Controlling access to a protected network
Claim Score by NHIP
Abstract
A system for controlling access to a protected network includes a network access control module that is coupled to the protected network and which is configured to restrict access to the network to an authorized user through a computer coupled to the protected network. The system also includes a communication device associated with the computer, which automatically transmits a unique identifier corresponding to the communication device to the network access control module when a user uses the communication device to request access to the protected network via the computer. When the network access control module receives the unique identifier, the network access control module is configured to authenticate the communication device based on the unique identifier, to authenticate the user via the communication device when the communication device is authenticated, and when the user is authenticated, to submit log-on information directly to a log-on interface of the computer associated with the communication device so that the user can access the protected network via the computer.

Term
3.1 yearsto projected expiry
Projected expiry 17 October 2029, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
31 claims: 5 independent, 26 dependent
- 1A system for controlling access to a protected network, the system comprising:a network access control module coupled to the protected network, the network access control module configured to restrict access to the network to an authorized user via a computer coupled to the protected network;and a communication device associated with the computer, the communication device configured to automatically transmit a unique identifier corresponding to the communication device to the network access control module when a user uses the communication device to request access to the protected network via the computer, wherein when the network access control module receives the unique identifier, the network access control module is configured to authenticate the communication device based on the unique identifier, to authenticate the user via the communication device when the communication device is authenticated, and when the user is authenticated, to submit log-on information directly to a log-on interface of the computer associated with the communication device so that the user can access the protected network via the computer.
- 12A method for controlling access to a protected network, the method comprising:receiving by a network access control module coupled to the protected network a unique identifier corresponding to a communication device associated with a computer when a user uses the communication device to request access to the protected network;using the unique identifier to authenticate the communication device;authenticating the user via the communication device when the communication device is authenticated;and when the user is authenticated, submitting log-on information directly to a log-on interface of the computer associated with the communication device so that the user can access the protected network via the computer.
- 22A computer readable medium containing program instructions which when executed perform a method for controlling access to a protected network, the computer readable medium comprising program instructions for:receiving over a secure communication channel a unique identifier corresponding to a communication device associated with a computer when a user uses the communication device to request access to a protected network;using the unique identifier to authenticate the communication device;authenticating the user via the communication device when the communication device is authenticated;and when the user is authenticated, submitting log-on information directly to a log-on interface of the computer associated with the communication device so that the user can access the protected network via the computer.
- 26A server for controlling access to a protected network, the server comprising:a network access module configured to restrict access to the protected network to an authorized user;a data store communicatively coupled to the network access control module for storing information comprising authentication information and log-on information of a computer coupled to a protected network;and a communication interface communicatively coupled to the network access control module and configured to receive over a first secure communication channel a unique identifier corresponding to a separate communication device associated with the computer when a user uses the communication device to request access to the protected network;wherein when the network access control module receives the unique identifier via the communication interface, the network access control module is configured to authenticate the communication device based on the unique identifier, to authenticate the user via the communication device over the first secure communication channel when the communication device is authenticated, and when the user is authenticated, to transmit over a second secure communication channel log-on information to a log-on interface of the computer associated with the communication device so that the user can access the protected network via the computer.
- 31Broadest claimClaim Score 75, broad(NHIP)A system for controlling access to a protected network, the server comprising:means for receiving over a secure communication channel a unique identifier corresponding to a communication device associated with a computer when a user uses the communication device to request access to the protected network;means for using the unique identifier to authenticate the communication device;means for authenticating the user via the communication device when the communication device is authenticated;and when the user is authenticated, means for submitting log-on information directly to a log-on interface of the computer associated with the communication device so that the user can access the protected network via the computer.
Independent claims5
46 paragraphs in 5 sections, as filed
FIELD OF INVENTION
0001The present invention relates to enterprise networks, and more particularly to controlling access to a protected enterprise network by authenticating an authorized user via voice biometrics.
