IP Library Granted Patent US 6,874,090
Granted Patent B2
US 6,874,090 · App. 09/886,930 · Granted Mar 29, 2005

Deterministic user authentication service for communication network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,874,090
App. No.
09/886,930
Granted
Mar 29, 2005
Kind
B2
Abstract

A user authentication service for a communication network authenticates local users before granting them access to personalized sets of network resources. Authentication agents on intelligent edge devices present users of associated end systems with log-in challenges. Information supplied by the users is forwarded to an authentication server for verification. If successfully verified, the authentication server returns to the agents authorized connectivity information and time restrictions for the particular authenticated users. The agents use the information to establish rules for filtering and forwarding network traffic originating from or destined for particular authenticated users during authorized time periods. An enhanced authentication server may be engaged if additional security is desired. The authorized connectivity information preferably includes identifiers of one or more virtual local area networks active in the network. Log-in attempts are recorded so that the identity and whereabouts of network users may be monitored from a network management station.

Claims (58)

1. A user authentication method for a communication network having a plurality of nodes, the method comprising:

entering on a first node first user identification information;

transmitting to an authentication agent on a second node communicating with the first node over a LAN link the first user identification information;

relaying from the authentication agent to an authentication server the first user identification information;

comparing on the authentication server the first user identification information with user identification information in a database of user identification information; and

transmitting from the authentication server to the authentication agent, if the first user identification information matches user identification information in the database of user identification information, notification information notifying the authentication agent that a user on the first node has been authenticated whereupon the authentication agent authorizes transmission on the second node of packets in data flows involving the first node, wherein the first user identification information is transmitted to the authentication agent as part of a MAC-based authentication flow between an authentication client on the first node and the authentication agent.

2. The method of claim 1 , further comprising relaying from the authentication agent to the authentication client as part of the MAC-based authentication flow the notification information.

3. The method of claim 1 , further comprising, prior to transmitting the first user identification information to the authentication agent, transmitting from the authentication client to the authentication agent as part of the MAC-based authentication flow a request to establish an authentication session.

4. The method of claim 1 , further comprising transmitting from the authentication client to the authentication agent as part of the MAC-based authentication flow a logoff request, whereupon the authentication agent revokes the authorization.

5. The method of claim 1 , further comprising transmitting from the authentication server to the authentication agent, if the first user identification information does not match user identification information in the database, second notification information notifying the authentication agent that the user on the first node has failed to become authenticated, whereupon the authentication agent fails to authorize transmission on the second node of packets in data flows involving the first node and relays to the authentication client as part of the MAC-based authentication flow the second notification information.

6. The method of claim 5 , wherein if the authentication agent determines that the user has made a predetermined number of failed authentication attempts, the authentication agent transmits to the authentication client as part of the MAC-based authentication flow information notifying the authentication client that further authentication attempts will be inhibited.

7. The method of claim 1 , wherein the packets transmitted pursuant to the authorization are neither encrypted nor decrypted by the second node.

8. A user authentication method for a communication network having a plurality of nodes, the method comprising:

entering on a first node first user identification information;

transmitting to an authentication agent on a second node communicating with the first node over a LAN link the first user identification information;

relaying from the authentication agent to an authentication server the first user identification information;

comparing on the authentication server the first user identification information with user identification information in a database of user identification information; and

transmitting from the authentication server to the authentication agent, if the first user identification information matches user identification information in the database of user identification information, information notifying the authentication agent that a user on the first node has been authenticated whereupon the authentication agent authorizes transmission on the second node of packets in data flows involving the first node, wherein the authorization comprises authorizing an interface to the LAN link to allow packets in data flows.

9. The method of claim 8 , wherein the interface is on the second node.

10. The method of claim 8 , wherein the LAN link is an Ethernet link.

11. The method of claim 8 , wherein the authentication server is a RADIUS server.

12. The method of claim 8 , wherein the authentication server is on a third node.

13. The method of claim 8 , wherein prior to the authorization, the second node drops all packets received from the first node that are not part of an authentication flow.

14. The method of claim 8 , wherein prior to the authorization, the second node drops all packets received from the first node that are not addressed to the authentication agent.

15. A user authentication method for a communication network having a plurality of nodes, the method comprising:

entering on a first node first user identification information;

transmitting to an authentication agent on a second node communicating with the first node over a LAN link the first user identification information;

relaying from the authentication agent to an authentication server the first user identification information;

comparing on the authentication server the first user identification information with user identification information in a database of user identification information; and

transmitting from the authentication server to the authentication agent, if the first user identification information matches user identification information in the database of user identification information, notification information notifying the authentication agent that a user on the first node has been authenticated whereupon the authentication agent authorizes transmission on the second node of packets in data flows involving the first node and one or more nodes reachable by the first node via the second node and relays to the first node the notification information.

16. The method of claim 15 , wherein prior to the authorization, the second node inhibits transmission to any nodes reachable by the first node via the second node of all packets received from the first node that are not part of an authentication flow.

17. The method of claim 15 , wherein prior to the authorization, the second node inhibits transmission to any nodes reachable by the first node via the second node of all packets received from the first node that are not addressed to the authentication agent.

18. The method of claim 15 , further comprising, prior to transmitting the first user identification information to the authentication agent, transmitting from the first node to the authentication agent a request to establish an authentication session.

