METHOD FOR DUPLICATING A PRIMARY LOCAL COMMUNICATION NETWORK ONTO A SECONDARY LOCAL COMMUNICATION NETWORK, DUPLICATION DEVICE AND CORRESPONDING COMPUTER PROGRAM.
The method duplicates primary network characteristics onto secondary networks using unique identifiers and user profiles, enabling seamless and secure connections to temporary networks without reconfiguration, addressing the challenges of connecting to new Wi-Fi networks.
Patent Information
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- SAGEMCOM BROADBAND SAS
- Filing Date
- 2023-09-25
- Publication Date
- 2026-05-08
AI Technical Summary
Users face the inconvenience of having to individually reconfigure their devices to connect to temporary Wi-Fi networks when traveling, often with restricted access and security concerns, and existing solutions require additional equipment or steps.
A method to duplicate the network characteristics of a primary local area network onto a secondary local area network using a unique identifier and user profile authentication, allowing seamless connection without reconfiguration, and optionally setting up a secure tunnel for secure access.
Enables users to connect their devices to temporary networks with identical network characteristics as their primary network, providing secure access to services without additional configuration and equipment, and allowing secure tunneling for continued network access.
Smart Images

Figure 00000023_0000 
Figure 00000023_0001 
Figure 00000024_0000
Abstract
Description
Title of the invention: METHOD FOR DUPLICATION OF A MAIN LOCAL COMMUNICATION NETWORK ON A SECONDARY LOCAL COMMUNICATION NETWORK, CORRESPONDING DUPLICATION DEVICE AND COMPUTER PROGRAM. technical field
[0001] The present invention relates to the field of telecommunication networks, for example, wireless telecommunication networks. In particular, the present invention relates to the duplication, or copying, of a first telecommunication network onto a second telecommunication network. Specifically, the present invention relates to the duplication of the network characteristics of a first wireless telecommunication network onto an access system of a second wireless telecommunication network. STATE OF PRIOR ART
[0002] Nowadays, the number of user devices (for example: telephones) The number of smart devices (smartphones, tablets, computers, game consoles, etc.) connecting to a telecommunications network is constantly increasing. All these user devices are configured to connect, in particular, to a Wi-Fi (Wireless Fidelity) telecommunications network, whether for home or business use.
[0003] A wireless communication network (hereinafter "network") conforming to one of the IEEE 802.11 standards (for example, one or more of amendments b, g, a, n, ac, ax, be, etc., of the IEEE 802.11 standard) typically comprises a plurality of nodes. Each node is an electronic device comprising, at a minimum, a radio frequency module enabling the establishment of communications in accordance with one of the IEEE 802.11 standards, or in other words, in accordance with one of the Wi-Fi standards. Such a network typically comprises one or more electronic devices, commonly called access points ("APs"), and a plurality of electronic devices called users (or clients) that can establish wireless connections with one of the access points and / or with each other. One of these access points may be designated as the "master" insofar as the other access points are dependent on its control.This can be the case in a mesh wireless communication network, in which one of the access points centralizes. certain configuration decisions of other access points providing wireless coverage extension.
[0004] In a residential or professional environment, the master electronic device, or access point, is typically a "box" provided by an Internet service provider, i.e., a home gateway (or "residential gateway") or a professional gateway. User electronic devices (hereinafter "user equipment") are typically computers, televisions, tablets, or smartphones. It is commonly said that the user equipment is connected to the access point via Wi-Fi.
[0005] The home or professional gateway is connected to the remote network, or WAN (Wide Area Network), such as an Internet network, by copper ADSL (Asymmetric Digital Subscriber Line) link, or similar, by fiber and / or by a 3G / 4G / 5G mobile access, allowing user equipment on the network to access the remote network and communicate with each other.
[0006] Thus, a local communication network, or LAN (“Local Area Network” in English) is for example a home network or professional network, to which several user devices are connected via the home or professional gateway.
[0007] User equipment connected to a local network can benefit from various services (on-demand video, music, or online video games, etc.). Once the user equipment is no longer connected to the same local network, these services are no longer available. This is the case, in particular, if the user equipment is moved by a user, for example, when going on vacation or traveling for work.
[0008] When traveling, it is cumbersome to have to individually reconfigure each user device to connect to the Wi-Fi network of the temporary residence (co-working space, host company, hotel room, campsite, etc.). Furthermore, this Wi-Fi network at the temporary residence is often controlled by a captive portal, which may restrict certain types of services. Another problem with this type of network is that the user has no control over its security configuration and is therefore dependent on the choices of the Wi-Fi network owner.
[0009] Some operators provide their subscribers with a wide-area Wi-Fi network broadcast by all of that operator's network equipment. Thus, a user who is a subscriber of the operator can connect to the operator's wide-area Wi-Fi network via another subscriber's network equipment. However, this network, "common" to all of the operator's subscribers, has very different characteristics from those of the Each user's home or work network requires an additional step to configure their equipment. Therefore, an additional step is necessary on each device the user wishes to use on this extended network.
