Authentication mechanisms for wireless networks
Abstract
Wireless network security techniques and mechanisms that send content such as advertisements. A control message containing unsolicited content can be sent in response to a request from the client device, and another exemplary technique is to send the control message without any request from the client device. Can be done. In some exemplary embodiments, security mechanisms such as public key encryption algorithms can be used to protect the communicator. Some of these techniques that implement public key encryption can require users to retrieve public keys from sources other than wireless access points that send encrypted ads, and users can encrypt. It is possible to verify that the encrypted content is from a source that matches the retrieved public key, and thus to verify the authenticity of the wireless access point. [Selection diagram] Fig. 1A

Term
Projected expiry 20 January 2029.
- Priority
- Filed
- Published
- Today
- Projected expiry
20 claims: 3 independent, 17 dependent
- 1商業サービスに関係する広告情報(108)を表示するためにクライアントデバイス(112)を動作させる方法であって、 (A)無線アクセスポイント(104)の信頼情報を入手するステップ(206)と、 (B)前記信頼情報に基づいて、前記無線アクセスポイントからの制御伝達物の真正性を検証するステップ(210)と、 (C)検証する前記行為に少なくとも部分的に基づいて、制御メッセージ内に含まれる少なくとも1つの商業サービスの広告をユーザーに選択的に表示するステップ(214)と を含む方法。
- 2検証する前記行為は、少なくとも1つのメッセージを前記無線アクセスポイントに送信するステップ(306)を含む、請求項1に記載の方法。
- 3営利団体(100)は、モールまたはショッピングセンターであり、前記信頼情報は、前記モールおよび/または前記モール内の店の1つまたは複数の信頼情報である、請求項2に記載の方法。
- 4前記少なくとも1つのメッセージは、前記方法を実行するデバイスのデバイス信頼情報を含み、検証する前記行為は、前記無線アクセスポイントから前記少なくとも1つのメッセージに対する少なくとも1つの応答を受信するステップ(308)と、前記デバイス信頼情報を使用して前記少なくとも1つの応答を検査するステップを含む、請求項3に記載の方法。
- 5検証する前記行為は、前記信頼情報を使用して前記制御伝達物の少なくとも一部を暗号化解除するステップを含む、請求項1に記載の方法。
- 6前記信頼情報を入手するステップは、営利団体に関連するNear-Field Communicationを実施するデバイス(102)から前記信頼情報を入手するステップを含む、請求項1に記載の方法。
- 7前記信頼情報を入手するステップは、信頼情報のリポジトリーとして働くウェブサービス(116)から前記信頼情報を入手するステップを含む、請求項1に記載の方法。
- 8前記信頼情報を入手する前記行為は、ユーザー(124)が、前記信頼情報をディレクトリー(126)から入手した後に前記信頼情報を入力するステップを含む、請求項1に記載の方法。
- 9前記信頼情報は、前記無線アクセスポイントによって実施される公開キー暗号化アルゴリズムの公開キーである、請求項1に記載の方法。
- 10前記制御伝達物は、前記制御伝達物の環境情報を含み、 前記方法は、前記環境情報を検証するステップをさらに含み、 前記広告を前記ユーザーに選択的に表示するステップは、前記環境情報を検証するステップの結果に少なくとも部分的に基づく 請求項1に記載の方法。
- 11前記環境情報は、前記制御伝達物を送信する前記無線アクセスポイントの位置および/または前記制御伝達物が送信された時刻である、請求項1に記載の方法。
- 12実行された時に、エンティティー(100)に関連する無線アクセスポイント(104)からの制御伝達物の真正性を確認する方法をコンピューターに実行させるコンピューター実行可能命令をエンコードされた少なくとも1つのコンピューター可読媒体であって、前記方法は、 (A)前記エンティティー(100)の信頼情報を入手するステップ(206)と、 (B)前記信頼情報を使用して、前記無線アクセスポイントからの制御伝達物の前記真正性を検証するステップ(210)と、 (C)検証する前記行為に少なくとも部分的に基づいて、前記制御伝達物のコンテンツを選択的に使用するステップ(214)と を含む、少なくとも1つのコンピューター可読媒体。
- 13前記信頼情報は、前記制御伝達物の少なくとも一部を暗号化するのに使用される公開キー暗号化アルゴリズムの公開キーである、請求項12に記載の少なくとも1つのコンピューター可読媒体。
- 14前記コンテンツは、前記無線アクセスポイントの位置データーであり、前記コンテンツを使用するステップは、クライアントデバイスの現在位置を判定するステップを含む、請求項12に記載の少なくとも1つのコンピューター可読媒体。
- 15前記信頼情報を入手するステップは、前記エンティティー(100)に関連するキオスク(102)から前記信頼情報を入手するステップを含む、請求項12に記載の少なくとも1つのコンピューター可読媒体。
- 16前記制御伝達物は、前記制御伝達物の環境情報を含み、 前記方法は、前記環境情報を検証するステップをさらに含み、 前記コンテンツを選択的に使用するステップは、前記環境情報を検証するステップの結果に少なくとも部分的に基づく 請求項12に記載の少なくとも1つのコンピューター可読媒体。
- 17無線ネットワーク内で制御メッセージを送信する装置(104)であって、 信頼情報(712)およびコンテンツ(710)を格納する少なくとも1つのデーターストアー(706)と、 前記コンテンツを含む制御伝達物を構成し、前記信頼情報を使用して前記制御伝達物の少なくとも一部を暗号化するように適合された少なくとも1つのプロセッサー(702)と、 前記制御伝達物を送信する通信回路(704)と を含む装置。
- 18前記信頼情報は、公開キー暗号化アルゴリズムの秘密キーである、請求項17に記載の装置。
- 19前記通信回路は、クライアントデバイスから受信されたテスト制御メッセージに応答して前記少なくとも1つのプロセッサーによって構成される応答テスト制御メッセージを送信するように適合され、前記テスト制御メッセージは、少なくとも1つのナンスを含む、請求項17に記載の装置。
- 20前記コンテンツは、前記装置の位置を記述する位置データーである、請求項17に記載の装置。
Independent claims20
89 paragraphs, as filed
Traditional web-based advertising frameworks typically send ads to consumers of web-based services over a network where client devices establish a connection to a server hosting web-based services. For example, a server owner / administrator configures a server to send a web page with ads to a client device in response to a user on the client device entering a URL (Uniform Resource Locator) on the client device. can do. The ad can be in the form of text / image / video / audio data, can be embedded in a web page, or is displayed to the user before displaying the web page accessed by the client device. It can be an initial web page.
In such an advertising framework, advertising is exchanged between web-based services (eg, websites) and users of web-based services. A network to which a user's client device is connected and through which the client device accesses web-based services has limited involvement in controlling the content of the web page and therefore advertises to the client device user. Has limited capacity to provide. Instead, some networks implement alternative complementary advertising frameworks, such as advertising frameworks that send web pages containing ads to users of networked client devices. Advertising frameworks implemented by these networks may, for example, require users of the network to view an initial web page the first time they connect to that network, or advertise to client devices that use that network. Web pages containing may be sent periodically.
Traditional advertising frameworks for wireless networks are limited in their ability to send ads to users. This is because the advertisement can only be sent to a client device that has an established connection to the wireless network and / or a client device that is requesting data from the wireless network. If an ad can be sent to a client device that is not connected to a wireless network, the ad will reach more users and the advertising business will be able to generate more customers and more revenue.
