US2017230350A1PendingUtilityA1

Network element and method for improved user authentication in communication networks

Assignee: TECTECO SECURITY SYSTEMS S LPriority: May 29, 2014Filed: May 29, 2014Published: Aug 10, 2017
Est. expiryMay 29, 2034(~7.8 yrs left)· nominal 20-yr term from priority
H04L 63/20H04L 63/10H04L 63/083H04L 49/20G06F 17/30312H04L 69/324H04L 63/0876H04L 63/0236H04L 2101/622H04L 61/5014G06F 21/44H04L 63/101H04L 69/326H04L 69/168H04L 69/161H04L 69/163H04L 63/1458H04L 63/162H04L 63/1416G06F 21/6218H04L 67/02H04L 63/145H04L 63/00G06F 21/00H04W 12/06H04L 63/107G06F 16/22
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention proposes a method and network element which allows improving, in different aspects, existing user authentication mechanisms in a communications network (for example, the 802.1x network), using a single network element. To that end, the element managing communications network access (for example, a router) will have a new physical and logical architecture (with various databases and verification and learning mechanisms) expanding the ability of said element, such that said element incorporates an authentication system to manage and provide the mechanisms needed for protecting communications, offering protection, management and automation abilities much greater than the systems existing today.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for the authentication of a user of an electronic device in a communications network, where the method comprises the following steps performed in a network element at layer 2 of an OSI model; where the network element is a router or switch which manages access to the communications network, comprising:
 a. receiving from the electronic device a network access request and an identifier of the device, an identifier of the user and a password for said user, in one or more OSI model layer 2 messages, where the identifier of the device is at least one of the following: the MAC address, the IMEI, the IMSI or the MSISDN of the electronic device;   b. authenticating the user, performing at least the following verifications:
 i. verifying that the identifier of the user is in an internal database of the network element as an identifier of a registered user and verifying that the password received corresponds to the one linked to said user in the database; 
 ii. verifying that the identifier of the device is in the database as linked to said user; 
   c. if any of the verifications performed in any of the authentication steps is negative, considering the authentication negative and denying the network access requested by said user.   
     
     
         2 . The method according to  claim 1 , where the user authentication step further comprises the following authentication steps after step (b)(ii) and before step (c):
 a. obtaining the date and/or time when the access is taking place and verifying that said date and/or time is within the allowed times of access stored in the internal database for said user and/or for said device;   b. verifying that the network access requested by the user is allowed by the security policies defined for said user stored in the database.   
     
     
         3 . The method according to  claim 2 , where a step of assigning a first access profile to the user is performed after step (b)(ii) of  claim 1  based at least on information stored in the database for said user, and where the security policies and/or the allowed times of access for said user will depend at least on the profile that has been assigned thereto. 
     
     
         4 . The method according to  claim 2 , where the step of verifying that network access is allowed by the security policies in step (2)(b) comprises verifying that the addressee and/or the web page and/or the service and/or the port which said user wishes to access is allowed in the security policies defined for said user stored in the internal database. 
     
     
         5 . The method according to  claim 2 , where the user's age is calculated after step (b)(ii) of  claim 1  based at least on information stored in the database and if the user is underage, allowed times of access specific for underage users are applied in step (2)(a) of  claim 2  and/or access to certain web pages is restricted according to the user's age. 
     
     
         6 . The method according to  claim 5 , where if the user is underage the following actions are performed after step (b)(ii) of  claim 1 :
 a. classifying the user in a given category according to the user's age, and   b. verifying if the web page the user wishes to access is classified as accessible for said category in which the user has been classified, where in order to classify a web page as accessible depending on the user's age, an analysis of the semantic content of said web page is performed by a semantic analyzer located in the network element.   
     
     
         7 . The method according to  claim 1  which further comprises, if the authentication is negative, sending a layer 2 message to the device indicating that access is denied to said user. 
     
     
         8 . The method according to  claim 1 , where if the authentication is negative, the identification of the user is stored in the internal database as an unauthorized user. 
     
     
         9 . The method according to  claim 1 , where step (a) includes:
 a. receiving from the electronic device a layer 2 message including a network access request and an identifier of the device;   b. sending to the device a layer 2 message requesting an identifier of the user and a password for said user;   c. receiving from the device a layer 2 message including an identifier of the user and the password for said user.   
     
     
         10 . The method according to  claim 1 , where to register the user in the network, the network element requests user information from the user and if the user does not provide said information, the network element denies registration in the network; where this user information includes at least one of the following parameters: full name of the user, mailing address, ID number, passport number, date of birth. 
     
     
         11 . The method according to  claim 1 , where the internal database includes for each registered user at least one of the following parameters: full name of the user, mailing address, ID number, passport number, date of birth, and where the network element sends said information concerning each user that is in the database, to a worldwide database, external to the network element. 
     
     
         12 . The method according to  claim 1  which further comprises:
 a. verifying if each user's communication in progress is within the allowed times of access for said user and/or for said device, stored in the database; 
 b. if that is not the case for any of the user's communications in progress, cutting off said communication. 
 
     
     
         13 . A network element for the authentication of a user of an electronic device at layer 2 of the OSI model in a communications network, where the network element is a router or switch which manages access to the communications network and it comprises:
 a. a database comprising a table of identifiers of registered users including the password linked to each user and a table of identifiers of devices which are linked to each registered user;   b. means for receiving from the device a network access request, an identifier of the device, an identifier of the user and a password for said user by means of one or more OSI model layer 2 messages where the identifier of the device is at least one of the following: the MAC address, the IMEI, the IMSI or the MSISDN of the electronic device;   c. a processor configured for authenticating the user, performing at least the following verifications:
 i. verifying that the identifier of the user is in the table of registered users and that the received password corresponds to the one linked to said user in said table; 
 ii. verifying that the identifier of the device is in the corresponding table of the database as linked to said user; 
 iii. if any of the verifications of the authentication is negative, denying said user's network access. 
   
     
     
         14 . A non-transitory digital storage medium for storing a computer program comprising computer executable instructions causing a computer executing the program to implement the method according to any of  claims 1 - 12 .

Join the waitlist — get patent alerts

Track US2017230350A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.