Controlling access to a protected network

Patent No. US8225103 (titled "Controlling access to a protected network") on Oct 24, 2006. The application was issued on Jul 17, 2012.

What is this patent about?

’103 is related to the field of network security and enterprise access control. Specifically, it addresses the vulnerabilities of traditional username and password systems by leveraging secondary hardware devices and biometric verification to manage how users log into workstations connected to a protected network.

The underlying idea behind ’103 is to decouple the authentication process from the workstation itself by using a separate, trusted communication device—such as an office telephone—as the primary security gateway. By shifting the authentication load to a device with consistent hardware specifications, the system avoids the security risks associated with varying microphone quality on different computers, enabling more reliable voice biometric verification.

The claims of ’103 focus on a multi-stage authentication sequence initiated by a dedicated hardware trigger. The process requires a network access control module to first identify a specific communication device via a unique identifier sent upon pressing a dedicated log-on button, then authenticate the human user through that device, and finally inject log-on credentials directly into the workstation’s log-on interface via a separate secure channel.

In practice, the system functions as a hardware-based gatekeeper where the user never needs to manually enter or even know their network password. When a user presses the log-on button on their desk phone, the server verifies the phone's identity and prompts the user for a voice sample or an answer to a challenge question. Once the server confirms the user's identity, it establishes a secure communication channel with the computer to automatically populate the log-on fields, effectively bypassing the need for manual keyboard entry.

This approach differentiates itself from prior solutions by eliminating the workstation as a point of failure for biometric capture. By using the PBX infrastructure or a dedicated telephone network for the initial handshake, the invention ensures that sensitive credentials are only transmitted to the computer after out-of-band authentication is complete. This creates a high-assurance environment where stolen passwords or compromised workstation peripherals are insufficient to gain unauthorized network access.

How does this patent fit in bigger picture?

Technical Landscape

In the mid-2000s when ’103 was filed, enterprise network security was typically implemented using alphanumeric credentials entered directly into a workstation to gain access to protected resources. At a time when systems commonly relied on local peripheral inputs for authentication, the varying quality and performance of integrated hardware components made the reliable capture of biometric data non-trivial. Furthermore, when hardware constraints necessitated a trade-off between authentication sensitivity and user accessibility, network access control was generally centralized at the workstation level, requiring the user to interact solely with the terminal requesting access.

Prosecution Position

The disclosed invention represents a technical advancement in secure network access through an architectural shift that decouples the authentication medium from the primary computing terminal. By utilizing a separate communication device that transmits a unique identifier to a network access control module, the system establishes a multi-stage trust relationship that authenticates both the hardware and the user before any credentials are exchanged. This integration allows for the secure capture of voice biometrics on a verified device, overcoming the technical constraint of inconsistent audio hardware on enterprise computers. The capability enabled by this architecture allows the system to inject log-on information directly into the computer's interface only after external verification, effectively isolating the sensitive authentication process from the workstation's local environment.

Claims

The patent contains 24 claims, with claims 1, 10, 18, 20, and 24 serving as the independent claims. These independent claims focus on a system, method, server, and computer-readable medium for managing access to a protected network by utilizing a communication device with a dedicated log-on button to transmit a unique identifier, which triggers a multi-stage authentication process that ultimately submits user log-on credentials directly to a computer interface via a secure channel. The dependent claims serve to further specify technical details such as the use of biometric data for user verification, the storage of access control rules, the specific types of unique identifiers like MAC addresses or phone numbers, and the implementation of the network access control module as a web service.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Dedicated log-on button
(Claim 1, Claim 10, Claim 18, Claim 20)
The communication device automatically transmits a unique identifier corresponding to the communication device to the network access control module when a user uses the communication device to request access. This request is triggered by the user activating a dedicated log-on button on the communication device. The activation of this button initiates the multi-stage authentication process involving both the device and the user.A specific physical or virtual button on a communication device that, when activated by a user, triggers the automatic transmission of a unique device identifier to initiate a network access request.
Log-on interface
(Claim 1, Claim 10, Claim 18, Claim 20, Claim 24)
When the user is authenticated, the system submits log-on information directly to a log-on interface of the computer associated with the communication device. This allows the user to access the protected network via the computer. The submission to the interface causes the computer to use the log-on information to provide access.The specific software component or entry point of a computer (such as a credential provider or login screen) that receives authentication credentials to grant access to the operating system or network.
Network access control module
(Claim 1, Claim 10, Claim 20)
A network access control module is coupled to the protected network and is configured to restrict access to the network to an authorized user through a computer. It receives the unique identifier, authenticates the communication device, and then authenticates the user via the communication device. It is responsible for submitting log-on information directly to the computer's log-on interface.A functional entity, often residing on a server, that manages and restricts access to a protected network by performing multi-factor authentication of both a communication device and a user.
Secure communication channel
(Claim 1, Claim 10, Claim 18, Claim 20, Claim 24)
The communication interface is configured to receive over a first secure communication channel a unique identifier corresponding to a separate communication device. When the user is authenticated, the module transmits over a second secure communication channel log-on information to a log-on interface of the computer. These channels ensure that sensitive and confidential information remains protected during the authentication process.An encrypted or protected data path established between the network access control module and either the communication device or the computer to safely transmit authentication data and log-on credentials.
Unique identifier
(Claim 1, Claim 10, Claim 18, Claim 20, Claim 24)
The communication device automatically transmits a unique identifier corresponding to the communication device to the network access control module. The network access control module is configured to authenticate the communication device based on the unique identifier. This ensures the hardware is recognized before proceeding to user authentication.A specific data string or code assigned to a communication device that allows a network access control module to identify and authenticate the hardware of the device itself, independently of the user's identity.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-03640Apr 24, 2025Avatier IP, LLC v. Microsoft Corporation

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US8225103

Application Number
US11552313A
Filing Date
Oct 24, 2006
Publication Date
Jul 17, 2012
External Links
Slate, USPTO , Google Patents