However, allowing client devices to openly accept unsolicited content from networks to which they are not connected can open up users of that device to various risks. For example, unwanted ads (eg, pornographic ads) can be sent by an organization that the user is not interested in, or by a malicious party pretending to be an organization that the user is interested in. Without a security mechanism and / or security method that identifies the network that sends ads and other content, such unwanted ads could be received by the client device and displayed to the user, offending the user. May cause anger or anger.
Frameworks other than advertising frameworks can also benefit from being able to send unsolicited content to client devices, which are security mechanisms and / / that identify networks that send unsolicited content. Or you can benefit from security methods. For example, wireless access points can send their location data to client devices that track their location, and verifying the identity of these wireless access points is fraudulent by a malicious party. It is possible to prevent the broadcast of target position data.
Disclosed herein are various principles of security techniques and mechanisms for wireless networks that transmit content such as advertisements. According to some exemplary techniques, control messages containing unsolicited content (eg, advertising data) can be sent in response to requests from client devices, with other exemplary techniques being controlled. The message can be sent without any request from the client device. In some exemplary embodiments, security mechanisms such as public key encryption algorithms can be used to protect the communicator. Some of these techniques that implement public key encryption can require users to retrieve public keys from sources other than wireless access points that send encrypted advertisements (eg, such). Users can verify that the encrypted content is from a source that matches the retrieved public key (from a sign or terminal within a commercial organization that sends a good advertisement, or a web service), and therefore The authenticity of the wireless access point can be confirmed.
In one embodiment, a method of operating a client device to display advertising information related to a commercial service is provided. This method is based on obtaining the trust information of the wireless access point, verifying the authenticity of the control transmission from the wireless access point based on the trust information, and at least partially based on the act of verification. Includes the selective display of at least one commercial service advertisement contained within the control message to the user.
In another embodiment, at least one computer-readable encoded computer-executable instruction causes the computer to perform a method of verifying the authenticity of the control transmission from the wireless access point associated with the entity when executed. The medium is provided. This method is based, at least in part, on obtaining the credit information of the entity and using the credit information to verify the authenticity of the control transmission from the wireless access point. Includes the selective use of the content of the control vehicle.
In a further embodiment, a device for transmitting a control message within the wireless network is provided. The device was adapted to configure at least one data store that stores trust information and content, and a control transmission that contains the content, and use the trust information to encrypt at least part of the control transmission. Includes at least one processor and a communication circuit that transmits control transmissions.
The attached drawings are not intended to be drawn to their original size. In the drawings, the same or nearly identical components shown in the various figures are represented by similar symbols. For clarity, some components may be unsigned in some drawings.
<figref num="1A">FIG. 5 illustrates an exemplary computer system in which some, if not all, of the techniques disclosed herein can work to send, receive, and verify the authenticity of control messages. This computer system includes a kiosk from which the credit information of the entity can be read.</figref><figref num="1B">FIG. 5 illustrates an exemplary computer system in which some, if not all, of the techniques disclosed herein can work to send, receive, and verify the authenticity of control messages. This computer system includes a web server that hosts websites from which trust information can be retrieved.</figref><figref num="1C">FIG. 5 illustrates an exemplary system in which some, if not all, of the techniques disclosed herein can work to send, receive, and verify the authenticity of control messages. The system contains a paper directory from which the trust information can be retrieved.</figref><figref num="2">FIG. 6 illustrates a process that implements some of the principles disclosed herein that can be performed by a computer system to exchange information about commercial services between a wireless network and a client device.</figref><figref num="3">It is a flow diagram showing one exemplary technique that implements some of the principles disclosed herein to verify the authenticity of a wireless access point in a wireless network.</figref><figref num="4">It is a flow diagram showing one exemplary technique that implements some of the principles disclosed herein to verify the authenticity of a control message received from a wireless access point in a wireless network.</figref><figref num="5">It is a flow diagram showing another exemplary technique that implements some of the principles disclosed herein to verify the authenticity of a control message received from a wireless access point in a wireless network.</figref><figref num="6">FIG. 6 illustrates a flow diagram illustrating an exemplary technique that implements some of the principles disclosed herein that can be used by wireless access points to transmit control messages.</figref><figref num="7">FIG. 6 is a block diagram showing an exemplary radio access point capable of performing some, but not all, of the techniques disclosed herein to transmit a control message and verify its authenticity.</figref><figref num="8">An exemplary client device capable of receiving, but not all, of the techniques disclosed herein to receive a control message received from a wireless access point on a wireless network and verify its authenticity. It is a block diagram which shows.</figref>
Applicants apply from a simple mechanism that makes computer-based advertising available to both stores and consumers, for example, from consumers who are very close to where the service being advertised is available. I understand that I can make a profit. For example, the user can learn about the bargains or special promotions offered by the store. The user can also know about the services provided by the store and determine that he or she is interested in the services provided by the store before entering the store's building.
Conversely, advertisers can focus their ads on potential customers who are close to their facility and are therefore most likely to make purchases. For example, a restaurant with a wireless network may endeavor to attract more customers by sending a description of the restaurant's daily specialties to client devices within range. Traditional advertising frameworks cannot serve ads in this way. Although it is possible to send ads to a large number of users, traditional frameworks display ads to users of client devices who have requested data from a wireless network and are already connected to that wireless network via a wireless access point. It is limited to that. Such traditional frameworks can display ads to users who are not connected to that wireless network, and that information to users who do not know that ads are available for stores that are very close to that user. It is also not possible to call attention to request.
Applicants acknowledge the desire to advertise the services of a store, including services such as the sale of one or more products, to users of client devices that are not connected to the wireless network operated by the store. .. If a store can advertise their products or services not only to client devices connected to their wireless network, but to all client devices within its wireless network, the advertisement can reach a wider audience. , The store should be able to attract more customers and more income. In addition, users of client devices within the range of the wireless network are most likely a group of potential customers due to their proximity to the store when receiving the transmitted advertisement.
However, Applicants also allow client devices to openly receive content from nearby networks and display that content to users without verifying the authenticity of the network and / or content. I understand that this opens up users to various risks. For example, you may see ads that you are not interested in and / or ads that are offensive to you. For example, a user walking in a shopping center may walk within a store that sells products that the user finds undesirable (for example, pornography), and the user wants all ads in that store. You may feel absent or uncomfortable. In addition, if the client device displays all the advertisements it receives to the user, a malicious third party may set up a fraudulent wireless network and appear to be a legitimate source, but in reality the client device. Can send advertisements that are offensive or unwanted images and / or text that are automatically displayed to the user.
In addition, Applicants can benefit from frameworks other than advertising frameworks sending unsolicited content to client devices over wireless networks, and these client devices provide content. I understand that I can benefit from verifying the identity of these networks before accepting them. For example, a wireless access point that broadcasts data indicating the location of a wireless access point can be useful for client devices that are trying to locate themselves within the range of that wireless access point. However, unless techniques have been deployed to verify the identity of wireless access points and / or wireless networks, client devices in this scenario are against accepting fraudulent location data from malicious third parties. It is defenseless. Other frameworks that wirelessly exchange information with client devices can likewise benefit from the techniques disclosed herein.
Therefore, Applicants have acknowledged the desire for a wireless network security mechanism that allows a client device to verify the identity of a wireless network before accepting unsolicited information from the wireless network. Security mechanisms can allow users and / or client devices to verify the authenticity of control messages from wireless access points that contain content (eg, advertising, location data, or other information). Instead or in addition, using security mechanisms, one or more wireless access points or any other of any suitable framework to send control messages before the content is displayed to the user. The authenticity of the wireless network including the components can be verified. In addition, security mechanisms can allow a user to limit the content that a client device wants to use (eg, the content that is selected for display to that user).
