IP Library Patent Application 14707695
Patent Application
App. No. 14/707,695

Techniques for Managing Network Access

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/707,695
Abstract

Computer-implemented systems, methods, and computer-readable media are provided for managing access of a wireless device to a network based on one or more policies. In accordance with some embodiments, a request for authorization to associate a wireless device with a network is received. A policy associated with the network is retrieved from a storage device in response to the request. A determination is then made as to whether information included in the request satisfies a condition in the policy. If the information satisfies the condition, a response is transmitted granting authorization to associate the wireless device with the network. If the information does not satisfy the condition, a response is transmitted denying authorization to associate the wireless device with the network.

Claims (56)

1 . A computer-implemented method for managing access of a wireless device to a network based on one or more policies, comprising:

receiving, by a computing device including a memory and a processor configured to execute instructions stored in the memory, a request for authorization from an access point to associate a wireless device with a network;

retrieving, by the computing device, a policy associated with the network from a storage device in response to the request;

determining, by the computing device, that information included in the request fails to satisfy a condition in the policy; and

transmitting, by the computing device, a response to the access point denying authorization to associate the wireless device with the network based at least in part on the determination that the information failed to satisfy the condition.

2 . The method of claim 1 , wherein the request is a first request, the network is a first network, the policy is a first policy, the information is first information, the condition is a first condition, and the response is a first response, further comprising:

receiving, by the computing device, a second request for authorization to associate the wireless device with a second network;

retrieving, by the computing device, a second policy associated with the second network from the storage device in response to the second request;

determining, by the computing device, that second information included in the second request satisfies a second condition in the second policy; and

transmitting, by the computing device, a second response granting authorization to associate the wireless device with the second network based at least in part on the determination that the second information satisfies the second condition.

3 . The method of claim 1 , wherein the condition of the policy restricts authorization to the network based on at least one of the following:

a type of the wireless device;

a location of the wireless device;

an application of the wireless device that caused the request to be generated;

a time at which the request was generated;

a type of subscriber associated with the wireless device;

a level of congestion on the network;

and a number of devices associated with a user of the wireless device that are associated with the wireless network.

4 . The method of claim 1 , wherein the information conveys a type of the wireless device, and the determining comprises identifying that the type of the wireless device is not a type that satisfies the condition of the policy.

5 . The method of claim 1 , wherein the request is generated as a result of a selection of a service set identifier (SSID) of the network at the wireless device.

6 . The method of claim 1 , wherein the computing device is a gateway, and the gateway includes the storage device.

7 . The method of claim 1 , wherein the request is a Remote Authentication Dial In User Service (RADIUS) access request message, and the response is a RADIUS response message.

8 . The method of claim 1 , wherein the policy was received from an authentication, authorization, and accounting (AAA) server.

9 . The method of claim 2 , wherein the first network is a public network, and the second network is a private network.

10 . The method of claim 2 , wherein at least one of the first network and the second network is a Wi-Fi network.

11 . A computer-implemented system for managing access of a wireless device to a network based on one or more policies, comprising:

one or more memory devices that store instructions; and

one or more processors that execute the instructions to:

receive a request for authorization from an access point to associate a wireless device with a network;

retrieve a policy associated with the network from a storage device in response to the request;

determine that information included in the request fails to satisfy a condition in the policy; and

cause a response to be transmitted to the access point denying authorization to associate the wireless device with the network based at least in part on the determination that the information failed to satisfy the condition.

12 . The system of claim 11 , wherein the request is a first request, the network is a first network, the policy is a first policy, the information is first information, the condition is a first condition, and the response is a first response, and the one or more processors further execute the instructions to:

receive a second request for authorization to associate the wireless device with a second network;

retrieve a second policy associated with the second network from the storage device in response to the second request;

determine that second information included in the second request satisfies a second condition in the second policy; and

cause a second response to be transmitted granting authorization to associate the wireless device with the second network based at least in part on the determination that the second information satisfies the second condition.

13 . The system of claim 11 , wherein the condition of the policy restricts authorization to the network based on at least one of the following:

a type of the wireless device;

a location of the wireless device;

an application of the wireless device that caused the request to be generated;

a time at which the request was generated;

a type of subscriber associated with the wireless device;

a level of congestion on the network;

and a number of devices associated with a user of the wireless device that are associated with the wireless network.

14 . The system of claim 11 , wherein the information conveys a type of the wireless device and the one or more processors further execute the instructions to identify that the type of the wireless device is not a type that satisfies the condition of the policy.

15 . The system of claim 11 , wherein the request is generated as a result of a selection of a service set identifier (SSID) of the network at the wireless device.

16 . The system of claim 11 , wherein the request is a Remote Authentication Dial In User Service (RADIUS) access request message, and the response is a RADIUS response message.

17 . The system of claim 11 , wherein the policy was received from an authentication, authorization, and accounting (AAA) server.

18 . The system of claim 12 , wherein the first network is a public network, and the second network is a private network.

19 . The system of claim 12 , wherein at least one of the first network and the second network is a Wi-Fi network.

20 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform a method for managing access of a wireless device to a network based on one or more policies, the method comprising:

receiving a request for authorization from an access point to associate a wireless device with a network;

retrieving a policy associated with the network from a storage device in response to the request;

determining that information included in the request fails to satisfy a condition in the policy; and

causing a response to be transmitted to the access point denying authorization to associate the wireless device with the network in response to the determination that the information failed to satisfy the condition.

Assignments (2)
RELEASE OF SECURITY INTEREST Recorded Aug 21, 2018
From: PACIFIC WESTERN BANK
To: BENU NETWORKS, INC.
Reel/Frame 046645/0977 →
SECURITY INTEREST Recorded Dec 31, 2015
From: BENU NETWORKS, INC.
To: PACIFIC WESTERN BANK
Reel/Frame 037391/0125 →