Zone migration in network access.
Abstract
The present disclosure is directed to providing a network user the ability to travel between different zones or locations within a network environment, such as, for example, a hospitality location, without requiring a user to re-login to the new location, while requiring a user to re-login to other locations within the network environment.

Term
3.8 yearsleft in the term
Expires 2 July 2030.
- Priority
- Filed
- Today
- Expires
21 claims: 4 independent, 17 dependent
- 1REIVINDICACIONES 1. Un método para determinar si se le permite a un usuario de red, que se comunica con una primera posición de acceso dentro de una red de computadora controlada en privado que incluye posiciones de acceso múltiples, ser capaz de migrar de una posición de acceso a otra posición de acceso sin una re-autenticación, el método comprende:proporcionar una pluralidad de posiciones de acceso a red configuradas para proporcionar uno o más accesos del dispositivo de usiario a una red de computadora controlada en privado;definir permisos de migración para migrar entre posiciones individuales de acceso a red en la pluralidad de posiciones de acceso a red, donde los permisos de migración establecen derechos de migración entre posiciones individuales de acceso a red en la pluralidad de posiciones de acceso a red sin requerir que un usuario se vuelva a dar de alta en el sistema;permitirle a un dispositivo de usuario poder migrar de la comunicación con una primera posición de acceso a red en la pluralidad de posiciones de acceso a red, a una segunda posición de acceso a red entre la pluralidad de posiciones de acceso a red sin requerir que el usuario se vuelva a dar de alta en el sistema;y requerirle al usuario volverse a dar de alta en el sistema al migrar desde la primera posición de acceso a red a una tercera posición de acceso a red.
- 2El método según la reivindicación 1, donde la posición de acceso a red es un puerto.
- 3El método según la reivindicación 2, donde el puerto es un puerto VLAN.
- 4El método según la reivindicación 1, donde las primeras y segundas posiciones de acceso a red son comprendidas en una primera zona de la posición de acceso a red y la tercera posición de acceso a red es comprendida en una segunda zona de posiciones de acceso a red.
- 5El método según la reivindicación 4, donde la primera zona comprende posiciones de acceso a red ubicadas en una primera área física y la segunda zona comprende posiciones de acceso a red ubicadas en una segunda área física.
- 6El método según la reivindicación 4, que adicionalmente comprende la asignación de un primer SSID a la primera zona y un segundo SSID a la segunda zona.
- 7El método según la reivindicación 1, que adicionalmente comprende la asignación de un primer SSID a las primeras y segundas posiciones de acceso a red y un segundo SSID a la tercera posición de acceso.
- 8Un sistema para proporcionar un acceso a red de computadora en una red segura de computadora que incluye una pluralidad de puntos de acceso a red de computadora, el sistema comprende:uno o más dispositivos de administración dé red configurados para proporcionar servicios de comunicaciones en red para uno o más dispositivos compatibles con la red;y una pluralidad de puntos de acceso a red configurados para proporcionar portales de comunicaciones para facilitar comunicaciones entre uno o más dispositivos de administración de red y uno o más dispositivos compatibles con la red, uno o más los puntos de acceso a la red son controlables por uno o más dispositivos de administración de red para permitir o negar comunicaciones mediante un segundo punto de acceso a red de la pluralidad de puntos de acceso a red basados en una autorización para poder usar un primer punto de acceso a red de la pluralidad de puntos de acceso a red.
- 9El sistema según la reivindicación 6, donde los puntos de acceso a red son organizados en una pluralidad de zonas, donde cada zona incluye al menos un punto de acceso a red.
- 10El sistema según la reivindicación 9, donde al menos un SSID es asignado con al menos una zona en la pluralidad de zonas.
- 11El sistema según la reivindicación 10, donde los al menos dos SSID son asignados a la al menos una zona entre la pluralidad de zonas.
- 12El sistema según la reivindicación 7, donde uno o más de los dispositivos de administración de red permiten comunicaciones mediante el segundo punto de acceso a red si el primér punto de acceso está en la misma zona y niega comunicaciones mediante el segundo punto de acceso a red si el segundo punto de acceso a red está en una zona diferente.
- 13El sistema según la reivindicación 7, donde uno o más de los dispositivos de administración de red definen la zona del primer punto de acceso a red como una zona habitacional y permiten comunicaciones con otros puntos de acceso en la pluralidad de puntos de acceso correspondiente a una segunda zona, si la zona habitacional se define para permitir el acceso a los segundos puntos de acceso zonal.
