IP Library Granted Patent US 8,134,987
Granted Patent B2
US 8,134,987 · App. 12/267,359 · Granted Mar 13, 2012

Methods and apparatus for split policy enforcement in wireless networks

Assignee: Symbol Technologies, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,134,987
App. No.
12/267,359
Granted
Mar 13, 2012
Kind
B2
Abstract

A wireless local area network system allows policy enforcement execution to be split between an access port and a centralized wireless controller. The policy may be of various types, including, but not limited to, a firewall policy, a QoS policy, a traffic shaping policy, and a bandwidth-management policy. On the AP, for all the traffic that is to be bridged or forwarded to specified ports, the policy table on the AP is checked. If it matches the policy table entry, then the specified action is taken. For all the traffic that gets forwarded to the controller by the AP, the match is checked with the policy table at the controller. If a match is detected, then the appropriate action specified by the policy is taken.

Claims (23)

1. A wireless local area network of the type including a controller and at least one access point, wherein policy enforcement for the wireless local area network is performed in part by both the controller and in part the access point, and wherein policy enforcement is conducted in accordance with policies included in a first policy table that includes: an access control list associated with the wireless local area network; and a set of rules associated with the access control list.

2. The wireless local area network of claim 1 , wherein the controller includes the first policy table associated with the network, and the access point includes a second policy table associated with the network, and the first and second policy tables collectively include all policies required for the policy enforcement.

3. The wireless local area network of claim 2 , wherein the second policy table includes: an access control list associated with the wireless local area network; and a set of rules associated with the access control list.

4. The wireless local area network of claim 2 , wherein at least one of the first policy table and the second policy table include at least one quality-of-service rule.

5. The wireless local area network of claim 2 , wherein at least one of the first policy table and the second policy table include at least one bandwidth rule.

6. The wireless local area network of claim 1 , wherein, each policy has an associated enforcement point corresponding to either the access point or the controller.

7. The wireless local area network of claim 6 , wherein the enforcement point associated with each policy is configured by an algorithm.

8. The wireless local area network of claim 2 , wherein the second policy table is pushed to the access point by the controller.

9. A method of performing policy enforcement in a wireless local area network of the type including a controller and at least one access point, comprising the steps of:

determining an enforcement point of each of a set of policies associated with the network,

wherein the enforcement point is one of the controller and the access point;

providing, within the controller, a first policy table associated with policies having an enforcement point corresponding to the controller, wherein the first policy table includes: an access control list associated with the wireless local area network; and a set of rules associated with the access control list;

providing, within the access point, a second policy table associated with policies having an enforcement point corresponding to the access point;

receiving data traffic;

comparing the data traffic with at least one of the first set of policies and the second set of policies to determine a matched policy; and

taking an action, with respect to the data traffic, as specified by the matched policy.

10. The method of claim 9 , wherein the second policy table includes: an access control list associated with the wireless local area network; and a set of rules associated with the access control list.

11. The method of claim 9 , wherein at least one of the first policy table and the second policy table include at least one quality-of-service rule.

12. The method of claim 9 , wherein at least one of the first policy table and the second policy table include at least one bandwidth rule.

13. The method of claim 9 , further including the step of configuring the enforcement points based on an algorithm.

14. The method of claim 9 , wherein providing the second policy table includes pushing the second policy table to the access point from the controller.

15. An access point configured to store a policy table consisting of a proper subset of a set of policies associated with a wireless local area network for which the access point is adapted, wherein the policy table includes: an access control list associated with the wireless local area network; and a set of rules associated with the access control list.

16. The access point of claim 15 , further configured to receive the policy table over the network from a controller.

Assignments (13)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: SYMBOL TECHNOLOGIES, LLC
To: EXTREME NETWORKS, INC.
Reel/Frame 040579/0410 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
RELEASE OF SECURITY INTEREST Recorded Aug 17, 2015
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 036371/0738 →
CHANGE OF NAME Recorded Jul 8, 2015
From: SYMBOL TECHNOLOGIES, INC.
To: SYMBOL TECHNOLOGIES, LLC
Reel/Frame 036083/0640 →
SECURITY AGREEMENT Recorded Oct 31, 2014
From: ZIH CORP.; LASER BAND, LLC; ZEBRA ENTERPRISE SOLUTIONS CORP.; SYMBOL TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC. AS THE COLLATERAL AGENT
Reel/Frame 034114/0270 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2008
From: VERMA, ANURAG; BHAT, LAXMINARAYAN
To: SYMBOL TECHNOLOGIES, INC.
Reel/Frame 021941/0306 →
Continuity (2)
Provisional Application 60988969 · Nov 19, 2007
Related Publication 20090129352A1 · May 21, 2009