IP Library Granted Patent US 8,793,782
Granted Patent B1
US 8,793,782 · App. 12/789,283 · Granted Jul 29, 2014

Enforcing a health policy in a local area network

Inventor: Jin Su (Sandy, UT)
Assignee: Crimson Corporation
H04L63/0807H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,793,782
App. No.
12/789,283
Granted
Jul 29, 2014
Kind
B1
Abstract

A method for injecting a security token into an authentication protocol response is disclosed. An authentication protocol response from a node requesting access to a network is intercepted. It is determined if the node complies with a health policy of the network. A security token is inserted into the authentication protocol response based on the compliance node.

Claims (84)

1. A method for injecting a security token into an authentication protocol response, comprising:

configuring at least one processor to perform the functions of:

intercepting the authentication protocol response sent from a node requesting access to a network after receiving, at said node, a request/identity message from an authenticator;

determining, at the node requesting access to the network, if the node complies with a health policy of the network;

inserting a security token by the access requesting node into the authentication protocol response based on the compliance of the node, wherein a value within the security token indicates whether the node complies with the health policy; and

forwarding said inserted authentication protocol response to the authenticator that restricts communications between the access requesting node and an authentication server in the network.

2. The method of claim 1 , wherein the inserting comprises unconditionally inserting the security token.

3. The method of claim 2 , further comprising allowing the node to unconditionally send the authentication protocol response with the security token to an authenticator.

4. The method of claim 1 , wherein the inserting comprises conditionally inserting the security token only if the node complies with the health policy.

5. The method of claim 4 , further comprising allowing the node to send the authentication protocol response to an authenticator only if the security token is inserted.

6. The method of claim 4 , further comprising terminating an authentication process if the node does not comply with the health policy.

7. The method of claim 1 , wherein the authentication protocol response is an Extensible Authentication Protocol (EAP) response.

8. A computing device that is configured for injecting a security token into an authentication protocol response, comprising:

a processor;

memory in electronic communication with the processor; instructions stored in the memory, the instructions being executable to:

intercept the authentication protocol response sent from a node requesting access to a network after receiving, at said node, a request/identity message from an authenticator;

determine, at the node requesting access to the network, if the node complies with a health policy of the network;

insert a security token by the access requesting node into the authentication protocol response based on the compliance of the node, wherein a value within the security token indicates whether the node complies with the health policy; and

forwarding said inserted authentication protocol response to the authenticator that restricts communications between the access requesting node and an authentication server in the network.

9. The computing device of claim 8 , wherein the instructions executable to insert comprise instructions executable to unconditionally insert the security token.

10. The computing device of claim 9 , further comprising instructions executable to allow the node to unconditionally send the authentication protocol response with the security token to an authenticator.

11. The computing device of claim 8 , wherein the instructions executable to insert comprise instructions executable to conditionally insert the security token only if the node complies with the health policy.

12. The computing device of claim 11 , further comprising instructions executable to allow the node to send the authentication protocol response to an authenticator only if the security token is inserted.

13. The computing device of claim 11 , further comprising instructions executable to terminate an authentication process if the node does not comply with the health policy.

14. The computing device of claim 8 , wherein the authentication protocol response is an Extensible Authentication Protocol (EAP) response.

15. A non-transitory tangible computer-readable medium for injecting a security token into an authentication protocol response comprising executable instructions for:

intercepting the authentication protocol response sent from a node requesting access to a network after receiving, at said node, a request/identity message from an authenticator;

determining, at the node requesting access to the network, if the node complies with a health policy of the network;

inserting a security token by the access requesting node into the authentication protocol response based on the compliance of the node, wherein a value within the security token indicates whether the node complies with the health policy; and

forwarding said inserted authentication protocol response to the authenticator that restricts communications between the access requesting node and an authentication server in the network.

16. The computer-readable medium of claim 15 , wherein the instructions for inserting comprise instructions for unconditionally inserting the security token.

17. The computer-readable medium of claim 16 , further comprising executable instructions for allowing the node to unconditionally send the authentication protocol response with the security token to an authenticator.

18. The computer-readable medium of claim 15 , wherein the instructions for inserting comprise instructions for conditionally inserting the security token only if the node complies with the health policy.

19. The computer-readable medium of claim 18 , further comprising executable instructions for allowing the node to send the authentication protocol response to an authenticator only if the security token is inserted.

20. The computer-readable medium of claim 18 , further comprising executable instructions for terminating an authentication process if the node does not comply with the health policy.

21. The computer-readable medium of claim 15 , wherein the authentication protocol response is an Extensible Authentication Protocol (EAP) response.

22. A method for forwarding an encapsulation protocol access request, comprising: configuring at least one processor to perform the functions of:

receiving at a proxy server the encapsulation protocol access request from an authenticator after the authenticator receives an authentication protocol response from a requesting node;

determining whether the access request includes a security token that indicates the requesting node has determined whether the requesting node complies with a health policy; and

forwarding the encapsulation protocol access request to an authentication server based on the determination.

