Methods and apparatus to improve security of a virtual private mobile network
US-9172678-B2 · Oct 27, 2015 · US
US9781006B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9781006-B2 |
| Application number | US-201514747930-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 23, 2015 |
| Priority date | Jun 24, 2014 |
| Publication date | Oct 3, 2017 |
| Grant date | Oct 3, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Methods and systems here may be used for managing a wireless network including associating a first and second wireless access device to an access point (AP), assigning the first and second wireless access device to respective first and second isolation groups, providing local communication via the AP within the isolation group, and prohibiting local communication via the AP between the first and second isolation groups.
Opening claim text (preview).
What is claimed is: 1. A method for managing a wireless network, comprising: via a controller in communication with a network and an access point (AP), receiving, from the AP, an indication that a wireless access device is requesting to associate to the AP; upon receiving the indication, associating the wireless access device to the AP; assigning the wireless access device to an isolation group; routing local communication through the AP locally, for any wireless access devices which are assigned to the same isolation group; and routing communication through the AP and then the network, for any wireless access devices which are not assigned to the same isolation group. 2. The method of claim 1 wherein the wireless access device is assigned to the isolation group using an access control list. 3. The method of claim 2 wherein the access control list uses at least one of a single service set identification (SSID) and a single virtual local area network (VLAN). 4. The method of claim 2 wherein the access control list uses at least one of a pre-shared key and a dynamic pre-shared key. 5. The method of claim 2 wherein the access control list uses media access control (MAC) information of the wireless access devices. 6. The method of claim 5 wherein the access control list uses MAC addresses of the wireless access devices. 7. The method of claim 2 wherein the access control list uses username and password credentials. 8. The method of claim 2 wherein the access control list uses third-party website credentials. 9. The method of claim 2 wherein the access control list is created at the controller and sent to the AP. 10. The method of claim 1 further comprising: assigning a different permission set of wireless network features of the AP to each isolation group. 11. A non-transitory computer-readable medium having computer-executable instructions thereon for a method for managing a wireless network, the method comprising: via at least one access point (AP) in communication with a network and two wireless access devices, aggregating the two wireless devices into an isolation group; assigning a specific permission set to the isolation group; wherein the at least one AP uses a single service set identification (SSID) and single virtual local area network (VLAN); and allowing direct, local communication between the two wireless devices in the same isolation group via the at least one AP locally; and routing communication through the network, among any wireless devices which are not assigned to the same isolation group. 12. The non-transitory computer-readable medium of claim 11 wherein the isolation group shares a dynamic pre-shared key. 13. The non-transitory computer-readable medium of claim 11 wherein the isolation group is identified in an identifier list stored in a lightweight directory access protocol server (LDAP). 14. The non-transitory computer-readable medium of claim 13 wherein the isolation group identifier includes a group name and password. 15. The non-transitory computer-readable medium of claim 11 further comprising an isolation group identifier that is a list of media access control (MAC) addresses. 16. The non-transitory computer-readable medium of claim 11 further comprising an isolation group identifier that is obtained via a third party website. 17. The non-transitory computer-readable medium of claim 16 wherein the third party website is a social network website. 18. The non-transitory computer-readable medium of claim 11 further comprising a controller in communication with the at least one access point. 19. The non-transitory computer-readable medium of claim 11 further comprising an authentication, authorization and accounting (AAA) server in communication with the network, wherein the isolation group is defined at the AAA server. 20. The non-transitory computer-readable medium of claim 11 further comprising a radius server, in communication with the network, wherein the isolation group is defined at the radius server. 21. The non-transitory computer-readable medium of claim 11 wherein the specific permission set determines accessibility to the network for the devices within the isolation group. 22. The non-transitory computer-readable medium of claim 11 wherein the specific permission set determines billing features of the isolation group. 23. The non-transitory computer-readable medium of claim 11 further comprising, via the at least one access point, aggregating a third and fourth wireless device in a second isolation group; assigning a different specific permission set to the second isolation group; allowing communication between the third and fourth wireless devices via the at least one AP. 24. The non-transitory computer-readable medium of claim 23 further comprising, routing through the network communication between wireless devices in different isolation groups. 25. A system for managing a wireless network, comprising: a controller in communication with a network and at least one access point (AP), the AP in communication with at least two wireless access devices, the controller configured to, aggregate the at least two wireless devices into an isolation group; assign a specific permission set to the isolation group; route local communication locally through the AP, among wireless access devices which are assigned to the same isolation group; and route communication through the network, among wireless access devices which are not assigned to the same isolation group, wherein the wireless network uses a single service set identification (SSID) and single virtual local area network (VLAN).
Assignment of logical groups to network elements · CPC title
Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title
Access point controller devices · CPC title
Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title
Virtual LANs, VLANs, e.g. virtual private networks [VPN] (LAN interconnection over a bridge based backbone H04L12/462; encapsulation techniques H04L12/4633; routing of packets H04L45/00; packet switches H04L49/00; virtual private networks for security H04L63/0272) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.