EP1721436A1 - Procede et systeme d'acces par un client a des services fournis par un fournisseur de services - Google Patents
Procede et systeme d'acces par un client a des services fournis par un fournisseur de servicesInfo
- Publication number
- EP1721436A1 EP1721436A1 EP05707685A EP05707685A EP1721436A1 EP 1721436 A1 EP1721436 A1 EP 1721436A1 EP 05707685 A EP05707685 A EP 05707685A EP 05707685 A EP05707685 A EP 05707685A EP 1721436 A1 EP1721436 A1 EP 1721436A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- client
- network
- compliant
- session
- clients
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000000034 method Methods 0.000 title claims abstract description 26
- 238000012546 transfer Methods 0.000 claims abstract description 30
- 238000013475 authorization Methods 0.000 claims description 4
- 239000011692 calcium ascorbate Substances 0.000 claims description 4
- 235000010376 calcium ascorbate Nutrition 0.000 claims description 4
- 239000004261 Ascorbyl stearate Substances 0.000 claims description 3
- 239000004283 Sodium sorbate Substances 0.000 claims description 3
- 239000004302 potassium sorbate Substances 0.000 claims description 3
- 239000004334 sorbic acid Substances 0.000 claims description 3
- 239000011668 ascorbic acid Substances 0.000 claims description 2
- 235000010323 ascorbic acid Nutrition 0.000 claims description 2
- 238000004590 computer program Methods 0.000 claims description 2
- PPASLZSBLFJQEF-RKJRWTFHSA-M sodium ascorbate Substances [Na+].OC[C@@H](O)[C@H]1OC(=O)C(O)=C1[O-] PPASLZSBLFJQEF-RKJRWTFHSA-M 0.000 claims description 2
- 235000010378 sodium ascorbate Nutrition 0.000 claims description 2
- 239000012141 concentrate Substances 0.000 claims 1
- XLYOFNOQVPJJNP-UHFFFAOYSA-N water Substances O XLYOFNOQVPJJNP-UHFFFAOYSA-N 0.000 claims 1
- 238000004891 communication Methods 0.000 description 9
- 238000005516 engineering process Methods 0.000 description 6
- 235000010385 ascorbyl palmitate Nutrition 0.000 description 4
- 239000000542 fatty acid esters of ascorbic acid Substances 0.000 description 4
- 238000012790 confirmation Methods 0.000 description 2
- 239000000541 tocopherol-rich extract Substances 0.000 description 2
- 230000005540 biological transmission Effects 0.000 description 1
- 239000004303 calcium sorbate Substances 0.000 description 1
- 239000000835 fiber Substances 0.000 description 1
- 230000006870 function Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/2854—Wide area networks, e.g. public data networks
- H04L12/2856—Access arrangements, e.g. Internet access
- H04L12/2858—Access network architectures
- H04L12/2859—Point-to-point connection between the data network and the subscribers
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/66—Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/18—Multiprotocol handlers, e.g. single devices capable of handling multiple protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/16—Implementing security features at a particular protocol layer
- H04L63/162—Implementing security features at a particular protocol layer at the data link layer
Definitions
- the present invention relates to a method and system for client access to services provided by a service provider.
- the invention relates to the field of access by a client to services provided by a service provider in which the client is able to transmit and / or receive information according to a point-to-point transport protocol via a telecommunications network and a session concentrator capable of transmitting and / or receiving information according to the point-to-point transport protocol, and in which an access control protocol is used in the telecommunications network to control access to services provided by the service provider.
- each client is connected to a digital multiplexer of client lines which is itself connected to a PPP session concentrator.
- DSL is the acronym for "Digital Subscriber Line”
- PPP is the acronym for "Point to Point Protocol”.
- a PPP session is a session established according to a point-to-point protocol such as for example the protocol defined in the IETF recommendation? RJFC 2516.
- a PPP session concentrator is conventionally called a BAS, acronym for "Broadband Access Server”.
- a PPP session concentrator routes the sessions established by the different network clients to the point of presence of the service provider to which they are subscribed.
- the telecommunication networks used in the prior art are based on ATM technology, acronym for "Asynchronous Transfer Mode".
- the virtual channels of clients subscribed to the same service provider, or even to a service of the service provider, are grouped in the same virtual paths or VP between the different digital multiplexers of client lines and the PPP session concentrator.
- Telecommunications networks based on ATM technology are complex and difficult to evolve.
