IP Library Granted Patent US 9,894,070
Granted Patent B2
US 9,894,070 · App. 14/507,292 · Granted Feb 13, 2018

Method and system for controlling access to shared devices

Inventors: Edward Vajravelu (Bangalore, IN); Arun R Kumar (Bangalore, IN); Ashish Vyas (Bangalore, IN); Ramalingeswara Reddy Onteddu (Bangalore, IN); Varun Shah (Sunnyvale, CA)
Assignee: ARUBA NETWORKS, INC.
H04L63/10H04L63/101H04L67/10H04L69/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,894,070
App. No.
14/507,292
Granted
Feb 13, 2018
Kind
B2
Abstract

A non-transitory computer readable medium includes computer readable program code including instructions for snooping a message from a client device addressed to a particular IP address corresponding to a shared device; determining whether the client device has authorization to access the shared device; responsive to determining that the client device does not have authorization to access the shared device, refraining from forwarding the message to the particular IP address; and responsive to determining that the client device has authorization to access the shared device, forwarding the message to the particular IP address.

Claims (45)

1. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, causes performance of operations comprising:

snooping, by a network device, a message sent from a client device and addressed to a particular IP address corresponding to a shared device while the message is being transmitted to the shared device, wherein the message is not addressed to the network device;

determining, by the network device, whether the client device is allowed to access the shared device based on the particular IP address;

responsive to determining that the client device is not allowed to access the shared device, refraining from forwarding the message to the particular IP address;

responsive to determining that the client device is allowed to access the shared device, forwarding the message to the particular IP address.

2. The medium of claim 1 , wherein refraining from forwarding the message to the particular IP address is further responsive to determining that the message comprises a request by the client device to open a connection with the shared device.

3. The medium of claim 1 , wherein the message comprises a Transmission Control Protocol (TCP) connection request.

4. The medium of claim 1 , wherein determining that the client device is not allowed to access the shared device comprises determining that the information corresponding to the shared device was not previously transmitted by the network device to the client device.

5. The medium of claim 1 , wherein determining that the client device is not allowed to access the shared device comprises determining that the particular IP address corresponding to the shared device was not previously transmitted by the network device to the client device.

6. The medium of claim 1 , wherein determining that the client device is allowed to access the shared device comprises determining that the information corresponding to the shared device was previously transmitted by the network device to the client device.

7. The medium of claim 1 , wherein determining whether the client device is allowed to access the shared device comprises checking whether the client device is listed in an access control list identifying devices that have access to the shared device.

8. The medium of claim 1 , wherein determining whether the client device is allowed to access the shared device comprises checking whether the shared device is listed in an access control list identifying devices that the client device is allowed to access.

9. A non-transitory computer readable medium comprising instructions which, when executed by one or more hardware processors, causes the one or more hardware processors to:

snoop, by a network device, a message sent from a client device and addressed to a particular IP address corresponding to a shared device while the message is being transmitted to the shared device, wherein the message is not addressed to the network device;

determine that the message comprises a request for functionality of the shared device based on the particular IP address;

responsive at least to a determination that the message comprises a request for functionality of the shared device:

refrain from forwarding the message to the particular IP address.

10. The medium of claim 9 , wherein the instructions are further to cause the one or more hardware processors to refrain from forwarding the message to the particular IP address responsive to a determination that the client device is not allowed to access the shared device.

11. The medium of claim 10 , wherein the instructions are further to cause the one or more hardware processors to determine that the client device is not allowed to access the shared device in response to a determination that the information corresponding to the shared device was not previously transmitted by the network device to the client device.

12. The medium of claim 10 , wherein the instructions are further to cause the one or more hardware processors to determine that the client device is not allowed to access the shared device in response to a determination that the client device is not listed in an access control list identifying devices that have access to the shared device.

13. The medium of claim 9 , wherein the instructions are further to cause the one or more hardware processors to:

responsive at least to a determination that the message comprises a request for functionality of the shared device:

instruct the client device to terminate a connection with the shared device.

14. The medium of claim 9 , wherein the instructions are further to cause the one or more hardware processors to:

responsive at least to a determination that the message comprises a request for functionality of the shared device:

transmit a message to the client device that spoofs the shared device and terminates a connection between the shared device and the client device.

15. The medium of claim 9 , wherein the instructions are further to cause the one or more hardware processors to:

responsive at least to a determination that the message comprises a request for functionality of the shared device:

determine whether the client device is allowed to access the shared device;

responsive to a determination that the client device is allowed to access the shared device:

transmit information to the client device that identifies the functionality of the shared device.

16. The medium of claim 9 , wherein the instructions are further to cause the one or more hardware processors to determine that the message comprises a request for functionality of the shared device in response to a determination that the message comprises one or more strings corresponding to a request for functionality of the shared device.

17. A system comprising:

a network device including a hardware processor;

a memory on which is stored instructions that are to cause the hardware processor to:

snoop a message sent from a client device and addressed to a particular IP address corresponding to a shared device while the message is being transmitted to the shared device, wherein the message is not addressed to the network device;

determine whether the client device is allowed to access the shared device based on the particular IP address;

responsive to a determination that the client device is not allowed to access the shared device, refrain from forwarding the message to the particular IP address; and

responsive to a determination that the client device is allowed to access the shared device, forward the message to the particular IP address.

18. The system of claim 17 , wherein the instructions are further to cause the hardware processor to determine whether the message comprises a request by the client device to open a connection with the shared device, and to refrain from forwarding the message to the particular IP address in response to a determination that the message comprises a request by the client device to open a connection with the shared device.

19. The system of claim 17 , wherein the message comprises a Transmission Control Protocol (TCP) connection request.

20. The system of claim 17 , wherein to determine that the client device is not allowed to access the shared device, the instructions are further to cause the hardware processor to determine that the information corresponding to the shared device was not previously transmitted by the network device to the client device.

21. The system of claim 17 , wherein to determine that the client device is not allowed to access the shared device, the instructions are further to cause the hardware processor to determine that the particular IP address corresponding to the shared device was not previously transmitted by the network device to the client device.

22. The system of claim 17 , wherein to determine that the client device is allowed to access the shared device, the instructions are further to cause the hardware processor to determine that the information corresponding to the shared device was previously transmitted by the network device to the client device.

23. The system of claim 17 , wherein to determine whether the client device is allowed to access the shared device, the instructions are further to cause the hardware processor to check whether the client device is listed in an access control list identifying devices that have access to the shared device.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2018
From: ARUBA NETWORKS, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 045921/0055 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2018
From: VAJRAVELU, EDWARD; KUMAR, ARUN R.; VYAS, ASHISH; ONTEDDU, RAMALINGESWARA REDDY; SHAH, VARUN
To: ARUBA NETWORKS, INC.
Reel/Frame 044742/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: ARUBA NETWORKS, INC.
Reel/Frame 036379/0274 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2015
From: ARUBA NETWORKS, INC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 035814/0518 →
Continuity (2)
Provisional Application 62042749 · Aug 27, 2014
Related Publication 20160065578A1 · Mar 3, 2016