IP Library Granted Patent US 10,063,417
Granted Patent B2
US 10,063,417 · App. 14/844,064 · Granted Aug 28, 2018

Automatically grouping, authenticating, and provisioning access points using cloud-based management of WLAN infrastructure

Inventors: Jeelan Basha Poola (Karnataka, IN); Davis Kochery (Karnataka, IN); Dominic Velikakath Peter (Bangalore, IN)
Assignee: Extreme Networks, Inc.
H04L41/0846H04L41/0806H04L63/0876H04L67/34H04W8/005H04W12/06H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,063,417
App. No.
14/844,064
Granted
Aug 28, 2018
Kind
B2
Abstract

Disclosed herein are systems and methods for automatically grouping, authenticating, and provisioning access points using cloud-based management of wireless-local-area-network (WLAN) infrastructure. In an embodiment, a given site has a master access point that is manually configured with an organization-and-site-specific master-access-point configuration for providing service in a WLAN. Additional access points installed for operation transmit self-identifying messages to neighboring access points. Each access point compiles information about its neighbor access points in access-point neighbor lists. The access-point neighbor lists are received and used by a cloud-based WLAN-management service to identify the associated master access point and to provision unauthenticated access points using the correct organization-and-site-specific master-access-point configuration.

Claims (26)

1. A method for automatically authenticating and provisioning access points, the method comprising:

receiving a first-access-point neighbor list from a first access point, the first access point having a first-access-point configuration;

receiving a second-access-point neighbor list from a second access point;

making a first determination that the first-access-point neighbor list includes an identifier of the second access point;

making a second determination that the second-access-point neighbor list includes an identifier of the first access point; and

responsive to making both of the first and second determinations, provisioning the second access point with the first-access-point configuration of the first access point.

2. The method of claim 1 , wherein making the matching determination further comprises making a determination that the first access point is an authenticated access point.

3. The method of claim 2 , wherein making the determination that the first access point is an authenticated access point comprises making a determination that the first access point is a master access point.

4. The method of claim 1 , wherein the first-access-point configuration contains one or more of a service set identifier (SSID), a wireless local area network (WLAN) security configuration, an operating frequency band, a dynamic host configuration protocol (DHCP) server configuration, a client-address assignment mode, a WLAN-rate-limiting setting, a virtual local area network (VLAN) configuration, a firewall configuration, a network address translation (NAT) configuration, an application-visibility configuration, a wireless-radio configuration, a physical-port configuration, a radio-frequency-(RF)-management configuration, a certificate configuration, and an Internet Protocol (IP) security (IPSec) configuration.

5. The method of claim 1 , wherein making the matching determination further comprises making a determination that the second access point is an unauthenticated access point.

6. The method of claim 1 , wherein making the matching determination further comprises making a determination that the second access point is a relocated access point.

7. The method of claim 1 , wherein the neighbor lists are wired-network-based neighbor lists.

8. The method claim 1 , wherein the neighbor lists are wireless-beacon-based neighbor lists.

9. The method of claim 8 , further comprising:

receiving a third-access-point neighbor list from a third access point, the third access point having a third-access-point configuration, wherein the third-access-point neighbor list includes an identifier of the second access point, and wherein the second-access-point neighbor list includes an identifier of the third access point,

wherein making the matching determination further comprises selecting, based on one or more selection criteria, the first-access-point configuration over the third-access-point configuration for provisioning the second access point.

10. The method of claim 9 , wherein the one or more selection criteria comprises signal-strength data.

11. The method of claim 9 , wherein the one or more selection criteria comprises information conveyed over at least one wired network connection.

12. The method of claim 1 , wherein making the matching determination further comprises confirming that neither the first access point nor the second access point is a rogue access point.

13. A system for automatically authenticating and provisioning access points, the system comprising:

a communication interface configured to:

receive a first-access-point neighbor list from a first access point, the first access point having a first-access-point configuration; and

receive a second-access-point neighbor list from a second access point and a processor configured to

make a first determination that the first-access-point neighbor list includes an identifier of the second access point;

make a second determination that the second-access-point neighbor list includes an identifier of the first access point; and

responsive to making both of the first and second determinations, provision the second access point with the first-access-point configuration of the first access point.

Assignments (10)
RELEASE OF PATENT AND TRADEMARK SECURITY INTEREST AT REEL/FRAME NO. 46050/0546 Recorded Jul 30, 2026
From: BANK OF MONTREAL, AS AGENT
To: EXTREME NETWORKS, INC.
Reel/Frame 076081/0088 →
SECURITY INTEREST Recorded Jul 29, 2026
From: EXTREME NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076078/0590 →
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: SYMBOL TECHNOLOGIES, LLC
To: EXTREME NETWORKS, INC.
Reel/Frame 040579/0410 →
AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2016
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 040521/0762 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2015
From: POOLA, JEELAN BASHA; KOCHERY, DAVIS; PETER, DOMINIC VELIKAKATH
To: SYMBOL TECHNOLOGIES, LLC
Reel/Frame 036484/0850 →
Continuity (1)
Related Publication 20170070390A1 · Mar 9, 2017
Cited By (1)
US 12,610,257