Public access point
Abstract
Problem to be solved.To provide a security model for a wireless LAN capable of supporting sharing of a single physical BSS by a station without inducing vulnerabilities or compromising the security of the station. The present invention instantiates a personal VLAN bridge using IEEE standard 802.11 elements. The result is a bridge called a public access point that is better suited for running public wireless data networks than the IEEE standard 802.11 architecture. The present invention provides a location update protocol for updating the forwarding table of a bridge that connects public access points together. The present invention further provides a method for providing more controlled bridging, called fine bridging. [Selection diagram] Fig. 3

Term
Projected expiry 18 March 2030.
- Priority
- Filed
- Published
- Today
- Projected expiry
41 claims: 3 independent, 38 dependent
- 1無線LANのセキュリティ装置であって、 複数の端末と、 単一の物理アクセスポイント(AP)内から複数の仮想ベーシックサービスセット(BSS)を提供する公衆アクセスポイント(PAP)とを備え、 各仮想BSSは、暗号化キーおよび認証コードキーを備えた固有のセキュリティアソシエーションを共有する一組の端末を備え、 前記PAPは、各前記一組の端末に複数の物理アクセスポイント、各仮想BSSにつき1つのAP、として見えることを特徴とするセキュリティ装置。
- 2請求項1に記載の装置であって、 前記PAPは、複数の別個のLANセグメントを提供すると共に、前記LANセグメントの各々について別個のリンクプライバシーおよび完全性を提供することを特徴とする装置。
- 3請求項1に記載の装置であって、前記端末のすべて、任意のローカルファイルサーバおよび前記LANと関連付けられた他のデバイスは、仮想アクセスポイントと関連付けられ、すべての仮想アクセスポイントは、同じ物理PAPから生じることを特徴とする装置。
- 4請求項1に記載の装置であって、 複数のPAPと、 前記PAPを接続するブリッジの転送テーブルを更新するロケーションアップデートプロトコルと をさらに備えたことを特徴とする装置。
- 5請求項1に記載の装置であって、 仮想BSSに属するすべての前記端末間で通信を制限するファインブリッジ方法をさらに備えたことを特徴する装置。
- 6無線LANのセキュリティ装置であって、 複数の802.11端末と、 公衆アクセスポイント(PAP)であって、前記PAPが単一の物理アクセスポイント(AP)内から仮想802.11ベーシックサービスセット(BSS)にインスタンス化されたパーソナル仮想ブリッジLANを備え、各仮想802.11BSSが暗号化キーおよび認証コードキーを備えた固有のセキュリティアソシエーションを共有する1組の端末を備える、PAPと を備えたことを特徴とする装置。
- 7セキュアな無線ネットワークであって、 仮想802.11ベーシックサービスセット(BSS)と、 局の各々がハードウェア(MAC)アドレスを有する複数の局と、 グループセキュリティアソシエーションを共有する前記BSSの1組の局であって、前記グループセキュリティアソシエーションは暗号化キーおよび認証コードキーを備える、1組の局と、 公衆アクセスポイント(PAP)を備える前記仮想BSS内の前記局の1つと を備えたことを特徴とするネットワーク。
- 8請求項6に記載のネットワークであって、前記仮想BSS内の前記局のまさに1つは、802.11無線媒体(WM)および802.11分散システム媒体(DSM)をブリッジする公衆アクセスポイントであることを特徴とするネットワーク。
- 9請求項6に記載のネットワークであって、前記グループセキュリティアソシエーションは、 前記仮想BSS内のあらゆる局について固有のユニキャストセキュリティアソシエーションをさらに備え、 前記セキュリティアソシエーションは、前記仮想BSSの各局と前記PAPとの間で共有されることを特徴とするネットワーク。
- 10請求項6に記載のネットワークであって、 各仮想BSSはそれ自体の識別子(BSSID)を有する、複数の仮想BSSをさらに備えたことを特徴とするネットワーク。
- 11請求項10に記載のネットワークであって、前記BSSIDは、 前記仮想BSSの仮想MACアドレスを備えたことを特徴とするネットワーク。
- 12請求項11に記載のネットワークであって、前記PAPは、その仮想MACアドレスの1つに行くことになっている802.11無線媒体(WM)からのフレームを受信し、前記PAPは、前記フレームのソースMACアドレスとしてその仮想MACアドレスの1つを使用して前記WMへのフレームを送信することを特徴とするネットワーク。
- 13請求項6に記載のネットワークであって、 単一のPAPにおいて、共用TSF(タイミング同期化機能)、DCF(分散調整機能)およびオプションとしてPCF(ポイント調整機能)によってサポートされる複数の仮想BSSをさらに備えたことを特徴とするネットワーク。
