IP Library Granted Patent US 11,792,192
Granted Patent B2
US 11,792,192 · App. 17/390,208 · Granted Oct 17, 2023

Automatic network configuration for security devices

Inventor: Mark Reimer (Denver, CO)
Assignee: The ADT Security Corporation
H04L63/0876H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,792,192
App. No.
17/390,208
Granted
Oct 17, 2023
Kind
B2
Abstract

A method, node, wireless device and installation device are disclosed. In one or more embodiments, a node configured to operate a security virtual local area network (VLAN) and a customer VLAN independent from the security VLAN is provided. The security VLAN is configured to operate using a first network partition different from a second network partition used by the customer VLAN. The node includes processing circuitry configured to receive information from a first device requesting access to the node, determine whether to add a first device to the security VLAN based at least on the received information from the first device meeting a predefined criterion, and configure the first device to access one of the security VLAN and customer VLAN based at least on the determination.

Claims (67)

1. A node configured to operate a security virtual local area network (VLAN) and a customer VLAN independent from the security VLAN, the security VLAN configured to operate using a first network partition different from a second network partition used by the customer VLAN, the node comprising:

a monitoring agent configured to monitor at least one network connectivity measure of the security VLAN;

a processor; and

a memory storing instructions that, when executed, cause the processor to:

receive information from a first device requesting access to the node;

determine whether to add the first device to the security VLAN based at least on the received information from the first device meeting a predefined criterion;

configure the first device to access the security VLAN or the customer VLAN based at least on the determination of whether to add the first device to the security VLAN;

determine the monitoring agent is disconnected from the security VLAN;

determine the security VLAN is not detectable;

evaluate a respective basic service set identifier (BSSID) value for each network that is detectable;

determine whether at least one respective BSSID value of the at least one detectable network equals a BSSID value of the security VLAN;

cause transmission of a message, via a cellular communication path, indicating a lost connection if at least one respective BSSID value for at least one network does not equal the BSSID value of the security VLAN; and

initiate re-connection to a first detectable network if the first detectable network is associated with a BSSID value that equals the BSSID value of the security VLAN.

2. The node of claim 1 , wherein the memory stores instructions that, when executed, further cause the processor to create the security VLAN in response to the received information.

3. The node of claim 1 , wherein the memory stores instructions that, when executed, further cause the processor to:

receive security data, from the first device, over the security VLAN;

determine that a destination internet protocol and port associated with the security data fails to meet a criterion associated with the first device; and

reject transmission of the security data in response to the determination that the destination internet protocol and port fail to meet the criterion.

4. The node of claim 1 , wherein the first device is one of a security alarm panel and premises security device; and

the node is a wireless router positioned at a premises.

5. The node of claim 1 , wherein the security VLAN is associated with a first service set identifier (SSID), the customer VLAN is associated with a second SSID different from the first SSID.

6. The node of claim 1 , wherein the memory stores instructions that, when executed, further cause the processor to identify the first device as a premises security device based at least on the received information, the determination to add the first device to the security VLAN being based at least on the identification of the first device.

7. The node of claim 1 , wherein, in response to determining to add the first device to the security VLAN, trigger installation of at least one firewall rule associated with the first device, the installation including adding the at least one firewall rule to an allow list; and

the memory stores instructions that, when executed, further cause the processor to block communications associated with the security VLAN where the communications fail to meet the at least one firewall rule in the allow list.

8. The node of claim 1 , wherein the customer VLAN is a consumer-managed VLAN, the security VLAN is a service provider managed VLAN; and

the first device is added to the security VLAN without knowledge of a service set identifier (SSID) and cryptographic key associated with the consumer VLAN.

9. The node of claim 1 , wherein the memory stores instructions that, when executed, further cause the processor to initialize the security VLAN in response to determining to add the first device to the security VLAN, the first device is configured to access the security VLAN.

10. The node of claim 1 , wherein the configuring of the first device to access the security VLAN includes communicating a network configuration object to the first device, the network configuration object including at least one of a service set identifier (SSID), pre-shared key (PSK) and network security credentials for accessing the security VLAN.

11. The node of claim 1 , wherein the memory stores instructions that, when executed, further cause the processor to:

monitor at least one network connectivity measure of the security VLAN;

indicate that at least one network connectivity measure fails to meet at least one predefined threshold; and

receive an indication to change at least one security VLAN parameter, the change of the at least one security VLAN parameter being based at least on the indication that at least one network connectivity measure fails to meet at least one predefined threshold.

