A method for grouping 802.11 stations into authorized service sets to differentiate network access and services
21 claims: 1 independent, 20 dependent
- 1A method wherein Wireless stations, WSTAs, (208, 302) are partitioned into Service Sets, each Service Set comprising a Service Set Identifier and a network access parameter value, comprising the steps of:configuring an access point, AP, (102, 202) with a list of at least one service set identifier (104, 106, 108, 110) that identifies the service set the AP will accept;sending a message from the WSTA (208, 302) to its parent AP (102, 202), the message comprising an active service set identifier for the WSTA, wherein the service set identifier is selected from the group consisting explicitly identifying a service set, and a wildcard so that the WSTA's service set is selected by a network infrastructure;verifying by the parent AP (102, 202) that the parent AP has an service set identifier that matches the service set identifier sent by the WSTA;and authorizing the WSTA (208, 302) to use its service set identifier by a security (304) server and a security protocol;wherein service set parameters that determine the WSTA's (208, 302) at least one of the group consisting of virtual local area network, VLAN, and home subnet may be configured with different values for the same service set identifier in a different AP (102, 202).
43 paragraphs in 4 sections, as filed
BACKGROUND OF THE INVENTION
0001The present invention relates generally to network access and more particularly to a method and system to differentiate network access for different classes of users.
0002It is becoming increasingly important to differentiate network access for different classes of users, in particular different classes of wireless LAN users. One proposal for providing differentiated network access and services is that Access Points should implement a method wherein a Remote Authentication Dial-In User Server (RADIUS server) explicitly assigns an 802.11 station to a Virtual LAN identifier (VLAN ID) by returning a VLAN ID attribute in the RADIUS record for the station. Such RADIUS based VLAN assignment has limited scope and severely restricts mobility. A large or campus network may contain multiple VLANs that provide equivalent services. For example, a campus network may contain multiple Voice VLANS. If a RADIUS server explicitly assigns an 802.11 Voice over IP (VoIP) phone to a voice VLAN, then the phone is limited to a single voice VLAN, for example the phone may be limited to a VLAN on a single floor in a single building. The only method for segregating users is "VLAN trunking"; therefore, the proposal is generally limited to network areas with a VLAN infrastructure. Thus there exists a need for a method and system wherein multiple parameters can be grouped into a Service Set, which is controlled by a single RADIUS attribute that is not limited to a VLAN ID assignment.
0003For the purposes of describing the present invention, an "authorized WSTA" is any station that is explicitly authorized to access the network via a security server, and a "guest WSTA" is not explicitly authorized to access the network. A RADIUS server is used as an example security server in describing the present invention, but as those skilled in the a11 can readily appreciate the concepts of the present invention apply with any security server.
0004It should be noted that a "Service Set" as defined herein is not the same as an 802.11 Extended Service Set (ESS).
0005Additional objects, advantages and novel features of embodiments of the invention will be set forth in part in the description which follows, and in part will become apparent to those skilled in the art upon examination of the following or may be learned by practice of embodiments of the invention. The objects and advantages of embodiments of the invention may be realized and attained by means of instrumentalities and combinations particularly pointed out in the appended claims.
0006Document <patcit id="pcit0001" dnum="WO0163843A"><text>WO 01/63843</text></patcit> describes a method for accessing a network in a telecommunication system which comprises at least one terminal and a plurality of networks. Information sets describing settings needed to access networks and their resources are stored in the terminal. The terminal scans for information about available networks. Available information sets are determined by comparing the information about available networks to the stored information sets. At least one network is accessed based on the settings defined in the available information sets.
BRIEF SUMMARY OF THE INVENTION
0007In view of the aforementioned needs, described herein is a method for an access point to associate a wireless station to either a home subnet or a VLAN based on a configuration stored locally at the access point. When a wireless station desires to associate with an access point, the wireless station sends a message to the access point, the message containing a service set identifier (SSID), which is an arbitrary "name" for a service set. The access point then associates the wireless station to either a home subnet or a VLAN based on the SSID.
0008The method may also further comprise creating one or more service sets at the access point wherein each service set has a unique SSID. The access point upon receiving a message from a wireless station then matches the SSID of the message with a service set stored locally at the access point. After the access point confirms that it has a match for the SSID, the access point may then verify that the connection by the wireless station is authorized and that the station is authorized to use the SSID. This would typically be accomplished by using a security server such as a RADIUS server.
0009If the wireless station is currently bound to a remote home subnet, the access point enables communication between the wireless station and home subnet by tunnelling to the home subnet. Alternatively, the access point may bind the wireless station to a home subnet that is local to the access point.
