IP Library Granted Patent US 7,536,543
Granted Patent B1
US 7,536,543 · App. 10/959,037 · Granted May 19, 2009

System and method for authentication and authorization using a centralized authority

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,536,543
App. No.
10/959,037
Granted
May 19, 2009
Kind
B1
Abstract

The invention features a system and method for authenticating and authorizing a user to log onto a network element in a telecommunications optical network. The administration of security for the network is handled by a centralized authority. The centralized authority maintains the accounts for individuals authorized to log onto the network elements and their associated privileges. In one embodiment, to log onto a network element a user provides a user identifier and user authentication information to the centralized authority. The centralized authority then processes the user identifier and user authentication information to authenticate the user. If authenticated, the centralized authority determines a privilege level for the user and generates an affirmative response that includes the user identifier and the privilege level. Provided with the affirmative response, the network element logs the user onto the network element with the associated privilege level.

Claims (29)

1. A method for authenticating and authorizing a user to log onto to a network element in a telecommunications network, the method comprising:

receiving by a network element a log-on communication from a user system, the log-on communication including a user identifier and user authentication information associated with a user who is attempting to log onto the network element;

generating, by the network element, an authentication request having the user identifier and user authentication information, for transmission to a centralized authority;

detecting, by the network element, failure in an attempt to transmit the authentication request to the centralized authority;

generating, by the network element, a challenge in response to detecting failure in the attempt to transmit the authentication request to the centralized authority;

transmitting, by the network element, the challenge to the user system;

receiving at a networks operation center (NOC) the challenge from the user;

authenticating the user by the NOC;

providing, to the user by the NOC, a response to the challenge in response to authenticating the user;

receiving, from the user system by the network element, the response to the challenge; and

authorizing, by the network element, the user to log on to the network element based on the response to the challenge received from the user system.

2. The method according claim 1 , wherein the centralized authority includes a central server.

3. The method according to claim 1 , wherein the request is transmitted in a cryptographically secure manner.

4. The method according to claim 1 , further comprising:

executing, by the network element, an algorithm common to a plurality of network elements in the telecommunications network, to generate the challenge.

5. The method according to claim 4 , wherein the response is uniquely associated with the challenge and includes information regarding the user identifier and a privilege level.

6. The method according to claim 5 , further comprising limiting the user to one session on the network element based on the response.

7. The method according to claim 4 , wherein the challenge is provided to the centralized authority by way of a telephone network.

8. The method according to claim 5 , wherein the privilege level limits user access to a particular domain.

9. The method according to claim 8 , wherein the domain specifies a set of network elements within a particular geographical region.

10. The method according to claim 5 , wherein the privilege level is determined based on the particular network element that the user is attempting to access.

11. The method of claim 1 , further comprising extracting, by the network element, the user identifier and a privilege level from the response to the challenge received from the user system.

12. The method of claim 1 , wherein receiving from the user at the NOC the challenge includes receiving a telephone call from the user by which the user communicates the challenge to a member of the NOC.

13. A system in a telecommunications network environment for authenticating and authorizing a user, the system comprising:

a network element connected to the telecommunications network, the network element receiving a user identifier and user authentication information associated a user who is attempting to log onto the network element, the network element generating an authentication request in response to the log-on attempt, the authentication request including the user identifier and user authentication information received from the user; and

a centralized authority receiving from the network element the authentication request having the user identifier and user authentication information associated with the user who is attempting to log onto the network element, the centralized authority generating a response to the authentication request and transmitting the response to the network element authorizing the user to log onto the network element, the response containing the user identifier and a user privilege level,

wherein the network element includes a challenge generator for producing a challenge to be provided to the centralized authority if the network element is unable to transmit the authentication request successfully to the centralized authority, the challenge generator executing an algorithm commonly employed by a plurality of network elements in the telecommunications network for producing challenges.

14. The system according to claim 13 , wherein the request is transmitted from the network element to the centralized authority in a cryptographically secure manner.

15. The system according claim 13 , wherein the centralized authority includes a central server.

Assignments (10)
RELEASE (REEL 038041 / FRAME 0001) Recorded Jan 2, 2018
From: JPMORGAN CHASE BANK, N.A.
To: RPX CORPORATION; RPX CLEARINGHOUSE LLC
Reel/Frame 044970/0030 →
SECURITY AGREEMENT Recorded Mar 9, 2016
From: RPX CORPORATION; RPX CLEARINGHOUSE LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 038041/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2015
From: ROCKSTAR CONSORTIUM US LP; ROCKSTAR CONSORTIUM LLC; BOCKSTAR TECHNOLOGIES LLC; CONSTELLATION TECHNOLOGIES LLC; MOBILESTAR TECHNOLOGIES LLC; NETSTAR TECHNOLOGIES LLC
To: RPX CLEARINGHOUSE LLC
Reel/Frame 034924/0779 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2014
From: ROCKSTAR CONSORTIUM US LP
To: CONSTELLATION TECHNOLOGIES LLC
Reel/Frame 032162/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2014
From: ROCKSTAR BIDCO, LP
To: ROCKSTAR CONSORTIUM US LP
Reel/Frame 032117/0078 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2011
From: NORTEL NETWORKS LIMITED
To: ROCKSTAR BIDCO, LP
Reel/Frame 027164/0356 →
CHANGE OF NAME Recorded Jun 3, 2011
From: NORTEL TECHNOLOGY LIMITED
To: NORTEL NETWORKS TECHNOLOGY CORPORATION
Reel/Frame 026389/0306 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2011
From: RYCROFT, STEVE
To: NORTEL TECHNOLOGY LIMITED
Reel/Frame 026356/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2011
From: NORTEL NETWORKS TECHNOLOGY CORPORATION
To: NORTEL NETWORKS LIMITED
Reel/Frame 026331/0645 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2005
From: SANDHU, ACHINT; GUO, ROSA; FIZZELL, CHARLES; RODRIGUES, JASON; ZHANG, MARINA-MAN
To: NORTEL NETWORKS LIMITED
Reel/Frame 015970/0474 →