IP Library Granted Patent US 9,825,936
Granted Patent B2
US 9,825,936 · App. 14/637,381 · Granted Nov 21, 2017

System and method for providing a certificate for network access

Inventors: Kevin Lee Koster (Westminster, CO); Roger Lynn Haney (Denver, CO)
H04L63/0823G06F21/00G06F21/33G06F21/34G06F21/51H04L9/3263H04L63/0815H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,825,936
App. No.
14/637,381
Filed
Mar 3, 2015
Granted
Nov 21, 2017
Kind
B2
Art Unit
2439
USPC
726/10
Abstract

Provided is a system and method for providing a certificate, and more specifically a certificate for network access upon a second system. The method includes, identifying a first system having at least one processor and a plurality of users, each user having at least one attribute; receiving from a third party at least one required attribute for certificate based network access; receiving from a user known to the first system a request for certificate based network layer network access to a second system having at least one processor, the request having at least one identifier; querying the first system with the at least one identifier for attributes associated with the user requesting the certificate based network layer network access to a second system; evaluating the attributes associated with the user requesting the certificate to the at least one predefined attribute; and in response to at least one attribute associated with the user requesting the certificate correlating to the at least one predefined attribute, providing from a system other than the first system, as requested by the user a certificate with at least one characteristic for certificate based network layer network access on the second system, the second system distinct from the first system. An associated system for providing a Certificate is also provided.

Claims (73)

1. A method of providing a certificate for based secured wireless network layer access in response to a user request comprising:

identifying a first system having at least one processor and a plurality of users, each user having at least one attribute;

receiving from a third party at least one predefined required attribute for secured network layer access upon a second system providing a secured wireless network, the secured wireless network requiring a Public Key Infrastructure (“PKI”) certificate for network layer authentication to the wireless network;

receiving from a user known to the first system a request for certificate based network layer network access to a second system having at least one processor, the request having at least one identifier;

querying the first system with the at least one identifier for attributes associated with the user requesting the certificate based network layer network access to a second system;

evaluating the attributes associated with the user requesting the certificate to the least one predefined required attribute for the PKI certificate in order to access the second system; and

in response to at least one attribute associated with the user requesting the PKI certificate correlating to the at least one predefined required attribute, providing the requesting user with a PKI certificate with at least one characteristic for certificate based network layer authentication for network layer access to the secured wireless network of the secured second system, the second system distinct from the first, the PKI certificate provided from a system other than the first system;

wherein a first user having a first set of correlating attributes is provided with a PKI certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlated attribute.

2. The method of claim 1 , wherein the network layer network access is OSI Layer 2-3 access.

3. The method of claim 1 , wherein network access to the second system is established based upon the PKI certificate before an application layer may request a user name and password.

4. The method of claim 1 , wherein without a PKI certificate the user cannot establish network access with the second system.

5. The method of claim 1 , wherein the at least one predefined required attribute is user information.

6. The method of claim 5 , wherein the user information is selected from the group consisting of: username, email address, city, state, gender, age, relationship status.

7. The method of claim 1 , wherein the predefined required attribute is specified by the second system.

8. The method of claim 1 , wherein the PKI certificate is an X.509 certificate.

9. The method of claim 1 , wherein the at least one characteristic of the PKI certificate is selected from a group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

10. A method of providing a certificate for certificate based secured wireless network layer access in response to a user request comprising:

identifying a first system having at least one processor and a plurality of users, each user having at least one attribute;

receiving from a third party at least one predefined required attribute for secured network layer access upon a second system providing a secured wireless network, the secured wireless network requiring a Public Key Infrastructure (“PKI”) certificate for network layer authentication to the wireless network;

receiving from a user known to the first system a request for OSI Layer 2-3 network access to a second system having at least one processor and distinct from the first system, the request having at least one identifier;

querying the first system with the at least one identifier for attributes associated with the user requesting the certificate based network layer network access to a second system;

evaluating the attributes associated with the user requesting the certificate to the at least one predefined required attribute for the PKI certificate in order to access the second system; and

in response to at least one attribute associated with the user requesting the PKI certificate correlating to the at least one predefined required attribute, providing the requesting user with a PKI certificate with at least one characteristic for certificate based network layer authentication for network OSI Layer 2-3 access to the secured wireless network of the secured second system, the second system distinct form from the first, the PKI certificate provided from a system other than the first system;

wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlated attribute.

