IP Library Granted Patent US 6,895,511
Granted Patent B1
US 6,895,511 · App. 09/314,601 · Granted May 17, 2005

Method and apparatus providing for internet protocol address authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,895,511
App. No.
09/314,601
Granted
May 17, 2005
Kind
B1
Abstract

A method and apparatus for storage of user identifier/IP address pairs in a network. The network includes a DHCP server for assigning IP addresses to computer and other devices in the network, a device (such as a computer) coupled to receive an IP address from the DHCP server, an authentication server coupled with the device for receiving user identifier/IP address pairs from the device and authenticating the user, and a directory server coupled to receive authenticated user identifier/IP address pairs from the authentication server.

Claims (43)

1. A method of binding a user with an internet protocol address comprising:

a) connecting the user with a binding system and identifying a user identifier and an internet protocol address to be used by the user;

b) storing the user identifier/internet protocol address pair in a data store using the binding system.

2. The method as recited by claim 1 wherein the connection with the binding system is a secure connection.

3. The method as recited by claim 1 wherein prior to identifying the user, the method further comprises issuing a registration request to the binding system, the registration request including the user identifier and a password.

4. The method as recited by claim 3 wherein the registration request is made using HTTP as the transport protocol.

5. The method as recited by claim 1 wherein the internet protocol address was assigned to the user by a dynamic host configuration protocol (DHCP) server.

6. The method as recited by claim 1 wherein the binding system comprises a combination of a lightweight directory access protocol (LDAP) data store and an authentication server.

7. The method as recited by claim 6 wherein the authentication server authenticates the user before storing the user identifier/internet protocol address pair.

8. A server for use in authentication of user identifier/internet protocol address pairs comprising:

a) a first data store having stored therein an authenticated user identifier/internet protocol address pair; and

b) a second data store having stored therein a program which when executed on a processor retrieves the authenticated user identifier/internet protocol address pair and transmits the pair to a requesting device.

9. The server as recited by claim 8 wherein the server further comprises a third data store having stored therein a program which when executed on a processor stores authenticated user identifier/internet protocol address pairs received from an authentication server.

10. The server as recited by claim 9 wherein the authentication server communicates over an encrypted communication channel with the server.

11. A method of providing authenticated user identifier/IP address pairs comprising:

a) a first device communicating with a dynamic host configuration protocol (DHCP) server to have an IP address assigned to the first device;

b) the first device communicating with an authentication server a user identifier and the IP address;

c) the authentication server authenticating the user;

d) the authentication server communicating to a directory server a user identifier/IP address pair; and

e) the directory server storing the user identifier/IP address pair.

12. The method as recited by claim 11 wherein the authentication server authenticates the user by use of a user identifier and password supplied by the computer.

13. The method as recited by claim 11 wherein the communication between the computer and the authentication server is encrypted.

14. The method as recited by claim 11 wherein the user identifier/IP address pair is communicated from the authentication server to the directory server over an encrypted channel.

15. The method as recited by claim 11 wherein the authentication server executed on the same hardware platform as the directory server.

16. A network comprising:

a) a dynamic host configuration protocol (DHCP) server;

b) a computer coupled in communication with the DHCP server over the network;

c) an authentication server coupled in communication over the network with the computer, the authentication server for authenticating a user using the computer based on a user identifier communicated from the computer; and

d) a directory server coupled in communication with the authentication server, the directory server receiving and storing authenticated user identifier/IP address pairs from the authentication server.

17. The network as recited by claim 16 wherein the communication channel between the computer and the authentication server is an encrypted communication channel.

18. The network as recited by claim 16 wherein the communication channel between the authentication server and the directory server is an encrypted communication channel.

19. The network as recited by claim 16 wherein the authentication server and the directory server execute on the same hardware platform.

20. The network as recited by claim 16 further comprising requesting devices coupled in communication with the directory server for requesting authenticated user identifier/IP address pairs.

21. A network comprising a dynamic host configuration protocol (DHCP) server for assigning IP addresses to computer and other devices in the network, a device coupled to receive an IP address from the DHCP server, an authentication server coupled with the device for receiving user identifier/IP address pairs from the device and authenticating the user, and a directory server coupled to receive authenticated user identifier/IP address pairs from the authentication server.

22. A lightweight directory access protocol (LDAP) server comprising:

a first data store having stored therein an user identifier/internet protocol address pair; and

a second data store having stored therein a program which when executed on processor retrieves the user identifier/internet protocol address pair and transmits the pair to a requesting device.

23. The LDAP server as recited by claim 22 wherein the server further comprises a third data store having stored therein a program which when executed on a processor stores user identifier/internet protocol address pairs received from an binding server.

24. A lightweight directory access protocol (LDAP) server comprising:

a first data store having stored therein an user identifier and dynamic information related to the user identifier; and

a second data store having stored therein a program which when executed on processor retrieves the user identifier and dynamic information and transmits the information to a requesting device.

25. The LDAP server as recited by claim 24 wherein the server further comprises a third data store having stored therein a program which when executed on a processor stores dynamic information related to a user identifier in the first data store.

26. The LDAP server as recited by claim 24 wherein the dynamic information is an internet protocol address.

Assignments (7)
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS (RELEASES RF 040575/0549) Recorded Dec 3, 2020
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: INFOBLOX INC.
Reel/Frame 054585/0914 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (RELEASES RF 040579/0302) Recorded Oct 23, 2019
From: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
To: INFOBLOX, INC.
Reel/Frame 050809/0980 →
RELEASE OF SECURITY INTEREST Recorded Jan 11, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.
Reel/Frame 045045/0564 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 023892/0500 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.
Reel/Frame 044891/0564 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 8, 2016
From: INFOBLOX INC.
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 040579/0302 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 7, 2016
From: INFOBLOX INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 040575/0549 →