A client connected to a network switch is continuously authenticated to a network switch by using biometrics, wherein the client and the network switch exchange Ethernet/802.3 frames associated with a client application, and wherein the client and the network switch are coupled by a full-duplex Ethernet/802.3...http://www.google.ca/patents/US7222360?utm_source=gb-gplus-sharePatent US7222360 - Continuous biometric authentication using frame preamble for biometric data
Continuous biometric authentication using frame preamble for biometric data
CONTINUOUS BIOMETRIC AUTHENTICATION USING FRAME PREAMBLE FOR BIOMETRIC DATA
Inventor: Eric E. Miller, Olathe, KS (US)
Assignee: Sprint Communications Company L.P., Overland Park, KS (US)
Notice: Subject to any disclaimer, the term of this patent is extended or adjusted under 35 U.S.C. 154(b) by 853 days.
App1.No.: 10/307,110
Filed: Nov. 27, 2002
OTHER PUBLICATIONS
Hamid Karimi, “New spec will help secure LANs”, Aug. 30, 1999, Network World, pp. 1-3.*
Mihir Bellare, et al. Message Authentication Using Hash Functions—The HMAC Construction, RSA Laboratories’ CryptoBytes, vol. 2, No. 1, Spring 1996, pp. 1-5.
* cited by examiner
Primary Examiner—AyaZ Sheikh Assistant Examiner—Trang Doan
(57) ABSTRACT
A client connected to a network switch is continuously authenticated to a network switch by using biometrics, wherein the client and the network switch exchange Ethernet/802.3 frames associated with a client application, and wherein the client and the network switch are coupled by a fiill-duplex Ethernet/802.3 communication channel. A biometric data sample of a user of the client is captured. Biometric data is encapsulated in an authentication protocol message frame. The authentication protocol message frame is separated into a sequence of a plurality of fragments, each fragment having a predetermined number of bytes. Respective sequence numbers are assigned to each of the fragments. Each of the fragments is inserted with its respective sequence number in a respective preamble of a respective one of a plurality of Ethernet/802.3 frames associated with the client application that are being transmitted from the client to the network switch.
19 Claims, 6 Drawing Sheets
MI:
Close Poit; Require Re- -—/ authentication
Authentication Server Compares Data to Template(s) 15
16 N Y 20 \\ Access-Deny Message Sent to Access-Accept Message Sent
Resource Via RADIUS to Resource Via RADIUS
I I
UserPort Remains User Port Becomes Functional Nonfunctional