- 14El método según la reivindicación 6, donde el punto de acceso a red es un puerto.
- 15Un método de proporcionarle a un usuario la capacidad de moverse entre diferentes posiciones del acceso a red sin requerir una re-autenticación, que comprende:requerir una nueva autorización para obtener acceso a la segunda posición de acceso a red, donde la primera posición de acceso a red y la segunda posición de acceso a red son parte de una primera zona en una o más zonas;y requerir una re-autenticación de usuario cuando éste se mueve de las primeras o segundas posiciones de acceso a red, a una tercera posición de acceso, donde la tercera posición comprende la asignación de una o más posiciones de dirección de red a una zona.
- 1619. El método según la reivindicación 11, donde la reautenticación comprende usar una pantalla de inicio de sesión.
- 1720. Un sistema que proporciona derechos de acceso a una red segura de computadora basada en una posición física de un usuario, el sistema comprende:una interconexión de red configurada para comunicarse con uno o más dispositivos de usuario habilitados a la red y comunicarse con otros dispositivos de red, la interconexión de red se configura para proporcionar comunicaciones entre uno o más dispositivos de usuario habilitados a red y otros dispositivos de red;una base de datos configurada con derechos de acceso a red dependientes de la ubicación;y un procesador en comunicación con la interconexión de redes y la base de datos, el procesador se configura para permitir o negar comunicaciones de red a través de la interconexión de red basada en una primera autorización dependiente de la ubicación para unos dispositivos de usuario habilitados a red en una primera posición para comunicarse a través de la interconexión de red, el procesador es configurado adicionalmente para permitir comunicaciones para el dispositivo de usuario habilitado a red en una segunda posición sin la nueva autorización y requerir una nueva autorización para el dispositivo de usuario habilitado a red en una tercera posición.
- 1821. El sistema según la reivindicación 16, donde la posición del dispositivo de usuario habilitado a red se determina con base en un puerto con acceso mediante el dispositivo de usuario habilitado a red.
- 1922. El sistema según la reivindicación 17, donde el derecho de acceso a red dependiente de la ubicación se configura para proporcionar acceso sin una nueva autorización entre puertos que sean parte de una primera zona, la primera zona incluye uno o más puertos, y a requiere de nueva autorización cuando el dispositivo de usuario habilitado a red emigra a un puerto en una segunda zona, la segunda zona incluye uno o más puertos.
- 2023. El sistema según la reivindicación 16, donde la autorización comprende uno o más de un inicio de sesión, pago de cuotas, una solicitud de acceso, o ingreso de un código. primer SSID es asignado a las primeras y segundas posiciones y un segundo SSID es asignado a la tercera posición.
- 2128. El sistema según la reivindicación 27, donde un tercer SSID es asignado a las primeras, segundas y terceras posiciones, y donde a un segundo dispositivo de usuario habilitado a red y configurado para obtener acceso a un tercer SSID, se le permite acceso a las primeras, segundas y terceras posiciones sin una nueva autorización.
Independent claims21
73 paragraphs in 1 section, as filed
(54) Title: ZONAL MIGRATION IN A NETWORK ACCESS. (54) Title: ZONE MIGRATION IN NETWORK ACCESS.
(57) Summary
This disclosure is intended to provide a network user with the ability to navigate between different zones or locations within a network environment, such as, for example, a hospitality location, without requiring a user to re-register. on the system at the new location, while requiring the user to re-register on the system at other locations within the network environment.
(57) Abstract
The present disclosure is directed to providing a network user the ability to travel between different zones or locations within a network environment, such as, for example, a hospitality location, without requiring a user to re-login to the new location, while requiring a user to re-login to other locations within the network environment.
ZONAL MIGRATION IN A NETWORK ACCESS
Field of the Invention.
The present description relates to the field of providing access to computer networks.
Background of the Invention
The use of a laptop, cell phone, personal digital assistant, and other mobile computing devices has become very common. Travelers, and particularly business travelers, expect and often require network access, such as Internet access, as they go from one place to the next. Similarly, students in schools and doctors in hospitals require access throughout their respective university campuses or medical buildings. ' Even in an individual venue, such as a hotel or conference center, travelers and guests want access to networks in various locations throughout the venue including guest rooms, restaurants, meeting rooms, lobby, business centers, etc. .
