IP Library Granted Patent US 11,038,761
Granted Patent B2
US 11,038,761 · App. 16/561,877 · Granted Jun 15, 2021

Group isolation in wireless networks

Inventor: David Stiff (Sunnyvale, CA)
Assignee: ARRIS Enterprises LLC
H04L41/0893H04L12/4641H04L63/065H04W4/08H04W12/02H04W12/04H04W12/71H04W12/76H04W88/08H04W88/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,038,761
App. No.
16/561,877
Granted
Jun 15, 2021
Kind
B2
Abstract

Methods and Systems here may be used for managing a wireless network including associating a first and second wireless access device to an access point (AP), assigning the first and second wireless access device to respective first and second isolation groups, providing local communication via the AP within the isolation group, and prohibiting local communication via the AP between the first and second isolation groups.

Claims (38)

1. An electronic device, comprising:

one or more antenna nodes configured to couple to one or more antennas;

an interface circuit, communicatively coupled to the one or more antenna nodes, configured to wirelessly communicate with a second electronic device and a third electronic device, wherein the electronic device is configured to:

establish a connection with the second electronic device;

assign the second electronic device to an isolation group;

receive, associated with the third electronic device, a packet or a frame addressed to the second electronic device;

when the third electronic device is assigned to the isolation group, routing the packet or frame addressed to the second electronic device, wherein the routing provides direct communication between the third electronic device and the second electronic device within the isolation group via the electronic device; and

when the third electronic device is not assigned to the isolation group, prohibiting direct communication between the third electronic device and the second electronic device via the electronic device.

2. The electronic device of claim 1 , wherein the electronic device comprises an access point.

3. The electronic device of claim 1 , wherein, when the third electronic device is not assigned to the isolation group, the electronic device is configured to drop the packet or the frame.

4. The electronic device of claim 1 , wherein, when the third electronic device is not assigned to the isolation group, the electronic device is configured to route the packet or the frame addressed to the second electronic device to a computer or a server in a network.

5. The electronic device of claim 1 , wherein a set of one or more electronic devices assigned to the isolation group have different network or other access permissions than a second set of one or more electronic devices assigned to a different isolation group.

6. The electronic device of claim 1 , wherein, when the third electronic device is not assigned to the isolation group, the electronic device does not provide, to the third electronic device, information that specifies one or more electronic devices in the isolation group that are connected to the electronic device.

7. The electronic device of claim 1 , wherein the electronic device has a single service set identification (SSID) and a single virtual local area network (VLAN).

8. The electronic device of claim 1 , wherein the assignment is based at least in part on information comprising one of: an access control list that specifies the second electronic device, a pre-share key associated with the second electronic device, a dynamically generated pre-share key associated with the second electronic device, a media access control (MAC) address of the second electronic device, a username and a password, or a credential associated with a third-party website.

9. The electronic device of claim 8 , wherein the information is stored on the electronic device.

10. The electronic device of claim 1 , wherein the electronic device is configured to receive, associated with a controller or an authentication, authorization and accounting (AAA) server, information that specifies the isolation group.

11. The electronic device of claim 1 , wherein the isolation group has an associated single service set identification (SSID) or a single virtual local area network (VLAN) that is different from a second SSID or a second VLAN associated with a different isolation group.

12. A non-transitory computer-readable storage medium for use in conjunction with an electronic device, the computer-readable storage medium storing program instructions that, when executed by the electronic device, cause the electronic device to perform one or more operations comprising:

establishing a connection with a second electronic device;

assigning the second electronic device to an isolation group;

receiving, associated with a third electronic device, a packet or a frame addressed to the second electronic device;

when the third electronic device is assigned to the isolation group, routing the packet or frame addressed to the second electronic device, wherein the routing provides direct communication between the third electronic device and the second electronic device within the isolation group via the electronic device; and

when the third electronic device is not assigned to the isolation group, prohibiting direct communication between the third electronic device and the second electronic device via the electronic device.

13. The non-transitory computer-readable storage medium of claim 12 , wherein the electronic device comprises an access point.

14. The non-transitory computer-readable storage medium of claim 12 , wherein, when the third electronic device is not assigned to the isolation group, the operations comprise dropping the packet or the frame.

15. The non-transitory computer-readable storage medium of claim 12 , wherein, when the third electronic device is not assigned to the isolation group, the operations comprise routing the packet or the frame addressed to the second electronic device to a computer or a server in a network.

16. The non-transitory computer-readable storage medium of claim 12 , wherein a set of one or more electronic devices assigned to the isolation group have different network or other access permissions than a second set of one or more electronic devices assigned to a different isolation group.

17. The non-transitory computer-readable storage medium of claim 12 , wherein the operations comprise receiving, associated with a controller or an authentication, authorization and accounting (AAA) server, information that specifies the isolation group.

18. The non-transitory computer-readable storage medium of claim 12 , wherein the isolation group has an associated single service set identification (SSID) or a single virtual local area network (VLAN) that is different from a second SSID or a second VLAN associated with a different isolation group.

19. A method for selectively providing direct communication within an isolation group, comprising:

by an electronic device:

establishing a connection with a second electronic device;

assigning the second electronic device to the isolation group;

receiving, associated with a third electronic device, a packet or a frame addressed to the second electronic device;

when the third electronic device is assigned to the isolation group, routing the packet or frame addressed to the second electronic device, wherein the routing provides the direct communication between the third electronic device and the second electronic device within the isolation group via the electronic device; and

when the third electronic device is not assigned to the isolation group, prohibiting direct communication between the third electronic device and the second electronic device via the electronic device.

20. The method of claim 19 , wherein the method comprises routing the packet or the frame addressed to the second electronic device to a computer or a server in a network.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2026
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 075600/0560 →
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067620/0675 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 074593/0001 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067620/0717 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 069743/0220 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
PATENT SECURITY AGREEMENT (TERM) Recorded Jun 4, 2024
From: RUCKUS IP HOLDINGS LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067620/0717 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jun 4, 2024
From: RUCKUS IP HOLDINGS LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067620/0675 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
Continuity (5)
Continuation 15642233 · Jul 5, 2017
Continuation 14747930 · Jun 23, 2015
Provisional Application 62016532 · Jun 24, 2014
Provisional Application 62097815 · Dec 30, 2014
Related Publication 20190394092A1 · Dec 26, 2019