IP Library › Granted Patent US 12,047,240
Granted Patent B2
US 12,047,240 · App. 18/545,817 · Granted Jul 23, 2024

System, method, and device for modifying network functionality based on provided passphrase

Inventor: Jeffrey Alma Hansen (Draper, UT)
Assignee: SoundVision Technologies, LLC
H04L41/0894H04W12/04H04W12/041H04W12/06H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,047,240
App. No.
18/545,817
Granted
Jul 23, 2024
Kind
B2
Abstract

A system and method for modifying functionality within a wireless network based on a provided passphrase is disclosed. The method includes defining a first and second set of network policies associated with a first and second passphrase, respectively, with the second passphrase being different from the first. The method also includes determining if the provided passphrase used by a client device while engaging in an authentication process with a mutable network device to secure a network connection matches one of the first or second passphrases. The method further includes configuring a traffic kernel module within the network device to provide the network connection to the client device, the connection defined by the set of network policies corresponding to the provided passphrase. Each network policy describes a functionality and governs the circumstances in which it is applied, the functionality being at least one of an access, a capacity, and a resource.

Claims (62)

1. A method for modifying functionality within a wireless network based on a provided passphrase, comprising:

defining a first set of network policies associated with a first passphrase for the wireless network;

defining a second set of network policies associated with a second passphrase for the wireless network, the second passphrase being different from the first passphrase;

determining if the provided passphrase used by a client device while engaging in an authentication process with a mutable network device to secure a network connection with the wireless network matches one of the first passphrase and the second passphrase, the mutable network device being communicatively coupled to the wireless network; and

configuring a traffic kernel module within the mutable network device to provide the network connection to the client device upon successful completion of the authentication process, the network connection defined at least in part by the first set of network policies if the provided passphrase is the first passphrase and defined at least in part by the second set of network policies if the provided passphrase is the second passphrase;

wherein the first set of network policies and the second set of network policies each comprise at least one network policy;

wherein each network policy describes a network functionality and governs the circumstances in which the network functionality is applied to the network connection, the network functionality being at least one of a network access, a network capacity, and a network resource;

wherein the first set of network policies differs from the second set of network policies by at least one unique network policy that is found exclusively in one of the first set of network policies and the second set of network policies.

2. The method of claim 1 , wherein the authentication process is a four-way handshake.

3. The method of claim 2 , wherein determining if the provided passphrase matches one of the first passphrase and the second passphrase is performed after a second message of the four-way handshake has been received.

4. The method of claim 1 , further comprising:

broadcasting a Service Set Identifier (SSID) for the wireless network through the mutable network device;

wherein the mutable network device is an access point;

wherein the authentication process is initiated in response to the mutable network device receiving a connection request from the client device directed to the SSID.

5. The method of claim 4 :

wherein the first set of network policies is associated with the first passphrase using a Pairwise Master Key (PMK) derived from the first passphrase and the SSID;

wherein the second set of network policies is associated with the second passphrase using a PMK derived from the second passphrase and the SSID;

wherein determining if the provided passphrase matches one of the first passphrase and the second passphrase further comprises, for each of the first passphrase and the second passphrase:

calculating a Pairwise Transient Key (PTK) based, in part, upon the respective PMK and unique identifiers of the mutable network device and the client device; and

determining if the client device used the same PTK during the authentication process.

6. The method of claim 1 , wherein the unique network policy is a scheduled network policy comprising a schedule and a network functionality that is periodically applied to the network connection according to the schedule.

7. The method of claim 6 , wherein the network functionality is a network access that is only available according to the schedule.

8. The method of claim 7 , further comprising:

redirecting the client device to a captive portal in response to the client device attempting to utilize the network access at a time prohibited by the schedule;

wherein the captive portal comprises a user interface through which a schedule exception can be requested.

9. The method of claim 1 , wherein the unique network policy is a network filtering policy that applies a filter on the network connection, the filter being at least one of a content-based filter and an application-based filter.

10. The method of claim 1 , further comprising:

defining a default network policy comprising a network functionality that is applied to every network connection provided through the mutable network device unless preempted by another network policy;

wherein the unique network policy comprises a policy exception that preempts and negates the default network policy.

11. The method of claim 1 , wherein the unique network policy is a dynamic network policy that applies a network functionality conditioned upon an action of a user associated with the client device.

12. The method of claim 1 , wherein the unique network policy is a usage policy that limits at least one of a throughput and a data limit.

13. A mutable network device for a wireless network, comprising:

a wired network interface communicatively coupled to a wired network;

a wireless network interface communicatively coupled to the wireless network;

a processor and a memory, the processor communicatively coupled to the wired network interface and the wireless network interface, the processor configured to:

define a first set of network policies and associate the first set of network policies with a first passphrase;

define a second set of network policies and associate the second set of network policies with a second passphrase, the second passphrase being different from the first passphrase;

broadcast a Service Set Identifier (SSID) for the wireless network through the wireless network interface;

receive a connection request from a client device through the wireless network interface, the connection request directed to the SSID;

engage in an authentication process with the client device to secure a network connection between the client device and the wireless network;

determine if a provided passphrase used by the client device while engaging in the authentication process matches one of the first passphrase and the second passphrase; and

configure a traffic kernel module within the memory to provide the network connection to the client device upon successful completion of the authentication process, the network connection defined at least in part by the first set of network policies if the provided passphrase is the first passphrase and defined at least in part by the second set of network policies if the provided passphrase is the second passphrase;

wherein the first set of network policies and the second set of network policies each comprise at least one network policy;

wherein each network policy describes a network functionality and governs the circumstances in which the network functionality is provisioned through the network connection, the network functionality being at least one of a network access, a network capacity, and a network resource;

wherein the first set of network policies differs from the second set of network policies by at least one unique network policy that is found exclusively in one of the first set of network policies and the second set of network policies.

14. The mutable network device of claim 13 :

wherein the unique network policy is a population policy comprising a network access and a population limit; and

wherein the population policy constrains the number of network connections authenticated through use of a specific passphrase and permitted to concurrently use the network access to be at most equal to the population limit.

15. The mutable network device of claim 13 :

wherein the authentication process is a four-way handshake; and

wherein the processor is configured to determine if the provided passphrase matches one of the first passphrase and the second passphrase after receiving a second message of the four-way handshake, the second message having been sent by the client device.

16. The mutable network device of claim 13 , wherein the unique network policy is a scheduled network policy comprising a schedule and a network functionality that is periodically applied to the network connection according to the schedule.

17. The mutable network device of claim 16 , wherein the network functionality is a network access that is only available according to the schedule.

18. The mutable network device of claim 17 , wherein the processor is further configured to:

redirect the client device to a captive portal in response to the client device attempting to utilize the network access at a time prohibited by the schedule;

wherein the captive portal comprises a user interface through which a schedule exception can be requested.

19. The mutable network device of claim 13 , wherein the processor is further configured to:

define a default network policy comprising a network functionality that is applied to every network connection;

determine if the network functionality is preempted by another network policy being enforced in response to completing the authentication process with the client device; and

apply the network functionality of the default network policy to the network connection unless the network functionality is determined to be preempted;

wherein the unique network policy comprises a policy exception that preempts and negates the default network policy.

20. The mutable network device of claim 13 , wherein the entire wireless network is provided solely by the wireless network interface of the mutable network device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2023
From: HANSEN, JEFFREY ALMA
To: SOUNDVISION TECHNOLOGIES, LLC
Reel/Frame 065925/0367 →
Continuity (2)
Provisional Application 63476143 · Dec 19, 2022
Related Publication 20240205088A1 · Jun 20, 2024
Cited By (1)
US 12,418,530