In view of the above, techniques have been devised for security mechanisms that verify the identity of wireless networks. In one exemplary technique, a user receives credit information from one or more commercial organizations and uses that credit information to verify the authenticity of one or more control transmissions or network components. Selectively display the content contained in one or more control transmissions from these commercial organizations based on successful validation.
Any suitable carrier can be a controlled carrier by one or more of the principles described herein. For example, an announcement Layer 2 control transmissions such as transmission) are optional with respect to the wireless access point, including one or more network characteristics that allow the client device receiving the control transmission to open a connection to the wireless access point. Can contain appropriate information about. Announcement transmissions are transmitted by, for example, IEEE (Institute of Electrical and Electronics Engineers) 802.11 wireless protocol beacons, client devices that are periodically broadcast by a wireless access point to all client devices within that wireless access point's range. It can be a probe response sent to a client device in response to a request for control information, or any other suitable announcement carrier sent by a wireless access point. The control transmission sent by the client device to the wireless access point may or may not contain test data, a probe requesting control information about the wireless access point and / or wireless network, any suitable type of authentication test message. , And / or any other suitable carrier.
In some, but not all, of the techniques described herein, security techniques can be implemented as unidirectional or bidirectional public key encryption algorithms. In embodiments that use public key encryption, any suitable public key algorithm, such as the popular RSA (Rivest-Shamir-Adleman) public key algorithm, can be used, but the present invention presents a particular security technique. Or, it is not limited to implementing a specific public key algorithm.
In some embodiments, such as those that perform public key encryption, the user or client device may be one of books, signs, key services, electronic key providers, kiosks, or NFC (Near-Field Communication) protocols. Trust information can be obtained from "out-of-band" sources such as other devices that communicate using multiple protocols (ie, sources other than those over the wireless network itself) or any other suitable source. The trust information can, in some embodiments, be a public key associated with a wireless network or wireless access point and / or a public key infrastructure (PKI) certificate approved by a certification authority. As described in more detail below, client devices that have a wireless network or wireless access point trust information will use that trust information in any suitable form to identify the wireless access point and / or wireless network. Can be confirmed.
For example, in some techniques that implement some of the principles described herein, the wireless access point, as part or all of the trust information, is a secret that corresponds to the public key retrieved by the client device. The key can be used to send an encrypted control transmission. In some embodiments, the control vehicle can be fully encrypted, but in the alternative vehicle, the control vehicle payload (eg, content such as advertising data, or an information element containing one or more content). ) Only part or all of it is encrypted. If the client device can successfully decrypt the control message using the public key, then the client device knows that the control message was encrypted using the private key that corresponds to the retrieved public key. It can be verified, and thus the wireless access point that sends the encrypted control message can be verified to be the wireless access point that the client device expects to receive information from.
In addition or instead, in some embodiments, the client device replaces one or more test communicators as control communicators to test the authenticity of the wireless access point and / or wireless network. be able to. For example, a client device can use credit information (eg, a retrieved public key) to encrypt test data and send the encrypted test data to a wireless access point. If the control transmission received from the wireless access point in response to the test transmission contains the correct test data, the client device allows the wireless access point to correctly decode the transmission, and thus the wireless access point, It can be confirmed that the wireless access point has a private key corresponding to the public key and the client device is expected to communicate with it. Higher security can be achieved by adding other information to the test data. The other information can be any suitable information, such as the client device's public key, and the response sent by the wireless access point is encrypted and sent using the client device's public key. Can be. In the alternative, the test data could be a nonce or other proprietary symbol (eg, proprietary text or transmission time), so that the control transmission from the wireless access point is intercepted, recorded, and from the fabrication device. Even if it is rebroadcast (to make the forged device look authentic), the client device, for example, by noting the repetition of what should be its own symbol or an unusual delay in transmission time (ie). An extreme difference between the current time and the alleged transmission time of the control vehicle may imply that the control information was recorded at the transmission time and rebroadcast by the fabrication device at a later time. ), Reply attack (reply)
Any suitable security that these techniques are merely examples of techniques that can implement the principles described herein and that the principles described herein confirm the identity of the wireless network. It should be understood that the mechanism can be used in any suitable manner (since the present invention is not limited in this regard).
In addition, it should be appreciated that the control vehicle can be formatted in any suitable form to include one or more of any suitable type of content (eg, advertising data and / or location data). Illustrative techniques for encapsulating content in the information elements of a control vehicle are US Patent Application No. 11/973589 and "Transmitting location" entitled "Advertising framework for wireless networks" that are simultaneously pending. It is discussed in US Patent Application No. 11/973590 entitled "data in wireless networks". These patent applications are, among other things, the IEEE for including advertising and location data in control transmissions such as beacons and probe responses. It describes the use of information elements in the 802.11 wireless communication protocol. However, the principles described herein can be practiced using suitable control communicators that incorporate content in any suitable form and are not limited to the techniques discussed in these patent applications.
Techniques described herein include one or more wireless networks, each containing one or more wireless access points and any suitable means for a client device to obtain wireless network trust information. It can be implemented in any suitable system. This is because the present invention is not limited in this regard. The description below is an exemplary system that implements some of the principles described herein.
Figure 1A shows an exemplary system in which some of the techniques disclosed herein can work. It should be appreciated that embodiments of the present invention may work in any suitable system and are not limited to implementation in the exemplary system shown in FIG. 1A.
The system of Figure 1A includes an exemplary client device 112 within the range of three radio access points 104, 104A, and 104B. Each of the wireless access points shown in Figure 1A is associated with an entity such as entity 100, entity 114A, and entity 114B. In some embodiments of the invention, the entity can be a store, a collection or coalition of stores, a non-profit / public organization, or another commercial organization, but embodiments of the invention are commercial. Please understand that it is not limited to being carried out with an organization. In addition, as used herein, an "entity", including a commercial organization, may be associated with a single entity, such as a person, group, organization, or store, or with any suitable form. Please understand that it can be any combination of groups, organizations, stores, or any other entity (for example, within a shopping center, a group of business groups or stores that share an infrastructure). For clarity, this description describes various examples in which an entity is described as a commercial entity such as a store or shopping center, but the invention presents one or more specific types of entities. Please understand that it is not limited to being carried out with.
FIG. 1A shows an exemplary embodiment of an entity according to an embodiment of the invention, including entities such as entities 114A and 114B, within entity 100. The entity may include at least one radio access point 104, which radio access point 104 may be communicatively coupled to the data store 106 and server 110 associated with the radio access point 104. The datastore 106 can be any suitable computer-readable medium, a component of the wireless access point 104, or directly or via any suitable wired and / or wireless communication medium. Can be coupled to the wireless access point 104. As shown in FIG. 1A, in some embodiments, the data store 106 can store information, including advertising data, that can be retrieved and transmitted by the wireless access point 104. Advertising data 108 shall be any suitable type of data that may be transmitted by the wireless access point 104, including data describing, for example, text, images, audio, or video, or any combination thereof. Can be done. The ad data 108 can be data that describes a single ad for one or more services associated with entity 100, or multiple ads for one or more services associated with entity 100. Can be used as data to describe. Please understand that, as mentioned above, advertising data is merely an example of the type of data that can be transmitted by a wireless access point in a wireless network and can transmit any type of information, one or more. .. This is because the present invention is not limited in this regard.