BACKGROUND
0002Many modern enterprises utilize one or more private or protected networks that allow workers to communicate with one another, to access shared information, and to perform every day tasks and functions. In most cases, the private network includes or provides access to sensitive and confidential information. For this and other reasons, the private network is typically restricted to authorized users, such as members of the enterprise.
0003Traditionally, an authorized user gains access to a protected network by submitting a credential that authenticates the user to the network. The credential is usually a username and password. The username/password credential, however, sometimes offers little security. For instance, because the username is typically some form of the user's name, it can easily be discovered by a malicious user. Moreover, when the password is created by the user, the user typically chooses a phrase that is easily discovered, e.g., the user's birthday, user's child's name. Once the username and password are misappropriated, i.e., stolen, the protected network can be vulnerable to attack.
0004To address these concerns, biometric features of the user are now being used in lieu of, or in addition to, the username/password credential. Exemplary biometric features include those features that uniquely identifying an individual such as a fingerprint and retinal pattern. Another identifying biometric feature is voice and speech patterns, which is particularly useful because a voice response can authenticate a user on two levels. For example, if the voice response is an answer to a challenge question, it can be used to authenticate the user based on a voiceprint and based on the response content. Thus, a person impersonating an authorized user would be required to imitate the authorized user's voiceprint and would be required to answer the challenge question correctly.
0005To implement voice authentication, the requesting user is typically prompted to submit a voice response via a microphone in a computer through which the user is seeking access to the network. The voice response should be of a quality such that an authentication application/module can accurately match the voice response to a stored sample corresponding to the user. This is problematic, however, because the quality and/or performance of a computer's microphone can vary from computer to computer within an enterprise where many different computer models and makes are used. To accommodate this, the matching algorithm can be designed to lower the matching criteria. This approach, however, can compromise security.
SUMMARY OF THE INVENTION
0006According to one aspect, a system for controlling access to a protected network includes a network access control module that is coupled to the protected network and which is configured to restrict access to the network to an authorized user through a computer coupled to the protected network. The system also includes a communication device associated with the computer, which automatically transmits a unique identifier corresponding to the communication device to the network access control module when a user uses the communication device to request access to the protected network via the computer. When the network access control module receives the unique identifier, the network access control module is configured to authenticate the communication device based on the unique identifier, to authenticate the user via the communication device when the communication device is authenticated, and when the user is authenticated, to submit log-on information directly to a log-on interface of the computer associated with the communication device so that the user can access the protected network via the computer.
0007According to another aspect, a method for controlling access to a protected network includes receiving by a network access control module coupled to the protected network a unique identifier corresponding to a communication device associated with a computer when a user uses the communication device to request access to the protected network. The method further includes using the unique identifier to authenticate the communication device, authenticating the user via the communication device when the communication device is authenticated, and when the user is authenticated, submitting log-on information directly to a log-on interface of the computer associated with the communication device so that the user can access the protected network via the computer.
0008According to another aspect, a server includes a network access module configured to restrict access to the protected network to an authorized user, a data store communicatively coupled to the network access control module for storing information comprising authentication information and log-on information of a computer coupled to a protected network, and a communication interface communicatively coupled to the network access control module. The communication interface is configured to receive over a first secure communication channel a unique identifier corresponding to a separate communication device associated with the computer when a user uses the communication device to request access to the protected network. When the network access control module receives the unique identifier via the communication interface, the network access control module is configured to authenticate the communication device based on the unique identifier, to authenticate the user via the communication device over the first secure communication channel when the communication device is authenticated, and when the user is authenticated, to transmit over a second secure communication channel log-on information to a log-on interface of the computer associated with the communication device so that the user can access the protected network via the computer.
