IP Library Granted Patent US 8,627,447
Granted Patent B1
US 8,627,447 · App. 11/857,084 · Granted Jan 7, 2014

Provisioning layer three access for agentless devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,627,447
App. No.
11/857,084
Granted
Jan 7, 2014
Kind
B1
Abstract

A method may include obtaining a layer two identification of an endpoint that is seeking access to a network, the endpoint omitting an agent to communicate a layer three address of the endpoint to a policy node, applying one or more authentication rules based on the layer two identification of the endpoint, assigning the layer three address to the endpoint, learning, by the policy node, the layer three address of the endpoint, and provisioning layer three access for the endpoint to the network based on the learned layer three address.

Claims (111)

1. A method comprising:

receiving, by a device, a request for providing an endpoint access to a network;

applying, by the device, one or more authentication rules to the endpoint seeking access to the network based on a layer two identification of the endpoint;

determining, by the device, to grant the endpoint access to the network based on applying the one or more authentication rules;

determining, by the device, a role to be afforded to the endpoint based on granting the endpoint access to the network,

the role defining one or more permissions granted to the endpoint,

the one or more permissions being associated with the endpoint accessing the network;

sending, by the device, a response to the request,

the response including information identifying the one or more permissions granted to the endpoint;

receiving, by the device and based on sending the response, information identifying a layer three address of the endpoint from an external device,

the external device being different than the endpoint,

the external device assign the layer three address being assigned, from a pool of layer three addresses, to the endpoint after application of the one or more authentication rules,

the layer three address being associated with the one or more permissions,

the layer three address being valid only for a particular amount of time,

the particular amount of time being assigned based on an estimated amount of time layer three access for the endpoint to the network is needed,

the endpoint having the layer three access to the network for the particular amount of time, and

after the particular amount of time, the endpoint being denied the layer three access to the network; and

provisioning, by the device, the layer three access for the endpoint to the network based on the determined layer three address and the one or more permissions.

2. The method of claim 1 , further comprising:

detecting transmissions from the endpoint; and

determining the layer two identification of the endpoint based on the detected transmissions.

3. The method of claim 1 , where the layer two identification of the endpoint includes a medium access control address of the endpoint or a character string that identifies the endpoint.

4. The method of claim 1 , further comprising:

scanning the endpoint for characteristics of the endpoint; and

determining the layer two identification of the endpoint based on the characteristics of the endpoint.

5. The method of claim 1 , where receiving the layer three address comprises:

receiving, from the external device, the layer two identification and the layer three address of the endpoint based on detecting transmissions from the endpoint,

the transmissions including the layer two identification of the endpoint and the layer three address of the endpoint.

6. The method of claim 1 , where receiving the layer three address comprises:

receiving notification of the layer three address from a layer three address assignment server.

7. The method of claim 1 , where the provisioning comprises:

providing, by the device, to a layer three enforcement node, the determined layer three address of the endpoint and the one or more permissions.

8. The method of claim 7 , where the provisioning comprises:

enforcing, by the layer three enforcement node, layer three access of the endpoint based on the determined layer three address of the endpoint and the one or more permissions.

9. A system to which an endpoint communicates, the system comprising:

a network device to:

receive a request for providing the endpoint access to a network;

authenticate the endpoint for access to the network at a layer two level;

determine a role to be afforded to the endpoint based on authenticating the endpoint,

the role defining one or more permissions granted to the endpoint,

the one or more permissions being associated with the endpoint accessing the network;

send a response to the request,

the response including information identifying the one or more permissions granted to the endpoint;

receive information identifying a layer three address of the endpoint from an external device,

the external device being different than the endpoint,

the layer three address being associated with the one or more permissions,

the layer three address being assigned, from a pool of layer three addresses, after the authentication of the endpoint, and

the layer three address being valid only for a particular amount of time,

the particular amount of time being assigned based on an estimated amount of time layer three access of the endpoint in the network is needed; and

provision layer three access of the endpoint in the network based on the layer three address of the endpoint and the one or more permissions.

10. The system of claim 9 , where the network device is further to:

determine a layer two identifier of the endpoint based on detected transmissions from the endpoint.