0010In another embodiment, it is contemplated that the access point may send a list of subnets and/or VLAN's available for the SSID. The wireless station then selects a subnet or VLAN.
0011Another embodiment contemplates a computer-readable medium instructions for an access point to associate a wireless station. The computer-readable medium comprising means for creating a service set at the access point. The computer-readable medium further comprising means for receiving a message from a wireless station, the message containing an SSID. The computer-readable medium also comprising means for verifying the access point has a matching service set for the SSID. The computer-readable medium further comprises means for authenticating a wireless station by accessing a security server that is communicatively coupled to the access point. The computer-readable medium having means for associating the wireless station to either a VLAN or a home subnet based on the SSID. In an alternative embodiment, the security server returns a list of one or more SSIDs for which the station is authorized. The station is prevented from accessing the network if its SSID does not match one of the SSIDs in the list returned by the security server.
0012There is further contemplated an access point, comprising means for assigning one of the group selected from a VLAN and a subnet to a service set; means suitably adapted for receiving a message from a wireless station, the message further comprising a SSID; means suitably adapted to match the SSID to the service set; means suitably adapted for authenticating a wireless station by accessing a security server; means for associating the wireless station to one of the group consisting of a home subnet or VLAN based on the SSID, wherein the service set home subnet or VLAN parameter is configured locally at the access point.
0013The access point may also further comprise means for binding the wireless station to the home subnet, means for tunnelling to the home subnet. In the alternative, the access point may have means for binding the wireless station to a local subnet.
0014In an embodiment, there is contemplated an access point, comprising means for creating a service set at the access point; means for accessing the access point by sending a message from the wireless station to the access point, the message comprising a SSID; means for verifying the access point has a matching service set for the SSID; means for authenticating the wireless station by the access point accessing a security server that is communicatively coupled to the access point; means for providing the wireless station with a list of subnets available for the SSID; and wherein the service set is configured locally at the access point.
0015There is also contemplated an 802.11 network, comprising a first basic service set comprising a first access point, and a second basic service sets, comprising a second access point. The first access point comprises means for creating a service set at the first access point; means for receiving a message from the wireless station to the first access point, the message comprising a SSID; means verifying the first access point has a matching service set for the SSID; and means for associating the wireless station to a first home subnet based on the SSID. The second access point comprises means for creating a service set at the second access point; means for receiving a message from the wireless station to the second access point, the message comprising the SSID used in the message to the first access point; means verifying the second access point has a matching service set for the SSID; and means for associating the wireless station to a second home subnet based on the SSID, wherein the first home subnet is different than the second home subnet.
0016In an embodiment, there is contemplated an 802.11 network, comprising a first basic service set comprising a first access point, and a second basic service sets, comprising a second access point. The first access point comprises means for creating a service set at the first access point; means for receiving a message from the wireless station to the first access point, the message comprising a SSID; means verifying the first access point has a matching service set for the SSID; and means for associating the wireless station to a first VLAN based on the SSID. The second access point comprises means for creating a service set at the second access point; means for receiving a message from the wireless station to the second access point, the SSID used in the message to the first access point; means verifying the second access point has a matching service set for the SSID; and means for associating the wireless station to a second VLAN based on the SSID, wherein the first VLAN is different than the second VLAN.
0017Among those benefits and improvements that have been disclosed, other objects and advantages of embodiments of this invention will become apparent from the following description taken in conjunction with the accompanying drawings. The drawings constitute a part of this specification and include exemplary embodiments of the present invention and illustrate various objects and features thereof.
BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWING
0018The drawings illustrate a preferred mode presently contemplated of carrying out the invention.
0019This the drawings: <ul id="ul0001" list-style="none" compact="compact"><li><figref idref="f0001">FIG 1</figref> is a block diagram illustrating the relationship between an AP, SSID and VLAN or Proxy Mobile IP Host;</li><li><figref idref="f0002">FIG 2</figref> is a block diagram illustrating a wireless station moving from one basic service set controlled by a first access point set to a second basic service set controlled by a second access point;</li><li><figref idref="f0003">FIG 3</figref> is a block diagram illustrating the communications between a wireless station, access point, and a security server when a wireless station attempts to gain entry to a network;</li><li><figref idref="f0004">FIG 4</figref> is a block diagram illustrating the steps for configuring an access point;</li><li><figref idref="f0005">FIG 5</figref> is a block diagram showing the steps for a wireless station to associate with an access point..</li></ul>
DETAILED DESCRIPTION OF INVENTION
0020The present invention is set out in the independent claim appended hereto and preferred embodiments are set out in the dependent claims that follow.
