IP Library Granted Patent US 7,606,242
Granted Patent B2
US 7,606,242 · App. 10/211,841 · Granted Oct 20, 2009

Managed roaming for WLANS

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,606,242
App. No.
10/211,841
Granted
Oct 20, 2009
Kind
B2
Abstract

The present invention allows any number of mobile units to roam between a large numbers of sub-networks, each with a large number of access points (tens of thousands or more total access points), with minimal direct administration effort. A hierarchy of management servers may be used across the multiple sub-networks, which can be under the control of multiple entities. The invention provides the capability for the mobile units to authenticate the access points associated with, to ensure they are both authorized and managed. Peer-to-peer and ad hoc associations between mobile units are managed as well. The invention may enforce a number of association policies such as, for example, forcing the mobile unit to only associate with access points or mobile units on a previously set mandatory association list, providing the mobile unit with a list of preferred access points to associate with, but allowing association with other access points, or providing the mobile unit with a excluded association list of access points or mobile units it is not to associate with.

Claims (97)

1. A system for securely accessing a wireless network, comprising:

a wireless mobile device configured to use wireless network protocols conforming to one or more of the IEEE 802.11 family of specifications;

wherein the wireless mobile device uses an association control list to control communication with access points; the association control list comprising a plurality of BSSIDs (Basic Service Set Identifier),

wherein the association control list is updated via communication with a server, and

wherein a second association control list and the association control list form at least a portion of an association control list hierarchy.

2. The system of claim 1 , wherein the association control list is specific to one or more network segments.

3. A system for securely accessing a wireless network, comprising:

a wireless mobile device;

wherein the wireless mobile device uses an association control list to control communication with an access point, the association control list comprising digital data representing information concerning at least one access point and whether the wireless mobile unit should communicate with the at least one access point,

wherein the association control list is updated by communicating with a server; and

wherein the server is used to facilitate the authentication of the access point by the mobile unit.

4. The system of claim 3 , wherein the wireless network conforms to one or more of the IEEE 802.11 family of specifications.

5. The system of claim 3 , wherein the wireless network conforms to one or more standards promulgated by The Bluetooth.

6. The system of claim 3 , wherein the wireless network is infrared.

7. The system of claim 3 , wherein the association control list comprises a list of preferred access points with which the wireless mobile device will associate with.

8. The system of claim 7 , wherein the wireless mobile device searches for an access point on the list of preferred access point when the wireless mobile unit is not associated with an access point on the list of preferred access points.

9. The system of claim 3 , wherein the association control list is determined to reduce the cost of network access.

10. The system of claim 3 , wherein the association control list is determined to increase network capacity and performance.

11. The system of claim 3 , wherein the association control list comprises information identifying one or more access points with which the wireless mobile device is forbidden to associate.

12. The system of claim 3 , wherein the association control list comprises information identifying one or more access points with which the wireless mobile device must exclusively associate.

13. The system of claim 3 , wherein the communication occurs over the wireless network.

14. The system of claim 13 , wherein access points are authenticated before updating the association control list via the access point.

15. The system of claim 3 , wherein the communication occurs when the one or more mobile units are connected to a wired network.

16. The system of claim 3 , wherein the server is authenticated before updating the association control list.

17. The system of claim 3 , wherein the association control list is updated by communicating with a first server and is further updated by communicating with one or more additional servers.

18. The system of claim 17 , wherein the first server and the one or more additional servers are hierarchically related.

19. The system of claim 17 , wherein a precedence of association control policies applied the access control lists is determined with respect to the hierarchy.

20. The system of claim 3 , wherein the association control list is updated by communicating with a first server, and a second association control list is updated by communicating with a second server, and

the mobile device uses the association control list and the second association control list to control communication with access points.

21. The system of claim 3 , wherein the server automatically detects the presence of at least one new access point on at least one network segment and subsequently updates the association control list.

22. The system of claim 21 , wherein the server adds the at least one access point with a known property or type to the association control list.

23. The system of claim 21 , wherein the server adds information identifying one or more access points of unknown type or properties to at least one association control list so as to forbid wireless devices using the at least one association control list from associating with the one or more access points of unknown type or properties.

24. The system of claim 21 , wherein authorization of a network administrator is required to update an association control list.

25. The system of claim 3 , wherein the association control list is specific to one or more network segments.

26. The system of claim 3 , wherein the mobile device selects among a plurality of association control lists to control communication with access points based on an access point identifier transmitted by each access point.

27. A system for securely accessing a wireless network, comprising:

a wireless mobile device comprising a processor and memory,

wherein the wireless mobile device associates with an access point and sends a request to a server for confirmation that the access point is authorized, the access point comprising a wireless device for communicating with other wireless devices and a wired network interface for communicating via a wired network,

wherein the wireless network conforms to one or more of the IEEE 802.11 family of specifications, and

wherein the wireless mobile device stores an identifier of the access point if the server does not confirm that the access point is authorized, and subsequently transmits the identifier to the server.

