EP1588261A1

Security apparatus and method for protecting access to local area networks

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 10 September 2023, 3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

45 claims: 45 independent, 0 dependent

  1. 1
    Claims of equivalent WO 2004025472 A1 CLAIMS We claim:1. A method for blocking access to one or more protected devices each having a physical device address on a computer network by a client device having a physical device address, comprising the steps of: (a) receiving address resolution requests broadcast on the network by the client device seeking access to one of the protected devices;(b) processing the address resolution requests to determine whether the client device is an unknown device;(c) if the client device is unknown as determined in step (b), transmitting address resolution replies on the computer network to block access to the protected devices and allow access to an authentication server;(d) if the client device is unknown as determined in step (b), monitoring the authentication server to determine if the client device is authorized or unauthorized by the authentication server;(e) if the client device is authorized as determined in step (d), allowing access to the protected devices;and (f) if the client device is unauthorized as determined in step (d), transmitting blocking address resolution replies on the computer network to block access to the protected devices.
  2. 2
    The method recited in claim 1 , wherein the restriction address resolution replies contain a source physical device address corresponding to the physical device address of the client device, an is-at physical device address different than the physical device address of the client device, and a destination physical device address corresponding to the physical device address of one of the protected devices.
  3. 3
    The method recited in claim 2, wherein the is-at physical device address is a randomly changing physical device address pre-determined to not be connected to the computer network.
  4. 4
    The method recited in claim 1 , wherein the blocking address resolution replies contain a source physical device address corresponding to the physical device address of the client device, an is-at physical device address different than the physical device address of the client device, and a destination physical device address corresponding to a broadcast address.
  5. 5
    The method recited in claim 2, wherein the is-at physical device address is a randomly changing physical device address pre-determined to not be connected to the computer network.
  6. 6
    The method recited in claim 1 , further comprising the steps of:(g) if the blocking address replies are transmitting in accordance with step (f), transmitting an address resolution request on the computer network destined for the client device;(h) if an address resolution reply is received in response to the transmitted address resolution request, determining whether the responsive address resolution reply contains a source physical device address corresponding to the physical device address of the client device;(i) if the source physical device address of the responsive address resolution reply and the physical device address of the client device are the same as determined in step (h), repeating step (g);(j) if the source physical device address of the responsive address resolution reply and the physical device address of the client device are different as determined in step (h), ceasing the transmission of the blocking address resolution replies.
  7. 7
    The method recited in claim 1 , further comprising the steps of:(g) if access is allowed in accordance with step (e), transmitting an address resolution request on the computer network destined for the client device;(h) if an address resolution reply is received in response to the transmitted address resolution request, determining whether the responsive address resolution reply contains a source physical device address corresponding to the physical device address of the client device;(i) if the source physical device address of the responsive address resolution reply and the physical device address of the client device are the same as determined in step (h), repeating step (g);(j) if the source physical device address of the responsive address resolution reply and the physical device address of the client device are different as determined in step (h), ceasing allowing the client device access to the protected devices.
  8. 8
    The method recited in claim 1 , further comprising the step of:transmitting correction address resolution requests on the computer network to update the client device with the physical device address of the protected devices.
  9. 9
    The method recited in claim 8, wherein the correction address resolution replies contain a is-at physical device address corresponding to the physical device address of one of the one or more protected devices and a destination physical device address corresponding to a broadcast address.
  10. 10
    The method recited in claim 1 , wherein no dedicated software is required on the client device.
  11. 11
    The method recited in claim 1 , wherein the blocking address resolution replies are configured to disable the client device.
  12. 12
    An apparatus for blocking access to one or more protected devices each having a physical device address on a computer network by a client device having a physical device address, comprising the steps of:means for receiving address resolution requests broadcast on the network by the client device seeking access to one of the protected devices;means for processing the address resolution requests to determine whether the client device is an unknown device;means for transmitting address resolution replies on the computer network to block access to the protected devices and allow access to an authentication server if the client device is unknown;means for monitoring the authentication server to determine if the client device is authorized or unauthorized by the authentication server if the client device is unknown;means for allowing access to the protected devices if the client device is authorized;and means for transmitting blocking address resolution replies on the computer network to block access to the protected devices if the client device is unauthorized.
  13. 13
    The apparatus recited in claim 12, wherein the restriction address resolution replies contain a source physical device address corresponding to the physical device address of the client device, an is-at physical device address different than the physical device address of the client device, and a destination physical device address corresponding to the physical device address of one of the protected devices.
  14. 14
    The apparatus recited in claim 13, wherein the is-at physical device address is a randomly changing physical device address pre-determined to not be connected to the computer network.
  15. 15
    The apparatus recited in claim 12, wherein the blocking address resolution replies contain a source physical device address corresponding to the physical device address of the client device, an is-at physical device address different than the physical device address of the client device, and a destination physical device address corresponding to a broadcast address.
  16. 16
    The apparatus recited in claim 15, wherein the is-at physical device address is a randomly changing physical device address pre-determined to not be connected to the computer network.
  17. 17
    The apparatus recited in claim 12, further comprising:means for transmitting an address resolution request on the computer network destined for the client device if blocking address replies are transmitted;means for receiving an address resolution reply in response to the transmitted address resolution request;means for determining whether the responsive address resolution reply contains a source physical device address different than the physical device address of the client device;and means for ceasing the transmission of the blocking address resolution replies if the source physical device address of the responsive address resolution reply is different than the physical device address of the client device.
  18. 18
    The apparatus recited in claim 12, further comprising the steps of:means for transmitting an address resolution request on the computer network destined for the client device if the client is allowed access to the protected devices;means for transmitting an address resolution request on the computer network destined for the client device if blocking address replies are transmitted;means for receiving an address resolution reply in response to the transmitted address resolution request;means for determining whether the responsive address resolution reply contains a source physical device address corresponding to the physical device address of the client device;and means for disallowing access to the protected devices by the client device if the source physical device address of the responsive address resolution reply is different than the physical device address of the client device.
  19. 19
    The apparatus recited in claim 12, further comprising:means for transmitting correction address resolution requests on the computer network to update the client device with the physical device address of the protected devices.
  20. 20
    The apparatus recited in claim 19, wherein the correction address resolution replies contain a is-at physical device address corresponding to the physical device address of one of the one or more protected devices and a destination physical device address corresponding to a broadcast address.
  21. 21
    The apparatus recited in claim 12, wherein the apparatus is connected as a peer device on the computer network.
  22. 22
    The apparatus recited in claim 12, wherein no dedicated software is required in the client device.
  23. 23
    The apparatus recited in claim 12, wherein the blocking address resolution replies are configured to disable the client device.
  24. 24
    A method for blocking access to one or more protected devices each having a physical device address and being connected to a computer network by a client device having a physical device address and being connected to the computer network, comprising the steps of:(a) receiving address resolution requests broadcast on the network by the client device seeking access to one of the protected devices;(b) processing the address resolution requests to determine whether the client device is an unknown device;(c) if the client device is unknown as determined in step (b), adding a record identifying the client device in a restricted client list;(d) while the client device record is present in the restricted client list, transmitting address resolution replies on the computer network to block access to the protected devices and allow access to an authentication server, and monitoring the authentication server to determine if the client device is authorized or unauthorized by the authentication server;(e) if the client device is authorized as determined in step (d), removing the client device record from the restricted client list and adding the client device record to an allowed client list;(f) while the client device record is present in the allowed client list, allowing access to the protected devices;(g) if the client device is unauthorized as determined in step (d), removing the client device record from the restricted client list and adding the client device record to a blocked client list;and (h) while the client device record is present in the blocked client list, transmitting blocking address resolution replies on the computer network to block access to the protected devices.
  25. 25
    The method recited in claim 24, further comprising the steps of:(i) determining when the client device is no longer connected to the computer network;and (j) when the client device is no longer connected to the computer network, removing the client device record from the allowed client list if the client device record is in the allowed client list and removing the client device record from the blocked client list if the client device record is in the blocked client list.
  26. 26
    An apparatus for controlling access to one or more protected devices each having a physical device address on a computer network by a client device having a physical device address, comprising:a central processing unit;a network interface configured to receive address resolution requests broadcast on the network by the client device seeking access to one of the protected devices and to transmit address resolution replies generated by the apparatus on the computer network;and a security module running on the central processing unit and configured to: (a) process the address resolution requests from the client device to determine whether the client device is unknown;(b) transmit address resolution replies on the computer network to block access to the protected devices and allow access to an authentication server, if the client device is unknown;(c) monitor the authentication server to determine if the client device is authorized or unauthorized by the authentication server, if the client device is unknown;(d) allow access to the protected devices, if the client device is authorized;and (e) transmit blocking address resolution replies on the computer network to block access to the protected devices, if the client device is unauthorized;wherein the apparatus is connected as a peer device on the computer network.
  27. 27
    The apparatus recited in claim 26, wherein the security module is further configured to:determine if the client device is connected to the computer network;wherein the access blocking module ceases blocking data link layer access to the network devices by the client device if the client device is no longer connected to the computer network;and wherein the access monitoring module causes the detection module to determine that the client device is unknown if the client device subsequently attempts to access the protected devices.
  28. 28
    The apparatus recited in claim 26, wherein the security module is further configured to transmit correction address resolution requests on the computer network to update the client device with the physical device address of the protected devices.
  29. 29
    The apparatus recited in claim 26, wherein the restriction address resolution replies contain a source physical device address corresponding to the physical device address of the client device, an is-at physical device address different than the physical device address of the client device, and a destination physical device address corresponding to the physical device address of one of the protected devices.
  30. 30
    The apparatus recited in claim 26, wherein the blocking address resolution replies contain a source physical device address corresponding to the physical device address of the client device, an is-at physical device address different than the physical device address of the client device, and a destination physical device address corresponding to a broadcast address.
