IP Library Granted Patent US 8,646,033
Granted Patent B2
US 8,646,033 · App. 12/173,051 · Granted Feb 4, 2014

Packet relay apparatus

Inventor: Motohide Nomi (Kawasaki, JP)
Assignee: ALAXALA Networks Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,646,033
App. No.
12/173,051
Granted
Feb 4, 2014
Kind
B2
Abstract

A packet relay apparatus keeps only packets specified as authentication target packets of MAC address authentication, to reduce the number of packets to be transferred from H/W to a CPU. In addition to a source MAC address, the authentication target packet of MAC address authentication is specified by an Ethernet type, a destination IP address, a protocol, a source port number and a destination port number of TCP/UDP, and the like. In this way, the packet relay apparatus excludes a terminal not transmitting authentication target packets of MAC address authentication, from the MAC address authentication target, while allowing selection from other authentication methods such as Web authentication and IEEE802.1X authentication.

Claims (43)

1. A packet relay apparatus for accommodating a terminal device to relay transmission/reception of a packet between the terminal device and an information processing device including an authentication device, the packet relay apparatus comprising:

a MAC address authentication processing unit for transmitting an authentication request to the authentication device which performs MAC address authentication using a source MAC address included in a packet received from the terminal device, while receiving an authentication determination;

a Web authentication processing unit for processing Web authentication using a user name of the terminal device and password;

an IEEE802.1X authentication processing unit for processing IEEE802/1X authentication; and

an unauthenticated packet processing unit for transferring a packet from an unauthenticated terminal to one of the MAC address authentication processing unit, the Web authentication processing unit, and the IEEE802.1X authentication processing unit, by referring to a database;

wherein the user name and the password are not the MAC address, and

wherein said unauthenticated packet processing unit identifies a type of the packet depending on at least one field of layer 2 header, layer 3 header or layer 4 header, or the combination of the fields of the received packet from the terminal device, compares the type of the packet from the unauthenticated terminal with the database, transfers the packet to one of the MAC address authentication processing unit, the Web authentication processing unit, and the IEEE802.1X authentication processing unit when a corresponding entry is found, and discards the packet when no corresponding entry is found.

2. The packet relay apparatus according to claim 1 , further comprising:

an authentication success packet processing unit for referring to a second database, and transferring a packet whose source address is not stored in the second database, to the unauthenticated packet processing unit.

3. The packet relay apparatus according to claim 2 ,

wherein said authentication processing unit is realized by software, and the unauthenticated packet processing unit is realized by hardware.

4. The packet relay apparatus according to claim 1 ,

wherein said authentication processing unit is realized by software, and the unauthenticated packet processing unit is realized by hardware.

5. The packet relay apparatus according to claim 1 , wherein said authentication processing unit is realized by software, and the unauthenticated packet processing unit is realized by hardware.

6. The packet relay apparatus according to claim 1 ,

wherein, of packets transmitted from an authentication target terminal, only a packet with a terminal MAC address and an IP address that can be identified, is treated as an authentication target packet.

7. The packet relay apparatus according to claim 1 ,

wherein said packet relay apparatus inquires different authentication servers for each received authentication target packet.

8. The packet relay apparatus according to claim 1 ,

wherein, when said determination result of the authentication server is communication permission, the packet relay apparatus permits communication of only a predetermined packet, instead of all the packets transmitted from the terminal.

9. The packet relay apparatus according to claim 1 ,

wherein, when said determination result of the authentication server is communication prohibition, the packet relay apparatus transmits a packet to instruct an operation to the terminal.

10. A packet relay apparatus for being connected to a terminal device via a network, and for transmitting/receiving a packet, the packet relay apparatus comprising:

a MAC address authentication processing unit for performing MAC address authentication using a source MAC address included in a packet received from the terminal device;

a Web authentication processing unit for processing Web authentication using a user name of the terminal device and password;

an IEEE802.1X authentication processing unit for processing IEEE802.1X authentication;

an unauthenticated packet processing unit for transferring a packet from an unauthenticated terminal to one of the MAC address authentication processing unit, the Web authentication processing unit, and the IEEE802.1X authentication processing unit; and

a database for correspondingly storing packet types and authentication to be processed;

wherein the user name and the password are not the MAC address, and

wherein said unauthenticated packet processing unit identifies a type of the packet depending on at least one field of layer 2 header, layer 3 header or layer 4 header, or the combination of the fields of the received packet from the terminal device, transfers the packet to one of the MAC address authentication processing unit, the Web authentication processing unit, and the IEEE802.1X authentication processing unit depending on the correspondence of the identified type of the packet and the authentication to be processed in the database, and discards the packet when the identified type of the packet is not stored in the database.

11. A packet relay apparatus for being connected to a terminal device via a network, and for transmitting/receiving a packet, the packet relay apparatus comprising:

a MAC address authentication processing unit for performing MAC address authentication using a source MAC address included in a packet received from the terminal device;

a Web authentication processing unit for processing Web authentication using a user name of the terminal device and password;

an unauthenticated packet processing unit for transferring a packet from an unauthenticated terminal to one of the MAC address authentication processing unit, the Web authentication processing unit and the IEEE802: IX authentication processing unit; and

a database for correspondingly storing packet types and authentication to be processed;

wherein the user name and the password are not the MAC address, and

wherein said unauthenticated packet processing unit identifies a type of the packet depending on at least one field of layer 2 header, layer 3 header or layer 4 header, or the combination of the fields of the received packet from the terminal device, transfers the packet to the MAC address authentication processing unit or the Web authentication processing unit depending on the correspondence of the identified type of the packet and the authentication to be proceed in the database, and discards the packet when the identified type of the packet is not stored in the database.

12. A packet relay apparatus for being connected to a terminal device via a network, and for transmitting/receiving a packet, the packet relay apparatus comprising:

a MAC address authentication processing unit for performing MAC address authentication using a source MAC address included in a packet received from the terminal device;

an IEEE802.1X authentication processing unit for processing IEEE802.1X authentication;

an unauthenticated packet processing unit for transferring a packet from an unauthenticated terminal to one of the MAC address authentication processing unit and the IEEE802.1X authentication processing unit; and

a database for correspondingly storing packet types and authentication to be processed;

wherein said unauthenticated packet processing unit identifies a type of the packet depending on at least one field of layer 2 header, layer 3 header or layer 4 header, or the combination of the fields of the received packet from the terminal device, transfers the packet to the MAC address authentication processing unit or the IEEE802.1X authentication processing unit depending on the correspondence of the identified type of the packet and the authentication to be processed in the database, and discards the packet when the identified type of the packet is not stored in the database.

Assignments (3)
CHANGE OF ADDRESS Recorded Jul 22, 2026
From: ALAXALA NETWORKS CORPORATION
To: ALAXALA NETWORKS CORPORATION
Reel/Frame 076028/0706 →
NUNC PRO TUNC ASSIGNMENT Recorded Jul 22, 2026
From: ALAXALA NETWORKS CORPORATION
To: FORTINET, INC.
Reel/Frame 076028/0721 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2008
From: NOMI, MOTOHIDE
To: ALAXALA NETWORKS CORPORATION
Reel/Frame 021565/0001 →
Priority Claims (1)
JP 2007-306238 · Nov 27, 2007 · national
Continuity (1)
Related Publication 20090183252A1 · Jul 16, 2009