Brief Description of the Invention The present description is concerned with providing a system for controlling network access at different physical locations on a network. In one embodiment, the description describes a system for controlling access to a network for a user moving between different physical positions on the network. For example, in one embodiment, when a user moves between different rooms to a particular location, the system implements rules that establish when the user will be automatically authenticated to the new location, or if a new authentication is required.
In one embodiment, network access is controlled by implementing different authentication regulations for different network access points. A network access point is any point connected or wireless connection point to a network. In one mode, a network access point is a connected or wireless port. Ports can include, for example, 802.1Q VLAN IDs or the like, TCP ports or the like, UDP ports or the like, and any other software for defined communication endpoints. In one embodiment, a network access point is a physical connection to the network, such as a connector to
Ethernet, a phone jack, a wireless router, or the like. An access point may also include any form of position identification, such as, for example, triangulating a wireless signal, using a Global Positioning System (GPS), or any other system to determine the position of a network user.
In one mode, the access points are grouped into zones. In a modality, a zone includes one or more access points. In one embodiment, a network includes at least a plurality of zones. In one mode, a network administrator can configure access regulations to allow a user to move between access points within a zone and / or between zones. In one embodiment, for example, a user is allowed to move from one access point to another access point within a zone without having to authenticate again. However, · a user may be required to authenticate again when moving between access points associated with different zones. This can be useful, for example, when a user is required to pay different amounts to gain access to the network through access points in different zones or where different zones associate different levels of security with them. As used in this specification, authentication may include, for example, a login, 'including a username and / or password, paying a fee, registering a computer, writing an access code, or any other positive discrimination obtained by a user of a user device to obtain permission to use a network.
For purposes of summarizing the description, certain aspects, advantages and novel aspects of the inventions have been described here. It is to be understood that not all of the advantages can be achieved according to any particular embodiment of the inventions described herein. Thus, the inventions described here can be represented or carried out in a way that achieves or optimizes an advantage or group of advantages shown here without necessarily achieving other advantages as may be shown or suggested here.
Brief Description of the Figures
Figures are provided to illustrate modalities of
<td>the</td><td>inventions</td><td>described</td><td>here</td><td>and not</td><td>limit</td><td>the scope of</td><td>the</td>
<td colspan="2">same.</td><td></td><td></td><td></td><td></td><td></td><td></td>
<td></td><td>THE FIGURE</td><td>1 illustrates</td><td colspan="3">schematically</td><td>a modality</td><td>of</td>
<td>a</td><td>net.</td><td></td><td></td><td></td><td></td><td></td><td></td>
<td></td><td>THE FIGURE</td><td>2 illustrates</td><td>a</td><td>cut</td><td colspan="3">cross section of various</td>
access points in a hospitality setting.
FIGURE 3 schematically illustrates access points and network connections of various users in a conference configuration.
FIGURE 4 illustrates a manager installer screen for defining a plurality of access zones.
FIGURE 5 illustrates a flowchart of a decision tree for determining when a login is required to obtain network access in one mode.
FIGURE 6 illustrates a flowchart showing when a login is required when moving between different zones in one mode.
FIGURE 7 illustrates a timeline of two examples of users moving between different positions in a network.
Detailed description of the invention
Figure 1 schematically illustrates one embodiment of a network access system. The system includes various user devices 141, 143, 145, 147, 149, 151, 153, 155. User devices may include, such as, for example, laptops, desktops, cell phones, personal digital assistants, and any other communication device enabled and connected to the wireless network. User devices 141, 143, 145, 147, 149, 151, 153, 155 communicate with access points 121, 123, 125, 127, 129. Access points 121, 123, 125, 127, 129 provide connection or wireless communications with network management device (s) 103. Network management device (s) 103, controls network communication broker access points and between network and access points 101. In one embodiment, the network management device (s) is operated by an individual entity. In one mode, the network management device (s) creates an individual network. Optionally, intermediate network devices 105 can also be used, including, for example, routers, switches, hubs, repeaters, etc. to assist in communications they provide between access points 121, 123, 125, 127 and network management device (s) 103. Network 101 can be, for example, a public network, such as the Internet. Network management device (s) 103 may include network gateways, such as, for example, commercially available network gateways from Nomadix, Inc. of Newbury Park, Almost As will be understood by those skilled in the art of In the present description, other network management devices can also be used. As illustrated in Figure 1, the network includes three different physical areas including lobby 107, conference center 109, and guest room 111. Each physical area includes one or more access points.
