Network security systems and methods
US-2015237071-A1 · Aug 20, 2015 · US
US2017195318A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2017195318-A1 |
| Application number | US-201614987253-A |
| Country | US |
| Kind code | A1 |
| Filing date | Jan 4, 2016 |
| Priority date | Jan 4, 2016 |
| Publication date | Jul 6, 2017 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A system, apparatus, and method are described for a secure IoT wireless network configuration. For example, one embodiment of an Internet of Things (IoT) hub comprises: a local wireless communication interface to establish local wireless connections with one or more IoT devices and/or IoT extender hubs; a network router to establish network connections over the Internet on behalf of the IoT devices and/or IoT extender hubs; an authentication module pre-configured with a passphrase and a hidden service set identifier (SSID), the authentication module to receive a connection requests from the IoT devices and/or an IoT extender hubs and to grant the connection requests when the IoT devices and/or IoT extender hubs use the pre-configured passphrase and hidden SSID; and a firewall of the IoT hub to block all outgoing and incoming connection requests other than those directed to designated servers of an IoT service with known host names.
Opening claim text (preview).
What is claimed is: 1 . An Internet of Things (IoT) hub comprising: a first local wireless communication interface to establish first local wireless connections with one or more IoT devices and/or IoT extender hubs using a first local wireless communication protocol; a network router to establish network connections over the Internet on behalf of all or a subset of the IoT devices and/or IoT extender hubs; an authentication module to receive connection requests from the IoT devices and/or an IoT extender hubs and to grant the connection requests when the IoT devices and/or IoT extender hubs use proper authentication; and a firewall of the IoT hub to block all outgoing and incoming connection requests other than those directed to designated servers of an IoT service with known host names. 2 . The IoT hub as in claim 1 wherein the authentication module is further configured to deny connection requests other than those from IoT devices and/or IoT extender hubs having known medium access control (MAC) addresses. 3 . The IoT hub as in claim 1 wherein the first local wireless communication interface comprises a WiFi interface. 4 . The IoT hub as in claim 3 wherein the WiFi interface comprises an 802.11ac interface. 5 . The IoT hub as in claim 1 wherein the firewall is to be updated over the Internet to include new host names of designated servers of the IoT service. 6 . The IoT hub as in claim 1 further comprising: a second local wireless communication interface to establish second local wireless connections with one or more other IoT devices using a second local wireless communication protocol. 7 . The IoT hub as in claim 6 wherein the second local wireless communication interface comprises a Bluetooth Low Energy (BTLE) interface. 8 . The IoT hub as in claim 1 wherein the authentication module is pre-configured with a passphrase and a hidden service set identifier (SSID), the authentication module to grant the connection requests to those IoT devices and/or IoT extender hubs which use the pre-configured passphrase and hidden SSID. 9 . A method comprising: establishing first local wireless connections between an IoT hub and one or more IoT devices and/or IoT extender hubs using a first local wireless communication protocol; receiving connection requests from the IoT devices and/or an IoT extender hubs use proper authentication; granting the connection requests when the IoT devices and/or IoT extender hubs use the pre-configured passphrase and hidden SSID, and responsively connecting the IoT devices and/or IoT hubs to an IoT service; and blocking all outgoing and incoming connection requests, other than those directed to designated servers of the IoT service with known host names. 10 . The method as in claim 9 further comprising: blocking all local wireless connection requests other than those from IoT devices and/or IoT extender hubs having known medium access control (MAC) addresses. 11 . The method as in claim 10 wherein the first local wireless communication protocol comprises a WiFi protocol. 12 . The method as in claim 11 wherein the WiFi protocol comprises an 802.11ac protocol. 13 . The method as in claim 9 further comprising: updating the IoT hub over the Internet to include new host names of designated servers of the IoT service. 14 . The method as in claim 9 further comprising: establishing second local wireless connections with one or more other IoT devices using a second local wireless communication protocol. 15 . The method as in claim 14 wherein the second local wireless communication protocol comprises a Bluetooth Low Energy (BTLE) protocol. 16 . The method as in claim 9 wherein the authentication module is pre-configured with a passphrase and a hidden service set identifier (SSID), and wherein proper authentication comprises the IoT devices and/or IoT extender hubs using the pre-configured passphrase and hidden SSID. 17 . A system comprising: an IoT service; a plurality of IoT devices and/or IoT extender hubs to attempt to connect with the IoT service over the Internet; an Internet of Things (IoT) hub comprising: a first local wireless communication interface to establish first local wireless connections with one or more IoT devices and/or IoT extender hubs using a first local wireless communication protocol; a network router to establish network connections over the Internet on behalf of all or a subset of the IoT devices and/or IoT extender hubs; an authentication module to receive connection requests from the IoT devices and/or an IoT extender hubs and to grant the connection requests when the IoT devices and/or IoT extender hubs use proper authentication; and a firewall of the IoT hub to block all outgoing and incoming connection requests other than those directed to designated servers of an IoT service with known host names. 18 . The system as in claim 17 wherein the authentication module is further configured to deny connection requests other than those from IoT devices and/or IoT extender hubs having known medium access control (MAC) addresses. 19 . The system as in claim 17 wherein the first local wireless communication interface comprises a WiFi interface. 20 . The system as in claim 19 wherein the WiFi interface comprises an 802.11ac interface. 21 . The system as in claim 17 wherein the firewall is to be updated over the Internet to include new host names of designated servers of the IoT service. 22 . The system as in claim 17 further comprising: a second local wireless communication interface to establish second local wireless connections with one or more other IoT devices using a second local wireless communication protocol. 23 . The system as in claim 22 wherein the second local wireless communication interface comprises a Bluetooth Low Energy (BTLE) interface. 24 . The system as in claim 17 wherein the authentication module is pre-configured with a passphrase and a hidden service set identifier (SSID), the authentication module to grant the connection requests to those IoT devices and/or IoT extender hubs which use the pre-configured passphrase and hidden SSID.
Services for machine-to-machine communication [M2M] or machine type communication [MTC] · CPC title
in which an application is distributed across nodes in the network (software deployment G06F8/60; multiprogramming arrangements G06F9/46) · CPC title
Filtering by address, protocol, port number or service, e.g. IP-address or URL · CPC title
Authentication · CPC title
specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.