Method for obtaining a user identity in a home network
By intercepting and processing domain name requests to infer user identities, the method addresses the issue of shared device access in home networks, enabling personalized access control and session management.
Patent Information
- Application Number
- FR2024008332
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-26
- Publication Date
- 2026-01-30
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for obtaining a user identity in a home network technical field
[0001] The invention relates to the field of telecommunications.
[0002] The invention relates more particularly to a method of managing access to an Internet site from a data processing device referred to as an access device in the following.
[0003] The access device chosen to illustrate the invention may be a tablet, a computer, or any equivalent connected object. State of the art
[0004] The home network gateway manages access rights to websites and relies on MAC addresses (Media Access Control, or physical address) associated with each device, which the user device registers with the DHCP server (Dynamic Host Configuration Protocol) of the local network. This is known as MAC address filtering. A MAC address is a physical identifier stored in a network card or similar network interface, generally consisting of 48 bits and represented in hexadecimal format.
[0005] The residential gateway stores a mapping table, allowing access permissions to be associated with the different MAC addresses of user devices on the local network. For example, the MAC address of a minor user's smartphone is recorded in association with certain authorization rules that restrict access to specific time periods or to certain content only. This mapping table is generated by the network administrator (the parent client) when configuring access permissions for all user devices in the household and is stored as a static table in the gateway.
[0006] However, this access control based on the MAC address of user devices does not allow users to know who is using the device in question. Several people may share the same device, for example, a family computer. This device sharing prevents access rights management in the home gateway.
[0007] The invention improves the solution
[0008] To this end, according to a first functional aspect, the invention relates to a method of obtaining a user identity associated with a request to access a domain name received by a home gateway, characterized in that it includes obtaining an identity at the basis of the domain name.
[0009] According to the invention, a DNS query intended to be resolved by a DNS server is used to infer an identity. The query is treated not as a DNS query but as a request to obtain an identity so as to apply an access profile associated with that identity in the home gateway.
[0010] According to a first embodiment, the domain name includes data representing an authentication request. This allows the home gateway to detect an authentication request at the very core of the domain name; this avoids sending the gateway a message accompanying the domain name informing it that the domain name is to be treated as an authentication request.
[0011] According to a variant of this first embodiment, since the domain name comprises a string of characters and an extension, the data representing an identification request corresponds to the domain name extension. As the gateway has access to the official extensions for the domain name, using the extension allows it to quickly determine whether the received request is a request for identity verification.
[0012] According to a second embodiment, which may be implemented alternatively or cumulatively with the previous embodiment, the domain name comprises a string of characters and an extension, and the identity is derived from the string of characters. This second embodiment makes it possible to distinguish one individual from several individuals.
[0013] According to a third embodiment, which may be implemented alternatively or cumulatively with the preceding embodiments, the request is intercepted and the routing of the request is prevented. This third embodiment avoids the transmission of a DNS query destined to fail. The number of queries transmitted is consequently reduced.
[0014] According to a fourth embodiment, which may be implemented alternatively or cumulatively with the previous embodiments, obtaining the identity is followed by applying an access profile associated with the extracted identity in the gateway. This fourth embodiment allows for the management of user profiles based on a domain name.
[0015] According to a fifth embodiment, which may be implemented alternatively or cumulatively with the preceding embodiments, the use of the profile is terminated upon receipt of a given domain name. This method ensures the termination of the session associated with the identity in question, thus preventing another individual from using the current session without their knowledge.
[0016] According to a first material aspect, the invention relates to an entity for managing the acquisition of an identity associated with a request received by a home gateway, the request including a domain name, characterized in that it comprises a module identification capable of obtaining an identity from the domain name when the domain name includes data representative of an identification request.
[0017] According to another material aspect, the invention relates to a home gateway comprising a management entity as defined above.
[0018] According to another material aspect, the invention relates to a computer program suitable for implementation on an entity as defined above, the program comprising code instructions which, when executed by a processor, performs the steps of the management process defined above.
[0019] According to another material aspect, the invention relates to a data carrier on which at least one series of program code instructions for the execution of a process as defined above has been stored.
[0020] According to a second functional aspect, the invention relates to a method of accessing an Internet site associated with a domain name, characterized in that the domain name includes data representing an identity and data representing a request for specific processing of the domain name in the gateway.
[0021] According to a first embodiment relating to the second functional aspect, the domain name comprising a string of characters and an extension, the data representing an identification request corresponds to the extension of the domain name.
[0022] According to a first embodiment relating to the second functional aspect, which may be implemented alternatively or cumulatively with the previous embodiment, the domain name comprising a string of characters and an extension, the identity is included in the string of characters.
