Authentication for relay deployment
Abstract
Techniques for providing enterprise mode security for repeaters are disclosed. For example, enterprise-mode security under IEEE 802.1x is provided for repeaters or other similar devices to extend the coverage of access point hotspots or other similar access point use cases. According to one aspect, the repeater incorporates an authentication client associated with the authentication server. According to another aspect, a 4-address format is used to tunnel messages via a repeater between the station and the access point. According to another aspect, the cryptographic master key associated with the access point and the station is provided to the repeater to allow the repeater to be an authenticator for the station. [Selection diagram] Fig. 12

Term
Projected expiry 13 March 2034.
- Priority
- Filed
- Published
- Today
- Projected expiry
30 claims: 4 independent, 26 dependent
- 1A device for communication, wherein the device is configured to be associated with a second device, the device is configured to authenticate to a server, and the device is encrypted from the server. A device comprising a first communication device configured to receive a master key and a second communication device configured to send the cryptographic master key to the second device.
- 8A method of communication, wherein the first device is associated with a second device, the first device is authenticated against the server, and the method is such that the first device is the said. A method comprising receiving a cryptographic master key from a server and sending the cryptographic master key to the second device.
- 15A device for communication, wherein the second device is configured to be associated with the device, the device is configured to be associated with the third device, and the device is configured to be associated with the second device. A communication device configured to receive a cryptographic master key from a device, wherein the cryptographic master key is from a server associated with the second device, said the third via a wireless channel. A device comprising the device and a processing system configured to use the cryptographic master key to establish secure communication.
- 24A method of communication, wherein the first device is associated with a second device, the second device is associated with a third device, and the method is such that the second device is associated with. Receiving the cryptographic master key from the first device, where the cryptographic master key is from a server associated with the first device, and with the third device via a wireless channel. A method comprising using the cryptographic master key to establish secure communication.
Independent claims4
254 paragraphs, as filed
Related application
Priority claim [0001] This application has been assigned Agent Reference No. 131982P1, which was filed on March 15, 2013, owned by the assignee of the present application, the entire disclosure of which is incorporated herein by reference. Claims the interests of US Provisional Patent Application No. 61 / 789,915 and US Non-Provisional Patent Application No. 14 / 207,463 filed on March 12, 2014, as well as their priority.
Cross-reference of related applications [0002] This application, of the title "AUTHENTICATION FOR RELAY DEPLOYMENT", has been assigned agent reference number 131982U1, filed March 12, 2014, the disclosure of which is incorporated herein by reference. Concerning US Patent Application No. 14 / 207,440 owned by the assignee of the present application, which was filed at the same time.
[0003] The present application generally relates to wireless communications and, in more detail, to network authentication, without limitation.
Introduction [0004] Communication networks allow users to exchange messages between several interacting spatially isolated devices. Communication networks can be classified according to a geographical range that can be, for example, a wide area, a metropolitan area, a local area, or a personal area. Such networks can be designated as wide area networks (WANs), metropolitan area networks (MANs), local area networks (LANs), or personal area networks (PANs), respectively. Communication networks also depend on the exchange and / or routing techniques used to interconnect various network devices and devices. For example, communication networks can use circuit switching, packet switching, or any combination of the two. Communication networks can vary depending on the type of physical medium that can be used for transmission. For example, a communication network may support wired communication, wireless communication, or both types of communication. Communication networks can also use different sets of communication protocols. Examples of such communication protocols are the Internet Protocol (IP) suite, Synchronous Optical Network (SONET) protocol, and Ethernet® protocol.
[0005] In general, wireless networks use intangible physical media in non-inductive propagation modes that use radio, microwave, infrared, light, or electromagnetic waves in other frequency bands. Therefore, wireless networks can be better adapted to facilitate user mobility and rapid field deployment compared to fixed wired networks. For example, wireless networks are mobile and easily support network elements with dynamic connectivity needs. The use of wireless networks may also be preferable for scenarios where it is desirable to provide a network architecture with an ad hoc topology rather than a fixed topology.
[0006] A wireless network can be deployed across a defined geographic area to provide different types of services (eg, voice, data, multimedia services, etc.) to users within that geographic area. .. In a typical implementation, one or more access points are deployed to provide wireless connectivity to access terminals (eg, STAs) operating within a geographic area served by a wireless network.
