IP Library › Granted Patent US 11,140,043
Granted Patent B2
US 11,140,043 · App. 16/576,387 · Granted Oct 5, 2021

Wireless client onboarding and segmentation

Inventors: Amine Choukir (Lausanne, CH); Roberto Muccifora (Ropraz, CH); Antonio Trifilo (Pully, CH); Domenico Ficara (Essertines-sur-Yverdon, CH); Vincent Cuissard (Eteaux, FR); Salvatore Valenza (Pomy, CH)
Assignee: CISCO TECHNOLOGY, INC.
H04L41/12H04L61/2015H04W12/06H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,140,043
App. No.
16/576,387
Granted
Oct 5, 2021
Kind
B2
Abstract

A method is provided in a wireless local area network controller in a wireless communication network. The wireless communication network includes one or more virtual networks identified with virtual network IDs, VNIDs. A request is received from a wireless client to onboard onto the network and the wireless client is mapped to an onboarding VNID. The onboarding VNID is associated with an onboarding virtual network that does not require an authentication of the wireless client. An Internet Protocol address assignment is forwarded to the wireless client. The wireless client is remapped from the onboarding VNID to the destination VNID after authenticating the wireless client. The wireless client maintains the assigned IP address after moving from the onboarding VNID to the destination VNID. Access to the wireless client on a virtual network identified by the destination VNID is provided via the assigned IP address.

Claims (69)

1. A method in a wireless local area network, LAN, controller in a wireless communication network comprising one or more virtual networks, wherein each virtual network is identified with a virtual network ID, VNID, the method comprising:

receiving a request from a wireless client to onboard onto the wireless communication network;

mapping the wireless client to an onboarding VNID, wherein the onboarding VNID is associated with an onboarding virtual network that does not require an authentication of the wireless client;

forwarding an Internet Protocol, IP, address assignment to the wireless client associated with the onboarding virtual network;

determining a destination VNID after authenticating the wireless client, wherein the destination VNID is different from the onboarding VNID;

remapping the wireless client from the onboarding VNID to the destination VNID, wherein the wireless client maintains the assigned IP address after moving from the onboarding VNID to the destination VNID; and

providing access to the wireless client on a virtual network identified by the destination VNID via the assigned IP address.

2. The method of claim 1 , wherein the authentication of the wireless client is a level 3 web authentication of the wireless client using the assigned IP address.

3. The method of claim 1 , further comprising:

forwarding a request from the wireless device to obtain an IP address to a DHCP server;

receiving, from the DHCP server, the IP address assignment; and

binding the IP address assignment to the onboarding VNID.

4. The method of claim 3 , further comprising:

transferring the binding of the IP address assignment to the destination VNID after determining the destination VNID after authenticating the wireless client; and

preventing, after the binding is transferred, the assignment of the IP address by the DHCP server for a second wireless client mapped to the onboarding VNID.

5. The method of claim 1 , wherein determining the destination VNID after authenticating the wireless client comprises:

determining a set of network properties associated with the wireless client; and

identifying a VNID as the destination VNID that matches the set of network properties.

6. The method of claim 5 , wherein determining the set of network properties associated with the wireless client comprises requesting the network properties from one or more network management systems using a property of the wireless client.

7. The method of claim 5 , wherein identifying a VNID as the destination VNID that matches the set of network properties comprises;

determining whether an existing virtual network matches the set of network properties; and

upon determining no existing virtual network matches the set of network properties:

creating a new virtual network with a new VNID that includes each of the network properties in the set of network properties; and

identifying the new VNID of the new virtual network as the destination VNID.

8. The method of claim 5 , wherein the set of network properties comprises one or more of a service to be available to the wireless client and a policy to apply to the wireless client.

