Method of accessing a network securely from a personal device, a personal device, a network server and an access point

US9769172B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9769172-B2
Application numberUS-201414319088-A
CountryUS
Kind codeB2
Filing dateJun 30, 2014
Priority dateSep 6, 2013
Publication dateSep 19, 2017
Grant dateSep 19, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method of accessing a network securely using a personal device which can only access the network via one or more authorized access points, the method including establishing a connection between the network and the personal device via an access point; checking in the network whether the access point is on a white list of authorized access points for use with the network; if the access point is on the white list, allowing the personal device to access the network securely via the access point; and if the access point is not on the white list, not allowing the personal device to access the network securely.

First claim

Opening claim text (preview).

The invention claimed is: 1. A computer-executed method of using a personal device to securely access a corporate server providing corporate services in a network, wherein personal devices can only access the server in the network via a restricted number of authorized access points, the method including: establishing a connection between the network and the personal device via an access point; checking in the network whether the access point is on a network white list of the restricted number of authorized access points for use with the server, wherein the network white list includes all the access points allowed for connection of personal devices to the server; if the access point is on the network white list, allowing the personal device to access the server securely via the access point; and if the access point is not on the network white list, not allowing the personal device to access the server securely, wherein the network white list includes an access point identification for each authorized access point, and specific hours and/or days of authorization for one of some and all authorized access points, wherein secure access to the server is only granted if the network white list check is made during the specific hours and/or days of authorization for those authorized access points. 2. A method according to claim 1 , further including a security check including at least a personal device check and a user check before secure access to the server is granted. 3. A method according to claim 1 , wherein the access point identification includes an access point hardware ID, preferably of the access point microprocessor. 4. A method according to claim 1 , wherein the access point identification includes a configured ID, preferably an encrypted field encrypted by a private key and extracted by a public key. 5. A method according to claim 1 , wherein checking whether the access point is on the network white list includes: the personal device requesting the access point identification from the access point, the access point providing the identification to the personal device; and optionally the personal device transmitting the access point identification to the network for comparison with the network white list. 6. A method according to claim 1 , wherein, the network requests access point authentication from the access point, which is then transmitted directly to the network for comparison with the network white list before server access is granted. 7. A method according to claim 1 , wherein once the personal device is accessing the server securely via the access point, if the personal device no longer accesses the server securely, any data downloaded from the network is cleared from the personal device memory. 8. A method according to claim 1 , wherein while the personal device is accessing the server via the access point and a cellular communication system, the personal device is prevented from handover to outside the current cell, and preferably wherein the access point supplies the access point authentication of any new access point to the server, for comparison against the white list. 9. A method according to claim 1 , wherein the access point is a portable access point, such as a portable router, portable internet connection to a cellular communication system or a portable base station for a femto cell. 10. A method according to claim 1 , wherein the connection path between the personal device and the access point is wireless, whereas the connection path between the access point and the network is wired. 11. A method according to claim 1 , including an initial set-up stage in which at least one access point is registered with the network and added to the list of authorized access points. 12. A method according to claim 1 , wherein the connection between the server and the personal device is a VPN connection, and the personal device accesses the network if the access point is on the network white list using a full VPN connection or session. 13. A personal device which is arranged to access a corporate server providing corporate services in a network only via a restricted number of authorized access points, the personal device including: a controller, a transmitter and a receiver; wherein the controller controls the transmitter and receiver: to connect to the network via an access point; and to communicate with the access point and the network to check whether the access point is on a network white list of the restricted number of authorized access points for use with the server, wherein the network white list includes all the access points allowed for connected of personal devices to the server; wherein if the access point is on the network white list, the personal device is allowed to access the server via the access point; and if the access point is not on the network white list, the personal device is not allowed to access the server, wherein the network white list includes an access point identification for each authorized access point, and specific hours and/or days of authorization for one of some and all authorized access points, wherein secure access to the server is only granted if the network white list check is made during the specific hours and/or days of authorization for those authorized access points. 14. A corporate server in a network, and arranged to allow secure access to corporate services via the network from a personal device only via an authorized access point, the server including: a processor, memory and an external link out of the network; wherein the memory is arranged to store a network white list of a restricted number of authorized access points, wherein the network white list includes all the access points allowed for connection of personal devices to the server; the processor is arranged to establish an external connection to the personal device via the external link and an access point for the personal device; the processor is arranged to check whether the access point is on the network white list; and if the access point is on the network white list, to allow the personal device to access the server via the access point; or if the access point is not on the network white list, not to allow the personal device to access the server, wherein the network white list includes an access point identification for each authorized access point, and specific hours and/or days of authorization for one of some and all authorized access points, wherein secure access to the server is only granted if the network white list check is made during the specific hours and/or days of authorization for those authorized access points. 15. An authorized access point arranged to allow a personal device to securely access a corporate server providing corporate services in a network, the access point including: an identification of the access point, a processor, and access means for connection to the network and the personal device; wherein the processor is arranged to establish a connection between the network and the personal device via the access means; the processor is arranged to transmit the identification of the access point when requested, for checking whether the access point is on a network white list of a restricted number of authorized access points for use with the corporate server, wherein the network white list includes all the access points allowed for connection of personal devices to the server and wherein if the access point is on the network white list, the access point is arranged to allow a secure connection between the personal device and the corporate server; whereas if the

Assignees

Inventors

Classifications

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9769172B2 cover?
A method of accessing a network securely using a personal device which can only access the network via one or more authorized access points, the method including establishing a connection between the network and the personal device via an access point; checking in the network whether the access point is on a white list of authorized access points for use with the network; if the access point is…
Who is the assignee on this patent?
Fujitsu Ltd
What technology area does this patent fall under?
Primary CPC classification H04W48/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 19 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).