Network management device (s) 103 provides the ability to group access points together for purposes of allowing a user device to move between certain access points without requiring re-authentication by requiring re-authentication when in movement to other access points. The grouping of access points can be done, for example, along physical boundaries such as, for example, a wall. This can be done, for example, by assigning certain access points to a defined zone. In a modality, a zone is a room, a group of rooms, a building, a group of buildings, or the like. For example, lobby 107 may be a first zone, conference center 109 may be a second zone, and guest room 111 may be a third zone. In a simple example, a user device will be able to move between access points within a zone without having to authenticate again, but will be required to authenticate again when moving between access points located in different zones. Authentication may include, for example, a login, the payment of fees, a request for access, the entry of a code, or any other action required by the user to request access to the network. In another example, a user device, once authenticated to lobby area 107 may be allowed to access conference center area 109 without re-authentication, but may be required to authenticate again when moving to the guest room area. 111.
In one mode, the access points announce their presence by transmitting a Set Identifier of
Service (SSID), Extended Service Set Identifier (ESSID), and / or Basic Service Set Identifier (BSSID), or the like, collectively referred to herein as SSID. In one mode, the same SSID is assigned to all access points and zones on a network. In one mode, a different SSID is assigned to each zone or to a group of zones. In one modality, multiple SSID's can be assigned to the same zone or the same set of access points. The virtual SSID'S in this respect can be configured corresponding to different groupings of zones or access points. For example, in the same hotel or conference center, two different conferences occurring simultaneously may have the SSID'S tailored for grated access to each group. 2009 Conference A2 for example may have custom SSID Conference titled A2 2009 that allows access to access points in the Lobby, Guest Rooms and Meeting Rooms without re-authentication, but not in the Business Center. A second conference, Conference B1 2009, may also have SSID to
<td>measure</td><td>Lecture titled</td><td>B1</td><td>2009 that</td><td>It allows</td><td>the</td>
<td>access that</td><td>to the Lobby, Rooms</td><td>of</td><td>meetings,</td><td>Cuartps</td><td>of</td>
<td>guests and</td><td>the Business Center</td><td>without</td><td colspan="2">re-authentication.</td><td>Of</td>
Similarly, network providers can also have different levels of SSIDs allowing access to different groups of access points where multiple SSIDs correspond to the same access point or zone. Different SSIDs can correspond to different payment levels. For example, inexpensive SSID access can only grant access to the Lobby, while more expensive SSID can grant access to the Business Center or Meeting Rooms.
In one mode, an amount of bandwidth, or maximum bandwidth, can be assigned to different access points, access point groups, zones, zone groups, or custom SSIDs.
The following is a non-limiting example of Zonal Migration. Used as in this example, a zone is a group of VLAN IDs. When clients connect to the network, for example, in a hotel, they are authenticated in one of four zones:
Lobby / Restaurant / Common area: 100-150
Connected Guest: 201-700
Wireless Guest: 801-1500
Meeting room A: 1601-1700
Zonal migration provides the ability for the network to group the VLANS together, meaning that 1Ú0-150 would be grouped together, so the user could go from access point 101 in the lobby to access point 125 in the restaurant without being required to authenticate from new. A user would then be required to authenticate again when moving between Lobby and Meeting Room A.
Figure 2 illustrates a cross section of various access points in a hospitality configuration. Hotel 201 includes guest rooms 203, conference room 205, restaurant 207 and lobby 209. Guest rooms 203, conference room 205, restaurant 207 and lobby 209 include various access points 221. Although illustrated as having one or more access points in each room, it must be understood that fewer or more access points can be used. For example, in one embodiment, an individual access point can be used for multiple guest rooms. Access points can be configured in various zones. Zones can be defined along quarter lines or in any other configuration. For example, access points 221 in guest rooms 203 area may all be an individual zone. Alternatively, access points 221 on an individual floor or through less than all floors can also be configured in a zone. As will be understood by a person skilled in the art, the zones can be defined along any desired physical position, incorporating the access points to those physical zones. As will also be understood by those skilled in the art, many different types of installations will benefit from the present disclosure. For example, although described primarily with respect to hotels, other facilities may use the present access point zone system for schools including, colleges, universities, hospitals, government buildings, businesses, or any other public or public network system. private. Also, the zones are not restricted to a particular building, but may include multiple buildings.