[0010] According to another solution, in the case of a distributed home network, it is possible to use one of the home network's range extenders to provide Wi-Fi access at the temporary residence and to use a configuration procedure. However, this solution requires the user to have a Wi-Fi extender and to take it with them when traveling.
[0011] It is therefore desirable to overcome these drawbacks of the prior art.
[0012] EXPOSE
[0013] It is desirable to provide a solution which allows each user device configured to connect to a primary network called "home" or "professional" to connect to a temporary secondary network called "host" without needing to reconfigure each user device individually or to bring network equipment to serve as a "bridge" between the host network and the user devices.
[0014] To this end, a method for duplicating a primary local area network managed by a gateway to a remote network and comprising at least one user device capable of connecting to the primary local area network, onto a secondary local area network managed by another gateway to the remote network, the method comprising:
[0015] - obtain from said at least one user device a unique identifier of a system host access of the secondary local network and authenticate the host access system using the unique identifier obtained,
[0016] - authenticate a user profile, the user profile being associated with network characteristics of the main local network,
[0017] - and, when the host access system and the user profile are authenticated: transmit a message to the host access system, the message including the network characteristics of the primary local network and a request to create, on the secondary local network, a so-called "copied" local network including the network characteristics of the primary local network and to which said at least one user device is able to connect.
[0018] Thus, it is possible for user equipment on a user's so-called "primary" local area network (home or work network) to connect to a so-called "secondary" local area network at a temporary residence via a connection to a "copied" local area network with network characteristics identical to the primary local area network. The connection of user equipment to the "copied" local area network does not No additional configuration is required because user devices are already aware of the network characteristics of the main local network. A user on the go can then easily connect any of their devices (e.g., computer, smartphone) to this copied local network and access the secondary local network of their temporary residence.
[0019] According to a particular embodiment, the method further comprises: setting up a secure tunnel between the so-called "copied" local network comprising the network characteristics of the main local network and the gateway of the main local network.
[0020] Advantageously, the implementation of the secure tunnel between the "copied" local network and the gateway managing the main local network allows the user to securely access his main local network and therefore all of his services, even when he is on the move.
[0021] According to a particular embodiment, the process further comprises a so-called "pre-configuration" step comprising:
[0022] - create the user profile from a user ID and a password pass,
[0023] - record the network characteristics of the user profile main local network.
[0024] Thus, it is possible to uniquely associate the network characteristics of a user's primary local network with their user profile.
[0025] According to a particular embodiment, the pre-configuration step further includes: maintaining an up-to-date list of host access systems authorized to duplicate the network characteristics of the primary local network on a secondary local network, the list including for each host access system a unique identifier.
[0026] In order to be authorized to copy the network characteristics of the primary local area network (LAN) onto the secondary LAN to create a "copied" LAN, the host access system of the secondary LAN must be included on a list of host access systems authorized to retrieve the characteristics of the primary LAN for copying. This makes it possible to secure the duplication of the primary LAN, since it can only be performed on a host access system of a secondary LAN authorized to carry out the duplication.
[0027] According to a particular embodiment, authenticating the user profile includes: determining whether said at least one user device used to obtain the unique identifier of the secondary LAN host access system belongs to a list of user devices authorized to be used to authenticate the user profile.
[0028] Advantageously, in order to increase the security of the duplication process, user profile authentication is based on a double verification: User identity verification and verification of the identity of the user equipment used to obtain the unique identifier of the host access system of the secondary local network visited by the user. This allows, in particular, in the event of user identity theft (for example, theft of the username and password used to authenticate the user profile), the prevention of duplication of the primary local network if the user equipment is not on the list of user equipment authorized to provide the user's identifier for user profile authentication.
[0029] According to a particular embodiment, transmitting a message to the host access system includes: determining whether said host access system is authorized, over a predefined period or on a predefined date, to configure said local network said "copied" on the secondary local network.
[0030] Thus, prior to moving, the user can provide information regarding the location (i.e., identity / location of the secondary LAN being visited) and the date or period during which their user equipment can connect to the host access system of the visited secondary LAN. This secures the duplication of the user's primary LAN characteristics by allowing duplication only on a host access system of a secondary LAN previously declared by the user.
[0031] According to a particular embodiment, the method further comprises,
[0032] - obtain: either a period during which said at least one user equipment is authorized to connect to said "copied" local network, or a date from which said user equipment is no longer authorized to connect to said copied local network,
[0033] - delete said copied local network:
[0034] - either when said period ends,
[0035] - either when said date is reached,
[0036] - either at the user's request.
[0037] Advantageously, it is possible to limit the copy of the main local network over time and to automatically delete (on the basis of a predetermined period or date) or manually (at the user's request) the copy of the main local network.
