IP Library Granted Patent US 8,681,800
Granted Patent B2
US 8,681,800 · App. 13/461,519 · Granted Mar 25, 2014

System, method and apparatus for providing multiple access modes in a data communications network

Inventor: Philip Kwan (San Jose, CA)
Assignee: Foundry Networks, LLC
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,681,800
App. No.
13/461,519
Granted
Mar 25, 2014
Kind
B2
Abstract

A system, method and apparatus for providing multiple access modes in a data communications network includes a network access device having a plurality of input ports, a plurality of output ports, and a switching fabric for routing data received on the plurality of input ports to at least one of the plurality of output ports. Control logic within the network access device is adapted to determine whether a user device coupled to one of the plurality of input ports supports a user authentication protocol used by a host network. If the user authentication protocol is not supported, then the input port to which the network access device is coupled is placed in a semi-authorized access state that limits access to a pre-configured network accessible via the host network.

Claims (46)

1. A method comprising:

at a network access device communicably coupled to a network,

sensing a user device coupled to a port of the network access device;

if authentication of a physical address of the user device is successful, determining if the user device supports a protocol used by the network to validate the identity of a user of the user device;

if the user device supports the protocol, validating the identity of the user according to the protocol; and

providing the user device with limited network access if the user device does not support the protocol.

2. The method of claim 1 , wherein the limited network access limits access by the user device to a network, the network selected from the group comprising a Voice over Internet Protocol (VoIP) network, the Internet, and a low security virtual local area network (VLAN).

3. The method of claim 1 , wherein the placing comprises selectively placing the port into one of a plurality of semi-authorized access states.

4. The method of claim 3 , wherein the placing comprises:

determining a type of the user device; and

selectively placing the port into one of a plurality of semi-authorized access states based on the type of the user device.

5. The method of claim 4 , wherein the selectively placing comprises selectively placing the port into a semi-authorized access state that limits access by the user device to a network comprising a Voice over Internet Protocol (VoIP) network.

6. The method of claim 4 , wherein the selectively placing comprises selectively placing the port into a semi-authorized access state that limits access by the user device to a network comprising the Internet if the user device is a portable computing device.

7. The method of claim 1 , wherein the protocol is IEEE 802.1x.

8. The method of claim 1 , wherein the network access device comprises a network switch.

9. A network access device comprising:

a switching fabric for routing data received on one or more of input ports of the device to one or more output ports of the device; and

control logic configured to:

sense a user device coupled to a port of the network access device;

if authentication of a physical address of the user device is successful, determine:

if the user device supports a protocol used by the network to validate the identity of a user of the user device;

if the user device supports the protocol, validate the identity of the user according to the protocol; and

provide the user device with limited network access if the user device does not support the protocol.

10. The device of claim 9 , wherein the limited network access limits access by the user device to a network, the network selected from the group comprising a Voice over Internet Protocol (VoIP) network, the Internet, and a low security virtual local area network (VLAN).

11. The device of claim 9 , wherein the control logic is configured to selectively place the one of the input ports into one of a plurality of semi-authorized access states.

12. The device of claim 11 , wherein the control logic is configured to determine a type of the user device and to selectively place the one of the input ports into one of a plurality of semi-authorized access states based on the type of the user device.

13. The device of claim 12 , wherein the control logic is configured to selectively place the one of the input ports into a semi-authorized access state that limits access by the user device to a network comprising a Voice over Internet Protocol (VoIP) network.

14. The device of claim 12 , wherein the control logic is configured to selectively place the one of the input ports into a semi-authorized access state that limits access by the user device to a network comprising the Internet if the user device is a portable computing device.

15. The device of claim 9 , wherein the protocol is IEEE 802.1x.

16. A method comprising:

at a network access device communicably coupled to a network, sensing a user device coupled to a port of the network access device;

authenticating a physical address of the user device;

if authentication of the physical address is successful, allowing the user device limited access to a network via the network access device if it is determined that the user device is unable to communicate using a particular user authentication protocol, the user authentication protocol comprising a protocol to validate the identity of a user of the user device; and

if the user device supports the user authentication protocol, validating, by the network access device, the identity of the user according to the user authentication protocol.

17. The method of claim 16 wherein the limited access comprises less access than access afforded a user device that is successfully authenticated using the user authentication protocol.

18. The method of claim 17 wherein the limited access comprises access to a low-security Virtual Local Area Network (VLAN).

19. A network access device comprising:

a memory;

a switching fabric configured to route data received on one or more input ports of the device to one or more output ports of the device; and

control logic configured to:

sense a user device coupled to a port of the network access device;

authenticate a physical address of the user device;

if authentication of the physical address is successful, allow the user device limited access to a network via the network access device if it is determined that the user device is unable to communicate using a particular user authentication protocol, the user authentication protocol comprising a protocol to validate the identity of a user of the user device; and

if the user device supports the user authentication protocol, validate, by the network access device, the identity of the user according to the user authentication protocol.

20. The network access device of claim 19 wherein the limited access comprises less access than access afforded a user device that is successfully authenticated using the user authentication protocol.

21. The network access device of claim 20 wherein the limited access comprises access to a low-security Virtual Local Area Network (VLAN).

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2018
From: BROCADE COMMUNICATIONS SYSTEMS LLC
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047270/0247 →
CHANGE OF NAME Recorded Mar 8, 2013
From: FOUNDRY NETWORKS, INC.
To: FOUNDRY NETWORKS, LLC
Reel/Frame 029956/0602 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2012
From: KWAN, PHILIP
To: FOUNDRY NETWORKS, INC.
Reel/Frame 028832/0736 →
Continuity (3)
Continuation 12869602 · Aug 26, 2010
Continuation 10631898 · Aug 1, 2003
Related Publication 20120216256A1 · Aug 23, 2012