0021Embodiments of the present invention contemplates a method where wireless stations (WSTAs) are partitioned into "Service Sets". A Service Set Identifier (SSID) identifies each service set. The SSID can be a standard 802.11 SSID.
0022A Service Set is an arbitrary grouping of one or more network service parameters. Service parameters may be used to differentiate network access for security purposes. For example, "guest" WSTAs that are restricted to secure "guest" subnets may be grouped into a "GUEST" Service Set. Service parameters may also be used to differentiate network services that are not necessarily related to security. For example, employee WSTAs that require a "Proxy Mobile IP" service for seamless campus mobility may be grouped into a "MOBILE-EMPLOYEE" Service Set.
0023Service Set authorization is accomplished in one of two ways. While the following examples use a RADIUS server, as those skilled in the art can readily appreciate, the authorization may be accomplished with any security server. First a RADIUS server can explicitly authorize a WSTA to join one or more Service Sets. In the first case, the RADIUS server returns a list of allowed SSID's in the RADIUS record for the WSTA. For backward compatibility with legacy 802.11 systems the absence of the SSID list can be interpreted asa list of all SSIDs. Second, a RADIUS server can explicitly assign a WSTA. to a Service Set. In that case, the RADIUS server returns an "assigned SSID" in the RADIUS record for the WSTA. Note that the first method enables the WSTA to change its active Service Set without requiring configuration changes to the RADIUS database.
0024A standard 802.11 WSTA sends an association message, which contains an 802.11 SSID, each time it associates with a parent AP. A WSTA is only associated if it successfully passes any authentication criteria that is defined for its SSID, and the WSTA is authorized to join the Service Set identified by its SSID or is explicitly assigned to a different SSID by the RADIUS server.
0025Unauthenticated "guest WSTAs" are assigned to a default guest Service Set, which may permit restricted access to the network.
0026Service set parameter values that determine a WSTA's home subnet are configured locally in wireless access points (APs) so that parameter values have local significance. For example, a campus network may have a voice VLAN in each building. A "VOICE" SSID can be bound to VLAN 10 in building 1 and VLAN 20 in building 2. A WSTA configured with the "VOICE" SSID can access any voice VLAN.
0027AP's determine current Service Set parameter values from SSID configuration values and WSTA 'context' information. For example, a WSTA may belong to a Service Set named "MOBILE" that has "seamless inter-subnet mobility" enabled. A "home subnet" may be configured for the "MOBILE" SSID in each AP. Initially, a "MOBILE" WSTA is bound to the home subnet configured for "MOBILE" in its parent AP. Thereafter, as the WSTA roams, it is seamlessly bound to its original home subnet, regardless of the "home subnet" configured for "MOBILE" in any new parent AP. A context transfer protocol is used to transfer the WSTA's home subnet context to a new parent AP.
0028The home subnet bindings for a "MOBILE" WSTA can be aged and discarded after the WSTA becomes inactive for some period of time so that the WSTA can be bound to a different, more optimal, home subnet when it becomes active again.
0029A WSTA's home subnet can be automatically derived by "snooping" the source IP address in IP packets transmitted by the WSTA rather than using an access point service set parameter value to bind the WSTA to a home subnet. In that case, an SSID/home-subnet database is used to determine if the WSTA is authorized to access the home subnet that corresponds to its IP address. The SSID/home-subnet database contains a list of "allowed" subnets for each SSID. The database can be statically configured. Alternatively, APs can automatically determine the subnet address for each subnet that is accessible via one of its configured SSIDs. Note that the subnet address for an SSID may not be the same in different APs. The list of allowed subnets for each SSID is the aggregate of the local SSID/subnet bindings in all APs. (This method is necessary to support WSTA's with a permanent IP address. It is also necessary to re-establish home subnet bindings that have been aged and discarded.)
0030By using the Service Set method as described herein, a WSTA can be assigned to a specific VLAN ID. However this method is not limited to VLAN ID assignment. Instead, multiple parameters can be grouped into a single Service Set, which may be controlled by a single RADIUS or other security server attribute. Because the Serve Set parameters are instantiated locally in parent AP's, the Service Set parameters can be set to values that are 15 optimal for the local network topology and current WSTA context. For example, either VLAN trunking or Proxy Mobile IP tunnelling can be used, as is locally appropriate, to restrict guest WSTAs to a secure guest subnet.