[0007] Some types of wireless networks use repeaters. In general, repeaters can be used to extend access point coverage. Thus, in some aspects, repeaters have access point-like functionality (for example, to communicate with an access terminal) and access terminal-like functionality (for example, to communicate with an access terminal). Including.
[0008] Traditional repeater designs (eg, repeater networks supported by Zigbee®, Z-Wave, etc.) use personal mode security. In some aspects, personal mode security means that the password for a given access terminal is known to the access point (or repeater) servicing the access terminal. Therefore, security is provided on a link-to-link basis.
[0009] A summary of some exemplary embodiments of the present disclosure is as follows. This summary is provided for the convenience of the reader in order to provide a basic understanding of such aspects and does not necessarily define the scope of this disclosure in its entirety. This overview is not a comprehensive overview of all intended aspects, nor does it identify the major or important elements of all aspects, nor does it define the scope of any or all aspects. Its sole purpose is to present some concepts in one or more embodiments in a simplified form as an introduction to a more detailed description presented later. For convenience, the term several aspects may be used herein to refer to a single aspect or multiple aspects of the present disclosure.
[0010] The present disclosure relates to authentication techniques for repeater deployment in some aspects. For example, repeaters can be used to extend the range of access points (eg, effective coverage areas) that are deployed as hotspots or in some other similar fashion. Traditionally, hotspots use corporate mode security where the password of the access terminal is, in some cases, unknown to the hotspot access point. Instead, the access terminal connects to the access point based on the authentication performed between the access terminal and the network authentication server (eg, RADIUS or DIAMETER server).
[0011] The present disclosure relates to techniques for providing enterprise mode security for repeaters in some aspects. In some embodiments, corporate mode security under the Institute of Electrical and Electronics Engineers (IEEE) 802.1x provides repeaters to enable hotspot use cases for repeaters and other similar use cases. Will be done.
[0012] According to one aspect, the repeater incorporates an authentication client associated with the authentication server. Therefore, the repeater can be an authenticator for any station that attempts to access the network through the repeater.
[0013] According to another aspect, a 4-address format is used to tunnel messages via a repeater between the station and the access point. In this case, the repeater may transfer the authentication message between the station and the access point.
[0014] According to another aspect, the access point and the cryptographic master key associated with the station are provided to the repeater to allow the repeater to be an authenticator for the station. Therefore, if a message from a station is destined for a repeater, the repeater can decipher those messages.
[0015] Various aspects of the present disclosure provide a device configured for communication, wherein the device is configured to be associated with a second device. The device comprises a processing system configured to authenticate the device to the server and a communication device configured to send a message to the server to authorize the second device as an authenticator.
[0016] A further aspect of the present disclosure provides a method of communication, wherein the first device is associated with a second device. This method comprises authenticating the first device to the server and sending a message from the first device to the server to authorize the second device as an authenticator.
[0017] Another aspect of the present disclosure provides another device configured for communication, wherein the device is configured to be associated with a second device. The device comprises means for authenticating the device to the server and means for sending a message to the server to authorize the second device as an authenticator.
[0018] An additional aspect of the present disclosure provides a computer program product comprising a computer-readable medium, wherein the first device is associated with a second device. This computer-readable medium is capable of authenticating the first device to the server and sending a message from the first device to the server to authorize the second device as an authenticator. Code.
[0019] Various aspects of the present disclosure provide a device configured for communication, wherein a second device is configured to be associated with the device, which device is a third device. The second device is configured to connect to the server. This device is configured to set up a session with a communication device that is configured to receive an authentication certificate from a second device to set up a session with the server and that authentication certificate. A processing system is provided, wherein the communication device is further configured to communicate with the server via a session to authenticate the server with a third device.
A further aspect of the present disclosure provides a method of communication, wherein the first device is associated with a second device, the first device is associated with a third device, and a second device. The device is connected to the server. In this method, the first device receives an authentication certificate from the second device to set up a session with the server, and the authentication certificate is used to set up a session with the server. It comprises communicating with the server through a session to authenticate the third device.
[0021] A further aspect of the present disclosure provides another device configured for communication, wherein a second device is configured to be associated with that device and the device is a third. The second device is configured to be connected to the server. This device is a means for receiving an authentication certificate from a second device to set up a session with a server, a means for setting up a session using the authentication certificate, and a server and a third device. It is provided with a means for communicating with the server via a session to authenticate the device.
