IP Library Granted Patent US 9,544,290
Granted Patent B2
US 9,544,290 · App. 14/810,356 · Granted Jan 10, 2017

Device authentication using proxy automatic configuration script requests

Inventor: Paul Michael Martini (San Diego, CA)
Assignee: iboss, Inc.
H04L63/08G06F21/44H04L67/02H04L67/10H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,544,290
App. No.
14/810,356
Granted
Jan 10, 2017
Kind
B2
Abstract

Methods and systems for performing device authentication using proxy automatic configuration script requests are described. One example method includes generating a unique key for a client device; configuring the client device to send a request for a proxy automatic configuration (PAC) script upon accessing a network, the request including the unique key; receiving, over a network, a request for the PAC script including a request key; and authenticating the client device on the network if the request key matches the client device's unique key.

Claims (52)

1. A computer-implemented method executed by a network management system including one or more processors, the method comprising:

generating, by the one or more processors of the network management system, a unique key for a first client device, wherein the unique key is a string of one or more alphanumeric characters;

receiving, by the network management system over a network, a first proxy automatic configuration (PAC) script request from the first client device, the first PAC script request including a uniform resource locator (URL), the URL including a request key, wherein the request key forms at least a portion of the URL, and wherein the first PAC script request is associated with a first source address;

determining that the request key matches the generated unique key for the client device;

in response to determining that the request key matches the generated unique key for the client device;

authenticating the client device on the network; and

associating, by the network management system, the first source address with the unique key;

receiving, by the network management system, over the network, a second PAC script request including a request key matching the unique key for the first client device;

determining that the second PAC script request is associated with a second source address different than the first source address; and

in response to determining that the second PAC script request is associated with the second source address different than the first source address, blocking, by the network management system, a second client associated with the second source address from accessing the network.

2. The method of claim 1 , further comprising:

determining that the client device is no longer associated with the first source address; and

de-authenticating the client device on the network upon determining that the client device is no longer associated with the first source address.

3. The method of claim 1 , wherein the PAC script request is received according to HyperText Transfer Protocol (HTTP).

4. The method of claim 1 , wherein the PAC script request is received according to HyperText Transfer Protocol Secure (HTTPS).

5. The method of claim 1 , further comprising after authenticating the client device, authenticating a user of the client device based on user-specific credentials associated with the user and different than the unique key.

6. The method of claim 1 , further comprising de-authenticating the client device on the network after a configured period of time.

7. A network management system comprising:

a computer storage device for storing computer program instructions; and

a processor coupled with the storage device to execute the computer program instructions to perform operations comprising:

generating, by the network management system, a unique key for a first client device, wherein the unique key is a string of one or more alphanumeric characters;

receiving, by the network management system over a network, a first proxy automatic configuration (PAC) script request from the first client device, the first PAC script request including a uniform resource locator (URL), the URL including a request key, wherein the request key forms at least a portion of the URL, and wherein the first PAC script request is associated with a first source address;

determining that the request key matches the generated unique key for the client device;

in response to determining that the request key matches the generated unique key for the client device;

authenticating the client device on the network; and

associating, by the network management system, the first source address with the unique key;

receiving, by the network management system, over the network, a second PAC script request including a request key matching the unique key for the first client device;

determining that the second PAC script request is associated with a second source address different than the first source address; and

in response to determining that the second PAC script request is associated with the second source address different than the first source address, blocking, by the network management system, a second client associated with the second source address from accessing the network.

8. The network management system of claim 7 , the operations further comprising:

determining that the client device is no longer associated with the first source address; and

de-authenticating the client device on the network upon determining that the client device is no longer associated with the first source address.

9. The network management system of claim 7 , wherein the PAC script request is received according to HyperText Transfer Protocol (HTTP).

10. The network management system of claim 7 , wherein the PAC script request is received according to HyperText Transfer Protocol Secure (HTTPS).

11. The network management system of claim 7 , the operations further comprising after authenticating the client device, authenticating a user of the client device based on user-specific credentials associated with the user and different than the unique key.

12. The network management system of claim 7 , further comprising de-authenticating the client device on the network after a configured period of time.

13. A non-transitory, computer-readable medium storing instructions operable when executed to cause at least one processor to perform operations comprising:

generating a unique key for a first client device, wherein the unique key is a string of one or more alphanumeric characters;

receiving, over a network, a first proxy automatic configuration (PAC) script request from the first client device, the first PAC script request including a uniform resource locator (URL), the URL including a request key, wherein the request key forms at least a portion of the URL, and wherein the first PAC script request is associated with a first source address;

determining that the request key matches the generated unique key for the client device;

in response to determining that the request key matches the generated unique key for the client device;

authenticating the client device on the network; and

associating the first source address with the unique key;

receiving, over the network, a second PAC script request including a request key matching the unique key for the first client device;

determining that the second PAC script request is associated with a second source address different than the first source address; and

in response to determining that the second PAC script request is associated with the second source address different than the first source address, blocking a second client associated with the second source address from accessing the network.

14. The computer-readable medium of claim 13 , the operations further comprising:

determining that the client device is no longer associated with the first source address; and

de-authenticating the client device on the network upon determining that the client device is no longer associated with the first source address.

15. The computer-readable medium of claim 13 , wherein the PAC script request is received according to HyperText Transfer Protocol (HTTP).

16. The computer-readable medium of claim 13 , wherein the PAC script request is received according to HyperText Transfer Protocol Secure (HTTPS).

17. The computer-readable medium of claim 13 , the operations further comprising after authenticating the client device, authenticating a user of the client device based on user-specific credentials associated with the user and different than the unique key.

Assignments (7)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0219 →
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
SECURITY INTEREST Recorded Dec 16, 2020
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 054789/0680 →
CHANGE OF NAME Recorded Aug 24, 2015
From: PHANTOM TECHNOLOGIES, INC.
To: IBOSS, INC.
Reel/Frame 036434/0333 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2015
From: MARTINI, PAUL MICHAEL
To: PHANTOM TECHNOLOGIES, INC.
Reel/Frame 036403/0078 →
Continuity (2)
Continuation 13951359 · Jul 25, 2013
Related Publication 20150334103A1 · Nov 19, 2015