US 11,870,604 B2
Communication system, communication device, communication method, terminal, non-transitory medium for providing secure communication in a network
Satoru Ishii, Tokyo (JP); Hideo Hasegawa, Tokyo (JP); and Shintaro Nakano, Tokyo (JP)
Assigned to NEC CORPOATION, Tokyo (JP)
Appl. No. 15/745,311
Filed by NEC CORPORATION, Tokyo (JP)
PCT Filed Jul. 14, 2016, PCT No. PCT/JP2016/070907
§ 371(c)(1), (2) Date Jan. 16, 2018,
PCT Pub. No. WO2017/014164, PCT Pub. Date Jan. 26, 2017.
Claims priority of application No. 2015-143405 (JP), filed on Jul. 17, 2015.
Prior Publication US 2019/0013967 A1, Jan. 10, 2019
Int. Cl. H04L 12/46 (2006.01); H04L 12/66 (2006.01); H04L 29/06 (2006.01); H04L 45/64 (2022.01); H04W 12/03 (2021.01); H04L 9/40 (2022.01); H04W 12/00 (2021.01); H04W 84/12 (2009.01); H04W 12/088 (2021.01)
CPC H04L 12/4641 (2013.01) [H04L 12/4633 (2013.01); H04L 45/64 (2013.01); H04L 63/0485 (2013.01); H04L 63/0876 (2013.01); H04L 63/0892 (2013.01); H04W 12/03 (2021.01); H04L 12/66 (2013.01); H04L 63/0227 (2013.01); H04L 63/0245 (2013.01); H04L 63/164 (2013.01); H04W 12/009 (2019.01); H04W 12/088 (2021.01); H04W 84/12 (2013.01)] 18 Claims
OG exemplary drawing
 
1. A communication system comprising
a data center of a cloud operator, the data center providing a communication service to a terminal via a first wide area network to which the data center connects, and a wireless LAN (Local Area Network) to which the terminal connects, wherein the data center comprises:
a first gateway configured to connect with the terminal using a VPN (Virtual Private Network) established between the first gateway and the terminal through the first wide area network and the wireless LAN and terminate the VPN;
a second gateway configured to connect to a second wide area network,
a virtual network connected to the first gateway and the second gateway; and
a function block that is provided between the first gateway and the second gateway and that performs, based on filter information, filtering of a first packet transmitted by the terminal using the VPN and received by the first gateway from the first wide area network, and a second packet destined to the terminal and received by the second gateway from the second wide area network, the function block comprising a plurality of function blocks between the first gateway and the second gateway, each of the plurality of function blocks corresponding to one of a plurality of terminals accessing the data center via the VPN established between the terminal and the first gateway through the wireless LAN and the first wide area network.