[0022] An additional aspect of the present disclosure provides a computer program product comprising a computer-readable medium, wherein the first apparatus is configured to be associated with a second apparatus, wherein the first apparatus. , The second device is configured to be associated with a third device, and the second device is configured to connect to a server. This computer-readable medium receives an authentication certificate from a second device to set up a session with a server by the first device, and uses that authentication certificate to set up a session. It has code that can be executed to communicate with the server through a session to authenticate the server with a third device.
[0023] Various aspects of the present disclosure provide a device configured for communication, wherein a second device is configured to authenticate to that device. This device identifies a communication device configured to receive a message from a second device, and here the message identifies a third device associated with the second device, as a result of receiving the message. , A processing system configured to allow a third device as an authenticator.
[0024] A further aspect of the present disclosure provides a method of communication, where the first device is authenticated against the server. This method involves receiving a message from the first device by the server, where the message identifies the second device associated with the first device, as a result of receiving the message. It is provided with the permission of the device as an authenticator.
[0025] A further aspect of the present disclosure provides another device configured for communication, wherein the second device is configured to authenticate to that device. This device is a means for receiving a message from the second device and, where the message identifies a third device associated with the second device, a third as a result of receiving the message. It is provided with a means for permitting the device as an authenticator.
An additional aspect of the present disclosure provides a computer program product comprising a computer-readable medium, wherein the first device is configured to authenticate to a server. This computer-readable medium receives a message from a first device by a server, where the message identifies a second device associated with the first device, as a result of receiving the message. It has code that can be executed to allow the second device as an authenticator.
[0027] Various aspects of the present disclosure provide a device configured for communication, wherein the device is configured to be associated with a second device, the second device being a third device. Configured to be associated with the device. This device uses a processing system configured to initiate communication with a third device through a second device and a message with a source address, destination address, transmitter address, and receiver address. , A communication device configured to communicate with a third device via a second device.
[0028] A further aspect of the present disclosure provides a method of communication, wherein the first device is associated with a second device and the second device is associated with a third device. This method uses the first device to initiate communication with the third device through the second device and a message with a source address, a destination address, a transmitter address, and a receiver address. , Combining with a third device via a second device.
[0029] A further aspect of the present disclosure provides another device configured for communication, wherein the device is configured to be associated with a second device, wherein the second device is a second device. Configured to be associated with 3 devices. This device uses a means for initiating communication with the third device through the second device and a message comprising a source address, a destination address, a transmitter address, and a receiver address. It is provided with a means for communicating with a third device via the device.
An additional aspect of the present disclosure provides a computer program product comprising a computer-readable medium, wherein the first apparatus is configured to be associated with a second apparatus, the second apparatus. , Configured to be associated with a third device. This computer-readable medium uses a message with a source address, a destination address, a transmitter address, and a receiver address to initiate communication with the third device through the second device by the first device. It is provided with code that can be executed to communicate with the third device via the second device.
[0031] Various aspects of the present disclosure provide a device configured for communication, wherein a second device is configured to be associated with the device, which device is a third device. It is configured to be associated with. This device transfers messages between a processing system configured to initiate the transfer of messages between the second and third devices and between the second and third devices. Each message comprises a source address, a destination address, a transmitter address, and a receiver address.
A further aspect of the present disclosure provides a method of communication, wherein the first device is associated with a second device and the second device is associated with a third device. This method initiates the transfer of messages between the first and third devices by the second device and transfers those messages between the first and third devices. Here, each message comprises a source address, a destination address, a transmitter address, and a receiver address.
[0033] Yet a further aspect of the present disclosure provides another device configured for communication, wherein a second device is configured to be associated with this device, which is a third device. It is configured to be associated with the device of. This device is a means for initiating the transfer of messages between the second device and the third device and a means for transferring those messages between the second device and the third device. Here, each message comprises a source address, a destination address, a transmitter address, and a receiver address.
[0034] An additional aspect of the present disclosure provides a computer program product comprising a computer-readable medium, wherein the first apparatus is configured to be associated with a second apparatus, the second apparatus. , Configured to be associated with a third device. This computer-readable medium initiates the transfer of messages between the first and third devices by the second device and those messages between the first and third devices. Each message comprises a source address, a destination address, a transmitter address, and a receiver address.
[0035] Various aspects of the present disclosure provide a device configured for communication, wherein the device is configured to be associated with a second device, which device authenticates to a server. It is configured to be. The device comprises a first communication device configured to receive the cryptographic master key from the server and a second communication device configured to send the cryptographic master key to the second device.
