IP Library Granted Patent US 9,973,507
Granted Patent B2
US 9,973,507 · App. 15/040,499 · Granted May 15, 2018

Captive portal having dynamic context-based whitelisting

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,973,507
App. No.
15/040,499
Granted
May 15, 2018
Kind
B2
Abstract

Methods, systems and computer readable media for a captive portal having dynamic, context-based whitelisting are described.

Claims (52)

1. A method comprising:

receiving, from a user device, a first request to access a website;

redirecting the user device to a captive portal;

receiving a selection from the user device via the captive portal to access a login page of the web site;

creating a client request table corresponding exclusively to the user device;

creating a domain whitelist table corresponding exclusively to the user device;

adding a client request table entry to the client request table corresponding exclusively to the user device, the client request table entry including an Internet protocol (IP) address and a port number of the user device;

adding a domain whitelist table entry to the domain whitelist table corresponding exclusively to the user device, the domain whitelist table entry including a domain name of the website and a DNS resolved IP address for the domain name;

permitting the user device to access the login page of the website based on the domain whitelist table entry;

receiving a second request from the user device to access the website, the second request including an IP address and a port number;

searching for the IP address and port number combination of the second request in the client request table corresponding exclusively to the user device;

when the IP address and port number combination of the second request do not match an existing combination in the client request table, redirecting the user device to the captive portal; and

when the IP address and port number combination of the second request match a combination existing in the client request table, permitting the user device to access the website via the second request.

2. The method of claim 1 , further comprising granting access to a network when the user 14 device completes an authentication process with the website.

3. The method of claim 1 , wherein the website is a social media website.

4. The method of claim 1 , further comprising deleting the client request table and the domain whitelist table when the user device completes an authentication process with the web site.

5. The method of claim 1 , wherein when a selection to login to a second website is received from the user device, adding an entry for the second website to the domain whitelist table corresponding exclusively to the user device.

6. A system comprising:

one or more processors coupled to a nontransitory computer readable medium having stored thereon on software instructions that, when executed by the one or more processors, cause to perform operations including:

receiving, from a user device, a first request to access a website;

redirecting the user device to a captive portal;

receiving a selection from the user device via the captive portal to access a login page of the website;

creating a client request table corresponding exclusively to the user device;

creating a domain whitelist table corresponding exclusively to the user device;

adding a client request table entry to the client request table corresponding exclusively to the user device, the client request table entry including an Internet protocol (IP) address and a port number of the user device;

adding a domain whitelist table entry to the domain whitelist table corresponding exclusively to the user device, the domain whitelist table entry including a domain name of the website and a DNS resolved IP address for the domain name;

permitting the user device to access the login page of the website based on the domain whitelist table entry;

receiving a second request from the user device to access the website, the second request including an IP address and a port number;

searching for the IP address and port number combination of the second request in the client request table corresponding exclusively to the user device;

when the IP address and port number combination of the second request do not match an existing combination in the client request table, redirecting the user device to the captive portal; and

when the IP address and port number combination of the second request match a combination existing in the client request table, permitting the user device to access the website via the second request.

7. The system of claim 6 , further comprising granting access to a network when the user device completes an authentication process with the website.

8. The system of claim 6 , wherein the website is a social media website.

9. The system of claim 6 , further comprising deleting the client request table and the domain whitelist table when the user device completes an authentication process with the web site.

10. The system of claim 6 , wherein when a selection to login to a second website is received from the user device, adding an entry for the second website to the domain whitelist table corresponding exclusively to the user device.

11. A nontransitory computer readable medium having stored thereon software instructions that, when executed by one or more processors, cause the one or more processors to:

receiving, from a user device, a first request to access a website;

redirecting the user device to a captive portal;

receiving a selection from the user device via the captive portal to access a login page of the web site;

creating a client request table corresponding exclusively to the user device;

creating a domain whitelist table corresponding exclusively to the user device;

adding a client request table entry to the client request table corresponding exclusively to the user device, the client request table entry including an Internet protocol (IP) address and a port number of the user device;

adding a domain whitelist table entry to the domain whitelist table corresponding exclusively to the user device, the domain whitelist table entry including a domain name of the website and a DNS resolved IP address for the domain name;

permitting the user device to access the login page of the website based on the domain whitelist table entry;

receiving a second request from the user device to access the website, the second request including an IP address and a port number;

searching for the IP address and port number combination of the second request in the client request table corresponding exclusively to the user device;

when the IP address and port number combination of the second request do not match an existing combination in the client request table, redirecting the user device to the captive portal; and

when the IP address and port number combination of the second request match a combination existing in the client request table, permitting the user device to access the website via the second request.

12. The nontransitory computer readable medium of claim 11 , further comprising granting access to a network when the user device completes an authentication process with the website.

13. The nontransitory computer readable medium of claim 11 , wherein the website is a social media website.

14. The nontransitory computer readable medium of claim 11 , further comprising deleting the client request table and the domain whitelist table when the user device completes an authentication process with the website.

15. The nontransitory computer readable medium of claim 11 , wherein when a selection to login to a second website is received from the user device, adding an entry for the second website to the domain whitelist table corresponding exclusively to the user device.

Assignments (9)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: AVAYA INC.; AVAYA COMMUNICATION ISRAEL LTD; AVAYA HOLDINGS LIMITED
To: EXTREME NETWORKS, INC.
Reel/Frame 043569/0047 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2016
From: KADUR, MANISH MANJUNATH; PRABHU, ATUL
To: AVAYA INC.
Reel/Frame 039473/0930 →