[0038] Also proposed here is a duplication device comprising electronic circuitry configured to perform the steps of the process described above.
[0039] Also proposed here is a server accessible via a remote network comprising a duplication device as described above.
[0040] Also proposed here is a gateway for a primary local communication network configured to manage said primary local communication network to which is connected at least one user device, said gateway being characterized in that it includes a duplication device as described above.
[0041] Also proposed here is a computer program product, comprising instructions causing the execution, by a processor, of the process as described above, when said instructions are executed by the processor.
[0042] Also proposed here is a storage medium, storing a computer program comprising instructions causing the execution, by a processor, of the process as described above, when said instructions are read and executed by the processor. Brief description of the drawings
[0043] The characteristics of the embodiments mentioned above, as well as others, will become clearer upon reading the following description of at least one exemplary embodiment, said description being made in relation to the accompanying drawings, among which:
[0044] [Fig.1] schematically illustrates an example of an implementation environment for a particular embodiment;
[0045] [Fig.2] schematically illustrates another example of an implementation environment for a particular embodiment;
[0046] [Fig.3] illustrates in diagram form a method of duplicating a primary local network on a host access system of a secondary local network according to a particular embodiment;
[0047] [Fig.4] schematically illustrates the exchanges between a duplication device, user equipment and the host access system of a secondary local network during the implementation of the duplication process according to a particular embodiment.
[0048] [Fig.5] schematically illustrates a particular implementation of a step in the duplication process;
[0049] [Fig.6] schematically illustrates a particular implementation of another step in the duplication process;
[0050] [Fig.7] schematically illustrates the hardware architecture of a duplication device configured to perform all or part of the steps of the process illustrated in Figs. 3 to 6.
[0051] DETAILED DESCRIPTION OF IMPROVEMENTS
[0052] The general principle of one or more embodiments relates to the temporary duplication, or copying, of the characteristics of a so-called "primary" local network, in particular a home or professional local network, at the level of a host access system of a so-called "secondary" host local network distant from the primary local network.
[0053] The terms "network characteristic(s)" or "network characteristic(s)" refer to a set of information necessary to enable the connection of a user device (for example: a computer, a tablet, a smartphone) to a wireless telecommunications network. Examples include the SSID (Service Set Identifier), the password for accessing the wireless telecommunications network, the security mode of the wireless telecommunications network (for example: WPA for "WiFi Protected Access" or WPA2 for "WiFi Protected Access 2"), etc.
[0054] The terms “access system” refer to an access point or a set of wireless access points connected together to form a mesh-type wireless telecommunications network.
[0055] This copying of the primary LAN's characteristics to the secondary LAN's host access system allows user devices (e.g., tablets, smartphones) belonging to the primary LAN to connect to it without requiring additional configuration. In other words, any user device configured to connect to a "primary" network can connect to a "secondary" host network without needing reconfiguration or providing equipment to act as a "bridge" between the secondary host network and the user's devices. To achieve this, the primary LAN's user devices connect to a so-called "copied" access point of the host access system as if it were an access point of the primary LAN.Indeed, this "copied" access point includes the network characteristics of the main local network and allows the formation of a new "copied" local network, existing in parallel with the secondary host local network.
[0056] The term "primary" local area network refers to a wireless network to which a user's equipment is initially connected. This could therefore be, for example, a local area network in the user's home, or a local area network in their company.
[0057] The term "secondary" or "host" local area network therefore refers, conversely, to a wireless network to which user equipment connects on an ad hoc basis and for a limited time. This is, for example, the wireless network of a holiday resort (hotel, campsite, etc.), or of a business trip (conference hall, host company, etc.).
[0058] Fig. 1 schematically illustrates an example of an implementation environment for the invention according to a particular embodiment.
[0059] In this example, the user is at home or at their business. Thus, all of the user's equipment is connected to a main local telecommunications network, denoted LAN1. In other words, the main local network LAN 1 is considered to be the one to which user devices regularly connect. Consequently, it is the local network whose network characteristics (e.g., SSID, password, security mode...) are known to user devices.
[0060] The main local area network (LAN1) is managed by a gateway, denoted GW1, which provides access to a remote WAN, for example, the Internet. The gateway GW1 is connected to the remote WAN via an ADSL or fiber optic connection. It can also connect to a cellular network operator's network via a 2G to 5G wireless connection. This main local area network (LAN1) also includes all user devices connected to each other via the gateway GW1, such as a smartphone UE1, a personal computer UE2, and a tablet UE3. These user devices can be connected to the gateway GW1 via a wired connection (for example, Ethernet) directly to the gateway GW1, or via other types of connections such as USB or wireless connections (for example, Wi-Fi, Bluetooth, Bluetooth Low Energy, Z-Wave, Zigbee, DECT-ULE, etc.).These user devices are capable of connecting to the main local network LAN1 because they have the necessary permissions and configurations to access the resources of said local network.