- 14請求項6に記載のネットワークであって、各PAPは、 単一のNAV(ネットワークアロケーションベクトル)およびPC(ポイント調整部)をさらに備えたことを特徴とするネットワーク。
- 15請求項6に記載のネットワークであって、PAPは、複数の仮想BSSに属し得ることを特徴とするネットワーク。
- 16請求項6に記載のネットワークであって、PAPではない任意の局は、多くて1つの仮想BSSに属し得ることを特徴とするネットワーク。
- 17請求項6に記載のネットワークであって、 各仮想BSSのPAPの接続により仮想BSSを別の仮想BSSとブリッジする仮想ブリッジLAN(VLAN)をさらに備えたことを特徴とするネットワーク。
- 18請求項17に記載のネットワークであって、各仮想BSSのPAPは、VLAN認識ブリッジのトランクされた、またはタグ付けされていないポートを介して分散システム(DS)に接続することを特徴とするネットワーク。
- 19請求項18に記載のネットワークであって、前記DSに送信されたフレームは、分散システム媒体(DSM)に知られているVLANタグを担持することを特徴とするネットワーク。
- 20請求項19に記載のネットワークであって、前記PAPは、VLANタグを仮想BSS識別子(BSSID)にマップするDSM VLANマッピングを維持することを特徴とするネットワーク。
- 21請求項6に記載のネットワークであって、前記仮想BSSは、 クラス-1およびクラス-3仮想BSSのいずれかを備え、 PAPは、まさに1つのクラス-1仮想BSSおよび1つ以上の多重クラス-3仮想BSSをサポートし、 クラス1仮想BSSは、前記PAPによって規律されるように、802.11の状態1または2にある間、局が占めることを許される唯一の仮想BSSであり、 状態3にあるとき、局は、クラス-3仮想BSSにジョインすることを許され、 クラス-3仮想BSSは、前記局を認証するために使用された種類の認証によって判定されることを特徴とするネットワーク。
- 22請求項21に記載のネットワークであって、クラス-1仮想BSSIDは、そのようなフィールドを有するあらゆるクラス1およびクラス2フレームのBSSIDフィールドであることを特徴とするネットワーク。
- 23請求項21に記載のネットワークであって、クラス-1仮想BSSIDは、適切な場合にはクラス1およびクラス2フレームの受信機または送信機アドレスフィールドであることを特徴とするネットワーク。
- 24請求項6に記載のネットワークであって、あらゆる仮想BSSは、タイムスタンプ、ビーコン間隔、能力情報プライバシー(保護)ビット、サービスセット識別子(SSID)、セキュリティ能力要素、およびトラフィック指示マップ(TIM)要素フィールドを除いて、同一のビーコンフレームコンテンツを有することを特徴とするネットワーク。
- 25請求項21に記載のネットワークであって、前記PAPは、そのBSS内の端末についてパワーセーブ(PS)モードをサポートしていなければ、クラス3仮想BSSについてビーコンしなくてもよく、 前記PAPがクラス-3BSSについてビーコンする場合は、あらゆるビーコンのSSID要素は、ブロードキャストSSIDを指定し、 クラス-3仮想BSSは、ビーコンすることを通じて識別されることから防止されることを特徴とするネットワーク。
- 26請求項25に記載のネットワークであって、クラス-1仮想BSSビーコンのみは、非ブロードキャストSSIDフィールド付きのSSID要素を有し、 局は、クラス-1仮想BSSのみと関連付け得ることを特徴とするネットワーク。
- 27請求項21に記載のネットワークであって、あらゆる局は、デフォルトでPAPにおけるクラス-1仮想BSSのメンバであり、 前記PAPは、前記クラス-1仮想BSSにおいて前記局のユーザまたは前記局自体のいずれかを認証することができ、 成功した場合、前記局は、前記PAPにおいて802.11状態2に入り、 前記PAPおよび前記局は、その後、前記クラス-1仮想BSSにある間、クラス1およびクラス2フレームを交換し得ることを特徴とするネットワーク。
- 28請求項27に記載のネットワークであって、クラス2フレームは、前記局および前記PAPが成功認証の後にユニキャストセキュリティアソシエーションを共有する場合、暗号的に保護されることを特徴とするネットワーク。
- 29請求項28に記載のネットワークであって、前記PAPおよび前記局は、認証の後にグループセキュリティアソシエーションを共有し、 前記グループセキュリティアソシエーションは、前記PAPと802.11アソシエーションを完了した場合、前記局が属するクラス-3仮想BSSについてのものであることを特徴とするネットワーク。
- 30請求項29に記載のネットワークであって、前記局および前記PAPがクラス3フレームを交換できる前に、前記局は、状態2から前記クラス-1仮想BSSとのアソシエーションをリクエストし、クラス-3仮想BSSに切り替えなければならないことを特徴とするネットワーク。
- 31請求項30に記載のネットワークであって、前記PAPは、ソースアドレス(アドレス2フィールド)またはBSSID(アドレス3フィールド)がその仮想BSSのクラス-3仮想BSSIDであるアソシエーション応答MMPDUで前記局のアソシエーションリクエストに応答することによって、前記局をクラス-3仮想BSSに切り替えることを特徴とするネットワーク。
- 32請求項31に記載のネットワークであって、前記クラス-3仮想BSSは、 前記DSにおける認証サーバは、ユーザのDSM VLANを指定し、前記PAPはそれをクラス-3仮想BSSIDにそのDSM VLANマッピングを使用してマップすること、 前記DSにおける認証サーバは、そのユーザのクラス-3仮想BSSを指定すること、または 前記PAPは、前記ユーザの新しいクラス-3仮想BSSを作成することであって、前記PAPは、認証サーバに新しい仮想BSSについて知らせ、他の局が前記新しいBSSにジョインできるようにするルールを提供すること のいずれかの方法で判定されることを特徴とするネットワーク。
- 33請求項21に記載のネットワークであって、クラス-1仮想BSSは、802.11ビーコンまたはプローブ応答マネージメントフレームを通じて発見され、BSSIDフィールド(アドレス3フィールド)およびソースアドレスフィールド(アドレス2フィールド)は各々クラス-1仮想BSSIDに設定されることを特徴とするネットワーク。