28. The system of claim 27 , wherein the wireless mobile device ceases association with the access point if the wireless mobile device does not receive confirmation that the access point is authorized.

29. The system of claim 27 , wherein the wireless network conforms to one or more standards promulgated by The Bluetooth.

30. The system of claim 27 , wherein the wireless network is infrared.

31. The system of claim 27 , wherein the server adds information identifying the access point to at least one association control list so as to forbid wireless devices using the at least one association control list from associating with the access point.

32. The system of claim 31 , wherein authorization of a network administrator is required to update the list of access points.

33. A system for securely accessing a wireless network, comprising a server configured to receive a request to authenticate an access point from a wireless mobile device, the server being further configured to determine whether the wireless mobile device is associated with the access point and whether the access point is authorized, and to provide a response to the wireless mobile device indicating whether the mobile device is authorized to continue association with the access point,

wherein the server is further configured to detect each association between the access point and the wireless mobile device and to disable communications between the access point and the wireless mobile device if no request to authenticate the access point is received within a predetermined interval.

34. The system of claim 33 , wherein the server restricts the network access or network service privileges of the mobile device if the mobile device is not authorized.

35. A wireless communication security system, comprising:

a first wireless mobile device;

a server system comprising a plurality of servers;

wherein the first wireless mobile uses an association control list to control communication with other wireless mobile devices via at least one access point; the association control list comprising a plurality of identifiers, each identifier uniquely identifying a wireless mobile device,

wherein one or more servers of the plurality of servers control the content of the association control list, and wherein the plurality of servers are organized hierarchically.

36. The system of claim 35 , wherein the wireless network conforms to one or more of the IEEE 802.11 family of specifications.

37. The system of claim 35 , wherein the wireless network conforms to one or more standards promulgated by The Bluetooth.

38. The system of claim 35 , wherein the wireless network is infrared.

39. The system of claim 35 , wherein the identifiers comprise IBSSIDs.

40. The system of claim 35 , wherein the association control list comprises information identifying one or more other mobile units with which a given mobile unit is forbidden to associate with.

41. The system of claim 35 , wherein the control list comprises information identifying one or more other mobile units with which a given mobile unit must exclusively associate with.

42. A system for securely accessing a wireless network, comprising:

a wireless mobile device,

wherein the mobile device uses an association control list to control communication with access points and to update the association control list by communicating with a server, and

wherein the association control list is a user-configurable association control list.

43. A system for securely accessing a wireless network comprising:

a server system comprising a plurality of computer servers, wherein at least one server computer of the plurality of computer servers being operatively connected to a communications network,

wherein the system being configured to receive at least one access point identifier from a wireless mobile unit via the communication network, the system being further configured to transmit to the wireless mobile unit information concerning at least one access point and whether the mobile unit should communicate with the at least one access point,

wherein the a plurality of servers are organized hierarchically, and wherein the server system is further configured to receive an identifier of the mobile unit.

44. The system of claim 43 , wherein the server system is further configured to apply a criterion to determine at least a portion of the information.

45. The system of claim 44 , wherein the criterion is inclusion of an identifier in an association control list.

46. The system of claim 45 , wherein the wireless mobile unit complies with one or more of the IEEE 802.11 family of standards.

47. The system of claim 46 , wherein the access point identifier comprises a BSSID.

48. The system of claim 45 , wherein the wireless network conforms to one or more standards promulgated by The Bluetooth.

49. The system of claim 45 , wherein the association control list comprises information identifying one or more access points with which the unit is forbidden to associate with.

50. The system of claim 45 , wherein the association control list comprises information identifying one or more access points with which the mobile unit must exclusively associate with.

51. The system of claim 45 , wherein the wireless network is infrared.

52. A system for securely accessing a wireless network, comprising:

a wireless mobile unit comprising a processor and memory,

wherein the wireless mobile unit transmits to a server system comprising a plurality of servers a data structure comprising identifiers of access points within range of the wireless mobile units;

wherein the wireless mobile unit receives from the server system information concerning at least one access point and whether the mobile unit should communicate with the at least one access point, and

wherein the server system is organized hierarchically.

53. A system for securely accessing a wireless network, comprising:

a wireless mobile unit comprising a processor and memory;

wherein the wireless mobile unit receives an association control list from an access point, the association control list comprising digital data representing information concerning at least one access point and whether the wireless mobile unit should communicate with the at least one access point,

wherein the association control list is updated by communicating with a server, and wherein the server is authenticated for associating the access point with the mobile unit before updating the association control list.