DESCRIPTION OF THE DRAWINGS
0009The accompanying drawings provide visual representations which will be used to more fully describe the representative embodiments disclosed here and can be used by those skilled in the art to better understand them and their inherent advantages. In these drawings, like reference numerals identify corresponding elements, and:
0010<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram of an exemplary system for controlling access to a protected network according to one embodiment;
0011<figref idref="DRAWINGS">FIG. 2</figref> is a block diagram of an exemplary computer coupled to the protected network according to one embodiment;
0012<figref idref="DRAWINGS">FIG. 3</figref> is a block diagram of an exemplary communication device according to one embodiment;
0013<figref idref="DRAWINGS">FIG. 4</figref> is a block diagram of an exemplary network access server according to one embodiment; and
0014<figref idref="DRAWINGS">FIG. 5</figref> is a flowchart illustrating an exemplary process for controlling access to a protected network according to one embodiment.
DETAILED DESCRIPTION
0015Various aspects will now be described in connection with exemplary embodiments, including certain aspects described in terms of sequences of actions that can be performed by elements of a computing device or system. For example, it will be recognized that in each of the embodiments, at least some of the various actions can be performed by specialized circuits or circuitry (e.g., discrete and/or integrated logic gates interconnected to perform a specialized function), by program instructions being executed by one or more processors, or by a combination of both. Thus, the various aspects can be embodied in many different forms, and all such forms are contemplated to be within the scope of what is described.
0016<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram of an exemplary system for controlling access to a protected network according to one embodiment. According to an exemplary embodiment, an enterprise <b>102</b> includes a private or protected network <b>104</b> that communicatively couples members of the enterprise <b>102</b> to one another and to enterprise resources <b>108</b> through a plurality of computer devices <b>200</b>. The computer devices <b>200</b> can be, for example, work stations, laptop computers coupled to docking stations, personal computers, servers, client terminals and other similar devices that enable users <b>130</b> to access the protected network <b>104</b>.
0017<figref idref="DRAWINGS">FIG. 2</figref> is a block diagram of an exemplary computer device <b>200</b> according to one embodiment. The computer <b>200</b> includes a communication interface <b>202</b> that allows an authorized user <b>130</b> to send and receive data to and from the protected network <b>104</b>. In one embodiment, a log-on interface <b>204</b> is communicatively coupled to the communication interface <b>202</b>. The log-on interface <b>204</b>, in one embodiment, can be an operating system independent application that is configured to receive and process log-on information to determine whether a user <b>130</b> should be allowed to use the computer <b>200</b> to access the protected network <b>104</b>. For example, the log-on interface <b>204</b> can be a module that replaces an operation system dependent log-on module such as a graphical identification and authentication (GINA) application. In another embodiment, the log-on interface <b>204</b> can be a GINA module that is modified to support the system and method described herein. In an exemplary embodiment, the log-on interface <b>204</b> is configured to send and receive information to and from a web server, i.e., the interface <b>204</b> is a web-service enabled identification and authentication module, such that the log-on process can be facilitated via a web service.
0018In one embodiment, computer device <b>200</b> can be physically located at an enterprise facility, e.g., an office building or site, as shown in <figref idref="DRAWINGS">FIG. 1</figref>, where it is available to one or more authorized users <b>130</b>. In another embodiment, the computer device <b>200</b> can be physically remote from the enterprise <b>102</b>.
0019Referring again to <figref idref="DRAWINGS">FIG. 1</figref>, the protected network <b>104</b> is communicatively coupled to an external network, such as the Internet <b>120</b>, so that users <b>130</b> can access resources outside of the enterprise <b>102</b>. At least one firewall <b>109</b> protects the private network <b>104</b> in a known manner from unauthorized access from the external network <b>120</b>.
0020According to one embodiment, each enterprise computer <b>200</b> is associated with a communication device <b>300</b>. In an exemplary embodiment, the communication device <b>300</b> is a telephone that is communicatively coupled to a private branch exchange (PBX) hub <b>106</b>. The PBX hub <b>106</b> is well known in the art and supports connections between the communication devices <b>300</b> within the enterprise <b>102</b> as well as connections from a telephone <b>300</b> to another device outside of the enterprise <b>102</b> via a public telephone network <b>110</b> or via the external network <b>120</b>.