- 34請求項21に記載のネットワークであって、前記PAPは、MACプロトコルデータユニット(MPDU)ブリッジプロトコルを実装し、前記DSMまたは前記WMのいずれかから受信したMPDUについて、前記プロトコルは、 前記DSMから受信したMPDUであって、 受信したMPDUはVLANタグを有しないか、空のVLANタグを有し、 前記MPDUの目的アドレスが前記仮想BSSに属する局のアドレスであり、前記局が前記PAPと関連付けられているか、 前記MPDUの目的アドレスがグループアドレスであり、前記仮想BSSが前記グループに属する局を有し、前記局が前記PAPと関連付けられている場合、前記DSMからの前記MPDUは、仮想BSSにリレーされ、または、 受信したMPDUは非空のVLANタグを有し、 前記MPDUがリレーされる前記仮想BSSは、前記非空のVLANタグが前記PAPのDSM VLANマッピングのもとでマップされる前記仮想BSSによって識別され、 前記マッピングがある与えられたタグについて未定義である場合、前記MPDUはリレーされず、 受信したMPDUがリレーされる任意の仮想BSSは、その仮想BSSにリレーされる802.11MPDUのソースアドレス(アドレス2フィールド)を形成するBSSIDを有する、MPDU、または 前記WMから受信したMPDUであって、 前記MPDUの目的アドレス(アドレス3フィールドのMPDU)が識別されたBSSに属する局のアドレスであり、前記局が前記PAPと関連付けられているか、 前記MPDUの目的アドレスがグループアドレスである場合、受信した802.11MPDUは、前記MPDUのアドレス1フィールドによって識別される仮想BSSにリレーされ、 そうでなければ、前記フレームは、いかなる仮想BSSにもリレーされず、 受信した802.11MPDUのアドレス1フィールドは、前記アドレス1フィールドによって識別される前記仮想BSSにリレーされる802.11MPDUのソースアドレス(アドレス2フィールド)である、MPDU のいずれかにアドレスすることを特徴とするネットワーク。
- 35請求項34に記載のネットワークであって、前記目的アドレス(MPDUのアドレス3フィールド)が前記PAPと関連付けられていない局のアドレスである場合にも、前記受信したMPDUは、前記DSMにリレーされ、または 前記目的アドレスがグループアドレスである場合、 前記DSMにリレーされた前記MPDUは、前記DSがVLAN認識であれば、VLANタグを有し、そうでなければタグ付けされず、 前記VLANタグは、前記PAPのDSM VLANマッピングのもとで前記受信したMPDUの前記アドレス1フィールドのプリイメージであることを特徴とするネットワーク。
- 36請求項21に記載のネットワークであって、 サブタイプアソシエーションリクエスト/応答、再アソシエーションリクエスト/応答、ディスアソシエーションおよび脱認証の802.11データ・フレームおよびマネジメントフレームを適用することによって暗号および複合を行う手段をさらに備えたことを特徴とするネットワーク。
- 37請求項36に記載のネットワークであって、802.11データまたはマネージメントフレームを前記WMに送る前に前記PAPによって使用される前記暗号プロセスは、 前記フレームのセキュリティアソシエーションを識別し、 その後、前記アソシエーションを使用して、暗号化および認証コードプロトコルによる送信のための拡張されたフレームを構築する ステップを行うメカニズムを備えたことを特徴とするネットワーク。
- 38請求項37に記載のネットワークであって、フレームの目的アドレス(アドレス1フィールド)が局のアドレスである場合、その局および前記PAPの間で共有されるユニキャストセキュリティアソシエーションは、前記フレームの拡張において使用され、 前記フレームがデータフレームであり、その目的アドレスがグループアドレスである場合、前記MPDUブリッジプロトコルは、前記フレームの目的仮想BSSを識別し、前記識別された仮想BSSのグループセキュリティアソシエーションは、前記フレームの拡張において使用されることを特徴とするネットワーク。
- 39請求項38に記載のネットワークであって、非PAP局は、その仮想BSSにおける前記PAPと共有するユニキャストセキュリティアソシエーションを使用してタイプデータまたはマネージメントの802.11MPDUを前記DSMに送信することを特徴とするネットワーク。
- 40請求項39に記載のネットワークであって、前記WMから802.11データまたはマネージメントフレームを受信するとき、前記PAPは、前記MPDUのソースアドレス(アドレス2フィールド)によって識別される局のユニキャストセキュリティアソシエーションを使用して復号し、前記フレームの完全性を検証することを試みることを特徴とするネットワーク。
- 41請求項40に記載のネットワークであって、前記PAPからタイプデータまたはマネージメントの802.11MPDUを受信するとき、非PAP局は、前記フレームの目的アドレス(アドレス1フィールド)が前記局のアドレスである場合、前記PAPと共有するユニキャストセキュリティアソシエーションを使用して、および前記フレームの前記目的アドレスがグループアドレスである場合、そのクラス-3仮想BSSのグループセキュリティアソシエーションを使用することによって復号し、前記フレームの完全性を検証することを特徴とするネットワーク。
Independent claims41
52 paragraphs, as filed
Technical field The present invention relates to wireless public access to electronic networks. In particular, the present invention relates to an architecture that allows the creation of a virtual basic service set from within a physical access point to an electronic network.