23. The method of claim 22 , further comprising:

if a security token in the access request indicates that a requesting node complies:

forwarding the encapsulation protocol access request to the authentication server.

24. The method of claim 22 , further comprising:

if a security token is not included in the access request or a security token is included that indicates non-compliance of the requesting node:

generating an encapsulation protocol access reject message; and

sending the access reject message to the authenticator.

25. The method of claim 22 , further comprising:

receiving an encapsulation protocol access challenge from the authentication server; and

forwarding the access challenge to the authenticator.

26. The method of claim 22 , wherein the encapsulation protocol access request is a Remote Authentication Dial In User Service (RADIUS) Access-Request message.

27. A computing device that is configured for forwarding an encapsulation protocol access request, comprising:

a processor;

memory in electronic communication with the processor;

instructions stored in the memory, the instructions being executable to:

receive at a proxy server the encapsulation protocol access request from an authenticator after the authenticator receives an authentication protocol response from a requesting node;

determine whether the access request includes a security token that indicates the requesting node has determined whether the requesting node complies with a health policy; and

forward the encapsulation protocol access request to an authentication server based on the determination.

28. The computing device of claim 27 , further comprising instructions executable to:

if a security token in the access request indicates that a requesting node complies:

forward the encapsulation protocol access request to the authentication server.

29. The computing device of claim 27 , further comprising instructions executable to:

if a security token is not included in the access request or a security token is included that indicates non-compliance of the requesting node:

generate an encapsulation protocol access reject message; and

send the access reject message to the authenticator.

30. The computing device of claim 27 , further comprising instructions executable to:

receive an encapsulation protocol access challenge from the authentication server; and

forward the access challenge to the authenticator.

31. The computing device of claim 27 , wherein the encapsulation protocol access request is a Remote Authentication Dial In User Service (RADIUS) Access-Request message.

32. A non-transitory tangible computer-readable medium for forwarding an encapsulation protocol access request comprising executable instructions for:

receiving at a proxy server the encapsulation protocol access request from an authenticator after the authenticator receives an authentication protocol response from a requesting node;

determining whether the access request includes a security token that indicates the requesting node has determined whether the requesting node complies with a health policy; and

forwarding the encapsulation protocol access request to an authentication server based on the determination.

33. The computer-readable medium of claim 32 , further comprising executable instructions for:

if a security token in the access request indicates that a requesting node complies:

forwarding the encapsulation protocol access request to the authentication server.

34. The computer-readable medium of claim 32 , further comprising executable instructions for:

if a security token is not included in the access request or a security token is included that indicates non-compliance of the requesting node:

generating an encapsulation protocol access reject message; and

sending the access reject message to the authenticator.

35. The computer-readable medium of claim 32 , further comprising executable instructions for:

receiving an encapsulation protocol access challenge from the authentication server; and

forwarding the access challenge to the authenticator.

36. The computer-readable medium of claim 32 , wherein the encapsulation protocol access request is a Remote Authentication Dial In User Service (RADIUS) Access-Request message.

Assignments (27)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
RELEASE OF SECURITY INTEREST Recorded Jan 19, 2017
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: LANDESK SOFTWARE, INC.
Reel/Frame 041420/0244 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 031029/0849 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0307 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 032333/0637 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0037 →
NUNC PRO TUNC ASSIGNMENT Recorded Sep 21, 2016
From: LANDESK SOFTWARE, INC.
To: CRIMSON CORPORATION
Reel/Frame 039819/0845 →
SECURITY AGREEMENT Recorded Feb 25, 2014
From: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 032333/0637 →
SECURITY AGREEMENT Recorded Aug 16, 2013
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; CRIMSON ACQUISITION CORP.; LANDESKSOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 031029/0849 →
PATENT SECURITY AGREEMENT Recorded Jul 13, 2012
From: LANDESK SOFTWARE, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 028541/0782 →
RELEASE OF SECURITY INTEREST Recorded Jun 20, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC
To: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
Reel/Frame 028413/0913 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 29, 2012
From: D.E. SHAW DIRECT CAPITAL PORTFOLIOS, L.L.C., AS AGENT
To: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
Reel/Frame 027783/0491 →
PATENT SECURITY AGREEMENT Recorded Sep 30, 2010
From: LAN DESK SOFTWARE, INC.; CRIMSON CORPORATION
To: D. E. SHAW DIRECT CAPITAL PORTFOLIOS, L.L.C. AS AGENT
Reel/Frame 025095/0982 →
PATENT SECURITY AGREEMENT Recorded Sep 28, 2010
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; LANDESK SOFTWARE, INC.; CRIMSON ACQUISITION CORP.; CRIMSON CORPORATION
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 025056/0391 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2010
From: SU, JIN
To: LANDESK SOFTWARE, INC.
Reel/Frame 024517/0843 →