0021<figref idref="DRAWINGS">FIG. 3</figref> is a block diagram of an exemplary communication device <b>300</b> according to one embodiment. As is shown, the communication device <b>300</b> is a telephone that includes a means, e.g., a handset <b>304</b> or an internal microphone, for allowing the user <b>130</b> to transmit and receive voice data, and a standard keypad <b>302</b> that allows the user <b>130</b> to submit key data, e.g., to select an extension or to enter a number of another telephone <b>300</b>. The communication device <b>300</b> includes a PBX interface (not shown) that is configured to transmit and receive key data and voice information from the PBX hub <b>106</b>.
0022In one exemplary embodiment, the communication device <b>300</b> is used by a user <b>130</b> to request access to the protected network <b>104</b>. In one embodiment, the communication device <b>300</b> can include a dedicated log-on button <b>310</b>. The dedicated log-on button <b>310</b>, which in one embodiment is separate from the keypad <b>302</b>, is programmed to facilitate a log-on process for the computer <b>200</b> associated with the communication device <b>300</b>. In this embodiment, the user <b>130</b> can initiate the log-on process in order to gain access to the protected network <b>104</b> via the computer <b>200</b> simply by activating, e.g., pressing, the dedicated log-on button <b>310</b>. In another embodiment, one of the keys of the keypad <b>302</b>, or a combination of keys in the keypad <b>302</b>, can be programmed to initiate the log-on process. For example, a particular key in the keypad <b>302</b> can be programmed to start the log-on process when it is pressed a predetermined number of times. A more detailed discussion of the log-on process will be provided below.
0023Referring again to the exemplary embodiment illustrated in <figref idref="DRAWINGS">FIG. 1</figref>, the enterprise <b>102</b> is communicatively coupled to a network access server <b>400</b> via the external network <b>120</b>, such as the Internet, and via the telephone network <b>110</b>. The network access server <b>400</b> is a secure server that is configured to control access to the enterprise's protected network <b>104</b> via the enterprise computers <b>200</b>.
0024<figref idref="DRAWINGS">FIG. 4</figref> is a block diagram of an exemplary network access server <b>400</b> according to one embodiment. The network access server <b>400</b> includes a means for sending and receiving information to and from the internet <b>120</b> and to and from the telephone network <b>110</b> using well known communication protocols. For example, the network access server <b>400</b> can include a communication interface <b>402</b> that is configured to send and receive information to and from the internet <b>120</b> and to and from the telephone network <b>110</b> using well known communication protocols. In one embodiment, the communication interface <b>402</b> can include well known software and hardware components that support both data and telephony connections. In one exemplary embodiment, the communication interface <b>402</b> is configured to traverse a firewall <b>109</b> protecting the enterprise's protected network <b>104</b>. Accordingly, a secure communication channel between the network access server <b>400</b> and the protected network <b>104</b> can be established via the communication interface <b>402</b>.
0025According to an exemplary embodiment, the network access server <b>400</b> also includes means for receiving a request to access the protected network <b>104</b> via an enterprise computer <b>200</b> from the communication interface <b>402</b> and managing the log-on process for the computer <b>200</b>. For example, the network access server <b>400</b> can include a network access module <b>404</b> communicatively coupled to the communication interface <b>402</b> and configured to receive a request to access the protected network <b>104</b> via an enterprise computer <b>200</b> and to manage the log-on process for the computer <b>200</b>. In one embodiment, the network access module <b>404</b> is coupled to the data store <b>410</b> via a data manager <b>406</b> that retrieves, submits and updates information stored in the data store <b>410</b>.
0026In an exemplary embodiment, the data store <b>410</b> includes device information <b>412</b>, user information <b>414</b>, and log-on information <b>416</b>. The device information <b>412</b> can include information that can be used to authenticate a communication device <b>300</b> associated with an enterprise computer <b>200</b>. Such authentication information <b>412</b> can include a unique identifier associated with each communication device <b>300</b>, e.g., a phone number, an IP address, a MAC address, a serial number, and the like.