The server 110 can be any suitable computing device that stores information (eg, data and / or instructions) provided to client devices connected to the wireless access point 104. Although the server 110 is shown separately from the wireless access point 104 and the data store 106 in FIG. 1, in some embodiments of the invention, the server 110 may be a component of the wireless access point 104. It can be implemented as an electronic device that can and / or contains a computer-readable medium (s) that acts as both a server 110 and a data store 106. In the illustrated embodiment, the server 110 is connected to a network that the device can access after the device associates with the wireless access point 104 and gains access to that network. However, the requirements of the present invention are that the system of Figure 1A is merely exemplary and that wireless access points that provide advertising data or other content ultimately support connections to other networked devices. Please understand that there is no such thing.
The information stored by the server 110 may include, in some embodiments, information related to one or more advertisements described by the advertisement data 108 stored by the data store 106. Information related to one or more advertisements should be any suitable information, including, for example, one or more web pages describing one or more products or services advertised by Advertising Data 108. Can be done. In the illustrated embodiment, the data store 106 may not completely define the content of the advertisement described by the advertisement data 108. However, such an advertisement can include, for example, a URL pointing to server 110, and the user can obtain information related to the service being advertised on the wireless access point 104 or any other suitable. You can choose to connect to server 110 over a network connection.
The radio access point 104 can be any suitable radio signal generator that produces a signal according to one or more radio networking protocols. For example, a wireless access point can be a WiFi access point that operates according to the IEEE (American Association of Electrical and Electronic Engineers) 802.11 standard for wireless local area networks (WLANs), and any suitable wireless wide area network (WWAN) protocol. (For example, personal area network (PAN) protocols such as WWAN and Bluetooth that follow GSM (Global System for Mobile Communications), WiMAX (Worldwide Interoperability for Microwave) It can be a cellular-style wireless access point running other protocols such as the Access) protocol and the UWB (Ultra-wideband) protocol, or any other suitable radio protocol. In an entity having a plurality of radio access points, the radio access points may operate according to the same radio protocol or may operate according to different radio protocols.
As mentioned above, a system that implements some of the principles disclosed herein is a method of obtaining trust information about a wireless access point and wireless network other than via the wireless access point and the wireless network itself. (Ie, out-of-band source) can be. In some unfavorable embodiments, the trust information can be retrieved from the wireless network itself, but it should be understood that out-of-band sources are preferred.
In the embodiment of FIG. 1A, entity 100 comprises a kiosk 102 from which a client device can retrieve trust information. The kiosk 102 can be, for example, an electronic device located in or near entity 100. In some embodiments, the kiosk 102 can be a device mounted at a store entrance or shopping mall entrance or anywhere in the store or shopping center (eg, mounted on a pillar or wall). The user can access this kiosk 102 to retrieve the trust information of one or more of the stores or shopping malls. The client device 112 can communicate with the kiosk 102 to retrieve trust information in any suitable form. In some embodiments, the client device 112 uses any suitable wireless protocol, such as the WLAN or PAN protocol, or an NFC (Near-Field Communication) protocol (eg, RFID (Radio Frequency)). Identification) techniques) or any suitable wired or contact-based communication technique can be used to communicate with the kiosk 102. For example, in some embodiments, the user can retrieve a memory unit (eg, a memory card) that is inserted into the client device 112 from the kiosk 102, from which the client device 112 provides trust information. It can be copied, or its memory unit can be retained while the user is shopping at a store or shopping center (or otherwise interacting with the entity). As mentioned above, the credit information retrieved from kiosk 102 can be any suitable credit information, such as the entity 100's public key or PKI certificate.
As shown in FIG. 1A, the client device 112 that receives communications from one or more wireless access points 104, 104A, and 104B can be a laptop personal computer. However, the embodiments of the present invention are not limited to being carried out using a laptop personal computer, and may be mobile, such as a desktop personal computer, a laptop personal computer, a personal digital assistant (PDA), or a smart phone. It should be understood that it can be carried out using any suitable electronic device that receives the radio signal, even if it is immobile.
Client device 112 may or may not have open connections to one or more wireless access points 104, 104A, and 104B, but each range of wireless access points 104, 104A, and 104B. Can receive communications from wireless access points 104, 104A, and 104B. As mentioned above, according to embodiments of the present invention, the transmission received from wireless access points 104, 104A, and 104B is any suitable information, including advertising data 108 stored by data store 106. Can be included. According to some exemplary techniques, the carrier transmitted by the wireless access points 104, 104A, and 104B and received by the client device 112 can be a Layer 2 control carrier. A layer 2 control transmission, such as an announcement transmission, is a wireless access point that contains one or more network characteristics that allow a client device receiving the control transmission to open a connection to the wireless access point 104. It can contain any suitable information about 104. As mentioned above, the announcement carrier is, for example, an IEEE 802.11 radio protocol that is periodically broadcast by the wireless access point 104 to all client devices (including client device 112) within range of the wireless access point 104. Being a beacon according to, a probe response sent to client device 112 in response to a request for control information sent by client device 112, or any other suitable announcement carrier sent by wireless access point 104. Can be done.
In some embodiments of the invention, the wireless access point 104 can encode the advertising data 108 stored by the data store 106 within the control transmission. As described in more detail below, the client device 112 receives a control vehicle containing content (eg, advertising data 108 or any other suitable content) and adapts it to read the content from the control vehicle. be able to. After being read, the content can be processed in any suitable form, such as serving the advertisement described by the ad data 108 to the user of the client device 112 via any suitable user interface. In some advertising frameworks that can implement the techniques described herein for security, a user can view an advertisement and provide further information about the product or service that the user describes in the advertisement. The request can be indicated on the client device 112. The client device establishes a connection to a wireless access point sending an advertisement indicating that the user is interested (if client device 112 has not yet established an open connection to that wireless access point). In), any appropriate additional information about one or more services described by the advertisement can be retrieved. Additional information may include one or more web pages containing additional information about the service or one or more web pages from which users can order or subscribe to the service. However, in some advertising frameworks that implement the techniques described herein, the additional information may not be one or more web pages and may instead be provided to the user of the client device. Please understand that it can be an appropriate additional piece of information.
The exemplary computer system of Figure 1A is merely exemplary, and any suitable computer system in which embodiments of the present invention include any suitable number of client devices, entities, and wireless access points. Please understand that you can work within. Further, an entity and a wireless access point are shown in the example of FIG. 1A so that embodiments of the present invention can be implemented with any suitable entity using any suitable hardware and / or software. Please understand that it is not limited to being carried out as it is.
Figures 1B and 1C show alternative systems in which techniques that implement some of the principles described herein can work. As shown in FIGS. 1B and 1C, the entities 100'and 114A' are substantially similar to the entities shown in FIG. 1A, but these entities are shown including the kiosk 102. Not. Instead, FIG. 1B illustrates a server 116 communicatively connected to a client device 112 over a communication network 118 that includes any suitable wired and / or wireless communication medium. There is. Server 116 can act as a certification authority that issues PKI certificates and / or a repository of any one or more types of trust information, MSN or Windows available from Microsoft Corporation in Redmond, Washington, USA. (Registered trademark) It can be a website that provides trust information for a website such as a Live service or any suitable form of trust information for one or more entities such as a web service. A website that acts as a repository of credit information can be built as an online directory of credit information for an entity, similar to an online directory for phone numbers. Techniques that work with systems, such as the system in Figure 1B, eliminate the need for users on client device 112 to retrieve trust information from kiosk 102, or have an entity (eg, entity 100'or entity 114A'). To eliminate the need to provide the kiosk 102, the user can retrieve the credit information for the entity before visiting it. In the alternative, the client device visits the entity by accessing server 116 over a wireless and / or wired network that is different from the wireless access point 104's network (for example, by accessing the WWAN network). You can retrieve trust information while you are (for example, shopping at a store).
