IP Library Granted Patent US 8,707,395
Granted Patent B2
US 8,707,395 · App. 11/320,603 · Granted Apr 22, 2014

Technique for providing secure network access

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,707,395
App. No.
11/320,603
Granted
Apr 22, 2014
Kind
B2
Abstract

A technique for providing secure network access is disclosed. In one particular exemplary embodiment, the technique may be realized as a method for providing secure network access. The method may comprise establishing a plurality of access zones in a network, wherein client devices assigned to different access zones have different access privileges and are isolated from one another. The method may also comprise assigning a client device to one of the plurality of access zones based on an assessment of a security context associated with the client device and a connection of the client device to the network.

Claims (56)

1. A method for providing secure network access comprising the steps of:

establishing a plurality of access zones in a network, wherein client devices assigned to different access zones have different access privileges and are isolated from one another, wherein the plurality of access zones are selected from a group consisting of:

at least one first access zone for client devices that have not been authenticated;

at least one second access zone for client devices that are authenticated but not fully trusted; and

at least one third access zone for client devices that are authenticated and fully trusted; and

assigning a client device to one of the plurality of access zones based on an authentication of the client device, an assessment of a security context associated with the client device, and a connection of the client device to the network, wherein the assessment of the security context is performed at least in part by an agent program in the client device to determine an access privilege of the client device and the assessment of the security context is performed prior to the authentication of the client device, and wherein network traffic associated with the client device is filtered for remediation messages only if the client device is assigned to the at least one second zone, wherein said remediation messages comprise security patches and antivirus definitions.

2. The method according to claim 1 , further comprising:

applying a filter to network traffic associated with the client device based at least in part on the access zone the client device is assigned to.

3. The method according to claim 1 further comprising:

reassigning the client device to another access zone in response to one or more triggering events, wherein the one or more triggering events are selected from a group consisting of:

a change in the security context;

a security violation associated with the client device;

a security violation detected in the network; and

an operator-initiated request to reassign the client device to another access zone.

4. The method according to claim 1 further comprising:

changing, based on a further assessment of the security context, a filter applied to network traffic associated with the client device without reassigning the client device to another access zone if the client device has a static Internet Protocol (IP) address.

5. The method according to claim 1 , further comprising:

assigning an Internet telephone device to all voice-over-IP (VOIP) virtual local area networks (VLANs) in the network; and maintaining the assignment.

6. The method according to claim 1 , wherein the agent program in the client device is downloaded to the client device.

7. The method according to claim 1 , wherein the client device is only permitted to access an authentication server if the client device is assigned to the at least one first access zone.

8. The method according to claim 1 , wherein the client device is granted access to the network based on a user profile, if the client device is assigned to the at least one third access zone.

9. The method according to claim 1 , wherein:

the client device connects to the network via a network element that is controlled by an access controller; and

the access controller maintains a persistent connection with the network element, thereby facilitating a prompt assignment or reassignment of the client device to one of the plurality of access zones.

10. The method according to claim 1 wherein:

the network is a virtual private network; and

each of the plurality of access zones is a virtual local area network (VLAN).

11. The method according to claim 1 , further comprising: causing the client device to obtain a network address based on the access zone the client device is assigned to.

12. The method according to claim 11 , further comprising:

blocking the client device's requests for any new network address;

causing the client device to initiate a request for a new network address and to retry the request upon rejection:

associating the new network address with the access zone the client device is assigned to; and

allowing the client device's request for the new network address to proceed.

13. The method according to claim 1 , wherein the plurality of access zones in the network are established for client devices having different levels of authentication and security assessment requirements.

14. The method of claim 1 wherein clients in said first access zone have traffic limited to only traffic necessary for authentication purposes and wherein clients in said second access zone have traffic limited to only traffic necessary for remediation purposes.

15. A system for providing secure network access, the system comprising: an access controller and at least one access device coupled to a network, wherein:

the access controller establishes a plurality of access zones in the network, wherein client devices assigned to different access zones have different access privileges and are isolated from one another, wherein the plurality of access zones are selected from a group consisting of:

at least one first access zone for client devices that have not been authenticated;

at least one second access zone for client devices that are authenticated but not fully trusted; and

at least one third access zone for client devices that are authenticated and fully trusted;

a client device connects to the network through the at least one access device; and

the access controller coordinates with the at least one access device to assign the client device to one of the plurality of access zones based on an authentication of the client device, an assessment of a security context associated with the client device, and the client device's connection to the network, wherein the assessment of the security context is performed at least in part by an agent program in the client device to determine an access privilege of the client device and the assessment of the security context is performed prior to the authentication of the client device, and wherein network traffic associated with the client device is filtered for remediation messages only if the client device is assigned to the at least one second zone, wherein said remediation messages comprise security patches and antivirus definitions.

16. The system according to claim 15 , wherein the access controller causes a filter to be applied to network traffic associated with the client device based at least in part on the access zone the client device is assigned to.

17. The system according to claim 15 , wherein the access controller causes the client device to be reassigned to another access zone in response to one or more triggering events, wherein the one or more triggering events are selected from a group consisting of:

a change in the security context;

a security violation associated with the client device;

a security violation detected in the network; and

an operator-initiated request to reassign the client device to another access zone.

18. The system according to claim 15 , wherein the agent program in the client device is downloaded from the access device to the client device.

19. The system according to claim 15 , wherein the access controller maintains a persistent connection with the network element, thereby facilitating a prompt assignment or reassignment of the client device to one of the plurality of access zones.

20. The system according to claim 15 , wherein:

the network is a virtual private network; and

each of the plurality of access zones is a virtual local area network (VLAN).

21. The system according to claim 15 , further comprising a captive web portal, wherein any unauthorized request from the client device redirected to an authentication page served by the captive web portal.

22. The system according to claim 15 , wherein the access controller is not specific to any access technology employed by the client device.

23. The system of claim 15 wherein clients in said first access zone have traffic limited to only traffic necessary for authentication purposes and wherein clients in said second access zone have traffic limited to only traffic necessary for remediation purposes.

Assignments (25)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
RELEASE OF SECURITY INTEREST Recorded Jan 11, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.
Reel/Frame 045045/0564 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 023892/0500 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.
Reel/Frame 044891/0564 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 029608/0256 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 044891/0801 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Jan 10, 2013
From: AVAYA, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 029608/0256 →
SECURITY AGREEMENT Recorded Feb 22, 2011
From: AVAYA INC., A DELAWARE CORPORATION
To: BANK OF NEW YORK MELLON TRUST, NA, AS NOTES COLLATERAL AGENT, THE
Reel/Frame 025863/0535 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2010
From: NORTEL NETWORKS LIMITED
To: AVAYA INC.
Reel/Frame 023998/0878 →
SECURITY AGREEMENT Recorded Feb 5, 2010
From: AVAYA INC.
To: CITICORP USA, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 023905/0001 →
SECURITY AGREEMENT Recorded Feb 4, 2010
From: AVAYA INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 023892/0500 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2005
From: SAHAY, VASANT; KUNJUKUNJU, BIJU SAJIBHAVAN; DAS, NIRMALENDU; MANDAL, SUBHASREE; LEVI, DAVID BURTON; GUGLANI, MANOJ KUMAR; MICHELET, PHILIPPE; KUMAR, RAVI CHAKRAVARTHI
To: NORTEL NETWORKS LIMITED
Reel/Frame 017426/0262 →