IP Library Granted Patent US 7,769,995
Granted Patent B2
US 7,769,995 · App. 10/999,555 · Granted Aug 3, 2010

System and method for providing secure network access

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,769,995
App. No.
10/999,555
Granted
Aug 3, 2010
Kind
B2
Abstract

Secure network access is provided by connecting a secure network provisioning device to a security authority, acquiring one or more network profiles, configuring one or more network interfaces of the secure network provisioning device with data corresponding to attributes of the acquired network profiles, switching the secure network provisioning device from an acquisition mode to a gateway mode, and connecting the secure network provisioning device to a client device. The secure network provisioning device includes a first set of network communication interfaces requiring configuration blocks to enable access to associated networks, a second set of network communication interfaces free from a requirement for configuration prior to network access, a communication interface gateway module configured to gate network traffic between network communication interfaces and a network profile acquisition module configured to acquire network profiles containing data required to configure the communication interfaces of the first set.

Claims (36)

1. A computer-implemented method of providing secure network access, comprising:

connecting, via a first interface, a secure network provisioning device to a security authority;

acquiring, by the secure network provisioning device operating in an acquisition mode, at least one network profile from the security authority;

configuring at least a second interface of the secure network provisioning device with data corresponding to attributes of said at least one network profile;

switching the secure network provisioning device from the acquisition mode to a gateway mode, in which gateway mode the secure network provisioning device functions as a gateway;

connecting, via the first interface, the secure network provisioning device to a client device, the first interface having been disconnected from the security authority; and

for each of said at least one network profile, providing the client device, while in the gateway mode, with access through at least the second interface to a secure network associated with the network profile,

wherein disconnection of the first interface of the secure network provisioning device from the client device terminates access to the secure network by the client device.

2. The method of claim 1 , further comprising, in response to a reset command:

erasing said at least one network profile from the secure network provisioning device; and

switching the secure network provisioning device from the gateway mode to the acquisition mode.

3. The method of claim 1 , wherein one of said at least a second interface is a wireless network interface.

4. The method of claim 1 , wherein connecting the secure network provisioning device to the security authority requires physical proximity of the secure network provisioning device and the security authority.

5. The method of claim 1 , wherein connecting the secure network provisioning device to the client device requires physical proximity of the secure network provisioning device and the client device.

6. The method of claim 1 , wherein the first interface is a secure network provisioning device is connected to the security authority through a network interface independent of said at least one network interface.

7. The method of claim 6 , wherein the first interface is a wire-line network interface.

8. The method of claim 6 , wherein the secure network provisioning device presents as a plurality of computing devices, the plurality of devices comprising:

a secure network provisioning device ready to acquire network profiles when in the acquisition mode; and

a standard network interface when in the gateway mode.

9. The method of claim 8 , wherein the first interface is a universal serial bus (USB) interface and presenting as a plurality of devices comprises enumerating different universal serial bus (USB) enumeration class identifiers in different modes.

10. A computer storage medium having thereon computer-executable instructions for providing secure network access to a client device through a secure network provisioning device, the instructions operable to perform a method comprising:

managing at least one network profile associated with a secure network;

accepting a connection from the secure network provisioning device in an acquisition mode, the connection over a first interface of the secure network provisioning device, the secure network provisioning device having a plurality of operating modes including the acquisition mode and a gateway mode; and

providing over the first interface said at least one network profile to the secure network provisioning device, each network profile enabling the secure network provisioning device to provide the client device with access to the secure network associated with the network profile by functioning as a gateway between the client device, connected via the first interface, and the secure network, connected via a second interface, when the secure network provisioning device switches to the gateway mode and the first interface of the secure network provisioning device is disconnected from the computer storage medium and connected to the client device.

11. The computer storage medium of claim 10 , wherein providing said at least one network profile to the secure network provisioning device comprises engaging in a network profile acquisition protocol with the secure network provisioning device.

12. The computer storage medium of claim 11 , wherein the secure network provisioning device switches from acquisition mode to gateway mode upon completion of the network profile acquisition protocol.

13. The computer storage medium of claim 10 , wherein access to each secure network requires valid authentication credentials.

14. The computer storage medium of claim 10 , wherein managing said at least one network profile comprises, for each network profile, at least one of creating, reading and updating the network profile.

15. The computer storage medium of claim 10 , further comprising recognizing the secure network provisioning device with plug-and-play (PnP).

16. The computer storage medium of claim 10 , wherein accepting the connection from the secure network provisioning device requires physical proximity of the secure network provisioning device and the computer-readable medium.

17. The computer storage medium of claim 10 , wherein providing the client device with access to the secure network requires physical proximity of the secure network provisioning device and the client device.

18. The computer storage medium of claim 10 , wherein the first interface is a wire-line network interface.

19. The computer storage medium of claim 10 , wherein the secure network provisioning device is capable of presenting as a plurality of computing devices, the plurality of devices comprising:

a secure network provisioning device ready to acquire network profiles when in the acquisition mode; and

a standard network interface when in the gateway mode.

20. The computer storage medium of claim 19 , wherein the first interface is a universal serial bus (USB) interface and presenting as the plurality of devices comprises enumerating different universal serial bus (USB) enumeration class identifiers in different modes.

Assignments (8)
CHANGE OF NAME Recorded Sep 25, 2024
From: ROVI TECHNOLOGIES CORPORATION
To: ADEIA TECHNOLOGIES INC.
Reel/Frame 069048/0223 →
RELEASE OF SECURITY INTEREST Recorded Jun 5, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
Reel/Frame 053481/0790 →
RELEASE OF SECURITY INTEREST Recorded Jun 5, 2020
From: HPS INVESTMENT PARTNERS, LLC
To: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
Reel/Frame 053458/0749 →
SECURITY INTEREST Recorded Jun 1, 2020
From: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS INC.; VEVEO, INC.; INVENSAS CORPORATION; INVENSAS BONDING TECHNOLOGIES, INC.; TESSERA, INC.; TESSERA ADVANCED TECHNOLOGIES, INC.; DTS, INC.; PHORUS, INC.; IBIQUITY DIGITAL CORPORATION
To: BANK OF AMERICA, N.A.
Reel/Frame 053468/0001 →
PATENT SECURITY AGREEMENT Recorded Nov 25, 2019
From: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 051110/0006 →
SECURITY INTEREST Recorded Nov 22, 2019
From: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 051143/0468 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2014
From: MICROSOFT CORPORATION
To: ROVI TECHNOLOGIES CORPORATION
Reel/Frame 034539/0676 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2005
From: CORBETT, CHRISTOPHER J.; MANCHESTER, SCOTT A.; NICK, BENJAMIN E.; ABIEZZI, SALIM S.
To: MICROSOFT CORPORATION
Reel/Frame 015545/0725 →