0031Another feature that may be incorporated with embodiments of the present invention is that a WSTA can change its Service Set without requiring changes to its RADIUS configuration. For example, a WSTA can inhibit seamless mobility, for example when it is running a non-IP application that prohibits inter-subnet mobility, by changing its active SSID to one that does not have Proxy Mobile IP enabled.
0032The method of embodiments of the present invention may be implemented by using the standard 802.11 SSID, therefore, no changes are required to existing to WSTAs to obtain the benefits of the present invention.
0033Referring now to <figref idref="f0001">Figure 1</figref>, there is shown an AP 102. The AP 102 as shown has for SSID numbers, 104, 106, 108, 110. Each SSID number 104, 106, 108, 110 has a corresponding parameter 112, 114, 116, 118 assigned to it. For example, the AP 102 will associate VLAN 112 with SSID1 104 VLAN2 114 with SSID2 106, Prox Mobile IP Home Agent 1 116 with SSID3 108, and Proxy Mobile IP Home Agent 2 118 with SSID4 110.
0034<figref idref="f0002">Figure 2</figref> shows an Extended Service Set (ESS) 200. The ESS comprises two basic service sets (BSS) 204 and 206. AP 102 controls BSS 204 and AP 202 controls BSS 206. A WSTA 208 is shown that travels a path 212 from BSS 204 to BSS 206. As contemplated herein, when WSTA 208 associates with each AP 102 and 202, it sends an SSID (not shown) to the AP 102 or 202. Because each AP is individually configured, when WSTA is associated with AP 202 it may be bound to a different VLAN or Proxy Mobile IP Home Agent than it was when it was associated with AP 102.
0035Referring now to <figref idref="f0003">Figure 3</figref> there is shown a WSTA 302 attempting to gain access to AP 102. A message is sent from WSTA 302 to the AP 102. The AP 102 then attempts to authenticate the WSTA 302 by sending authentication message 306 comprising the WSTA 302 and the WSTA' s SSID to security server 304. If the security server 304 authenticates WSTA 302, it then sends a message 308 containing parameters for the WSTA 302 to the AP 102.
0036<figref idref="f0004">Figure 4</figref> shows an exemplar of a method that can be used for configuring an AP for use with embodiments of the present invention. The process begins by defining a configuration at step 402. At step 404 the authentication criteria is defined. At step 406 the Service Sets and Identifiers are defined. Then as shown at step 408, for each ID which maybe done either at the same time the for Service Set are defined or separately, the parameters for each SSID are defined. As shown in step 410 Proxy Mobile IP is either configured or disabled for each SSID. As shown in step 412, if Proxy Mobile IP is enabled, then the default home subnet is configured as shown at step 414. If Proxy Mobile IP is disabled, then the default VLAN ID is configured as shown at 416. If there are more Service Sets to configure, then as shown in step 418 processing returns to step 410, otherwise, as shown in step 420 the process is completed.
0037In <figref idref="f0005">Figure 5</figref> there is shown a procedure 500 contemplated herein for a WSTA 208 to associate with an AP 102. Beginning at step 502, the WSTA 208 accesses the AP 102 by sending a message to the AP 102, the message including a SSID (SSID). As shown in step 504, the AP 102 checks to ascertain if it has a matching SSID. If the AP 102 does not have a matching SSID, then as shown in step 506 the AP 102 does not allow the connection.
0038If the AP 102 does have a matching SSID, then the AP determines at step 508 if the association is allowed for the WSTA 208. This can be done by accessing a security server, such as a RADIUS server. For example, when the RADIUS server is accessed, the RADIUS server returns a list of allowed SSIDs. The association for the WSTA is only allowed if the WSTA's SSID is in the list. This prevents unauthorized access to a service set that is supported in the AP. If the association is not allowed, then at step 510 the AP does not allow the connection.
0039If the AP 102 does have a matching SSID and the WSTA 208 is allowed to associate, then the AP 102 determines whether to associate the WSTA 208 by Subnet or VLAN. If the association is by subnet, then the AP 102 binds the WSTA 208 to the home subnet 514. At step 516 the AP 102 determines if it can tunnel to the home subnet, if it can than the process is completed as shown in step 518.
0040If the AP 102 can not tunnel to the home subnet at step 516, then the AP 102 can bind the WSTA 208 to a local subnet as shown in step 520. Then as shown in step 518, the process is completed.
0041If at step 512 it is determined that the WSTA 208 is to be bound to a VLAN, then the procedure goes to step 522 wherein the WSTA 208 is bound to a VLAN. Then the procedure is completed as shown in step 518.
