Controlling access to resources in a network
US-9436820-B1 · Sep 6, 2016 · US
US12047382B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12047382-B2 |
| Application number | US-202016904929-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 18, 2020 |
| Priority date | Aug 31, 2012 |
| Publication date | Jul 23, 2024 |
| Grant date | Jul 23, 2024 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Techniques for managing access control policies are described herein. According to one embodiment, access control policies (ACPs) and access control rules (ACRs) are downloaded from a management server to a network access device (NAD) over the Internet, where the network access device is one of a plurality of network access devices managed by the management server over the Internet. In response to a request from a network client device for entering a network, a device type of the network client device is detected and an ACP identifier is determined based on the device type using the ACRs An ACP is selected from the ACPs based on the ACP identifier and enforced against the network client device. At least the selected ACP is reported to the management server to distribute the selected ACP to other network access devices.
Opening claim text (preview).
What is claimed is: 1. A method comprising: determining, at a network access device communicating on a local area network and a wide area network (WAN), one or more characteristics of a device from which one or more network packets are received at the network access device; identifying, at the network access device, an access control rule for the device based on the one or more characteristics of the device; assigning, by the network access device, the access control rule to at least one of the device or network traffic associated with the device; reporting, by the network access device, the access control rule to a network management server to be propagated to other network access devices for use when the device roams on one or more of the other network access devices, the other network access devices not being part of the network in which the network access device operates, wherein information exchanged between devices attached to different corresponding local area networks and the local area network are exchanged via the WAN; before receiving, by the network access device, information originating from a roaming device not authorized to communicate, or authenticated with the local area network, receiving, from the network management server, propagated access control rules including a second access control rule of the roaming device communicating on and authenticated with the different corresponding local area network; receiving, at the network access device, a request from a roaming device to roam on the network access device subsequent to the receiving of the second access control rule; and in response to the request, providing, by the network access device, the authorization for network connectivity with the local area network for the roaming device according to the received second access control rule without re-authenticating the roaming device. 2. The method of claim 1 , wherein the one or more characteristics of the device comprise an indication of a manufacturer of the device, wherein the manufacturer of the device is identified based on a media access control (MAC) address associated with the device. 3. The method of claim 1 , wherein the one or more characteristics of the device comprise an indication of a device type associated with the device, wherein the access control rule for the device is identified from a plurality of rules based on the indication of the device type. 4. The method of claim 3 , wherein the device type is identified based on at least one of dynamic host control protocol (DHCP) information associated with the device or a user agent identified in a header associated with the one or more network packets generated by the device. 5. The method of claim 3 , wherein the indication of the device type comprises an indication of at least one of a type of operating system, a type of mobile device, or a type of wireless device, the access control rule being identified based on the at least one of the type of operating system, the type of mobile device, or the type of wireless device. 6. The method of claim 1 , further comprising: receiving at least one of the one or more network packets from the device; selecting the access control rule assigned to the at least one of the device or the network traffic associated with the device; and applying the access control rule to the at least one of the one or more network packets from the device. 7. The method of claim 1 , further comprising: sending, to one or more additional devices associated with the network, updated access control information comprising a first indication of the access control rule assigned to the at least one of the device or the network traffic associated with the device and a second indication of the one or more characteristics of the device. 8. The method of claim 1 , wherein the access control rule comprises at least one of a bandwidth limit, a traffic shaping rule, a virtual local area network (VLAN) assignment, or a firewall rule. 9. A network access device comprising: one or more processors; and at least one non-transitory computer-readable storage medium having stored thereon instructions which, when executed by the one or more processors, cause the one or more processors to: determine, a t the network access device that is communications on a local area network and a wile area network (WAN), one or more characteristics of a device from which one or more network packets are received at the network access device; identify an access control rule for the device based on the one or more characteristics of the device; assign the access control rule to at least one of the device or network traffic associated with the device; report the access control rule to a network management server to be propagated to other network access devices for use when the device roams on one or more of the other network access devices, the other network access devices not being p art of the network in which the network access device operates, wherein information exchanged between devices attached to different corresponding local area networks and the local area network are exchanged via the WAN; before receiving information originating from a roaming device not authorized to communicate, or authenticated with the local area network, receive, from the network management server, propagated access control rules including a second access control rule of the roaming device communicating on and authenticated with the different corresponding local area network; receive a request from a roaming device to roam on the network access device subsequent to the receiving of the second access control rule; and in response to the request, provide the authorization for network connectivity with the local area network for the roaming device according to the received second access control rule without re-authenticating the roaming device. 10. The network access device of claim 9 , wherein the one or more characteristics of the device comprise an indication of a manufacturer of the device, wherein the manufacturer of the device is identified based on a media access control (MAC) address associated with the device. 11. The network access device of claim 9 , wherein the one or more characteristics of the device comprise an indication of a device type associated with the device, wherein the access control rule for the device is identified from a plurality of rules based on the indication of the device type. 12. The network access device of claim 11 , wherein the device type is identified based on at least one of dynamic host control protocol (DHCP) information associated with the device or a user agent identified in a header associated with the one or more network packets generated by the device. 13. The network access device of claim 11 , wherein the indication of the device type comprises an indication of at least one of a type of operating system, a type of mobile device, or a type of wireless device, the access control rule being identified based on the at least one of the type of operating system, the type of mobile device, or the type of wireless device. 14. The network access device of claim 9 , the at least one non-transitory computer-readable storage medium storing instructions which, when executed by the one or more processors, cause the one or more processors to: receive at least one of the one or more network packets from the device; select the access control rule assigned to the at least one of the device or the network traffic associated with the device; and apply the access control rule to the at least one of the one or more network packets from the device.
Policy-based network configuration management · CPC title
based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Protocols · CPC title
based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.