IP Library Granted Patent US 12,368,704
Granted Patent B2
US 12,368,704 · App. 18/133,555 · Granted Jul 22, 2025

Certificate-based connections reflecting a network architecture

Inventor: Huang-Ju Hsieh (Taichung, TW)
Assignee: Ruckus IP Hollings LLC
H04L63/0823H04L41/044H04L41/28
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,704
App. No.
18/133,555
Granted
Jul 22, 2025
Kind
B2
Abstract

A computer network device that implements a data plane is described. During operation, the computer network device may receive, associated with a second computer network device, a request to establish a connection, where the request includes an instance of a first type of certificate associated with a first certificate authority for a first layer in a hierarchy in the network, and/or an instance of a second type of certificate associated with a second certificate authority for a second layer in the hierarchy, where the first layer is lower in the hierarchy than the second layer. Then, the computer network device may selectively establish a connection in the network with the second computer network device based at least in part on the instance of the first type of certificate and/or the instance of the second type of certificate.

Claims (37)

1. A computer network device, comprising:

an interface circuit configured to communicate with a second computer network device in a network;

a processor coupled to the interface circuit; and

memory, coupled to the processor, storing program instructions, wherein, when executed by the processor, the program instructions cause the computer network device to perform operations comprising:

receiving, associated with the second computer network device, a request to establish a connection, wherein the request comprises an instance of a first type of certificate associated with a first certificate authority for a first layer in a hierarchy in the network, an instance of a second type of certificate associated with a second certificate authority for a second layer in the hierarchy, or both, wherein the first layer is lower in the hierarchy than the second layer, wherein the first layer is associated with a tenant and the second layer is associated with a managed service provider (MSP) of the network, and wherein the tenant is a customer of the MSP;

selectively establishing a connection in the network with the second computer network device based at least in part on the instance of the first type of certificate, the instance of the second type of certificate, or both; and

based at least in part on the instance of the first type of certificate, the instance of the second type of certificate, or both, excluding the connection with the second computer network device when the second computer network device is associated with a different tenant of the MSP, a different MSP or both.

2. The computer network device of claim 1 , wherein the computer network device is configured to implement a data plane.

3. The computer network device of claim 1 , wherein the second computer network device comprises: an access point, or implements a data plane.

4. The computer network device of claim 1 , wherein, when the second computer network device is in the first layer, the second computer network device comprises an access point.

5. The computer network device of claim 1 , wherein, when the second computer network device is in the second layer, the second computer network device implements a data plane.

6. The computer network device of claim 1 , wherein the second computer network device is associated with a different manufacturer or provider than a manufacturer or a provider of the computer network device.

7. The computer network device of claim 1 , wherein the instance of the first type of certificate is associated with a first computer system and the instance of the second type of certificate is associated with a second computer system; and

wherein the second computer system is different from the first computer system.

8. The computer network device of claim 7 , wherein the first computer system, the second computer system or both comprise a controller of the computer network device and the second computer network device.

9. The computer network device of claim 1 , wherein the instance of the first type of certificate is signed by the first certificate authority, and the instance of the second type of certificate is signed by the second certificate authority.

10. A non-transitory computer-readable storage medium for use in conjunction with a computer network device, the computer-readable storage medium storing program instructions that, when executed by the computer network device, cause the computer network device to perform operations comprising:

receiving, associated with a second computer network device, a request to establish a connection, wherein the request comprises an instance of a first type of certificate associated with a first certificate authority for a first layer in a hierarchy in a network, an instance of a second type of certificate associated with a second certificate authority for a second layer in the hierarchy, or both, wherein the first layer is lower in the hierarchy than the second layer, wherein the first layer is associated with a tenant and the second layer is associated with a managed service provider (MSP) of the network, and wherein the tenant is a customer of the MSP;

selectively establishing a connection in the network with the second computer network device based at least in part the instance of the first type of certificate, the instance of the second type of certificate, or both; and

based at least in part on the instance of the first type of certificate, the instance of the second type of certificate, or both, excluding the connection with the second computer network device when the second computer network device is associated with a different tenant of the MSP, a different MSP or both.