0042While in the description of the process of <figref idref="f0005">Figure 5</figref> the process terminates after associating the WSTA 208 to either a subnet or VLAN, as those skilled in the art can readily appreciate, other parameters may be configured at this point in time. As the WSTA 208 associates with another AP 202, the process is repeated. Because each AP 102, 202 has its own separate bindings for the Service Sets, when a WSTA 208 moves from one AP 102, to another AP 202, the VLAN or subnet that the WSTA 208 is bound to may change.
0043Although the invention has been shown and described with respect to a certain preferred embodiment, it is obvious that equivalent alterations and modifications will occur to others skilled in the art upon the reading and understanding of this specification. The present invention includes all such equivalent alterations and modifications and is limited only by the scope of the following claims.
Contents4
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| EP0917318A2 | Cites | European Patent Office (EPO) |
| WO0163843A1 | Cites | World Intellectual Property Organization (WIPO) |
| US6097960A | Cites | United States of America |
| US6181927B1 | Cites | United States of America |
| US6181935B1 | Cites | United States of America |
| US6332077B1 | Cites | United States of America |
| US6577643B1 | Cites | United States of America |
30 members in 6 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 212193 | United States of America | – | |
| 21219302 | United States of America | A | |
| 0322982 | United States of America | W |
Members30
| Document | Office | Kind | |
|---|---|---|---|
| CA2526978A1 | Canada | A1 | |
| WO2004013986A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003254133A1 | Australia | A1 | |
| US2005060319A1 | United States of America | A1 | |
| EP1529352A1 | European Patent Office (EPO) | A1 | |
| US2005185626A1 | United States of America | A1 | |
| US6950628B1 | United States of America | B1 | |
| US2005243860A1 | United States of America | A1 | |
| WO2005112316A2 | World Intellectual Property Organization (WIPO) | A2 | |
| CA2582977A1 | Canada | A1 | |
| WO2006039087A2 | World Intellectual Property Organization (WIPO) | A2 | |
| EP1743442A2 | European Patent Office (EPO) | A2 | |
| WO2005112316A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1794669A2 | European Patent Office (EPO) | A2 | |
| CN101084663A | China | A | |
| WO2006039087A3 | World Intellectual Property Organization (WIPO) | A3 | |
| AU2003254133B2 | Australia | B2 | |
| US7493084B2 | United States of America | B2 | |
| CN101390408A | China | A | |
| US7760692B2 | United States of America | B2 | |
| US2010246551A1 | United States of America | A1 | |
| EP1794669A4 | European Patent Office (EPO) | A4 | |
| EP1529352A4 | European Patent Office (EPO) | A4 | |
| CN101084663B | China | B | |
| CA2526978C | Canada | C | |
| US8693450B2 | United States of America | B2 | |
| CA2582977C | Canada | C | |
| EP1743442A4 | European Patent Office (EPO) | A4 | |
| EP1743442B1 | European Patent Office (EPO) | B1 | |
| EP1529352B1This record | European Patent Office (EPO) | B1 |
66 legal events, as 9 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent lapsedLapsedMM4A | MM4A | IE | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Fee paymentPLFP | PLFP | FR | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Deletion acc. to par. 5 (withdrawal of the translation of the ep patent)MK05 | MK05 | AT | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent invalid in the netherlands as no translation has been filedMP | MP | NL | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04B0005000000R079 | R079 | DE | |
| First examination report despatched17Q | 17Q | EP | |
| Supplementary search report drawn up and despatchedA4 | A4 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1529352
- Application
- 37668894
Titles3
- German
- VERFAHREN ZUR GRUPPIERUNG VON 802.11-STATIONEN IN GRUPPEN AUTORISIERTER DIENSTE ZUR UNTERSCHEIDUNG VON NETZWERKZUGANG UND DIENSTEN
- English
- A METHOD FOR GROUPING 802.11 STATIONS INTO AUTHORIZED SERVICE SETS TO DIFFERENTIATE NETWORK ACCESS AND SERVICES
- French
- PROCEDE SERVANT A REGROUPER DES STATION 802.11 EN ENSEMBLES DE SERVICES AUTORISES AFIN DE DIFFERENTIER L'ACCES AU RESEAU ET LES SERVICES
Classification
- CPC, 8
- H04L63/104
- H04L12/4641
- H04W4/08
- H04W12/08
- H04W28/18
- H04W80/04
- H04W84/12
- H04W72/27
- IPC, 5
- H04L12 46
- H04W12 08
- H04L29 06
- G01S19 25
- H04L12 28
Designated states27
- Contracting states, 27
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Romania
- Sweden
and 3 moreShow fewer
- Slovenia
- Slovakia
- Türkiye