11. The method of claim 10 , wherein network access to the second system is established based upon the PKI certificate before an application layer may request a user name and password.

12. The method of claim 10 , wherein without a PKI certificate the user cannot establish network access with the second system.

13. The method of claim 10 , wherein the at least one predefined required attribute is user information.

14. The method of claim 10 , wherein the user information is selected from the group consisting of: username, email address, city, state, gender, age, relationship status.

15. The method of claim 10 , wherein the predefined required attribute is specified by the second system.

16. The method of claim 10 , wherein the PKI certificate is an X.509 certificate.

17. The method of claim 10 , wherein the at least one characteristic of the PKI certificate is selected from a group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

18. A non-transitory machine readable medium on which is stored a computer program for providing a certificate for based secured wireless network layer access in response to a user request for network access, the computer program comprising instructions which when executed by a computer system having at least one processor performs the steps of:

identifying a first system having at least one processor and a plurality of users, each user having at least one attribute;

receiving from a third party at least one predefined required attribute for secured network layer access upon a second system providing a secured wireless network, the secured wireless network requiring a Public Key Infrastructure (“PKI”) certificate for network layer authentication to the wireless network;

receiving from a user known to the first system a request for certificate based network layer network access to a second system having at least one processor, the request having at least one identifier;

querying the first system with the at least one identifier for attributes associated with the user requesting the certificate based network layer network access to a second system;

evaluating the attributes associated with the user requesting the certificate to the least one predefined required attribute for the PKI certificate in order to access the second system; and

in response to at least one attribute associated with the user requesting the PKI certificate correlating to the at least one predefined required attribute, providing the requesting user with a PKI certificate with at least one characteristic for certificate based network layer authentication for network layer access to the secured wireless network of the secured second system, the second system distinct from the first, the PKI certificate provided from a system other than the first system;

wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlated attribute.

19. The non-transitory machine readable medium of claim 18 , wherein the network layer network access is OSI Layer 2-3 access.

20. The non-transitory machine readable medium of claim 18 , wherein network access to the second system is established based upon the PKI certificate before an application layer may request a user name and password.

21. The non-transitory machine readable medium of claim 18 , wherein without a PKI certificate the user cannot establish network access with the second system.

22. The non-transitory machine readable medium of claim 18 , wherein the at least one predefined required attribute is user information.

23. The non-transitory machine readable medium of claim 18 , wherein the user information is selected from the group consisting of: username, email address, city, state, gender, age, relationship status.

24. The non-transitory machine readable medium of claim 18 , wherein the predefined required attribute is specified by the second system.

25. The non-transitory machine readable medium of claim 18 , wherein the PKI certificate is an X.509 certificate.

26. The non-transitory machine readable medium of claim 18 , wherein the at least one characteristic of the PKI certificate is selected from a group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

27. A non-transitory machine readable medium on which is stored a computer program comprising instructions to adapt a computer system having a processor to provide a certificate for certificate based secured wireless network layer access in response to a user request for network access, the computer program comprising:

an input routine operative associated with an input device for receiving from a third party at least one predefined required attribute as criteria for receiving a Public Key Infrastructure (“PKI”) certificate for secured network layer access upon a second system providing a secured wireless network, the secured wireless network requiring a PKI certificate for network layer authentication to the wireless network, and for receiving from a user authenticated to a first system a request for certificate based OSI Layer 2-3 wireless network access to a second system distinct from the first system, the request having at least one identifier;

a query routine for querying the first system with the at least one identifier for attributes associated with the user requesting the certificate based secured wireless network access and evaluating the associated attributers to the predefined required attribute for the PKI certificate in order to access the second system, the querying performed by other than one of the user requesting the PKI certificate; and

an output routine for providing the requesting user with a PKI certificate with at least one characteristic for certificate based network layer authentication for network OSI Layer 2-3 access to the secured wireless network of the secured second system, the second system distinct from the first, the PKI certificate provided from a system other than the first system;

wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlated attribute.