Public WiFi hotspots are deployed using traditional IEEE standard 802.11 compliant access points, with a few exceptions. However, the IEEE standard 802.11 architecture and security model are unsuitable for public use. The stations associated with the access point (AP) share the 802.11 Basic Services Set (BSS) or wireless LAN. No station in the BSS is safe against attacks initiated by other members unless all members of the BSS are credible. Attacks of this type also include stealing basic services and any confidential information provided by subscribers to obtain services, such as password and credit card information. Other attacks include disrupting network integrity and quality of service. It is impractical to consider the public BSS, that is, all members of what consists of stations associated with public APs, to be credible. Therefore, stations are vulnerable to public BSS.
Sharing the public BSS also poses other threats. BSS members may contaminate other member stations with warm or Trojan horses. Port-based DCOM RPC attacks, MS blasters and Welchia warms are good examples. This threat is exacerbated by the public BSS, which is an electronic sewage reservoir. How can the agency deal with these threats? Stations in the BSS may protect themselves with defenses such as private firewalls. Public WiFi providers, on the other hand, may deploy security models that protect subscribers from each other. One approach is to ban inter-station communication. This approach, however, is an unsupportable solution. Stations that trust each other should be allowed to communicate between themselves, even in public settings. For example, the station must be able to access a file server on the same local LAN at a meeting held at a convention center. For example, this is what is normally done in a standard meeting. If this kind of sharing is allowed, the intruder will use the IEEE. Under standard 802.11, it will be easy to disable the entire BSS. This was demonstrated at the 2001 Yousenix Security Conference and the 2001 DEFCON Conference in Las Vegas. No security model for any wireless LAN today can support this type of sharing without leading to vulnerabilities.
It is advantageous to provide a security model for wireless LANs that can support the sharing of a single physical BSS without inducing vulnerabilities or compromising security between stations using BSS. There will be.
<p> The present invention provides a security model for wireless LANs that can support the sharing of a single physical BSS by a station without inducing vulnerabilities or compromising the security of the station. Thus, a new kind of access point is provided. And it is referred to herein as a public access point (PAP). PAP has a different security architecture than that specified by IEEE Standard 802.11. The PAP architecture allows the creation of virtual basic service sets from within a single physical AP. Any number of virtual service sets can be created, and any number of terminals can be attributed to the virtual BSS. The PAP appears to the terminal as multiple physical 802.11 access points, one for each virtual BSS. Therefore, PAPs are fully interoperable with any 802.11 terminal.</p><p> Consider a convention center as an example of using PAP. Different conferences may use 802.11 standard projectors. PAP provides separate link privacy and integrity for each, allowing separate LAN segments to be provided for each conference. Using only the IEEE standard 802.11 instead, the conference projector and all stations that can be projected using it use a private access point or ad hoc WLAN, and WLAN membership, authentication and keying. You have to manage the keying material. Otherwise, anyone can project with the projector, or worse, intercept valid projector traffic before it is displayed and it will be monitored by outsiders. , Could be modified.</p><p> In addition to the overwhelming security management burden associated with traditional approaches, conference planners utilize local access points rather than installing and configuring their own access points for each venue. I like that. PAP can manage all security. Thereby, all terminals in each conference, including shared projectors and any local file server, are efficiently associated with virtual 802.11 access points for that conference, and all virtual basic access points have the same physical. It arises from PAP.</p><p> The present invention also provides a location update protocol for updating the forwarding table of a bridge that connects public access points together.</p><p> The present invention also provides a method for more controlled bridging called fine bridging.</p>
<figref num="1">It is a schematic diagram of an IEEE standard 802.11 protocol entity.</figref><figref num="2">It is a block diagram of the configuration infrastructure of IEEE standard 802.11.</figref><figref num="3">It is a schematic diagram of the public access point architecture according to this invention.</figref><figref num="4">It is a block diagram of the policy for accessibility within the virtual BSS of three stations, one of which is an AP, according to the present invention.</figref><figref num="5">According to the present invention, stations A and B share server stations S and D, but A and B are block diagrams of a policy between four stations that are not allowed access to each.</figref><figref num="6">It is a block diagram of the policy modified by this invention so that the edge from B to A is added to the policy in FIG.</figref><figref num="7">A block diagram of an IEEE standard 802.1Q bridge that eliminates direct communication between edge hosts connected to an infrastructure system via port-based VLAN allocation, egress filtering, and shared VLAN learning (SVL). is there.</figref>
U.S. Patent Application No. 10 / 057,566 states a virtual bridge LAN (VLAN) in which a terminal clones an existing VLAN by duplicating a member set that is tagged and untagged with the existing VLAN. The protocols on which you can create are described. In addition, this new VLAN is unique because of its unique security association. This association provides a cryptographic keying material that keeps packets belonging to a VLAN private and allows VLAN membership to be cryptographically verified by a keyed MAC. This new VLAN is owned by its creator. This owner controls which stations can join, which stations can discover the VLAN, and the lifetime of the VLAN. Therefore, the VLAN is called a personal virtual bridge LAN (PVLAN).