Figure 3 schematically illustrates access points and network connections of various users in a conference configuration. As illustrated, various user devices connect to, attempting to connect to, or move between connections to various access points. For example, user device 351 communicates wirelessly with access point 321. User device 352 attempts to gain access to the network through access points 321, 323, 325, but has not yet been authenticated and thus is unable to send or receive communications over the network.
Devices are generally programmed to automatically select between access points, for example by determining which access point provides the most concentrated signal. User device 356 is intermediate three different access points and is capable of communicating with all of them, but will eventually select an access point to communicate with. In some cases, an access point will not allow a device to communicate through it, in which case the user device will try to communicate with the other the access point. For example, user device 357 may have the most concentrated signal with access point 325, but can only be authenticated with access point 337. In this case, user devices will communicate with access point 337. Of course, as will be understood, user devices can be configured to select access points based on any number of different selection options, including, for example, signal strength, bandwidth availability, access rights, access points corresponding access to particular SSID, etc. When an access point is outside qama, a user device will no longer be able to communicate with it and will try to find another access point. In one embodiment, switching between access points is seamless, eg there is no loss of network session, and a user may not even understand that they have changed access points.
Figure 4 illustrates a manager installer screen for defining a plurality of access zones. The installer screen can be a standalone computer program or it can work in an internet browser. The installer screen provides the ability, as described above, to define zones that include multiple access points (marked as Port positions in Figure 4). The zonal installer information is stored in a database internal or external to the network management device (s) 103 and accessible to the network management device (s) 103. When a user attempts to access the network through an access point, the connection request is sent to the network management device (s) 103 that allows access to be requested or denied based on the information programmed in the database.
A new login after migration selection 403 is provided to allow an administrator to determine whether to require a user to log on to the system again after migrating between access points. An administrator can enter a zone name as preferred in input area 407. The administrator can then enter the ports or positions that correspond to that zone in input area 409. Optionally, an administrator can provide a description in input area 411. The administrator can then determine whether a new login (or new authentication) will be required for movement between access points within the zone in selection 413. With The new login within zone 413 disabled, a user can freely move between access points without having to sign in to the system again. Adding zone buckles 415 provides a subsequent screen that allows an administrator to define another zone. Reset button 417 allows an administrator to reset zone settings. Exising zones section 419 lists all previously defined zones for the network with corresponding ports or locations along with the new login policy for each zone. To modify an existing zone, the administrator can click on the 'Edit' link for a particular zone. The spaces at the top will then be populated with the attributes of the selected area (name, ports, description and new login policy). To delete a zone, the administrator can click the Delete link. A block that appears will request confirmation of the delete operation.
In one mode, the zones cannot overlap, meaning that a port can belong to one and only one zone. In this mode, an error will be returned if the administrator writes a new zone that overlaps an existing zone. In another embodiment, the zones can be configured to overlap such that the same port or access position can be part of two or more separate zones.
Many different zone to zone migration policies can be implemented, such as, for example, in the Login Portal. In one mode, the network can be configured to (1) load separately for each zone, or (2) allow free migration from Zone 1 to Zone 2 after accepting terms and conditions, but require payment when migrating from the Zone 2 to Zone 1. Similarly, an individual payment may be accepted for one group of zones, but an additional or separate charge may be required for other zones.
Zones can also be configured on other interfaces, such as Command Line Interface (CLI) and Simple Network Management Protocol (SNMP). As would be understood by one skilled in the art of the present disclosure, various options and tools available in the interface mode of Figure 4 may correspond to SNMP and CLI interfaces.
In one mode, an unlimited number of zones can be configured. In one embodiment, the number of configurable zones is limited by the capacity of the network equipment used. For example, in one mode, up to 64 Zones or up to 32 Zones can be configured.
In a mode where the number of zones is limited, if there is already the maximum number of zones in the configuration, the network device will return a maximum number of error zones already reached.
In one mode, when a zone is added or modified by the administrator, the network device (s) will log errors in, such as, for example, the zone name; the specified network access positions, such as, for example, port assignments;
In one embodiment, the zonal name is a string of a specified length, such as between 1 and 16 characters in length. In one mode, if this check fails, the network device (s) will return an Invalid Zonal Name length error; the zonal description; and / or any other variable.
In one modality, the Zonal Name must be unique. If this check fails, the network device (s) will return a Zone Name already in use error.