19. The method of claim 15 , further comprising transmitting from the first node to the authentication agent a logoff request, whereupon the authentication agent revokes the authorization.

20. The method of claim 15 , further comprising transmitting from the authentication serve to the authentication agent, if the first user identification information does not match user identification information in the database, second notification information notifying the authentication agent that the user on the first node has failed to become authenticated, whereupon the authentication agent fails to authorize transmission on the second node of packets in data flows involving the first node and any nodes reachable by the first node via the second node and relays to the first node the second notification information.

21. The method of claim 20 , wherein upon receipt of the second notification information, the authentication agent determines the number of failed authentication attempts made by the user.

22. The user authentication method of claim 21 , wherein if the authentication agent determines that the user has made a predetermined number of failed authentication attempts, the authentication agent inhibits further authentication attempts.

23. The user authentication method of claim 21 , wherein if the authentication agent determines that the user has made a predetermined number of failed authentication attempts, the authentication agent transmits to the first node information notifying the first node that further authentication attempts will be inhibited.

24. A user authentication method for a communication network having a plurality of nodes, the method comprising:

entering on a first node first user identification information;

transmitting to an authentication agent on a second node communicating with the first node over a LAN link the first user identification information;

relaying from the authentication agent to an authentication server the first user identification information;

comparing on the authentication server the first user identification information with user identification information in a database of user identification information; and

transmitting from the authentication server to the authentication agent, if the first user identification information matches user identification information in the database of user identification information, information notifying the authentication agent that a user on the first node has been authenticated whereupon the authentication agent authorizes transmission on the second node of packets in data flows involving the first node, wherein the packets that are transmitted pursuant to the authorization bypass the authentication agent.

25. A user authentication method for a communication network having a plurality of nodes, the method comprising:

entering on a first node first user identification information;

transmitting to an authentication agent on a second node communicating with the first node over a LAN link the first user identification information;

relaying from the authentication agent to an authentication server the first user identification information;

comparing on the authentication server the first user identification information with user identification information in a database of user identification information; and

transmitting from the authentication server to the authentication agent, if the first user identification information matches user identification information in the database of user identification information, information notifying the authentication agent that a user on the first node has been authenticated and information identifying a VLAN for which the user has been authenticated whereupon the authentication agent authorizes transmission on the second node of packets in data flows that involve the first node and are within the VLAN.

26. The method of claim 25 , wherein the information notifying the authentication agent that the user on the first node has been authenticated and the information identifying the VLAN for which the user has been authenticated are transmitted from the authentication server to the authentication agent in a single packet.

27. The method of claim 25 , wherein one or more of the packets that are transmitted pursuant to the authorization are appended on the second node and transmitted from the second node to a backbone network with an identifier of the VLAN.

28. The method of claim 25 , further comprising dropping on the second node of packets in data flows involving the first node and other nodes that are not within the VLAN.

29. The method of claim 25 , further comprising, before the authorization, dropping on the second node of packets in data flows involving the first node.

30. The method of claim 25 , further comprising, after the authorization, forwarding on the second node of packets in data flows involving the first node and other nodes that are within the VLAN.

31. The method of claim 25 , wherein the first user identification information is transmitted front the first node to the authentication agent as part of a MAC-based authentication flow between an authentication client on the first node and the authentication agent.

32. The method of claim 25 , wherein the authorization comprises authorizing an interface to the LAN link to allow packets in data flows.

33. The method of claim 25 , wherein the packets that are transmitted pursuant to the authorization bypass the authentication agent.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2014
From: CREDIT SUISSE AG
To: ALCATEL LUCENT
Reel/Frame 033868/0001 →
SECURITY AGREEMENT Recorded Jan 30, 2013
From: ALCATEL LUCENT
To: CREDIT SUISSE AG
Reel/Frame 029821/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED ON REEL 029378 FRAME 0729. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF ASSIGNORS INTEREST. Recorded Dec 6, 2012
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 029422/0296 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2012
From: ALCATEL-LUCENT USA INC.
To: ALCATEL
Reel/Frame 029378/0729 →
MERGER Recorded Nov 28, 2012
From: ALCATEL USA SOURCING, INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 029364/0933 →
MERGER Recorded Sep 3, 2008
From: ALCATEL USA RESOURCES, INC.
To: ALCATEL USA SOURCING, INC.
Reel/Frame 021462/0956 →
CHANGE OF NAME Recorded Sep 22, 2006
From: XYLAN CORPORATION
To: ALCATEL INTERNETWORKING, INC.
Reel/Frame 018293/0176 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2006
From: ALCATEL
To: ALCATEL USA RESOURCES, INC.
Reel/Frame 018247/0418 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2005
From: GOODWIN, MICHELE WRIGHT; SANGRONIZ, ROBERT LEON
To: ALCATEL
Reel/Frame 016385/0027 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2002
From: ALCATEL INTERNETWORKING, INC.
To: ALCATEL
Reel/Frame 013484/0292 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2001
From: SEE, MICHAEL E.; BAILEY, JOHN W.; PANZA, CHARLES L.; PIKOVER, YURI; STONE, GEOFFREY C.
To: XYLAN CORPORATION
Reel/Frame 012237/0360 →