METHOD AND APPARATUS FOR AUTOMATICALLY RE-VALIDATING MULTIPLE CLIENTS OF AN AUTHENTICATION SYSTEM
    4.
    发明申请
    METHOD AND APPARATUS FOR AUTOMATICALLY RE-VALIDATING MULTIPLE CLIENTS OF AN AUTHENTICATION SYSTEM 审中-公开
    用于自动重新验证认证系统的多个客户端的方法和装置

    公开(公告)号:WO2006025989B1

    公开(公告)日:2006-12-28

    申请号:PCT/US2005026624

    申请日:2005-07-26

    Abstract: A method is disclosed for performing on-demand posture validation for all of multiple clients or supplicants of an authentication system, comprising creating and storing a session list identifying communication sessions relating to supplicants that access a computer network through an access device; receiving input requesting performing posture validation for all the supplicants; determining a time value for starting the posture validation for a particular supplicant identified in the session list; generating and sending to the access device, a request to perform posture validation, wherein the request comprises supplicant identifying information and the time value and instructs the access device to initiate the posture validation for that supplicant only after the time value has expired; and repeating the steps of determining, generating and sending for all supplicants in the session list.

    Abstract translation: 公开了一种用于对认证系统的所有多个客户端或请求者执行按需姿势验证的方法,包括创建和存储会话列表,该会话列表标识与通过接入设备访问计算机网络的请求者有关的通信会话; 接收请求对所有请求者执行姿势验证的输入; 确定用于开始在会话列表中标识的特定请求者的姿势验证的时间值; 生成并向所述访问设备发送执行姿势验证的请求,其中所述请求包括请求者识别信息和所述时间值,并且仅在所述时间值到期之后指示所述访问设备才启动所述请求者的姿势验证; 并重复在会话列表中为所有请求者确定,生成和发送的步骤。

    METHOD AND APPARATUS FOR AUTOMATICALLY RE-VALIDATING MULTIPLE CLIENTS OF AN AUTHENTICATION SYSTEM
    5.
    发明申请
    METHOD AND APPARATUS FOR AUTOMATICALLY RE-VALIDATING MULTIPLE CLIENTS OF AN AUTHENTICATION SYSTEM 审中-公开
    用于自动重新验证认证系统的多个客户的方法和设备

    公开(公告)号:WO2006025989A3

    公开(公告)日:2006-11-23

    申请号:PCT/US2005026624

    申请日:2005-07-26

    Abstract: A method is disclosed for performing on-demand posture validation for all of multiple clients or supplicants of an authentication system, comprising creating and storing a session list identifying communication sessions relating to supplicants that access a computer network through an access device; receiving input requesting performing posture validation for all the supplicants; determining a time value for starting the posture validation for a particular supplicant identified in the session list; generating and sending to the access device, a request to perform posture validation, wherein the request comprises supplicant identifying information and the time value and instructs the access device to initiate the posture validation for that supplicant only after the time value has expired; and repeating the steps of determining, generating and sending for all supplicants in the session list.

    Abstract translation: 公开了一种用于对认证系统的多个客户端或请求者中的全部进行按需姿态验证的方法,包括:创建并存储识别与通过接入设备接入计算机网络的请求者有关的通信会话的会话列表; 接收请求对所有请求者进行姿势验证的输入; 确定开始对在会话列表中识别的特定请求者的姿势验证的时间值; 生成并向接入设备发送执行姿势验证的请求,其中所述请求包括请求者识别信息和时间值,并且仅在所述时间值已经到期之后才指示所述接入设备启动对该请求者的姿势验证; 并重复为会话列表中的所有请求者确定,生成和发送的步骤。

    METHOD AND APPARATUS FOR DETERMINING AUTHENTICATION CAPABILITIES
    6.
    发明申请
    METHOD AND APPARATUS FOR DETERMINING AUTHENTICATION CAPABILITIES 审中-公开
    用于确定认证能力的方法和装置

    公开(公告)号:WO2006020329B1

    公开(公告)日:2006-12-28

    申请号:PCT/US2005025795

    申请日:2005-07-20

    Abstract: A method is disclosed for determining the authentication capabilities of a supplicant before initiating an authentication conversation with a client (104), for example, using Extensible Authentication Protocol (EAP). In one aspect, the method provides for sending (130), to a supplicant (104) that is requesting access to a computer network (110) subject to authentication of a user (102) of the supplicant (104), a list of first authentication methods (112) that are supported by an authentication server (150); receiving (152), from the supplicant (104), a counter-list of second authentication methods (112) that are supported by the supplicant (104); determining how many second authentication methods in the counter-list match the first authentication methods (154); and performing an authentication policy action based on how many of the second authentication methods match the first authentication methods (156). Policy actions can include blocking access, re-directing to sources of acceptable authentication methods, granting one of several levels of network access, etc (162-170).

    Abstract translation: 公开了一种用于在例如使用可扩展认证协议(EAP)发起与客户机(104)的认证会话之前确定请求方的认证能力的方法。 在一个方面,该方法提供发送请求者(104),请求者(104)正在请求接入请求者(104)的用户(102)的认证的计算机网络(110),第一 由认证服务器(150)支持的认证方法(112); 从所述请求者(104)接收(152)由所述请求者(104)支持的第二认证方法(112)的对应列表; 确定所述计数器列表中的第二认证方法与所述第一认证方法匹配(154); 以及基于所述第二认证方法中的多少与所述第一认证方法(156)相匹配来执行认证策略动作。 政策行动可以包括阻止访问,重新指向可接受的认证方法的来源,授予几个级别的网络访问等等(162-170)。

    METHOD AND APPARATUS FOR DETERMINING AUTHENTICATION CAPABILITIES
    7.
    发明申请
    METHOD AND APPARATUS FOR DETERMINING AUTHENTICATION CAPABILITIES 审中-公开
    确定认证能力的方法和设备

    公开(公告)号:WO2006020329A3

    公开(公告)日:2006-11-09

    申请号:PCT/US2005025795

    申请日:2005-07-20

    Abstract: A method is disclosed for determining the authentication capabilities of a supplicant before initiating an authentication conversation with a client (104), for example, using Extensible Authentication Protocol (EAP). In one aspect, the method provides for sending (130), to a supplicant (104) that is requesting access to a computer network (110) subject to authentication of a user (102) of the supplicant (104), a list of first authentication methods (112) that are supported by an authentication server (150); receiving (152), from the supplicant (104), a counter-list of second authentication methods (112) that are supported by the supplicant (104); determining how many second authentication methods in the counter-list match the first authentication methods (154); and performing an authentication policy action based on how many of the second authentication methods match the first authentication methods (156). Policy actions can include blocking access, re-directing to sources of acceptable authentication methods, granting one of several levels of network access, etc (162-170).

    Abstract translation: 公开了一种用于在例如使用可扩展认证协议(EAP)发起与客户端(104)的认证对话之前确定请求者的认证能力的方法。 在一个方面,该方法提供了向请求访问经受请求方(104)的用户(102)的认证的计算机网络(110)的请求方(104)发送(130)第一 认证服务器(150)支持的认证方法(112); 从请求者(104)接收(152)由请求者(104)支持的第二认证方法(112)的计数器列表; 确定计数器列表中的第二认证方法与第一认证方法相匹配(154); 以及基于多少第二认证方法与第一认证方法匹配来执行认证策略动作(156)。 策略操作可以包括阻止访问,重定向可接受认证方法的来源,授予多个级别的网络访问等之一(162-170)。

Patent Agency Ranking