In one embodiment, the port name is a string of a specified length, such as between 1 and 128 characters in length (eg, enough for at least 20 separate ports, or for at least 10 port ranges ). The string can contain an individual numeric value (eg, 211), or a comma separated list of numeric values (eg, 211, 212), or a range of numeric values with separate delimiters for the stroke (p , eg, 111-799), or a list of ranges of numerical values (eg, 100-150, 201-700), or a separate comma list of individual numerical values and ranges (eg, 211, 212, 21317
651). In one mode, if the string contains non-numeric values, the NSE will return values that can only be numeric, comma separated values or error ranges.
In one modality, numeric values cannot exceed 65535. When intervals are used, the right delimiter cannot be smaller than the left delimiter. In one mode, if these checks fail, the network management device will return an Invalid Port Format or value greater than 65535 error.
In one mode, the ports of different zones cannot overlap. In one mode, if this check fails, the network devices will return some Ports may not overlap intervals in other zones. Modify the overlapping area first or change this input error. In one mode, the ports are allowed to overlap and this check is not carried out.
In one embodiment, the description is a string of specified length, such as between 0 and 128 characters in length. In one mode, if this check fails, the network device (s) will return an invalid Description length error.
In one mode, the new login is a Boolean Value 'where no registration is required. In some WMI modes, those greater than errors will be displayed in an error block appear, and in some modes, the space causing the error will be highlighted simultaneously with a red border.
There are several cases to take into account when the subscriber's zone (eg port in some modes) changes: (1) If the New login after the migration parameter is disabled, the subscriber will not register in the system again; (2) If the New login after the migration parameter is enabled, and no zone is specified, the subscriber will log in to the system again; (3) If the New login after the migration parameter is enabled, 'and one or more zones are specified, the subscriber would need to sign in to the system again when: (1) the port changes to that of a different area; or (2) the zone's new login policy is to require a new login.
In one mode, 'ports that do not belong to any of the configured zone are automatically assigned to a default Zone. In one mode, the absence of a port is also assigned to a default Zone. The default Zone new login policy is simply derived from the New login after migration parameter. When the subscriber is accessed again, and a portal is involved in the new login process, the zone name will also be sent to the portal along with the other portal parameters (MAC address, room number, etc.).
In one mode, the Administrator installer page also allows the administrator to enlist the SSID'S corresponding to different zones, zone groups, access points, or access point groups. In one modality, the SSID'S can be programmed to correspond to overlapping access points or zones. For example, a plurality of SSID's can be assigned to the same access point or zone. The Administrator installer page can also temporarily (or permanently) secure the SSID'S to the extent corresponding to a plurality of access points or zones. For example, a conference can be configured with a custom SSID for a set of access points or zones.
In one mode, the Administrator installer page can also allow an administrator to assign an amount of bandwidth to a particular access point, the access point group, zone, zone group, or SSID. For example, the Lobby may provide less bandwidth than Guest Rooms. Similarly, a conference with custom SSIDs can provide a set amount of Bandwidth for custom SSID users.
Figure 5 illustrates a flowchart of a decision tree to determine when a login is required to obtain network access in one mode. In block 510, a subscriber's access point (marked as the Port's position) has changed. The system is moved to decision block 503 where the system determines if new login after migration is enabled. If not, then the system allows users to freely migrate between access points in block 505. If the new login after migration is enabled, then the system moves to decision block 507 where the system determines whether the zones have been specified. If there are no specified zones then the system will require a new login at each access point in block 509. If the zones have been specified, then the system moves to decision block 511. In decision block 511, the system determines whether the access point, or port in Figure 5 is included within the same zone as the point of previous access used by the user. If the answer is not, then a new login is required at block 513. If the access point is included within the same zone, then the system moves to decision block 517. In decision block 517, the system determines whether the new login is required within a zone. If not, then no new login is required in block 515. If yes, then the user is required to log in to the system again in block 519.
In one mode, an administrator can separately define different access rights when moving between zones. For example, in a modality, at any time a user moves between zones, they are required to register in the system. This type of system is illustrated in Figure 5. In one mode, an administrator can specify that users can move between certain zones without requiring re-authentication by requiring re-authentication when moving to other zones. This type of system is illustrated in Figure 6.
