IP Library Granted Patent US 10,666,653
Granted Patent B2
US 10,666,653 · App. 16/365,654 · Granted May 26, 2020

Internetwork authentication

Inventors: Kenshin Sakura (San Francisco, CA); Matthew Stuart Gast (San Francisco, CA); Long Fu (Saratoga, CA)
Assignee: Aerohive Networks, Inc.
H04L63/0884H04L63/08H04L63/0892H04L63/166H04L63/20H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,666,653
App. No.
16/365,654
Granted
May 26, 2020
Kind
B2
Abstract

A technique for network authentication interoperability involves initiating an authentication procedure on a first network, authenticating on a second network, and allowing access at the first network. The technique can include filtering access to a network, thereby restricting access to users with acceptable credentials. Offering a service that incorporates these techniques can enable incorporation of the techniques into an existing system with minimal impact to network configuration.

Claims (46)

1. A method comprising:

receiving a request for a policy-based identity routing service for a first network;

providing a first local authoritative user datastore interface (LAUDI) to a first network device of the first network;

obtaining a set of rules for identity routing to the first network;

establishing a connection between the first LAUDI and an authentication proxy;

receiving, at the first LAUDI, an authentication request for a station;

determining, based on the set of rules, whether to analyze the authentication request at the first LAUDI or to route the authentication request to a second LAUDI of a second network device of a second network;

in response to determining that the authentication request matches a characteristic defined by the set of rules, analyzing the authentication request at the first LAUDI; and

in response to determining that the authentication request does not match the characteristic defined by the set of rules, routing the authentication request to the second LAUDI, wherein an authentication result from the second LAUDI indicates whether the station is approved to access services on the second network.

2. The method of claim 1 , wherein receiving the request for the policy-based identity routing service comprises receiving the request from a party having appropriate credentials.

3. The method of claim 1 , wherein receiving the request for the policy-based identity routing service comprises receiving the request from an agent that received a previous request from a party.

4. The method of claim 1 , wherein providing the first LAUDI comprises pre-installing the first LAUDI on the first network device prior to implementation of the first network device.

5. The method of claim 1 , wherein the first network device includes a wireless access point.

6. The method of claim 1 , wherein the first LAUDI is coupled to a datastore to enable the first LAUDI to carry out authentication procedures.

7. The method of claim 1 , wherein obtaining the set of rules comprises obtaining the set of rules from an agent via an administrative interface.

8. The method of claim 1 , wherein the set of rules establish conditions under which the authentication request is sent to the first network based on credentials associated with the authentication request.

9. A non-transitory, tangible computer-readable device having instructions stored thereon for a policy-based identity routing service that, when executed by at least one computing device, causes the at least one computing device to perform operations comprising:

receiving a request for the policy-based identity routing service for a first network;

providing a first local authoritative user datastore interface (LAUDI) to a first network device of the first network;

obtaining a set of rules for identity routing to the first network;

establishing a connection between the first LAUDI and an authentication proxy;

receiving, at the first LAUDI, an authentication request for a station;

determining, based on the set of rules, whether to locally analyze the authentication request or to route the authentication request to a second LAUDI of a second network device of a second network;

in response to determining that the authentication request matches a characteristic defined by the set of rules, analyzing the authentication request at the first LAUDI; and

in response to determining that the authentication request does not match the characteristic defined by the set of rules, routing the authentication request to the second LAUDI, wherein an authentication result from the second LAUDI indicates whether the station is approved to access services on the second network.

10. The non-transitory, tangible computer-readable device of claim 9 , wherein receiving the request for the policy-based identity routing service comprises receiving the request from a party having appropriate credentials.

11. The non-transitory, tangible computer-readable device of claim 9 , wherein receiving the request for the policy-based identity routing service comprises receiving the request from an agent that received a previous request from a party.

12. The non-transitory, tangible computer-readable device of claim 9 , wherein providing the first LAUDI comprises pre-installing the first LAUDI on the first network device prior to implementation of the first network device.

13. The non-transitory, tangible computer-readable device of claim 9 , wherein the first LAUDI is coupled to a datastore to enable the first LAUDI to carry out authentication procedures.

14. The non-transitory, tangible computer-readable device of claim 9 , wherein the set of rules establish conditions under which the authentication request is sent to the first network based on credentials associated with the authentication request.

15. A system comprising:

a memory for storing instructions for a policy-based identity routing service; and

a processor configured to execute the instructions, the instructions causing the processor to:

receive a request for the policy-based identity routing service for a first network;

provide a first local authoritative user datastore interface (LAUDI) to a first network device of the first network;

obtain a set of rules for identity routing to the first network;

establish a connection between the first LAUDI and an authentication proxy

receive, at the first LAUDI, an authentication request for a station;

determine, based on the set of rules, whether to locally analyze the authentication request or to route the authentication request to a second LAUDI of a second network device of a second network;

in response to determining that the authentication request matches a characteristic defined by the set of rules, analyze the authentication request at the first LAUDI; and

in response to determining that the authentication request does not match the characteristic defined by the set of rules, route the authentication request to the second LAUDI, wherein an authentication result from the second LAUDI indicates whether the station is approved to access services on the second network.

16. The system of claim 15 , wherein receiving the request for the policy-based identity routing service comprises receiving the request from a party having appropriate credentials.

17. The system of claim 15 , wherein receiving the request for the policy-based identity routing service comprises receiving the request from an agent that received a previous request from a party.

18. The system of claim 15 , wherein providing the first LAUDI comprises pre-installing the first LAUDI on the first network device prior to implementation of the first network device.

19. The system of claim 15 , wherein the first LAUDI is coupled to a datastore to enable the first LAUDI to carry out authentication procedures.

20. The system of claim 15 , wherein the set of rules establish conditions under which the authentication request is sent to the first network based on credentials associated with the authentication request.

Assignments (3)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2020
From: AEROHIVE NETWORKS, INC.
To: EXTREME NETWORKS, INC.
Reel/Frame 052473/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2019
From: SAKURA, KENSHIN; GAST, MATTHEW STUART; FU, LONG
To: AEROHIVE NETWORKS, INC.
Reel/Frame 049770/0344 →
Continuity (7)
Continuation 15962816 · Apr 25, 2018
Continuation 15645711 · Jul 10, 2017
Continuation 15239470 · Aug 17, 2016
Continuation 14820251 · Aug 6, 2015
Continuation 14014247 · Aug 29, 2013
Provisional Application 61695282 · Aug 30, 2012
Related Publication 20190334898A1 · Oct 31, 2019