IP Library Granted Patent US 12,519,789
Granted Patent B2
US 12,519,789 · App. 18/065,311 · Granted Jan 6, 2026

Virtual authentication realm specified by wildcard elements

Inventors: Liangyi Huang (Taoyuan, TW); Ya-Ling Yang (Taipei, TW); Yao Wen Chang (Taipei, TW); Pin Hsiao (Taoyaun, TW)
Assignee: Ruckus IP Holdings LLC
H04L63/0892
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,789
App. No.
18/065,311
Granted
Jan 6, 2026
Kind
B2
Abstract

During operation, a computer system may receive, from an electronic device, a login request, where the login request includes or specifies an authentication realm in a network. Then, the computer system may compute whether the authentication realm at least partially matches a predefined authentication realm in the network, where the predefined authentication realm in the network includes at least one wildcard element, and where the partial match is for elements in the predefined authentication realm other than the at least one wildcard element. When there is a partial match, the computer system may provide, to a second computer system, an authentication request based at least in part on the login request. Next, the computer system may receive, from the second computer system, an authentication response. When the authentication response indicates successful authentication, the computer system may provide, to the electronic device, a login response.

Claims (39)

1 . A computer system, comprising:

an interface circuit configured to communicate with an electronic device and a second computer system;

a processor coupled to the interface circuit; and

memory, coupled to the processor, configured to store program instructions, wherein, when executed by the processor, the program instructions cause the computer system to perform operations comprising:

receiving, associated with the electronic device, a login request, wherein the login request comprises or specifies an authentication realm in a network;

computing whether the authentication realm at least partially matches a predefined authentication realm in the network, wherein the predefined authentication realm in the network comprises at least one wildcard element, and wherein the partial match is for elements in the predefined authentication realm other than the at least one wildcard element;

when there is a partial match, providing, addressed to the second computer system, an authentication request based at least in part on the login request, wherein the second computer system provides authentication services for multiple predefined authentication realms corresponding to a customer associated with the multiple predefined authentication realms, the multiple predefined authentication realms comprise the predefined authentication realm, the multiple predefined authentication realms are segmented according to geographic regions comprising cities, states or countries, and different second computer systems than the second computer system provide authentication services for different customers than the customer;

receiving, associated with the second computer system, an authentication response; and

when the authentication response indicates successful authentication, providing, addressed to the electronic device, a login response that indicates a successful login to the network.

2 . The computer system of claim 1 , wherein the computer system comprises a controller of computer network devices in the network.

3 . The computer system of claim 1 , wherein the second computer system comprises an authentication, authorization and accounting (AAA) server.

4 . The computer system of claim 1 , wherein the authentication realm is associated with an address in the network of the second computer system.

5 . The computer system of claim 1 , wherein, when there is a full match between the authentication realm and a second predefined authentication realm, the operations comprise performing authentication associated with the electronic device with a third computer system associated with the second predefined authentication realm.

6 . The computer system of claim 5 , wherein the third computer system is different from the second computer system.

7 . The computer system of claim 1 , wherein the computer system is not preconfigured with all elements in the authentication realm.

8 . The computer system of claim 1 , wherein computing whether there is at least a partial match comprises performing a look-up operation in a data structure with predefined authentication realms and one or more associated addresses of one or more computer systems that provide authentication services for the predefined authentication realms.

9 . The computer system of claim 1 , wherein the authentication request comprises a remote authentication dial-in user service (RADIUS) authentication request and the authentication response comprises a RADIUS authentication response.

10 . A non-transitory computer-readable storage medium for use in conjunction with a computer system, the computer-readable storage medium storing program instructions that, when executed by the computer system, cause the computer system to perform operations comprising:

receiving, associated with an electronic device, a login request, wherein the login request comprises or specifies an authentication realm in a network;

computing whether the authentication realm at least partially matches a predefined authentication realm in the network, wherein the predefined authentication realm in the network comprises at least one wildcard element, and wherein the partial match is for elements in the predefined authentication realm other than the at least one wildcard element;

when there is a partial match, providing, addressed to the second computer system, an authentication request based at least in part on the login request, wherein the second computer system provides authentication services for multiple predefined authentication realms corresponding to a customer associated with the multiple predefined authentication realms, the multiple predefined authentication realms comprise the predefined authentication realm, the multiple predefined authentication realms are segmented according to geographic regions comprising cities, states or countries, and different second computer systems than the second computer system provide authentication services for different customers than the customer;

receiving, associated with the second computer system, an authentication response; and

when the authentication response indicates successful authentication, providing, addressed to the electronic device, a login response that indicates a successful login to the network.

11 . The non-transitory computer-readable storage medium of claim 10 , wherein the computer system comprises a controller of computer network devices in the network.

