×

Multiple tiered network security system, method and apparatus using dynamic user policy assignment

  • US 7,735,114 B2
  • Filed: 09/04/2003
  • Issued: 06/08/2010
  • Est. Priority Date: 09/04/2003
  • Status: Active Grant
First Claim
Patent Images

1. A network access device comprising:

  • a plurality of input ports;

    a memory for storing data packets received on the plurality of input ports;

    a switching fabric configured for packet switching of the data packets to at least one output port; and

    control logic adapted to;

    examine a first data packet comprising a physical address of a user device coupled to one of the plurality of input ports;

    authenticate the physical address;

    if the authentication of the physical address indicates the physical address is valid, authenticate one or more user credentials provided in a second data packet by a user of the user device after the physical address is authenticated;

    if the authentication of the one or more user credentials indicates the one or more user credentials are valid, determine if the network access device has sufficient system resources to dynamically configure a user policy;

    if the determination indicates the network access device has sufficient system resources, dynamically assign the user policy to the one of the plurality of input ports; and

    restrict further traffic on the one of the plurality of input ports in accordance with the user policy; and

    if the authentication of the physical address indicates the physical address is invalid, or if the determination indicates insufficient system resources, block traffic on the one of the plurality of ports except for packets related to a user authentication protocol.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×