- the deployment of networks based on technologies other than ATM is envisaged.
- GigaEthernet networks offer a very high bandwidth for the transmission of information.
- These networks use accreditation protocols for access to a network such as for example the protocol defined in the IEEE 802 standard. Ix.
- the accreditation protocol as defined in the IEEE 802 standard. Ix is also called the access control protocol.
- the object of the invention is to solve the drawbacks of the prior art by proposing a method and a system for access by a client to services provided by a service provider in which clients conform to the protocols used in telecommunications networks.
- the invention proposes a method of access by a client to services provided by a service provider, the client being able to transmit and / or receive information according to a point-to-point transport protocol.
- an access control protocol is used in the telecommunications network to control access to the services provided by the service provider and in that it comprises the steps of: - determining whether or not the client is in compliance with the access control protocol, - authorization of the non-compliant client with the access control protocol to access a network for non-compliant clients, the network for non-compliant clients being established on the telecommunications network n and allowing access to the session concentrator, - establishment of a session between the non-compliant client and the session concentrator according to the point-to-point transport protocol on the network for non-compliant clients, - transfer, by the session concentrator, information transmitted by the non-compliant client in the established session to a network for clients compliant with the access control protocol, the network for compliant clients being established on the telecommunications network and allowing access to services provided by the service provider and vice versa.
- the invention relates to a system for access by a client to services provided by a service provider, the client being able to transmit and / or receive information according to a point-to-point transport protocol via '' a telecommunications network and a session concentrator capable of transmitting and / or receiving information according to the point-to-point transport protocol, characterized in that an access control protocol is used in the telecommunications network for control access to the services provided by the service provider and in that the system includes: - means for determining whether or not the client is in compliance with the access control protocol, - means of authorizing the non-compliant client with the access control protocol to access a network for non-compliant clients, the network for non-compliant clients being established on the telecommunications network and allowing access to the session concentrator , - means for establishing a session between the non-conforming client and the session concentrator according to the point-to-point transport protocol on the network for non-conforming clients, - means for transferring, by the session concentrator
- a client able to transmit and / or receive information according to a point-to-point transport protocol, to access services provided by a service provider even if the latter is not compatible with the access control protocol allowing access to the services of service providers.
- the client can access a session concentrator capable of transmitting and / or receiving information according to the point-to-point transport protocol.
- the session concentrator can thus transmit the information transmitted by the client to a network for compliant clients and thus allow access to the services provided by the service provider.
- the session concentrator determines among the information transmitted by the service provider in the network for conforming clients, information intended for the non-conforming client and transfers the determined information to the non-conforming client in the session established between the noncompliant client and the session concentrator.
- a non-compliant customer can receive information from a service provider or from a service from a service provider.
- several service providers are accessible by clients, each service provider being accessible by at least one network for clients conforming to the access control protocol and the session concentrator determines the network for clients. comply with the access control protocol allowing access to the customer's service provider not compliant and transfers information transmitted by the non-compliant client in the established session to the network for determined compliant clients.
- the session concentrator receives at least one broadcast message sent by the non-conforming client on the client network non-compliant, the broadcast message comprising at least the address of the non-compliant client and the session concentrator transfers over the network for non-compliant clients at least one identification request message intended for the non-compliant client.
- the session concentrator receives at least one message comprising at least one identifier sent by the non-conforming client on the network for non-compliant clients, transfers the identifier to an authentication server, obtains an authenticator from the non-compliant client, transfers the authenticator to the authentication server and establishes the session if the authentication server authenticates the non-compliant client.
- the session concentrator receives at least one message comprising at least one identifier sent by the non-conforming client on the network for non-compliant clients, transfers the identifier to an authentication server, obtains an authenticator from the non-compliant client, transfers the authenticator to the authentication server and establishes the session if the authentication server authenticates the non-compliant client.
- the client accesses the telecommunications network via a digital customer line multiplexer and the digital customer line multiplexer determines whether or not the customer is in compliance with the control protocol d 'access.
- the digital customer line multiplexer authorizes the compliant client with the access control protocol to access a network for compliant clients, the network for compliant customers being established on the telecommunications network and allowing access to a service provider.
- compliant customers can directly access networks allowing access to a service provider without the need to establish a PPP session conforming to the point-to-point transport protocol such as for example the protocol conforming to RFC 2516.