Server 116 can have a data store 120 that contains one or more credit information 122 (illustrated as a "key" in Figure 1B, but not limited to) of one or more entities. .. Some techniques that work with this system allow the user to request the individual keys of individual entities from server 116, or enterties within a geographic location or within a range of a geographic location. You can request multiple keys in any suitable group, such as tees, certain types of entities, and / or entities that are somehow related to each other (for example, all stores in a given shopping center). it can.
The system in Figure 1C shows another form in which the client device 112 can retrieve the trust information of one or more entities. In the system of Figure 1C, user 124 on client device 112 uses physical directory 126 to retrieve the credit information for one or more entities 100', and then uses that credit information for any appropriate user interface. It can be manually entered into the client device 112 via. The directory is a sign that lists trust information (for example, wall-mounted) that can be viewed in or near an entity in a book format similar to a traditional phone book (as shown in Figure 1C). It can be constructed in any suitable form, such as (for example, in a format similar to a floor map directory in a shopping center or as a sign at the entrance of a store). Directory 126 can provide trust information for one or more entities. If directory 126 provides information for multiple entities, the listed entities are one or more specific types of entities, entities within a geographic area, or any other grouping. It can be an entity included in any appropriate grouping, such as by following. User 124 can use directory 126 to retrieve the trust information for an entity before visiting it (for example, if directory 126 is constructed like a phone book), or the entity. You can use directory 126 while visiting (for example, if directory 126 is a sign).
It should be appreciated that in some embodiments, multiple techniques can be performed within a system to allow the client device to retrieve the trust information. For example, an entity can have its trust information available through a web service and / or a directory, and can also have one or more kiosks from which the trust information can be retrieved. , Any other suitable technique can also be practiced. This is because the present invention is not limited to the practice of any single technique of providing or retrieving credit information alone or in combination with any other technique (s). Also, any suitable technique for retrieving credit information can be performed according to the principles described herein, and thus the invention is limited to being performed using the exemplary techniques described above with respect to retrieving credit information. Please understand that it will not be done.
FIG. 2 shows the principles disclosed herein with respect to passing content (eg, information about products and / or services in the form of advertisements) between the wireless access point 104 of entity 100 and the client device 112. An exemplary process 200 that implements some is shown. It is understood that Process 200 is merely exemplary and that the present invention is not limited to performing any particular process of exchanging content between a wireless access point and a client device. I want to. As mentioned above, Process 200 is described in the context of advertising, but this type of content is merely exemplary as the invention is not limited to the exchange of any particular type or number of content. Please understand that there is.
Process 200 begins at block 202, where the entity (or any person or device associated with the entity) advertises information related to one or more services associated with that entity. specify. One or more services can be commercial services, such as selling products through any service that can be performed by an entity, as shown in Figure 2. For example, if the entity is a restaurant, the commercial service provided by the entity can be a food offering, and the service-related advertisements describe the daily special dishes offered by the restaurant for the day. Can be done. As used herein, the term "commercial service" is not limited to services provided by an entity for profit. Commercial services can include announcements of events held by non-profit or governmental organizations, such as free concerts.
According to some techniques that implement the principles described herein, the designation of information to advertise in block 202 is a wireless access point with data describing one or more advertisements for a designated commercial service. In other embodiments, the designation of a commercial service may include encoding within a data store associated with which product (s) from a preconfigured list of products and / or services. ) And / or the choice of whether the service (s) should be the specified commercial service.
In block 204, the wireless access point transmits advertising data related to the designated advertising information of the commercial service. In some embodiments, the vehicle transmitted by block 204 can be part of a control vehicle transmitted by a wireless access point, and some exemplary techniques for transmitting unsolicited content. According to this, it can be an announcement message such as a beacon that is periodically broadcast to all client devices within the range of the wireless access point. Advertising data can be incorporated into the control vehicle in any suitable form. For example, techniques implemented within an IEEE 802.11 wireless network can include advertising data in the information elements of a beacon or probe response, but the invention is not limited to this exemplary technique, but in any suitable form. The content can be incorporated into the control vehicle with.
At block 206, the client device retrieves the trust information (eg, public key or PKI certificate) of the entity (ie, the wireless network including the wireless access point and / or the wireless access point). This can be done in parallel with Acts 202 and 204, with the credit information retrieved at the same time the advertising information is specified and transmitted, or at any appropriate time after Acts 202 and 204 are completed. It can be carried out. Retrieval information can be retrieved in any suitable manner, such as by any of the exemplary techniques described above. Credit information can be retrieved from a kiosk, a server that holds one or more credit information, a directory of credit information, and / or any other suitable "out-of-band" source of credit information.
At block 208, the client device 112 retrieves the control communicator of block 204 containing the advertising data and performs any appropriate processing on the communicator. According to the principles disclosed herein, this process involves using the trust information in block 210 to verify the identity of the wireless access point and / or the wireless network to which the wireless access point is connected. .. The processing of block 210 can be performed in any suitable manner, including by any of the processes 300, 400, and 500 described in more detail below.
In block 212 following the verification process of block 210, process 200 determines whether the wireless access point from which the control transmission was received is the wireless access point that the client device 112 expected to receive content from (eg,). , Whether the wireless access point is genuine or fraudulent). If the wireless access point is determined to be the expected wireless access point, at block 214, the client device controls, for example, by presenting advertising data to the user of the client device via the appropriate user interface. Process 200 ends using the content of the message. However, if at block 212 it is determined that the wireless access point is not the expected wireless access point, then at block 216 the wireless access point (and the control message it sends) will have an appropriate time period. Ignored for a period of time (for example, minutes, days, forever, or any other suitable time period, until the client device is out of range of its wireless access point, new trust information is available).
Process 200 is merely an example of a technique that implements some of the principles described herein and any process in which the present invention performs one or more actions of process 200, such as process 200. Please understand that you are not limited to implementing a particular process. Any suitable technique (s) for exchanging information about products and / or services between the wireless access point associated with the entity and the client device may be performed in accordance with the principles described herein. it can. For example, FIG. 2 illustrates process 200 for a commercial service advertised by a commercial organization, but in an alternative technique, embodiments of the present invention can be implemented by a non-profit entity, and thus to the entity. Related products (s) and / or services (s) may be non-commercial services. In addition, it should be understood that some alternative techniques can perform the actions shown in Figure 2 in different orders. As an example, in some techniques that operate according to the principles described herein, the client device 112 of the wireless access point 104 before receiving all control transmissions, including advertising data (or other content). The actions described above (ie, actions 210 and 212), which can confirm the identity and confirm the identity of the wireless access point and / or the wireless network, can be performed before the action 208.
As mentioned above in connection with Process 200, verifying the identity of the wireless access point and / or wireless network (as in Block 210 of Process 200) can be done in any suitable way. it can. Described below in connection with Figures 3-5 are exemplary techniques for verifying the identity of wireless access points and / or wireless networks. However, it should be understood that these techniques are merely examples of the types of techniques that can be performed according to the principles described herein, and that other techniques are possible.
