VPN access control system, operating method thereof, program, VPN router, and server

US10637830B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10637830-B2
Application numberUS-201514843954-A
CountryUS
Kind codeB2
Filing dateSep 2, 2015
Priority dateSep 18, 2014
Publication dateApr 28, 2020
Grant dateApr 28, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

To provide a VPN access control system, an operating method thereof, a non-transitory computer-readable recording medium having a program recorded thereon, a VPN router, and a server capable of reducing the effort of work of an administrator and quickly permitting remote access. A VPN access control system includes a VPN router and an image server. The VPN router executes a router authentication process based on router authentication information, and the image server executes a server authentication process based on server authentication information. The image server receives an access right granting request from a portable terminal of a registered user to which the access right has been granted and executes a first user registration process. The VPN router executes a second user registration process based on a command from the image server, and transmits an authentication information notification to a user who is an access right granting target.

First claim

Opening claim text (preview).

What is claimed is: 1. A VPN access control system including a VPN router having an authentication function of providing access permission based on router authentication information in case where receiving an access request from a terminal of a registered user to which an access right has been granted, and a server having an authentication function of providing access permission based on server authentication information separate from the router authentication information in case where receiving the access request from the terminal of the registered user via the VPN router, the VPN access control system controlling remote access to an internal communication network to which the server is connected, from an external communication network of the VPN router, wherein the server includes: a hardware processor configured at least to: receive, from the terminal of the registered user which is stored in a first user registration table within the server as a permanent user, an access right granting request for automatically granting the access right to a terminal of an unregistered user who is not a same user as the registered user and is stored in the first user registration table as a temporary user and to which the access right to the VPN router and the server has not been granted, wherein the access right has been granted for the terminal of the registered user; execute issuing of the server authentication information and first user registration for granting an access right to access the server for the unregistered user for a validity duration based on the access right granting request in response to receiving the access right request, wherein the server authentication including first temporary identification data and first temporary password for the unregistered user to access the server are registered to the first user registration table when the first user registration is executed; and issue automatically, to the VPN router through an intranet without going through an external network or an internet, a command including the server authentication information and instructing the VPN router to issue the router authentication information different from the server authentication information to perform second user registration for the terminal for the unregistered user, and the VPN router includes: a hardware processor configured at least to: issue automatically the router authentication information based on the command and execute the second user registration for granting an access to access the VPN router for the terminal of the unregistered user in response to receiving the command, wherein the router authentication including second temporary identification data and a second temporary password for the unregistered user to access the VPN router are registered to a second user registration table within the VPN router when the second user registration is executed; and transmit authentication information including the router authentication information and the server authentication information to the terminal of the unregistered user. 2. The VPN access control system according to claim 1 , wherein a destination of the unregistered user is included in the access right granting request, and the hardware processor of the VPN router transmits the authentication information to the destination. 3. The VPN access control system according to claim 1 , wherein the hardware processor of the server transmits the server authentication information and the command in an e-mail format to the VPN router. 4. The VPN access control system according to claim 2 , wherein the hardware processor of the server transmits the server authentication information and the command in an e-mail format to the VPN router. 5. The VPN access control system according to claim 1 , wherein VPN client software for performing the remote access is installed in the terminal of the registered user, and the VPN router receives the router authentication information through the VPN client software. 6. The VPN access control system according to claim 2 , wherein VPN client software for performing the remote access is installed in the terminal of the registered user, and the VPN router receives the router authentication information through the VPN client software. 7. The VPN access control system according to claim 3 , wherein VPN client software for performing the remote access is installed in the terminal of the registered user, and the VPN router receives the router authentication information through the VPN client software. 8. The VPN access control system according to claim 5 , wherein the hardware processor of the VPN router encrypts the server authentication information and the router authentication information into information that is decrypted by the VPN client software, and transmits the encrypted information. 9. The VPN access control system according to claim 6 , wherein the hardware processor of the VPN router encrypts the server authentication information and the router authentication information into information that can be decrypted by the VPN client software, and transmits the encrypted information. 10. The VPN access control system according to claim 8 , wherein the hardware processor of the VPN router also encrypts an address of the server. 11. The VPN access control system according to claim 1 , wherein the hardware processor of the server or the hardware processor of the VPN router has a validity period setting function of setting a validity period of the router authentication information or the server authentication information. 12. The VPN access control system according to claim 11 , wherein the validity period of the access right is designated in the access right granting request, and the hardware processor of the server or the hardware processor of the VPN router sets the validity period of the server authentication information or the router authentication information based on the designation. 13. The VPN access control system according to claim 12 , wherein the hardware processor of the server or the hardware processor of the VPN router sets an initial value of the validity period set in advance in case where there is no designation. 14. The VPN access control system according to claim 1 , wherein the VPN router determines that the command is included in the IP packet in case where the source address is the server and the destination address is the VPN router by referring to address information of the received IP packet. 15. The VPN access control system according to claim 1 , wherein the server is a medical information server that distributes medical information. 16. The VPN access control system according to claim 15 , wherein the medical information server is installed in a medical facility. 17. A method of operating a VPN access control system including a VPN router having an authentication function of providing access permission based on router authentication information in case where receiving an access request from a terminal of a registered user to which an access right has been granted, and a server having an authentication function of providing access permission based on server authentication information separate from the router authentication information in case where receiving the access request from the terminal of the registered user via the VPN router, the VPN access control system controlling remote access to an internal communication network to which the server is connected, from an external communication network of the VPN router, wherein the s

Assignees

Inventors

Classifications

  • Entity profiles · CPC title

  • Virtual private networks · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10637830B2 cover?
To provide a VPN access control system, an operating method thereof, a non-transitory computer-readable recording medium having a program recorded thereon, a VPN router, and a server capable of reducing the effort of work of an administrator and quickly permitting remote access. A VPN access control system includes a VPN router and an image server. The VPN router executes a router authenticatio…
Who is the assignee on this patent?
Fujifilm Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/0272. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 28 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).