- each service provider being accessible by at least one network for clients conforming to the access control protocol and the digital multiplexer of client lines determines the network for clients in compliance with the access control protocol allowing access to the service provider of the compliant client and transfers the information transmitted by the compliant client to the network for determined compliant clients.
- the telecommunications network is a GigaEthemet type network
- the access control protocol is an IEEE 802.
- the point-to-point transport protocol is a protocol conforming to RFC 2516 recommendation.
- a GigaEthemet network is a high speed telecommunications network based on Ethernet technology.
- a GigaEthemet network allows data transfers at rates higher than one Gigabits per second.
- the information transmitted according to the point-to-point transport protocol is in the form of packets and the session concentrator, before the transfer of the information transmitted by the non-compliant client in the established session to a network for clients conform to the access control protocol, form from packets of information frames.
- the invention also relates to computer programs stored on an information medium, said programs comprising instructions making it possible to implement the method described above, when it is loaded and executed by a computer system.
- Fig. 1 represents the architecture of the system for accessing services provided by service providers by a client, whether or not it conforms to an authentication and access control protocol via a telecommunications network
- Fig. 2 represents the algorithm implemented by a digital multiplexer of the customer line telecommunication network for the access to services provided by service providers by a customer conforming or not to an authentication and control protocol. access
- Fig. 3 represents the algorithm implemented by a session concentrator of the telecommunication network for the access to services provided by service providers by a client not conforming to an authentication and access control protocol.
- Fig. 1 represents the architecture of the system for accessing services provided by service providers by a client, whether or not it conforms to an authentication and access control protocol via a telecommunications network.
- clients 110a, 110b and 110c access providers of services 160, 170 and 180 via a digital multiplexer for customer lines 130, a telecommunications network 150 and a session concentrator 100.
- the digital multiplexer for customer lines 130 determines whether or not a client 110 complies with an access control protocol and directs communications from the non-compliant client 110 to a network for clients that do not comply with the access control protocol.
- the network for clients not conforming to the access control protocol is preferably a virtual network established on the telecommunications network 150.
- the network for non-conforming clients 140 can also alternatively be a physical network distinct from the telecommunications network 150.
- the multiplexer digital of customer lines 130 includes a communication bus 201 to which a central unit 200, a non-volatile memory 202, a random access memory 203, a customer interface 205 and a network interface are connected
- the non-volatile memory 202 stores the programs implementing the invention such as the algorithm which will be described later with reference to FIG. 2.
- the non-volatile memory 202 is for example a hard disk. More generally, the programs according to the present invention are stored in a storage means. This storage means can be read by a computer or a microprocessor 200. This storage means is integrated or not in the digital multiplexer of customer lines 130, and can be removable. When the digital multiplexer for customer lines 130 is switched on, the programs are transferred to the random access memory 203 which then contains the executable code of the invention as well as the data necessary for the implementation of the invention.
- the digital customer line multiplexer 130 also includes a telecommunications network interface 206.
- the digital customer line multiplexer 130 also includes a customer interface 205. This interface is in a preferred embodiment of a DSL type interface.
- the client interface 205 includes for each client 110a, 110b and 110c a port dedicated to point-to-point communications between the digital multiplexer of client lines 130 and the client 110 connected to this port.
- the digital multiplexer for customer lines 130 includes means for determining whether a customer 110 is in conformity with an access control protocol used in the telecommunications network 150 to control access to the services provided by the suppliers of services 160, 170 and 180. These determination means are more precisely the processor 200 which executes the instructions of the algorithm of FIG. 2.
- the digital customer line multiplexer 130 also includes means for authorizing the customer 110 which does not comply with the access control protocol to access a network for non-compliant customers 140 established on the telecommunications network 150 and allowing the access to a session concentrator 100.
- the session concentrator 100 is more precisely a PPP session concentrator 100.
- the PPP session concentrator 100 is connected to the network for non-compliant clients 140 and transfers the messages sent by the non-compliant client 110 to a network for compliant clients 161, 162 or 163 after formatting of the messages sent by the client 110.
- a PPP session is a session established according to a point-to-point protocol. Client compliant networks 161, 162 or 163 thus allow access to services provided by service providers 160, 170 and 180.
- Client client networks compliant with the access control protocol are preferably virtual networks established on the telecommunications network 150 and in which it is not necessary to establish a PPP session to access the services provided by the service providers.
