IP Library Granted Patent US 7,831,996
Granted Patent B2
US 7,831,996 · App. 11/496,788 · Granted Nov 9, 2010

Authentication techniques

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,831,996
App. No.
11/496,788
Granted
Nov 9, 2010
Kind
B2
Abstract

Techniques for authenticating clients of differing capabilities in an efficient manner. Two or more authentication techniques, including one preferred authentication technique, are initiated to run in parallel to authenticate a client. Upon determining that the client can support the preferred authentication technique, the preferred technique is used to authenticate the client and the other authentication techniques are aborted. If it is determined that the client cannot support the preferred authentication technique, then one of the other authentication techniques is used to authenticate the client. In this manner, based upon the capabilities of the client, an appropriate authentication technique is used to authenticate the client in an efficient manner.

Claims (71)

1. A method of performing authentication, the method comprising:

initiating, by a server, a first authentication technique and a second authentication technique for authenticating a client such that the first authentication technique and the second authentication technique are performed concurrently;

determining if the client supports the first authentication technique;

using the first authentication technique to authenticate the client upon determining that the client supports the first authentication technique; and

using the second authentication technique to authenticate the client upon determining that the client does not support the first authentication technique.

2. The method of claim 1 further comprising:

denying or permitting the client to access a network based upon the first authentication technique if the client supports the first authentication technique and based upon the second authentication technique if the client does not support the first authentication technique.

3. The method of claim 1 wherein the second authentication technique uses an address associated with the client.

4. The method of claim 3 wherein the address associated with the client is a medium access control (MAC) address of the client or an Internet Protocol (IP) address of the client.

5. The method of claim 1 wherein the first authentication technique is based upon IEEE 802.1x.

6. The method of claim 1 wherein initiating the first authentication technique and the second authentication technique comprises:

sending, as part of the first authentication technique, an information request to the client; and

sending, as part of the second authentication technique, a first authentication request comprising an address of the client to an authentication server.

7. The method of claim 6 wherein determining if the client supports the first authentication technique comprises determining if a response is received from the client responsive to the information request, wherein receipt of a response indicates that the client supports the first authentication technique.

8. The method of claim 7 further comprising receiving a response from the client responsive to the information request, and wherein using the first authentication technique to authenticate the client comprises:

sending a second authentication request to the authentication server, the authentication request comprising information received in the response; and

receiving an authentication result from the authentication server indicative of authentication performed by the authentication server based upon the second authentication request.

9. The method of claim 8 wherein using the first authentication technique to authenticate the client comprises aborting the second authentication technique.

10. The method of claim 6 wherein using the second authentication technique to authenticate the client comprises receiving an authentication result from the authentication server indicative of authentication performed by the authentication server based upon the first authentication request.

11. A method of authenticating a client, the method comprising:

initiating, by a server, a first authentication technique and a second authentication technique for authenticating a client;

performing the first authentication technique and the second authentication technique concurrently;

determining, during performing the first authentication technique, if the client supports the first authentication technique;

continuing to perform the first authentication technique and aborting the second authentication technique upon determining that the client supports the first authentication technique; and authenticating the client using the second authentication technique upon determining that the client does not support the first authentication technique.

12. A system for authenticating a client, the system comprising:

an access server; and

an authentication server coupled to the access server;

wherein the access server is adapted to:

initiate a first authentication technique and a second authentication technique for authenticating a client such that the first authentication technique and the second authentication technique are performed concurrently, wherein the second authentication technique uses the authentication server;

determine if the client supports the first authentication technique;

use the first authentication technique to authenticate the client upon determining that the client supports the first authentication technique; and

use the second authentication technique to authenticate the client upon determining that the client does not support the first authentication technique.

13. The system of claim 12 wherein the access server is adapted to deny or permit the client to access a network based upon the first authentication technique if the client supports the first authentication technique and based upon the second authentication technique is the client does not support the first authentication technique.

14. The system of claim 12 wherein the second authentication technique uses an address associated with the client.

15. The system of claim 14 wherein the address associated with the client is a medium access control (MAC) address of the client or an Internet Protocol (IP) address of the client.

16. The system of claim 12 wherein the first authentication technique is based upon IEEE 802.1x.

17. The system of claim 12 wherein the access server is adapted to:

send, as part of the first authentication technique, an information request to the client; and

send, as part of the second authentication technique, a first authentication request comprising an address of the client to the authentication server.

18. The system of claim 17 wherein the access server is adapted to determine if a response is received from the client responsive to the information request, wherein receipt of a response indicates that the client supports the first authentication technique.