54. A system for securely accessing a wireless network comprising:

an access point for communicating with wireless devices;

a server system comprising a plurality of servers; and

a wired network interface for communicating via a wired network,

wherein the access point is configured to wirelessly transmit an association control list, the association control list comprising digital data representing information concerning at least one access point and whether at least one wireless mobile device should communicate with the at least one access point,

wherein the access point is further configured to periodically broadcast the association control list,

wherein one or more servers of the plurality of servers control the content of the association control list, and wherein the plurality of servers are organized hierarchically.

55. The system of claim 54 , wherein the wireless network conforms to one or more of the IEEE 802.11 family of specifications.

56. The system of claim 55 , wherein the digital data comprises a BSSID.

57. The system of claim 54 , wherein the wireless network conforms to one or more standards promulgated by The Bluetooth.

58. The system of claim 54 , wherein the wireless network is infrared.

59. The system of claim 54 , wherein the association control list comprises information identifying one or more access points with which the at least one mobile device is forbidden to associate with.

60. The system of claim 54 , wherein the association control list comprises information identifying one or more access points with which the at least one mobile device must exclusively associate with.

Assignments (32)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41052/0762 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054560/0857 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 41459/0387 Recorded Dec 1, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: CRIMSON CORPORATION
Reel/Frame 054637/0161 →
MERGER Recorded Apr 19, 2018
From: CRIMSON CORPORATION
To: IVANTI, INC.
Reel/Frame 045983/0075 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40183/0506 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0457 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 40182/0345 Recorded Jan 23, 2017
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 041463/0581 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041459/0387 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jan 20, 2017
From: CRIMSON CORPORATION
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 041052/0762 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040183/0506 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 29, 2016
From: CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 040182/0345 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 031029/0849 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0307 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 032333/0637 Recorded Sep 28, 2016
From: JEFFERIES FINANCE LLC
To: CRIMSON CORPORATION
Reel/Frame 040171/0037 →
SECURITY AGREEMENT Recorded Feb 25, 2014
From: LANDESK SOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 032333/0637 →
SECURITY AGREEMENT Recorded Aug 16, 2013
From: LANDESK GROUP, INC.; LANDSLIDE HOLDINGS, INC.; CRIMSON ACQUISITION CORP.; LANDESKSOFTWARE, INC.; CRIMSON CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 031029/0849 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: CRIMSON CORPORATION
Reel/Frame 030993/0644 →
ARTICLES OF CORRECTION FOR CERTIFICATE OF MERGER. THE EFFECTIVE DATE OF THE MERGER IS JUNE 29, 2012. Recorded Nov 15, 2012
From: WAVELINK CORPORATION
To: WAVELINK SOFTWARE LLC
Reel/Frame 029309/0177 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2012
From: WAVELINK SOFTWARE LLC
To: CRIMSON CORPORATION
Reel/Frame 029213/0681 →
MERGER Recorded Oct 8, 2012
From: WAVELINK CORPORATION
To: WAVELINK SOFTWARE LLC
Reel/Frame 029092/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2012
From: WAVELINK SOFTWARE LLC
To: CRIMSON CORPORATION
Reel/Frame 029092/0559 →
PATENT SECURITY AGREEMENT Recorded Jul 26, 2012
From: CRIMSON CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 028643/0847 →
RELEASE OF SECURITY INTEREST Recorded Jun 20, 2012
From: SILICON VALLEY BANK
To: WAVELINK CORPORATION
Reel/Frame 028413/0021 →
RELEASE OF SECURITY INTEREST Recorded Jun 14, 2012
From: SILICON VALLEY BANK
To: WAVELINK CORPORATION
Reel/Frame 028407/0024 →
RELEASE OF SECURITY INTEREST Recorded Aug 3, 2010
From: CAPITALSOURCE FINANCE LLC, AS AGENT
To: WAVELINK CORPORATION
Reel/Frame 024776/0781 →
SECURITY AGREEMENT Recorded Jul 6, 2010
From: WAVELINK CORPORATION
To: SILICON VALLEY BANK
Reel/Frame 024630/0981 →
ACK OF INTEL. PROP. COLLATERAL LIEN Recorded Nov 1, 2006
From: WAVELINK CORPORATION
To: CAPITALSOURCE FINANCE LLC
Reel/Frame 018471/0522 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2002
From: WHELAN, ROBERT; WAGENEN, LAMAR VAN; MORRIS, ROY
To: WAVELINK CORPORATION
Reel/Frame 013381/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 24, 2002
From: WHELAN, ROBERT; VAN WAGENEN, LAMAR; MORRIS, ROY
To: WAVELINK CORPORATION
Reel/Frame 013334/0316 →