IP Library Granted Patent US 9,787,502
Granted Patent B2
US 9,787,502 · App. 15/073,454 · Granted Oct 10, 2017

Captive portal systems, methods, and devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,787,502
App. No.
15/073,454
Granted
Oct 10, 2017
Kind
B2
Abstract

Embodiments of the present technology provide out-of-band captive portal devices, networks, and methods. An example of a method includes executing a redirection of a client request for network access to a captive portal login, initiating an association between the wireless controller and the client, receiving authentication credentials of client from the captive portal login, negotiating a change of authorization with a wireless controller in accordance with RFC 5176 protocol, wherein the controller includes a mapping to a captive portal Internet Protocol (IP) address, and redirecting the client to a URL specified in the client request for network access.

Claims (37)

1. A method comprising:

receiving, from a client, a client request for network access;

receiving authentication credentials of a user of the client, wherein the authentication credentials are received via a captive portal user interface;

identifying an active network session for the client based on an Internet protocol (IP) address of the client;

causing a change of authorization at a wireless controller to authenticate the client based on dynamic authorization extensions to a remote authentication dial in user service (RADIUS); and

redirecting the client to a uniform resource locator (URL) specified in the client request for network access.

2. The method of claim 1 , further comprising creating a finite state machine, wherein, to cause the change of authorization, the finite state machine negotiates the change of authorization with the wireless controller.

3. The method of claim 1 , wherein an access point may load balance the client request for network access with other client requests for network access based on a mapping between the wireless controller and a captive portal IP address associated with the captive portal user interface.

4. The method of claim 1 , further comprising mapping one or more captive portal IP addresses to the wireless controller prior to receiving the client request for network access.

5. The method of claim 1 , wherein control of multiple mobility virtual local area networks (VLANs) is mediated by an external captive portal device.

6. The method of claim 1 , wherein the wireless controller includes a mapping to a captive portal IP address.

7. The method of claim 1 , wherein a plurality of floating IP addresses are used for load balancing and distribution of captive portal IP addresses.

8. A non-transitory computer-readable storage medium carrying program instructions thereon, the instructions when executed by one or more hardware processors cause the one or more hardware processors to perform operations comprising:

receiving, from a client, a client request for network access;

receiving authentication credentials of a user of the client, wherein the authentication credentials are received via a captive portal user interface;

identifying an active network session for the client based on an Internet protocol (IP) address of the client;

causing a change of authorization at a wireless controller to authenticate the client based on dynamic authorization extensions to a remote authentication dial in user service (RADIUS); and

redirecting the client to a uniform resource locator (URL) specified in the client request for network access.

9. The computer-readable storage medium of claim 8 , wherein the instructions further cause the one or more hardware processors to perform operations comprising creating a finite state machine, wherein, to cause the change of authorization, the finite state machine negotiates the change of authorization with the wireless controller.

10. The computer-readable storage medium of claim 8 , wherein an access point may load balance the client request for network access with other client requests for network access based on a mapping between the wireless controller and a captive portal IP address associated with the captive portal user interface.

11. The computer-readable storage medium of claim 8 , wherein the instructions further cause the one or more hardware processors to perform operations comprising mapping one or more captive portal IP addresses to the wireless controller prior to receiving the client request for network access.

12. The computer-readable storage medium of claim 8 , wherein control of multiple mobility virtual local area networks (VLANs) is mediated by an external captive portal device.

13. The computer-readable storage medium of claim 8 , wherein the wireless controller includes a mapping to a captive portal IP address.

14. The computer-readable storage medium of claim 8 , wherein a plurality of floating IP addresses are used for load balancing and distribution of captive portal IP addresses.

15. A system comprising:

one or more hardware processors; and

logic circuit encoded in one or more non-transitory computer-readable media for execution by the one or more hardware processors and when executed operable to perform operations comprising:

receiving, from a client, a client request for network access;

receiving authentication credentials of a user of the client, wherein the authentication credentials are received via a captive portal user interface;

identifying an active network session for the client based on an Internet protocol (IP) address of the client;

causing a change of authorization at a wireless controller to authenticate the client based on dynamic authorization extensions to a remote authentication dial in user service (RADIUS); and

redirecting the client to a uniform resource locator (URL) specified in the client request for network access.

16. The system of claim 15 , wherein the logic circuit when executed is further operable to perform operations comprising creating a finite state machine, wherein, to cause the change of authorization, the finite state machine negotiates the change of authorization with the wireless controller.

17. The system of claim 15 , wherein an access point may load balance the client request for network access with other client requests for network access based on a mapping between the wireless controller and a captive portal IP address associated with the captive portal user interface.

18. The system of claim 15 , wherein the logic circuit when executed is further operable to perform operations comprising mapping one or more captive portal IP addresses to the wireless controller prior to receiving the client request for network access.

19. The system of claim 15 , wherein control of multiple mobility virtual local area networks (VLANs) is mediated by an external captive portal device.

20. The system of claim 15 , wherein the wireless controller includes a mapping to a captive portal IP address.

Assignments (12)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: AVAYA INC.; AVAYA COMMUNICATION ISRAEL LTD; AVAYA HOLDINGS LIMITED
To: EXTREME NETWORKS, INC.
Reel/Frame 043569/0047 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →