IP Library Granted Patent US 8,189,608
Granted Patent B2
US 8,189,608 · App. 12/724,363 · Granted May 29, 2012

Wireless extender secure discovery and provisioning

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,189,608
App. No.
12/724,363
Granted
May 29, 2012
Kind
B2
Abstract

According to embodiments of the invention, a first wireless access point discovers a second wireless access point, the first wireless access point tunes its radio and privacy settings, without user input, based upon parameters automatically exchanged in response to the discovery of the second wireless access point, and a secure direct wireless connection is established between the first and second wireless access points using the radio and privacy settings. Adding the first wireless to an existing mesh network includes a determination of the best available direct wireless connection.

Claims (71)

1. A computer-implemented method to extend a wireless network, the method comprising:

discovering a first wireless access point by a second wireless access point capable of acting as a wireless extender;

automatically, in response to the discovery of the first wireless access point, exchanging parameters between the first and second wireless access points;

self-tuning, by the second wireless access point without user input, radio and privacy settings to establish a secure direct wireless connection between the first and second wireless access points based upon the exchanged parameters; and

establishing the secure direct wireless connection between the first and second wireless access points using the radio and privacy settings.

2. The computer-implemented method of claim 1 , wherein the discovery of the first wireless access point includes receiving, at the second wireless access point, advertisement data from the first wireless access point.

3. The computer-implemented method of claim 2 , wherein:

the exchanging parameters includes

automatically transmitting discovery parameters from the second wireless access point to the first wireless access point in response to receiving the advertisement data, wherein the second wireless access point's parameters include a secret key,

generating, by the second wireless access point, a session key using the secret key,

receiving an offer from the first wireless access point including offer parameters encrypted by a session key generated by the first wireless access point, wherein the session keys generated by the first and second wireless access points are both generated using the secret key transmitted by the second access point, and wherein the offer parameters include a privacy setting for the second wireless access point,

decrypting, by the second wireless access point, the offer using the session key generated by the second wireless access point.

4. The computer-implemented method of claim 3 , wherein the secret key includes a random number and version data.

5. The computer-implemented method of claim 3 , further comprising:

determining if the first wireless access point is compatible with the second wireless access point using the advertisement data.

6. The computer-implemented method of claim 3 , further comprising:

verifying a first public key that is included with the advertisement data.

7. The computer-implemented method of claim 6 , wherein the second wireless access point's parameters are encrypted by the first public key.

8. The computer-implemented method of claim 3 , wherein the second wireless access point's parameters include a second public key, and wherein the offer is encrypted by the second public key.

9. The computer-implemented method of claim 3 , further comprising:

adding the first wireless access point to a candidate list; and

determining that the first wireless access point is a best candidate in the candidate list based upon the advertisement data.

10. The computer-implemented method of claim 9 , wherein the determination of the best candidate is based upon one or more of the following: signal strength, hop count, or client number.

11. The computer-implemented method of claim 3 , wherein acting as a wireless extender includes the second wireless access point managing a basic service set and relaying traffic from the basic service set to the first wireless access point.

12. A first wireless access point capable of acting as a wireless extender, the first wireless access point comprising:

a processor; and

a memory coupled to the processor and storing instructions, which when executed, cause the first wireless access point to:

discover a second wireless access point;

automatically, in response to the discovery of the second wireless access point, exchange parameters with the second wireless access point;

self-tune, without user input, the first wireless access point radio and privacy settings to establish a secure direct wireless connection between the first and second wireless access points based upon the exchanged parameters; and

establish the secure direct wireless connection between the first and second wireless access points using the radio and privacy settings.

13. The first wireless access point of claim 12 , wherein:

the discovery of the second wireless access point includes receipt of advertisement data from the second wireless access point;

the exchanging parameters includes:

automatic transmission of discovery parameters from the first wireless access point to the second wireless access point in response to the advertisement data, wherein the first wireless access point's parameters include a secret key;

generation, by the first wireless access point, of a session key using the secret key;

receipt of an offer from the second wireless access point including offer parameters encrypted by a session key generated by the second wireless access point, wherein the session keys generated by the first and second wireless access points are both generated using the secret key transmitted by the first access point, and wherein the offer parameters include a privacy setting for the first wireless access point;

decryption, by the first wireless access point, of the offer using the session key generated by the first wireless access point.