Figure 6 illustrates a flowchart showing when a login is required when moving between different zones in one mode. Figure 6 illustrates four zones, lobby 601, business center 605, guest rooms 603, and meeting room About 607. As illustrated, when a user moves from guest rooms 603 to lobby 601, no new login is required. When a user moves from lobby 601 to guest rooms 603, a new login is required. When a user moves between guest rooms 603 and business center 605 no new login is required. When a user moves from Guest Rooms to Meeting Room A, no new login is required, but when a user moves from Meeting Room 1 to Guest Rooms, a new login is required. . When a user moves from meeting room About 607 to lobby 601, no new login is required, but when a user moves from lobby to meeting room A, a new login is required. When a user moves between Meeting Room A and the Business Center, a new login is required. When a user moves from business center 605 to lobby 601, no new login is required, but when a user moves from lobby 601 to business center 605, a new login is required. Although Figure 6 has been described with respect to certain designated zones, it is to be understood that any number of zones, zone names, or zone positions can be used with the present system. Also, although described with respect to a new login, any type of new authentication can be used to move between zones.
In one mode, migration between zones can be additionally configured to use a home authentication or initial authentication position to track the migration policy. This allows a user, for example, to move from a first zone to a second zone and back to the first zone without a new login on a system that generally requires a new login to move from the second zone to the first zone. Figure 7 illustrates an example timeline of two users moving between different positions, on a network that uses a home authentication aspect to track the migration permission. As illustrated in Figure 7, User A's initial 701 login is in the guest wireless zone at block 711. The network places User A's initial authentication position out of memory and refers back to User A's initial authentication position when determining migration access rights. User About 701 then moves to the lobby in block 713, then to the business center in block 715 and then back to the guest room in block 717 without a new login. However, when the user moves to meeting room one in block 719, a new login is required. At this point, the home login can be changed to meeting room one, or the home login can be both the guest and wireless meeting room permissions that provide both sets of home authentication permission. The initial login of user B 751 is meeting room one in block 7 61. The user then moves to the lobby in block 7 63 and then back to meeting room one in block 765 without requiring a new login. However, when the user moves the wireless zone to the guest at block 767, a new login is required. Again, the home login is then altered to Guest or both Wireless Guest and Wireless Meeting Room A.
The conditional language used here, such as, among others, can, could, could, can, eg,. And the like, unless specifically not stated otherwise, or otherwise understood within the context used as, generally be Conceptualized to convey this, certain modalities include, while other modalities do not include, certain aspects, elements and / or states. Thus, such conditional language is not generally conceptualized to imply that aspects, elements and / or states are in any way required for one or more modalities or that the one or more modalities necessarily include the logic for the decision, with or without the entry of author or ¿award, if these aspects, elements and / or states are included or should be carried out in any particular modality.
While certain embodiments of the inventions described herein have been described, these embodiments have only been presented by way of example, and are not conceptualized to limit the scope of the inventions described herein. Indeed, the novel methods and systems described here can be represented in a variety of other ways;
In addition, various omissions, substitutions, and changes in the form of the methods and systems described here can be made without departing from the spirit of the inventions described here. The claims and their equivalents are intended to cover such forms or modifications as would be included within the scope and spirit of certain inventions described herein.
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
157 members in 15 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 22366709 | United States of America | P | |
| 53481409 | United States of America | A | |
| 2010040971 | United States of America | W |
Members157
| Document | Office | Kind | |
|---|---|---|---|
| US2008227471A1 | United States of America | A1 | |
| AU2007349233A1 | Australia | A1 | |
| CA2681474A1 | Canada | A1 | |
| WO2008115299A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2009204457A1 | United States of America | A1 | |