An embodiment of the present invention provides an improved version of PVLAN that uses only the standard elements of IEEE Standard 802.11-1999. (See Part 11: Wireless LAN Media Access Control (MAC) and Physical Layer (PHY) Specifications, ISO / IEC 8802-11: 1999 (E) ANSI / IEEE Standard 802.11, 1999 Edition, and Part 11: Wireless LAN Media Access Control (MAC) and Physical Layer (PHY) Specifications, Media Access Control (MAC) Security Enhancements, Draft Amendments to IEEE Standard 802.11i / D7.0, ISO / IEC 8802-11,1999 (E) , ANSI / IEEE standard. 802.11, 1999 edition. ) Figure 1, which is a block diagram of IEEE standard 802.11 protocol entities, and where each BSS (BSS-A, BSS-B) is associated with its access point (AP-A, AP-B) (AP-A, AP-B). See Figure 2, which is a block diagram of an IEEE standard 802.11 configuration infrastructure with A1 / A2, B1 / B2). Modifications to the behavior of any 802.11 standard compliant terminal that does not act as an access point are unnecessary in the present invention. The improvements instantiate PVLANs for virtual 802.11 BSS and only affect access points.
FIG. 3 is a block diagram of the public access point architecture according to the present invention. Virtual 802.11 BSSs, such as BSS-1 or BSS-2, have a set of stations that share a unique security association, called a group security association, each with a hardware (MAC) address (see Figure 1). ). The security association consists of an encryption key and an authentication code key.
Exactly one of the stations in the virtual BSS is the public access point 31 (PAP). It bridges 802.11 wireless media (WM) 32 and 802.11 distribution system media (DSM) 33.
A unique unicast security association exists for every station in the virtual BSS. It is shared between the virtual BSS station and the PAP.
Each virtual BSS, such as BSS-1 or BSS-2, has its own identifier, the BSSID. It is the virtual MAC address of the PAP that belongs to that BSS. The PAP receives any frame from the WM destined for one of its virtual MAC addresses and uses one of its virtual MAC addresses as the source MAC address of the frame to frame the WM. To send.
A group of virtual basic services sets are supported by a shared TSF (timing synchronization function), DCF (distributed adjustment function), and optionally PCF (point adjustment function) in a single PAP. In each PAP, there is a single NAV (Network Allocation Vector) and PC (Point Coordinator). This type of sharing is possible because the 802.11 virtual carrier detection and media reservation mechanism is designed to work with multiple basic service sets that use the same channel overlap. This type of overlap can occur between virtual basic service sets supported by a single channel PAP. Virtual service sets can use one channel and can be overlapped in the PAP.
A PAP can belong to one or more virtual BSSs. See BSS-1 and BSS-2 on Figure 1. Any station that is not a PAP can belong to at most one virtual BSS.
Virtual 802.11 BSSs can be bridged with other virtual BSSs through the connection of their public access points via a virtual bridge LAN. The PAP of each virtual BSS connects to the distribution system (DS) through a trunked or untagged port on the VLAN-aware bridge. Frames sent to the DS can carry VLAN tags known to the DSM. The PAP may maintain a DSM VLAN mapping that maps the VLAN tag to the virtual BSSID.
Currently, there are two types of virtual BSS: Class-1 and Class-3 virtual BSS. The PAP supports exactly one Class-1 virtual BSS and one or more Multiple Class-3 virtual basic service sets. As managed by the PAP, a Class-1 virtual BSS is the only virtual BSS that a station is allowed to occupy while in state 1 or 2 of 802.11. When in state 3, the station is allowed to join a class-3 virtual BSS. Class-3 virtual BSS can be determined, for example, by authentication such as an open system or shared key used to authenticate a station.
A class-1 virtual BSSID is a BSSID field for any Class 1 and Class 2 frame that has this type of field. It is also a receiver or transmitter address field for Class 1 and Class 2 frames, where appropriate.
All virtual BSSs have the same Beacon Frame Content, except for Timestamp, Beacon Interval, Capability Information Privacy (Protection) Bits, Service Set Identifier (SSID), Security Capability Elements, and Traffic Direction Map (TIM) Element fields. Has.
The PAP does not need to send a beacon to a Class-3 virtual BSS if it does not support PS (Power Save) mode for the terminal in that BSS. If it is sending a beacon to a Class-3 virtual BSS, the SSID element of every beacon specifies the broadcast SSID. These steps prevent any Class-3 virtual BSS from being identified by the beacon.
Only Class-1 Virtual BSS Beacons have SSID elements with non-broadcast SSID fields. Stations can only be associated with class-1 virtual BSS. This station uses the non-broadcast SSID in the SSID element of the association or reassociation request frame.
