IP Library Granted Patent US 12,640,928
Granted Patent B2
US 12,640,928 · App. 17/016,676 · Granted May 26, 2026

Device-independent authentication based on a passphrase and a policy

Inventors: David Sheldon Stephenson (San Jose, CA); Ron Sidi (San Jose, CA); Ming-Jye Sheu (Saratoga, CA)
Assignee: Ruckus IP Holdings LLC
H04L9/3226H04L9/0869H04L63/0892H04L63/107H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,640,928
App. No.
17/016,676
Filed
Sep 10, 2020
Granted
May 26, 2026
Kind
B2
Art Unit
2496
USPC
713/155
Abstract

An electronic device that selectively approves secure access of a second electronic device to a network is described. This electronic device receives an access request associated with a computer, where the access request includes passphrase parameters associated with a user, and the passphrase parameters include inputs to and an output of a cryptographic calculation. In response, the electronic device calculates one or more second outputs of the cryptographic calculation based at least in part on the inputs and one or more stored passphrases. Moreover, when there is a match between one of the one or more second outputs and the output, the electronic device accesses a policy associated with the user. Then, when one or more criteria associated with the policy are met, the electronic device selectively provides an access acceptance message to the computer, which includes information for establishing the secure access of the second electronic device.

Claims (39)

1 . An electronic device, comprising:

an interface circuit configured to communicate with a computer;

a processor coupled to the interface circuit; and

memory, coupled to the processor, configured to store program instructions, wherein, when executed by the processor, the program instructions cause the electronic device to perform operations comprising:

receiving an access request associated with the computer, wherein the access request comprises passphrase parameters corresponding to a passphrase associated with a user, the passphrase parameters comprise inputs to a cryptographic calculation and an output of the cryptographic calculation, and the cryptographic calculation is associated with a pre-shared key (PSK) of the user;

calculating one or more second outputs of the cryptographic calculation based at least in part on the inputs, a passphrase and an identifier of the computer, which is included in the passphrase parameters;

when there is a match between one of the one or more second outputs and the output, accessing a policy associated with the user, wherein the policy is different from an authentication credential associated with the user, the policy specifies spatial validity temporal validity, or both, of the passphrase, and wherein accessing the policy comprises receiving the policy from a second computer associated with property management of different hotels in a hotel brand or chain and the different hotels are located at different geographic locations; and

when one or more criteria associated with the policy are met, selectively providing an access acceptance message addressed to the computer, wherein the access acceptance message is intended for a second electronic device associated with the user and comprises information for establishing secure access of the second electronic device to a network.

2 . The electronic device of claim 1 , wherein the electronic device comprises an authentication, authorization, and accounting (AAA) server.

3 . The electronic device of claim 1 , wherein the passphrase parameters comprises: a random number associated with the second electronic device, a random number associated with a computer network device, the output of the cryptographic calculation, an identifier of the second electronic device, and an identifier of the computer network device.

4 . The electronic device of claim 3 , wherein the stored passphrase is included in stored passphrases, which are organized based at least in part on identifiers of different networks.

5 . The electronic device of claim 1 , wherein the policy comprises a time interval when the passphrase is valid.

6 . The electronic device of claim 1 , wherein the policy comprises a physical location where the passphrase is valid or the network that the user is allowed to access.

7 . The electronic device of claim 6 , wherein the interface circuit is configured to communicate with a third computer;

wherein the operations comprise communicating with the third computer to determine whether the second electronic device is associated with the location; and

wherein, when the second electronic device is associated with the location, the access acceptance message is selectively provided.

8 . The electronic device of claim 1 , wherein the network comprises a virtual network associated with a location, and the information in the access acceptance message allows the second electronic device to establish secure communication with the virtual network.

9 . The electronic device of claim 8 , wherein the virtual network comprises: a virtual local area network (VLAN) or a virtual extensible local area network (VXLAN).