| US2009204815A1 | United States of America | A1 | |
| CA2752089A1 | Canada | A1 | |
| CA2752090A1 | Canada | A1 | |
| WO2009102385A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2009102388A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2009139890A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2130357A1 | European Patent Office (EPO) | A1 | |
| AU2007349233A2 | Australia | A2 | |
| MX2009009925A | Mexico | A | |
| KR20100015663A | Republic of Korea | A | |
| IL200949D0 | Israel | D0 | |
| US2010130165A1 | United States of America | A1 | |
| CA2794585A1 | Canada | A1 | |
| WO2010118057A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2248295A1 | European Patent Office (EPO) | A1 | |
| EP2248371A1 | European Patent Office (EPO) | A1 | |
| CA2767245A1 | Canada | A1 | |
| CA2804455A1 | Canada | A1 | |
| WO2011005710A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2011005900A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CA2805177A1 | Canada | A1 | |
| US2011030037A1 | United States of America | A1 | |
| WO2011014837A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2281386A1 | European Patent Office (EPO) | A1 | |
| WO2011005710A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2011154447A1 | United States of America | A1 | |
| US2011202407A1 | United States of America | A1 | |
| CA2823181A1 | Canada | A1 | |
| CA2832545A1 | Canada | A1 | |
| US2011208601A1 | United States of America | A1 | |
| WO2011103429A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2011103432A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2007349233B2 | Australia | B2 | |
| AU2010270756A1 | Australia | A1 | |
| US8116731B2 | United States of America | B2 | |
| EP2417755A1 | European Patent Office (EPO) | A1 | |
| SG177476A1 | Singapore | A1 | |
| MX2012000355AThis record | Mexico | A | |
| EP2452303A1 | European Patent Office (EPO) | A1 | |
| EP2452461A2 | European Patent Office (EPO) | A2 | |
| US2012130898A1 | United States of America | A1 | |
| US2012131121A1 | United States of America | A1 | |
| CN102484593A | China | A | |
| EP2460114A1 | European Patent Office (EPO) | A1 | |
| US2012144498A1 | United States of America | A1 | |
| KR20120062699A | Republic of Korea | A | |
| NZ580499A | New Zealand | A | |
| ZA201200071B | South Africa | B | |
| US8280348B2 | United States of America | B2 | |
| US2012297459A1 | United States of America | A1 | |
| US2012302209A1 | United States of America | A1 | |
| WO2011103429A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2011103432A3 | World Intellectual Property Organization (WIPO) | A3 | |
| JP2012533119A | Japan | A | |
| EP2537132A2 | European Patent Office (EPO) | A2 | |
| EP2537134A2 | European Patent Office (EPO) | A2 | |
| US8374634B2 | United States of America | B2 | |
| EP2281386A4 | European Patent Office (EPO) | A4 | |
| EP2130357A4 | European Patent Office (EPO) | A4 | |
| US2013132568A1 | United States of America | A1 | |
| US2013197998A1 | United States of America | A1 | |
| WO2013113025A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2013262311A1 | United States of America | A1 | |
| WO2013113025A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US8566912B2 | United States of America | B2 | |
| EP2248295A4 | European Patent Office (EPO) | A4 | |
| US8588748B2 | United States of America | B2 | |
| WO2013181151A2 | World Intellectual Property Organization (WIPO) | A2 | |
| EP2248371A4 | European Patent Office (EPO) | A4 | |
| EP2537132A4 | European Patent Office (EPO) | A4 | |
| EP2537134A4 | European Patent Office (EPO) | A4 | |
| US2014040155A1 | United States of America | A1 | |
| US2014047514A1 | United States of America | A1 | |
| WO2013181151A3 | World Intellectual Property Organization (WIPO) | A3 | |
| IL200949A | Israel | A | |
| US2014187205A1 | United States of America | A1 | |
| BRPI0721466A2 | Brazil | A2 | |
| US8831564B2 | United States of America | B2 | |
| US8839394B2 | United States of America | B2 | |
| EP2460114A4 | European Patent Office (EPO) | A4 | |
| US2014351899A1 | United States of America | A1 | |
| CN102484593B | China | B | |
| US2015017947A1 | United States of America | A1 | |
| KR101490132B1 | Republic of Korea | B1 | |
| IN913DEN2012A | India | A | |
| US2015142623A1 | United States of America | A1 | |
| US2015178715A1 | United States of America | A1 | |
| AU2010270756B2 | Australia | B2 | |
| US9141773B2 | United States of America | B2 | |
| US9154952B2 | United States of America | B2 | |
| EP2130357B1 | European Patent Office (EPO) | B1 | |
| US9185123B2 | United States of America | B2 | |
| JP5830017B2 | Japan | B2 | |
| US2016021537A1 | United States of America | A1 | |
| BR112012000373A2 | Brazil | A2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Application
- 2012000355
Titles2
- English
- ZONE MIGRATION IN NETWORK ACCESS.
- Spanish
- MIGRACION ZONAL EN UN ACCESO A RED.
Classification
- CPC, 9
- H04W12/08
- H04L63/08
- H04L12/4641
- H04L63/102
- H04L63/107
- H04W84/12
- G06F21/30
- H04L63/0209
- H04L63/10
- IPC, 3
- H04L12 08
- H04L29 06
- H04W12 08