12 . The non-transitory computer-readable storage medium of claim 10 , wherein the second computer system comprises an authentication, authorization and accounting (AAA) server.

13 . The non-transitory computer-readable storage medium of claim 10 , wherein, when there is a full match between the authentication realm and a second predefined authentication realm, the operations comprise performing authentication associated with the electronic device with a third computer system associated with the second predefined authentication realm.

14 . The non-transitory computer-readable storage medium of claim 10 , wherein the computer system is not preconfigured with all elements in the authentication realm.

15 . A method for performing flexible authentication to an authentication realm in a network, comprising:

by a computer system:

receiving, associated with an electronic device, a login request, wherein the login request comprises or specifies the authentication realm in the network;

computing whether the authentication realm at least partially matches a predefined authentication realm in the network, wherein the predefined authentication realm in the network comprises at least one wildcard element, and wherein the partial match is for elements in the predefined authentication realm other than the at least one wildcard element;

when there is a partial match, providing, addressed to the second computer system, an authentication request based at least in part on the login request, wherein the second computer system provides authentication services for multiple predefined authentication realms corresponding to a customer associated with the multiple predefined authentication realms, the multiple predefined authentication realms comprise the predefined authentication realm, the multiple predefined authentication realms are segmented according to geographic regions comprising cities, states or countries, and different second computer systems than the second computer system provide authentication services for different customers than the customer;

receiving, associated with the second computer system, an authentication response; and

when the authentication response indicates successful authentication, providing, addressed to the electronic device, a login response that indicates a successful login to the network.

16 . The method of claim 15 , wherein the computer system comprises a controller of computer network devices in the network.

17 . The method of claim 15 , wherein the second computer system comprises an authentication, authorization and accounting (AAA) server.

18 . The method of claim 15 , wherein, when there is a full match between the authentication realm and a second predefined authentication realm, the method comprises performing authentication associated with the electronic device with a third computer system associated with the second predefined authentication realm.

19 . The method of claim 18 , wherein the third computer system is different from the second computer system.

20 . The method of claim 15 , wherein the computer system is not preconfigured with all elements in the authentication realm.

Assignments (9)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067252/0657 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA)
Reel/Frame 074593/0348 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067259/0697 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069790/0575 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2024
From: HUANG, LIANGYI; YANG, YA-LING; CHANG, YAO WEN; HSIAO, PIN
To: ARRIS ENTERPRISES LLC
Reel/Frame 068494/0769 →
PATENT SECURITY AGREEMENT (TERM) Recorded Apr 29, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067259/0697 →
PATENT SECURITY AGREEMENT (ABL) Recorded Apr 29, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067252/0657 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2022
From: HUANG, LIANGYI; YANG, YA-LING; CHANG, YAO WEN; HSIAO, PIN
To: ARRIS ENTERPRISES LLC
Reel/Frame 062072/0391 →
Continuity (2)
Provisional Application 63290683 · Dec 17, 2021
Related Publication 20230198986A1 · Jun 22, 2023
References Cited (21)
US 8555350B1 · Shatzkamer · 2013 [cited by examiner]
US 20030217285A1 · Sanchez Herrero · 2003 [cited by examiner]
US 20040153555A1 · Haverinen · 2004 [cited by examiner]
US 20040193712A1 · Benenati · 2004 [cited by examiner]
US 20060077926A1 · Rune · 2006 [cited by examiner]
US 20070143613A1 · Sitch · 2007 [cited by examiner]
US 20070201469A1 · Iyer · 2007 [cited by examiner]
US 20080072301A1 · Chia · 2008 [cited by examiner]
US 20090077618A1 · Pearce · 2009 [cited by examiner]
US 20100303064A1 · Bari · 2010 [cited by examiner]
US 20110292830A1 · Yanggratoke · 2011 [cited by examiner]
US 20130210391A1 · Zhou · 2013 [cited by examiner]
US 20150143453A1 · Erb · 2015 [cited by examiner]
US 20160301680A1 · Main · 2016 [cited by examiner]
US 20210281445A1 · Trim · 2021 [cited by examiner]
US 20230140828A1 · Durvasula · 2023 [cited by examiner]
CN 111049789A · 2020 [cited by examiner]
NO 336812B1 · 2015 [cited by examiner]
Oiwa, Yutaka, et al. “PAKE-based mutual HTTP authentication for preventing phishing attacks.” Proceedings of the 18th international conference on World wide web. 2009. (Year: 2009). [cited by examiner]
Oiwa, Yutaka, et al. Mutual authentication protocol for HTTP. No. rfc8120. 2017. (Year: 2017). [cited by examiner]
Cisco. “Wildcard in realm list for RADIUS server?”, published Jul. 5, 2021. < https://community.cisco.com/t5/wireless/wildcard-in-realm-list-for-radius-server/td-p/3045703>. (Year: 2021). [cited by examiner]