19. The system of claim 18 wherein the access server is adapted to:

receive a response from the client responsive to the information request;

send a second authentication request to the authentication server, the authentication request comprising information received in the response; and

receive an authentication result from the authentication server indicative of authentication performed by the authentication server based upon the second authentication request.

20. The system of claim 19 wherein the access server is adapted to abort the second authentication technique.

21. The system of claim 17 wherein the access server is adapted to receive an authentication result from the authentication server indicative of authentication performed by the authentication server based upon the first authentication request.

22. An apparatus comprising:

means for initiating a first authentication technique and a second authentication technique for authenticating a client such that the first authentication technique and the second authentication technique are performed concurrently;

means for determining if the client supports the first authentication technique;

means for using the first authentication technique to authenticate the client upon determining that the client supports the first authentication technique; and

means for using the second authentication technique to authenticate the client upon determining that the client does not support the first authentication technique.

23. The apparatus of claim 22 further comprising:

means for denying or permitting the client to access a network based upon the first authentication technique if the client supports the first authentication technique and based upon the second authentication technique if the client does not support the first authentication technique.

24. The apparatus of claim 22 wherein the second authentication technique uses an address associated with the client.

25. The method of claim 22 wherein the address associated with the client is a medium access control (MAC) address of the client or an Internet Protocol (IP) address of the client.

26. The apparatus of claim 22 wherein the first authentication technique is based upon IEEE 802.1x.

27. The apparatus of claim 22 wherein the means for initiating the first authentication technique and the second authentication technique comprise:

means for sending, as part of the first authentication technique, an information request to the client; and

means for sending, as part of the second authentication technique, a first authentication request comprising an address of the client to an authentication server.

28. The apparatus of claim 27 wherein the means for determining if the client supports the first authentication technique comprise means for determining if a response is received from the client responsive to the information request, wherein receipt of a response indicates that the client supports the first authentication technique.

29. The apparatus of claim 28 further comprising means for receiving a response from the client responsive to the information request, and wherein the means for using the first authentication technique to authenticate the client comprise:

means for sending a second authentication request to the authentication server, the authentication request comprising information received in the response; and

means for receiving an authentication result from the authentication server indicative of authentication performed by the authentication server based upon the second authentication request.

30. The apparatus of claim 29 wherein the means for using the first authentication technique to authenticate the client comprise means for aborting the second authentication technique.

31. The apparatus of claim 27 wherein the means for using the second authentication technique to authenticate the client comprise means for receiving an authentication result from the authentication server indicative of authentication performed by the authentication server based upon the first authentication request.

32. An apparatus comprising:

means for initiating a first authentication technique and a second authentication technique for authenticating a client;

means for performing the first authentication technique and the second authentication technique concurrently;

means for determining, during performing the first authentication technique, if the client supports the first authentication technique;

means for continuing to perform the first authentication technique and aborting the second authentication technique upon determining that the client supports the first authentication technique; and

means for authenticating the client using the second authentication technique upon determining that the client does not support the first authentication technique.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2018
From: BROCADE COMMUNICATIONS SYSTEMS LLC
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047270/0247 →
RELEASE OF SECURITY INTEREST Recorded Jan 22, 2015
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: BROCADE COMMUNICATIONS SYSTEMS, INC.; FOUNDRY NETWORKS, LLC
Reel/Frame 034804/0793 →
RELEASE OF SECURITY INTEREST Recorded Jan 21, 2015
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: BROCADE COMMUNICATIONS SYSTEMS, INC.; INRANGE TECHNOLOGIES CORPORATION; FOUNDRY NETWORKS, LLC
Reel/Frame 034792/0540 →
CHANGE OF NAME Recorded Jul 21, 2010
From: FOUNDRY NETWORKS, INC.
To: FOUNDRY NETWORKS, LLC
Reel/Frame 024733/0739 →
SECURITY AGREEMENT Recorded Jan 20, 2010
From: BROCADE COMMUNICATIONS SYSTEMS, INC.; FOUNDRY NETWORKS, LLC; INRANGE TECHNOLOGIES CORPORATION; MCDATA CORPORATION; MCDATA SERVICES CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 023814/0587 →
SECURITY AGREEMENT Recorded Dec 22, 2008
From: BROCADE COMMUNICATIONS SYSTEMS, INC.; FOUNDRY NETWORKS, INC.; INRANGE TECHNOLOGIES CORPORATION; MCDATA CORPORATION
To: BANK OF AMERICA, N.A. AS ADMINISTRATIVE AGENT
Reel/Frame 022012/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2006
From: DHOLAKIA, MEHUL; TALMOR, RON
To: FOUNDRY NETWORKS, INC.
Reel/Frame 018336/0522 →