Figure 3 shows an exemplary process 300 through which the identity of a wireless access point can be confirmed. Similar to the above, Figure 3 is described in relation to advertising and commercial organizations, but any suitable type of content may be used.
Process 300 begins at block 302, where the client device retrieves the trust information of one or more commercial organizations. The trust information can include the entity's public key and / or PKI certificate and can be retrieved in any suitable form, such as from the kiosk associated with the entity. At block 304, the client device detects that it is within the range of the radio access point that has the trust information (for example, by comparing the detected radio access point identifier with the credit information identifier). At block 306, the client device sends an encrypted test control transmission to the wireless access point using the trust information. The test control vehicle can contain any suitable information and can include a challenge phrase and / or a nonce. Any suitable message can be used within the test control vehicle (for example, a random or pseudo-random bitstring, "Red trees are". Proprietary text such as "blue", transmission time and / or transmission position, or any other suitable data). In some techniques that work according to the example in Figure 3, the payload of the test control vehicle is the trust information of the client device 112, such as the client device's public key / PKI certificate and / or the user's public key / PKI certificate. Below, for clarity, it can also include (collectively referred to as client trust information).
At block 308, the client device receives a control transmission from the wireless access point in response to the test control message. The response control message can include the content of the test control message transmitted unencrypted, or in embodiments where the test control message further contains client trust information, the content of the response control message, the client. It can be encrypted and sent back using the credit information. When receiving (and, with some techniques, decrypting) the response control transmission, the client device matches the content with what was encrypted and transmitted (for example, the content of the test control transmission). In determining, the client device can assume that the wireless access point holds the private key that corresponds to the public key that the content of the test control transmission is encrypted with it, and thus the client device It can be assumed that the wireless access point exchanging messages is the expected wireless access point.
At block 310, if the wireless access point is the expected wireless access point (for example, if the wireless access point is authentic), the client device accepts all future communications from the wireless access point as authentic. You can freely use the content of the control message (for example, you can display the advertisement sent by the wireless access point to the user), and this process ends. However, in block 310, if the wireless access point is determined not to be the expected wireless access point, then in block 314, the client device is the wireless access point and wireless access point for any suitable time period. Control transmissions from can be ignored.
In some embodiments of the technique that works according to the example of FIG. 3, a control message containing content (eg, advertising data) can be sent unencrypted rather than encrypted. In some alternative embodiments, following the authentication technique of process 300, the wireless access point sends a control message encrypted using the client credit information as an alternative to or in addition to broadcasting the control message to the client device. Can be sent to. In other embodiments, all or part of the control message, including the content transmitted by the wireless access point, is encrypted using the wireless access point's trust information and the client device uses the content (eg, content). Before displaying to the user), use the trust information to decrypt each message.
In some techniques that implement the principles disclosed herein, wireless access point identity verification is the correct decryption of control messages to verify the identity of wireless access points and / or wireless networks. You can only rely on it. Figure 4 shows Process 400, which is an example of such a technique. As before, Process 400 is described below in relation to commercial advertising, but any technique that can be performed in accordance with some of the principles disclosed herein is any suitable one for the content of the control message. Or multiple types of information can be exchanged.
Process 400 is initiated at block 402, where the client device retrieves the credit information of the commercial organization. The credit information can be retrieved in any appropriate form, such as by reading the credit information from a kiosk associated with a commercial organization. At block 404, the client detects that it is within the range of the radio access point that has the trust information (for example, by comparing the detected radio access point identifier with the trust information identifier) and block 406. Receives a control transmission (eg, a response to a probe request sent by a beacon or client device) from a wireless access point.
At block 408, client device 112 uses the trust information retrieved at block 402 to process the control transmission to verify the identity of the wireless access point. The processing of the control transmission can include decrypting the control transmission using the trust information. If the control transfer can be successfully decrypted using the retrieved trust information, the client device 112 has the control transfer encrypted using the private key that corresponds to the public key of the trust information. It can be assumed that the radio access point is the expected radio access point and the transmission is authentic.
If block 410 determines that the communicator is authentic, block 412 uses the content of the control communicator in any appropriate form, such as by extracting an ad and displaying it to the user. You can then end this process. However, in block 410, if the transmission is determined to be unauthentic (ie, it cannot be confirmed that the transmission came from the expected radio access point), then in block 414, the radio access point is optional. Ignoring for an appropriate period of time, this process ends without using any content.
FIG. 5 shows an alternative process 500 that operates according to some of the principles disclosed herein. Process 500 is started at block 502, where client device 112 retrieves the credit information of the commercial organization. Credit information retrieves credit information from a server, such as Server 116, which can perform a web service that acts as a certification authority and / or a repository of credit information in some embodiments of the technique that works according to the example in Figure 5. It can be taken out in any suitable form, such as by. The credit information retrieved in block 502 can be a single credit information or multiple credit information retrieved within any suitable grouping. In some embodiments, the trust information can be retrieved in response to a user request, but in some embodiments, the client device 112 responds to any suitable stimulus in addition or instead. Can be adapted to automatically retrieve credit information. The stimulus is the time or location (for example, when it detects that the client device is near the location of the entity), the detection of wireless access points associated with the entity, the addition of previously retrieved credit information or It can be a display of what has changed, received from server 116, or any other suitable stimulus.
At block 504, the client device 112 detects that it is within the range of the radio access point that has the trust information (eg, by comparing the detected radio access point identifier with the trust information identifier). At block 506, the radio access point receives a control transmission (eg, a response to a probe request sent by a beacon or client device).
At block 508, client device 112 uses the trust information retrieved at block 502 to process the control transmission to verify the identity of the wireless access point. The processing of the control transmission can include decrypting the control transmission using the trust information. If the control transfer can be successfully decrypted using the retrieved trust information, the client device 112 has the control transfer encrypted using the private key that corresponds to the public key of the trust information. It can be assumed that the radio access point is the expected radio access point and the transmission is authentic.
If block 510 determines that the communicator is authentic, block 512 uses the content of the control communicator in any suitable form, such as by extracting an ad and displaying it to the user. You can then end this process. However, in block 510, if the transmission is determined to be unauthentic (ie, it cannot be confirmed that the transmission came from the expected radio access point), then in block 514, the radio access point is optional. Ignoring for an appropriate period of time, this process ends without using any content.
The techniques described above in connection with FIGS. 3-5 are merely illustrations of the types of techniques that can implement some of the principles described herein to verify the identity of wireless networks and / or wireless access points. Please understand that. The present invention is not limited to performing any particular technique of any of these techniques, as any suitable technique can be performed in accordance with the principles disclosed herein. Please understand that it is not limited to the implementation of.
Although the exemplary technique described above focused on verifying the identity of wireless access points and / or wireless networks by decrypting encrypted control messages using trust information, The present invention is not limited thereto. In addition to or instead, techniques can be implemented to verify the identity of the wireless network in other ways, including the use of environmental information. For example, the wireless access point or wireless network trust information can be the expected location of the wireless access point or wireless network, the location of the client device and / or the wireless access point when within range of the wireless access point. It can be compared with the position information contained in the control transmission from. In this way, if the client device detects a wireless access point when it is not in the expected location, or if the location information in the control transmission is not the expected location information, the detected radio access point is , May be a scam. The location information that can be used can be any suitable location information, such as a mailing address, a location within a building, latitude / longitude data, and / or any other suitable location information. In addition to or instead, environmental information can include time information of the control vehicle. For example, the control vehicle can include time information that describes the time when the control vehicle was first transmitted. When the client device receives the control transmission, the client device can compare the time information of the control transmission with the trust information including the current time. The trust information can be used to determine if the broadcast time is within a reasonable difference from the current time. For example, if the difference between the broadcast time of the control carrier and the current time is longer than a certain length of time (for example, 10 seconds), the client device depends on the device it rebroadcasts the control message. It can be determined that it is the target of a reply attack, and the detected radio It can be determined that the access point is fraudulent. As the present invention is not limited in this regard, other embodiments may implement other techniques for verifying the identity of wireless access points and / or wireless networks.