28. The non-transitory machine readable medium of claim 27 , wherein the network layer network access is OSI Layer 2-3 access.

29. The non-transitory machine readable medium of claim 27 , wherein network access to the second system is established based upon the PKI certificate before an application layer may request a user name and password.

30. The non-transitory machine readable medium of claim 27 , wherein without a PKI certificate the user cannot establish network access with the second system.

31. The non-transitory machine readable medium of claim 27 , wherein the at least one predefined required attribute is user information.

32. The non-transitory machine readable medium of claim 27 , wherein the user information is selected from the group consisting of: username, email address, city, state, gender, age, relationship status.

33. The non-transitory machine readable medium of claim 27 , wherein the predefined required attribute is specified by the second system.

34. The non-transitory machine readable medium of claim 27 , wherein the PKI certificate is an X.509 certificate.

35. The non-transitory machine readable medium of claim 27 , wherein the at least one characteristic of the PKI certificate is selected from a group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

36. A system for providing a certificate for based secured wireless network layer access in response to a third party request comprising:

a first system having at least one processor structured and arranged as a single sign on system having a plurality of user accounts corresponding to a plurality of users remote from the first system;

a third party structured and arranged to establish at least one predefined required attribute for receiving a Public Key Infrastructure (“PKI”) certificate permitting secured network layer access upon a second system providing a secured wireless network, the secured wireless network requiring a PKI certificate for network layer authentication to the wireless network, the second system having at least one processor, the second system distinct from the first system; and

an authorizing system structured and arranged to receive from the third party the at least one predefined required attribute for the PKI certificate in order to access the second system, and in response to a request from a user of the first system for a PKI certificate for certificate based network access to the second system the authorizing system further structured and arranged to access the first system to query the remote user accounts for attributes associated with at least one user, the authorizing system providing a PKI certificate with at least one characteristic derived from the attributes associated with the requesting user for certificate based network layer authentication to the secured wireless network of the secured second system to at least one requesting user having at least one attribute associated with the requesting user correlated to the at least one predefined required attribute;

wherein a first user having a first set of correlating attributes is provided with a certificate permitting different access than a second user having a second set of correlating attributes, the first and second sets being different with respect to at least one correlated attribute.

37. The system of claim 36 , wherein the network layer network access is OSI Layer 2-3 access.

38. The system of claim 36 , wherein network access to the second system is established based upon the PKI certificate before an application layer may request a user name and password.

39. The system of claim 36 , wherein without a PKI certificate the user cannot establish network access with the second system.

40. The system of claim 36 , wherein the at least one predefined required attribute is user information.

41. The system of claim 36 , wherein the user information is selected from the group consisting of: username, email address, city, state, gender, age, relationship status.

42. The system of claim 36 , wherein the predefined required attribute is specified by the second system.

43. The system of claim 36 , wherein the PKI certificate is an X.509 certificate.

44. The system of claim 36 , wherein the at least one characteristic of the PKI certificate is selected from a group consisting of root certificate authority, intermediate certificate authority, time period, common name, subject name, subject's alternative name.

Assignments (14)
PARTIAL TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jul 2, 2026
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 075892/0107 →
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 8, 2019
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: RUCKUS WIRELESS, INC.
Reel/Frame 048817/0832 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2018
From: RUCKUS WIRELESS, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 046730/0854 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2018
From: RUCKUS WIRELESS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 046379/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2016
From: CLOUDPATH NETWORKS, INC.
To: RUCKUS WIRELESS, INC.
Reel/Frame 037679/0278 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2015
From: KOSTER, KEVIN LEE; HANEY, ROGER LYNN
To: CLOUDPATH NETWORKS, INC.
Reel/Frame 035080/0452 →
Continuity (3)
Continuation In Part 13454737 · Apr 24, 2012
Provisional Application 61614990 · Mar 23, 2012
Related Publication 20160261587A1 · Sep 8, 2016