IP Library Granted Patent US 11,129,021
Granted Patent B2
US 11,129,021 · App. 17/190,887 · Granted Sep 21, 2021

Network access control

Inventors: Jerome Henry (Pittsboro, NC); Damodar Banodkar (San Jose, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04W12/06H04L9/0819H04L9/14H04L9/3218H04L9/3271H04L61/203H04L63/0876H04W12/069H04W12/08H04L61/6022H04L63/0892H04L67/104H04L67/42H04L2209/80H04W12/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,129,021
App. No.
17/190,887
Granted
Sep 21, 2021
Kind
B2
Abstract

A network controller configured to provide network access to client devices, receives a network access request from a client device. The network access request includes a media access control (MAC) address of the client device and information about a first private key. The network controller sends to a server an authentication request, which includes the MAC address of the client device. The network controller receives an authentication response from the server, which includes a second private key. The network controller determines whether the first private key is the same as the second private key. In response to determining that the first private key is different from the second private key, network access is denied to the client device, and in response to determining that the first private key is the same as the second private key, network access is granted to the client device.

Claims (57)

1. A method comprising:

at a network device configured to provide network access to client devices, receiving a network access request from a client device, the network access request including a media access control (MAC) address of the client device;

sending, by the network device, an authentication request to a server, wherein the authentication request includes the MAC address of the client device;

receiving an authentication response from the server, the authentication response including a private key;

initiating a four-way handshake with the client device using the private key returned by the server;

in response to determining from the four-way handshake that the client device has not been configured with the private key, denying network access to the client device; and

in response to determining from the four-way handshake that the client device has been configured with the private key, granting network access to the client device.

2. The method of claim 1 , wherein the authentication response further includes vendor-specific attributes.

3. The method of claim 1 , further comprising:

registering the client device with the server, wherein the server generates the private key for the client device.

4. The method of claim 1 , wherein the private key is unique to the client device.

5. The method of claim 1 , wherein the private key is unique to a group of devices that includes the client device.

6. The method of claim 1 , wherein the network access request received from the client device is an authentication request.

7. The method of claim 1 , wherein the network device comprises a link layer network access controller.

8. The method of claim 1 , wherein the network device comprises a wireless LAN controller.

9. The method of claim 1 , further comprising denying network access to the client device if the authentication response does not include a private key.

10. The method of claim 1 , wherein the authentication response includes access restriction parameters to restrict the network access to the client device to a predetermined network resource.

11. The method of claim 1 , wherein the private key is a pre-shared key.

12. An apparatus comprising:

a network interface that enables network communications;

a processor; and

a memory to store data and instructions executable by the processor, wherein the processor is configured to execute the instructions to:

receive a network access request from a client device, the network access request including a media access control (MAC) address of the client device;

send an authentication request to a server, wherein the authentication request includes the MAC address of the client device;

receive an authentication response from the server, the authentication response including a private key;

initiate a four-way handshake with the client device using the private key returned by the server;

in response to determining from the four-way handshake that the client device has not been configured with the private key, deny network access to the client device; and

in response to determining from the four-way handshake that the client device has been configured with the private key, grant network access to the client device.

13. The apparatus of claim 12 , wherein the authentication response further includes vendor-specific attributes.

14. The apparatus of claim 12 , wherein the processor is configured to execute the instructions to:

register the client device with the server, wherein the server generates the private key for the client device.

15. The apparatus of claim 12 , wherein the private key is unique to the client device.

16. The apparatus of claim 12 , wherein the private key is unique to a group of devices that includes the client device.

17. The apparatus of claim 12 , wherein the network access request received from the client device is an authentication request.

18. The apparatus of claim 12 , wherein the apparatus comprises a link layer network access controller.

19. The apparatus of claim 12 , wherein the apparatus comprises a wireless LAN controller.

20. The apparatus of claim 12 , wherein the processor is configured to execute the instructions to:

deny network access to the client device if the authentication response does not include a private key.

21. The apparatus of claim 12 , wherein the authentication response includes access restriction parameters to restrict the network access to the client device to a predetermined network resource.

22. The apparatus of claim 12 , wherein the private key is a pre-shared key.

23. A non-transitory computer-readable storage media encoded with software comprising computer executable instructions which, when executed by a processor, cause the processor to:

receive a network access request from a client device, the network access request including a media access control (MAC) address of the client device;

send an authentication request to a server, wherein the authentication request includes the MAC address of the client device;

receive an authentication response from the server, the authentication response including a private key;

initiate a four-way handshake with the client device using the private key returned by the server;

in response to determining from initiation of the four-way handshake that the client device has not been configured with the private key, deny network access to the client device; and

in response to determining from initiation of the four-way handshake that the client device has been configured with the private key, grant network access to the client device.

24. The non-transitory computer-readable storage media of claim 23 , wherein the authentication response further includes vendor-specific attributes.

25. The non-transitory computer-readable storage media of claim 23 , wherein the instructions further cause the processor to:

register the client device with the server, wherein the server generates the private key for the client device.

26. The non-transitory computer-readable storage media of claim 23 wherein the private key is unique to the client device.

27. The non-transitory computer-readable storage media of claim 23 wherein the private key is unique to a group of devices that includes the client device.

28. The non-transitory computer-readable storage media of claim 23 , wherein the network access request received from the client device is an authentication request.

29. The non-transitory computer-readable storage media of claim 23 , wherein the instructions further cause the processor to:

deny network access to the client device if the authentication response does not include a private key.

30. The non-transitory computer-readable storage media of claim 23 , wherein the authentication response includes access restriction parameters to restrict the network access to the client device to a predetermined network resource.

31. The non-transitory computer-readable storage media of claim 23 , wherein the private key is a pre-shared key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2021
From: HENRY, JEROME; BANODKAR, DAMODAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 055480/0656 →
Continuity (4)
Continuation 17098677 · Nov 16, 2020
Continuation 15982476 · May 17, 2018
Provisional Application 62536177 · Jul 24, 2017
Related Publication 20210195414A1 · Jun 24, 2021