IP Library Granted Patent US 12,418,537
Granted Patent B2
US 12,418,537 · App. 17/750,198 · Granted Sep 16, 2025

Industrial device MAC authentication bypass bootstrapping

Inventors: Swapna Anandan (Fremont, CA); Flemming Stig Andreasen (Marlboro, NJ); Robert E. Barton (Richmond, CA)
Assignee: Cisco Technology, Inc.
H04L63/102H04L63/0876H04L63/101H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,537
App. No.
17/750,198
Granted
Sep 16, 2025
Kind
B2
Abstract

In one embodiment, an illustrative method herein may comprise: detecting, by a device, a new asset in a network with a media access control address; monitoring, by the device, the new asset to learn one or more contextual attributes of the new asset in the network; generating, by the device, a profile of the new asset based on the media access control address and the one or more contextual attributes; and using, by the device, the profile to define access and control over the new asset in the network.

Claims (49)

1. A method, comprising:

detecting, by a device, a new asset in a network with a media access control address, wherein the new asset does not support authentication by a central authority;

monitoring, by the device, the new asset to learn one or more contextual attributes of the new asset in the network, wherein at least one of the one or more contextual attributes is based on control system behavioral analytics insights of the new asset and comprises a component or activity tag;

generating, by the device, a profile of the new asset based on the media access control address and the one or more contextual attributes; and

using, by the device, the profile to define access and control over the new asset in the network.

2. The method as in claim 1 , wherein using the profile to define access and control over the new asset in the network comprises:

sharing the profile with an administrative controller to accept or reject the new asset in the network.

3. The method as in claim 1 , wherein using the profile to define access and control over the new asset in the network comprises:

sharing the profile with a policy engine in the network to assign an appropriate network access and control for the new asset.

4. The method as in claim 1 , wherein using the profile to define access and control over the new asset in the network comprises:

denying access to the network for the new asset when the profile is invalid.

5. The method as in claim 1 , further comprising:

detecting a change in behavior of the new asset in the network;

generating a new profile of the new asset based on the change in behavior; and

using the new profile to redefine access and control over the new asset in the network.

6. The method as in claim 1 , further comprising:

detecting the new asset on a specific switch in the network, wherein one of the one or more contextual attributes is an indication of validity based on the new asset being detected on the specific switch.

7. The method as in claim 1 , further comprising:

detecting the new asset as a replacement to an old asset in the network, wherein one of the one or more contextual attributes is an indication of validity based on the new asset being a replacement to the old asset.

8. The method as in claim 1 , wherein one or more of the one or more contextual attributes are based on one or more network association characteristics of the new asset.

9. The method as in claim 8 , wherein the one or more network association characteristics of the new asset are selected from a group consisting of: an access type of the new asset; a location of the new asset; an authentication type of the new asset; and an authentication status of the new asset.

10. The method as in claim 1 , wherein one or more of the one or more contextual attributes are based on one or more ports and/or one or more protocols used by the new asset.

11. The method as in claim 10 , further comprising:

determining the one or more ports and/or one or more protocols used by the new asset by one or both of active probing of the new asset or passive scanning of the new asset.

12. The method as in claim 1 , wherein the device comprises one of either an access switch or an access point in the network.

13. The method as in claim 1 , wherein the device comprises a profiling device, the method further comprising:

receiving traffic from the new asset forwarded via one of either an access switch or an access point in the network.

14. A tangible, non-transitory, computer-readable medium having computer-executable instructions stored thereon that, when executed by a processor on a computer, cause the computer to perform a method comprising:

detecting a new asset in a network with a media access control address, wherein the new asset does not support authentication by a central authority;

monitoring the new asset to learn one or more contextual attributes of the new asset in the network, wherein at least one of the one or more contextual attributes is based on control system behavioral analytics insights of the new asset and comprises a component or activity tag;

generating a profile of the new asset based on the media access control address and the one or more contextual attributes; and

using the profile to define access and control over the new asset in the network.

15. The tangible, non-transitory, computer-readable medium as in claim 14 , wherein using the profile to define access and control over the new asset in the network comprises:

sharing the profile with an administrative controller to accept or reject the new asset in the network.

16. The tangible, non-transitory, computer-readable medium as in claim 14 , wherein using the profile to define access and control over the new asset in the network comprises:

sharing the profile with a policy engine in the network to assign an appropriate network access and control for the new asset.

17. The tangible, non-transitory, computer-readable medium as in claim 14 , wherein using the profile to define access and control over the new asset in the network comprises:

denying access to the network for the new asset when the profile is invalid.

18. The tangible, non-transitory, computer-readable medium as in claim 14 , wherein the method further comprises:

detecting a change in behavior of the new asset in the network;

generating a new profile of the new asset based on the change in behavior; and

using the new profile to redefine access and control over the new asset in the network.

19. An apparatus, comprising:

a processor configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process, when executed, configured to:

detect a new asset in a network with a media access control address, wherein the new asset does not support authentication by a central authority;

monitor the new asset to learn one or more contextual attributes of the new asset in the network, wherein at least one of the one or more contextual attributes is based on control system behavioral analytics insights of the new asset and comprises a component or activity tag;

generate a profile of the new asset based on the media access control address and the one or more contextual attributes; and

use the profile to define access and control over the new asset in the network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2022
From: ANANDAN, SWAPNA; ANDREASEN, FLEMMING STIG; BARTON, ROBERT E.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 059976/0849 →
Continuity (1)
Related Publication 20230412603A1 · Dec 21, 2023
References Cited (11)
US 9325516B2 · Pera et al. · 2016 [cited by applicant]
US 20200287924A1 · Zhang · 2020 [cited by examiner]
US 20210344738A1 · Petrie et al. · 2021 [cited by applicant]
US 20220030334A1 · Stamatakis et al. · 2022 [cited by applicant]
KR 20100090489 · 2010 [cited by applicant]
WO WO2018142697A1 · 2018 [cited by examiner]
WO 2022045851 · 2022 [cited by applicant]
Li, et al., “Behaviour Profiling for Transparent Authentication for Mobile Devices”, Edith Cowan University, Research Online, ECU Publications, 2011, pp. 307-314. [cited by applicant]
“Configure device profiling authentication”, online: https://backstage.forgerock.com/docs/idcloud/latest/solution-configure-device-profiling.html, accessed May 18, 2022, 4 pages, ForgeRock. [cited by applicant]
Ashibani, et al., “A Behavior Profiling Model for User Authentication in IoT Networks based on App Usage Patterns”, IECON 2018—44th Annual Conference of the IEEE Industrial Electronics Society, Oct. 2018, pp. 2841-2846,… [cited by applicant]
Nicholson, et al., “Deceptive security based on authentication profiling”, The Proceedings of 15th Australian Information Security Management Conference, Dec. 5-6, 2017, Edith Cowan University, Perth, Western Australia,… [cited by applicant]