10 . The electronic device of claim 8 , wherein the access acceptance message comprises an identifier of the virtual network; and

wherein the identifier comprises a virtual local area network identifier (VLANID) or a virtual network identifier (VNI).

11 . The electronic device of claim 10 , wherein the identifier comprises information that specifies one of more than 4,096 virtual networks.

12 . The electronic device of claim 1 , wherein the secure communication is independent of traffic associated with other users of the network.

13 . The electronic device of claim 1 , wherein the access request comprises a remote authentication dial-in user service (RADIUS) access request and the access acceptance message comprises a RADIUS access acceptance message.

14 . The electronic device of claim 1 , wherein the policy allows the user to access multiple networks at different locations.

15 . The electronic device of claim 14 , wherein the inputs used in the calculation of the one or more second outputs comprise a given identifier of a given network.

16 . The electronic device of claim 1 , wherein the passphrase is independent of an identifier associated with the second electronic device.

17 . The electronic device of claim 1 , wherein the passphrase is independent of the second electronic device or hardware in the second electronic device.

18 . A non-transitory computer-readable storage medium for use in conjunction with an electronic device, the computer-readable storage medium storing program instructions that, when executed by the electronic device, cause the electronic device to perform operations comprising:

receiving an access request associated with a computer, wherein the access request comprises passphrase parameters corresponding to a passphrase associated with a user, the passphrase parameters comprise inputs to a cryptographic calculation and an output of the cryptographic calculation, and the cryptographic calculation is associated with a pre-shared key (PSK) of the user;

calculating one or more second outputs of the cryptographic calculation based at least in part on the inputs, a passphrase and an identifier of the computer, which is included in the passphrase parameters;

when there is a match between one of the one or more second outputs and the output, accessing a policy associated with the user, wherein the policy is different from an authentication credential associated with the user, the policy specifies spatial validity temporal validity, or both, of the passphrase, and wherein accessing the policy comprises receiving the policy from a second computer associated with property management of different hotels in a hotel brand or chain and the different hotels are located at different geographic locations; and

when one or more criteria associated with the policy are met, selectively providing an access acceptance message addressed to the computer, wherein the access acceptance message is intended for a second electronic device associated with the user and comprises information for establishing secure access of the second electronic device to a network.

19 . A method for selectively approving secure access to a network, comprising:

by an electronic device:

receiving an access request associated with a computer, wherein the access request comprises passphrase parameters corresponding to a passphrase associated with a user, the passphrase parameters comprise inputs to a cryptographic calculation and an output of the cryptographic calculation, and the cryptographic calculation is associated with a pre-shared key (PSK) of the user;

calculating one or more second outputs of the cryptographic calculation based at least in part on the inputs, a stored passphrase and an identifier of the computer, which is included in the passphrase parameters;

when there is a match between one of the one or more second outputs and the output, accessing a policy associated with the user, wherein the policy is different from an authentication credential associated with the user, the policy specifies spatial validity temporal validity, or both, of the passphrase, and wherein accessing the policy comprises receiving the policy from a second computer associated with property management of different hotels in a hotel brand or chain and the different hotels are located at different geographic locations; and

when one or more criteria associated with the policy are met, selectively providing an access acceptance message addressed to the computer, wherein the access acceptance message is intended for a second electronic device associated with the user and comprises information for establishing secure access of the second electronic device to the network.

20 . The method of claim 19 , wherein the policy comprises a time interval when the passphrase is valid, a physical location where the passphrase is valid, or the network that the user is allowed to access.