- the digital customer line multiplexer 130 is connected via its interface 205 to customers 110a, 110b and 110c by dedicated physical links.
- the dedicated physical links are of DSL type
- the digital multiplexer for customer lines 130 is known by the term DSLAM.
- DSLAM is the acronym for "Digital Subscriber Line Access Multiplexor".
- the function of the digital customer line multiplexer 130 is to group together several customer lines 110a, 110b and 110c on a physical medium which ensures the transport of the data exchanged between customers 110a, 110b and 110c and their respective service providers 160, 170 or 180.
- the digital multiplexer of customer lines 130 is connected to the telecommunications network 150 which is for example a network of the GigaEthemet type.
- Networks for compliant customers 161, 162 and 163 are established on the telecommunications network 150 between the digital multiplexer of customer lines 130 and each service provider 160 and 180.
- the information conveyed on the networks for compliant customers 161, 162 and 163 are transmitted in the form of Ethernet frames.
- a network for non-compliant customers 140, distinct from the networks for non-compliant customers 161, 162 and 163 is also established for access, by a customer not complying with an access control protocol, to the services provided by service providers.
- the access control protocol is more precisely an authentication and access control protocol such as for example the IEEE 802 protocol. Ix.
- the networks for compliant clients 161, 162 and 163 are preferably virtual networks.
- Virtual networks or VLANs acronym for "Virtual Local Arèa Network”
- VLANs acronym for "Virtual Local Arèa Network”
- One or more virtual networks can also be associated with one or more services of the service provider 160.
- the clients 110a, 110b and 110c are more precisely telecommunications terminals.
- the clients 110 are connected to the digital multiplexer of client lines 130 via the switched telephone network and use modulation techniques of the DSL type.
- a client 110 is for example a telecommunication device such as a computer comprising a communication card suitable for the existing link with the digital multiplexer for customer lines 130 or a computer connected to an external communication device suitable for the existing link with the digital customer line multiplexer 130.
- FIG. 1 only three customers 110a, 110b and 110c are represented. Of course, a larger number of clients 110 are connected to the digital multiplexer of client lines 130.
- the session concentrator 100 or more precisely the PPP session concentrator 100, is conventionally called a BAS, acronym for “Broadband Access Server” .
- the PPP session concentrator 100 routes the sessions established with the different non-compliant clients 110 to the service provider 160, 170 or 180 to which they are subscribed.
- the PPP session concentrator 100 is connected to the network for non-compliant clients 140 and is capable of detecting broadcast messages conforming to the PPP protocol sent by a non-compliant client 110 on the network for non-compliant clients 140, to be established with the non-compliant client a session according to a point-to-point transport protocol, to determine the service provider to which the non-compliant client subscribes and to transfer the information transmitted by the non-compliant client according to the point-to-point transport protocol over the network for non-compliant customers 140 to the network for compliant customers 161 or 162 or 163 to which the service providers 160, 180 and 170 are connected respectively.
- the PPP session concentrator 100 determines among the information transmitted by the service providers 160, 170, 180 in networks for compliant customers 161, 162 and 163, information intended for non-compliant customers that i have a PPP session established with the PPP 100 session concentrator.
- the PPP 100 session concentrator formats the determined information so that it is compatible with the point-to-point transport protocol and transfers this set information forms in the session established between the client receiving this information and the session concentrator.
- the PPP session concentrator 100 includes a communication bus 101 to which a central unit 104, a non-volatile memory 102, a random access memory 103, a server interface 105 and a network interface 106 are connected.
- the non-volatile memory 102 stores the programs putting implementing the invention such as the algorithm which will be described later with reference to FIG. 3.
- the non-volatile memory 102 is for example a hard disk.
- the programs according to the present invention are stored in a storage means.
- This storage means can be read by a computer or a microprocessor 104.
- This storage means is integrated or not into the PPP session concentrator 100, and can be removable.
- the programs are transferred into the random access memory 103 which then contains the executable code of the invention as well as the data necessary for the implementation of the invention.
- the PPP session concentrator 100 also includes a telecommunications network interface 106 connected to the communication network 150.
- the PPP session concentrator 100 also includes a server interface 105 allowing the exchange of information with a DHCP server 120 and an authentication server 121.
- the DHCP server 120 distributes IPv4 or IPv6 addresses to clients 110 which do not comply with the protocol access control when they want to access the services offered by a service provider 160 or 170 or 180.
- DHCP is the acronym for "Dynamic Host Configuration Protocol".