0027The user information <b>414</b> can include information that can be used to authenticate a user <b>130</b>. In one embodiment, the information <b>414</b> can include biometric data associated with each user <b>130</b>. Such biometric data can include voice data that captures the user's unique voice pattern or voice print. In addition, the voice data can capture an answer to one or more challenge questions. In another embodiment, the information <b>414</b> can include access control rules associated with each user <b>130</b>. In this embodiment, the access control rules can indicate which computer(s) <b>200</b> a user <b>130</b> is authorized to use.
0028The log-on information <b>416</b> can include information that can be used to log-on to an enterprise computer <b>200</b>. In one embodiment, the log-on information <b>416</b> can include a username/password associated with each enterprise computer <b>200</b>. In another embodiment, the log-on information <b>416</b> can be a username and a randomly generated password that is unknown to the user <b>130</b>.
0029In an exemplary embodiment, the network access module <b>404</b> is configured to manage the log-on process for an enterprise computer <b>200</b> by authenticating the communication device <b>300</b> associated with the computer <b>200</b>, and then authenticating the user <b>130</b> by retrieving device and user information <b>412</b>, <b>414</b> from the data store <b>410</b>. The network access module <b>404</b> is configured to use a compare module <b>408</b> to compare the retrieved information <b>412</b>, <b>414</b> to the information received from the enterprise <b>102</b> via the communication interface <b>402</b>. Once the communication device <b>300</b> and user <b>130</b> are authenticated, the network access module <b>404</b> is configured to retrieve the log-on information <b>416</b> associated with the enterprise computer <b>200</b> and to send the log-on information <b>416</b> to the computer <b>200</b> via the communication interface <b>402</b>.
0030In the embodiment shown in <figref idref="DRAWINGS">FIG. 1</figref>, the network access module <b>404</b> resides in a standalone server <b>400</b> that is located external to the enterprise <b>102</b>. In this embodiment, the network access server <b>400</b> can be controlled by an application service provider (“ASP”) that can provide network access control services to more than one enterprise <b>102</b>. In another embodiment, the network access server <b>400</b> can be utilized exclusively by an enterprise <b>102</b> to control access to the enterprise's protected network <b>104</b>. In this embodiment, the network access server <b>400</b> can be directly coupled to the protected network <b>104</b>, i.e., located behind the enterprise's firewall <b>109</b>.
0031<figref idref="DRAWINGS">FIG. 5</figref> is a flowchart illustrating an exemplary process for controlling access to a protected network <b>104</b> according to one embodiment. Referring to <figref idref="DRAWINGS">FIGS. 1-4</figref>, the process begins when the user <b>130</b> requests access to the protected network <b>104</b> using the communication device <b>300</b> that is associated with the computer <b>200</b> coupled to the protected network <b>104</b> (block <b>500</b>). In one embodiment, the user <b>130</b> can activate, i.e., press, the dedicated log-on button <b>310</b> on the communication device <b>300</b> associated with the computer <b>200</b>. In another embodiment, the user <b>130</b> can activate one or more preprogrammed keys in the communication device's keypad <b>302</b>.
0032In response to activating the log-on button <b>310</b> or preprogrammed key(s), the communication device <b>300</b> automatically establishes a secure communication channel between the communication device <b>300</b> and the network access server <b>400</b> and transmits the unique identifier of the communication device <b>300</b> to the network access server <b>400</b> (block <b>502</b>). In one embodiment, the communication device <b>300</b> can be a telephone, and the secure communication channel is provided via the internal PBX module <b>106</b> and/or the public telephone network <b>110</b>. In this embodiment, the unique identifier can be the telephone number or IP address of the telephone <b>300</b>. In addition to, or alternatively, the unique identifier can be a serial number or a MAC address of the telephone <b>300</b> or any other identifier that uniquely identifies the device <b>300</b>.
