IP Library › Granted Patent US 12,309,134
Granted Patent B2
US 12,309,134 · App. 17/824,721 · Granted May 20, 2025

Methods and systems for pre-shared key (PSK) based authentication in communications

Inventors: Shiv Mehra (Saratoga, CA); Suresh Katukam (Milpitas, CA)
Assignee: Nile Global, Inc.
H04L63/0815H04L63/10H04W4/24H04W12/069
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,134
App. No.
17/824,721
Granted
May 20, 2025
Kind
B2
Abstract

Embodiments of a device and method are disclosed. In an embodiment, a method for communications involves at a cloud server, restricting network access of a user after a Pre-Shared Key (PSK) of the user is transmitted, and at the cloud server, redirecting the user to an identity provider for authentication after restricting network access of the user.

Claims (27)

1. A method for communications, the method comprising:

at a cloud server that comprises a network management module, a customer information portal connected to the network management module, and a network management database configured to store network management data, restricting network access of a user after a Pre-Shared Key (PSK) of the user is transmitted from the user to a network element that is located between the user and the cloud server in a first sign-on session for the user to verify against a plurality of pre-stored keys in a database, wherein at the cloud server, restricting network access of the user after the PSK of the user is transmitted comprises determining that a Media Access Control (MAC) address of a network device at which the user operates does not match an entry in a predetermined list of allowed MAC addresses; and

at the cloud server, redirecting the user to an identity provider for authentication after restricting network access of the user, wherein at the cloud server, redirecting the user to the identity provider for authentication after restricting network access of the user comprises at the cloud server, redirecting the user to the identity provider for Security Assertion Markup Language (SAML) based authentication after restricting network access of the user.

2. The method of claim 1 , wherein at the cloud server, redirecting the user to the identity provider for authentication after restricting network access of the user comprises at the cloud server, redirecting the user to the identity provider for single sign-on (SSO) authentication after restricting network access of the user.

3. The method of claim 1 , further comprising at the cloud server, allowing network access of a second user after a second PSK of the second user is transmitted when a MAC address of a second network device at which the second user operates matches an entry in the predetermined list of allowed MAC addresses.

4. The method of claim 1 , further comprising exchanging Dynamic Host Configuration Protocol (DHCP) information between a network device at which the user operates and a network element that has access to the cloud server.

5. The method of claim 1 , wherein the identity provider is not a Remote Authentication Dial-In User Service (RADIUS) server.

6. The method of claim 1 , wherein the user operates a network device that is connected to the cloud server through a wireless link.

7. The method of claim 6 , wherein the network device is wirelessly connected to a wireless access point (AP) that has access to the cloud server.

8. The method of claim 1 , further comprising at the cloud server, receiving a plurality of attributes of the user from the identity provider after the user is successfully authenticated.

9. The method of claim 8 , further comprising at the cloud server, allowing network access of the user after the attributes of the user are received from the identity provider.

10. The method of claim 8 , further comprising at the cloud server, performing an accounting operation of the user based on the attributes of the user are received from the identity provider.

11. The method of claim 10 , wherein at the cloud server, performing the accounting operation of the user comprises at the cloud server, performing the accounting operation of the user to generate billing information for the user based on the attributes of the user are received from the identity provider.

12. The method of claim 1 , further comprising at the cloud server, allowing network access of the user after the Pre-Shared Key (PSK) of the user is retransmitted in a subsequent sign-on session.

13. The method of claim 12 , further comprising at the cloud server, exchanging Media Access Control (MAC) Authentication Bypass (MAB) request and response messages in the subsequent sign-on session.

14. A method for communications, the method comprising:

at a cloud server that comprises a network management module, a customer information portal connected to the network management module, and a network management database configured to store network management data, restricting network access of a user after a Pre-Shared Key (PSK) of the user is transmitted from the user to a network element that is located between the user and the cloud server in a first sign-on session for the user to verify against a plurality of pre-stored keys in a database, wherein the user operates a network device that is connected to the cloud server through a wireless link, and wherein at the cloud server, restricting network access of the user after the PSK of the user is transmitted comprises determining that a Media Access Control (MAC) address of a network device at which the user operates does not match an entry in a predetermined list of allowed MAC addresses; and

redirecting the user to an identity provider for single sign-on (SSO) authentication after restricting network access of the user, wherein at the cloud server, redirecting the user to the identity provider for authentication after restricting network access of the user comprises at the cloud server, redirecting the user to the identity provider for Security Assertion Markup Language (SAML) based authentication after restricting network access of the user.

15. The method of claim 14 , further comprising at the cloud server, allowing network access of a second user after a second PSK of the second user is transmitted when a MAC address of a second network device at which the second user operates matches an entry in the predetermined list of allowed MAC addresses.

16. The method of claim 14 , further comprising:

at the cloud server, receiving a plurality of attributes of the user from the identity provider after the user is successfully authenticated; and

at the cloud server, allowing network access of the user after the attributes of the user are received from the identity provider.

17. A method for communications, the method comprising:

at a cloud server that comprises a network management module, a customer information portal connected to the network management module, and a network management database configured to store network management data, restricting network access of a user after a Pre-Shared Key (PSK) of the user is transmitted from the user to a network element that is located between the user and the cloud server in a first sign-on session for the user to verify against a plurality of pre-stored keys in a database, wherein at the cloud server, restricting network access of the user after the PSK of the user is transmitted comprises determining that a Media Access Control (MAC) address of a network device at which the user operates does not match an entry in a predetermined list of allowed MAC addresses;

at the cloud server, redirecting the user to an identity provider for Security Assertion Markup Language (SAML) based authentication after restricting network access of the user;

receiving a plurality of attributes of the user from the identity provider after the user is successfully authenticated; and

at the cloud server, allowing network access of the user after the attributes of the user are received from the identity provider.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2022
From: MEHRA, SHIV; KATUKAM, SURESH
To: NILE GLOBAL, INC.
Reel/Frame 060030/0593 →
Continuity (1)
Related Publication 20230388285A1 · Nov 30, 2023
References Cited (16)
US 9674892B1 · Li · 2017 [cited by examiner]
US 10680806B1 · Kaliski, Jr. · 2020 [cited by examiner]
US 10735397B2 · Ronda et al. · 2020 [cited by applicant]
US 20130176897A1 · Wang · 2013 [cited by examiner]
US 20130298209A1 · Targali · 2013 [cited by examiner]
US 20140165162A1 · Black · 2014 [cited by examiner]
US 20140365777A1 · Cha · 2014 [cited by examiner]
US 20160044124A1 · Sarukkai · 2016 [cited by examiner]
US 20160149898A1 · Parla · 2016 [cited by examiner]
US 20190028892A1 · Henry · 2019 [cited by examiner]
US 20190253407A1 · Livanos · 2019 [cited by examiner]
US 20190319962A1 · Karunakaran · 2019 [cited by examiner]
US 20200092254A1 · Goeringer · 2020 [cited by examiner]
US 20200099675A1 · Mardiks Rappaport · 2020 [cited by examiner]
US 20200137054A1 · Isola · 2020 [cited by examiner]
Aerohive Networks, “Aerohive PPSK Guide”, 2017, 29 pgs. [cited by applicant]
Cited By (1)
US 12,647,409