- the DHCP server 120 is also able to distribute IPv4 or IPv6 addresses to clients 110 conforming to the access control protocol.
- the digital customer line multiplexer 130 directly accesses the DHCP server 120.
- the authentication server 121 authenticates a client 110 with the PPP session concentrator 100 when the client 110 wishes to access a service provider 160, 170 or 180. This authentication is carried out on the basis of the client's identifier 110 such as his user name and the provision by the client 110 of authentication equipment such as a password. This authentication will be described in more detail with reference to FIG. 3.
- the DHCP server can also alternatively be a DHCP relay or "proxy" server which redirects the information transferred to DHCP servers (not shown in FIG.
- a proxy is a piece of equipment which receives information from a first telecommunication device and transfers it to a second telecommunication device, and conversely which receives information from the second telecommunication device and transfers this information to the first telecommunication device.
- the authentication server 121 authenticates a client that does not comply with the access control protocol.
- the authentication server 121 is also able to authenticate a client conforming to the access control protocol.
- the digital multiplexer of client lines 130 directly accesses the authentication server 121 to authenticate a client conforming to the access control protocol. We understand here as authentication of a client both the authentication of the communication terminal 110 or of the user of the communication terminal 110.
- This authentication is carried out using the identifier of the client 110 such as his username. and the supply by the client 110 of a password or of an authentication hardware validated by the authentication server 121.
- the authentication server 121 can also be a proxy authentication server which redirects the information transferred to authentication servers (not shown in FIG. 1) associated with each service provider 160, 170 and 180.
- each authentication server associated with a service provider stores all the clients authorized to access the services offered by the service provider with which it is associated as well as the identifier and authentication equipment of each client.
- Service providers 160, 170 and 180 offer different services to their respective customers. These services are for example and without limitation Internet access services, video on demand services, electronic mail services, telephony services on the Internet, videoconferencing services on the Internet, etc.
- Fig. 2 represents the algorithm implemented by a digital multiplexer of the customer line telecommunication network for the access to services provided by service providers by a customer conforming or not to an authentication and control protocol. access.
- the digital multiplexer of customer lines 130 detects the presence of a customer 110 on one of the dedicated physical links.
- the processor 200 checks whether the client is compatible with the access control protocol such as for example the IEEE 802 protocol. Ix. This is for example determined by checking whether the information transmitted by the client 110 conforms to the EAPOL protocol, acronym for “EAP Over Lan” and where EAP is the acronym for “Extensible Authentication Protocol”. More specifically, the processor 200 checks whether the client complies with the IEEE 802.
- step E201 the digital customer line multiplexer 130 authorizes the non-compliant customer 110, for example the customer 110a, to access a network for non-compliant customers 140.
- step E202 the digital customer line multiplexer 130, more precisely the processor 200, determines the network for clients conforming to the access control protocol 161 or 162 allowing access to the service provider 160 or 180 of the conforming client 110.
- step E203 the digital multiplexer of customer lines 130, more precisely the processor 200, authorizes the compliant client 110, for example the client 110b to access the network for compliant clients 161 or 162 to which its service provider 160 or 180 is connected.
- the information transmitted by the compliant client 110b are then transferred to the network for determined conforming clients.
- the access authorization is in this case subject to an authentication procedure.
- the digital multiplexer for customer lines 130, more precisely the processor 200 receives from the customer 110 an identifier and a password or authentication equipment.
- the processor 200 of the digital customer line multiplexer 130 controls the transfer of a registration confirmation request to the destination of the authentication server 121.
- the authentication server 121 searches the client database if the client 110 is included in the client database, checks the validity of the password or of the authentication hardware and, in the affirmative, transfers to the digital multiplexer of customer lines 130 a confirmation of the registration of the customer 110.
- the authentication procedure is preferably in accordance with that described in the IEEE 802 protocol. Ix. It should also be noted here that the digital line multiplexer for clients 130 having verified that the clients comply with an access control protocol authorizes them to access a network 161 or 162 in which PPP sessions are not used to access the services provided by service providers 160 or 180.
- the digital customer line multiplexer 130 by determining that the customers do not comply with an access control protocol, authorizes them to access to a network 140 in which PPP sessions can be used to access the services provided by the service providers 160, 170 or 180.
- FIG. 3 represents the algorithm implemented by a session concentrator of the telecommunication network for the access to services provided by service providers by a client not conforming to an authentication and access control protocol.
