IP Library Granted Patent US 10,321,306
Granted Patent B2
US 10,321,306 · App. 15/262,707 · Granted Jun 11, 2019

Network device selective synchronization

Inventors: Geoffrey Joseph Mason (Auckland, NZ); Shruti Narayan (Sunnyvale, CA)
Assignee: Aerohive Networks, Inc.
H04W8/245H04L9/0833H04L9/0861H04L9/12H04L63/062H04L63/105H04L67/10H04W12/04H04W12/08H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,321,306
App. No.
15/262,707
Granted
Jun 11, 2019
Kind
B2
Abstract

Techniques for selectively synchronizing network devices to authenticate wireless device to access a network using a key. A system utilizing such techniques can include a unique pre-shared key assignment system and a network device selective synchronization system. A method utilizing such techniques can include unique pre-shared key assignment and selective synchronization management.

Claims (47)

1. A method comprising:

assigning a unique private pre-shared key to a wireless device, a media access control (MAC) address of the wireless device being bound to the unique private pre-shared key;

determining network personas of a user of the wireless device;

mapping the user to a network group according to the network personas of the user;

maintaining synchronization policies for selectively synchronizing a plurality of network devices to authenticate wireless devices to access a network;

determining a network device of the plurality of network devices to which to send key data associated with the unique private pre-shared key in accordance with the synchronization policies and the network group and as part of selective synchronization of the plurality of network devices, the key data including the MAC address of the wireless device bound to the unique private pre-shared key;

sending the key data to the network device for storage in local storage of the network device for purposes of locally authenticating the wireless device to access the network.

2. The method of claim 1 , wherein the synchronization policies are maintained, at least in part, according to input received from a network administrator of the network.

3. The method of claim 1 , wherein the synchronization policies are modified according to network access patterns of wireless devices including the wireless device in accessing the network.

4. The method of claim 1 , wherein the network device is configured to authenticate the wireless device to access the network using the key data according to a 4-way handshake.

5. The method of claim 1 , further comprising:

determining characteristics of the network devices;

selecting the network device according to the characteristics of the network device.

6. The method of claim 1 , further comprising:

determining characteristics of the network devices including physical locations of the network devices;

selecting the network device according to a physical location of the network device.

7. The method of claim 1 , wherein the plurality of network devices are selectively synchronized in response to a threshold number of wireless devices being onboarded to access the network using unique pre-shared keys.

8. The method of claim 1 , wherein the network personas of the user include the user gaining a right to have key data associated with wireless devices utilized by the user stored locally at the plurality of network devices.

9. The method of claim 1 , further comprising sending an expiration stamp with the key data, the expiration stamp specifying a time at which to delete the key data from the local storage of the network device, the expiration stamp set according to an expiration time indicated by the synchronization policies.

10. The method of claim 1 , further comprising assigning a connection limit with the unique private pre-shared key, the connection limit specifying a number of wireless devices that can authenticate using the unique private pre-shared key.

11. A system comprising:

a unique private pre-shared key assignment engine configured to assign a unique private pre-shared key to a wireless device, a media access control (MAC) address of the wireless device being bound to the unique private pre-shared key;

a network persona based mapping engine configured to:

determine network personas of a user of the wireless device;

map the user to a network group according to the network personas of the user;

a synchronization policies management engine configured to maintain synchronization policies for selectively synchronizing a plurality of network devices to authenticate wireless devices to access a network;

a selective synchronization engine configured to determine a network device of the plurality of network devices to which to send key data associated with the unique private pre-shared key in accordance with the synchronization policies and the network group and as part of selective synchronization of the plurality of network devices, the key data including the MAC address of the wireless device bound to the unique private pre-shared key;

a network device communication engine configured to send the key data to the network device for storage in local storage of the network device for purposes of locally authenticating the wireless device to access the network.

12. The system of claim 11 , wherein the synchronization policies management engine is further configured to maintain the synchronization policies, at least in part, according to input received from a network administrator of the network.

13. The system of claim 11 , wherein the synchronization policies management engine is further configured to modify the synchronization policies according to network access patterns of wireless devices including the wireless device in accessing the network.

14. The system of claim 11 , wherein the network device is configured to authenticate the wireless device to access the network using the key data according to a 4-way handshake.

15. The system of claim 11 , further comprising:

a network device characteristics determination engine configured to determine characteristics of the network devices;

wherein the selective synchronization engine is further configured to select the network device according to the characteristics of the network device.

16. The system of claim 11 , further comprising:

a network device characteristics engine configured to determine characteristics of the network devices including physical locations of the network devices;

wherein the selective synchronization engine is further configured to select the network device according to a physical location of the network device.

17. The system of claim 11 , wherein the selective synchronization engine is further configured to selectively synchronize the plurality of network devices in response to a threshold number of wireless devices being onboarded to access the network using unique pre-shared keys.

18. The system of claim 11 , wherein the network personas of the user include the user gaining a right to have key data associated with wireless devices utilized by the user stored locally at the plurality of network devices.

19. The system of claim 11 , wherein the network device communication engine is further configured to send an expiration stamp with the key data, the expiration stamp specifying a time at which to delete the key data from the local storage of the network device, the expiration stamp set according to an expiration time indicated by the synchronization policies.

20. A system comprising:

means for assigning a unique private pre-shared key to a wireless device, a media access control (MAC) address of the wireless device being bound to the unique private pre-shared key;

means for determining network personas of a user of the wireless device;

means for mapping the user to a network group according to the network personas of the user;

means for maintaining synchronization policies for selectively synchronizing a plurality of network devices to authenticate wireless devices to access a network;

means for determining a network device of the plurality of network devices to which to send key data associated with the unique private pre-shared key in accordance with the synchronization policies and the network group and as part of selective synchronization of the plurality of network devices, the key data including the MAC address of the wireless device bound to the unique private pre-shared key;

means for sending the key data to the network device for storage in local storage of the network device for purposes of locally authenticating the wireless device to access the network.

Assignments (4)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2020
From: AEROHIVE NETWORKS, INC.
To: EXTREME NETWORKS, INC.
Reel/Frame 052473/0843 →
SECURITY INTEREST Recorded Aug 12, 2019
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 050023/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2016
From: MASON, GEOFFREY JOSEPH; NARAYAN, SHRUTI
To: AEROHIVE NETWORKS, INC.
Reel/Frame 039704/0594 →
Continuity (2)
Provisional Application 62354665 · Jun 24, 2016
Related Publication 20170374548A1 · Dec 28, 2017