[0023] According to another material aspect, the invention relates to a second entity for managing access to an Internet site associated with a domain name, characterized in that it comprises a transmission module capable of transmitting a domain name including data representing an identity and data representing a request for specific processing of the domain name in the gateway.
[0024] According to another material aspect, the invention relates to an access device comprising a second management entity as defined above.
[0025] According to another material aspect, the invention relates to a computer program suitable for implementation on a second management entity as defined above, the program comprising code instructions which, when executed by a processor, performs the steps of the process defined in the process relating to the second functional aspect.
[0026] According to another material aspect, the invention relates to a data carrier on which at least one series of program code instructions has been stored. for the execution of a process according to the second functional aspect defined above with respect to the second functional aspect.
[0027] Such a recording medium referred to above can be any entity or device capable of storing the program. For example, the medium may include a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a USB flash drive or a hard drive.
[0028] On the other hand, such a recording medium can be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means, so that the computer program it contains is executable remotely. The program according to the invention can, in particular, be uploaded to a network, for example, the Internet.
[0029] Alternatively, the recording medium may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the aforementioned display control method.
[0030] The invention will be better understood upon reading the following description, given by way of example and with reference to the accompanying drawings in which:
[0031] [Fig-1] represents a computer system on which an example of is illustrated realization of the invention.
[0032] [Fig.2] is a simplified synoptic diagram of the material structure of an access device;
[0033] [Fig.3] is a simplified synoptic diagram of the material structure of a home gateway.
[0034] [Fig.4] schematically illustrates communication between a computer and the home gateway according to an embodiment of the method of the invention.
[0035] Detailed description of an example embodiment illustrating the invention:
[0036] A wireless local area network, for example a home Wi-Fi network, is now presented in relation to [Fig. 1]. Such a home network comprises a residential gateway (GTW), for example an Orange® Livebox®, and a plurality of user devices, for example a mobile phone (MOB), a home computer (PC), and a tablet (TAB). These various user devices can connect to the residential gateway (GTW), as symbolized by the double arrows in [Fig. 1], to access the resources of the local area network, or the resources of a wide area network (LU), for example the Internet, to which the GTW gateway acts as an access point. Furthermore, this home network is considered, by way of example, to be that of a family with two parents and two minor children, Alice and Bob. The mobile phone (MOB) and the home computer (PC) are also included. for example are used exclusively by each of the two parents, while Alice and Bob can both use the family computer 13 or the tablet 14.
[0037] In order to limit the time Alice and Bob spend in front of screens, and to prevent any addiction, it is important for their parents to be able to schedule the time slots during which Alice and Bob are allowed to connect to the GTW residential gateway. These time slots are not necessarily the same for Alice and Bob. For example, Alice is allowed from 4 p.m. to 9 p.m., and Bob is allowed from 4 p.m. to 7 p.m.
[0038] Furthermore, it is also important to implement parental controls, allowing Alice or Bob's access to only those content available on the LU wide area network that is appropriate for their age. Again, this content is not necessarily the same for Alice and Bob.
[0039] It is therefore important for parents to apply respective user profiles to Alice and Bob in order to implement a set of permissions, or access rules, customized according to Alice's or Bob's identity. As administrators of the GTW home gateway and the local network, they can configure these rules in the GTW home gateway, where they are stored as a lookup table associating each family user's identity with a set of rules or access rights assigned to them.
[0040] To enable the implementation of reliable access control that respects these rules and permissions, the method according to the invention relies on the use of a specific internet address recognized by an ENT management entity, ideally included in the GTW gateway, as an address to be processed differently from a standard address. This address includes a domain name containing an identity and data representing a specific processing operation to be performed on that domain name (also called an internet address).
[0041] To achieve this end, the process includes the ENT management entity performing an extraction of an identity in the domain name and an application of an access profile associated with the extracted identity and an application to said user device of a network access profile customized for said user to whom the identity belongs.
[0042] The transmitted request includes a domain name that incorporates data representing an identity and data representing a specific request for processing the domain name in the gateway. In other words, the transmitted DNS query is interpreted by the entity not as a DNS query but as a request to obtain an identity and apply a profile associated with the obtained identity.
[0043] Figure 4 illustrates an embodiment in which the gateway will identify the person in front of the device, for example the PC computer.
[0044] In this example, the GTW gateway stores a lookup table between BOB and ALICE identifiers and their respective profiles defining permissions or even prohibitions as explained previously.
[0045] In this example, the data representing a message to be intercepted in order to obtain an identifier corresponds to a specifically created extension in the domain name, in our example ".nac". This extension is preferably one not known to the DNS server.
