IP Library › Granted Patent US 11,689,926
Granted Patent B2
US 11,689,926 · App. 16/597,341 · Granted Jun 27, 2023

Onboarding wireless devices to private networks

Inventor: Rajesh S. Pazhyannur (Fremont, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04W12/08H04L61/10H04L61/4511H04L63/101H04W8/18H04W76/10H04W84/042
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,926
App. No.
16/597,341
Granted
Jun 27, 2023
Kind
B2
Abstract

An access point for a private network onboards a wireless device obtaining a connection request from the wireless device and detecting a standardized identifier that indicates the wireless device is unprovisioned for access to the private network. The access point disables an authentication protocol for granting access to the wireless device on the private network and limits access of the private network by the wireless device to accessing a provisioning server. The access point provides a connection response to the wireless device that indicates limited access to the private network.

Claims (50)

1. A method comprising:

obtaining at an access point for a private network, a connection request from a wireless device, the connection request including a standardized identifier;

detecting a predetermined value for the standardized identifier that indicates the wireless device is unprovisioned for access to the private network, the predetermined value codified in an industry standard for the standardized identifier to signal limited access to the private network for a plurality of unprovisioned wireless devices;

disabling an authentication protocol for granting access to the wireless device on the private network;

providing the wireless device access only to a provisioning server through the private network; and

providing a connection response to the wireless device, the connection response indicating that the wireless device is provided access to the private network only for communicating with the provisioning server.

2. The method of claim 1 , wherein detecting the predetermined value for the standardized identifier includes detecting a Public Land Mobile Network Identifier (PLMN-ID) assigned in the industry standard to be a provisioning PLMN-ID.

3. The method of claim 1 , wherein detecting the predetermined value for the standardized identifier comprises detecting a predetermined attach type of the connection request.

4. The method of claim 1 , further comprising:

forwarding a provisioning request from the wireless device to the provisioning server; and

forwarding a provisioning response to the wireless device, the provisioning response including an operational profile authorized to access the private network.

5. The method of claim 4 , further comprising:

obtaining another connection request from the wireless device, the another connection request identifying the operational profile; and

providing access to the private network based on the operational profile.

6. The method of claim 1 , wherein providing the wireless device access only to the provisioning server through the private network includes allowing a domain name resolution of the provisioning server for the wireless device.

7. The method of claim 1 , wherein providing the wireless device access only to the provisioning server through the private network includes comparing network traffic from the wireless device to at least one access control list configured for unprovisioned devices.

8. An apparatus comprising:

a network interface configured to communicate with a plurality of computing devices across one or more networks;

a wireless interface configured to wirelessly communicate with a wireless device; and

a hardware processor coupled to the network interface and the wireless interface, the hardware processor configured to:

obtain from the wireless device via the wireless interface, a connection request for access to a private network, the connection request including a standardized identifier;

detect a predetermined value for the standardized identifier that indicates the wireless device is unprovisioned for access to the private network, the predetermined value codified in an industry standard for the standardized identifier to signal limited access to the private network for a plurality of unprovisioned wireless devices;

disable an authentication protocol for granting access to the wireless device on the private network;

provide the wireless device access only to a provisioning server through the private network; and

cause the wireless interface to provide a connection response to the wireless device, the connection response indicating that the wireless device is provided access to the private network only for communicating with the provisioning server.

9. The apparatus of claim 8 , wherein the hardware processor is configured to detect the predetermined value for the standardized identifier by detecting a Public Land Mobile Network Identifier (PLMN-ID) assigned in the industry standard to be a provisioning PLMN-ID.

10. The apparatus of claim 8 , wherein the hardware processor is configured to detect the predetermined value for the standardized identifier by detecting a predetermined attach type of the connection request.

11. The apparatus of claim 8 , wherein the hardware processor is further configured to:

forward a provisioning request from the wireless device to the provisioning server; and

forward a provisioning response to the wireless device, the provisioning response including an operational profile authorized to access the private network.

12. The apparatus of claim 11 , wherein the hardware processor is further configured to:

obtain another connection request from the wireless device via the wireless interface, the another connection request identifying the operational profile; and

provide access to the private network based on the operational profile.

13. The apparatus of claim 8 , wherein the hardware processor is configured to provide the wireless device access only the provisioning server through the private network by allowing a domain name resolution of the provisioning server for the wireless device.

14. The apparatus of claim 8 , wherein the hardware processor is configured to provide the wireless device access only the provisioning server through the private network by comparing network traffic from the wireless device to at least one access control list configured for unprovisioned devices.

15. One or more non-transitory computer readable storage media encoded with instructions that, when executed by a processor of an access point for a private network, cause the processor to:

obtain a connection request from a wireless device, the connection request including a standardized identifier;

detect a predetermined value for the standardized identifier that indicates the wireless device is unprovisioned for access to the private network, the standardized identifier having a predetermined value codified in an industry standard for the standardized identifier to signal limited access to the private network for a plurality of unprovisioned wireless devices;

disable an authentication protocol for granting access to the wireless device on the private network;

provide the wireless device access only to a provisioning server through the private network; and

provide a connection response to the wireless device, the connection response indicating that the wireless device is provided access to the private network only for communicating with the provisioning server.

16. The non-transitory computer readable storage media of claim 15 , further comprising instructions operable to cause the processor to detect the predetermined value for the standardized identifier by detecting a Public Land Mobile Network Identifier (PLMN-ID) assigned in the industry standard to be a provisioning PLMN-ID.

17. The non-transitory computer readable storage media of claim 15 , further comprising instructions operable to cause the processor to detect the predetermined value for the standardized identifier by detecting a predetermined attach type of the connection request.

18. The non-transitory computer readable storage media of claim 15 , further comprising instructions operable to cause the processor to:

forward a provisioning request from the wireless device to the provisioning server; and

forward a provisioning response to the wireless device, the provisioning response including an operational profile authorized to access the private network.

19. The non-transitory computer readable storage media of claim 18 , further comprising instructions operable to cause the processor to:

obtain another connection request from the wireless device, the another connection request identifying the operational profile; and

providing access to the private network based on the operational profile.

20. The non-transitory computer readable storage media of claim 15 , further comprising instructions operable to cause the processor to provide the wireless device access only to the provisioning server through the private network by allowing a domain name resolution of the provisioning server for the wireless device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2019
From: PAZHYANNUR, RAJESH S.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 050667/0679 →
Continuity (1)
Related Publication 20210112413A1 · Apr 15, 2021