[0061] The environment illustrated in [Fig. 1] further includes a secondary host local area network, denoted LAN2. This secondary host local area network, LAN2 (or secondary LAN2 hereafter), is, for example, a local area network at a holiday destination (e.g., hotel, campsite, etc.) or a business trip location (e.g., conference venue, co-working space, etc.). In other words, it is the local area network at the user's location. Thus, as described previously, the term "secondary" refers to a local communication network to which the user's equipment (i.e., smartphone UE1, personal computer UE2, tablet UE3) connects temporarily and exceptionally.
[0062] The secondary host local area network (LAN2) is managed by a gateway, denoted GW2, providing access to a remote WAN, for example, the Internet. The gateway GW2 is connected to the remote WAN via an ADSL or fiber optic link. Of course, it can also connect to a cellular network of an operator via a 2G to 5G wireless radio link. This secondary host local area network (LAN2) also includes one or more devices or access points (for example: extenders, wireless repeaters, etc., not shown). In particular, the term "host access system" refers to an access point (for example, gateway GW2) or a set of wireless access points (for example, a set of wireless repeaters) connected together to form the secondary host local area network (LAN2), located at the user's location. compatible with the process, and its embodiment variants, described below in relation to Figs. 3 to [Fig. 6]. The access point(s) of the host access system can be connected to the GW2 gateway by wired or wireless connection.
[0063] In one embodiment, the secondary LAN2 is, for example, a mesh Wi-Fi network. For this purpose, this secondary LAN2 includes, for example, a wireless communication coverage extension system coordinating several access points integrated into communication nodes labeled NI, N2, and N3. These different access points are interconnected by means of a backhaul subnetwork and thus form the host access system. These access points allow user devices UE1 to UE3, as appropriate, to access the secondary LAN2.
[0064] Fig. 1 thus illustrates in a simplified and schematic way a secondary local area network LAN2 comprising such a wireless communication coverage extension system built around a routing subnetwork comprising a set of access points (i.e. host access system) located in the interconnected nodes NI, N2 and N2.
[0065] In general, in the case of a mesh-type wireless network, each NI, N2 and N3 communication node of the routing subnetwork comprises a plurality of radio interfaces:
[0066] - a radio interface called "AP-BH" (for "Access Point Backhaul" in English) corresponding to an access point interface of the routing subnetwork,
[0067] - a "STA-BH" radio interface (for "Station Backhaul" in English) corresponding to a user (or client) interface of the routing subnetwork,
[0068] - an "AP-FH" radio interface (for "Access Point Fronthaul" in English) corresponding to an access point interface of the secondary local network LAN2, this interface being dedicated to the association of user equipment UE1 to UE3 with the secondary local network LAN2.
[0069] The communication nodes NI, N2, and N3 of the routing subnetwork are interconnected via a tree-like structure, with one node acting as a relay between two other nodes in the routing subnetwork. The communication nodes NI, N2, and N3 are thus interconnected by means of wired links, for example, Ethernet, or wireless links. The communication nodes NI, N2, and N3 of the routing subnetwork communicate with each other via logical links, for example, IP communications, encrypted tunnels, or communications using a proprietary communication protocol.
[0070] In one example, node NI is connected to node N2 via a wireless link between the access point radio interface AP-BH of node NI and the client radio interface ST-BH of node N2. Node NI is also connected to node N3 via a wireless link between the access point radio interface AP-BH of node NI and the client radio interface ST-BH of node N3. Links between two nodes in the routing subnetwork are called backhaul links and can be wired or wireless.
[0071] Where appropriate, user equipment UE1 to UE3 can connect to the various NI to N3 nodes via their AP-FH radio interface for their access to the secondary local area network LAN2.
[0072] Figure 2 schematically illustrates another example of an implementation environment for the invention, according to a particular embodiment. In this example, the user is traveling outside their home or business premises. The user therefore wishes to connect their user devices, such as their smartphone UE1 or tablet UE3, to the secondary local area network LAN2 of their location (e.g., campsite, co-working space, host company, etc.).
[0073] In this example, user devices UE1 (e.g. smartphone) and UE3 (e.g. tablet) are connected via a wireless link to the access point of the communication node N3. User devices UE1 and UE3 are thus connected to the secondary local area network LAN2 via node N3 acting as a so-called "fronthaul" access point.
[0074] To prevent user devices UE1 and UE3 from needing to be reconfigured to connect to the access point of node N3, the network characteristics of the primary LAN1 are copied to node N3 of the secondary LAN2, according to the process described below in relation to [Fig. 3] to [Fig. 6]. In particular, this new access point, having the same network characteristics (e.g., SSID, password, security mode, etc.) as the primary LAN1, is created at the communication node N3 to allow user devices UE1 and UE3 to connect to node N3 without additional configuration, thus forming a new "copied" LAN3. This new "copied" access point is therefore a copy of an access point of the primary LAN1.