- Step E300 consists of a waiting loop, more precisely by the processor 104, of the reception of a broadcast message from the network for non-compliant clients 140.
- the broadcast message is for example in accordance with the PPP protocol or to one of its two variants: PPPoE (acronym for "Point to Point Protocol over Ethernet") and PPPoA (acronym for "Point to Point Protocol over ATM").
- PPPoE ancronym for "Point to Point Protocol over Ethernet
- PPPoA acronym for "Point to Point Protocol over ATM”
- the PPP point-to-point transport protocol enables multi-protocol datagrams to be transported over a point-to-point link.
- the broadcast message is sent by a non-compliant client on the network for non-compliant clients 140. Indeed, according to the PPP protocol, each PPP session must learn the Ethernet address of the remote machine in order to establish and identify a single session.
- This broadcast message includes the address of the non-compliant client 110, the predetermined recipient address, identified as the broadcast address and a session identifier.
- the PPP session concentrator 100 On receipt of a broadcast message, the PPP session concentrator 100 goes to the next step E301. At this stage, an identification message is sent by the PPP session concentrator 100 more precisely by the processor 104, to the client 110 whose broadcast message was previously detected via the virtual network 140.
- the next step E302 is a step of interpretation more precisely by the processor 104, of the result of the authentication request for the client 110.
- the result of the authentication request is issued by the authentication server 121. On the result of the authentication request depends the establishment or not of a PPP session between the client and the session concentrator, which, if established, will allow facto the client to access the services of the service providers 160, 180 or 170.
- the PPP session concentrator 100 prohibits the establishment of the session between the client 110 and the session concentrator PPP 100.
- the client cannot access any of the service providers 160, 170 and 180.
- the session concentrator PPP 100 receives at least one message comprising at minus an identifier issued by the client 110 on the network for non-compliant clients 140, the PPP session concentrator 100 transfers the identifier to the authentication server 121 which recognizes or not the client 110 as having an identifier known by the server authentication 121. If the authentication server 121 recognizes the client 110, the latter generates a message intended for the PPP session concentrator 100 so that the latter obtains the authenticator of the client 110.
- the PPP session concentrator 100 When the PPP session concentrator 100 has obtained this authenticator from the client 110, the authenticator is transferred to the authentication server 121 which authenticates or not the client 110. If the authentication of the client 110 is confirmed, the PPP session concentrator 100 goes to the next step E303.
- the PPP session concentrator 100 more precisely by the processor 104, determines in step E303 the service provider to which the client 110 is subscribed. This is for example done by analyzing the identification message previously received from the client 110 in step E302.
- step E304 the PPP session is established between the client 110 and the PPP session concentrator 100.
- the PPP session concentrator 100 more precisely by the processor 104, receives from the client 110, via the virtual network 140, information according to the point-to-point transport protocol.
- the PPP session concentrator 100 transfers in step E305 the information received on the network for conforming clients 161, 162 or 163 corresponding to the service provider to which is customer 110 subscriber. It should be noted here that the information transported in the form of packets in accordance with the point-to-point transport protocol is previously shaped to form Ethernet type frames. It should also be noted that a packet consists of an Ethernet type frame encapsulated in accordance with the PPP protocol.
- the PPP session is interrupted when the client 110 disconnects according to the PPP protocol or when an exceptional event occurs.
- This event is for example an explicit order sent to the PPP session concentrator 100 to interrupt a session, a broken link in the network for non-compliant clients 140, or the like.
- the PPP session concentrator 100 determines, among the information transmitted by the service providers 160, 170, 180 in the networks for compliant clients 161, 162 and 163, the information for only non-compliant clients who have a PPP session established with the PPP 100 session concentrator.
- the PPP 100 session concentrator formats the determined information so that it is compatible with the point transport protocol and transfers this formatted information in the session established between the client receiving this information and the session concentrator.
