Systems and Methods for Providing Automated Access to Resources of Computer Systems
US-2024430261-A1 · Dec 26, 2024 · US
US10104083B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10104083-B2 |
| Application number | US-201514808193-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jul 24, 2015 |
| Priority date | Jul 24, 2014 |
| Publication date | Oct 16, 2018 |
| Grant date | Oct 16, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems and methods for securing a network, for admitting new nodes into an existing network, and/or securely forming a new network. As a non-limiting example, an existing node may be triggered by a user, in response to which the existing node communicates with a network controller node. Thereafter, if a new node attempts to enter the network, and also for example has been triggered by a user, the network controller may determine, based at least in part on parameters within the new node and the network controller, whether the new node can enter the network.
Opening claim text (preview).
The invention claimed is: 1. A network comprising: a first node; and a second node, wherein: the first node comprises a user-actuated trigger and at least one circuit operable to, at least: receive a trigger indication that a user has actuated the user-actuated trigger; in response to the received trigger indication, send a first message comprising an information element indicating that the first node has been triggered by a user; and the second node comprises at least one circuit operable to, at least: receive the first message; in response to the received first message, set a local state variable to indicate that the protected set-up session is in progress; while the protected set-up session is in progress, receive a second message from a third node that is not a member of the network, the second message comprising an information element indicating a plurality of protected set-up parameters, different from encryption information, of the third node; and determine, based at least in part on protected set-up parameters of the second node and on the protected set-up parameters of the third node, whether to share security information with the third node; and if it is determined, based at least in part on protected set-up parameters of the second node and on the protected set-up parameters of the third node, to share security information with the third node, then share security information with the third node, wherein the protected set-up parameters of each node of the second node and the third node comprise: a first parameter that indicates whether said each node is allowed to receive a network password from another node; a second parameter that indicates whether privacy is enabled at said each node; and a third parameter that indicates whether said each node is allowed to accept a privacy downgrade. 2. The network of claim 1 , wherein each of the first, second, and third parameters is a single-bit parameter. 3. The network of claim 1 , wherein the first message is a reservation request message, and the second message is a discovery request message communicated prior to the communication of encryption information from the third node. 4. A network node, the node comprising: at least one circuit operable to, at least: receive a first message from a first other node that is a member of a network, the first message comprising an information element indicating that the first other node has been triggered by a user; in response to the received first message set a local state variable to indicate that the protected set-up session is in progress; while the protected set-up session is in progress, receive a second message from a second other node that is not a member of the network, the second message comprising an information element indicating a plurality of protected set-up parameters, different from encryption information, of the second other node; and determine, based at least in part on protected set-up parameters of the node and on the protected set-up parameters of the second other node, whether to share security information with the second other node; and if it is determined, based at least in part on protected set-up parameters of the node and on the protected set-up parameters of the second other node, to share security information with the second other node, then share security information with the second other node, wherein the protected set-up parameters of each node of the node and the second other node comprise: a first parameter indicating whether said each node is allowed to receive a network password from another node; a second parameter indicating whether privacy is enabled at said each node; and a third parameter indicating whether said each node is allowed to accept a privacy downgrade. 5. The node of claim 4 , wherein the at least one circuit is operable to, in response to the received second message and prior to encryption key information being exchanged between the second other node and the node, transmit a third message to the second other node comprising information indicating that a protected set-up session is in progress. 6. The node of claim 4 , wherein the first message is a reservation request message. 7. The node of claim 6 , wherein the second message is a discovery request message. 8. The node of claim 4 , wherein the first message is a reservation request message, the second message is a discovery request message, and the third message is a discovery response message, wherein the first, second, and third messages are communicated prior to the node sending encrypted information to the second other node. 9. The node of claim 4 , wherein the at least one circuit is operable to, in response to the received first message: set a timer; and if the timer expires before the second message is received, then cancel the protected set-up session. 10. The node of claim 4 , wherein the at least one circuit is operable to, in response to the received first message, determine whether a protected set-up session is already in progress. 11. The node of claim 10 , wherein the at least one circuit is operable to, if it is determined that a protected set-up session is already in progress, then: determine if the first other node initiated the protected set-up session that is already in progress; and if it is determined that the first other node initiated the protected set-up session that is already in progress, then ignore the received first message. 12. The node of claim 11 , wherein the at least one circuit is operable to, if it is determined that a protected set-up session is already in progress, then: if it is determined that the first other node did not initiate the protected set-up session that is already in progress, then cancel the protected set-up session that is already in progress. 13. The node of claim 4 , wherein the first parameter is a one-bit parameter. 14. The node of claim 4 , wherein the second parameter is a one-bit parameter. 15. The node of claim 4 , wherein the third parameter is a one-bit parameter. 16. The node of claim 4 , wherein the at least one circuit is operable to, if it is determined to share security information with the second other node, then determine whether to send password information to the second other node or whether to receive password information from the second other node.
Configuration setting · CPC title
Restricting access to network management systems or functions, e.g. using authorisation function to access network configuration · CPC title
for controlling access to devices or network resources · CPC title
using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.