Device zoning in a network gateway device
Abstract
The disclosure is directed to a network gateway device (“gateway”) that provides various network management features, including a device zoning feature in which client computing devices (“client devices”) connected to the gateway are assigned to different device zones. The client devices connected to the gateway form a local area network (LAN) of the gateway, and can access an external network, e.g., Internet, using the gateway. Each of the device zones has a specific set of network access privileges. Different device zones can have different network access privileges and can provide device isolation in the LAN at different degrees.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method performed at a network gateway device, comprising:
generating multiple device zones in a local area network of the network gateway device; measuring a network bandwidth usage associated with the multiple device zones in the local area network; and assigning a first computing device to at least one device zone based on a current measurement of the network bandwidth usage associated with the at least one device zone.
2 . The computer-implemented method of claim 1 , further comprising: extracting one or more parameters associated with the first computing device, wherein the one or more parameters include a software related parameter or a hardware related parameter of the first computing device.
3 . The computer-implemented method of claim 2 , wherein assigning the first computing device to the one of the multiple device zones includes:
assigning the first computing device to a new device zone in an event the first computing device is not in a known-devices list, wherein the new device zone restricts the first computing device from accessing other resources in the local area network while providing limited access to the external network.
4 . The computer-implemented method of claim 3 further comprising:
determining a type of the first computing device based on the one or more parameters; and
assigning the first computing device from the new device zone to one of the multiple device zones based on the type of the first computing device.
5 . The computer-implemented method of claim 4 , wherein assigning the first computing device to one of the device zones includes:
generating, by the network gateway device, a notification recommending a specified zone to which the first computing device is to be assigned, and receiving an approval from a user associated with the network gateway device to assign the first computing device to the specified zone.
6 . The computer-implemented method of claim 3 , wherein providing the limited access to the external network includes limiting an available network bandwidth to the first computing device.
7 . The computer-implemented method of claim 4 , wherein assigning the first computing device to one of the device zones includes assigning the first computing device to a PC zone if the first computing device is of a personal computer type, wherein the PC zone allows the first computing device to access other computing devices in the PC zone, at least some other resources in the local area network, and the external network.
8 . The computer-implemented method of claim 4 , wherein assigning the first computing device to one of the device zones includes assigning the first computing device to a mobile device zone if the first computing device is of a mobile device type, wherein the mobile device zone allows the first computing device to access the external network while restricting the first computing device from accessing other resources in the local area network other than a portion of the data storage system.
9 . The computer-implemented method of claim 2 , wherein assigning the first computing device to the one of the multiple device zones includes:
determining from the one or more parameters that the first computing device failed an integrity or a security check, and moving the first computing device to a timeout zone, wherein the timeout zone restricts the first computing device from accessing other resources in the local area network while permitting limited access to the external network.
10 . The computer-implemented method of claim 9 further comprising:
generating an alert to indicate a user associated with the network gateway device that the first computing device failed the integrity or security check.
11 . (canceled)
12 . (canceled)
13 . (canceled)
14 . (canceled)
15 . (canceled)
16 . (canceled)
17 . (canceled)
18 . (canceled)
19 . (canceled)
20 . (canceled)
21 . (canceled)
22 . (canceled)
23 . (canceled)
24 . A computer-readable storage medium storing computer-readable instructions, comprising:
instructions for generating multiple device zones in a local area network of a network gateway device; instructions for measuring a network bandwidth usage associated with the multiple device zones in the local area network; and instructions for assigning a first computing device to at least one device zone based on a current measurement of the network bandwidth usage associated with the at least one device zone.
25 . The computer-readable storage medium of claim 24 , wherein the instructions for assigning include:
instructions for determining from the one or more parameters that the first computing device is an IoT device, and instructions for assigning the first computing device to an IoT device zone, wherein the IoT device zone provides the first computing device access to an external network and a limited access to a data storage system in a storage zone of the device zones, and wherein the IoT device zone restricts the first computing device from accessing any resources in the local area network other than computing devices within the IoT device zone.
26 . The computer-readable storage medium of claim 25 , wherein the data storage system stores content that can be accessed by the first computing device for streaming onto a presentation device.
27 . The computer-readable storage medium of claim 24 , wherein the instructions for assigning include:
instructions for determining from one or more parameters that the first computing device failed an integrity or a security check, and instructions for moving the first computing device to a timeout zone, wherein the timeout zone restricts the first computing device from accessing other resources in the local area network while permitting limited access to an external network.
28 . The computer-readable storage medium of claim 27 , wherein the instructions for permitting the limited access to the external network include instructions for at least one of limiting an available network bandwidth to the first computing device or restricting the first computing device from accessing one or more websites.
29 . The computer-readable storage medium of claim 27 further comprising:
instructions for generating an alert to indicate a user associated with the network gateway device that the first computing device failed the integrity or security check.
30 . The computer-readable storage medium of claim 24 further comprising:
instructions for receiving device configuration information that assigns the first computing device to one of the multiple device zones, wherein the device configuration information is received from a first user associated with the network gateway device via a client device within the local area network.
31 . The computer-readable storage medium of claim 24 further comprising:
instructions for receiving device configuration information that assigns the first computing device to one of the multiple device zones, wherein the device configuration information is received from a first user associated with the network gateway device via a client device outside of the local area network.
32 . A system for managing device zones, comprising:
a memory configured to store non-transitory computer readable instructions; and a processor communicatively coupled to the memory, wherein the processor, when executing the non-transitory computer readable instructions, is configured to: generate multiple device zones in a local area network of a network gateway device; measure a network bandwidth usage associated with the multiple device zones in the local area network; and assign a first computing device to at least one device zone based on a current measurement of the network bandwidth usage associated with the at least one device zone.
33 . The system of claim 32 , wherein the network gateway device is a set-top box.Join the waitlist — get patent alerts
Track US2021385229A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.