-up access route .
And the PPP server disconnects the dial-up connection when processing of the secret information has been completed at the service providing site.
Since the route changing is done between the PPP server and the service providing site, the security for important information such as credit-card ID can be increased without the user terminal disconnecting and restoring the route.
BRIEF DESCRIPTION OF THE DRAWINGS
Fig. 1 is a block diagram showing a system configuration according to an embodiment of the present invention; and Fig. 2 is a sequence diagram showing an operation of the embodiment as shown in Fig. 1.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENT
Hereinafter, taking an on-line shopping system as an example, an embodiment of the present invention will be described in detail.
Referring to Fig . 1, a user terminal which may be a personal computer equipped with a communication device such as a modem connected to a public telephone network 102 . The public telephone network 102 may be a public switched telephone network ( PSTN ) or an integrated services digital network (ISDN). The user terminal 101 can be connected to a PPP (point-to-point protocol) server 103 via the public telephone network 102. The PPP server 103 is connected to a computer network ( the Internet 105 ) through a fire wall 104 for security and further is connected to an on-line shopping service provider 106 via the Internet 105. The service provider 106 is provided with a WWW (World Wide Web) server 107 and a dial-up account-settlement server 108. Therefore, the user can access the WWW server 107 through an Internet access route.
As will be described later, when receiving account-settlement information from the WWW server 107, the dial-up account-settlement server 108 sets up a connection to the PPP
server 103 by a dial-up access over the public telephone network 109 which may be the same as the public telephone network 102.
And important information to be secret such as credit-card ID and personal information is transferred through the dial-up access route.
The PPP server 103 accommodates a plurality of users and has a plurality of user ports 110 connected to the public telephone network 102. Therefore, the user terminal 101 can be connected to the PPP server 103 by dial-up access over the public telephone network 102. The PPP server 103 further has an Internet port 111 connected to the Internet 105 through the fire wall 104 and a special port 112 which is connected to the public telephone network 109 with limited access permission (in the case of no contract between the PPP server 103 and the dial-up account-settlement server 108).
The PPP server 103 is provided with a router 113 and a control processor 114. Under control of the control processor 114, the router 113 normally connects the user port 110 to the Internet port 111 to cause the user to access the WWW server 107 through the Internet access route. However, when receiving the dial-up connection setup request from the dial-up account-settlement server 108, the control processor 114 controls the router 113 using the user information such that the route is changed from the current Internet access route between the user port 110 and the Internet port 111 to a dial-up access route between the user port 110 and the special port 111. When the dial-up account-settlement server 108 completes the settlement of accounts, the dial-up access route is disconnected and the control processor 114 controls the router 113 such that the route is changed from the dial-up access route back to the Internet access route.
Next, an on-line shopping operation according to the embodiment will be described in detail with reference to Fig. 2.
Referring to Fig. 2, after a dial-up connection has been set up between the user terminal 101 and the PPP server 103 , the user terminal 101 sends an address of the WWW server 107 on the Internet 105 to the PPP server 103. When receiving the address of the WWW server 107 from the user terminal 101 at the user port 110 , the PPP server 103 connects the user port 110 to the Internet port 111 and sets up a data link to the WWW server 107 ( step S201 ) .
This causes WWW files to be transmitted from the WWW server 107 to the user terminal 101 through the Internet access route and the WWW files are displayed on a WWW browser running on the user terminal 101 (step 5202).
When the user clicks an order button for an item on the WWW
browser, the order data of the selected item is sent to the PPP

server 103 through the public telephone network 102 and then the PPP server 103 transmits PPP server information thereof and user information to the WWW server 107 of the service provider 106.
The PPP server information is used as dial-up information to the special port 112 by the dial-up account-settlement server 108 of the service provider 106. The user information is a user identification in the PPP server 103. When receiving the order data, the PPP server information and the user information from the PPP server 103, the WWW server 107 transfers them to the dial-up account-settlement server 108 (step S203).
The dial-up account-settlement server 108 uses the PPP
server information of the PPP server 103 to make a dial-up connection to the special port 112 through the public telephone network 109 and, after the dial-up connection has been established, logs in to the PPP server 103 (step S204).
After logging in to the PPP server 103, the dial-up account-settlement server 108 sends the user information to the PPP server 103 through the public telephone network 109 ( step 5205 ) .
When receiving the user information from the dial-up account-settlement server 108, the processor 114 of the PPP server 103 connects the special port 112 to the user port 110 identified by the user information. In other words, the router 113 changes from the Internet access route to the dial-up access route ( step S206 ) .
Therefore, the user terminal 101 is connected to the dial-up account-settlementserver108via the dial-up access route without the user terminal 101 performing any route changeover.