U.S. Patent Application No. 10/057566 identifies PVLAN joins and discovery steps. PVLANs, represented as virtual BSS, instantiate these steps as follows:
join By default, every station is a member of a Class-1 virtual BSS with a PAP. The PAP can authenticate either the station user or the station itself in a Class-1 virtual BSS. If successful, the station enters 802.11 state 2 at that PAP. At this time, the PAP and the station may exchange class 1 and class 2 frames while in the class-1 virtual BSS.
Class 1 frames are not cryptographically protected. After successful authentication, Class 2 frames can be cryptographically protected if the station and PAP share a unicast security association. PAPs and stations can also share group security associations after authentication. The Group Security Association is for that Class-3 virtual BSS to which the station belongs once it completes the PAP and 802.11 association.
Before the station and PAP can exchange class 3 frames, the station 1) Request an association with a Class-1 virtual BSS from state 2 and 2) Must switch to Class-3 Virtual BSS.
The PAP classifies a station by responding to a station's association request with an association response MMPDU whose source address (address 2 field) or BSSID (address 3 field) is a class-3 virtual BSSID for that virtual BSS. Switch to virtual BSS. The ability information field of the association response may have its privacy bit set to 1.
Class-3 Virtual BSS is determined in one of three ways: 1) The authentication server in the DS specifies the DSM VLAN to the user, and the PAP maps it to a class-3 virtual BSSID using its DSM VLAN mapping. 2) The authentication server in DS specifies a class-3 virtual BSS for the user, or 3) PAP creates a new class-3 virtual BSS for the user. The PAP can inform the authentication server of the new virtual BSS and provide it with rules that allow other stations to join the new BSS.
Discovery Class-1 virtual BSSs are discovered by 802.11 beas or probe response management frames. Here, the BSSID field (address 3 field) and the source address field (address 2 field) are set for the class 1 virtual BSSID, respectively. The privacy bit of the capability information in these frames is set to zero. Beacon TIM elements apply to class-1 virtual BSS. Only Class-1 virtual BSSs are advertised via beacon frames.
Data frame (MPDU) distribution The PAP implements the MAC Protocol Data Unit (MPDU) Bridge Protocol. The protocol for MPDUs received from DSM or WM is defined by two cases: 1. MPDU received from DSM. There are two sub-cases. (Note: The two subcases deal with the delivery of received MPDUs to the PAP's local LLC, because every PAP station belongs to at least one virtual BSS.): The received MPDU has no VLAN tag or has an empty VLAN tag. If the destination address is the address of a station belonging to the BSS, and the station is associated with a PAP, the MPDU from the DSM is relayed to the virtual BSS, or the destination address is a group address. If so, the virtual BSS has stations that belong to the group, and that station is associated with the PAP. All stations belong to the broadcast group. b. The received MPDU has a non-empty VLAN tag. The virtual BSS through which the MPDU is relayed is identified by a BSSID whose non-empty VLAN tag is mapped under the PAP's DSM VLAN mapping. If the mapping is undefined for the given tag, the MPDU will not be relayed. Any virtual BSS to which a received MPDU is relayed has a BSSID that forms the source address (address 2 field) of the 802.11 MPDU relayed to that virtual BSS. 2. MPDU received from WM. The received 802.11 MPDU is in the virtual BSS identified by the address 1 field of the MPDU, if its destination address (address 3 field of the MPDU) is the address of the station belonging to the identified virtual BSS, and its The station is associated with a PAP, or is relayed if its destination address is a group address. Otherwise, the frame will not be relayed to any virtual BSS. The address 1 field of the received 802.11 MPDU is the source address (address 2 field) of the 802.11 MPDU relayed to the virtual BSS identified by the address 1 field. If the destination address (address 3 field of the MPDU) is the address of a station that is not associated with a PAP, or if the destination address is a group address, the received MPDU will also be relayed to the DSM. If the DS is aware of the VLAN, the MPDU relayed to the DSM will have a VLAN tag, otherwise it will not be tagged. VLAN tag is DSM of PAP A pre-image of the address 1 field of the received MPDU under VLAN mapping.
Encryption and decryption process Cryptography and decryption apply 802.11 data and management frames for subtype association request / response, reassociation request / response, disassociation and deauthentication.
The encryption process used by the PAP before sending 802.11 data or management frames to WM involves two main steps: Identifying security associations for frames and Use that association to build an extended frame for transmission according to some cryptographic and authentication code protocols. Different cryptographic and authentication code protocols can be used for broadcast and multicast traffic between virtual basic service sets, and different cryptographic and authentication code protocols can be used between stations in a single virtual BSS. Can be used for directed (unicast) traffic.
If the frame purpose address (address 1 field) is the address of a station, the unicast security association shared between that station and the PAP will be used in the extension. If this frame is a data frame and its destination address is a group address, the MPDU bridge protocol identifies the target virtual BSS for the frame. The Group Security Association for the identified BSS is used for extension.
A non-PAP station sends an 802.11 MPDU of type data or management to the DS using the Unicast Security Association it shares with the PAP in its BSS.
When receiving 802.11 data or management frames from the WM, the PAP decrypts them using a unicast security association for the station identified by the source address (address 2 field) of the MPDU and verifies the frame integrity. Try to do that.
