IP Library Patent Application 13691360
Patent Application
App. No. 13/691,360

Secure Hotspot Roaming

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/691,360
Abstract

Secure hotspot roaming in wireless networks. An enterprise works with one or more hotspot providers to provide secure access to its clients through hotspot locations. The enterprise provides the (hotspot) service provider (SP), with the addresses of enterprise controllers used for client authentication. The SP maintains a database which maps the enterprise realm to the address of the enterprise controller. When a client connects to a hotspot access point (AP), the hotspot AP sends client information such as MAC address to a SP controller. The SP controller determines if the client is new or already known. If the client is known and the realm associated with the client has an entry in the realm to enterprise database, the hotspot AP is instructed to begin client authentication with the specified enterprise controller. If the client is unknown, authentication begins with the SP controller, and the client is queried for realm information.

Claims (52)

1 . A method comprising:

receiving an association request by an access point from a client, the access point being configured to communicate with a first controller;

responsive to a determination that the client is mapped to a second controller that is different than the first controller, establishing a communication path between the access point and the second controller;

forwarding, by the access point, incoming traffic from the client to the second controller via the communication path.

2 . The method of claim 1 , wherein the determination that the client is associated with the second controller is based on an identification of the client.

3 . The method of claim 1 , wherein the client is mapped to the second controller by the client being mapped to a particular realm and the particular realm being mapped to the second controller.

4 . The method of claim 1 , wherein the second controller authenticates the client based on the incoming traffic received from the access point.

5 . The method of claim 1 , wherein establishing the communication path comprises establishing an IPSec tunnel between the access point and the second controller.

6 . The method of claim 5 , wherein Wi-Fi encryption is terminated after authentication of the client by the second controller.

7 . The method of claim 1 , wherein all authentication of the client is performed by the second controller.

8 . The method of claim 1 ,

wherein an authentication procedure for authenticating the client is started by the first controller;

wherein the authentication procedure is dynamically transferred, prior to completion, from the first controller to the second controller in response to determining that the client is mapped to the second controller.

9 . A method comprising:

receiving, by a first controller, client information identifying a client;

determining, by the first controller while performing an authentication procedure to authenticate the client, that the client is mapped to a second controller;

responsive to determining that the client is mapped to the second controller, transferring control of the authentication procedure to the second controller.

10 . The method of claim 9 , wherein transferring control of the authentication procedure is performed prior to completion of the authentication procedure by the first controller.

11 . The method of claim 9 , wherein determining that the client is mapped to the second controller comprises:

determining that the client is mapped to a particular realm; and

determining that the particular realm is mapped to the second controller.

12 . The method of claim 11 , wherein the first controller determines that the client is mapped to the particular realm based on a user name associated with the client.

13 . The method of claim 9 , wherein the transferring control of the authentication procedure comprises:

terminating an initial authentication session with the first controller as an authenticator;

establishing a new authentication session with the second controller as the authenticator.

14 . The method of claim 9 , further comprises temporarily disconnecting the client from an access point in communication with the first controller while transferring control of the authentication procedure from the first controller to the second controller.

15 . A non-transitory computer readable medium comprising instructions which, when executed by one or more processors, causes at least:

receiving an association request by an access point from a client, the access point being configured to communicate with a first controller;

responsive to a determination that the client is mapped to a second controller that is different than the first controller, establishing a communication path between the access point and the second controller;

forwarding, by the access point, incoming traffic from the client to the second controller via the communication path.

16 . The computer readable medium of claim 15 , wherein the determination that the client is associated with the second controller is based on an identification of the client.

17 . The computer readable medium of claim 15 , wherein the client is mapped to the second controller by the client being mapped to a particular realm and the particular realm being mapped to the second controller.

18 . The computer readable medium of claim 15 , wherein the second controller authenticates the client based on the incoming traffic received from the access point.

19 . The computer readable medium of claim 15 , wherein establishing the communication path comprises establishing an IPSec tunnel between the access point and the second controller.

20 . The computer readable medium of claim 19 , wherein Wi-Fi encryption is terminated after authentication of the client by the second controller.

21 . The computer readable medium of claim 15 , wherein all authentication of the client is performed by the second controller.

22 . The computer readable medium of claim 15 ,

wherein an authentication procedure for authenticating the client is started by the first controller;

wherein the authentication procedure is dynamically transferred, prior to completion, from the first controller to the second controller in response to determining that the client is mapped to the second controller.

23 . A non-transitory computer readable medium comprising instructions which, when executed by one or more processors, causes at least:

receiving, by a first controller, client information identifying a client;

determining, by the first controller during an authentication procedure to authenticate the client, that the client is mapped to a second controller;

responsive to determining that the client is mapped to the second controller, transferring control of the authentication procedure to the second controller.

24 . The computer readable medium of claim 23 , wherein transferring control of the authentication procedure is performed prior to completion of the authentication procedure by the first controller.

25 . The computer readable medium of claim 23 , wherein determining that the client is mapped to the second controller comprises:

determining that the client is mapped to a particular realm; and

determining that the particular realm is mapped to the second controller.

26 . The computer readable medium of claim 25 , wherein the first controller determines that the client is mapped to the particular realm based on a user name associated with the client.

27 . The computer readable medium of claim 26 , wherein the transferring control of the authentication procedure comprises:

terminating an initial authentication session with the first controller as an authenticator;

establishing a new authentication session with the second controller as the authenticator.

28 . The computer readable medium of claim 23 , further comprises temporarily disconnecting the client from an access point in communication with the first controller while transferring control of the authentication procedure from the first controller to the second controller.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2018
From: ARUBA NETWORKS, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 045921/0055 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: ARUBA NETWORKS, INC.
Reel/Frame 036379/0274 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2015
From: ARUBA NETWORKS, INC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 035814/0518 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2015
From: IYER, PRADEEP J.
To: ARUBA NETWORKS, INC.
Reel/Frame 035578/0443 →