IP Library Granted Patent US 8,074,259
Granted Patent B1
US 8,074,259 · App. 11/118,506 · Granted Dec 6, 2011

Authentication mark-up data of multiple local area networks

Assignee: SonicWall, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,074,259
App. No.
11/118,506
Granted
Dec 6, 2011
Kind
B1
Abstract

An authentication mark-up data of multiple local area networks is disclosed. In one embodiment of a system, the system includes a wide area network, an update device coupled to the wide area network, and any number of gateway devices coupled to the wide area network. Each of the gateway devices is associated with a separate local area network. Each of the plurality of gateway devices automatically provide an authentication page stored in the update device based upon a data provided to the update device. In addition, the authentication page is the same for at least some of the plurality of gateway devices, according to the one embodiment.

Claims (34)

1. A system, comprising:

an update device coupled to a wide area network and having stored therein authentication markup data; and

a plurality of network access devices (NADs) coupled to the wide area network, each of the NADs associated with a separate local area network (LAN), and each of the NADs to redirect clients attempting access through the NAD to an authentication page constructed using authentication markup data in the update device, wherein at least a portion of the authentication markup data stored in the update device is shared to construct authentication pages of at least two of the NADs, wherein the authentication markup data used to construct the authentication page is selected based on predetermined criteria of a respective LAN and a respective NAD, and wherein a first NAD of the plurality of NADs periodically requests operational status of the device and informs said operational status to other NADs of the plurality of NADs.

2. The system of claim 1 , wherein the authentication page is the same for at least some of the plurality of NADs.

3. The system of claim 1 , wherein an authentication page of a NAD is generated using at least a portion of the authentication markup data stored in the update device and is cached within the NAD when presented to the client over the respective LAN.

4. The system of claim 1 , wherein at least one of the NADs performs at least a portion of the authentication.

5. The system of claim 1 , wherein authentication is performed in at least one of an external authentication server and an internal authentication server.

6. The system of claim 1 , wherein the authentication page is transmitted to each of the NADs from the update device, and stored locally in each of the plurality of NADs.

7. The system of claim 1 , wherein a secure connection is formed between at least one of the NADs and the update device using at least one of a virtual private network protocol (VPN), a hypertext transport protocol secure socket layer protocol (HTTPS), an encryption method over a communications channel, a fully qualified domain name protocol (FQDN), and at least one internet protocol (IP) address.

8. The system of claim 1 , wherein a list of at least one defined internet protocol (IP) address and at least one port name is maintained on each of the plurality of NADs to specify permitted communication channels between the plurality of NADs and the update device.

9. A machine implemented method, comprising:

in response to a request for accessing a destination received from a client over a first local area network (LAN), a first network access device (NAD) establishing a first authentication page, which is constructed using authentication markup data stored in an update device communicatively coupled to the first NAD over a wide area network (WAN), wherein the authentication markup data used to construct the first authentication page is selected based on predetermined criteria of the first LAN and the first NAD, and wherein first NAD of the plurality of NADs periodically requests operational status of the update device and informs said operational status to other NADs of the plurality of NADs; and

the first NAD redirecting the request of the client to the established first authentication page for authenticating the client, wherein at least a portion of the authentication markup data used in the first authentication page is shared with another authentication page established by a second NAD for authenticating a client of another LAN.

10. The method of claim 9 , wherein at least a portion of the first authentication page is cached within the first NAD.

11. The method of claim 9 , wherein the first NAD performs a portion of the authentication of the client using a user database maintained within the first NAD.

12. The method of claim 9 , wherein the authentication is performed via at least one of an external authentication server and an internal authentication server with respect to at least one of the first NAD and the update device.

13. The method of claim 9 , further comprising forming a secure connection between the update device and the first NAD using at least one of a virtual private network protocol (VPN), a hypertext transport protocol secure socket layer protocol (HTTPS), an encryption method over a communications channel, a fully qualified domain name protocol (FQDN), and at least one internet protocol (IP) address.

14. The method of claim 9 , further comprising maintaining a list of at least one defined Internet protocol (IP) address and at least one port identity within the first NAD to specify permitted communications channels between the first NAD and the update device.

15. The method of claim 9 , further comprising the update device transmitting the first authentication page to the first NAD to authenticate the client.

16. The method of claim 15 , further comprising the first authentication page invoking an authentication facility to authenticate the client in response to a user input received via the first authentication page.

17. The method of claim 16 , further comprising:

determining status of the authentication facility while presenting the first authentication page to the client; and

presenting a second authentication page to the client indicating authentication service unavailable if the authentication facility is unavailable based on the status of the authentication facility, wherein the second authentication page is constructed using at least a portion of the authentication markup data stored in the update device.

18. The method of claim 16 , further comprising:

in response to authentication information received from the client, the authentication facility authenticating the client; and

presenting a third authentication page to the client indicating a failure of the authentication if the authentication fails and redirecting the client back to the first authentication page, wherein the third authentication page is constructed using at least a portion of the authentication markup data stored in the update device.

19. The method of claim 18 further comprising the first NAD directing the client to the requested destination if the authentication facility successfully authenticates the client.

20. A machine implemented method, comprising:

centralizing control of markup data for generating authentication pages by, storing the markup data in an update device accessible over a wide area network (WAN); and

operating a plurality of gateway in different local area networks (LANs) coupled to the WAN to cause redirection of clients attempting access through the plurality of gateway devices to authentication pages constructed using the markup data in the update device, wherein the authentication markup data used to construct the authentication pages is selected based on predetermined criteria of respective LANs and respective plurality of gateway devices, and wherein a first gateway device of the plurality of gateway devices periodically requests operational status of the update device and informs said operational status to other gateway devices of the plurality of gateway devices.

21. The method of claim 20 , wherein the markup data is stored in storage accessible by the update device, and wherein the markup data is configured by an administrator by accessing the update device.

22. The method of claim 20 , further comprising invoking an authentication server to authenticate the clients in response to user inputs received via the authentication pages.

23. The method of claim 22 , wherein the authentication pages are constructed by the update device using the markup data stored therein, wherein at least one of the authentication pages is transmitted to each of the plurality of gateway devices and hosted by a respective gateway device, and wherein the respective gateway device invokes the authentication server to authenticate the clients.

24. The method of claim 20 , wherein the authentication pages are constructed by the update device using the markup data stored therein and hosted by the update device, and wherein the update device invokes the authentication server to authenticate the clients.

Assignments (24)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Apr 30, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046040/0277 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
CONVERSION AND NAME CHANGE Recorded Dec 15, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037299/0855 →
MERGER Recorded Dec 15, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037292/0987 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024823/0280 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0126 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024776/0337 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0115 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024823/0280 →
SECURITY AGREEMENT Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024776/0337 →
CHANGE OF NAME Recorded Jul 28, 2010
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 024755/0091 →
MERGER Recorded Jul 28, 2010
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 024755/0083 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2005
From: LEVY, JOSEPH H.; JOHNSON, SHANNON L.; TELEHOWSKI, DAVID M.; CHEN, ZHONG
To: SONICWALL
Reel/Frame 016530/0256 →