×

Local authentication of a client at a network device

  • US 7,506,054 B1
  • Filed: 06/30/2003
  • Issued: 03/17/2009
  • Est. Priority Date: 07/02/1999
  • Status: Expired due to Fees
First Claim
Patent Images

1. A system for controlling access of a client to a network resource, the system comprising:

  • a network resource that is communicatively coupled to a network;

    a network firewall routing device that is communicatively coupled to the network and that is logically interposed between the client and the network resource, wherein the network firewall routing device comprises;

    a firewall that protects the network resource by means for selectively blocking messages initiated by client and directed to the network resource, wherein the firewall comprises;

    an external interface and an internal interface; and

    an Output Access Control List at the internal interface and an Input Access Control List at the external interface;

    an authentication server that is communicatively coupled to the network and to the network firewall routing device and comprising user profile information;

    means for creating and storing client authorization information at the network firewall routing device, based in part on the user profile information, wherein the client authorization information comprises information indicating whether the client is authorized to communicate with the network resource and information indicating what access privileges the client has with respect to the network resource;

    means for receiving a request from the client to communicate with the network resource;

    means for determining whether the client is authorized to communicate with the network resource based on the authorization information; and

    means for reconfiguring the network firewall routing device to permit the client to communicate with the network resource only when the client is authorized to communicate with the network resource based on the authorization information, wherein the means for reconfiguring the network firewall routing device opens a logical passageway for network traffic from the client, wherein the logical passageway does not automatically close when a user terminates a session, and wherein the means for reconfiguring the network firewall routing device further comprises;

    means for determining a current IP address of the client;

    means for creating a new user profile information, based on the user profile information, that includes the current IP address; and

    means for adding the new user profile information as temporary entries to the Input Access Control List at the external interface and to the Output Access Control List at the internal interface.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×