Patent No. US8499166 (titled "Controlling access to a protected network") on Jul 13, 2012. The application was issued on Jul 30, 2013.
’166 is related to the field of enterprise network security and user authentication. Specifically, it addresses the vulnerabilities of traditional username and password systems and the hardware inconsistencies encountered when using computer-based biometric sensors, such as varying microphone quality across different workstation models.
The underlying idea behind ’166 is to decouple the authentication hardware from the workstation itself by using a secondary, standardized communication device—such as an office telephone—as the primary security gateway. By utilizing the consistent audio quality of a telephone handset for voice biometrics, the system ensures a reliable and high-fidelity signal for authentication while bypassing the need for the user to manually enter credentials into the computer.
The claims of ’166 focus on a multi-stage verification process where a network access control module first identifies a specific communication device via a unique identifier, then authenticates the user through that device, and finally establishes a separate secure channel to inject log-on credentials directly into the computer’s log-on interface. This architecture ensures that the computer only grants access after an out-of-band confirmation is received from the trusted secondary device.
In practice, the invention works by having the user initiate a log-on sequence directly from their telephone, often via a dedicated button. The system identifies the phone's hardware ID, prompts the user for a voiceprint or a response to a challenge question, and, upon successful verification, automatically pushes the necessary credentials to the workstation's GINA or web-based log-on interface. This creates a hands-free login experience for the user while maintaining high security standards.
This approach differs from prior solutions by eliminating the user's knowledge of the actual password, as the system submits the log-on information directly to the computer's operating system. By routing the biometric data through a controlled telephony environment rather than a generic PC microphone, the invention solves the problem of high false-rejection rates caused by poor hardware, effectively turning the office phone into a standardized security token.
In the mid-2000s when ’166 was filed, enterprise network security was typically implemented using alphanumeric credentials entered directly into a workstation terminal. At a time when systems commonly relied on local hardware peripherals for biometric capture, such as integrated computer microphones or specialized scanners, hardware and software constraints made consistent authentication non-trivial due to varying signal quality and driver performance across heterogeneous device fleets. Engineering practices during this era generally treated the workstation as the primary interface for both the authentication request and the credential submission, often resulting in a single-channel security model that was susceptible to credential misappropriation or localized hardware limitations.
The disclosed invention represents a meaningful technical advancement through an architectural shift that decouples the authentication path from the primary computing terminal. By integrating a separate communication device that transmits a unique hardware identifier to a network access control module, the system establishes a multi-factor trust relationship that validates both the hardware and the user before access is granted. This structural solution overcomes the technical constraint of inconsistent audio capture quality on standard computers by utilizing a dedicated communication device for voice biometric verification. The resulting technical effect is the ability to securely inject log-on information directly into a computer's interface from a remote control module only after out-of-band authentication is successful, effectively isolating the credential submission process from the local workstation environment.
This patent includes a total of 25 claims, with claims 1, 11, 19, 21, and 25 serving as the independent claims. The independent claims focus on a multi-stage security architecture for controlling network access, specifically utilizing a separate communication device to transmit a unique identifier that triggers a sequence of device authentication, user authentication, and the subsequent delivery of log-on credentials directly to a computer's interface via a secure channel. The dependent claims serve to further define the system by specifying hardware features like dedicated log-on buttons, incorporating biometric data such as voice verification, detailing specific network identifiers like IP or MAC addresses, and outlining the use of web services and access control rules to manage the authentication process.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents