The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 10, 2023

Filed:

Apr. 18, 2022
Applicant:

Cisco Technology, Inc., San Jose, CA (US);

Inventors:

Sujal Sheth, Gujarat, IN;

Shwetha Subray Bhandari, Bangalore, IN;

Eric Voit, Bethesda, MD (US);

William F. Sulzen, Apex, NC (US);

Frank Brockners, Cologne, DE;

Assignee:

Cisco Technology, Inc., San Jose, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 9/08 (2006.01); H04L 9/32 (2006.01); H04L 9/40 (2022.01);
U.S. Cl.
CPC ...
H04L 9/0866 (2013.01); H04L 9/0869 (2013.01); H04L 9/3242 (2013.01); H04L 9/3247 (2013.01); H04L 63/0869 (2013.01); H04L 63/10 (2013.01); H04L 63/108 (2013.01); H04L 2209/12 (2013.01);
Abstract

Systems, methods, and computer-readable media for authenticating access control messages include receiving, at a first node, access control messages from a second node. The first node and the second node including network devices and the access control messages can be based on RADIUS or TACACS+ protocols among others. The first node can obtain attestation information from one or more fields of the access control messages determine whether the second node is authentic and trustworthy based on the attestation information. The first node can also determine reliability or freshness of the access control messages based on the attestation information. The first node can be a server and the second node can be a client, or the first node can be a client and the second node can be a server. The attestation information can include Proof of Integrity based on a hardware fingerprint, device identifier, or Canary Stamp.


Find Patent Forward Citations

Loading…