IP Library Granted Patent US 8,224,983
Granted Patent B2
US 8,224,983 · App. 12/753,390 · Granted Jul 17, 2012

System and method for dynamic bandwidth provisioning

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,224,983
App. No.
12/753,390
Granted
Jul 17, 2012
Kind
B2
Abstract

Embodiments disclosed herein provide a control device and a method executing thereon for allocating network bandwidth to users accessing a controlled network. In response to a user connecting to the control device using a user device, the control device obtains a user bandwidth allocation profile for that user based on user credentials. The user bandwidth allocation profile may be stored local or remote to the control device. A provisioning module running on the control device can map attributes in the user bandwidth allocation profile to a traffic control rule and associate the traffic control rule with the user based on the user credentials and considering information identifying the user device used by the user to connect to the control device. A traffic conditioning module running on the control device can regulate the network bandwidth usage by the user utilizing the traffic control rule associated with the user.

Claims (36)

1. A method for allocating network bandwidth to users in a system having an authentication database storing user profiles, an access control device having a plurality of network interfaces coupled to a plurality of user devices and a provisioning device coupled to the access control device, comprising:

configuring the access control device to operate in a first state, wherein operation in the first state comprises regulating network bandwidth usage for a set of users based on a first network bandwidth limit associated with each of the users, and each of the set of users is associated with one of the plurality of user devices;

receiving a first network communication from a first network application running on a first user device coupled to one of the plurality of network interfaces;

accessing a first user profile for a first user associated with the first user device from the authentication database, wherein the first user profile comprises one or more attributes associated with the first user and the first user profile was retrieved from the authentication database based on credentials associated with the first user;

determining a second network bandwidth limit for the first user based on the first network bandwidth limit associated with each of the users and the one or more attributes associated with the first user; and

dynamically updating at least one of the first network bandwidth limits associated with the plurality of users based on the second network bandwidth limit including configuring the access control device to operate in a second state, wherein operation of the access control device in the second state comprises regulating network bandwidth usage for each of the plurality of users based on the first network bandwidth limits.

2. The method of claim 1 , further comprising:

receiving a second network communication from a second network application on the first user device, including user credentials provided by a second user at the first user device;

retrieving a second user profile for the second user associated with first device from the authentication database; and

determining a third network bandwidth limit for the second user based on the one or more attributes of the second user profile and the first user device.

3. The method of claim 1 , wherein the first user is one of the plurality of users and wherein dynamically updating at least one of the first network bandwidth limits based on the second network bandwidth limit comprises dynamically updating the first network bandwidth associated with the first user to the second network bandwidth.

4. A system, comprising:

an authentication database storing user profiles;

an access control device having a plurality of network interfaces coupled to a plurality of user devices; and

a provisioning device coupled to the access control device and comprising a computer readable medium comprising instructions for:

configuring the access control device to operate in a first state, wherein operation in the first state comprises regulating network bandwidth usage for a set of users based on a first network bandwidth limit associated with each of the users, and each of the set of users is associated with one of the plurality of user devices;

receiving a first network communication from a first network application running on a first user device coupled to one of the plurality of network interfaces;

accessing a first user profile for a first user associated with the first user device from the authentication database, wherein the first user profile comprises one or more attributes associated with the first user and the first user profile was retrieved from the authentication database based on credentials associated with the first user;

determining a second network bandwidth limit for the first user based on the first network bandwidth limit associated with each of the users and the one or more attributes associated with the first user; and

dynamically updating at least one of the first network bandwidth limits associated with the plurality of users based on the second network bandwidth limit including configuring the access control device to operate in a second state, wherein operation of the access control device in the second state comprises regulating network bandwidth usage for each of the plurality of users based on the first network bandwidth limits.

5. The system of claim 4 , the instructions further for:

receiving a second network communication from a second network application on the first user device, including user credentials provided by a second user at the first user device;

retrieving a second user profile for the second user associated with first device from the authentication database; and

determining a third network bandwidth limit for the second user based on the one or more attributes of the second user profile and the first user device.

