US2017171162A1PendingUtilityA1

Proxy authentication for a multiple core network device

Assignee: SONICWALL INCPriority: Jan 26, 2015Filed: Feb 28, 2017Published: Jun 15, 2017
Est. expiryJan 26, 2035(~8.5 yrs left)· nominal 20-yr term from priority
H04L 63/102H04L 63/0281H04L 63/10H04L 63/0884H04L 63/083H04L 63/164
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention is generally related to a network computing device including a first processor communicating with a second processor as a proxy for a client device when authenticating access privileges of the client device. The present invention may include more than two processors where at least one of the multiple processors may be optimized for performing one or more control functions and one or more other processors may be optimized for transferring data or administrating the transfer of data through a gateway or firewall.

Claims

exact text as granted — not AI-modified
1 . A method for proxy authentication, the method comprising:
 receiving an authentication request at a first processor of a multi-processor computing device, the authentication request sent by a client device in order to access computing resources of a computing network;   forwarding the authentication request from the first processor to a second processor of the multi-processor computing device, the second processor executing software to authenticate the client device;   forwarding an authentication response from the second processor to the first processor; and   enabling the client device to access the computing resources of the computing network when the authentication response indicates that the client device is authorized, wherein the first processor executes software to process data transfer to the client device.   
     
     
         2 . The method of  claim 1 , further comprising establishing a connection between the first processor and the second processor, wherein the authentication request is forwarded from the first processor to the second processor over the established connection, and wherein the authentication response is forwarded from the second processor to the first processor over the established connection. 
     
     
         3 . The method of  claim 2 , wherein the established connection is a socket connection, and wherein the first processor uses an internet protocol address and a port number associated with the client device to forward the authentication request to the second processor. 
     
     
         4 . The method of  claim 1 , wherein the authentication request includes credentials, and wherein the client device is validated when the credentials match credential information stored at an authentication server. 
     
     
         5 . The method of  claim 1 , further comprising receiving a request to initiate secure communications over a secure socket layer at the multi-processor computing device, the request received prior to receiving the authentication request. 
     
     
         6 . The method of  claim 1 , wherein enabling the client device to access the computing resources of the computing network is based on an access rule defined in the first software. 
     
     
         7 . A non-transitory computer-readable storage medium, having embodied thereon a program comprising instructions executable by a processor to perform a method for proxy authentication, the method comprising:
 receiving an authentication request at a first processor of a multi-processor computing device, the authentication request sent by a client device in order to access computing resources of a computing network;   forwarding the authentication request from the first processor to a second processor of the multi-processor computing device, the second processor executing software to authenticate the client device;   forwarding an authentication response from the second processor to the first processor; and   enabling the client device to access the computing resources of the computing network when the authentication response indicates that the client device is authorized, wherein the first processor executes software to process data transfer to the client device.   
     
     
         8 . The non-transitory computer readable medium of  claim 7 , further comprising instructions executable to establish a connection between the first processor and the second processor, wherein the authentication request is forwarded from the first processor to the second processor over the established connection, and wherein the authentication response is forwarded from the second processor to the first processor over the established connection. 
     
     
         9 . The non-transitory computer readable medium of  claim 8 , wherein the established connection is a socket connection, and wherein the first processor uses an internet protocol address and a port number associated with the client device to forward the authentication request to the second processor. 
     
     
         10 . The non-transitory computer readable medium of  claim 7 , wherein the authentication request includes credentials, and wherein the client device is validated when the credentials match credential information stored at an authentication server. 
     
     
         11 . The non-transitory computer readable medium of  claim 7 , further comprising receiving a request to initiate secure communications over a secure socket layer at the multi-processor computing device, the request received prior to receiving the authentication request. 
     
     
         12 . The non-transitory computer readable medium of  claim 7 , wherein enabling the client device to access the computing resources of the computing network is based on an access rule defined in the first software. 
     
     
         13 . A system for proxy authentication, the system comprising:
 a computing network server that hosts computing resources; and   a multi-processor computing device comprising:
 a first processor that receives an authentication request sent by a client device in order to access computing resources of a computing network; and 
 a second processor that:
 receives the authentication request forwarded by the first processor, 
 executes software to authenticate the client device, and 
 forwards an authentication response to the first processor; 
 
 wherein the first processor executes software to process data transfer to the client device when the authentication response indicates that the client device is authorized, thereby enabling the client device to access the computing resources of the computing network. 
   
     
     
         14 . The system of  claim 13 , wherein the multi-processor computing device further establishes a connection between the first processor and the second processor, wherein the authentication request is forwarded from the first processor to the second processor over the established connection, and wherein the authentication response is forwarded from the second processor to the first processor over the established connection. 
     
     
         15 . The system of  claim 14 , wherein the established connection is a socket connection, wherein the first processor uses an internet protocol address and a port number associated with the client device to forward the authentication request to the second processor. 
     
     
         16 . The system of  claim 13 , wherein the authentication request includes credentials, and wherein the client device is validated when the credentials match credential information stored at an authentication server. 
     
     
         17 . The system of  claim 13 , wherein the multi-processor computing device further receives a request to initiate secure communications over a secure socket layer at the multi-processor computing device, the request received prior to receiving the authentication request. 
     
     
         18 . The system of  claim 13 , wherein enabling the client device to access the computing resources of the computing network is based on an access rule defined in the first software.

Join the waitlist — get patent alerts

Track US2017171162A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.