Described above are various techniques that can be used by client devices to implement some of the principles described herein. However, in some systems that implement one or more of the principles described herein, one or more elements of the wireless network to which the client device is connected may use techniques that follow these principles. Please understand that it can be done. Figure 6 shows an exemplary process 600 that can be performed by a wireless access point that follows some of these principles.
Process 600 is started at block 602, where the wireless access point retrieves local trust information from the data store. The local trust information can include any suitable trust information, such as a private key that can be used in a public key encryption algorithm or any other suitable local trust information. At block 604, the content is retrieved from the data store 106, encoded within the control transmission, and the control transmission is encrypted using the local trust information in block 602. The content encrypted in block 604 is advertising data, location data, data describing one or more services (eg, printing services) provided by wireless access points and / or wireless networks, or any other. It can be any suitable content, such as type information. At block 606, the control transmission is transmitted by the wireless access point. In some embodiments, the control carrier can be transmitted as a beacon to all client devices within the range of the wireless access point, whereas in an alternative embodiment, the control carrier is delivered from the client device by the wireless access point. It can be sent as a response to a received probe request or as any other suitable control carrier.
Techniques for implementing one or more of the principles described herein can be implemented in any of a number of computer system configurations and are not limited to a particular type of configuration. Figures 7-8 show various computer systems in which the embodiments of the present invention can work, but other computer systems are possible. It should be understood that Figures 7-8 are not intended to be either an illustration or a comprehensive illustration of the components required for a computing device to act as a wireless access point or client device.
FIG. 7 shows an exemplary wireless access point 104. The wireless access point 104 includes a processor 702, a network adapter 704, and a computer-readable medium 706. The network adapter 704 is with any suitable hardware and / or software that allows the wireless access point 104 to communicate with any other suitable computing device over any suitable computing network. can do. The computing network can be any suitable wired and / or wireless communication medium that exchanges data between multiple computers, including the Internet. For example, computing networks, at least in part, IEEE It can be a wireless network that operates according to any suitable wireless networking protocol such as 802.11, GSM, Bluetooth, WiMAX, UWB, and / or any other suitable protocol. In some embodiments of the invention, the wireless access point 104 allows the wireless access point 104 to communicate with two different communication networks, such as a wired computing network and a wireless computing network, and exchange data between the two. Two network adapters 704 can be included to make this possible. The computer-readable medium 706 can be adapted to store the data processed by the processor 702 and / or the instructions executed by it. Processor 702 enables processing of data and execution of instructions. Data and instructions can be stored on a computer-readable medium 706, which can allow communication between, for example, components of the wireless access point 104.
According to some of the exemplary techniques described herein, the data stores 106 of FIGS. 1A, 1B, and 1C can be implemented as computer-readable media 706, and the data stored in computer-readable media 706. And instructions take any appropriate content (eg, advertising data 710 or other suitable content) from the data store for transmission, encode that content within the control transmission, generate the control transmission, and so on. It can include access point firmware 708, which can be software executed by processor 702, which directs the wireless access point 104 to perform various functions. The computer-readable medium 706 can further store content such as advertising data 710 (ie, advertising data 108). Advertising data 710 shall be any suitable type or number of data that can be transmitted by the wireless access point 104, including, for example, data describing text, images, audio, or video, or any combination thereof. Can be done. Advertising data 710 can be data that describes a single advertisement for one or more services associated with an entity associated with wireless access point 104, or one or more associated with an entity. It can be data that describes multiple advertisements related to the service of. In an embodiment of the invention, the entity can be a commercial organization (eg, a store) and the service can be a commercial service. As mentioned above, it should be understood that the advertising data is merely an example of the types of content that can be transmitted by the wireless access point 104 according to one or more of the principles described herein.
According to some of the exemplary techniques described herein, the computer-readable medium 706 further retains the wireless access point 104 and / or the trust information 712 of the wireless network to which the wireless access point is connected. be able to. The trust information 712 can be any suitable credit information used in the public key encryption algorithm, such as the wireless access point 104 and / or the private key of the wireless network. However, it is understood that any suitable credit information, including, for example, environmental information, can be used as credit information 712, as the private key is merely an example of the type of information that can be used as credit information according to the principles described herein. I want to be.
FIG. 8 shows an exemplary client device 112 that can be implemented as a client device according to the principles described herein. As mentioned above, any suitable computing device, mobile or immobile, can be used as the client device 112. The client device 112 is designed and used for multiple purposes, including desktop personal computers, laptop personal computers, servers, personal digital assistants (PDAs), smartphones / mobile phones, or any other suitable electronic device. It can be a computing device designed for use by. An alternative is to make the client device 110 any computing device, such as a server or rack-mounted networking device, that is not intended for normal use by the user, or is intended for a single or limited purpose. Can be done.
The client device 112 includes a processor 802, a network adapter 804, and a computer-readable medium 808. The network adapter 804 is any suitable hardware and / or software that allows the client device 112 to communicate with any other suitable computing device over any suitable computing network. be able to. The computing network can be any suitable wired and / or wireless communication medium that exchanges data between multiple computers, including the Internet. For example, computing networks, at least in part, IEEE It can be a wireless network that operates according to any suitable wireless networking protocol such as 802.11, GSM, Bluetooth, WiMAX, UWB, and / or any other suitable protocol. The network adapter 804 can further include an application programmer interface (API) 806 that allows the interaction between the network adapter 804 and the application running on the client device 112. API 806 requires the application to initiate monitoring of the transmission from the wireless access point by the network adapter 804 and the content from the transmission (eg, advertising data, location data, or any other suitable content). The executable function can be provided to the application on the client device 112 so that the wireless access point can request additional information or perform any other suitable function. The computer-readable medium 808 can be adapted to store the data processed by processor 802 and / or the instructions executed by it. Processor 802 enables processing of data and execution of instructions. Data and instructions can be stored on a computer-readable medium 806, which can allow communication between, for example, components of client device 112.
According to some embodiments of the invention, the data and instructions stored on the computer-readable medium 808 are the content of the control vehicle received by the network adapter 804 (eg, advertising data and / or the product being advertised (eg, advertising data and / or the product being advertised) It can include a user interface 810 that can present one or more) or additional information about the service (one or more) to the user. The user interface 810 can present the content in any suitable format. In some embodiments of the client device 112, the user interface 810 can be a component of the operating system or firmware of the client device 112, whereas in alternative embodiments of the invention the content can be displayed and used within an application. As such, the user interface 810 can be an independent application or part of an application.
According to one or more of the principles described herein, the computer-readable medium 808 of client device 112 may further include a data store of trust information 812. The credit information 812 can be one or more credit information for one or more wireless access points and / or wireless networks and can include any suitable one or more types of credit information. .. For example, as mentioned above, the trust information can be a wireless access point and / or wireless network public key and / or PKI certificate, and / or time data or wireless access point and / or wireless network. It can be used as environmental information such as location data of.
