Dynamic network and security policy for iot devices
US-2018316563-A1 · Nov 1, 2018 · US
US11064354B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11064354-B2 |
| Application number | US-201815903120-A |
| Country | US |
| Kind code | B2 |
| Filing date | Feb 23, 2018 |
| Priority date | Feb 23, 2018 |
| Publication date | Jul 13, 2021 |
| Grant date | Jul 13, 2021 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
An apparatus and method provide personal networks to tenants on a multiple dwelling unit (MDU) network. Virtual Local Area Networks (VLANs) are assigned to a plurality of tenants to define a plurality of personal networks on the MDU network such that each of the personal networks is for a different tenant and is assigned a different VLAN. Onboarding requests are received from a plurality of client devices of a tenant for access to a personal network assigned to the tenant such that, when provisioned onto the personal network, intercommunication between the client devices of the tenant across the MDU network within the personal network is provided while access thereto by client devices of other tenants is blocked.
Opening claim text (preview).
We claim: 1. A method of providing personal networks to tenants on a multiple dwelling unit (MDU) network, the MDU network having a captive portal and a property identification (ID), the property ID is a relationship between a subscriber session controller (SSC) and a wireless access gateway (WAG) infrastructure, the WAG infrastructure including tunnel appliances, the SSC being provisioned using restful API, comprising the steps of: assigning Virtual Local Area Networks (VLANs) to a plurality of tenants to define a plurality of personal networks on the MDU network such that each of the personal networks is assigned to a different one of the tenants and each of the personal networks is assigned a different VLAN, wherein the VLANs are assigned to the plurality of tenants using dynamic VLAN assignment with Media Access Control (MAC) Authentication Bypass (MAB); receiving onboarding requests from a plurality of client devices on a first personal network of the plurality of personal networks, the first personal network assigned to a first tenant of the plurality of tenants; and processing the onboarding requests in a manner permitting intercommunication among the plurality of client devices, within the first personal network to which the first tenant and no other tenant of the plurality of tenants has access, to take place across the MDU network. 2. The method according to claim 1 , wherein the plurality of client devices includes at least one wireless client device. 3. The method according to claim 1 , wherein the plurality of client devices includes at least one client device wired to a switch. 4. The method according to claim 1 , wherein the plurality of client devices includes at least one wireless client device and at least one client device wired to a switch. 5. The method according to claim 1 , wherein the MDU network has one or more Service Set Identifiers (SSIDs) used by client devices of the plurality of tenants to access the MDU network. 6. The method according to claim 1 , wherein the MDU network has a common Service Set Identifier (SSID) which must be used by all client devices of all tenants to access the MDU network. 7. The method according to claim 1 , wherein an assigned VLAN is accessible to client devices of a corresponding tenant via any of a plurality of access points spread across a multiple dwelling unit (MDU) property. 8. The method according to claim 1 , further comprising the step of associating a unique VLAN assigned to a tenant with a Media Access Control (MAC) address of a client device of the tenant. 9. The method according to claim 8 , wherein said associating step includes associating the unique VLAN with a plurality of Media Access Control (MAC) addresses of a plurality of client device of the tenant. 10. The method according to claim 1 , further comprising the step of providing a tenant portal on which a tenant registers the MAC addresses of their client devices to enable access of an assigned VLAN to the tenant with the registered client devices of the tenant. 11. The method according to claim 10 , wherein the tenant portal provides client device usage statistics. 12. The method according to claim 1 , further comprising the step of providing a management portal for assisting tenant account creation and tenant on-boarding of client devices. 13. The method according to claim 12 , wherein the management portal provides network usage statistics. 14. An apparatus for providing personal networks to tenants on a multiple dwelling unit (MDU) network having a captive portal and a property identification (ID), the property ID is a relationship between a subscriber session controller (SSC) and a wireless access gateway (WAG) infrastructure, the WAG infrastructure including tunnel appliances, the MDU manager configured to provision the SSC using restful API, the MDU comprising an electronic MDU manager that assigns a unique Virtual Local Area Network (VLAN) using dynamic VLAN assignment with Media Access Control (MAC) Authentication Bypass (MAB) to each newly added tenant to thereby define a plurality of personal networks on the MDU network, such that client devices of each tenant are able to use the MDU network only to access the assigned unique VLAN of the tenant, in a manner permitting intercommunication among the client devices of the tenant across the MDU network within the personal network of the tenant. 15. Apparatus according to claim 14 , wherein the MDU manager is connected to infrastructure of the MDU network, and wherein the infrastructure includes a plurality of wireless access points and a plurality of switches spread across a multiple dwelling unit (MDU) property such that a personal network of a tenant is accessible to the client devices of the tenant via any of the plurality of access points and switches. 16. Apparatus according to claim 14 , wherein the MDU manager is configured to provide a tenant portal permitting a tenant to register a MAC address of a client device to a VLAN assigned to the tenant and a management portal for assisting tenant account creation and tenant on-boarding of client devices, and wherein the MDU manager is configured to provide client device and network usage tracking. 17. Apparatus according to claim 14 , wherein said client devices include at least one electronic device selected from the group consisting of a computer, laptop computer, tablet computer, smartphone, gaming device, customer premises equipment, gateway, set top box, television, a wireless client device, and a client device wired to a switch. 18. A non-transitory computer-readable storage medium comprising stored instructions which, when executed by one or more computer processors, cause the one or more computer processors to perform steps of: assigning Virtual Local Area Networks (VLANs) to a plurality of tenants on a multiple dwelling unit (MDU) network to define a plurality of personal networks on the MDU network such that each of the personal networks is assigned to a different one of the tenants and each of the personal networks is assigned a different VLAN, wherein the VLANs are assigned to the plurality of tenants using dynamic VLAN assignment with Media Access Control (MAC) Authentication Bypass (MAB), the MDU network having a captive portal and a property identification (ID), the property ID is a relationship between a subscriber session controller (SSC) and a wireless access gateway (WAG) infrastructure, the WAG infrastructure including tunnel appliances, the SSC being provisioned using restful API; receiving onboarding requests from a plurality of client devices for a first personal network of the plurality of personal networks, the first personal network assigned to a first tenant of the plurality of tenants; and processing the onboarding requests in a manner permitting intercommunication among the plurality of client devices, within the first personal network to which the first tenant and no other tenant if the plurality of tenants has access, to take place across the MDU network.
Directories for service discovery · CPC title
by using authentication-authorization-accounting [AAA] servers or protocols · CPC title
Automatic deployment of services triggered by the service manager, e.g. service implementation by automatic configuration of network components · CPC title
Virtual LANs, VLANs, e.g. virtual private networks [VPN] (LAN interconnection over a bridge based backbone H04L12/462; encapsulation techniques H04L12/4633; routing of packets H04L45/00; packet switches H04L49/00; virtual private networks for security H04L63/0272) · CPC title
Virtual private networks · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.