US2017302644A1PendingUtilityA1

Network user identification and authentication

Individually held — no corporate assignee on recordPriority: Sep 22, 2011Filed: Jun 28, 2017Published: Oct 19, 2017
Est. expirySep 22, 2031(~5.2 yrs left)· nominal 20-yr term from priority
H04L 9/3247H04L 63/164H04L 63/08H04L 63/126H04L 63/0853H04L 9/3263H04L 9/32H04L 63/102H04L 63/20
34
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method of identifying and authenticating a network user includes receiving a first network layer packet from a first user entity. The first network layer packet may include first unique identification information unique to the first user entity and independent of a first network address associated with the first network layer packet. The method further includes verifying, at a network layer of a network, that the first network layer packet is from the first user entity based on the first unique identification information.

Claims

exact text as granted — not AI-modified
1 . A method of identifying and authenticating a network user comprising:
 receiving a first network layer packet from a first user entity, the first network layer packet including first unique identification information unique to the first user entity and independent of a first network address associated with the first network layer packet; and   verifying, at a network layer of a network, that the first network layer packet is from the first user entity based on the first unique identification information.   
     
     
         2 . The method of  Claim 1 , further comprising:
 receiving a second network layer packet from a second user entity, the second network layer packet associated with the first network address and including second unique identification information unique to the second user entity and independent of the first network address; and   verifying, at the network layer of the network, that the second network layer packet is from the second user entity based on the second unique identification information.   
     
     
         3 . The method of  Claim 1 , further comprising:
 receiving a second network layer packet from the first user entity, the second network layer packet associated with a second network address different from the first network address and including the first unique identification information; and   verifying, at the network layer of the network, that the second network layer packet is from the first user entity based on the first unique identification information.   
     
     
         4 . The method of  Claim 1 , further comprising verifying that the first network layer packet is from the first user entity based on a digital signature associated with the first user entity, the digital signature generated based on a key shared by the first user entity and an authentication domain configured to perform the verifying. 
     
     
         5 . The method of  Claim 1 , further comprising verifying that the first network layer packet is from the first user entity based on a digital signature associated with the first user entity, the digital signature generated based on a public/private key pair authentication scheme. 
     
     
         6 . The method of  Claim 1 , further comprising applying a policy to the received first network layer packet based on the first unique identification information. 
     
     
         7 . The method of  Claim 6 , further comprising allowing or disallowing receipt of the first network layer packet at an intended destination endpoint based on the application of the policy. 
     
     
         8 . The method of  Claim 6 , further comprising applying the policy anywhere in a path between the first user entity and an intended destination endpoint. 
     
     
         9 . The method of  Claim 6 , further comprising applying the policy at a plurality of points included in a path between the first user entity and an intended destination point. 
     
     
         10 . The method of  Claim 1 , further comprising associating a malicious attack with the first user identification information. 
     
     
         11 . The method of  Claim 1 , further comprising identifying the first user entity based on the first user identification information after verifying that the first network layer packet is from the first user entity without re-verifying that the first network layer packet is from the first user entity. 
     
     
         12 . The method of  Claim 1 , further comprising verifying that the first network layer packet is from the first user entity based on the unique identification information before allowing an application layer connection with an intended destination endpoint. 
     
     
         13 . The method of  Claim 1 , further comprising allowing an application layer connection with an intended destination endpoint based on the unique identification information. 
     
     
         14 . The method of  Claim 13 , further comprising maintaining the application layer connection with the destination endpoint based on the unique identification information. 
     
     
         15 . A processor configured to execute computer instructions to cause a system to perform operations for identifying and authenticating a network user, the operations comprising:
 receiving a first network layer packet from a first user entity, the first network layer packet including first unique identification information unique to the first user entity and independent of a first network address associated with the first network layer packet; and   verifying, at a network layer of a network, that the first network layer packet is from the first user entity based on the first unique identification information.   
     
     
         16 . The processor of  Claim 15 , wherein the operations further comprise: receiving a second network layer packet from a second user entity, the second network 
       layer packet associated with the first network address and including second unique identification information unique to the second user entity and independent of the first network address; and
 verifying, at the network layer of the network, that the second network layer packet is from the second user entity based on the second unique identification information. 
 
     
     
         17 . The processor of  Claim 15 , wherein the operations further comprise: receiving a second network layer packet from the first user entity, the second network
 layer packet associated with a second network address different from the first network address and including the first unique identification information; and   verifying, at the network layer of the network, that the second network layer packet is from the first user entity based on the first unique identification information.   
     
     
         18 . The processor of  Claim 15 , wherein the operations further comprise verifying that the first network layer packet is from the first user entity based on a digital signature associated with the first user entity, the digital signature generated based on a key shared by the first user entity and an authentication domain configured to perform the verifying. 
     
     
         19 . The processor of  Claim 15 , wherein the operations further comprise verifying that the first network layer packet is from the first user entity based on a digital signature associated with the first user entity, the digital signature generated based on a public/private key pair authentication scheme. 
     
     
         20 . The processor of  Claim 15 , wherein the operations further comprise applying a policy to the received first network layer packet based on the first unique identification information.

Join the waitlist — get patent alerts

Track US2017302644A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.