IP Library Granted Patent US 10,285,054
Granted Patent B2
US 10,285,054 · App. 15/074,890 · Granted May 7, 2019

Method and system for storing and accessing client device information in a distributed set of nodes

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,285,054
App. No.
15/074,890
Granted
May 7, 2019
Kind
B2
Abstract

A method includes identifying a first node in a plurality of nodes based on a client device identifier for a client device, the client device being associated with a first network device; storing, information for the client device, on the first node; responsive to the client device associating with a second network device, retrieving the information for the client device by: identifying the first node based on the client device identifier for the client device and obtaining the information from the first node.

Claims (72)

1. A method comprising:

storing, information for a client device including at least (1) a client device identifier identifying the client device and (2) authentication information associated with the client device from a prior authentication, on a first controller of a plurality of controllers, wherein the client device is associated with a first access point comprising a first hardware processor;

receiving, by a second access point, a request to associate with the second access point from the client device; the second access point comprising a second hardware processor;

responsive to receiving the request to associate with the second access point from the client device, retrieving, by the second access point that the client device is not associated with, the information for the client device from the first controller stored by the first access point that the client device is associated with; and

communicating concurrently, by the second access point, with the client device to create at least one encryption key for encrypting communications between the second access point and the client device based on the retrieved information;

creating, using at least the shared key, one or more encryption keys for encrypting communication between the first access point and the client device;

concurrently with creating the one or more encryption keys, obtaining the multicast information, for the client device, from the second access point.

2. The method of claim 1 , wherein the information comprises one or more of:

an identification of a particular device storing multicast information for the client device; or

a shared key associated with the client device.

3. The method of claim 1 , wherein identifying the first controller comprises:

applying a hash function to the client device identifier to obtain a hash value;

identifying the first controller responsive to determining that the first controller corresponds to the hash value.

4. The method of claim 1 , wherein the information comprises an identification of a particular device storing additional information for the client device, the additional information comprising one or more of:

firewall session information;

multicast proxy information;

Dynamic Host Configuration Protocol (DHCP) parameters used by an access point that was previously configured to grant access to the client device; or

prior authentication information;

wide area network optimization information.

5. A non-transitory computer readable storage medium comprising instructions which, when executed by at least one processor of a first access point, cause the first access point to:

receive a request to associate with the first access point from the client device, the first access point comprising a hardware processor;

responsive to receiving the request to associate with the first access point from the client device, retrieve, by the first access point that the client device is not associated with, information for the client device, wherein the information for the client device is stored by a second access point that the client device is associated with on a first controller of a plurality of controllers, and wherein the information for the client device includes at least (1) a client device identifier identifying the client device and (2) authentication information associated with the client device from a prior authentication; and

communicating concurrently with the client device to create at least one encryption key for encrypting communications between the second access point and the client device based on the retrieved information;

create, using at least the shared key, one or more encryption keys for encrypting communication between the first access point and the client device; and

obtain the multicast information, for the client device, from the second access point concurrently with creating the one or more encryption keys.

6. The non-transitory computer readable storage medium of claim 5 , wherein the information comprises one or more of:

an identification of a particular device storing multicast information for the client device; or

a shared key associated with the client device.

7. The non-transitory computer readable storage medium of claim 5 , wherein identifying the first controller comprises:

applying a hash function to the client device identifier to obtain a hash value;

identifying the first controller responsive to determining that the first controller corresponds to the hash value.

8. The non-transitory computer readable storage medium of claim 5 , wherein the information comprises an identification of a particular device storing additional information for the client device, the additional information comprising one or more of:

firewall session information;

multi cast proxy information;

Dynamic Host Configuration Protocol (DHCP) parameters used by an access point that was previously configured to grant access to the client device; or

prior authentication information;

wide area network optimization information.

9. A system comprising:

a first access point comprising a first hardware processor, and a second access point comprising a second hardware processor, the first access point and the second access point to:

identify a first controller of a plurality of controllers based on a client device identifier for a client device, the client device being associated with the first access point;

store by the first access point, information for the client device including at least (1) a client device identifier identifying the client device and (2) authentication information associated with the client device from a prior authentication, on the first controller of a plurality of controllers;

responsive to receiving a request to associate with the second access point from the client device, retrieve the information for the client device from the first controller stored by the first access point that the client is associated with; and

communicate concurrently, by the second access point, with the client device to create at least one encryption key for encrypting communications between the second access point and the client device based on the retrieved information;

create, using at least the shared key, one or more encryption keys for encrypting communication between the first access point and the client device;

concurrently with creating the one or more encryption keys, obtain the multicast information, for the client device, from the second access point.

10. The system of claim 9 , wherein the information comprises one or more of:

an identification of a particular device storing multicast information for the client device; or

a shared key associated with the client device.

11. The system claim 9 , wherein identifying the first controller comprises:

applying a hash function to the client device identifier to obtain a hash value;

identifying the first controller responsive to determining that the first controller corresponds to the hash value.

12. The system of claim 9 , wherein the information comprises an identification of a particular device storing additional information for the client device, the additional information comprising one or more of:

firewall session information;

multicast proxy information;

Dynamic Host Configuration Protocol (DHCP) parameters used by an access point that was previously configured to grant access to the client device; or

prior authentication information;

wide area network optimization information.

13. The method of claim 1 , wherein retrieving the information for the client device from the first controller stored by the first access point comprises:

identifying the first controller based on a client device identifier for the client device by the first access point,

requesting the information for the client device from the first controller, and

receiving the information for the client device from the first controller.

14. The method of claim 1 , wherein the first access point is separate and different from the second access point and the first controller.

15. The non-transitory computer readable storage medium of claim 5 , wherein the instructions further cause the first access point to:

identify the first controller based on a client device identifier for the client device by the first access point,

request the information for the client device from the first controller, and

receive the information for the client device from the first controller.

16. The non-transitory computer readable storage medium of claim 5 , wherein the first access point is separate and different from the second access point and the first controller.

17. The system of claim 9 , wherein the second access point further to:

identify the first controller based on a client device identifier for the client device by the first access point,

request the information for the client device from the first controller, and

receive the information for the client device from the first controller,

wherein the first access point is separate and different from the second access point and the first controller.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2018
From: ARUBA NETWORKS, INC.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 045921/0055 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2016
From: ARUBA NETWORKS, INC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 040371/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2016
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: ARUBA NETWORKS, INC.
Reel/Frame 040647/0687 →