IP Library Granted Patent US 7,861,285
Granted Patent B2
US 7,861,285 · App. 11/672,296 · Granted Dec 28, 2010

System, method and computer program product for authenticating users using a lightweight directory access protocol (LDAP) directory server

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,861,285
App. No.
11/672,296
Granted
Dec 28, 2010
Kind
B2
Abstract

A system, method and computer program product for providing authentication to a firewall using a lightweight directory access protocol (LDAP) directory server is disclosed. The firewall can be configured through a graphical user interface to implement an authentication scheme. The authentication scheme is based upon a determination of whether at least part of one or more LDAP entries satisfy an authorization filter.

Claims (32)

1. A method of configuring a firewall process that executes on a device, the method comprising:

receiving a host computer identification, the host computer including at least one directory schema defined by an entity and configured to store information concerning the entity's organization;

receiving authentication settings for the firewall process to use in authenticating network resource requests received over a computer network by the firewall process as a function of the at least one directory schema;

generating an authorization filter for the firewall process to apply to computer network traffic as a function of the one or more authentication settings and the at least one directory schema; and

enabling the firewall process to intercept computer network resource requests from client users on an internal computer network and authorize computer network resource requests based on a comparison of at least a portion of the at least one directory schema to the authorization filter.

2. The method of claim 1 , further comprising:

receiving a host port setting, wherein communication between the firewall and the host computer is performed over a port identified by the host port setting.

3. The method of claim 2 , wherein the port setting specifies one or more ports and a secure socket layer communication setting to cause communication between the firewall and the host computer to be performed in a secure fashion.

4. The method of claim 1 , wherein at least one directory schema is a lightweight directory access protocol directory schema.

5. The method of claim 4 , wherein the lightweight directory access protocol directory schema is preexisting.

6. The method of claim 1 , wherein receiving the authentication settings includes:

receiving an identification of at least one directory schema and a portion of the at least one directory schema to search.

7. The method of claim 6 , wherein:

receiving the authentication settings includes receiving one or more user attributes; and

generating the authorization filter includes generating the authorization filter implementing a per-user authentication scheme as a further function of the one or more user attributes.

8. The method of claim 1 , wherein generating the authorization filter includes implementing a per-service authentication scheme.

9. A non-transitory computer program product for enabling a processor in a computer system to implement a firewall configuration process, said computer program product comprising:

a non transitory computer usable medium having computer readable program code embodied in said medium for causing a program to execute on the computer system, said computer readable code comprising:

first computer readable program code for enabling the computer system to receive a host computer identification, the host computer including at least one directory schema defined by an entity and configured to store information concerning the entity's organization;

second computer readable program code for enabling the computer system to receive authentication settings for the firewall to use in authenticating network resource requests as a function of the at least one directory schema;

third computer readable program code for enabling the computer system to generate an authorization filter as a function of the one or more authentication settings and the at least one directory schema; and

fourth computer readable program code for enabling the computer system to enable the firewall to intercept network resource requests from client users on an internal network and authorize network resource requests based on a comparison of at least a portion of the at least one directory schema to the authorization filter.

10. The non-transitory computer program product of claim 9 , said computer readable code further comprising:

fifth computer readable program code for enabling the computer system to receive a host port setting, wherein communication between the firewall and the host computer is performed over a port identified by the host port setting.

11. The non-transitory computer program product of claim 10 , wherein the port setting specifies one or more ports and a secure socket layer communication setting to cause communication between the firewall and the host computer to be performed in a secure fashion.

12. The non-transitory computer program product of claim 9 , wherein at least one directory schema is a lightweight directory access protocol directory schema.

13. The non-transitory computer program product of claim 12 , wherein the lightweight directory access protocol directory schema is preexisting.

14. The non-transitory computer program product of claim 9 , wherein receiving the authentication settings of the second computer readable program code includes receiving an identification of at least one directory schema and a portion of the at least one directory schema to search.

15. The non-transitory computer program product of claim 14 , wherein:

receiving the authentication settings of the second computer readable program code includes receiving one or more user attributes; and

generating the authorization filter of the third computer readable program code includes generating the authorization filter implementing a per-user authentication scheme as a further function of the one or more user attributes.

16. The non-transitory computer program product of claim 9 , wherein generating the authorization filter of the third computer readable program code includes implementing a per-service authentication scheme.

Assignments (14)
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 024456/0724 →
CHANGE OF NAME Recorded Mar 25, 2010
From: SECURE COMPUTING CORPORATION
To: SECURE COMPUTING, LLC
Reel/Frame 024128/0806 →