US2007039039A1PendingUtilityA1

Authorization of device access to network services

Assignee: MICROSOFT CORPPriority: Aug 10, 2005Filed: Aug 10, 2005Published: Feb 15, 2007
Est. expiryAug 10, 2025(expired)· nominal 20-yr term from priority
G06F 2221/2101G06F 2221/2129G06F 2221/2149H04L 63/06H04L 63/0853H04L 63/10H04L 63/08H04L 63/0876G06F 21/6218
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The invention provides for authorization of devices entering a network. A new device entering a network sends an authorization request. Another device in the network may receive the request and display a User Interface (UI) which prompts the user to approve the device. The user can use a device identifier provided by the new device in approving the new device. Assuming the identifier provided by the new device matches an identifier accessible by the authorizing device, the user authorizes the new device. A key is then generated for the new device, which allows access to an appropriate range of network services. Authorization decisions can be synchronized among the various devices in a network, so even if an authorizing device leaves the network, the new device key can be validated. A security service can be replicated in a new device once the device is authorized to access the network.

Claims

exact text as granted — not AI-modified
1 . A method for securing a network, comprising: 
 sending, by a first device, an authorization request;    presenting, by a second device, a representation of the authorization request in a User Interface (UI);    providing, by said first device, a device identifier (ID);    approving, by a user via said UI, the first device, wherein said approving comprises using the device ID;    generating a key for the first device, wherein at least one network service may be accessed using said key.    
     
     
         2 . The method of  claim 1 , wherein said authorization request comprises the device ID.  
     
     
         3 . The method of  claim 2 , wherein said representation of the authorization request comprises the device ID.  
     
     
         4 . The method of  claim 3 , wherein said using the device ID comprises comparing, by the user, the device ID in said representation of the authorization request with the device ID provided by said first device.  
     
     
         5 . The method of  claim 1 , wherein said using the device ID comprises entering, by the user, the device ID provided by said first device, and wherein the device ID is entered into the second device.  
     
     
         6 . The method of  claim 5 , wherein the key is generated by the first device and by the second device.  
     
     
         7 . The method of  claim 1 , further comprising broadcasting, by the second device, the authorization request.  
     
     
         8 . The method of  claim 1 , further comprising sending, by the second device to a third device, an indication that the first device is authorized to access the at least one network service.  
     
     
         9 . An article of manufacture comprising computer readable instructions for execution by a computing device, the instructions comprising: 
 instructions for detecting a signal from a first computing device, wherein said signal comprises an authorization request;    instructions for displaying said authorization request in a User Interface (UI);    instructions for generating a key for said first computing device, wherein said key allows said first computing device to access at least one network service, and wherein said instructions for generating are carried out in response to an approval from a user provided via said UI.    
     
     
         10 . The article of manufacture of  claim 9 , wherein the network service comprises a software application executing on one or more of a plurality of networked computing devices.  
     
     
         11 . The article of manufacture of  claim 9 , wherein the instructions for detecting a broadcast signal utilize the Web Services Security (WS-Security) protocol.  
     
     
         12 . The article of manufacture of  claim 9 , wherein the instructions for detecting a signal utilize the Universal Plug and Play (UPnP) discovery protocol.  
     
     
         13 . The article of manufacture of  claim 9 , wherein the UI prompts the user to compare a first device ID in said UI with a second device ID provided by said first computing device to determine if the first and second device IDs are identical.  
     
     
         14 . The article of manufacture of  claim 9 , further comprising instructions for restricting access by said first computing device to a subset of network services corresponding to a device class associated with said first computing device.  
     
     
         15 . The article of manufacture of  claim 9 , further comprising instructions for restricting access by said first computing device to a subset of network services allowed to a user of said first computing device.  
     
     
         16 . The article of manufacture of  claim 9 , further comprising instructions for synchronizing security information with at least one second computing device, such that if the first computing device delivers the key to the second computing device, then the second computing device allows access to the network service.  
     
     
         17 . A computing device comprising means for requesting authorization to access a network service, said means comprising: 
 means for detecting that said computing device is operably connected to a network;    means for determining if said computing device can access a network service available on said network;    means for sending an authorization request, wherein said means for sending is triggered if it is determined by said means for determining that said computing device can not access said network service;    means for providing a device ID;    means for receiving a key from a second computing device associated with said network;    means for using the key to access the network service.    
     
     
         18 . The computing device of  claim 17 , wherein said means for sending an authorization request utilizes the Web Services Security (WS-Security) protocol.  
     
     
         19 . The computing device of  claim 17 , said means for sending an authorization request utilizes the Universal Plug and Play (UPnP) discovery protocol.  
     
     
         20 . The computing device of  claim 17 , further comprising means for authorizing a third device to access the network service.

Join the waitlist — get patent alerts

Track US2007039039A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.