[0075] Once connected to this new access point "copied" from the N3 node, which replicates the network characteristics of the primary LAN1, user devices UE1 and UE3 can communicate with each other within the LAN3, and also access the secondary LAN2. User devices can thus communicate with the gateway GW2 of the secondary LAN2 via the N3 node, for access to the remote WAN, for example.
[0076] Figures 1 and 2 also schematically illustrate a SER server of a primary local area network (LAN1) duplication service provider, or more simply: a service provider. Indeed, in order to create this new, so-called "copied" access point with the network characteristics of the primary LAN1, at the N3 communication node, the user may have previously subscribed to a duplication service for their primary LAN1. This service is provided by a service provider, such as an Internet service provider or a third-party entity. This service provider operates equipment, such as the SER server, located, for example, in the cloud, and accessible via the WAN.
[0077] All or part of the duplication process as described below in relation to [Fig.3] to [Fig.6] is implemented by a DISP duplication device described below in relation to [Fig.7].
[0078] This DISP duplication device is a hardware and / or software device that can be located, for example, in the SER server of the service provider or, alternatively, in a remote network access gateway (for example, home or business gateway GW1).
[0079] Figure 3 illustrates in diagram form a method of duplicating a primary local area network LAN1 onto a host access system of a secondary local area network LAN2 according to a particular embodiment.
[0080] Fig. 4 schematically illustrates the exchanges between: a duplication device DISP, user equipment UE1 and UE3 and the host access system (denoted SYS) during the implementation of the duplication process according to a particular embodiment.
[0081] During an optional pre-configuration step 301, the user subscribes to a service for replicating the characteristics of their primary local area network (LAN 1) from a service provider. This pre-configuration step 301 only needs to be performed once.
[0082] In one embodiment, this step 301 is implemented by the DISP duplication device. More specifically, during this step 301, the DISP duplication device obtains, via a user device, such as a UE1 smartphone, information such as a user identifier (e.g., username, email address, etc.) and a password for the creation of a unique user profile with the service provider. The provision of this information to the DISP duplication device and the creation of the user profile are carried out, for example, via a dedicated mobile application of the service provider on the UE1 smartphone or on a web page dedicated to the service provider's duplication service.
[0083] Once the user profile is created, the DISP duplication device obtains the network characteristics (e.g., SSID, password, security mode, etc.) of the user's main local network LAN1. In a first embodiment, the user manually enters the network characteristics via their smartphone UE1, for example, using an interface (e.g., a mobile application or web page) provided by the service provider. This is the case, for example, when the service provider is different from the user's Internet service provider.
[0084] In a second embodiment, the user authorizes the service provider to access the user equipment on their home local area network (e.g., gateway GW1). The DISP replication device then directly and automatically retrieves the network characteristics. This is the case, for example, when the service provider is also the user's Internet service provider. Subscribing to the replication service is then, for example, an option within the user's Internet subscription.
[0085] In a third embodiment, the user configures a user device on their main local area network LAN1 (for example: gateway GW1) to automatically transmit network characteristics to the replication device DISP. Similarly to the previous embodiment, when the service provider is also the user's Internet provider, the user can configure their gateway GW1 to transmit network characteristics to the replication device DISP.
[0086] These network characteristics are then recorded, for example in a memory of the DISP duplication device, in association with the user's user profile. This recording makes it possible to associate the network characteristics with the user in a unique way.
[0087] In one variant, the network characteristics are stored in association with a user profile in a memory of the SER server. If necessary, the duplication device DISP can access this memory to implement all or part of the duplication process described.
[0088] In one embodiment, upon arrival at its temporary residence, during step 302, the DISP duplication device obtains, via for example the UE1 smartphone, a unique identifier of an access point, for example of the N3 node, of the host access system SYS. This access point, also referred to hereafter as the "access point of interest," corresponds to the access point to which the mobile user devices (UE1 smartphone, UE3 tablet) wish to connect in order to access the secondary local area network LAN2.
[0089] In one example, during step 302, the UE1 smartphone scans (substep 401) (for example: in a shared workroom, on a room key (hotel, on the reception access point screen...etc.) a QR Code (Quick Response Code) containing the unique identifier specific to the access point of interest of the N3 node of the host access system SYS. The UE1 smartphone thus retrieves (substep 402) the unique identifier specific to the access point of interest of the N3 node.
[0090] In one variant, the unique identifier of the host access system can be contained in a barcode, in an RFID chip (“Radio Frequency Identification”), an alphanumeric code, etc.
[0091] This unique identifier allows the DISP duplication device to identify the access point(s) of interest of the host access system SYS to which one or more user devices UE1, UE3 wish to connect.
[0092] This unique identifier corresponds, for example, to the identity of an access point of interest of the host access system SYS. In one embodiment, the unique identifier of an access point of interest of the host access system SYS is the serial number of the primary equipment (for example: gateway GW2 or a controller implementing the "EasyMesh" protocol) of the host access system and / or of a secondary equipment (for example: wireless repeater).
