Network element and method for improved user authentication in communication networks
Abstract
The present invention proposes a method and network element which allows improving, in different aspects, existing user authentication mechanisms in a communications network (for example, the 802.1x network), using a single network element. To that end, the element managing communications network access (for example, a router) will have a new physical and logical architecture (with various databases and verification and learning mechanisms) expanding the ability of said element, such that said element incorporates an authentication system to manage and provide the mechanisms needed for protecting communications, offering protection, management and automation abilities much greater than the systems existing today.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for the authentication of a user of an electronic device in a communications network, where the method comprises the following steps performed in a network element at layer 2 of an OSI model; where the network element is a router or switch which manages access to the communications network, comprising:
a. receiving from the electronic device a network access request and an identifier of the device, an identifier of the user and a password for said user, in one or more OSI model layer 2 messages, where the identifier of the device is at least one of the following: the MAC address, the IMEI, the IMSI or the MSISDN of the electronic device; b. authenticating the user, performing at least the following verifications:
i. verifying that the identifier of the user is in an internal database of the network element as an identifier of a registered user and verifying that the password received corresponds to the one linked to said user in the database;
ii. verifying that the identifier of the device is in the database as linked to said user;
c. if any of the verifications performed in any of the authentication steps is negative, considering the authentication negative and denying the network access requested by said user.
2 . The method according to claim 1 , where the user authentication step further comprises the following authentication steps after step (b)(ii) and before step (c):
a. obtaining the date and/or time when the access is taking place and verifying that said date and/or time is within the allowed times of access stored in the internal database for said user and/or for said device; b. verifying that the network access requested by the user is allowed by the security policies defined for said user stored in the database.
3 . The method according to claim 2 , where a step of assigning a first access profile to the user is performed after step (b)(ii) of claim 1 based at least on information stored in the database for said user, and where the security policies and/or the allowed times of access for said user will depend at least on the profile that has been assigned thereto.
4 . The method according to claim 2 , where the step of verifying that network access is allowed by the security policies in step (2)(b) comprises verifying that the addressee and/or the web page and/or the service and/or the port which said user wishes to access is allowed in the security policies defined for said user stored in the internal database.
5 . The method according to claim 2 , where the user's age is calculated after step (b)(ii) of claim 1 based at least on information stored in the database and if the user is underage, allowed times of access specific for underage users are applied in step (2)(a) of claim 2 and/or access to certain web pages is restricted according to the user's age.
6 . The method according to claim 5 , where if the user is underage the following actions are performed after step (b)(ii) of claim 1 :
a. classifying the user in a given category according to the user's age, and b. verifying if the web page the user wishes to access is classified as accessible for said category in which the user has been classified, where in order to classify a web page as accessible depending on the user's age, an analysis of the semantic content of said web page is performed by a semantic analyzer located in the network element.
7 . The method according to claim 1 which further comprises, if the authentication is negative, sending a layer 2 message to the device indicating that access is denied to said user.
8 . The method according to claim 1 , where if the authentication is negative, the identification of the user is stored in the internal database as an unauthorized user.
9 . The method according to claim 1 , where step (a) includes:
a. receiving from the electronic device a layer 2 message including a network access request and an identifier of the device; b. sending to the device a layer 2 message requesting an identifier of the user and a password for said user; c. receiving from the device a layer 2 message including an identifier of the user and the password for said user.
10 . The method according to claim 1 , where to register the user in the network, the network element requests user information from the user and if the user does not provide said information, the network element denies registration in the network; where this user information includes at least one of the following parameters: full name of the user, mailing address, ID number, passport number, date of birth.
11 . The method according to claim 1 , where the internal database includes for each registered user at least one of the following parameters: full name of the user, mailing address, ID number, passport number, date of birth, and where the network element sends said information concerning each user that is in the database, to a worldwide database, external to the network element.
12 . The method according to claim 1 which further comprises:
a. verifying if each user's communication in progress is within the allowed times of access for said user and/or for said device, stored in the database;
b. if that is not the case for any of the user's communications in progress, cutting off said communication.
13 . A network element for the authentication of a user of an electronic device at layer 2 of the OSI model in a communications network, where the network element is a router or switch which manages access to the communications network and it comprises:
a. a database comprising a table of identifiers of registered users including the password linked to each user and a table of identifiers of devices which are linked to each registered user; b. means for receiving from the device a network access request, an identifier of the device, an identifier of the user and a password for said user by means of one or more OSI model layer 2 messages where the identifier of the device is at least one of the following: the MAC address, the IMEI, the IMSI or the MSISDN of the electronic device; c. a processor configured for authenticating the user, performing at least the following verifications:
i. verifying that the identifier of the user is in the table of registered users and that the received password corresponds to the one linked to said user in said table;
ii. verifying that the identifier of the device is in the corresponding table of the database as linked to said user;
iii. if any of the verifications of the authentication is negative, denying said user's network access.
14 . A non-transitory digital storage medium for storing a computer program comprising computer executable instructions causing a computer executing the program to implement the method according to any of claims 1 - 12 .Join the waitlist — get patent alerts
Track US2017230350A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.