0033The unique identifier is received by the network access module <b>404</b> at the network access server <b>400</b> via the communication interface <b>402</b> that is configured to transmit and receive data to and from the telephone network <b>110</b> and/or the internal PBX module <b>106</b>, and the network access module <b>404</b> uses the unique identifier to authenticate the communication device <b>300</b> (block <b>504</b>). In one embodiment, the network access module <b>404</b> can use the data manager <b>406</b> to retrieve device information <b>412</b> associated with the enterprise <b>102</b> from the data store <b>410</b>. In one embodiment, the device information <b>412</b> can include the unique identifiers associated with each of the communication devices <b>300</b> in the enterprise <b>102</b>. The network access module <b>404</b> can then use the compare module <b>408</b> to determine whether there is a match between the device information <b>412</b> and the received unique identifier. If a match is not found, the network access module <b>404</b> can return an error message to the communication device <b>300</b> over the established secure communication channel that indicates to the user <b>130</b> that the communication device <b>300</b> is not registered with the enterprise <b>102</b> and access to the network <b>104</b> is denied.
0034If a match is determined, the communication device <b>300</b> is authenticated and the network access module <b>404</b> transmits a message over the established secure communication channel to the authenticated communication device <b>300</b> that prompts the user <b>130</b> to submit biometric data (block <b>506</b>). In one embodiment, the user <b>130</b> can be asked to submit voice data using the communication device <b>300</b>. For example, the user <b>130</b> can be prompted to speak his or her name. In addition, or alternatively, the user <b>130</b> can be prompted to answer one or more challenge questions, such as his employee number, birthday, address, or place of birth.
0035When the user <b>130</b> receives the message, he can submit the requested biometric data over the established secure communication channel (block <b>508</b>) using the authenticated communication device <b>300</b>. For example, if the communication device <b>300</b> is a telephone, the user <b>130</b> can hear the message and submit voice data through the handset <b>304</b>.
0036The network access module <b>404</b> receives the biometric data from the user <b>130</b> via the established secure communication channel and uses the biometric data to authenticate the user <b>130</b> (block <b>510</b>). In one embodiment, the network access module <b>404</b> can retrieve user information <b>414</b> from the data store <b>410</b>. In one embodiment, the user information <b>414</b> can include the biometric data associated with authorized users <b>130</b> of the enterprise <b>102</b>. In addition, the biometric data can be processed to determine its content using well known speech to text (STT) technology.
0037The network access module <b>404</b> can then use the compare module <b>408</b> to determine whether there is a match between the retrieved user information <b>414</b> and the received biometric data. In addition, the network access module <b>404</b> can determine whether the content of the biometric data correctly matches the answer to one or more challenge questions. If a match is not found, the network access module <b>404</b> can return an error message to the communication device <b>300</b> over the established secure communication channel that indicates to the user <b>130</b> that an authentication error has occurred and that access to the network <b>104</b> is denied.
0038Alternatively, or in addition, the error message can ask the user <b>130</b> to resubmit his biometric data and the access module <b>404</b> can try to authenticate the user <b>130</b> again. The number of chances allowed to authenticate correctly is configurable. If the user <b>130</b> continues to provide the incorrect biometric data, the network access module <b>404</b> can deny access and terminate the secure communication channel.
0039In another embodiment, the user information <b>414</b> can also include access control rules that indicate which computers <b>200</b> in the enterprise the user <b>130</b> is authorized to use. Thus, in addition to authenticating the user <b>130</b>, the network access module <b>404</b> can also determine whether the authenticated user <b>130</b> is authorized to use the computer <b>200</b> associated with the communication device <b>300</b>. In this embodiment, when both criteria are satisfied, the network access module <b>404</b> can grant access to the network <b>104</b>.