When receiving a type data or management 802.11 MPDU from a PAP, the non-PAP station shares a unicast security association with the PAP if the target address (address 1 field) of the frame is the station's address. And if the target address of the frame is a group address, it attempts to decrypt and verify the integrity of the frame using its Class 3 Virtual BSS Group Security Association.
Location update protocol The present invention also comprises a location update protocol for updating the transfer table of the bridge, or other interconnect medium to which public access points are connected together.
Given multiple public access points attached to different bridges in the spanning tree of a bridge LAN, and terminals that associate and reassociate one of them with each other, the new PAP is the indicated bridge. The station sends a protocol data unit (BPDU) (called a relocation PDU) to the previously associated PAP. The BPDU's destination address is the current AP address of the reassociation request frame, which is a class-3 virtual BSSID. The source address is the hardware address of the station.
Upon receiving a relocation MPDU on a particular port, the bridge updates its forwarding table with an entry that binds the receiving port to the source address of the MPDU.
The receive bridge forwards the relocation MPDU to its designated root port unless the MPDU arrives at that port or the receive bridge is the root of the subaning tree. If it is received on or by the bridge's designated root port, it is forwarded according to the bridge's learned forwarding table, which is for all ports except the receiving port. Includes flooding MPDUs.
Fine bridging One embodiment of the invention discussed above narrows down PVLANs to virtual BSS. Under the MPDU Bridge Protocol, any station in a virtual BSS can send directed or group-addressed frames to any other station in that virtual BSS. This would be undesirable. Meetings at the conference center may have their own virtual BSS, for example, but not all attendees trust each other. By sharing the same virtual BSS, an attendee can fly a worm or virus. Attempting to thwart these attacks by assigning each attendee to a unique virtual BSS would prevent attendees from sharing the server. Ideally, the server should be shared by all conference participants, but no one should be able to access other participants, that is, send frames. The above public access points cannot provide this level of access control. APs that support fine bridging can provide it.
See also Figure 7, which is a block diagram of the IEEE standard 802.1.Q. An 802.1Q bridge connects a pair of edge hosts to an infrastructure system such as a LAN. Untagged frames arriving from the edge host are assigned to VLAN A by port-based VLAN assignment (PVID A), and untagged frames arriving from the infrastructure system are assigned to VLAN B (P). Assigned to PVID B). The described output rule allows frames belonging to A or B to go out to the infrastructure, while only frames belonging to B are allowed to go out to the edge host. To. In this way, edge hosts are prevented from communicating directly with each other.
Fine bridging decouples the identification of broadcast or multicast domains with BSS.
Under fine bridging, the bridging behavior of an AP is determined by a policy represented as a directed graph. The nodes in the graph are stations, and there is an edge from station A to station B only if station A has access to station B. In other words, station B must be able to receive station A's designated or group frames.
For a given policy, the broadcast domain for a node is itself and all the nodes it must access. A policy broadcast domain set is a set of broadcast domains for that node.
There is a group security association for each broadcast domain in implementing the policy. In addition, each station (node) owns a group security association for the broadcast domain to itself in the policy and for any other broadcast domain in the policy to which it is a member. The former association can be used by the station to send group frames, and the latter association to receive group frames.
Accessibility within a three-station virtual BSS, one of which is an AP, is captured by the policy shown in Figure 2. Each node in the policy has {A, B, AP} as its broadcast domain. Thus, there is only one broadcast domain for the policy, which is expected given that the policy reflects the virtual BSS. Each station knows the group security association for the domain and can send and receive group frames under that association.
In Figure 3, stations A and B share server stations S and D, but A and B capture policies between four stations that are not allowed access to each.
This policy has broadcast domains B1: {A, S, D}, B2: {B, S, D} and B3: {D, A, S, B}. Station A knows the group security association for B1 to send the group frame and knows the group security association for B3 to receive the group frame sent by S and D. Station D knows the group security association for B3 to send group frames and receive them from S, and the group security association for both B1 and B2 to receive group frames from A and B respectively. know.
If the policy in FIG. 3 is modified so that, for example, the edge from B to A is attached to the policy, domain B2 is removed and B1 and as shown in FIG. Only B3 will remain.
If the A-to-B edge is added to the policy in Figure 4, domains B1, B2 and B3 will shrink to a single domain B3 for this policy.
The provision of other policy variations is within the ability of those skilled in the art.
Although the present invention is described herein with respect to preferred embodiments, one of ordinary skill in the art will replace other applications with those described herein without departing from the spirit and scope of the invention. You will immediately understand that it is okay. Therefore, the present invention should be limited only by the appended claims.
