IP Library Granted Patent US 10,110,638
Granted Patent B2
US 10,110,638 · App. 15/186,084 · Granted Oct 23, 2018

Enabling dynamic authentication with different protocols on the same port for a switch

Inventors: Alexandru Z. Vank (Bellevue, WA); Xin Shen (Mercer Island, WA); Matt B. Cobb (Redmond, WA); Brad Robel-Forrest (North Bend, WA); Evan M. Phoenix (Seattle, WA)
Assignee: McAfee, LLC
H04L63/205H04L63/08H04L63/10H04L63/162H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,110,638
App. No.
15/186,084
Granted
Oct 23, 2018
Kind
B2
Abstract

The invention enables a client device that does not support IEEE 802.1X authentication to access at least some resources provided through a switch that supports 802.1X authentication by using dynamic authentication with different protocols. When the client device attempts to join a network, the switch monitors for an 802.1X authentication message from the client device. In one embodiment, if the client fails to send an 802.1X authentication message, respond to an 802.1X request from the switch, or a predefined failure condition is detected the client may be deemed incapable of supporting 802.1X authentication. In one embodiment, the client may be initially placed on a quarantine VLAN after determination that the client fails to perform an 802.1X authentication within a backoff time limit. However, the client may still gain access to resources based on various non-802.1X authentication mechanisms, including name/passwords, digital certificates, or the like.

Claims (51)

1. One or more non-transitory, computer readable media, the computer readable media comprising code for execution that, when executed, causes one or more processors to:

detect a request to join a network from a client device at a network device;

initiate a backoff timer with a backoff time-limit based on the request to join the network; and

apply a first policy to grant access to a network resource associated with a local area network based on determining the client device is capable of supporting an 802.1X authentication protocol before the backoff timer expires and on the client device being authenticated according to the 802.1X authentication protocol, wherein

a second policy is applied based, at least in part, on a determination that the client device is incapable of supporting the 802.1X authentication protocol and on the client device being authenticated according to another authentication protocol.

2. The one or more media of claim 1 , wherein the code for execution, when executed, causes the one or more processors to:

disable the backoff timer based on determining the client device is capable of supporting the 802.1X authentication protocol before the backoff time-limit expires.

3. The one or more media of claim 1 , wherein the client device is determined to be capable of supporting the 802.1X authentication protocol based on receiving an 802.1X authentication request before the backoff time-limit expires.

4. The one or more media of claim 1 , wherein the determination that the client device is incapable of supporting the 802.1X authentication protocol is made based on the backoff time-limit expiring without the network device receiving an authentication request according to the 802.1X authentication protocol.

5. The one or more media of claim 1 , wherein the determination that the client device is incapable of supporting the 802.1X authentication protocol is made based on detecting one or more failure conditions.

6. The one or more media of claim 5 , wherein the one or more failure conditions is selected from a group of failure conditions consisting of an incorrect authentication credential, an improperly configured supplicant, and an inoperable network device.

7. The one or more media of claim 1 , wherein the code for execution, when executed, causes the one or more processors to:

based on the determination that the client device is incapable of supporting the 802.1X authentication protocol, configure the network device to allow the client device to access quarantined resources on a different local area network.

8. The one or more media of claim 1 , wherein the code for execution, when executed, causes the one or more processors to:

based on the determination that the client device is incapable of supporting the 802.1X authentication protocol, configure the network device to block the client device from accessing any resources in the network.

9. The one or more media of claim 1 , wherein the second policy is applied to allow the client device to access one or more different network resources in the network.

10. The one or more media of claim 1 , wherein the code for execution, when executed, causes the one or more processors to:

enable, prior to the request to join the network being detected, the network device to detect an 802.1X authentication request.

11. The one or more media of claim 1 , wherein the code for execution, when executed, causes the one or more processors to:

disable the network device from using the 802.1X authentication protocol based on the determination that the client device is incapable of supporting the 802.1X authentication protocol.

12. The one or more media of claim 1 , wherein the local area network is virtualized.

13. The one or more media of claim 1 , wherein the code for execution, when executed, causes the one or more processors to:

provide an interface to the client device if the client device is incapable of using the 802.1X authentication protocol, and the interface is to enable initiation of the other authentication protocol.

14. The one or more media of claim 1 , wherein the request to join the network is detected by an enforcer component for detecting a Link Up request generated by the network device.

15. A system, comprising:

a network device to route network traffic from a client device; and

an enforcer element comprising instructions executable by at least one processor to

detect a request to join a network from a client device;

initiate a backoff timer with a backoff time-limit based on the request to join the network; and

apply a first policy to grant access to a network resource associated with a local area network based on determining the client device is capable of supporting an 802.1X authentication protocol before the backoff timer expires and on the client device being authenticated according to the 802.1X authentication protocol, wherein

a second policy is applied based, at least in part, on a determination that the client device is incapable of supporting the 802.1X authentication protocol and on the client device being authenticated according to another authentication protocol.

16. The system of claim 15 , wherein the instructions of the enforcer element are executable by the at least one processor to:

enable, prior to the request to join the network being detected, the network device to detect an 802.1X authentication request.

17. The system of claim 15 , wherein the instructions of the enforcer element are executable by the at least one processor to:

direct the network device to route network traffic from the client device to the enforcer element.

18. The system of claim 15 , wherein, if the client device is determined to be incapable of supporting authentication according to the 802.1X authentication protocol, then hypertext transfer protocol (HTTP) packets associated with the client device are permitted to propagate through the network device.

19. An apparatus, comprising:

a memory element for storing code; and

at least one processor configured to execute instructions associated with the code to:

detect a request to join a network from a client device to a network device associated with the network;

initiate a backoff timer with a backoff time-limit based on the request to join the network; and

apply a first policy to grant access to a network resource associated with a local area network based on determining the client device is capable of supporting a an 802.1X authentication protocol before the backoff timer expires and on the client device being authenticated according to the 802.1X authentication protocol, wherein

a second policy is applied based, at least in part, on a determination that the client device is incapable of supporting the 802.1X authentication protocol and on the client device being authenticated according to another authentication protocol.

20. The apparatus of claim 19 , wherein the backoff time-limit is set to a value based on at least one of characteristics of the network or characteristics of the network device.

21. A method, comprising:

detecting a request to join a network from a client device at a network device;

initiating a backoff timer with a backoff time-limit based on the request to join the network; and

applying a first policy to grant access to a network resource associated with a local area network based on determining the client device is capable of supporting an 802.1X authentication protocol before the backoff timer expires and on the client device being authenticated according to the 802.1X authentication protocol, wherein

a second policy is applied based, at least in part, on a determination that the client device is incapable of supporting the 802.1X authentication protocol and on the client device being authenticated according to another authentication protocol.

22. The method of claim 21 , further comprising:

disabling 802.1X processing on a switch port, on the client device not successfully authenticating using the 802.1X authentication protocol.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
Continuity (6)
Continuation 13952245 · Jul 26, 2013
Continuation 12879319 · Sep 10, 2010
Continuation 11337408 · Jan 23, 2006
Provisional Application 60750643 · Dec 14, 2005
Provisional Application 60647692 · Jan 26, 2005
Related Publication 20170019427A1 · Jan 19, 2017