A further aspect of the present disclosure provides a method of communication, wherein the first device is associated with a second device and the first device is authenticated against the server. This method comprises receiving the cryptographic master key from the server by the first device and sending the cryptographic master key to the second device.
[0037] A further aspect of the present disclosure provides another device configured for communication, wherein the device is configured to be associated with a second device, which device is directed to a server. Is configured to be authenticated. This device includes means for receiving the cryptographic master key from the server and means for sending the cryptographic master key to the second device.
[0038] An additional aspect of the present disclosure provides a computer program product comprising a computer readable medium, wherein the first device is associated with a second device and the first device is to a server. Is authenticated. The computer-readable medium comprises code that can be executed by the first device to receive the cryptographic master key from the server and send the cryptographic master key to the second device.
[0039] Various aspects of the present disclosure provide a device configured for communication, wherein a second device is configured to be associated with the device, which device is a third device. It is configured to be associated with. This device is configured to receive a cryptographic master key from a second device, and here the cryptographic master key is from a server associated with the second device, via a wireless channel. It comprises a third device and a processing system configured to use its cryptographic master key to establish secure communication.
A further aspect of the present disclosure provides a method of communication, wherein the first device is associated with a second device and the second device is associated with a third device. This method receives the cryptographic master key from the first device by the second device, where the cryptographic master key is from the server associated with the first device, over a wireless channel. It comprises using its cryptographic master key to establish secure communication with a third device.
[0041] A further aspect of the present disclosure provides another device configured for communication, wherein a second device is configured to be associated with this device, which is a third device. It is configured to be associated with the device of. This device is a means for receiving a cryptographic master key from a second device, and here the cryptographic master key is from a server associated with the second device, via a wireless channel, a third device. And a means for using the cryptographic master key to establish secure communication.
An additional aspect of the present disclosure provides a computer program product comprising a computer-readable medium, wherein the first apparatus is configured to be associated with a second apparatus, the second apparatus. , Configured to be associated with a third device. This computer-readable medium receives the cryptographic master key from the first device by the second device, where the cryptographic master key is from the server associated with the first device, wireless channel. It contains code that can be executed to use its cryptographic master key to establish secure communication with a third device via.
[0043] These and other exemplary embodiments of the present disclosure will be described in the following detailed description and claims, as well as in the accompanying drawings.<figref num="1">The figure which shows an example of the network entity which supports authentication by some aspects of this disclosure.</figref><figref num="2">The figure which shows an example of the network environment where one or more aspects of this disclosure may find an application example.</figref><figref num="3">The figure which shows an example which repeater includes an authentication client by some aspects of this disclosure.</figref><figref num="4">The figure which shows an example of the scheme for authentication by some aspects of this disclosure.</figref><figref num="5">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="6">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="7">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="8">The figure which shows an example in which an authentication message is tunneled through a repeater by some aspects of this disclosure.</figref><figref num="9">The figure which shows an example of the scheme for repeater tunneling by some aspects of this disclosure.</figref><figref num="10">Flowchart of some exemplary aspects of operation relating to repeater tunneling, according to some aspects of the present disclosure.</figref><figref num="11">Flowchart of some exemplary aspects of operation relating to repeater tunneling, according to some aspects of the present disclosure.</figref><figref num="12">The figure which shows an example in which a repeater functions as an authenticator according to some aspects of this disclosure.</figref><figref num="13">The figure which shows an example of the scheme for authentication by some aspects of this disclosure.</figref><figref num="14">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="15">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="16">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="17">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="18">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="19">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="20">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="21">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="22">Flowchart of some exemplary aspects of authentication behavior according to some aspects of the present disclosure.</figref><figref num="23">A functional block diagram of an exemplary device that can be used within a wireless communication system according to some aspects of the disclosure.</figref><figref num="24">Functional block diagram of an exemplary component that can be used in the device of FIG. 23 to transmit wireless communication.