- the present invention is not limited to the embodiments described here, but encompasses, quite the contrary, any variant within the reach of ordinary skill in the art.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP05707685A EP1721436A1 (fr) | 2004-03-03 | 2005-03-02 | Procede et systeme d'acces par un client a des services fournis par un fournisseur de services |
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP04290583A EP1571800A1 (fr) | 2004-03-03 | 2004-03-03 | Procédé et système d'accès par un client à des services fournis par un fournisseur de services |
| EP05707685A EP1721436A1 (fr) | 2004-03-03 | 2005-03-02 | Procede et systeme d'acces par un client a des services fournis par un fournisseur de services |
| PCT/EP2005/002191 WO2005096587A1 (fr) | 2004-03-03 | 2005-03-02 | Procede et systeme d’acces par un client a des services fournis par un fournisseur de services |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1721436A1 true EP1721436A1 (fr) | 2006-11-15 |
Family
ID=34746162
Family Applications (2)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP04290583A Withdrawn EP1571800A1 (fr) | 2004-03-03 | 2004-03-03 | Procédé et système d'accès par un client à des services fournis par un fournisseur de services |
| EP05707685A Withdrawn EP1721436A1 (fr) | 2004-03-03 | 2005-03-02 | Procede et systeme d'acces par un client a des services fournis par un fournisseur de services |
Family Applications Before (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP04290583A Withdrawn EP1571800A1 (fr) | 2004-03-03 | 2004-03-03 | Procédé et système d'accès par un client à des services fournis par un fournisseur de services |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20080046974A1 (fr) |
| EP (2) | EP1571800A1 (fr) |
| WO (1) | WO2005096587A1 (fr) |
Families Citing this family (15)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10862994B1 (en) * | 2006-11-15 | 2020-12-08 | Conviva Inc. | Facilitating client decisions |
| FR2885464A1 (fr) * | 2005-05-09 | 2006-11-10 | France Telecom | Procede et dispositif de controle d'acces |
| US20080102867A1 (en) * | 2006-10-26 | 2008-05-01 | Lasse Olsson | Network Support for Non-Compliant Mobile Terminals and Core Network Nodes |
| US8874725B1 (en) * | 2006-11-15 | 2014-10-28 | Conviva Inc. | Monitoring the performance of a content player |
| US8751605B1 (en) | 2006-11-15 | 2014-06-10 | Conviva Inc. | Accounting for network traffic |
| US9154942B2 (en) | 2008-11-26 | 2015-10-06 | Free Stream Media Corp. | Zero configuration communication between a browser and a networked media device |
| US8402494B1 (en) | 2009-03-23 | 2013-03-19 | Conviva Inc. | Switching content |
| US9760916B1 (en) * | 2009-05-20 | 2017-09-12 | Photobucket Corporation | Methods and systems for internet distribution of aggregated media actions |
| US9100288B1 (en) * | 2009-07-20 | 2015-08-04 | Conviva Inc. | Augmenting the functionality of a content player |
| US8539020B2 (en) * | 2010-06-14 | 2013-09-17 | Microsoft Corporation | Sessions to host processes with special requirements |
| US8369834B2 (en) * | 2010-09-24 | 2013-02-05 | Verizon Patent And Licensing Inc. | User device identification using a pseudo device identifier |
| US9246965B1 (en) | 2012-09-05 | 2016-01-26 | Conviva Inc. | Source assignment based on network partitioning |
| US10182096B1 (en) | 2012-09-05 | 2019-01-15 | Conviva Inc. | Virtual resource locator |
| US10178043B1 (en) | 2014-12-08 | 2019-01-08 | Conviva Inc. | Dynamic bitrate range selection in the cloud for optimized video streaming |
| US10305955B1 (en) | 2014-12-08 | 2019-05-28 | Conviva Inc. | Streaming decision in the cloud |
Family Cites Families (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6457130B2 (en) * | 1998-03-03 | 2002-09-24 | Network Appliance, Inc. | File access control in a multi-protocol file server |
| US6118785A (en) * | 1998-04-07 | 2000-09-12 | 3Com Corporation | Point-to-point protocol with a signaling channel |
| EP0994616A2 (fr) * | 1998-10-16 | 2000-04-19 | Siemens Information and Communication Networks Inc. | Dispositif et procédé de mise à la disposition de services supplémentaires améliorés aux systèmes de téléphonie-sur-LAN |
| US6381646B2 (en) * | 1998-11-03 | 2002-04-30 | Cisco Technology, Inc. | Multiple network connections from a single PPP link with partial network address translation |
| US7565326B2 (en) * | 2000-05-25 | 2009-07-21 | Randle William M | Dialect independent multi-dimensional integrator using a normalized language platform and secure controlled access |