0040After the user <b>130</b> is authenticated (and optionally authorized), the network access module <b>404</b> can establish a secure communication channel between the network access server <b>400</b> and the enterprise computer <b>200</b> associated with the communication device <b>300</b>, and transmit log-on information to the computer <b>200</b> (block <b>512</b>). In one embodiment, the network access module <b>404</b> can retrieve log-on information <b>416</b> associated with the enterprise computer <b>200</b> from the data store <b>410</b> using the data manager <b>406</b>. In one embodiment, the log-on information <b>416</b> can include the user's username and password. The password can be a randomly generated password or a password created by the user <b>130</b>. Alternatively, or in addition, the log-information <b>416</b> can include any data used to allow the user <b>130</b> to access the protected network <b>104</b>. In another embodiment, the network access module can be configured to establish the secure communication channel over the internet <b>120</b>, through the enterprise's firewall <b>109</b>, and to the enterprise computer <b>200</b> via the protected network <b>104</b>.
0041The enterprise computer <b>200</b> receives the log-on information <b>416</b> from the network access server <b>400</b> via the communication interface <b>202</b> that is configured to send and receive data to and from the protected network <b>104</b> (block <b>514</b>). The communication interface <b>402</b> routes the log-on information to the log-on interface <b>204</b>, which is configured to process the log-on information. In one embodiment, the log-on interface <b>204</b> is modified GINA interface, which is well known in the art. Once the log-on information is properly processed, the enterprise computer <b>200</b> can be used to provide access to the protected network <b>104</b> (block <b>516</b>).
0042In one embodiment, the network access module <b>404</b> can be a web service and the network access server <b>400</b> can be a web server that securely receives and transmits IP packets over the internet <b>120</b>. In this embodiment, the log-on interface <b>204</b> can be a web-enabled service, i.e., the interface <b>204</b> is configured to process data using an internet protocol.
0043In another embodiment, the log-on interface <b>204</b> can serve as a single sign-on service, that is, once the user <b>130</b> is authenticated (and optionally authorized), the log-on interface <b>204</b> can provide access to other protected resources, e.g., web pages, for which the user <b>130</b> is authorized.
0044Through aspects of the methods and systems described, a user seeking to access a protected network <b>104</b> using a computer <b>200</b> coupled to the protected network <b>104</b> is authenticated using a communication device <b>300</b> associated with a computer <b>200</b>. A network access module <b>404</b> is configured to authenticate the communication device <b>300</b> and to authenticate the user <b>130</b> who submits biometric data via the communication device <b>300</b>. Once authenticated, the network access module <b>404</b> is configured to send log-on information directly to the computer <b>200</b> so that the user <b>130</b> can access the protected network <b>104</b>.
0045In one embodiment, the communication device <b>300</b> is a telephone and the biometric data is voice data. Because the telephone <b>300</b> can be a standardized device throughout the enterprise <b>102</b>, the quality of the voice data can be controlled, and voice print authentication can be accurately implemented. Moreover, because the network access module <b>404</b> securely provides the log-on information directly to the computer <b>200</b>, the user <b>130</b> is not required to know the log-on information.
0046Methods and systems for controlling access to a protected network have been described. It will be appreciated by those of ordinary skill in the art that the concepts and techniques described here can be embodied in various specific forms without departing from the essential characteristics thereof. The presently disclosed embodiments are considered in all respects to be illustrative and not restrictive. The scope of the invention is indicated by the appended claims, rather than the foregoing description, and all changes that come within the meaning and range of equivalence thereof are intended to be embraced.