31 Public access point 32 wireless media 33 Distribution system medium 33 Distribution system medium
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO02058336A2 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| WO03055151A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| US2003037169A1 | Cites | United States of America | Examiner |
| US2003227893A1 | Cites | United States of America | Examiner |
84 members in 8 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10754402 | United States of America | – | |
| 75440204 | United States of America | A | |
| 75440204 | United States of America | A | |
| 2004754402 | – | – | – |
| US20040754402 | – | – | – |
Members84
| Document | Office | Kind | |
|---|---|---|---|
| US2003120763A1 | United States of America | A1 | |
| WO03055151A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002240211A1 | Australia | A1 | |
| US2003145118A1 | United States of America | A1 | |
| WO2004042984A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003294242A1 | Australia | A1 | |
| AU2003294242A8 | Australia | A8 | |
| US2004141617A1 | United States of America | A1 | |
| KR20040066902A | Republic of Korea | A | |
| EP1457004A1 | European Patent Office (EPO) | A1 | |
| WO2004042984A3 | World Intellectual Property Organization (WIPO) | A3 | |
| CN1606849A | China | A | |
| JP2005513915A | Japan | A | |
| EP1556990A2 | European Patent Office (EPO) | A2 | |
| WO2005069784A2 | World Intellectual Property Organization (WIPO) | A2 | |
| CN1708940A | China | A | |
| JP2006505222A | Japan | A | |
| WO2005069784A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2006206944A1 | United States of America | A1 | |
| EP1702434A2 | European Patent Office (EPO) | A2 | |
| US7120791B2 | United States of America | B2 | |
| KR20060129005A | Republic of Korea | A | |
| CN1910861A | China | A | |
| US7188364B2 | United States of America | B2 | |
| CN1976317A | China | A | |
| JP2007518356A | Japan | A | |
| HK1100111A1 | Hong Kong, China | A1 | |
| US2008022390A1 | United States of America | A1 | |
| US2008198821A1 | United States of America | A1 | |
| US2008198863A1 | United States of America | A1 | |
| JP4190421B2 | Japan | B2 | |
| US2008301442A1 | United States of America | A1 | |
| KR100891041B1 | Republic of Korea | B1 | |
| KR20090081006A | Republic of Korea | A | |
| KR100933097B1 | Republic of Korea | B1 | |
| US7644437B2 | United States of America | B2 | |
| KR20100002283A | Republic of Korea | A | |
| JP4447463B2 | Japan | B2 | |
| US7703132B2 | United States of America | B2 | |
| CN101707596A | China | A | |
| EP1702434A4 | European Patent Office (EPO) | A4 | |
| CN1976317B | China | B | |
| JP2010178356A | Japan | A | |
| JP2010178357A | Japan | A | |
| JP2010183610AThis record | Japan | A | |
| US7818796B2 | United States of America | B2 | |
| CN1910861B | China | B | |
| KR101002448B1 | Republic of Korea | B1 | |
| US7877080B2 | United States of America | B2 | |
| US7886354B2 | United States of America | B2 | |
| US2011033047A1 | United States of America | A1 | |
| EP1457004A4 | European Patent Office (EPO) | A4 | |
| US2011126278A1 | United States of America | A1 | |
| CN1606849B | China | B | |
| CN102130919A | China | A | |
| US7986937B2 | United States of America | B2 | |
| EP1556990A4 | European Patent Office (EPO) | A4 | |
| CN1708940B | China | B | |
| US2011310872A1 | United States of America | A1 | |
| US2011321128A1 | United States of America | A1 | |
| EP2469772A2 | European Patent Office (EPO) | A2 | |
| EP2479936A1 | European Patent Office (EPO) | A1 | |
| US8276198B2 | United States of America | B2 | |
| US8347377B2 | United States of America | B2 | |
| US2013024692A1 | United States of America | A1 | |
| KR101260100B1 | Republic of Korea | B1 | |
| KR20130049812A | Republic of Korea | A | |
| CN102130919B | China | B | |
| JP5253442B2 | Japan | B2 | |
| EP2640008A2 | European Patent Office (EPO) | A2 | |
| CN101707596B | China | B | |
| JP5330298B2 | Japan | B2 | |
| EP2469772A3 | European Patent Office (EPO) | A3 | |
| KR101365830B1 | Republic of Korea | B1 | |
| US8675559B2 | United States of America | B2 | |
| US8767623B2 | United States of America | B2 | |
| US2014337966A1 | United States of America | A1 | |
| EP2640008A3 | European Patent Office (EPO) | A3 | |
| US8966611B2 | United States of America | B2 | |
| JP5865578B2 | Japan | B2 | |
| EP1556990B1 | European Patent Office (EPO) | B1 | |
| EP2640008B1 | European Patent Office (EPO) | B1 | |
| US9730070B2 | United States of America | B2 | |
| EP1457004B1 | European Patent Office (EPO) | B1 |
18 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A821A521 | A521 | |
| Notification of appointment of power of sub attorneyJAPANESE INTERMEDIATE CODE: A7433RD13 | RD13 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 2010183610
- Publication, DOCDB
- 2010183610
- Publication, EPODOC
- JP2010183610
- Application
- 62702
- Application, DOCDB
- 2010062702
- Application, EPODOC
- JP20100062702
Titles2
- Japanese
- 公衆アクセス・ポイント
- English
- Public access point
Classification
- CPC, 13
- H04W12/08
- H04L12/4625
- H04L12/4641
- H04L12/4645
- H04L63/0272
- H04L63/08
- H04L63/105
- H04L63/123
- H04W64/00
- H04W84/12
- H04W88/10
- H04W92/02
- H04W40/023
- IPC, 6
- H04W88 08
- H04L9 32
- H04L12 56
- H04L12 28
- H04L12 46
- H04L29 06