11. The non-transitory computer-readable storage medium of claim 10 , wherein the computer network device implements a data plane.

12. The non-transitory computer-readable storage medium of claim 10 , wherein the instance of the first type of certificate is associated with a first computer system and the instance of the second type of certificate is associated with a second computer system; and

wherein the second computer system is different from the first computer system.

13. The non-transitory computer-readable storage medium of claim 10 , wherein, when the second computer network device is in the first layer, the second computer network device comprises an access point.

14. A method for selectively establishing a connection in a network, comprising:

by a computer network device:

receiving, associated with a second computer network device, a request to establish a connection, wherein the request comprises an instance of a first type of certificate associated with a first certificate authority for a first layer in a hierarchy in the network, an instance of a second type of certificate associated with a second certificate authority for a second layer in the hierarchy, or both, wherein the first layer is lower in the hierarchy than the second layer, wherein the first layer is associated with a tenant and the second layer is associated with a managed service provider (MSP) of the network, and wherein the tenant is a customer of the MSP;

selectively establishing the connection in the network with the second computer network device based at least in part the instance of the first type of certificate, the instance of the second type of certificate, or both; and

based at least in part on the instance of the first type of certificate, the instance of the second type of certificate, or both, excluding the connection with the second computer network device when the second computer network device is associated with a different tenant of the MSP, a different MSP or both.

15. The method of claim 14 , wherein the computer network device implements a data plane.

16. The method of claim 14 , wherein the instance of the first type of certificate is associated with a first computer system and the instance of the second type of certificate is associated with a second computer system; and

wherein the second computer system is different from the first computer system.

17. The method of claim 14 , wherein, when the second computer network device is in the first layer, the second computer network device comprises an access point.

18. The method of claim 14 , wherein the instance of the first type of certificate is signed by the first certificate authority, and the instance of the second type of certificate is signed by the second certificate authority.

19. The method of claim 14 , wherein the second computer network device is associated with a different manufacturer or provider than a manufacturer or a provider of the computer network device.

20. The method of claim 14 , wherein the instance of the first type of certificate is associated with a first computer system and the instance of the second type of certificate is associated with a second computer system; and

wherein the second computer system is different from the first computer system.

Assignments (8)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067252/0657 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA)
Reel/Frame 074593/0348 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067259/0697 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069790/0575 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
PATENT SECURITY AGREEMENT (TERM) Recorded Apr 29, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067259/0697 →
PATENT SECURITY AGREEMENT (ABL) Recorded Apr 29, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067252/0657 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2023
From: HSIEH, HUANG-JU
To: ARRIS ENTERPRISES LLC
Reel/Frame 063295/0873 →
Continuity (2)
Provisional Application 63330329 · Apr 13, 2022
Related Publication 20230336540A1 · Oct 19, 2023
References Cited (14)
US 7600113B2 · Kuehnel · 2009 [cited by examiner]
US 10700791B2 · Al-Mousa · 2020 [cited by examiner]
US 10841102B2 · Nitschke · 2020 [cited by examiner]
US 11265714B2 · Wan · 2022 [cited by examiner]
US 20020103909A1 · Devine · 2002 [cited by examiner]
US 20040250062A1 · Douglas · 2004 [cited by examiner]
US 20040268152A1 · Xia · 2004 [cited by examiner]
US 20060047951A1 · Reilly · 2006 [cited by examiner]
US 20080162928A1 · Qiu · 2008 [cited by examiner]
US 20080307221A1 · Horita · 2008 [cited by examiner]
US 20090125721A1 · Numaoka · 2009 [cited by examiner]
US 20160337127A1 · Schultz · 2016 [cited by examiner]
US 20220393891A1 · Mackcay · 2022 [cited by examiner]
US 20230127516A1 · Tartan · 2023 [cited by examiner]