IP Library Granted Patent US 9,794,265
Granted Patent B1
US 9,794,265 · App. 14/658,356 · Granted Oct 17, 2017

Authentication and authorization without the use of supplicants

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,794,265
App. No.
14/658,356
Granted
Oct 17, 2017
Kind
B1
Abstract

Provided is authentication and authorization without the use of supplicants. Authentication and authorization includes generating a profile for a device based on at least one characteristic observed during a successful attempt by the device to access an 802.1X network infrastructure. Expected characteristics for a next attempt to access the infrastructure by the device are determined. A characteristic of the next access attempt is matched to the expected characteristic and access to the network is selectively controlled as a result of the matching. This is achieved without a supplicant being installed on the device.

Claims (37)

1. A system, comprising:

a processor that executes the following computer executable components stored in a memory:

an identification manager component that generates profile data for a device based on the device being authorized to access a secure network and in response to a first authentication request, and

wherein the profile data includes at least data specific to a verifying user identity associated with an acceptance of the first authentication request;

an evaluation component that determines an expected characteristic of a second authentication request by the device to access the secure network prior to receipt of the second authentication request, the expected characteristic is a prediction of a characteristic of the second authentication request,

wherein the evaluation component combines the profile data with other profile data to predict a port connection for the second authentication request; and

a validation component that, in response to the receipt of the second authentication request compares the characteristic of the second authentication request to the expected characteristic and, based on the comparison, controls access to the secure network, wherein a supplicant is not deployed on the device,

wherein the validation component automatically authenticates the device with the secure network based on a determination that the characteristic of the second authentication request matches the expected characteristic, and

wherein the validation component automatically denies the device access to the secure network based on a determination that the characteristic of the second authentication request does not match the expected characteristic.

2. The system of claim 1 , wherein the validation component requests additional information from the device based on a determination that the characteristic of the second authentication request does not match the expected characteristic.

3. The system of claim 2 , wherein the additional information comprises a reauthentication to a port.

4. The system of claim 1 , wherein the validation component requests an authentication of the device based on a detected state change between the device and the secure network, wherein the request is the second authentication request.

5. The system of claim 1 , wherein the identification manager component generates the profile data based on usage characteristics of the device, and wherein the usage characteristics comprise a location.

6. The system of claim 1 , wherein the identification manager component generates the profile data based on usage characteristics of the device, and wherein the usage characteristics comprise an Internet protocol address.

7. The system of claim 1 , wherein the identification manager component generates the profile data based on usage characteristics of the device, and wherein the usage characteristics comprise a device type.

8. The system of claim 1 , wherein the identification manager component generates the profile data based on usage characteristics of the device, and wherein the usage characteristics comprise an access history for the device.

9. A method, comprising:

generating, by a system comprising a processor, a profile for an endpoint based on a characteristic observed during a successful attempt by the endpoint to access a protected communications network,

wherein the successful attempt is in response to a first authentication request, and,

wherein the profile includes at least data specific to a verifying user identity associated with an acceptance of the first authentication request, and

wherein a supplicant is not deployed on the endpoint;

determining, by the system, an expected characteristic for another attempt by the endpoint to access the protected communications network, the other attempt is a future attempt, and the expected characteristic is a prediction of a characteristic of the other authentication request, wherein the determining includes combining profile data with other profile data to predict a port connection for the second authentication request;

comparing, by the system, a characteristic of the other attempt by the endpoint to access the protected communications network with the expected characteristic; and

selectively controlling, by the system, access to the protected communications network by the endpoint as a result of the comparing,

wherein the selectively controlling access comprises automatically granting access based on a determination that the characteristic of the other attempt matches the expected characteristic, and

wherein the selectively controlling access comprises automatically denying access based on a determination that the characteristic of the other access attempt does not match the expected characteristic.

10. The method of claim 9 , wherein the observed characteristic and the expected characteristic are a same characteristic.

11. The method of claim 9 , wherein the observed characteristic and the expected characteristic are different characteristics.

12. The method of claim 9 , further comprising generating layer-2 802.1 X extensible authentication protocol responses and requests in place of the supplicant.

13. A computer-readable storage device storing executable instructions that, in response to execution, cause a system comprising a processor to perform operations, comprising:

generating profile data for a device based on the device being authorized to access a secure network in response to a first authentication request, and

wherein the profile data includes at least data specific to a verifying user identity associated with an acceptance of the first authentication request;

determining an expected characteristic of a second authentication request by the device to access the secure network, the expected characteristic is a prediction of a characteristic of the second authentication request, wherein the determining includes combining the profile data with other profile data to predict a port connection for the second authentication request;

after receipt of the second authentication request, comparing the characteristic of the second authentication request to the expected characteristic; and

controlling access to the secure network based on the comparison, wherein a supplicant is not deployed on the device, wherein controlling access includes:

upon a determination that the characteristic of the second authentication request matches the expected characteristic, automatically authenticating the device with the secure network, and

upon a determination that the characteristic of the second authentication request does not match the expected characteristic, automatically denying the device access to the secure network.

Assignments (2)
ADDRESS CHANGE Recorded Jun 2, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071769/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2016
From: BENSKIN, RYAN B.; BELTON, LAWRENCE T., JR.; HOUSER, CHRISTOPHER; MAKOHON, PETER A.; MORRIS, TIMOTHY; BRACEY, OMAR
To: WELLS FARGO BANK, N.A.
Reel/Frame 037953/0133 →