IP Library Granted Patent US 11,218,488
Granted Patent B2
US 11,218,488 · App. 16/704,656 · Granted Jan 4, 2022

Access enforcement at a wireless access point

Inventors: Oscar Ernohazy (Saratoga, CA); Nicholas S. Dade (Santa Cruz, CA); Randall Wayne Frei (Los Altos, CA); Robert J. Friday (Los Gatos, CA)
Assignee: Juniper Networks, Inc.
H04L63/102H04L45/74H04L63/0263H04L63/20H04W8/005H04W12/082H04W12/084H04W12/088H04W48/20H04L63/108H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,218,488
App. No.
16/704,656
Granted
Jan 4, 2022
Kind
B2
Abstract

A first set of access rules is received from an access configuration service. The first set of access rules specifies addresses of devices authorized for a first user. A second set of access rules is received from the access configuration service. The second set of the access rules specifies addresses of devices authorized for a second user. At a wireless access point, a network packet associated with the first user is received. The first set of access rules is applied to filter the network packet.

Claims (45)

1. A wireless access point system, comprising:

hardware processing circuitry;

one or more hardware memories storing instructions that when executed configure the hardware processing circuitry to perform operations comprising:

receiving an access rule specifying a device authorized for access by a source;

receiving a packet;

determining the packet is from the source; and

routing the packet according to the access rule based on the determination,

wherein the packet is addressed to a second device, and wherein the routing of the packet comprises determining, based on the access rule, that the second device is not permitted for access by the source, and dropping the packet in response to the determination.

2. The system of claim 1 , wherein the access rule specifies a plurality of devices authorized for access by the source, and wherein the packet is addressed to a second device of the plurality of devices, and routing the packet according to the access rule comprises forwarding the packet to the second device based on the access rule.

3. The system of claim 1 , wherein the access rule specifies the device is authorized for access by specifying an Internet Protocol or MAC addresses of the device.

4. The system of claim 1 , the operations further comprising receiving a device identifier, and requesting access rules for the device identifier from a server, wherein the receiving of the access rules is in response to the requesting.

5. The system of claim 1 , the operations further comprising receiving an updated access rule indicating an additional device authorized for access by the source.

6. The system of claim 1 , the operations further comprising generating one or more messages advertising the device authorized for access by the first source.

7. A wireless access point system, comprising:

hardware processing circuitry;

one or more hardware memories storing instructions that when executed configure the hardware processing circuitry to perform operations comprising:

receiving an access rule specifying a device authorized for access by a source;

receiving a packet;

determining the packet is from the source; and

routing the packet according to the access rule based on the determination,

wherein the packet is addressed to a second device, and wherein the routing of the packet comprises determining, based on the access rule, that the second device is permitted for access by the source, and forwarding the packet to the second device based on the determination.

8. A non-transitory computer readable storage medium comprising instructions that when executed by hardware processing circuitry, configure the hardware processing circuitry to perform operations comprising:

receiving, by an access point, an access rule specifying a device authorized for access by a source;

receiving, by the access point, a packet;

determining, by the access point, the packet is from the source; and

routing, by the access point, the packet according to the access rule based on the determination,

wherein the packet is addressed to a second device, and wherein the routing of the packet comprises determining, based on the access rule, that the second device is not permitted for access by the source, and dropping the packet in response to the determination.

9. The non-transitory computer readable storage medium of claim 8 , wherein the access rule specifies a plurality of devices authorized for access by the source, and wherein the packet is addressed to a second device of the plurality of devices, and routing the packet according to the access rule comprises forwarding the packet to the second device based on the access rule.

10. The non-transitory computer readable storage medium of claim 8 , wherein the access rule specifies the device is authorized for access by specifying an Internet Protocol or MAC addresses of the device.

11. The non-transitory computer readable storage medium of claim 8 , the operations further comprising receiving a device identifier, and requesting access rules for the device identifier from a server, wherein the receiving of the access rules is in response to the requesting.

12. The non-transitory computer readable storage medium of claim 8 , the operations further comprising receiving an updated access rule indicating an additional device authorized for access by the source.

13. The non-transitory computer readable storage medium of claim 8 , the operations further comprising generating one or more messages advertising the device authorized for access by the first source.

14. A non-transitory computer readable storage medium comprising instructions that when executed by hardware processing circuitry, configure the hardware processing circuitry to perform operations comprising:

receiving, by an access point, an access rule specifying a device authorized for access by a source;

receiving, by the access point, a packet determining, by the access point, the packet is from the source; and

routing, by the access point, the packet according to the access rule based on the determination,

wherein the packet is addressed to a second device, and wherein the routing of the packet comprises determining, based on the access rule, that the second device is permitted for access by the source, and forwarding the packet to the second device based on the determination.

15. A method, comprising:

receiving, by an access point, an access rule specifying a device authorized for access by a source;

receiving, by the access point, a packet;

determining, by the access point, the packet is from the source;

routing, by the access point, the packet according to the access rule based on the determination; and

generating one or more messages advertising the device authorized for access by the source.

16. The method of claim 8 , wherein the access rule specifies a plurality of devices authorized for access by the source, and wherein the packet is addressed to a second device of the plurality of devices, and routing the packet according to the access rule comprises forwarding the packet to the second device based on the access rule.

17. The method of claim 8 , further comprising receiving a device identifier, and requesting access rules for the device identifier from a server, wherein the receiving of the access rules is in response to the requesting.

Assignments (3)
CONFIRMATORY ASSIGNMENT Recorded Jan 8, 2024
From: ERNOHAZY, OSCAR S.; DADE, NICOLAS S.; FREI, RANDALL; FRIDAY, ROBERT J.
To: JUNIPER NETWORKS, INC.
Reel/Frame 066224/0870 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2020
From: MIST SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 053539/0912 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2019
From: ERNOHAZY, OSCAR S.; DADE, NICHOLAS S.; FREI, RANDALL W.; FRIDAY, ROBERT J.
To: MIST SYSTEMS, INC.
Reel/Frame 051193/0106 →
Continuity (4)
Continuation 16118184 · Aug 30, 2018
Continuation 15496331 · Apr 25, 2017
Continuation 14788496 · Jun 30, 2015
Related Publication 20200112567A1 · Apr 9, 2020