Search Images Maps Play YouTube News Gmail Drive More »
Advanced Patent Search | Page images | Web History | Sign in

Patents

  
[merged small][merged small][merged small][merged small][graphic][merged small][merged small][merged small][merged small][merged small]

(51)

(52)

(58)

(56)

CONTINUOUS BIOMETRIC AUTHENTICATION USING FRAME PREAMBLE FOR BIOMETRIC DATA

Inventor: Eric E. Miller, Olathe, KS (US)

Assignee: Sprint Communications Company L.P., Overland Park, KS (US)

Notice: Subject to any disclaimer, the term of this patent is extended or adjusted under 35 U.S.C. 154(b) by 853 days.

App1.No.: 10/307,110

Filed: Nov. 27, 2002

[blocks in formation]

OTHER PUBLICATIONS

Hamid Karimi, “New spec will help secure LANs”, Aug. 30, 1999, Network World, pp. 1-3.*

Mihir Bellare, et al. Message Authentication Using Hash Functions—The HMAC Construction, RSA Laboratories’ CryptoBytes, vol. 2, No. 1, Spring 1996, pp. 1-5.

* cited by examiner

Primary Examiner—AyaZ Sheikh Assistant Examiner—Trang Doan

(57) ABSTRACT

A client connected to a network switch is continuously authenticated to a network switch by using biometrics, wherein the client and the network switch exchange Ethernet/802.3 frames associated with a client application, and wherein the client and the network switch are coupled by a fiill-duplex Ethernet/802.3 communication channel. A biometric data sample of a user of the client is captured. Biometric data is encapsulated in an authentication protocol message frame. The authentication protocol message frame is separated into a sequence of a plurality of fragments, each fragment having a predetermined number of bytes. Respective sequence numbers are assigned to each of the fragments. Each of the fragments is inserted with its respective sequence number in a respective preamble of a respective one of a plurality of Ethernet/802.3 frames associated with the client application that are being transmitted from the client to the network switch.

19 Claims, 6 Drawing Sheets

[graphic][merged small][graphic][merged small][graphic][merged small][merged small][merged small][subsumed][graphic][merged small][subsumed][merged small][subsumed][merged small][merged small][subsumed][subsumed][merged small][subsumed][graphic][merged small][subsumed][subsumed][graphic][graphic][merged small]
[graphic]

MI:

[graphic]

Close Poit; Require Re- -—/ authentication

[graphic]
[graphic][merged small][graphic][graphic][graphic][graphic][merged small][graphic][merged small][merged small][merged small][merged small][graphic][graphic][graphic][graphic][graphic][graphic][merged small][graphic]
[graphic]

Authentication Server
Compares Data to Template(s) 15

[graphic]
[graphic]

16 N Y 20 \\ Access-Deny Message Sent to Access-Accept Message Sent

Resource Via RADIUS to Resource Via RADIUS

[graphic]
[graphic]
[graphic]

I I

[graphic]
[graphic]

User Port Remains User Port Becomes Functional
Nonfunctional

[graphic]

P.

K2,

l-,.

[merged small][merged small][merged small][graphic]
[merged small][graphic][merged small][merged small][merged small][merged small][merged small][merged small][graphic][merged small][merged small][merged small][graphic][merged small][merged small][merged small][merged small][merged small][merged small][merged small][merged small][graphic][merged small][merged small][merged small][graphic][merged small][merged small][merged small][graphic][merged small][graphic][merged small][merged small][merged small][merged small][merged small][merged small][merged small][merged small][graphic][merged small][graphic][merged small][merged small]
« PreviousContinue »