IP Library Granted Patent US 12,537,691
Granted Patent B2
US 12,537,691 · App. 17/986,041 · Granted Jan 27, 2026

Offloading authentication to an authenticator

Inventors: Yuzhou Chen (Shenzhen, CN); Zhineng Cui (San Ramon, CA); Caiyu Wang (Shenzhen, CN); Wenjun Ji (Shenzhen, CN); Tyan-Shu Jou (Fremont, CA)
Assignee: Ruckus IP Holdings LLC
H04L9/3242H04L63/0892
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,537,691
App. No.
17/986,041
Granted
Jan 27, 2026
Kind
B2
Abstract

An electronic device (such as an access point) that selectively performs authentication to a network is described. During operation, the electronic device provides an identity request addressed to the second electronic device. Then, the electronic device receives, associated with the second electronic device, an identity response. In response, when the authentication computer is unavailable, the electronic device accesses, in memory, a predefined hash function and associated authentication parameters for an authentication technique. Next, the electronic device performs authentication with the second electronic device based at least in part on the predefined hash function, where the authentication is compatible with the authentication technique (a type of Extensible Authentication Protocol or EAP). Moreover, the electronic device generates an encryption key, and establishes secure communication with the second electronic device by performing a four-way handshake with the second electronic device based at least in part on the encryption key.

Claims (58)

1 . A first electronic device, comprising:

one or more interface circuits configured to communicate with a second electronic device and an authentication computer;

a processor coupled to the interface circuit; and

memory, coupled to the processor, configured to store program instructions, wherein, when executed by the processor, the program instructions cause the first electronic device to perform operations comprising:

providing an identity request addressed to the second electronic device;

receiving, associated with the second electronic device, an identity response;

when the authentication computer is unavailable, accessing, in the memory, a predefined hash function and associated authentication parameters for an authentication technique, wherein the predefined hash function is configured to provide an output based at least in part on an input to the predefined hash function;

performing authentication to a network with the second electronic device based at least in part on the predefined hash function, wherein the authentication is compatible with the authentication technique;

generating an encryption key; and

establishing secure communication with the second electronic device by performing a four-way handshake with the second electronic device based at least in part on the encryption key, wherein the authentication parameters specify a time interval for the predefined hash function; and the operations comprise, after the time interval has elapsed, deleting the predefined hash function.

2 . The first electronic device of claim 1 , wherein the first electronic device comprises an access point.

3 . The first electronic device of claim 1 , wherein the authentication computer comprises a remote authentication dial-in user service (RADIUS) server or an authentication, authorization, and accounting (AAA) server.

4 . The first electronic device of claim 1 , wherein the second electronic device was previously authenticated by the authentication computer and then disconnected from the first electronic device.

5 . The first electronic device of claim 4 , wherein, after the authentication computer authenticated the second electronic device, the operations comprise:

receiving, associated with the authentication computer, the predefined hash function and the authentication parameters, wherein the predefined hash function and the authentication parameters are associated with the second electronic device; and

storing, in the memory, the predefined hash function and the authentication parameters.

6 . The first electronic device of claim 1 , wherein the authentication technique comprises a type of Extensible Authentication Protocol (EAP).

7 . The first electronic device of claim 1 , wherein the operations comprise, prior to providing the identity request, associating with the second electronic device.

8 . The first electronic device of claim 1 , wherein the encryption key comprises a pairwise master key (PMK).

9 . The first electronic device of claim 1 , wherein the authentication parameters specify a time interval for the predefined hash function; and

wherein the operations comprise:

providing, addressed to the authentication computer, a renewal request prior to the time interval elapsing;

receiving, associated with the authentication computer, a second predefined hash function and second authentication parameters; and

storing, in the memory, the second predefined hash function and the second authentication parameters.

10 . The first electronic device of claim 1 , wherein the four-way handshake comprises or is compatible with Extensible Authentication Protocol (EAP) over local area network (EAPol).

11 . The first electronic device of claim 1 , wherein the network comprises a virtual network associated with a location.

12 . The first electronic device of claim 11 , wherein the virtual network comprises: a virtual local area network (VLAN) or a virtual extensible local area network (VXLAN).