6. The system of claim 4 , wherein the first user is one of the plurality of users and wherein dynamically updating at least one of the first network bandwidth limits based on the second network bandwidth limit comprises dynamically updating the first network bandwidth associated with the first user to the second network bandwidth.

7. A non-transitory computer readable storage medium comprising instructions for allocating network bandwidth to users in a system having an authentication database storing user profiles, an access control device having a plurality of network interfaces coupled to a plurality of user devices and a provisioning device coupled to the access control device, the instructions further for:

configuring the access control device to operate in a first state, wherein operation in the first state comprises regulating network bandwidth usage for a set of users based on a first network bandwidth limit associated with each of the users, and each of the set of users is associated with one of the plurality of user devices;

receiving a first network communication from a first network application running on a first user device coupled to one of the plurality of network interfaces;

accessing a first user profile for a first user associated with the first user device from the authentication database, wherein the first user profile comprises one or more attributes associated with the first user and the first user profile was retrieved from the authentication database based on credentials associated with the first user;

determining a second network bandwidth limit for the first user based on the first network bandwidth limit associated with each of the users and the one or more attributes associated with the first user; and

dynamically updating at least one of the first network bandwidth limits associated with the plurality of users based on the second network bandwidth limit including configuring the access control device to operate in a second state, wherein operation of the access control device in the second state comprises regulating network bandwidth usage for each of the plurality of users based on the first network bandwidth limits.

8. The non-transitory computer readable storage medium of claim 7 , further comprising instructions for:

receiving a second network communication from a second network application on the first user device, including user credentials provided by a second user at the first user device;

retrieving a second user profile for the second user associated with first device from the authentication database; and

determining a third network bandwidth limit for the second user based on the one or more attributes of the second user profile and the first user device.

9. The non-transitory computer readable storage of claim 7 , wherein the first user is one of the plurality of users and wherein dynamically updating at least one of the first network bandwidth limits based on the second network bandwidth limit comprises dynamically updating the first network bandwidth associated with the first user to the second network bandwidth.

Assignments (13)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2024
From: RPX CORPORATION
To: NETSKOPE, INC.
Reel/Frame 067918/0690 →
RELEASE OF SECURITY INTEREST IN SPECIFIED PATENTS Recorded May 31, 2024
From: BARINGS FINANCE LLC
To: RPX CORPORATION
Reel/Frame 067596/0606 →
RELEASE OF SECURITY INTEREST Recorded Oct 26, 2020
From: JEFFERIES FINANCE LLC
To: RPX CORPORATION
Reel/Frame 054486/0422 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054198/0029 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054244/0566 →
SECURITY INTEREST Recorded Jun 29, 2018
From: RPX CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 046486/0433 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2012
From: ROCKSTEADY TECHNOLOGIES LLC
To: RPX CORPORATION
Reel/Frame 028774/0036 →
CONFIRMATORY ASSIGNMENT Recorded Jul 16, 2012
From: LOONEY, KELLY
To: WHITE, ERIC
Reel/Frame 028610/0184 →
CONFIRMATORY ASSIGNMENT Recorded Jun 28, 2012
From: WHITE, ERIC
To: ROCKSTEADY TECHNOLOGIES, LLC
Reel/Frame 028457/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2011
From: WHITE, ERIC
To: ROCKSTEADY TECHNOLOGIES, LLC
Reel/Frame 025715/0123 →
SEPARATION AGREEMENT Recorded Jan 18, 2011
From: LOONEY, KELLY
To: ROCKSTEADY NETWORKS, INC.
Reel/Frame 025648/0857 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2010
From: TA, TUAN; TURLEY, PATRICK; CLENDINING, KERRY
To: ROCKSTEADY NETWORKS, INC.
Reel/Frame 024562/0825 →
ASSET PURCHASE AGREEMENT Recorded Jun 18, 2010
From: ROCKSTEADY NETWORKS, INC.
To: WHITE, ERIC
Reel/Frame 024562/0834 →