[0093] This unique identifier is associated, for example, with the user's temporary place of residence (e.g., name, geographical location...), and / or with information concerning the point of interest, such as its location (e.g., room numbers, camping spots...).
[0094] In one embodiment, during step 303, the DISP duplication device obtains from the user equipment (smartphone UE1) the unique identifier of the access point of interest of the host access system SYS. Thus, in substep 403, the DISP duplication device can then authenticate, using this unique identifier, the access point of interest of the access system SYS to which the user equipment UE1 and UE3 wish to connect (for example: the access point of node N3).
[0095] In order for the DISP duplication device to authenticate this access point of interest of the host access system SYS using its unique identifier, it is necessary that this unique identifier be known to the DISP duplication device. Therefore, it is necessary that this unique identifier be previously recorded, for example in a memory of the DISP duplication device or in a memory of the SER server accessible to the DISP duplication device. In other words, the user's secondary residence must be registered with the service provider's duplication service, for example through a subscription. The unique identifier is then recorded in association with location or identity information of the temporary place of residence, as presented above.
[0096] In one embodiment, the DISP duplication device stores in memory a list of unique identifiers of the access point(s) of the host access system SYS that can benefit from the duplication service of the service provider.
[0097] This list is updated for example with each new subscription to the service (for example: adding a unique identifier of a new host access system), with each termination of the service (for example: removing a unique identifier of a host access system) or with each change in the architecture of the secondary local network LAN2 (for example: adding or removing access points).
[0098] In one embodiment, after authenticating the access point of interest of the host access system SYS, the DISP replication device authenticates the user profile. To do this, the DISP replication device prompts the user to authenticate. In one example, the DISP replication device then redirects the user device UE1 to an interface provided by the service provider (e.g., a mobile application or web page) so that the user can authenticate. The user device UE1 therefore transmits, during a substep 404, to the DISP replication device a username and password associated with the user's profile, which it already knows.
[0099] In one embodiment, to authenticate themselves, the user manually transmits, via their user equipment, their username and password known to the DISP duplication device. In other words, the DISP duplication device receives the user's username and password via the user equipment for user profile authentication.
[0100] In another embodiment, this user profile authentication substep 404 can be automatic if the user is using an application in which they have already logged in. For example, the user is already logged in to a mobile application on their UE1 smartphone.
[0101] Alternatively or additionally, substep 404 of user profile authentication can be performed by implementing specific security, for example, using a user device "certified" by the user of the main LAN1 (e.g., their smartphone UE1). In other words, the DISP duplication device authenticates, on the one hand, the "certified" user device used for user profile authentication and obtaining the unique identifier of the host system's access point of interest, and on the other hand, the user themselves. The use of the "certified" user device is therefore required to transmit the unique identifier of the host access system's access point of interest to the DISP duplication device and authenticate the user profile, acting This is similar to a two-factor authentication method. For the DISP replication device to authenticate the "certified" device, a unique identifier for the "certified" user device (e.g., MSISDN) is registered on a list of user devices authorized for user profile authentication in the DISP replication device's memory, in association with the user profile, during pre-configuration step 301. This double verification provides a higher level of security than simple user authentication.
[0102] Alternatively or additionally, substep 404 of user profile authentication can be implemented only if the user has previously notified the DISP replication device of their move, for example, via an interface provided by the service provider (mobile application or web page). In one example, prior to moving, the user transmits, via a user device, the date, or period, and possibly the destination of their move to the DISP replication device. This embodiment makes it possible to proactively limit the creation of a copy of the characteristics of the main LAN1 in time and space.
[0103] In one embodiment, during step 303 or prior to the move, it is also possible to define a duration or an end date for this "copying" of the characteristics of the main LAN1, so that it is automatically deleted (for example, during step 307 described below) upon expiry of the defined period or date. This configuration can also be done in an interface provided by the service provider (mobile application or web page, for example). The user, via the user equipment, thus transmits information regarding the duration or date of the move to the duplication device DISP. This allows, among other things, limiting the duration of the copying of the characteristics of the main LAN1.
[0104] At the end of step 303, the DISP duplication device then has:
[0105] - information required to identify an access point of interest in the system SYS host access (i.e., the unique identifier, contained for example in a QR code, associated with information concerning the location of the secondary residence or the location of the access point of interest),
[0106] - network characteristics to be copied (i.e. those of the main local area network LAN1 of the user) via user authentication.
[0107] The DISP duplication device then triggers, in step 304, the creation of a new wireless local area network, labeled LAN3 in [Fig. 1] and [Fig. 2]. This new LAN3 local area network, broadcast by the communication node N3, includes the same network characteristics that the main local network LAN1. The local network LAN3 is therefore a "copy" of the main local network.