</figref><figref num="25">Functional block diagram of an exemplary component that may be utilized in the device of FIG. 23 to receive wireless communication.</figref><figref num="26">Simplified block diagram of some exemplary aspects of components that may be used within a communication node, according to some aspects of the present disclosure.</figref><figref num="27">Simplified block diagram of some exemplary embodiments of the device configured with features relating to authentication and use of repeaters, according to some embodiments of the present disclosure.</figref><figref num="28">Simplified block diagram of some exemplary embodiments of the device configured with features relating to authentication and use of repeaters, according to some embodiments of the present disclosure.</figref><figref num="29">Simplified block diagram of some exemplary embodiments of the device configured with features relating to authentication and use of repeaters, according to some embodiments of the present disclosure.</figref><figref num="30">Simplified block diagram of some exemplary embodiments of the device configured with features relating to authentication and use of repeaters, according to some embodiments of the present disclosure.</figref><figref num="31">Simplified block diagram of some exemplary embodiments of the device configured with features relating to authentication and use of repeaters, according to some embodiments of the present disclosure.</figref><figref num="32">Simplified block diagram of some exemplary embodiments of the device configured with features relating to authentication and use of repeaters, according to some embodiments of the present disclosure.</figref><figref num="33">Simplified block diagram of some exemplary embodiments of the device configured with features relating to authentication and use of repeaters, according to some embodiments of the present disclosure.</figref>
By convention, the features shown in the drawings have been simplified for clarity and are generally not drawn to a constant scale. That is, the dimensions and spacing of these features are often expanded or contracted for clarity. Moreover, for illustration purposes, drawings generally do not show all of the components commonly used in a given device (eg, device) or method. Finally, similar reference numbers may be used to indicate similar features throughout the specification and figures.
[0072] Various aspects of the present disclosure are described below. The teachings herein can be embodied in a wide variety of forms, and any particular structure, function, or both disclosed herein is representative only. Will be clear. Based on the teachings herein, the embodiments disclosed herein can be implemented independently of any other embodiment, and two or more of these embodiments can be combined in various ways. Those skilled in the art will understand that they can do it. For example, any number of aspects described herein can be used to implement the device or practice the method. Further, in addition to or using one or more of the aspects described herein, or other other structures, functions, or structures and functions, such devices are implemented or used. You can practice such a method. Moreover, any aspect disclosed herein can be embodied by one or more elements of the claims. As an example of the above, in some embodiments, the wireless communication method authenticates the first device to the server and sends a message from the first device to authorize the second device as an authenticator. Prepare to send to the server. Further, in some embodiments, the server may include a RADIUS server or a DIAMETER server.
[0073] FIG. 1 shows a wireless network 100 in which a repeater 102 is used to extend the range of a hotspot access point (AP) 104. Thus, when station (STA) 106 is within the coverage of repeater 102, STA 106 may access network 108 via repeater 102 and AP 104.
[0074] Authentication server 110 controls whether STA106 is allowed to access network 108. For example, when the STA 106 first establishes communication with the repeater 102, the STA 106 and the authentication server 110 can execute an authentication procedure, which allows the authentication server 110 to allow the STA 106 to access network 108. Verify that the STA106 holds a valid credential (for example, a master key) that indicates that it is allowed.
[0075] According to the teachings herein, the authenticator function may be implemented in the repeater 102 and / or AP104. As discussed in more detail below, AP104 may include authenticator function 112 as it is an authenticator for STA106. In addition or as an alternative, repeater 102 may include authenticator function 114 as it is an authenticator for STA106.
[0076] Wireless network technology may include various types of wireless local area networks (WLANs). WLANs can be used to interconnect neighboring devices to each other using widely used networking protocols. The various aspects described herein can be applied to any communication standard, such as Wi-Fi®, or more generally, any member of the IEEE 802.11 family of wireless protocols.
[0077] In some embodiments, the wireless signal uses Orthogonal Frequency Division Multiplexing (OFDM), Direct Sequence Spread Spectrum (DSSS) communication, a combination of OFDM and DSSS communication, or other methods of the 802.11 protocol. Can be sent according to.
[0078] Some of the devices described herein may further implement multi-input, multi-output (MIMO) technology and be implemented as part of the 802.11 protocol. MIMO systems have multiple (N) for data transmission<sub>T</sub>) Transmitting antennas and multiple (N)<sub>R</sub>) With receiving antennas. N<sub>T</sub>Transmitting antennas and N<sub>R</sub>The MIMO channel formed by the receiving antennas is also called a spatial channel or a spatial stream, N<sub>S</sub>Can be decomposed into independent channels, in this case N<sub>S</sub> min {N<sub>T</sub>, N<sub>R</sub>}. N<sub>S</sub>Each of the independent channels corresponds to one dimension. MIMO systems can provide improved performance (eg, higher throughput and / or greater reliability) when the additional dimensions created by multiple transmit and receive antennas are utilized.
