IP Library Granted Patent US 9,824,193
Granted Patent B2
US 9,824,193 · App. 14/445,306 · Granted Nov 21, 2017

Method for using mobile devices with validated user network identity as physical identity proof

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,824,193
App. No.
14/445,306
Granted
Nov 21, 2017
Kind
B2
Abstract

The present disclosure discloses a method and network device for using mobile devices with validated user network identity as physical identity proof. Responsive to successfully authenticating a client device for network access, a system generates a network credential for the client device and transmits the network credential to the client device. Further, the system detects that the client device is within a range of a short range wireless device that is associated with a particular physical action. Consequently, the system validates the network credential that the client device possesses. Based on the network credential, the system determines that the client device has permissions for performing the particular physical action, and causes performance of the particular physical action.

Claims (45)

1. A system comprising:

a network access control server on a wireless local area network (WLAN), the network access control server to:

verify an identity of a user of a client device including a hardware processor against an identity in an identity store to authenticate the client device;

responsive to successful identification of the client device for network access to the WLAN:

generate a network credential including a user certificate employable by the client device to connect to a service set identifier (SSID) of the WLAN;

transmit the network credential to the client device, wherein transmitting the network credential includes installing the user certificate on the client device;

transmit a first message identifying a particular physical action associated with a short range wireless device to the client device, wherein the short range wireless device is within range of the client device;

receive a second message from the client device comprising a request to perform the particular physical action and the network credential, wherein the network credential includes the user certificate;

based on the network credential, determine that the client device has permissions to perform the particular physical action, wherein the network credential is a same network credential that is provided to the client device after successful authentication for network access; and

transmit a third message to the client device, wherein the third message indicates that the client device is granted access to the particular physical action.

2. The system of claim 1 , wherein the particular physical action is an opening of an entryway for a user of the client device.

3. The system of claim 1 , wherein the particular physical action is a distribution of a product for use by a user of the client device.

4. The system of claim 1 , wherein transmitting the first message causes execution of an application on the client device that transmits the second message.

5. The system of claim 1 , wherein determining that the client device has permissions comprises:

identifying the client device based on the network credential; and

determining that the client device is authorized for causing performance of the particular physical action.

6. The system of claim 1 , further comprising the system to transmit an authentication token to the client device in response to the determination that the client device has permission to perform the particular physical action, wherein the particular physical action is performed by an access control device that receives the authentication token from the client device.

7. A non-transitory computer readable medium comprising instructions executable by a hardware processor to:

verify an identity of a user of a client device against an identity in an identity store to authenticate the client device;

responsive to successful authentication of the client device for network access to a wireless local area network (WLAN):

generate, at an access control server, a network credential including a user certificate employable by the client device to connect to a service set identifier (SSID) of the WLAN;

transmit the network credential to the client device, wherein transmitting the network credential to the client device includes installing the user certificate on the client device;

authenticate the client device using the network credential including the user certificate from the client device;

based on the network credential, determine that the client device has permissions for performing a particular physical action associated with a short range wireless device, wherein the network credential is a same network credential that is provided to the client device after successful authentication for network access;

transmit a third message to the client device, wherein the third message indicates that the client device is granted access to the particular physical action; and

perform the particular physical action in response to receipt of the third message.

8. The medium of claim 7 , wherein the particular physical action is an opening of an entryway for a user of the client device.

9. The medium of claim 7 , wherein the particular physical action is a distribution of a product for use by a user of the client device.

10. The medium of claim 7 , wherein determining that the client device has permissions comprises:

identifying the client device based on the network credential; and

determining that the client device is authorized for causing performance of the particular physical action.

11. The medium of claim 7 , wherein authenticating further comprises initiating a network authentication procedure, and wherein the network authentication procedure comprises an Extensible Authentication Protocol (EAP).

12. The medium of claim 7 , wherein the particular physical action is performed by an access control device that receives an access-accept message from a network access control server.

13. A system comprising:

a network access control server on a wireless local area network (WLAN), the network access control server to:

verify an identify of a user of a client device including a hardware processor against an identity in an identity store to authenticate the client device;

responsive to successful identification of a client device for network access, generate a network credential including a user certificate employable by the client device to connect to a service set identifier (SSID) of the WLAN and transmitting the network credential to the client device;

validate the network credentials that are processed by the client device;

based on the network credential including the user certificate, determine that the client device has permissions to perform a particular physical action associated with a short range wireless device, wherein the network credential is a same network credential that is provided to the client device after successful authentication for network access;

transmit a third message to the client device, wherein the third message indicates that the client device is granted access to the particular physical action; and

perform the particular physical action in response to receipt of the third message.

14. The system of claim 13 , wherein the client device performs the particular physical action.

15. The system of claim 13 , wherein:

a network access control device performs the particular physical action; and

the network access control device has no access to the internet.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2018
From: ARUBA NETWORKS, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 045921/0055 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: ARUBA NETWORKS, INC.
Reel/Frame 036379/0274 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2015
From: ARUBA NETWORKS, INC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 035814/0518 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2014
From: GANAPATHY ACHARI, RAJESH KUMAR; NAIR, ANOOP KUMARAN; RAMACHANDRAN, VENKATESH; VENKATANARANAPPA, VENKATRAJU
To: ARUBA NETWORKS INC.
Reel/Frame 033435/0517 →