The computer-readable medium 808 also provides validation module 814 to test the control message received by the network adapter 804 using trust information 812 to determine the authenticity of the wireless access point and / or wireless network. Can include. Validation module 814 can implement any suitable technique, including, but not limited to, any one or more of the exemplary techniques described above. In some embodiments, the validation module 814 can be incorporated into the operating system of the client device 112, but in an alternative embodiment, the validation module 814 can be incorporated, for example, as an independent application running on the client device 112 or optionally. It can be implemented separately from the operating system in other suitable ways.
The embodiments described above of the present invention can be implemented in any of a number of forms. For example, embodiments can be implemented using hardware, software, or a combination thereof. When implemented in software, software code can be executed on any suitable processor or set of processors, whether located within a single computer or distributed among multiple computers. ..
In addition, please understand that the computer can be implemented in any of several forms, including rack-mounted computers, desktop computers, laptop computers, or tablet computers. In addition, the computer may be incorporated into devices that are not generally considered computers but have adequate processing power, including personal digital assistants (PDAs), smart phones, or any other suitable portable or fixed electronic device. it can.
The computer can also have one or more input and output devices. These devices can be used, among other things, to present a user interface. Examples of output devices that can be used to provide a user interface include a printer or display for visual presentation of output and a speaker or other sound generation device for audible presentation of output. Examples of input devices that can be used for the user interface include keyboards and pointing devices such as mice, touchpads, and digitizing tables. As another example, a computer can receive input information via voice recognition or in other audible formats.
Such computers can be interconnected by any suitable form of network, including as a local area network or wide area network, such as a corporate network or the Internet. Such networks can be based on any suitable technology, can operate according to any suitable protocol, and can include wireless networks, wired networks, or fiber optic networks.
Also, the various methods or methods outlined herein can be coded as software that can run on one or more processors using any one of different operating systems or platforms. In addition, such software can be written using multiple suitable programming languages and / or either traditional programming tools or scripting tools and run in executable machine language code or frameworks or virtual machines. It can also be compiled as intermediate code.
In this regard, when the invention is run on one or more computers or other processors, it encodes one or more programs that perform the methods of implementing the various embodiments of the invention described above. Computer storage (or multiple computer-readable media) (eg, computer memory, one or more floppy (registered trademark) disks, compact disks, optical disks, magnetic tapes, flash memory, field programmable gate arrays or other semiconductors. It can be implemented as a circuit configuration in the device, etc.). A computer-readable medium may load one or more programs stored on it into one or more different computers or other processors to accommodate the various aspects of the invention described above. It can be portable so that it can be carried out.
The term "program" or "software" is used herein to describe any type of computer code or computer that can be used to program a computer or other processor to implement the various aspects of the invention described above. Used in a comprehensive sense to refer to a set of executable instructions. Further, according to one aspect of this embodiment, one or more computer programs that execute the methods of the invention when executed do not need to reside on a single computer or processor, but the invention. It should be appreciated that it can be distributed in a modular manner among multiple different computers or processors to carry out the various aspects of.
Computer-executable instructions can be in many forms, such as program modules, executed by one or more computers or other devices. In general, a program module includes routines, programs, objects, components, data structures, etc. that perform a particular task or implement a particular abstract data type. In general, the functionality of program modules can be combined or distributed as desired in various embodiments.
The various aspects of the invention can be used alone, in combination, or in various arrangements not specifically described in the embodiments described above, and thus in their application, in the aforementioned description. The details and arrangement of the components shown or illustrated in the drawings are not limited. For example, the embodiments described in one embodiment can be combined in any form with the embodiments described in another embodiment.
The use of order-indicating terms such as "first," "second," and "third" in a claim to modify a claim element is itself a priority, priority, or another claim. It does not mean the order of certain claim elements for an element or the temporal order in which an act of a certain method is performed, but simply to distinguish the claim elements, a certain claim element with a certain name has the same name. Used as a label to distinguish from another claim element having (except for the use of ordering terms).
Also, the terminology and terminology used herein are for illustration purposes only and should not be considered limiting. The use of "including", "comprising", or "having", "containing", "involving", and their inflectional changes herein is used. , Means to include the items listed thereafter and their equivalents as well as additional items.
Therefore, it should be understood that those skilled in the art will immediately think of various changes, modifications, and improvements as a plurality of aspects of at least one embodiment of the present invention have been described. Such changes, modifications, and improvements are intended to be part of this disclosure and are intended to be included in the spirit and scope of the present invention. Therefore, the above description and drawings are merely examples.
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US9607320B2 | Cited by | United States of America | Applicant |
| JP2013535160A | Cited by | Japan | Examiner |
| US9607320B2 | Cited by | United States of America | Applicant |
| JP2013535160A | Cited by | Japan | Search report |
| US9607320B2 | Cited by | United States of America | Applicant |
| JP2003091679A | Cites | Japan | Examiner |
| JP2003333636A | Cites | Japan | Examiner |
| JP2007036790A | Cites | Japan | Examiner |
| JP2007068164A | Cites | Japan | Examiner |
| JP2007088737A | Cites | Japan | Examiner |
| JP2007509565A | Cites | Japan | Examiner |
| JP2008042862A | Cites | Japan | Examiner |
16 members in 6 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 12035531 | United States of America | – | |
| 3553108 | United States of America | A | |
| 3553108 | United States of America | A | |
| 2009031451 | United States of America | W | |
| 2009031451 | United States of America | W | |
| 2008035531 | – | – | – |
| 2009031451 | – | – | – |
| US20080035531 | – | – | – |
| WO2009US31451 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| US2009214036A1 | United States of America | A1 | |
| WO2009105302A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2009105302A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201006201A | Taiwan Province of China | A | |
| EP2245790A1 | European Patent Office (EPO) | A1 | |
| CN101965710A | China | A | |
| JP2011518450AThis record | Japan | A | |
| JP5271362B2 | Japan | B2 | |
| TWI450554B | Taiwan Province of China | B | |
| US9105031B2 | United States of America | B2 | |
| CN101965710B | China | B | |
| US2015327067A1 | United States of America | A1 | |
| EP2245790A4 | European Patent Office (EPO) | A4 | |
| US9591483B2 | United States of America | B2 | |
| US2017142586A1 | United States of America | A1 | |
| EP2245790B1 | European Patent Office (EPO) | B1 |
20 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Notification of acceptance of power of attorneyJAPANESE INTERMEDIATE CODE: R3D02RD02 | RD02 | |
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2011518450
- Publication, DOCDB
- 2011518450
- Publication, EPODOC
- JP2011518450
- Application
- 2010547662
- Application, DOCDB
- 2010547662
- Application, EPODOC
- JP20100547662
Titles2
- Japanese
- 無線ネットワークの認証機構
- English
- Wireless network authentication mechanism
Classification
- CPC, 27
- H04W12/10
- H04W12/06
- H04L9/3263
- H04L9/3271
- H04L2209/56
- H04L2209/60
- H04L2209/805
- H04L63/126
- H04W4/00
- H04L63/0442
- H04L63/0823
- H04W84/12
- G06Q30/02
- G06Q30/0251
- G06Q30/0267
- H04W4/80
- G06Q30/0277
- H04W4/02
- H04W12/63
- H04W12/122
- H04W48/08
- H04W48/16
- H04W12/08
- H04L9/30
- H04W12/12
- H04L63/123
- H04W12/04
- IPC, 2
- H04L9 32
- G06Q30 00
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo