EP1779293A2

Method and apparatus for determining authentication capabilities

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 20 July 2025, 1.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

17 claims: 5 independent, 12 dependent

  1. 1
    Claims of equivalent WO 2006020329 A2 CLAIMS What is claimed is:1. A method, comprising the computer-implemented steps of: sending, to a supplicant that is requesting access to a computer network subject to authentication of a user of the supplicant, a list of first authentication methods that are supported by an authentication server;receiving, from the supplicant, a counter- list of second authentication methods that are supported by the supplicant;determining how many second authentication methods in the counter-list match the first authentication methods;and performing an authentication policy action based on how many of the second authentication methods match the first authentication methods.
  2. 8
    A method as recited in any of Claims 6 or 7, wherein the authentication conversations comprise any one or more of:receiving and evaluating machine certificates, machine identity information, software or policy compliance information, machine or user governance information, or performing other user or machine credential checks.
  3. 14
    A method of determining capabilities of a supplicant under Extensible Authentication Protocol (EAP), the method comprising the computer-implemented steps of:sending, to a supplicant that is requesting access to a computer network subject to authentication of a user of the supplicant, a list of first EAP methods that are supported by an authentication server, in a Capability Assertion Request comprising one or more EAP type-length-value objects;receiving, from the supplicant, a counter- list of second authentication methods that are supported by the supplicant, in a Capability Assertion Response comprising one or more EAP TLV objects;determining how many second authentication methods in the counter-list match the first authentication methods;and performing an authentication policy action based on how many of the second authentication methods match the first authentication methods.
  4. 15
    A computer-readable medium carrying one or more sequences of instructions, which instructions, when executed by one or more processors, cause the one or more processors to carry out the steps of any of Claims 1, 2, 3, 4, 5, 6, 7, 9, 10, 11, 12, or 13.
  5. 16
    An apparatus, comprising:means for sending, to a supplicant that is requesting access to a computer network subject to authentication of a user of the supplicant, a list of first authentication methods that are supported by an authentication server;means for receiving, from the supplicant, a counter-list of second authentication methods that are supported by the supplicant;means for determining how many second authentication methods in the counter-list match the first authentication methods;and means for performing an authentication policy action based on how many of the second authentication methods match the first authentication methods.