12. The node of claim 1 , wherein the memory stores instructions that, when executed, further cause the processor to:

determine the first device is not listed in a preconfigured device list that indicates devices allowed to operate in the security VLAN; and

in response to the determination that the first device is not listed in the preconfigured device list, add the first device to the customer VLAN.

13. A method implemented by a node that is configured to operate a security virtual local area network (VLAN) and a customer VLAN independent from the security VLAN, the security VLAN configured to operate using a first network partition different from a second network partition used by the customer VLAN, the node comprising a monitoring agent configured to monitor at least one network connectivity measure of the security VLAN, the method comprising:

receiving information from a first device requesting access to the node;

determining whether to add the first device to the security VLAN based at least on the received information from the first device meeting a predefined criterion;

configuring the first device to access the security VLAN or the customer VLAN based at least on the determination of whether to add the first device to the security VLAN;

determining the monitoring agent is disconnected from the security VLAN;

determining the security VLAN is not detectable;

evaluating a respective basic service set identifier (BSSID) value for each network that is detectable;

determining whether at least one respective BSSID value of the at least one detectable network equals a BSSID value of the security VLAN;

causing transmission of a message, via a cellular communication path, indicating a lost connection if at least one respective BSSID value for at least one network does not equal the BSSID value of the security VLAN; and

initiate re-connection to a first detectable network if the first detectable network is associated with a BSSID value that equals the BSSID value of the security VLAN.

14. The method of claim 13 , further comprising creating the security VLAN in response to the received information.

15. The method of claim 13 , further comprising:

receiving security data, from the first device, over the security VLAN;

determining that a destination internet protocol and port associated with the security data fails to meet a criterion associated with the first device; and

rejecting transmission of the security data in response to the determination that the destination internet protocol and port fail to meet the criterion.

16. The method of claim 13 , wherein the first device is one of a security alarm panel and premises security device; and

the node is a wireless router positioned at a premises.

17. The method of claim 13 , wherein the security VLAN is associated with a first service set identifier (SSID), the customer VLAN is associated with a second SSID different from the first SSID.

18. The method of claim 13 , further comprising identifying the first device as a premises security device based at least on the received information, the determination to add the first device to the security VLAN being based at least on the identification of the first device.

19. The method of claim 13 , wherein, in response to determining to add the first device to the security VLAN, trigger installation of at least one firewall rule associated with the first device, the installation including adding the at least one firewall rule to an allow list; and

the method further includes blocking communications associated with the security VLAN where the communications fail to meet the at least one firewall rule in the allow list.

20. The method of claim 13 , wherein the customer VLAN is a consumer-managed VLAN, the security VLAN is a service provider managed VLAN; and

the first device is added to the security VLAN without knowledge of a service set identifier (SSID) and cryptographic key associated with the consumer VLAN.

21. The method of claim 13 , further comprising initializing the security VLAN in response to determining to add the first device to the security VLAN, the first device is configured to access the security VLAN.

22. The method of claim 13 , wherein the configuring of the first device to access the security VLAN includes communicating a network configuration object to the first device, the network configuration object including at least one of a service set identifier (SSID), pre-shared key (PSK) and network security credentials for accessing the security VLAN.

23. The method of claim 13 , further comprising:

monitoring at least one network connectivity measure of the security VLAN;

indicating that at least one network connectivity measure fails to meet at least one predefined threshold; and

receiving an indication to change at least one security VLAN parameter, the change of the at least one security VLAN parameter being based at least on the indication that at least one network connectivity measure fails to meet at least one predefined threshold.

24. The method of claim 13 , further comprising:

determining the first device is not listed in a preconfigured device list that indicates devices allowed to operate in the security VLAN; and

in response to the determination that the first device is not listed in the preconfigured device list, adding the first device to the customer VLAN.

Assignments (2)
SECURITY INTEREST Recorded Apr 28, 2023
From: THE ADT SECURITY CORPORATION
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 063489/0434 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2021
From: REIMER, MARK
To: THE ADT SECURITY CORPORATION
Reel/Frame 057765/0066 →
Continuity (2)
Provisional Application 63059411 · Jul 31, 2020
Related Publication 20220038457A1 · Feb 3, 2022
Cited By (1)
US 12,425,852