IP Library Granted Patent US 11,558,355
Granted Patent B2
US 11,558,355 · App. 16/908,971 · Granted Jan 17, 2023

Gateway with access checkpoint

Inventors: German Lancioni (San Jose, CA); Eric Donald Wuehler (Beaverton, OR)
Assignee: McAfee, LLC
H04L63/0281H04L63/0263H04L63/08H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,558,355
App. No.
16/908,971
Granted
Jan 17, 2023
Kind
B2
Abstract

There is disclosed in one example a gateway apparatus to operate on an intranet, including: a hardware platform; and an access proxy engine to operate on the hardware platform and configured to: intercept an incoming packet; determine that the incoming packet is an access request directed to an access interface of a resource of the intranet; present an access checkpoint interface; receive an authentication input response; validate the authentication input response; and provide a redirection to the access interface of the device.

Claims (42)

1. A gateway apparatus, comprising:

a network interface that receives an access request for a network resource, presents an access checkpoint interface that requests an authentication input, and receives the authentication input;

a memory that stores login credentials for an authentication to the network resource; and

a processor configured to perform, based on an authentication of the authentication input, the authentication to the network resource, wherein the gateway apparatus provides a redirection to the network resource.

2. The gateway apparatus of claim 1 , further comprising:

a memory that stores a session token for the network resource, wherein the processor further is configured to determine that a session exists, based on the session token.

3. The gateway apparatus of claim 2 , wherein the processor further is configured to provide the redirection based on a determination that the access request is within a scope of the session.

4. The gateway apparatus of claim 2 , wherein the processor further is configured to craft a security policy defining a maximum session time length or a maximum number of unsuccessful login attempts before access to the network resource is locked out.

5. The gateway apparatus of claim 1 , wherein the processor further is configured to craft a security policy defining whether the network resource can be accessed only via a local network.

6. The gateway apparatus of claim 1 , wherein the network resource is an Internet of things (IoT) device.

7. One or more non-transitory, computer-readable storage mediums having stored thereon instructions to instruct a device to perform a method comprising:

receiving an access request for a network resource;

presenting an access checkpoint interface that requests an authentication input;

receiving the authentication input;

storing login credentials for an authentication to the network resource;

performing, based on an authentication of the authentication input, the authentication to the network resource; and

providing a redirection to the network resource.

8. The one or more storage mediums of claim 7 , the method further comprising:

storing a session token for the network resource; and

determining that a session exists, based on the session token.

9. The one or more storage mediums of claim 8 , the method further comprising:

providing the redirection based on a determination that the access request is within a scope of the session.

10. The one or more storage mediums of claim 8 , the method further comprising:

crafting a security policy defining a maximum session time length or a maximum number of unsuccessful login attempts before access to the network resource is locked out.

11. The one or more storage mediums of claim 7 , the method further comprising:

crafting a security policy defining whether the network resource can be accessed only via a local network.

12. The one or more storage mediums of claim 7 , wherein the network resource is an Internet of things (IoT) device.

13. A method for a gateway device, comprising:

receiving an access request for a network resource;

presenting an access checkpoint interface that requests an authentication input;

receiving the authentication input;

storing login credentials for an authentication to the network resource;

performing, based on an authentication of the authentication input, the authentication to the network resource; and

providing a redirection to the network resource.

14. The method of claim 13 , further comprising:

storing a session token for the network resource; and

determining that a session exists, based on the session token.

15. The method of claim 14 , further comprising:

providing the redirection based on a determination that the access request is within a scope of the session.

16. The method of claim 14 , further comprising:

crafting a security policy defining a maximum session time length or a maximum number of unsuccessful login attempts before access to the network resource is locked out.

17. The method of claim 13 , wherein the network resource is an Internet of things (IoT) device.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Continuity (2)
Continuation 15905606 · Feb 26, 2018
Related Publication 20200322314A1 · Oct 8, 2020