US2021289354A1PendingUtilityA1

System and method for policy-based extensible authentication protocol authentication

Assignee: AT & T IP I LPPriority: Aug 30, 2018Filed: Jun 1, 2021Published: Sep 16, 2021
Est. expiryAug 30, 2038(~12.1 yrs left)· nominal 20-yr term from priority
H04L 61/103H04L 2101/622H04L 2101/654H04W 12/06H04L 63/162H04W 8/04H04L 63/08H04L 63/0876H04W 84/12H04L 63/0853H04W 12/02H04W 8/18H04L 61/6022H04L 61/6054
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Aspects of the subject disclosure may include, for example, a device that includes a processing system and a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations such as receiving an extensible authentication protocol (EAP) authentication message addressed to an EAP authentication server from a communication device; extracting information from the EAP authentication message; determining whether to reject a request in the EAP authentication message of the communication device based on the information extracted; and sending an EAP Failure message to the communication device after intercepting an authentication and key agreement message from the communication device based on the determining indicating that the request should be rejected. Other embodiments are disclosed.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A device, comprising:
 a processing system including a processor; and   a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations, the operations comprising:   extracting information from an extensible authentication protocol (EAP) authentication message transmitted by a communication device, wherein the information identifies media access control (MAC) addresses of the communication device and of a WiFi access point (AP) associated with the communication device;   sending a first query to a database comprising the MAC address of the communication device to identify an international mobile subscriber identity (IMSI) of the communication device;   determining whether to reject a request in the EAP authentication message of the communication device based on the information, wherein the determining comprises sending a second query comprising the IMSI of the communication device and the MAC address of the WiFi AP to an external device, and receiving, from the external device, a result indicating whether to reject the request of the communication device, and wherein the request is to offload the communication device to a WiFi network; and   based on the result indicating that the request should be rejected and after intercepting an authentication and key agreement message from the communication device, sending an EAP Failure message to the communication device.   
     
     
         2 . The device of  claim 1 , wherein the processing system comprises a plurality of processors operating in a distributed processing environment. 
     
     
         3 . The device of  claim 1 , wherein the request is to offload the communication device to a WiFi network associated with the WiFi AP. 
     
     
         4 . The device of  claim 1 , wherein the database is stored in the memory of the device. 
     
     
         5 . The device of  claim 1 , wherein the result is determined by the external device by measuring an amount of communications traffic load on a radio access network (RAN) associated with the communication device. 
     
     
         6 . The device of  claim 1 , wherein the result is determined by the external device based on a status of a subscription plan of a subscriber using the communication device. 
     
     
         7 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor, facilitate performance of operations, the operations comprising:
 determining whether to reject a request in an extensible authentication protocol (EAP) authentication message transmitted by a communication device, based in part on an amount of communications traffic load on a radio access network supplying communications services to the communication device at an identified location of the communication device;   intercepting an authentication and key agreement message transmitted from the communication device responsive to an authentication and key agreement request message from an EAP authentication server; and   sending an EAP Failure message to the communication device based on a determination that the request should be rejected, after intercepting the authentication and key agreement message.   
     
     
         8 . The non-transitory machine-readable medium of  claim 7 , wherein the operations further comprise forwarding the EAP authentication message to the EAP authentication server based on the determining indicating that the request should not be rejected. 
     
     
         9 . The non-transitory machine-readable medium of  claim 7 , wherein the operations further comprise sending a query to a database comprising a media access control (MAC) address of the communication device and receiving an IMSI of the communication device. 
     
     
         10 . The non-transitory machine-readable medium of  claim 9 , wherein the database is stored in the non-transitory machine-readable medium. 
     
     
         11 . The non-transitory machine-readable medium of  claim 9 , wherein the determining decides whether to offload the communication device from the radio access network to a WiFi network based on the IMSI of the communication device. 
     
     
         12 . The non-transitory machine-readable medium of  claim 7 , wherein the identified location of the communication device is determined based on a media access control (MAC) address of a WiFi access point associated with the communication device. 
     
     
         13 . The non-transitory machine-readable medium of  claim 7 , wherein the identified location of the communication device is determined from global positioning system (GPS) information. 
     
     
         14 . The non-transitory machine-readable medium of  claim 7 , wherein the processing system comprises a plurality of processors operating in a distributed processing environment. 
     
     
         15 . The non-transitory machine-readable medium of  claim 7 , wherein the determining decides whether to offload the communication device from the radio access network to a WiFi network based on the identified location of the communication device. 
     
     
         16 . A method comprising:
 intercepting, by a processing system including a processor, an authentication and key agreement message transmitted from a communication device;   determining, by the processing system, whether to reject a request in an extensible authentication protocol (EAP) authentication message transmitted by the communication device, based in part on an amount of communications traffic load on a radio access network supplying communications services to the communication device at an identified location of the communication device; and   causing, by the processing system, an EAP Failure message to be transmitted to the communication device after intercepting the authentication and key agreement message and based on a determination that the request should be rejected.   
     
     
         17 . The method of  claim 16 , further comprising forwarding the EAP authentication message to an EAP authentication server based on the determining indicating that the request should not be rejected. 
     
     
         18 . The method of  claim 16 , further comprising sending a query to a database comprising a media access control (MAC) address of the communication device and receiving an IMSI of the communication device. 
     
     
         19 . The method of  claim 18 , wherein the determining decides whether to offload the communication device from a communications network to a WiFi network based on the IMSI of the communication device. 
     
     
         20 . The method of  claim 16 , wherein the identified location of the communication device is determined from global positioning system (GPS) information.

Join the waitlist — get patent alerts

Track US2021289354A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.