IP Library Granted Patent US 10,581,863
Granted Patent B2
US 10,581,863 · App. 16/118,184 · Granted Mar 3, 2020

Access enforcement at a wireless access point

Inventors: Oscar S. Ernohazy (Saratoga, CA); Nicolas S. Dade (Santa Cruz, CA); Randall W. Frei (San Jose, CA); Robert J. Friday (Los Gatos, CA)
Assignee: Mist Systems, Inc.
H04L63/102H04L45/74H04L63/0263H04L63/20H04W8/005H04W12/08H04W48/20H04L63/108H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,581,863
App. No.
16/118,184
Granted
Mar 3, 2020
Kind
B2
Abstract

A first set of access rules is received from an access configuration service. The first set of access rules specifies addresses of devices authorized for a first user. A second set of access rules is received from the access configuration service. The second set of the access rules specifies addresses of devices authorized for a second user. At a wireless access point, a network packet associated with the first user is received. The first set of access rules is applied to filter the network packet.

Claims (35)

1. A wireless access point system, comprising:

a communication interface configured to:

receive a first set of access rules from an access configuration service, wherein the first set of access rules specifies addresses of devices authorized for a first user;

receive a second set of access rules from the access configuration service, wherein the second set of the access rules specifies addresses of devices authorized for a second user; and

receive at the wireless access point system a network packet associated with the first user; and

a hardware processor coupled with the communication interface and configured to apply the first set of access rules to filter the network packet, wherein the network packet is at least a part of a device discovery communication requesting discovery of devices available for communication, and filtering the network packet includes selectively routing the network packet to one or more of the devices authorized for the first user.

2. The system of claim 1 , wherein a software process of the wireless access point system configures a programmable rule filter of a software kernel of the wireless access point A system to at least in part implement the first set of access rules.

3. The system of claim 1 , wherein applying the first set of access rules to filter the network packet includes forwarding the network packet to a destination of a network tunnel.

4. The system of claim 1 , wherein the addresses of devices authorized for the first user include Internet Protocol or MAC addresses of the devices authorized for the first user.

5. The system of claim 1 , wherein the access configuration service is provided by one or more remote servers.

6. The system of claim 1 , wherein the communication interface is further configured to request the first set of access rules from the access configuration service at least in part by providing a user identifier of the first user received from the first user.

7. The system of claim 1 , wherein the communication interface is further configured to request the first set of access rules from the access configuration service at least in part by providing an identifier of a device of the first user wirelessly communicating with the access point.

8. The system of claim 1 , wherein the access configuration service dynamically provides to the wireless access point system an update to the first set of access rules in response to determining that a new device of the first user has connected to a network.

9. The system of claim 1 , wherein filtering the network packet includes determining that a source address of the network packet is not included in the addresses of devices authorized for the first user and in response, dropping the network packet.

10. The system of claim 1 , wherein filtering the network packet includes determining that a source address of the network packet is included in the addresses of devices authorized for the first user and in response, allowing the network packet to be received by a client device of the first user connected to the wireless access point system.

11. The system of claim 1 , wherein filtering the network packet includes determining that a destination address of the network packet is not included in the addresses of devices authorized for the first user and in response, blocking the network packet.

12. The system of claim 1 , wherein filtering the network packet includes determining that a source address of the network packet does not match an address of a client device of the first user connected to the wireless access point system and in response, blocking the network packet.

13. The system of claim 1 , wherein the hardware processor is further configured to request a renewal of the first set of access rules that is associated with an expiration time.

14. The system of claim 1 , wherein although the first set of access rules is removed from the wireless access point system after a client device of the first user disconnects from the wireless access point, the first set of access rules is cached for at least a predetermined amount of time after the client device of the first user disconnects from the wireless access point system.

15. The system of claim 1 , wherein filtering the network packet includes generating by the wireless access point system one or more responses advertising one or more of the devices authorized for the first user.

16. The system of claim 1 , wherein filtering the network packet includes providing a cached response advertising one of the devices authorized for the first user.

17. The system of claim 1 , wherein the access configuration service preemptively provides the first set of access rules to a second wireless access point system in response to determining that a client device of the first user is likely to migrate to the second wireless access point system.

18. The system of claim 17 , wherein the access configuration service determined that the client device of the first user is likely to migrate to the second wireless access point system at least in part by analyzing historical sequences of requests for the first set of access rules from one or more wireless access point systems for the client device of the first user.

19. A method, comprising:

receiving a first set of access rules from an access configuration service, wherein the first set of access rules specifies addresses of devices authorized for a first user;

receiving a second set of access rules from the access configuration service, wherein the second set of the access rules specifies addresses of devices authorized for a second user;

receiving at a wireless access point a network packet associated with the first user; and

using a hardware processor to apply the first set of access rules to filter the network packet;

wherein the network packet is at least a part of a device discovery communication requesting discovery of devices available for communication, and filtering the network packet includes selectively routing the network packet to one or more of the devices authorized for the first user.

20. A method, comprising:

receiving a first set of access rules from an access configuration service, wherein the first set of access rules specifies addresses of devices authorized for a first user;

receiving a second set of access rules from the access configuration service, wherein the second set of the access rules specifies addresses of devices authorized for a second user;

receiving at a wireless access point a network packet associated with the first user; and

using a hardware processor to apply the first set of access rules to filter the network packet;

wherein the network packet is at least a part of a device discovery communication requesting discovery of devices available for communication, and filtering the network packet includes providing a cached response advertising one of the devices authorized for the first user.

Assignments (2)
CONFIRMATORY ASSIGNMENT Recorded Jan 8, 2024
From: ERNOHAZY, OSCAR S.; DADE, NICOLAS S.; FREI, RANDALL; FRIDAY, ROBERT J.
To: JUNIPER NETWORKS, INC.
Reel/Frame 066224/0588 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2020
From: MIST SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 053539/0912 →
Continuity (3)
Continuation 15496331 · Apr 25, 2017
Continuation 14788496 · Jun 30, 2015
Related Publication 20190020660A1 · Jan 17, 2019