  31. 31
    An apparatus for controlling access to one or more network devices, including one or more protected devices among the network devices, each having a physical device address on a computer network by a client device having a physical device address, comprising:a central processing unit;a network interface configured to receive address resolution requests broadcast on the network by the client device seeking access to one of the protected devices;a detection module running on the central processor and configured to process the address resolution requests from the client device to determine whether the client device is unknown;an access restriction module running on the central processor and configured to block data link layer access to the protected devices and allow access to an authentication server, if the client device is unknown;an authentication monitoring module running on the central processor and configured to monitor the authentication server to determine if the client device is authorized or unauthorized by the authentication server, if the client device is unknown;and an access blocking module running on the central processor and configured to block data link layer access to the network devices on the computer network, if the client device is unauthorized;wherein the apparatus is connected as a peer device on the computer network;and wherein the apparatus does not require dedicated software on the client device in order to control access to the network devices.
  32. 32
    The apparatus recited in claim 31 , further comprising:an access monitoring module running on the central processing unit and configured to determine if the client device is connected to the computer network;wherein the access blocking module ceases blocking data link layer access to the network devices by the client device if the client device is no longer connected to the computer network;and wherein the access monitoring module causes the detection module to determine that the client device is unknown if the client device subsequently attempts to access the protected devices.
  33. 33
    The apparatus recited in claim 31 , further comprising:a correction module running on the central processor and configured to transmit correction address resolution requests on the computer network via the network interface to update the client device with the physical device address of the protected devices.
  34. 34
    The apparatus recited in claim 31 , wherein the access restriction module blocks access to the protected devices by transmitting restriction address resolution replies on the computer network via the network interface to the protected devices.
  35. 35
    The apparatus recited in claim 34, wherein the restriction address resolution replies contain a source physical device address corresponding to the physical device address of the client device, an is-at physical device address different than the physical device address of the client device, and a destination physical device address corresponding to the physical device address of one of the protected devices.
  36. 36
    The apparatus recited in claim 31 , wherein the access blocking module blocks data link layer access to the network devices by broadcasting blocking address resolution replies on the computer network via the network interface.
  37. 37
    The apparatus recited in claim 36, wherein the blocking address resolution replies contain a source physical device address corresponding to the physical device address of the client device, an is-at physical device address different than the physical device address of the client device, and a destination physical device address corresponding to a broadcast address.
  38. 38
    A computer readable memory for directing a computer connected as a peer in a computer network to control access to one or more protected devices each having a physical device address on a computer network by a client device having a physical device address, the computer being configured to receive address resolution requests broadcast on the network by the client device seeking access to one of the protected devices and to transmit address resolution replies generated by the apparatus on the computer network, the memory comprising:a security module configured to: (a) run on the computer;(b) process the address resolution requests from the client device to determine whether the client device is unknown;(c) transmit address resolution replies on the computer network to block access to the protected devices and allow access to an authentication server, if the client device is unknown;(d) monitor the authentication server to determine if the client device is authorized or unauthorized by the authentication server, if the client device is unknown;(e) allow access to the protected devices, if the client device is authorized;and (f) transmit blocking address resolution replies on the computer network to block access to the protected devices, if the client device is unauthorized.
  39. 39
    The computer readable memory recited in claim 38, wherein the security module is further configured to:determine if the client device is connected to the computer network;wherein the access blocking module ceases blocking data link layer access to the network devices by the client device if the client device is no longer connected to the computer network;and wherein the access monitoring module causes the detection module to determine that the client device is unknown if the client device subsequently attempts to access the protected devices.
  40. 40
    The computer readable memory recited in claim 38, wherein the security module is further configured to transmit correction address resolution requests on the computer network to update the client device with the physical device address of the protected devices.
  41. 41
    The computer readable memory recited in claim 38, wherein the restriction address resolution replies contain a source physical device address corresponding to the physical device address of the client device, an is-at physical device address different than the physical device address of the client device, and a destination physical device address corresponding to the physical device address of one of the protected devices.
  42. 42
    The computer readable memory recited in claim 38, wherein the blocking address resolution replies contain a source physical device address corresponding to the physical device address of the client device, an is-at physical device address different than the physical device address of the client device, and a destination physical device address corresponding to a broadcast address.
  43. 43
    A computer readable memory for directing a computer connected as a peer in a computer network to control access to one or more protected devices each having a physical device address on a computer network by a client device having a physical device address, the computer being configured to receive address resolution requests broadcast on the network by the client device seeking access to one of the protected devices and to transmit address resolution replies generated by the apparatus on the computer network, the memory comprising:a detection module configured to run on the computer and to process the address resolution requests from the client device to determine whether the client device is unknown;an access restriction module configured to run on the computer and to block data link layer access to the protected devices and allow access to an authentication server, if the client device is unknown;an authentication monitoring module configured to run on the computer and to monitor the authentication server to determine if the client device is authorized or unauthorized by the authentication server, if the client device is unknown;and an access blocking module configured to run on the computer and to block data link layer access to the network devices on the computer network, if the client device is unauthorized.
  44. 44
    The computer readable memory recited in claim 43, wherein the access restriction module blocks access to the protected devices by transmitting restriction address resolution replies on the computer network via the network interface to the protected devices.
  45. 45
    The computer readable memory recited in claim 43, wherein the access blocking module blocks data link layer access to the network devices by broadcasting blocking address resolution replies on the computer network via the network interface.
Independent claims45