IP Library Granted Patent US 8,176,543
Granted Patent B2
US 8,176,543 · App. 12/640,195 · Granted May 8, 2012

Enabling network communication from role based authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,176,543
App. No.
12/640,195
Granted
May 8, 2012
Kind
B2
Abstract

Network communications are secured on clients that do not have a user properly logged in and authenticated. The clients have transmit and/or receive functionality disabled. When a user logs into the client and is properly authenticated, the transmit and/or receive functionality is enabled. In some embodiments, the client can then download firewall policy information to prevent the client from communicating on certain ports or with certain clients. The firewall policy information may be specific to a role that a user logged into the client has. For example, administrators, executives and employee roles may each use different firewall policy information.

Claims (19)

1. A network interface device for use in a host computer on a network, the network device comprising:

a network port adapted to send and receive network information for the host computer; and

a module that disables at least one of transmit and receive functionality to the network port of the network interface device until the network interface device is notified that a user of the host computer has been authenticated.

2. The network interface device of claim 1 , further comprising a firewall adapted to prevent the network interface device from communicating with other devices in the network according to firewall policy information stored at the firewall.

3. The network interface device of claim 2 , further comprising nonvolatile memory, and wherein the firewall policy information is stored in the nonvolatile memory.

4. The network interface device of claim 2 , wherein the network interface device is adapted to receive firewall policy information from a firewall policy server.

5. The network interface device of claim 1 , wherein the network interface device is embodied as a network interface card.

6. The network interface device of claim 5 , wherein the network interface device is embodied as a Secure CardBus network card.

7. A non-transitory computer readable medium storing programmable code which, when executed by a processor, secures a network interface device of a host computer, the code comprises instructions to:

initialize the network interface device such that at least one of the transmit and receive functionality of the network interface device is disabled;

receive, at the network interface device, a notification that a user of the host computer has been authenticated; and

in response to the notification, enable the at least one of the transmit and receive functionality of the network interface device.

8. The non-transitory computer readable medium of claim 7 , wherein the code further comprises instructions to:

download firewall policy information from a firewall policy server to the network interface device, after enabling at least one of the transmit and receive functionality of the network interface device.

9. The non-transitory computer readable medium of claim 8 , wherein the code further comprises instructions to:

store the downloaded firewall policy information in a nonvolatile memory.

10. The non-transitory computer readable medium of claim 8 , wherein the notification that the user of the host computer has been authenticated includes a notification that the authenticated user is associated with a role, and wherein the instructions to download the firewall policy information from the firewall policy server comprise instructions to download firewall policy information for the role.

11. The non-transitory computer readable medium of claim 7 , wherein the network interface device is embodied as a network interface card.

12. The non-transitory computer readable medium of claim 11 , wherein the network interface device is embodied as a Secure CardBus network card.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2021
From: OT PATENT ESCROW, LLC
To: VALTRUS INNOVATIONS LIMITED
Reel/Frame 057650/0537 →
PATENT ASSIGNMENT, SECURITY INTEREST, AND LIEN AGREEMENT Recorded Jan 26, 2021
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP; HEWLETT PACKARD ENTERPRISE COMPANY
To: OT PATENT ESCROW, LLC
Reel/Frame 055269/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
CORRECTIVE ASSIGNMENT PREVIUOSLY RECORDED ON REEL 027329 FRAME 0001 AND 0044. Recorded May 1, 2012
From: HEWLETT-PACKARD COMPANY
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 028911/0846 →