US 11,811,765 B1
Maximum device access restriction at authenticator level
Nandan Debnath, Bangalore (IN); Alfa Prakash Puhan, Bangalore (IN); and Subha Sankar Mishra, Bangalore (IN)
Assigned to Juniper Networks, Inc., Sunnyvale, CA (US)
Filed by Juniper Networks, Inc., Sunnyvale, CA (US)
Filed on Mar. 31, 2020, as Appl. No. 16/836,733.
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01)
CPC H04L 63/10 (2013.01) [H04L 63/083 (2013.01); H04L 63/0892 (2013.01); H04L 63/1416 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method, comprising:
receiving, by a network device, a request to access a network from a client device;
obtaining, by the network device, a set of authentication credentials for the client device based on receiving the request,
wherein the set of authentication credentials includes one or more of:
a security certificate,
a security token, or
a biometric;
determining, by the network device, that the client device is authenticated based on a type of device and based on the set of authentication credentials,
wherein determining that the client device is authenticated comprises:
sending, by the network device and to a server device, an authentication response, and
receiving, by the network device and from the server device, an authentication acceptance message that includes information indicating that the set of authentication credentials are accepted;
determining, by the network device and based on the client device being authenticated, a first quantity,
wherein the first quantity identifies a maximum quantity of the type of device permitted to concurrently access the network utilizing a same authentication credential of the set of authentication credentials;
determining, by the network device, a second quantity,
wherein the second quantity identifies a quantity of the type of device currently accessing the network utilizing the set of authentication credentials;
determining, by the network device, whether the second quantity is less than the first quantity; and
selectively permitting, by the network device, the client device access to the network based on whether the second quantity is less than the first quantity,
wherein the client device is to be permitted access to the network when the second quantity is less than the first quantity,
wherein the client device is to be denied access to the network when the second quantity is not less than the first quantity.