IP Library Granted Patent US 10,084,797
Granted Patent B2
US 10,084,797 · App. 15/284,131 · Granted Sep 25, 2018

Enhanced access security gateway

Inventors: Rifaat Shekh-Yusef (Belleville, CA); William T. Walker (Evergreen, CO)
Assignee: Extreme Networks, Inc.
H04L63/108H04L63/08G06F2221/2103H04L9/3265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,084,797
App. No.
15/284,131
Granted
Sep 25, 2018
Kind
B2
Abstract

A first login request of a user is received from a first login window. The first login request comprises a login name, a user identifier, and a challenge. The challenge is generated and received from a second login request to a product in a second login window. The user copies and pastes the challenge into the first login window. A central control system determines if the login name and the user identifier are valid. If the login name and user identifier are valid, a response to the challenge is generated based a private key and is displayed in the first login window. The response to the challenge is copied from the first login window and pasted as part of a second step the second login process. The second login process verifies the response to the challenge using a public key to allow the user access to the product.

Claims (37)

1. A system comprising:

a microprocessor; and

a computer readable medium, coupled with the microprocessor and comprising microprocessor readable and executable instructions that program the microprocessor to execute a central control system that:

receives a first login request of a first user, wherein the first login request comprises a login name, a user identifier, and a challenge received as part of a second login request to a first product;

determines if the login name and the user identifier are valid;

generates a response to the challenge in response to the login name and the user identifier being valid, wherein the response to the challenge is generated using a first private key, and wherein the first private key is specific to a first version of the first product;

sends the response to the challenge, wherein the response to the challenge is used as part of the second login request by the first user and wherein the first product verifies the response to the challenge using a first public key to allow the first user access to the first product, and wherein the first public key is specific to the first version of the first product; and

enables the first user to access a second version of the first product using a second private key and a second public key.

2. The system of claim 1 , wherein the challenge is based on a serial number of the first product and a random number.

3. The system of claim 1 , wherein the first product records the first login request based a login name extracted from the response to the challenge using the first public key and a user identifier in the response to the challenge.

4. The system of claim 1 , wherein the generated response to the challenge is generated using a hash of the challenge.

5. The system of claim 4 , wherein the generated response to the challenge is further generated based on one of: an organization who issued the first product, an organization who maintains the first product, or a serial number of the first product.

6. The system of claim 4 , wherein the generated response to the challenge is further generated based on the user identifier.

7. The system of claim 1 , wherein the first private key and the first public key are used for a second user login with a second user to the first product.

8. The system of claim 1 , wherein the first and second login requests also comprises a product identifier.

9. The system of claim 1 , wherein the first private key and the first public key are associated with the first product and wherein a second private key and a second public key are associated with a second product.

10. A method comprising:

receiving, by a microprocessor, a first login request of a first user, wherein the first login request comprises a login name, a user identifier, and a challenge received as part of a second login request to a first product;

determining, by the microprocessor, if the login name and the user identifier are valid;

in response to the login name and the user identifier being valid, generating, by the microprocessor, a response to the challenge, wherein the response to the challenge is generated using a first private key, and wherein the first private key is specific to a first version of the first product;

sending, by the microprocessor, the response to the challenge, wherein the response to the challenge is used as part of the second login request by the first user and wherein the first product verifies the response to the challenge using a first public key to allow the first user access to the first product, and wherein the first public key is specific to the first version of the first product; and

enabling the first user to access a second version of the first product using a second private key and a second public key.

11. The method of claim 10 , wherein the challenge is based on a serial number of the first product and a random number.

12. The method of claim 10 , wherein the first product records the first login request based a login name extracted from the response to the challenge using the first public key and a user identifier in the response to the challenge.

13. The method of claim 10 , wherein the generated response to the challenge is generated using a hash of the challenge.

14. The method of claim 13 , wherein the generated response to the challenge is further generated based on the user identifier.

15. The method of claim 10 , wherein the first private key and the first public key are used for a second user login with a second user to the first product.

16. A system comprising:

a microprocessor; and

a computer readable medium, coupled with the microprocessor and comprising microprocessor readable and executable instructions that program the microprocessor to execute a central control system that:

receives a first login request of a first user, wherein the first login request comprises a login name, a user identifier, and a challenge received as part of a second login request to a first product, wherein the central control system is on an isolated network;

determines if the login name and user identifier are valid;

generates a response to the challenge in response to the login name and the user identifier being valid, wherein the response to the challenge is generated using a temporary first private key, wherein the temporary first private key is installed locally on the central control system, and wherein the temporary first private key is specific to a first version of the first product;

sends the response to the challenge, wherein the response to the challenge is used as part the second login request and wherein the first product verifies the response to the challenge using a first public key associated with the temporary first private key to allow the first user access to the first product, and wherein the first public key is specific to the first version of the first product; and

enables the first user to access a second version of the first product using a temporary second private key and a second public key.

17. The system of claim 16 , wherein the temporary first private key automatically expires after a defined time period.

18. The system of claim 16 , wherein removal of the temporary first private key denies access to the first user.

Assignments (9)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: AVAYA INC.; AVAYA COMMUNICATION ISRAEL LTD; AVAYA HOLDINGS LIMITED
To: EXTREME NETWORKS, INC.
Reel/Frame 043569/0047 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2016
From: SHEKH-YUSEF, RIFAAT; WALKER, WILLIAM T.
To: AVAYA INC.
Reel/Frame 039925/0174 →
Continuity (1)
Related Publication 20180097818A1 · Apr 5, 2018