| US7184764B2 (en) * | 2001-02-08 | 2007-02-27 | Starhome Gmbh | Method and apparatus for supporting cellular data communication to roaming mobile telephony devices |
| US20030110379A1 (en) * | 2001-12-07 | 2003-06-12 | Tatu Ylonen | Application gateway system, and method for maintaining security in a packet-switched information network |
| US20030167338A1 (en) * | 2002-03-01 | 2003-09-04 | Globespanvirata Incorporated | System and method to provide PPPoE connectivity to non-PPPoE clients |
| US7249187B2 (en) * | 2002-11-27 | 2007-07-24 | Symantec Corporation | Enforcement of compliance with network security policies |
-
2004
- 2004-03-03 EP EP04290583A patent/EP1571800A1/fr not_active Withdrawn
-
2005
- 2005-03-02 US US10/598,598 patent/US20080046974A1/en not_active Abandoned
- 2005-03-02 WO PCT/EP2005/002191 patent/WO2005096587A1/fr not_active Ceased
- 2005-03-02 EP EP05707685A patent/EP1721436A1/fr not_active Withdrawn
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2005096587A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| EP1571800A1 (fr) | 2005-09-07 |
| US20080046974A1 (en) | 2008-02-21 |
| WO2005096587A1 (fr) | 2005-10-13 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US8650617B2 (en) | Method and system for real-time insertion of services during a call session over a communication network | |
| US8488569B2 (en) | Communication device | |
| US7036142B1 (en) | Single step network logon based on point to point protocol | |
| US7039049B1 (en) | Method and apparatus for PPPoE bridging in a routing CMTS | |
| EP1721436A1 (fr) | Procede et systeme d'acces par un client a des services fournis par un fournisseur de services | |
| EP1445916A2 (fr) | Procédé et système d'authentification d'un utilisateur au niveau d'un réseau d'accès lors d'une connexion de l'utlisateur au réseau internet | |
| US20060165082A1 (en) | System and method for facilitating communication between a CMTS and an application server in a cable network | |
| WO2009023998A1 (fr) | Procédé de l'équipement d'accès à large bande pour mettre en œuvre le positionnement de port d'abonné | |
| US7228358B1 (en) | Methods, apparatus and data structures for imposing a policy or policies on the selection of a line by a number of terminals in a network | |
| WO2018193203A1 (fr) | Système et procédé de communications | |
| EP1738526B1 (fr) | Procede et systeme d'accreditation d'un client pour l'acces a un reseau virtuel permettant d'acceder a des services | |
| US6985935B1 (en) | Method and system for providing network access to PPP clients | |
| KR20000076720A (ko) | 패킷 서버 내에서의 이용 방법 | |
| EP2073432B1 (fr) | Procédé de liaison entre un terminal et un opérateur, et terminal correspondant | |
| WO2004014045A1 (fr) | Affectation dependant de la classe de service d'adresses ip en vue du controle de l'acces a une prestation d de services electroniques | |
| EP1964359B1 (fr) | Procede et systeme de mise a jour des conditions d'acces d'un dispositif de telecommunication a des services delivres par un reseau de telecommunication | |
| WO2008012471A2 (fr) | Procede d'acces par un client a un service au travers d'un reseau, par utilisation combinee d'un protocole de configuration dynamique et d'un protocole point a point, equipement et programme d'ordinateur correspondants | |
| EP1884099B1 (fr) | Procede et dispositif de controle d'acces | |
| CN100556034C (zh) | 传输信息的方法 | |
| FR2858145A1 (fr) | Procede et systeme de double authentification securise d'un utilisateur lors de l'acces a un service par l'intermediaire d'un reseau ip | |
| US20090262738A1 (en) | Method for promptly redialing a broadband access server | |
| EP2031809B1 (fr) | Procédé de traitement de flots dans un réseau de communication | |
| WO2007074308A1 (fr) | Procede et systeme de connexion a un service | |
| CA2417116C (fr) | Traduction d'identificateurs dans un reseau de paquets | |
| EP2011273B1 (fr) | Procede et dispositif d'adaptation d'un protocole de communication point a point dans un reseau de telecommunications |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20060909 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU MC NL PL PT RO SE SI SK TR |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: IVANOFF, GILLES Inventor name: MINODIER, DAVID |
|
| DAX | Request for extension of the european patent (deleted) | ||
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: FRANCE TELECOM |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: H04L 29/06 20060101AFI20091201BHEP Ipc: H04L 12/28 20060101ALI20091201BHEP |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20100601 |