11. The system of claim 9 , where, when authenticating the endpoint, the network device is further to:

obtain a layer two identifier of the endpoint using 802.1X.

12. The system of claim 11 , where the layer two identifier of the endpoint includes a character string that identifies the endpoint,

the character string being input by a user associated with the network device.

13. The system of claim 9 , where the network device is further to:

determine a layer two identifier of the endpoint based on a scan of the endpoint.

14. The system of claim 9 , where the network device is further to:

determine a layer two identifier of the endpoint and the layer three address of the endpoint based on detected transmissions from the endpoint.

15. The system of claim 9 , where, when receiving the layer three address of the endpoint, the network device is further to:

receive information identifying a layer two identifier of the endpoint and the layer three address of the endpoint,

the layer two identifier and the layer three address being determined based on scanning the endpoint.

16. A device comprising:

a processor to:

receive a request for providing an endpoint access to a network;

obtain a layer two identification of the endpoint that is seeking access to the network,

the endpoint being unassigned a layer three address;

authenticate the endpoint based on the layer two identification of the endpoint and one or more network polices;

determine to grant the endpoint access to the network based on authenticating the endpoint;

determine a role to be afforded to the endpoint based on granting the endpoint access to the network,

the role defining one or more permissions granted to the endpoint,

the one or more permissions being associated with the endpoint accessing the network;

send a response to the request,

the response including information identifying the one or more permissions granted to the endpoint;

receive information identifying a layer three address of the endpoint from an external device other than the endpoint,

the layer three address being associated with the one or more permissions,

the layer three address being assigned, from a pool of layer three addresses, to the endpoint after authentication of the endpoint,

the layer three address being valid for only a particular amount of time,

the particular amount of time being assigned based on an estimated amount of time layer three access for the endpoint to the network is needed,

the endpoint having the layer three access to the network for the particular amount of time, and

after the particular amount of time, the endpoint being denied the layer three access to the network; and

provision layer three access for the endpoint to the network based on the one or more permissions and the layer three address of the endpoint.

17. The device of claim 16 , where the layer two identification of the endpoint includes a character string that identifies the endpoint.

18. The device of claim 16 , where the processor is further to:

receive the layer two identification of the endpoint and the layer three address of the endpoint from the external device,

where the external device is at least one of a sensor device or a network access device.

19. A device comprising:

a processor to:

receive a request for providing an endpoint access to a network;

authenticate the endpoint based on a layer two identifier of the endpoint;

determine a role to be afforded to the endpoint based on authenticating the endpoint,

the role defining one or more permissions granted to the endpoint,

the one or more permissions being associated with the endpoint accessing the network;

send a response to the request,

the response including information identifying the one or more permissions granted to the endpoint;

receive information identifying a layer three address of the endpoint from an external device that is different than the endpoint,

the layer three address being associated with the one or more permissions,

the layer three address being assigned to the endpoint, from a pool of layer three addresses, after authentication of the endpoint,

the layer three address being valid only for a particular amount of time,

the particular amount of time being assigned based on an estimated amount of time layer three access for the endpoint to the network is needed,

the endpoint having the layer three access to the network for the particular amount of time,

after the particular amount of time, the endpoint being denied the layer three access to the network, and

the external device acquiring the layer three address based on at least one of:

a scanning of the endpoint,

an assigning of the layer three address to the endpoint, or

an intercepting of a transmission from the endpoint, the transmission not including the layer three address; and

control access to the network, by the endpoint and through a layer three enforcement point, by providing the layer three enforcement point with information identifying the one or more permissions and the layer three address of the endpoint.

20. The device of claim 19 , where the layer two identifier of the endpoint includes a medium access control address of the endpoint or a character string that identifies the endpoint.

21. The device of claim 19 , where the processor is further to:

determine the layer two identifier of the endpoint based on detected transmissions from the endpoint.

Assignments (15)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
Reel/Frame 053271/0307 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
SECURITY INTEREST Recorded Dec 30, 2014
From: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 034713/0950 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2014
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 034045/0717 →