14. The first wireless access point of claim 13 , wherein the secret key includes a random number and version data.

15. The first wireless access point of claim 13 , wherein the first wireless access point further determines if the second wireless access point is compatible with the first wireless access point using the advertisement data.

16. The first wireless access point of claim 13 , wherein the first wireless access point further verifies a first public key that is included with the advertisement data.

17. The first wireless access point of claim 16 , wherein first wireless access point's parameters are encrypted by the first public key.

18. The first wireless access point of claim 13 , wherein the first wireless access point's parameters include a second public key, and wherein the offer is encrypted by the second public key.

19. The first wireless access point of claim 13 , wherein the first wireless access point further:

adds the second wireless access point to a candidate list; and

determines that the second wireless access point is a best candidate in the candidate list based upon the advertisement data.

20. The first wireless access point of claim 19 , wherein the determination of the best candidate is based upon one or more of the following: signal strength, hop count, or client number.

21. The first wireless access point of claim 13 , wherein the first wireless access point acting as a wireless extender includes causing the first wireless access point to:

manage a basic service set; and

relay traffic from the basic service set to the second wireless access point.

22. A non-transitory computer-readable storage medium storing instructions, which when executed by a machine cause a first wireless access point to:

discover a second wireless access point;

automatically, in response to the discovery of the second wireless access point, exchange parameters with the second wireless access point;

self-tune, without user input, the first wireless access point radio and privacy settings to establish a secure direct wireless connection between the first and second wireless access points based upon the exchanged parameters; and

establish the secure direct wireless connection between the first and second wireless access points using the radio and privacy settings.

23. The non-transitory computer-readable storage medium of claim 22 , wherein:

the discovery of the second wireless access point includes receipt of advertisement data from the second wireless access point;

the exchanging parameters includes:

automatic transmission of discovery parameters from the first wireless access point to the second wireless access point in response to the advertisement data, wherein the first wireless access point's parameters include a secret key;

generation, by the first wireless access point, of a session key using the secret key;

receipt of an offer from the second wireless access point including offer parameters encrypted by a session key generated by the second wireless access point, wherein the session keys generated by the first and second wireless access points are both generated using the secret key transmitted by the first access point, and wherein the offer parameters include a privacy setting for the first wireless access point;

decryption, by the first wireless access point, of the offer using the session key generated by the first wireless access point.

24. The non-transitory computer-readable storage medium of claim 23 , wherein the first wireless access point further determines if the second wireless access point is compatible with the first wireless access point using the advertisement data.

25. The non-transitory computer-readable storage medium of claim 23 , wherein the first wireless access point further verifies a first public key that is included with the advertisement data and wherein the first wireless access point's parameters are encrypted by the first public key.

26. The non-transitory computer-readable storage medium of claim 23 , wherein the first wireless access point's parameters include a second public key, and wherein the offer is encrypted by the second public key.

27. The non-transitory computer-readable storage medium of claim 23 , wherein the first wireless access point further:

adds the second wireless access point to a candidate list; and

determines that the second wireless access point is a best candidate in the candidate list based upon the advertisement data that includes one or more of the following: signal strength, hop count, or client number.

28. The non-transitory computer-readable storage medium of claim 23 , wherein the first wireless access point further acts as a wireless extender which includes causing the first wireless access point to:

manage a basic service set; and

relay traffic from the basic service set to the second wireless access point.

Assignments (24)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071777/0641 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Apr 30, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046040/0277 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
CONVERSION AND NAME CHANGE Recorded Dec 14, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037289/0720 →
MERGER Recorded Dec 14, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037287/0589 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024823/0280 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0126 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED ON REEL/FRAME 024776/0337 Recorded May 8, 2012
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; SONICWALL, INC.
Reel/Frame 028177/0115 →
SECURITY AGREEMENT Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024776/0337 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Aug 3, 2010
From: AVENTAIL LLC; SONICWALL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 024823/0280 →
MERGER Recorded Jul 28, 2010
From: SONICWALL, INC.
To: PSM MERGER SUB (DELAWARE), INC.
Reel/Frame 024755/0083 →
CHANGE OF NAME Recorded Jul 28, 2010
From: PSM MERGER SUB (DELAWARE), INC.
To: SONICWALL, INC.
Reel/Frame 024755/0091 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2010
From: DUO, ZHUANGZHI; CHEN, ZHONG; GMUENDER, JOHN
To: SONICWALL, INC.
Reel/Frame 024087/0153 →