After the dial-up access route has been established, the user terminal 101 transmits the credit-card ID and the personal information of the user and other secret information to the dial-up account-settlement server 108 via the dial-up access route ( step S207 ) . Then, the dial-up account-settlement server 108 performs the settlement of accounts for the purchased item (step S208).
When the settlement of accounts has been completed, the dial-up account-settlement server 108 disconnects the dial-up access route (step 5209).
When the dial-up access route is disconnected, the control processor 114 of the PPP server 103 restores the Internet access route to the WWW server 107 through the Internet 105. In other words, the router 113 changes the route state such that the user port 110 is connected to the Internet port 111 (step 5210). In this case, the user terminal 101 continues to be connected to the PPP server 103 through the public telephone network 102 and is in no need of any route changeover.
When informed of the completion of the account settlement (step S211) and the user no longer purchases any more, the user terminal 101 disconnects the Internet access route (step S212).
As described above, a relatively low security network such as the Internet is used to access public information files and communicate with a public WWW site. A relatively high security network such as the public telephone network is used for transmission of more important information such as user ID and personal information. Such network switching between the relatively low and high security networks is performed between the PPP server and the accessed server and the dial-up connection between the user terminal and the PPP server is in no need of disconnection or changeover. Therefore, the user terminal needs only one communication device for connection to the public telephone network 102.
The present invention can be applied to not only the on-line shopping system but also other service system such as electronic commerce or electronic-facilitated transactions requiring transmission of information to be secret.

Claims (11)

What is claimed is:
1. A communication method for increasing security for information communicating between a user terminal and a service providing site via a PPP (point-to-point protocol) server, comprising the steps of:
setting up a dial-up connection between the user terminal and the PPP server via a public network;
setting up an Internet access route between the PPP
server and the service providing site through the Internet to allow communication between the user terminal and the service provider;
setting up a dial-up access route between the PPP
server and the service providing site through the public network when important information is transferred between the user terminal and the service providing site;
changing from the Internet access route to the dial-up access route to transmit the important information through the dial-up access route; and disconnecting the dial-up access route and changing back to the Internet access route when processing of the important information has been completed.
2. The communication method according to claim 1, wherein the PPP server comprises:
a user port for accommodating the user terminal;

an Internet port for communicating with the service providing site through the Internet access route;
a special port for communicating with the service providing site through the dial-up access route; and a router for changing a route state from a first state that the user port is connected to the Internet port to a second state that the user port is connected to the special port, depending on a dial-up connection request received from the service providing site.
3. The communication method according to claim 1, wherein the service providing site comprises:
a WWW (World Wide Web) server for providing Internet information to the user terminal through the Internet access route; and a dial-up server for setting up the dial-up access route depending on an instruction received from the WWW server when the important information is needed.
4. The communication method according to claim 1, wherein the important information is secret information of a user associated with the user terminal.
5. The communication method according to claim 1, wherein changing between the Internet access route and the dial-up access route is done without disconnecting the dial-up connection between the user terminal and the PPP server.
6. A communication method for communicating between a user terminal and a service providing site via a PPP
(point-to-point protocol) server, comprising the steps of:
at the PPP server, transmitting dial-up information and PPP user information identifying the user terminal within the PPP server to the service providing site through an Internet access route;
at the service providing site, setting up a dial-up connection to the PPP server using the dial-up information;
transmitting the user information to the PPP server;
at the PPP server, connecting the user terminal to the service providing site through the dial-up connection to produce a dial-up access route depending on the user information received from the service providing site through the dial-up connection, wherein secret information is transferred from the user terminal to the service providing site through the dial-up access route; and disconnecting the dial-up connection when processing of the secret information has been completed at the service providing site.
7. The communication method according to claim 6, wherein the service providing site comprises:

