Controlling access to a protected network

Patent No. US8499166 (titled "Controlling access to a protected network") on Jul 13, 2012. The application was issued on Jul 30, 2013.

What is this patent about?

’166 is related to the field of enterprise network security and user authentication. Specifically, it addresses the vulnerabilities of traditional username and password systems and the hardware inconsistencies encountered when using computer-based biometric sensors, such as varying microphone quality across different workstation models.

The underlying idea behind ’166 is to decouple the authentication hardware from the workstation itself by using a secondary, standardized communication device—such as an office telephone—as the primary security gateway. By utilizing the consistent audio quality of a telephone handset for voice biometrics, the system ensures a reliable and high-fidelity signal for authentication while bypassing the need for the user to manually enter credentials into the computer.

The claims of ’166 focus on a multi-stage verification process where a network access control module first identifies a specific communication device via a unique identifier, then authenticates the user through that device, and finally establishes a separate secure channel to inject log-on credentials directly into the computer’s log-on interface. This architecture ensures that the computer only grants access after an out-of-band confirmation is received from the trusted secondary device.

In practice, the invention works by having the user initiate a log-on sequence directly from their telephone, often via a dedicated button. The system identifies the phone's hardware ID, prompts the user for a voiceprint or a response to a challenge question, and, upon successful verification, automatically pushes the necessary credentials to the workstation's GINA or web-based log-on interface. This creates a hands-free login experience for the user while maintaining high security standards.

This approach differs from prior solutions by eliminating the user's knowledge of the actual password, as the system submits the log-on information directly to the computer's operating system. By routing the biometric data through a controlled telephony environment rather than a generic PC microphone, the invention solves the problem of high false-rejection rates caused by poor hardware, effectively turning the office phone into a standardized security token.

How does this patent fit in bigger picture?

Technical Landscape

In the mid-2000s when ’166 was filed, enterprise network security was typically implemented using alphanumeric credentials entered directly into a workstation terminal. At a time when systems commonly relied on local hardware peripherals for biometric capture, such as integrated computer microphones or specialized scanners, hardware and software constraints made consistent authentication non-trivial due to varying signal quality and driver performance across heterogeneous device fleets. Engineering practices during this era generally treated the workstation as the primary interface for both the authentication request and the credential submission, often resulting in a single-channel security model that was susceptible to credential misappropriation or localized hardware limitations.

Prosecution Position

The disclosed invention represents a meaningful technical advancement through an architectural shift that decouples the authentication path from the primary computing terminal. By integrating a separate communication device that transmits a unique hardware identifier to a network access control module, the system establishes a multi-factor trust relationship that validates both the hardware and the user before access is granted. This structural solution overcomes the technical constraint of inconsistent audio capture quality on standard computers by utilizing a dedicated communication device for voice biometric verification. The resulting technical effect is the ability to securely inject log-on information directly into a computer's interface from a remote control module only after out-of-band authentication is successful, effectively isolating the credential submission process from the local workstation environment.

Claims

This patent includes a total of 25 claims, with claims 1, 11, 19, 21, and 25 serving as the independent claims. The independent claims focus on a multi-stage security architecture for controlling network access, specifically utilizing a separate communication device to transmit a unique identifier that triggers a sequence of device authentication, user authentication, and the subsequent delivery of log-on credentials directly to a computer's interface via a secure channel. The dependent claims serve to further define the system by specifying hardware features like dedicated log-on buttons, incorporating biometric data such as voice verification, detailing specific network identifiers like IP or MAC addresses, and outlining the use of web services and access control rules to manage the authentication process.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Communication device
(Claim 1, Claim 11, Claim 19, Claim 21, Claim 25)
The system includes a communication device associated with the computer. The user is prompted to submit a voice response via a microphone, which should be of a quality such that an authentication application can accurately match the voice response to a stored sample. The communication device transmits a unique identifier to the network access control module to initiate the authentication process.A hardware device separate from the computer being used to access the network, utilized to provide device identification and user authentication (such as voice biometrics).
Log-on interface
(Claim 1, Claim 11, Claim 19, Claim 21, Claim 25)
When the user is authenticated, the system submits log-on information directly to a log-on interface of the computer associated with the communication device. This causes the computer to use said log-on information to provide the user access to the protected network. This process allows the user to access the network via the computer after being authenticated through the separate communication device.The specific software entry point or credential input mechanism of a computer through which access to the protected network is granted.
Network access control module
(Claim 1, Claim 11, Claim 21)
The network access control module is configured to restrict access to the network to an authorized user through a computer coupled to the protected network. It receives a unique identifier to authenticate the communication device and then authenticates the user via that device. Once authenticated, it submits log-on information directly to a log-on interface of the computer.A component coupled to a protected network that restricts access to authorized users by authenticating both a communication device and the user, and subsequently delivering log-on credentials to a target computer.
Secure communication channel
(Claim 1, Claim 11, Claim 19, Claim 21, Claim 25)
The communication interface is configured to receive over a first secure communication channel a unique identifier corresponding to a separate communication device. The network access control module is configured to establish a second secure communication channel and transmit log-on information of the user to a log-on interface of the computer. These channels ensure that sensitive authentication and log-on information are protected during transmission.A protected data path established between the control module and the computer or communication device to safely transmit authentication data or log-on credentials.
Unique identifier
(Claim 1, Claim 11, Claim 19, Claim 21, Claim 25)
The communication device automatically transmits a unique identifier corresponding to the communication device to the network access control module when a user uses the communication device to request access. The network access control module is configured to authenticate the communication device based on the unique identifier. This ensures the device itself is authorized before user authentication occurs.A distinct code or data string transmitted automatically by a communication device upon initiation of a log-on process to identify the specific hardware device to the control module.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-03640Apr 24, 2025Avatier IP, LLC v. Microsoft Corporation

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US8499166

Application Number
US13549091A
Filing Date
Jul 13, 2012
Publication Date
Jul 30, 2013
External Links
Slate, USPTO , Google Patents