9. A wireless local area network, LAN, controller in a wireless communication network comprising one or more virtual networks, wherein each virtual network is identified with a virtual network ID, VNID, the WLAN controller comprising:

a memory comprising instructions; and

a hardware processor;

wherein the WLAN controller, when executing the instructions at the hardware processor, is configured to:

receive a request from a wireless client to onboard onto the wireless communication network;

map the wireless client to an onboarding VNID, wherein the onboarding VNID is associated with an onboarding virtual network that does not require an authentication of the wireless client;

forward an Internet Protocol, IP, address assignment to the wireless client associated with the onboarding virtual network;

determine a destination VNID after authenticating the wireless client, wherein the destination VNID is different from the onboarding VNID;

remap the wireless client from the onboarding VNID to the destination VNID, wherein the wireless client maintains the assigned IP address after moving from the onboarding VNID to the destination VNID; and

provide access to the wireless client on a virtual network identified by the destination VNID via the assigned IP address.

10. The WLAN controller of claim 9 , wherein the authentication of the wireless client is a level 3 web authentication of the wireless client using the assigned IP address.

11. The WLAN controller of claim 9 , wherein the WLAN controller is further configured to:

forward a request from the wireless device to obtain an IP address to a DHCP server;

receive, from the DHCP server, the IP address assignment; and

bind the IP address assignment to the onboarding VNID.

12. The WLAN controller of claim 11 , wherein the WLAN controller is further configured to:

transfer the binding of the IP address assignment to the destination VNID after determining the destination VNID after authenticating the wireless client; and

prevent, after the binding is transferred, the assignment of the IP address by the DHCP server for a second wireless client mapped to the onboarding VNID.

13. The method of claim 9 , wherein the WLAN controller determining the destination VNID after authenticating the wireless client comprises:

determining a set of network properties associated with the wireless client; and

identifying a VNID as the destination VNID that matches the set of network properties.

14. The method of claim 13 , wherein the WLAN controller determining the set of network properties associated with the wireless client comprises requesting the network properties from one or more network management systems using a property of the wireless client.

15. The method of claim 13 , wherein the WLAN controller identifying a VNID as the destination VNID that matches the set of network properties comprises;

determining whether an existing virtual network matches the set of network properties; and

upon determining no existing virtual network matches the set of network properties:

creating a new virtual network with a new VNID that includes each of the network properties in the set of network properties; and

identifying the new VNID of the new virtual network as the destination VNID.

16. The method of claim 13 , wherein the set of network properties comprises one or more of a service to be available to the wireless client and a policy to apply to the wireless client.

17. A method in a wireless client in a wireless communication network comprising one or more virtual networks, wherein each virtual network is identified with a virtual network ID, VNID, the method comprising:

communicating a request to a wireless access point to onboard onto the wireless communication network;

receiving an Internet Protocol, IP, address assignment associated with an onboarding virtual network configured on the wireless communication network;

using the IP address assignment to complete an authentication process; and

after completing the authentication process, accessing, using the received IP address assignment, the wireless communication network on a destination virtual network different from the onboarding virtual network.

18. The method of claim 17 , wherein the authentication process is a level 3 web authentication completed by the wireless client using the assigned IP address.

19. A wireless client in a wireless communication network comprising one or more virtual networks, wherein each virtual network is identified with a virtual network ID, VNID, the wireless client comprising:

one or more interfaces configured to receive wireless transmissions;

a memory comprising instructions; and

a hardware processor;

wherein the wireless node, when executing the instructions at the hardware processor, is configured to:

communicate a request to a wireless access point to onboard onto the wireless communication network;

receive an Internet Protocol, IP, address assignment associated with an onboarding virtual network configured on the wireless communication network; and

use the IP address assignment to complete an authentication process;

after completing the authentication process, access, using the received IP address assignment, the wireless communication network on a destination virtual network different from the onboarding virtual network.

20. The wireless client of claim 19 , wherein the authentication process is a level 3 web authentication completed by the wireless client using the assigned IP address.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2019
From: CHOUKIR, AMINE; MUCCIFORA, ROBERT; TRIFILO, ANTONIO; FICARA, DOMENICO; CUISSARD, VINCENT; VALENZA, SALVATORE
To: CISCO TECHNOLOGY, INC.
Reel/Frame 050436/0505 →
Continuity (1)
Related Publication 20210092021A1 · Mar 25, 2021