IP Library Granted Patent US 11,589,224
Granted Patent B2
US 11,589,224 · App. 17/098,677 · Granted Feb 21, 2023

Network access control

Inventors: Jerome Henry (Pittsboro, NC); Damodar Banodkar (San Jose, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04W12/06H04L9/0819H04L9/14H04L9/3218H04L9/3271H04L61/503H04L63/0876H04W12/069H04W12/08H04L63/0892H04L67/01H04L67/104H04L2101/622H04L2209/80H04W12/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,589,224
App. No.
17/098,677
Granted
Feb 21, 2023
Kind
B2
Abstract

A network controller configured to provide network access to client devices, receives a network access request from a client device. The network access request includes a media access control (MAC) address of the client device and information about a first private key. The network controller sends to a server an authentication request, which includes the MAC address of the client device. The network controller receives an authentication response from the server, which includes a second private key. The network controller determines whether the first private key is the same as the second private key. In response to determining that the first private key is different from the second private key, network access is denied to the client device, and in response to determining that the first private key is the same as the second private key, network access is granted to the client device.

Claims (57)

1. A method comprising:

at a network controller, receiving a network access request from a client device, the network access request including a media access control (MAC) address of the client device and information about a first private key;

sending, by the network controller, an authentication request to a server, wherein the authentication request includes the MAC address of the client device;

receiving an authentication response from the server;

determining whether the authentication response includes a second private key;

in response to determining that the authentication response includes the second private key, determining whether the first private key is the same as the second private key;

in response to determining that the first private key is different than the second private key or that the authentication response does not include the second private key, denying network access to the client device; and

in response to determining that the first private key is the same as the second private key, granting network access to the client device.

2. The method of claim 1 , further comprising:

in response to a failure to receive the authentication response within a predetermined period of time, denying network access to the client device.

3. The method of claim 1 , wherein the authentication response further includes a change of authorization (CoA) message that includes vendor-specific attributes.

4. The method of claim 3 , wherein the vendor-specific attributes further allow peer-to-peer traffic between the client device and other client devices having a same user identification.

5. The method of claim 3 , wherein the CoA message includes access restriction parameters to restrict the network access to the client device to a predetermined network resource.

6. The method of claim 5 , further comprising:

monitoring network activities of the client device;

determining whether the client device accesses a network resource other than the predetermined network resource; and

in response to determining the client device accesses a network resource other than the predetermined network resource, blocking the client device from accessing the network resource.

7. The method of claim 5 , wherein the access restriction parameters further require the client device to obey a set of traffic patterns.

8. The method of claim 5 , wherein the access restriction parameters further require traffic from and to the client device be with a predetermined set of access points.

9. An apparatus comprising:

a network interface that enables network communications;

a processor; and

a memory to store data and instructions executable by the processor,

wherein the processor is configured to execute the instructions to:

receive a network access request from a client device, the network access request including a media access control (MAC) address of the client device and information about a first private key;

send, via the network interface, an authentication request to a server, wherein the authentication request includes the MAC address of the client device;

receive an authentication response from the server;

determine whether the authentication response includes a second private key;

in response to determining that the authentication response includes the second private key, determine whether the first private key is the same as the second private key;

in response to determining that the first private key is different than the second private key or that the authentication response does not include the second private key, deny network access to the client device; and

in response to determining that the first private key is the same as the second private key, grant network access to the client device.

10. The apparatus of claim 9 , wherein the processor is configured to execute the instructions to:

in response to a failure to receive the authentication response within a predetermined period of time, deny network access to the client device.

11. The apparatus of claim 9 , wherein the authentication response further includes a change of authorization (CoA) message that includes vendor-specific attributes.

12. The apparatus of claim 11 , wherein the vendor-specific attributes further allow peer-to-peer traffic between the client device and other client devices having a same user identification.

13. The apparatus of claim 11 , wherein the CoA message includes access restriction parameters to restrict the network access to the client device to a predetermined network resource.

14. The apparatus of claim 13 , wherein the processor is configured to execute the instructions to:

monitor network activities of the client device;

determine whether the client device accesses a network resource other than the predetermined network resource; and

in response to determining the client device accesses a network resource other than the predetermined network resource, block the client device from accessing the network resource.

15. The apparatus of claim 13 , wherein the access restriction parameters further require the client device to obey a set of traffic patterns.

16. The apparatus of claim 13 , wherein the access restriction parameters further require traffic from and to the client device be with a predetermined set of access points.

17. A non-transitory computer-readable storage media encoded with software comprising computer executable instructions which, when executed by a processor, cause the processor to perform operations including:

receiving a network access request from a client device, the network access request including a media access control (MAC) address of the client device and information about a first private key;

sending an authentication request to a server, wherein the authentication request includes the MAC address of the client device;

receiving an authentication response from the server;

determining whether the authentication response includes a second private key;

in response to determining that the authentication response includes the second private key, determining whether the first private key is the same as the second private key;

in response to determining that the first private key is different than the second private key or that the authentication response does not include the second private key, denying network access to the client device; and

in response to determining that the first private key is the same as the second private key, granting network access to the client device.

18. The non-transitory computer-readable storage media of claim 17 , wherein the instructions further cause the processor to perform operations including:

in response to a failure to receive the authentication response within a predetermined period of time, denying network access to the client device.

19. The non-transitory computer-readable storage media of claim 17 , wherein the authentication response further includes a change of authorization (CoA) message that includes vendor-specific attributes, wherein the CoA message includes access restriction parameters to restrict the network access to the client device to a predetermined network resource.

20. The non-transitory computer-readable storage media of claim 19 , wherein the instructions further cause the processor to perform operations including:

monitoring network activities of the client device;

determining whether the client device accesses a network resource other than the predetermined network resource; and

in response to determining the client device accesses a network resource other than the predetermined network resource, blocking the client device from accessing the network resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2020
From: HENRY, JEROME; BANODKAR, DAMODAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 054375/0022 →
Continuity (3)
Continuation 15982476 · May 17, 2018
Provisional Application 62536177 · Jul 24, 2017
Related Publication 20210067965A1 · Mar 4, 2021