[0108] More specifically, according to one embodiment, the duplication device DISP transmits, during a substep denoted 405, the characteristics of the main local area network LAN1 to the host access system SYS. This new local area network LAN3, referred to as "copied", can coexist with other wireless networks configured on the same host access system.
[0109] Figure 5 schematically illustrates a particular implementation of a step in the duplication process. In particular, Figure 5 schematically illustrates a particular implementation of step 304 of creating a copy of the primary LAN1 on the host access system of the secondary LAN2.
[0110] In one embodiment, the secondary LAN2 is a wireless mesh network capable of implementing the "EasyMesh" protocol. Thus, the replication device DISP transmits, during substep 405, the characteristics of the primary LAN1 to a primary device of the secondary LAN2, such as an "EasyMesh" CONT controller. For this purpose, the replication device DISP uses, for example, the TR-69 protocol or the USP protocol.
[0111] This CONT controller is, for example, included in the GW2 gateway.
[0112] The characteristics of the primary LAN1 are then added to the configuration of the CONT controller of the secondary LAN2.
[0113] The CONT controller then transmits these characteristics to the "EasyMesh" agents of the secondary LAN2. These agents are, for example, included in the communication nodes NI, N2 (not shown), and N3. To do this, the CONT controller can, for example, send an "AP_Autoconfiguration_Renew" message to the agents, which triggers each agent to send "AP_Autoconfiguration_WSC_M1" messages to the CONT controller. The CONT controller responds to these M1 messages and transmits "AP_Autoconfiguration_WSC_M2" messages to the agents, including an additional TLV M2 containing the characteristics of the primary LAN1 network to instruct each agent to configure an additional BSS ("Basic Service Set") with these characteristics on each of its radio interfaces.
[0114] Thus, at the end of step 304, a new "copied" access point reproducing the characteristics of the main LAN1 is created at a communication node (for example, node N3) initially comprising only the access point of interest. User devices such as the UE1 smartphone and the UE3 tablet can then connect to this new "copied" access point without requiring any additional configuration.
[0115] Thus, during a step 306, the user equipment, such as the UE1 smartphone and the UE3 tablet, connect, in substep 406, to the access point "copied" as on an access point of the main LAN1 network to use the "copied" LAN3 network.
[0116] In one embodiment, during a step marked 305 in Figs. 4 and 5, a secure network tunnel can then be set up between the host access system SYS and the gateway GW1 of the user's main local network LAN1 to allow him to access his main local network LAN1 securely, even when traveling.
[0117] In an example illustrated in [Fig. 5], the host access system (for example, via the N3 communication node) transmits a request, denoted "DE_TUNNEL", to establish a tunnel to the DISP replication device. In return, the DISP replication device transmits the "DE_TUNNEL" request to establish a tunnel to the GW1 gateway of the main LAN1. A tunnel (denoted TUNNEL) is then established between the "copied" access point of the N3 node of the host access system and the GW1 gateway of the main LAN1. The term "tunnel" refers to a tunnel in the context of communication networks, in which the transmitted / to-be-transmitted data is encapsulated in order to isolate said data.
[0118] When the move to the temporary residence is complete, the copy of the primary LAN is deleted during step 307. In particular, the duplication device DISP requests (substep 407) that the network characteristics of the primary LAN1 be removed from the host access system SYS. In one embodiment, this implies that the "copied" access point containing the characteristics of the primary LAN1 is removed from the communication node.
[0119] According to one embodiment, the copy of the main local network (i.e. the "copied" local network LAN3) is deleted after a given period or date, which are predefined during step 303.
[0120] In another embodiment, the copy of the main local network (i.e. the "copied" local network LAN3) is deleted at the user's request.
[0121] Figure 6 schematically illustrates a particular implementation of a step in the duplication process. In particular, Figure 6 schematically illustrates a particular implementation of step 307 of removing the network characteristics of the main local area network LAN1 of the host access system SYS.
[0122] In an embodiment in which the secondary LAN2 is a wireless mesh network using the "EasyMesh" protocol, the duplication device DISP can request to remove the characteristics of the primary LAN1 from the configuration of the controller CONT.
[0123] For this purpose, the duplication device DISP sends a message to remove the characteristics of the home network LAN1 to the controller CONT, for example a message based on the TR-069 protocol.
[0124] The CONT controller then sends a message labeled "AP_AutoConfiguration_Renew" to each agent, which triggers the agents to send messages labeled "AP_AutoConfiguration_WSC_M1" to the CONT controller. The CONT controller responds to these M1 messages by sending the agents messages labeled "AP_AutoConfiguration_WSC_M2" that do not contain a TLV M2 with the characteristics of the primary LAN1 (unlike what is done in substep 405). The absence of this TLV containing the characteristics of the primary LAN1 signals to the agents that they must stop broadcasting the "copied" LAN3.
[0125] Fig. 7 schematically illustrates the hardware architecture of a duplication device configured to perform all or part of the steps of the process illustrated in Figs. 4 and 5.