Assignments (9)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058843/0712 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA); COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 074591/0389 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058875/0449 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069743/0057 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
ABL SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058843/0712 →
TERM LOAN SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058875/0449 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2021
From: STEPHENSON, DAVID SHELDON; SIDI, RON; SHEU, MING-JYE
To: ARRIS ENTERPRISES LLC
Reel/Frame 057371/0555 →
Continuity (2)
Provisional Application 62899130 · Sep 11, 2019
Related Publication 20210075618A1 · Mar 11, 2021
References Cited (37)
US 6363154B1 · Peyravian · 2002 [cited by examiner]
US 8045961B2 · Ayed · 2011 [cited by examiner]
US 8756668B2 · Ranade · 2014 [cited by examiner]
US 9161219B2 · Bryksa et al. · 2015 [cited by applicant]
US 10230522B1 · Roths · 2019 [cited by examiner]
US 10299126B2 · Bryksa · 2019 [cited by examiner]
US 10554657B1 · Siddiqui · 2020 [cited by examiner]
US 10873858B2 · Olshansky · 2020 [cited by examiner]
US 11451959B2 · Windsor · 2022 [cited by examiner]
US 20050254651A1 · Porozni et al. · 2005 [cited by applicant]
US 20070094356A1 · Sethi · 2007 [cited by examiner]
US 20080028445A1 · Dubuc · 2008 [cited by examiner]
US 20080235772A1 · Janzen · 2008 [cited by applicant]
US 20100131756A1 · Schneider · 2010 [cited by examiner]
US 20100303231A1 · Gorissen et al. · 2010 [cited by applicant]
US 20130269008A1 · Sheu · 2013 [cited by examiner]
US 20140068739A1 · Taratine et al. · 2014 [cited by applicant]
US 20150257009A1 · Sheu et al. · 2015 [cited by applicant]
US 20160241550A1 · Burch et al. · 2016 [cited by applicant]
US 20180041360A1 · Shen · 2018 [cited by examiner]
US 20190182666A1 · Kotay · 2019 [cited by examiner]
US 20190190892A1 · Menachem · 2019 [cited by examiner]
US 20190303561A1 · Humble · 2019 [cited by examiner]
US 20190312726A1 · Sierra · 2019 [cited by examiner]
US 20200162517A1 · Wong · 2020 [cited by examiner]
US 20200228571A1 · Aharchaou · 2020 [cited by examiner]
US 20210021597A1 · Salman · 2021 [cited by examiner]
CN 107800539A · 2018 [cited by examiner]
Rigney C. et al. Remote Authentication Dial In User Service (RADIUS), RFC 2865; Network Working Group; Jun. 2000. (Year: 2000). [cited by examiner]
Saraf, et al., “Text and Image Encryption Decryption Using Advanced Enryption Standard.” In: International Journal of Emerging Trends in Technology in Computer Science (IJETTCS). Jun. 2014 (Jun. 2014). [cited by applicant]
International Search Report and the Written Opinion of the International Searching Authority corresponding to International Patent Application No. PCT/US2020/049836 (19 pages) (mailed Dec. 8, 2020). [cited by applicant]
“European Search Report for Corresponding Application No. 20863781.9, mailed Sep. 7, 2023, 15 pages”. [cited by applicant]
“External DPSK Radius Attribute Value Pairs”, URL:https://docs.commscope.com/bundle/unle ashed-200.12-onlinehelp/page/GUID-2392DF4B-DBE7-4DD5-868E-6222118BE6D4.html, 2020, 1-2. [cited by applicant]
“IEEE 802.11i-2004-Wikipedia”, URL:https://en.wikipedia.org/w/index.php?title=IEEE_802.lli-2004&oldid=912943898, 2019, 1-3. [cited by applicant]
“IEEE 802.1X—Wikipedia”, URL:https://en.wikipedia.org/w/index.php?title=IEEE_802.1X&oldid=745770193, 2016, 1-3. [cited by applicant]
“Using External DPSK with Radius Authentication”, URL:https://docs.commscope.com/bundle/zd-10.5.1-userguide/page/GUID-98007EBD-43CA-4C41-9F99-626A0295D75F.html, 2020, 1-2. [cited by applicant]
“Notification of Third Office Action and English language translation”, CN Application No. 202080076150.4, Dec. 24, 2025, 25 pp. [cited by applicant]