13 . A non-transitory computer-readable storage medium for use in conjunction with a first electronic device, the computer-readable storage medium storing program instructions that, when executed by the first electronic device, cause the first electronic device to perform operations comprising:

providing an identity request addressed to a second electronic device;

receiving, associated with the second electronic device, an identity response;

when an authentication computer is unavailable, accessing, in memory in the first electronic device, a predefined hash function and associated authentication parameters for an authentication technique, wherein the predefined hash function is configured to provide an output based at least in part on an input to the predefined hash function;

performing authentication to a network with the second electronic device based at least in part on the predefined hash function, wherein the authentication is compatible with the authentication technique;

generating an encryption key; and

establishing secure communication with the second electronic device by performing a four-way handshake with the second electronic device based at least in part on the encryption key, wherein the authentication parameters specify a time interval for the predefined hash function; and the operations comprise, after the time interval has elapsed, deleting the predefined hash function.

14 . The non-transitory computer-readable storage medium of claim 13 , wherein the first electronic device comprises an access point.

15 . The non-transitory computer-readable storage medium of claim 13 , wherein the second electronic device was previously authenticated by the authentication computer and then disconnected from the first electronic device; and

wherein the operations comprise, after the authentication computer authenticated the second electronic device:

receiving, associated with the authentication computer, the predefined hash function and the authentication parameters, wherein the predefined hash function and the authentication parameters are associated with the second electronic device; and

storing, in the memory, the predefined hash function and the authentication parameters.

16 . A method for selectively perform authentication to a network, comprising:

by a first electronic device:

providing an identity request addressed to a second electronic device;

receiving, associated with the second electronic device, an identity response;

based at least in part on unavailability of an authentication computer, accessing, in memory in the first electronic device, a predefined hash function and associated authentication parameters for an authentication technique, wherein the predefined hash function provides an output based at least in part on an input to the predefined hash function;

performing the authentication with the second electronic device based at least in part on the predefined hash function, wherein the authentication is compatible with the authentication technique;

generating an encryption key; and

establishing secure communication with the second electronic device by performing a four-way handshake with the second electronic device based at least in part on the encryption key, wherein the authentication parameters specify a time interval for the predefined hash function; and the operations comprise, after the time interval has elapsed, deleting the predefined hash function.

17 . The method of claim 16 , wherein the first electronic device comprises an access point.

18 . The method of claim 16 , wherein the second electronic device was previously authenticated by the authentication computer and then disconnected from the first electronic device; and

wherein the method comprises, after the authentication computer authenticated the second electronic device:

receiving, associated with the authentication computer, the predefined hash function and the authentication parameters, wherein the predefined hash function and the authentication parameters are associated with the second electronic device; and

storing, in the memory, the predefined hash function and the authentication parameters.

19 . The method of claim 18 , wherein the authentication parameters specify a time interval for the predefined hash function; and

wherein the method comprises:

providing, addressed to the authentication computer, a renewal request prior to the time interval elapsing;

receiving, associated with the authentication computer, a second predefined hash function and second authentication parameters; and

storing, in the memory, the second predefined hash function and the second authentication parameters.

20 . The method of claim 16 , wherein the second electronic device was previously authenticated by the authentication computer and then disconnected from the first electronic device.

Assignments (8)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067620/0675 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 074593/0001 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067620/0717 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 069743/0220 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2024
From: CHEN, YUZHOU; WANG, CAIYU; JI, WENJUN; CUI, ZHINENG; JOU, TYAN-SHU
To: ARRIS ENTERPRISES LLC
Reel/Frame 068448/0516 →
PATENT SECURITY AGREEMENT (TERM) Recorded Jun 4, 2024
From: RUCKUS IP HOLDINGS LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067620/0717 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jun 4, 2024
From: RUCKUS IP HOLDINGS LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067620/0675 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
Continuity (2)
Provisional Application 63280182 · Nov 17, 2021
Related Publication 20230155838A1 · May 18, 2023
References Cited (8)
US 10389708B1 · Goodsitt · 2019 [cited by examiner]
US 20040168054A1 · Halasz · 2004 [cited by examiner]
US 20200137056A1 · Havaralu Rama Chandra Adiga et al. · 2020 [cited by applicant]
US 20200358860A1 · Venkataraman et al. · 2020 [cited by applicant]
US 20210194860A1 · Lee · 2021 [cited by examiner]
WO 2017171835A1 · 2017 [cited by applicant]
“European Search Report in Corresponding Patent Application No. 22207913.9, mailed Apr. 19, 2023, 9 pages”. [cited by applicant]
“Public key certificate—wikipedia”, Retrieved from the Internet: URL:https://en.wikipedia.org/w/index.php?title=Public_key_certificate&oldid=10548334 68, 2021. [cited by applicant]