Contents5
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2009199282A1 | Cited by | United States of America | Pre-grant |
| US9818115B2 | Cited by | United States of America | Applicant |
| US2009199298A1 | Cited by | United States of America | Pre-grant |
| US9118488B2 | Cited by | United States of America | Search report |
| US8976943B2 | Cited by | United States of America | Search report |
| CN113179517A | Cited by | China | Search report |
| US8776198B2 | Cited by | United States of America | Search report |
| US2013239172A1 | Cited by | United States of America | Pre-grant |
| US2023109716A1 | Cited by | United States of America | Search report |
| US10112560B2 | Cited by | United States of America | Search report |
| US9219750B2 | Cited by | United States of America | Search report |
| US2007177615A1 | Cited by | United States of America | Pre-grant |
| US2011314530A1 | Cited by | United States of America | Pre-grant |
| US2013022180A1 | Cited by | United States of America | Pre-grant |
| US12408221B2 | Cited by | United States of America | Search report |
| US2012291106A1 | Cited by | United States of America | Pre-grant |
| US10909538B2 | Cited by | United States of America | Applicant |
| CN108076500A | Cited by | China | Search report |
| US2007192867A1 | Cited by | United States of America | Pre-grant |
| US2003046083A1 | Cites | United States of America | Pre-grant |
| US2005231760A1 | Cites | United States of America | Pre-grant |
| US2005268107A1 | Cites | United States of America | Pre-grant |
| US2006041755A1 | Cites | United States of America | Pre-grant |
| US5315636A | Cites | United States of America | Pre-grant |
| US5384831A | Cites | United States of America | Pre-grant |
| US5550907A | Cites | United States of America | Pre-grant |
| US5636282A | Cites | United States of America | Pre-grant |
| US6065120A | Cites | United States of America | Pre-grant |
| US6606543B1 | Cites | United States of America | Pre-grant |
| US6871287B1 | Cites | United States of America | Pre-grant |
| US6934858B2 | Cites | United States of America | Pre-grant |
| US6993658B1 | Cites | United States of America | Pre-grant |
| US7054819B1 | Cites | United States of America | Pre-grant |
| US7577847B2 | Cites | United States of America | Pre-grant |
4 members in 1 office; this record represents the family
Members4
| Document | Office | Kind | |
|---|---|---|---|
| US2008098461A1 | United States of America | A1 | |
| US8225103B2 | United States of America | B2 | |
| US2012284778A1 | United States of America | A1 | |
| US8499166B2 | United States of America | B2 |
69 transactions on the USPTO file
Allowed after 2 non-final rejections, 1 final rejection and 1 RCE.
- Non-final rejections
- 2
- Final rejections
- 1
- RCEs
- 1
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 12th Yr, Small EntityM2553 | M2553 | |
| Payment of Maintenance Fee, 8th Yr, Small EntityM2552 | M2552 | |
| Applicant Has Filed a Verified Statement of Small Entity Status in Compliance with 37 CFR 1.27SMAL | SMAL | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Notice of Informal or Non-Responsive AmendmentNINA | NINA | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Examiner Interview Summary (PTOL - 413)MEXIN | MEXIN | |
| Informal or Non-Responsive Amendment after Examiner ActionA.I. | A.I. | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Examiner Interview Summary Record (PTOL - 413)EXIN | EXIN | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Correspondence Address ChangeC.AD | C.AD | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Withdraw Flagged for 5/25W525 | W525 | |
| Flagged for 5/25F525 | F525 | |
| Transfer Inquiry to GAUTI1050 | TI1050 | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| Maintenance fee paymentMAFP | MAFP | |
| Fee paymentFPAY | FPAY | |
| Fee payment procedurePAT HOLDER CLAIMS SMALL ENTITY STATUS, ENTITY STATUS SET TO SMALL (ORIGINAL EVENT CODE: LTOS); ENTITY STATUS OF PATENT OWNER: SMALL ENTITYFEPP | FEPP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication
- 20080098461
- Application
- 11552313
Titles
- English
- CONTROLLING ACCESS TO A PROTECTED NETWORK
Patent term adjustment
- A delay
- +829 daysthe office missed an examination deadline
- B delay
- +481 dayspendency past three years
- Overlap
- −48 daysdelays counted once
- Applicant delay
- −173 days
- Net adjustment
- 1,089 days
Classification
- CPC, 4
- G06F21/31
- G06F21/41
- G06F21/85
- G06F2221/2129
- IPC, 9
- H04L9 32
- G06K9 00
- H04L9 00
- H04K1 00
- G06F17 30
- G06F15 16
- G06F7 04
- G06F7 58
- G06K19 00