[0126] The DISP 700 duplication device comprises, connected by a communication bus 710: a processor or CPU (Central Processing Unit) 701; a RAM (Random Access Memory) 702; a ROM (Read Only Memory) 703, for example a Flash memory; a data storage device, such as a HDD (Hard Disk Drive), or a storage media reader, such as an SD (Secure Digital) card reader 704; at least one communication interface 705 enabling the DISP 700 duplication device to interact with user equipment, such as the UE1 smartphone, the UE2 laptop, the UE3 tablet, the GW1 and GW2 gateways, the NI, N2, N3 nodes of the SYS host access system.
[0127] The processor 701 is capable of executing instructions loaded into RAM 702 from ROM 703, external memory (not shown), the data storage device 704, such as an SD card, or a communication network (not shown). When the duplication device DISP 700 is powered on, the processor 701 is capable of reading instructions from RAM 702 and executing them. These instructions form a computer program causing the processor 701 to implement the behaviors, steps, and algorithms described herein, particularly in combination with all or part of the steps in Figures 4 and / or 5.
[0128] All or part of the behaviors, steps and algorithm described herein can thus be implemented in software form by executing a set of instructions by a programmable machine, such as a DSP (Digital Signal Processor) or a microcontroller, or be implemented in hardware form by a dedicated machine or component (chip) or a set of components (chipset). (English) dedicated, such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit). Generally speaking, the DISP 700 duplication device comprises electronic circuitry arranged and configured to implement the behaviors, steps, and algorithms described here.
Claims
Demands
1. A method for duplicating a primary local area network (LAN1) managed by a gateway (GW1) for access to a remote area network (WAN) and comprising at least one user device (UE1, UE2, UE3) capable of connecting to the primary local area network (LAN1), onto a secondary local area network (LAN2) managed by another gateway (GW2) for access to the remote area network (WAN), said method comprising: - obtaining from said at least one user device (UE1, UE2, UE3) a unique identifier of a host access system (SYS) of the secondary local area network (LAN2) and authenticating said host access system (SYS) from said unique identifier obtained, - authenticating a user profile, said user profile being associated with network characteristics of the primary local area network (LAN1), - and, when said host access system (SYS) and said user profile are authenticated: transmitting a message to said host access system (SYS),said message including the network characteristics of said primary local area network (LAN1) and a request to create, on the secondary local area network (LAN2), a local area network (LAN3) referred to as "copied" comprising the network characteristics of said primary local area network (LAN1) and to which said at least one user device (UE1, UE2, UE3) is capable of connecting, said method being characterized in that transmitting a message to said host access system (SYS) includes: determining whether said host access system (SYS) is authorized, over a predefined period or on a predefined date, to configure said local area network referred to as "copied" on the secondary local area network (LAN2).
2. A duplication method according to claim 1, characterized in that it further comprises: setting up a secure tunnel between said local network said "copied" comprising the network characteristics of said main local network (LAN1) and said gateway (GW1) of said main local network (LAN1).
3. A duplication method according to any one of claims 1 and 2, characterized in that it further comprises a so-called "pre-configuration" step comprising: - creating the user profile from a user ID and a password, - record in association with the user profile the network characteristics of the main local network (LAN1).
4. A duplication method according to claim 3, characterized in that said pre-configuration step further comprises: maintaining an up-to-date list of host access systems authorized to duplicate the network characteristics of the primary local area network (LAN1) on a secondary local area network, said list comprising for each host access system a unique identifier.
5. A duplication method according to any one of claims 1 to 4, characterized in that authenticating said user profile includes: determining whether said at least one user device (UE1, UE2, UE3) used to obtain the unique identifier of the host access system (SYS) of the secondary local area network (LAN2), belongs to a list of user devices authorized to be used to authenticate the user profile.
6. A duplication method according to any one of claims 1 to 5, characterized in that it further comprises: - obtaining: either a period during which said at least one user equipment is authorized to connect to said "copied" local network, or a date from which said user equipment is no longer authorized to connect to said copied local network, - deleting said copied local network: - either when said period ends, - or when said date is reached, - or at the user's request.
7. Duplication device (DISP) comprising electronic circuitry configured to perform the steps of the process according to any one of claims 1 to 6.
8. Server (SER) accessible via a remote network (WAN) comprising a duplication device (DISP) according to claim 7.
9. Gateway (GW1) of a primary local area network (LAN1) configured to manage said primary local area network (LAN1) to which at least one user device (UE1, UE2, UE3) is connected, said gateway being characterized in that it comprises a duplication device (DISP) according to claim 7.
10. Product computer program, comprising instructions causing a processor to execute the process according to one
11. any of claims 1 to 6, when said instructions are executed by the processor. Storage medium, storing a computer program comprising instructions causing a processor to execute the method according to any one of claims 1 to 6, when said instructions are read and executed by the processor.