US 12,407,670 B2
Zero sign-on authentication
Stuart Hoggan, Longmont, CO (US); and Seetharama R. Durbha, Louisville, CO (US)
Assigned to Cable Television Laboratories, Inc., Louisville, CO (US)
Filed by CABLE TELEVISION LABORATORIES, INC., Louisville, CO (US)
Filed on Nov. 15, 2021, as Appl. No. 17/526,859.
Application 17/526,859 is a continuation of application No. 15/967,730, filed on May 1, 2018, granted, now 11,178,130.
Application 15/967,730 is a continuation of application No. 14/617,757, filed on Feb. 9, 2015, granted, now 9,961,067, issued on May 1, 2018.
Application 14/617,757 is a continuation of application No. 13/173,630, filed on Jun. 30, 2011, granted, now 8,955,078, issued on Feb. 10, 2015.
Prior Publication US 2022/0078179 A1, Mar. 10, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01); H04L 9/32 (2006.01)
CPC H04L 63/0815 (2013.01) [H04L 9/3263 (2013.01); H04L 63/0823 (2013.01); H04L 63/083 (2013.01); H04L 63/0876 (2013.01)] 18 Claims
OG exemplary drawing
 
1. A method for authenticating a device for zero sign-on (ZSO) access to a service available through one or more access points, the method comprising:
(i-a) ensuring an Internet Protocol (IP) subnet address of the device matches an IP subnet address of a first access point of the one or more access points;
(i-b) determining a Media Access Control (MAC) address for the first access point as being associated with the device when a mapping of device IP addresses and MAC addresses performed upstream of the first access point maps a device IP address of the device to the MAC address of the first access point;
(ii) identifying the first access point and the device as falling within a trusted domain when the subnet address of the device matches the subnet address of the first access point in step (i-a) and the MAC address of the first access point is determined to be associated with the device in step (i-b); and
(iii) facilitating transport of a trust credential to the device when the first access point and the device fall within the trusted domain, thereby enabling the device to use the trust credential to facilitate ZSO access to the service,
wherein the mappings of the device IP addresses and the MAC addresses is generated prior to a credential request being issued from the device to the first access point, the credential request being used to request transport of the trust credential, to the device, and
wherein the credential request includes the MAC address of the first access point.