[0046] It should be noted here that the extension is also called a top-level domain or a top-level domain (TLD) by those skilled in the art. In the Internet domain name system, this extension is a subdomain of root 1.
[0047] In a domain name, the top-level domain is usually the last element of the domain name (example: in the domain name fr.orange.org., the top-level domain is "org").
[0048] The list of Internet top-level domains includes several thousand top-level domains managed by 1TANA (Internet Assigned Numbers Authority). These include one special top-level domain; approximately 260 country-code top-level domains; and approximately 1,500 generic top-level domains. A database containing these top-level domains is stored in a database.
[0049] Each top-level domain is managed by an organization which is responsible for allocating (possibly on a commercial basis) its subdomains.
[0050] The steps of an embodiment are described below in connection with [Fig. 4]. This figure includes two axes associated with the PC and the gateway. Arrows then indicate the direction of message transmission between them.
[0051] In a first step, the user Bob identifies himself on the PC computer.
[0052] For example, it can use a domain name such as
[0053] «BOB.nac».
[0054] In our example, a first management entity ENT1 installed on the PC requires the transmission of this domain name to the GTW home gateway. This domain name can also be transmitted automatically without prior input; a software module, for example, coupled with an internet browser, can be executed and, upon execution, display a user interface offering, for example, the user to enter an identifier "BOB" or select a name BOB; the user then simply needs to validate the identification request for a DNS query including the domain name "BOB.nac" to be transmitted by the first entity from the PC to the GTW gateway. Access to the module is Ideally secured by a password to prevent another user from using the domain name or selecting a name other than their own.
[0055] Once the domain name has been entered, it “BOB.nac” is transmitted to the destination GTW gateway.
[0056] The gateway receives the request, and a second management entity, ENT2, present in our example in the GTW home gateway, detects the ".nac" extension as being an identity management extension. In our example, after detection, the second management entity, ENT2, blocks the received DNS query to avoid unnecessarily forwarding a DNS query for resolution, as this query is diverted for the purpose of identifying the originator of the BOB request. According to a variant, the query could not be blocked and could be forwarded to a DNS server; the DNS server's response would then be that resolution is not possible.
[0057] Note that the first entity can be located inside the PC or outside the PC. Similarly, the second entity ENT2 can be located inside the gateway or outside of it. If the entity is located outside, a communication link (wired or wireless) allows communication with the computer in the case of the first entity, or with the gateway in the case of the second entity. More generally, the location of an entity is arbitrary.
[0058] It should be noted that 1TANA, defined above, operates and coordinates the root zone of the Domain Name System (DNS), whose levels (top-level domain, second-level domain, and subdomain) constitute the fully qualified domain names. In this context, 1TANA maintains a database of all top-level domains (TLDs), the last part of the fully qualified domain name. The second management entity ENT2 is aware of the complete list of extensions in the database referred to above and can, when a received query includes a domain name with an extension not known to the database, treat this query not as a DNS query but as an identity management query.
[0059] To avoid reviewing the database after receiving each request, the second entity ENT2 stores the extension dedicated to identity management. In this way, if the gateway receives a domain name with a ".nac" extension, having stored this extension as being associated with user identity management, it immediately detects that the request is not a DNS query but a request for identification and session opening to communicate with the profile associated with the identity in question, here BOB.
[0060] In our example, the extension used is ".nac"; however, the invention is not limited to this example but obviously extends to any ideally not included in the list referred to above, an extension could be ".ID" or ".USER".
[0061] The gateway extracts the BOB identity from the domain name "BOB.nac" ((id=BOB) and accesses the BDD matching database to obtain the profile associated with this identifier.
[0062] Next, in this embodiment, the second management entity ENT2 requires the transmission of a response message to the PC informing that the identification has succeeded or failed.
[0063] If authentication is successful (OK), user BOB can enter a standard domain name with an extension known to DNS servers, such as "www.orange.fr"; a DNS query is sent to the gateway, which checks for the ".fr" extension. Since this extension is not a ".nac" extension, if the user's profile allows it, the gateway will route the domain name to the DNS server for resolution. We will not describe the resolution of a standard DNS query, as this is a matter of expertise.
[0064] In our example, the user also has the option to end the session. The same principle is used for this; a DNS query including data representing a session termination request is included in the DNS query; the domain name is, for example:
[0065] “stop.nac” or “BOB.stop.nac”
[0066] In this example, the identity BOB is also included.
[0067] The gateway detects the ".nac" extension and treats this request not as a DNS query but as an identity management query.
[0068] The request including the data "stop", the second entity ENT2 interprets this request as a request to close the session with the identity BOB.
