Patent No. US8225103 (titled "Controlling access to a protected network") on Oct 24, 2006. The application was issued on Jul 17, 2012.
’103 is related to the field of network security and enterprise access control. Specifically, it addresses the vulnerabilities of traditional username and password systems by leveraging secondary hardware devices and biometric verification to manage how users log into workstations connected to a protected network.
The underlying idea behind ’103 is to decouple the authentication process from the workstation itself by using a separate, trusted communication device—such as an office telephone—as the primary security gateway. By shifting the authentication load to a device with consistent hardware specifications, the system avoids the security risks associated with varying microphone quality on different computers, enabling more reliable voice biometric verification.
The claims of ’103 focus on a multi-stage authentication sequence initiated by a dedicated hardware trigger. The process requires a network access control module to first identify a specific communication device via a unique identifier sent upon pressing a dedicated log-on button, then authenticate the human user through that device, and finally inject log-on credentials directly into the workstation’s log-on interface via a separate secure channel.
In practice, the system functions as a hardware-based gatekeeper where the user never needs to manually enter or even know their network password. When a user presses the log-on button on their desk phone, the server verifies the phone's identity and prompts the user for a voice sample or an answer to a challenge question. Once the server confirms the user's identity, it establishes a secure communication channel with the computer to automatically populate the log-on fields, effectively bypassing the need for manual keyboard entry.
This approach differentiates itself from prior solutions by eliminating the workstation as a point of failure for biometric capture. By using the PBX infrastructure or a dedicated telephone network for the initial handshake, the invention ensures that sensitive credentials are only transmitted to the computer after out-of-band authentication is complete. This creates a high-assurance environment where stolen passwords or compromised workstation peripherals are insufficient to gain unauthorized network access.
In the mid-2000s when ’103 was filed, enterprise network security was typically implemented using alphanumeric credentials entered directly into a workstation to gain access to protected resources. At a time when systems commonly relied on local peripheral inputs for authentication, the varying quality and performance of integrated hardware components made the reliable capture of biometric data non-trivial. Furthermore, when hardware constraints necessitated a trade-off between authentication sensitivity and user accessibility, network access control was generally centralized at the workstation level, requiring the user to interact solely with the terminal requesting access.
The disclosed invention represents a technical advancement in secure network access through an architectural shift that decouples the authentication medium from the primary computing terminal. By utilizing a separate communication device that transmits a unique identifier to a network access control module, the system establishes a multi-stage trust relationship that authenticates both the hardware and the user before any credentials are exchanged. This integration allows for the secure capture of voice biometrics on a verified device, overcoming the technical constraint of inconsistent audio hardware on enterprise computers. The capability enabled by this architecture allows the system to inject log-on information directly into the computer's interface only after external verification, effectively isolating the sensitive authentication process from the workstation's local environment.
The patent contains 24 claims, with claims 1, 10, 18, 20, and 24 serving as the independent claims. These independent claims focus on a system, method, server, and computer-readable medium for managing access to a protected network by utilizing a communication device with a dedicated log-on button to transmit a unique identifier, which triggers a multi-stage authentication process that ultimately submits user log-on credentials directly to a computer interface via a secure channel. The dependent claims serve to further specify technical details such as the use of biometric data for user verification, the storage of access control rules, the specific types of unique identifiers like MAC addresses or phone numbers, and the implementation of the network access control module as a web service.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents