IP Library Granted Patent US 12,519,864
Granted Patent B2
US 12,519,864 · App. 15/638,457 · Granted Jan 6, 2026

Device, apparatus, method and computer programs for a network gateway, server, server apparatus, server method, system, router, mobile device, vehicular gateway and cloud server

Inventor: Mohamed Omar (Unterhaching, DE)
Assignee: MaxLinear, Inc.
H04L67/34G06F21/53H04L12/46H04L45/586H04L67/025H04L41/5096
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,864
App. No.
15/638,457
Granted
Jan 6, 2026
Kind
B2
Abstract

A device for controlling a network gateway comprises at least one network interface configured to communicate in at least one computer network. The device further comprises a processing module configured to at least partially execute at least a first software module and a second software module. The first software module is configured to provide a gateway functionality of the network gateway via the at least one network interface. A functionality of the second software module is different from the gateway functionality of the first software module. The second software module is encapsulated from the first software module.

Claims (52)

1 . A device, comprising:

at least one network interface configured to communicate in at least one computer network; and

a processing module configured to at least partially execute, at least a first software module and a second software module, wherein:

the first software module is configured to provide a gateway functionality of a network gateway via the at least one network interface,

a functionality of the second software module is different from the gateway functionality,

the processing module is configured to:

redirect a write access of the second software module to resources of the first software module in response to a disallowed access of the second software module,

determine one or more capabilities required for executing the second software module,

transmit the one or more capabilities to a remote server, and

in response to the remote server determining the one or more capabilities will execute the second software module, obtain the second software module, where the second software module is selected by the remote server based on the one or more capabilities.

2 . The device according to claim 1 , wherein the processing module is configured to obtain the second software module from the remote server.

3 . The device according to claim 2 , wherein the processing module is configured to download the second software module directly from the remote server.

4 . The device according to claim 1 , wherein the processing module is configured to obtain the second software module based on information related to software modules previously used by a user of the network gateway.

5 . The device according to claim 1 , wherein the processing module is configured to obtain the second software module separately from the first software module.

6 . The device according to claim 1 , wherein the processing module is configured to provide a software interface between the first software module and the second software module.

7 . The device according to claim 6 , wherein the processing module is configured to limit an access from the second software module to the first software module through the software interface.

8 . The device according to claim 7 , wherein the processing module is configured to limit the access from the second software module to the first software module through the software interface based on a plurality of access rights.

9 . The device according to claim 6 , wherein the processing module is configured to monitor an access from the second software module to the first software module through the software interface.

10 . The device according to claim 6 , wherein the processing module is configured to adjust an access limit and/or a monitoring of the access from the second software module to the first software module through the software interface based on an input of an operator.

11 . The device according to claim 1 , wherein the first software module is an operating system or a pre-installed software package of the device.

12 . The device according to claim 1 , wherein the second software module is one of an internet of things gateway, a smart home hub, a home server, a home security application, a face recognition application or a virus scanner.

13 . The device according to claim 1 , wherein the processing module is configured to sandbox the second software module within an execution environment of the first software module.

14 . The device according to claim 1 , wherein the processing module is further configured to at least partially execute a third software module, wherein the third software module is encapsulated from the first software module and from the second software module.

15 . The device according to claim 1 , wherein the first software module and/or the second software module are at least partially executed on the remote server.

16 . The device according to claim 1 , wherein the processing module is configured to provide an interface for administering the device, and wherein the processing module is configured to authenticate a user requesting to use the interface using a proximity sensor.

17 . A router comprising the device according to claim 1 .

18 . A server comprising:

at least one interface, configured to communicate with the device according to claim 1 ; and

a control module, configured to:

maintain a plurality of software modules, wherein at least a subset of the plurality of software modules are suitable to be executed by the device;

receive a download request related to a software module of the plurality of software modules for the device via the at least one interface; and to

provide the software module for the device via the at least one interface.

19 . The server according to claim 18 , wherein the control module is configured to obtain information related to one or more capabilities of the device from the device, wherein the control module is configured to provide information related to one or more software modules of the plurality of software modules to the device based on the one or more capabilities of the device.

20 . A method comprising:

at least partly executing at least a first software module and a second software module, wherein the first software module is configured to provide a gateway functionality of a network gateway, wherein a functionality of the second software module is different from the gateway functionality of the first software module;

redirecting a write access of the second software module to resources of the first software module in response to a disallowed access of the second software module;

determining one or more capabilities required for executing the second software module at a device;

transmitting the one or more capabilities to a remote server, determining that the device has the one or more capabilities required for executing the second software module;

in response to the remote server determining the one or more capabilities will execute the second software module, obtaining the second software module, where the second software module is selected by the remote server based on the one or more capabilities; and

encapsulating the second software module from the first software module, wherein the second software module is blocked from access to at least some of the gateway functionality of the network gateway,

wherein the functionality of the second software module is comprised within a virtual machine.

21 . A non-transitory machine readable storage medium including program code, when executed, to cause a machine to perform operations comprising:

at least partly executing at least a first software module;

at least partly executing a second software module on an application engine layer, wherein the first software module is configured to provide a gateway functionality of a network gateway, wherein a functionality of the second software module is different from the gateway functionality of the first software module;

at least partly executing a third software module on the application engine layer; and

encapsulating the second software module from the first software module on the application engine layer and encapsulating the third software module from the first software module on the application engine layer, wherein:

the second software module is blocked from access to at least some of the gateway functionality of the network gateway,

the third software module communicates with the second software module via the first software module,

redirect a write access of the second software module to resources of the first software module in response to a disallowed access of the second software module,

one or more capabilities required for executing the second software module at a device are determined,

transmit the one or more capabilities to a remote server, and

in response to the remote server determining the one or more capabilities will execute the second software module, the second software module is obtained, where the second software module is selected by the remote server based on the one or more capabilities.

Assignments (3)
SECURITY AGREEMENT Recorded Jul 9, 2021
From: MAXLINEAR, INC.; MAXLINEAR COMMUNICATIONS, LLC; EXAR CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 056816/0089 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2020
From: INTEL CORPORATION
To: MAXLINEAR, INC.
Reel/Frame 053626/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2017
From: OMAR, MOHAMED
To: INTEL CORPORATION
Reel/Frame 042871/0115 →