13~

a WWW (World Wide Web) server for providing Internet information to the user terminal through the Internet access route; and a dial-up server for setting up the dial-up access route depending on an instruction received from the WWW server when the secret information is needed.
8. The communication method according to claim 6, wherein at the PPP server, disconnection of the dial-up access route is done without disconnecting the dial-up connection between the user terminal and the PPP server.
9. A communication system for increasing security for information communicating between a user terminal and a service providing site via a PPP (point-to-point protocol) server, ] the PPP server comprising:
a user port for setting up a dial-up connection to the user terminal via a public network;
an Internet port for setting up an Internet access route to the service providing site through the Internet to allow communication between the user terminal and the service provider;
a dial-up port for setting up a dial-up access route to the service providing site through the public network depending on a request of the service providing site when important information is transferred between the user terminal and the service providing site;

a router for changing a connection state among the user port, the Internet port and the dial-up port; and a controller controlling the router such that the switch changes the connection state from the Internet access route to the dial-up access route to transmit the important information through the dial-up access route and disconnects the dial-up access route and switches back to the Internet access route when processing of the important information has been completed, and the service providing site comprising:
a WWW (World Wide Web) server for providing Internet information to the user terminal through the Internet access route; and a dial-up server for setting up the dial-up access route depending on an instruction received from the WWW server when the important information is needed.
10. The communication system according to claim 9, wherein the important information is secret information of a user associated with the user terminal.
11. The communication system according to claim 9, wherein changing between the Internet access route and the dial-up access route is done without disconnecting the dial-up connection between the user terminal and the PPP server.
CA002275561A 1998-06-19 1999-06-18 Communication system and method increasing security Abandoned CA2275561A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP18806698A JP2000010921A (en) 1998-06-19 1998-06-19 Communication method and system and recording medium
JP188066/1998 1998-06-19

Publications (1)

Publication Number Publication Date
CA2275561A1 true CA2275561A1 (en) 1999-12-19

Family

ID=16217118

Family Applications (1)

Application Number Title Priority Date Filing Date
CA002275561A Abandoned CA2275561A1 (en) 1998-06-19 1999-06-18 Communication system and method increasing security

Country Status (2)

Country Link
JP (1) JP2000010921A (en)
CA (1) CA2275561A1 (en)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001325551A (en) * 2000-05-17 2001-11-22 成禎 ▲高▼岡 On-line settlement system and commodity selling center
US7917751B2 (en) 2003-05-22 2011-03-29 International Business Machines Corporation Distributed filesystem network security extension

Also Published As

Publication number Publication date
JP2000010921A (en) 2000-01-14

Similar Documents

Publication Publication Date Title
CA2205124C (en) A mechanism for enabling secure electronic transactions on the open internet
JP3795754B2 (en) Communication method between a user device and a network, in particular the Internet, and an architecture for the implementation of the communication method
JP3877782B2 (en) Method and apparatus for secure data communication
EP0801479B1 (en) Data network security system and method
KR100343172B1 (en) Wireless data transmission method and interworking device between mobile terminal and heterogeneous signal
JP3989960B2 (en) Method and apparatus for improving network transaction performance using network address information
JP3471523B2 (en) Communication method and communication terminal
US6912593B2 (en) Information switching platform
KR19990068618A (en) Method for financial transaction using a mobile commnication network and system for performing the same
CN100514925C (en) Resource sharing broadband access system, methods, and devices
JP2003110596A (en) Data communication service providing method
US6178454B1 (en) Data communication method and system therefor
CA2275561A1 (en) Communication system and method increasing security
KR100285743B1 (en) Point-to-point protocol
KR100763145B1 (en) Network apparatus using branch processor with routing function
JP2972581B2 (en) PC compatible wireless modem card device
JPH10229416A (en) Information processing method and information processor
KR100642320B1 (en) Externally-mounted wireless modem
JP3439153B2 (en) Wireless terminal authentication method
KR100318309B1 (en) How to process incoming intelligent network service number in outgoing intelligent network service
WO2001027709A8 (en) Access control of a service
CA2161983A1 (en) Confidential information transmission bypassing the internet
JP2000244640A (en) Method for transmitting communication signal to network server through communication network from telephone exchange
WO2002027597A2 (en) E-commerce transactions using pre-paid phone service
JP2002077307A (en) Line-switching method of information-processing device

Legal Events

Date Code Title Description
EEER Examination request
FZDE Discontinued
FZDE Discontinued

Effective date: 20031208