[0069] As we have seen above, the domain name comprises a string of characters and an extension. We have also seen that the data representing an identification request corresponds to the domain name extension. The invention is not limited to this example; according to one variant, this data could be in the string of characters. This variant is less efficient because it requires reading all the characters, sometimes composed of several substrings of characters; this variant has the disadvantage of a longer processing time than when the data is the extension.
[0070] On the other hand, the identity could also be included in the extension. The latter would be capable of providing two pieces of information, namely
[0071] - the fact that the received domain name is to be treated differently
[0072] - and identity.
[0073] We have also seen that in the embodiment described above, the request is intercepted and processed differently. Ideally, the routing of the request is prevented; for example, the second management entity ENT2 requires the request to be deleted after processing.
[0074] According to another variant, the request may still be routed despite any chance of resolution. The gateway receives an unsurprising error message in return.
[0075] According to another variant, the domain name also includes a secret. This secret is previously stored in the gateway so that the gateway can verify the secret when a domain name is received for the purpose of obtaining an identity.
[0076] Finally, according to another variant allowing termination of a current session, when an identity is in use and a profile is activated in the gateway, the latter can be activated for a given duration which starts from the activation or from a later time for example from the last request from the user concerned.
[0077] Finally, specifying here that the first management entity ENT1 includes an identification module capable of obtaining an identity from the domain name when the domain name includes data representing an identification request; and that the second entity ENT2 includes a transmission module capable of transmitting a domain name including data representing an identity and data representing a request for specific processing of the domain name in the gateway.
[0078] Finally, it should be noted here that the term entity or module can refer to a software component, a hardware component, or a set of hardware and software components. A software component itself corresponds to one or more computer programs or subprograms, or more generally, to any element of a program capable of implementing a function or set of functions as described for the modules concerned. Similarly, a hardware component corresponds to any element of a hardware assembly capable of implementing a function or set of functions for the module concerned (integrated circuit, smart card, memory card, etc.).
Claims
Demands
1. A method for obtaining a user identity associated with a domain name access request received by a home gateway (GTW), characterized in that it includes obtaining an identity at the basis of the domain name.
2. A method of obtaining according to claim 1, characterized in that the domain name includes data representative of an identification request.
3. A method of obtaining according to claim 2, characterized in that, the domain name comprising a string of characters and an extension, the data representing an identification request corresponds to the extension of the domain name.
4. A method of obtaining according to claim 1, characterized in that, the domain name comprising a string of characters and an extension, the identity is derived from the string of characters.
5. A method of obtaining according to claim 1, characterized in that the request is intercepted and in that the routing of the request is prevented.
6. A method of obtaining according to claim 1, characterized in that obtaining the identity is followed by applying in the gateway an access profile associated with the extracted identity.
7. A method of obtaining according to claim 1, characterized in that a cessation of use of the profile is carried out following the receipt of a given domain name.
8. Management entity (ENT1) for obtaining an identity associated with a request received by a home gateway, the request including a domain name, characterized in that it includes an identification module capable of obtaining an identity from the domain name when the domain name includes data representative of an identification request.
9. Domestic gateway (GTW) characterized in that it comprises a management entity as defined in claim 8.
10. A computer program capable of being implemented on a management entity (MTE) as defined in claim 8, the program comprising code instructions which, when executed by a processor, performs the steps of the process defined in claim 1.
11. Data carrier on which at least one series of program code instructions for executing a method according to claim 1 has been stored
12. Method of accessing an Internet site associated with a domain name, characterized in that the domain name includes data representing an identity and data representing a request for specific processing of the domain name in the gateway.
13. Management method according to claim 12, characterized in that, the domain name comprising a string of characters and an extension, the data representing an identification request corresponds to the extension of the domain name.
14. Management method according to claim 12, characterized in that the domain name comprises a string of characters and an extension, the identity is included in the string of characters.
15. Management entity (ENT2) of access to an Internet site associated with a domain name, characterized in that it includes a transmission module capable of transmitting a domain name including data representing an identity and data representing a request for specific processing of the domain name in the gateway.
16. Access device (PC) comprising a management entity as defined in claim 15.
17. A computer program capable of being implemented on a management entity (ENT2) as defined in claim 15, the program comprising code instructions which, when executed by a processor, carries out the steps of the process defined in claim 12.
18. Data carrier on which at least one series of program code instructions for the execution of a method according to claim 12 has been stored.
Citation Information
Patent Citations
Business domain name configuration method, elastic compute service and terminal device
CN107948682A
Techniques for dynamic domain-based isolation
US20130111560A1
User Identity Differentiated DNS Resolution
US20170155645A1
Methods and apparatus for providing domain name service based on a client identifier
US7228359B1