[0079] In some implementations, a WLAN includes various devices that access a wireless network. For example, there may be two types of devices: an access point (AP) and a client (also known as a station or STA). In general, the AP acts as a hub or base station for the WLAN, and the STA acts as the user of the WLAN. For example, the STA can be a laptop computer, a personal digital assistant (PDA), a mobile phone, and so on. In one example, the STA connects to the AP over a Wi-Fi (eg, IEEE 802.11 protocol) compliant wireless link for general connectivity to the Internet or other wide area networks. In some implementations, the STA may also be used as an AP.
[0080] The access point ("AP") is also a node B, wireless network controller ("RNC"), e-node B, base station controller ("BSC"), transmit / receive base station ("BTS"), base station ("BTS"). "BS"), transmitter / receiver function ("TF"), wireless router, wireless transmitter / receiver, or any other term, implemented as any of them, or may be known as any of them.
[0081] The station "STA" is also an access terminal ("AT"), a subscriber station, a subscriber unit, a mobile station, a remote station, a remote terminal, a user terminal, a user agent, a user device, a user device, or something else. And can be implemented as one of them, or known as one of them. In some implementations, access terminals include cellular phones, cordless phones, session initiation protocol ("SIP") phones, wireless local loop ("WLL") stations, personal digital assistants ("PDA"), and wireless connectivity. It may have a handheld device that it has, or any other suitable processing device connected to a wireless modem. Thus, one or more aspects taught herein are telephones (eg, cellular phones or smartphones), computers (eg, laptops), portable communication devices, headsets, portable computing devices (eg, mobile phones). An information terminal), an entertainment device (eg, a music or video device, or satellite radio), a game device or game system, a Global Positioning System device, or any other configured to communicate via a wireless medium. May be incorporated into the appropriate device.
[0082] FIG. 2 shows an example of a wireless communication system 200 in which aspects of the present disclosure can be used. The wireless communication system 200 can operate according to a wireless standard, for example 802.11 standard. The wireless communication system 200 may include AP204 communicating with STA206a, 206b, 206c, 206d, 206e, and 206f (collectively STA206).
[0083] STA206e and 206f may have difficulty communicating with AP204 or may be out of range and unable to communicate with AP204. Therefore, another STA206d may be configured as a relay device (eg, a device with STA and AP functions) that relays communication between the AP204 and the STA206e and 206f.
[0084] Various processes and methods may be used for transmission in the wireless communication system 200 between AP204 and STA206. For example, signals may be sent and received between AP204 and STA206 according to OFDM / OFDMA techniques. In this case, the wireless communication system 200 may be referred to as an OFDM / OFDMA system. Alternatively, the signal may be sent and received between AP204 and STA206 according to CDMA techniques. In this case, the wireless communication system 200 may be referred to as a CDMA system.
[0085] A communication link that facilitates transmission from AP204 to one or more of STA206s is sometimes referred to as downlink (DL) 208, and transmissions from one or more of STA206s to AP204. The facilitating communication link is sometimes referred to as the uplink (UL) 210. Alternatively, the downlink 208 may be referred to as the forward link or forward channel and the uplink 210 may be referred to as the reverse link or reverse channel.
[0086] AP204 can act as a base station and provide wireless communication coverage in Basic Service Area (BSA) 202. The AP204 may be referred to as the Basic Services Set (BSS), along with the STA206, which is associated with the AP204 and uses the AP204 for communication.
[0087] Thus, an access point may be located within a coverage area of a network, or may roam over the coverage area of a network, and may have one or more services for one or more access terminals (eg, a network connection). Can be deployed within a communications network to provide access to (sex). For example, at various times, the access terminal may connect to the AP204, or any other access point (not shown) in the network.
[0088] Each of the access points communicates with one or more network entities (represented by network entity 212 in FIG. 2 for convenience), including each other, to facilitate wide area network connectivity. obtain. Network entities can take various forms, for example, one or more radios and / or core network entities. Therefore, in various implementations, the network entity 212 may have network management, session management, mobility management, gateway functionality, interworking functionality, database functionality, or, for example, via an authentication, authorization, and billing (AAA) server. It may represent a function, such as at least one of any other suitable network function. Two or more of such network entities may be co-located and / or two or more of such network entities may be distributed throughout the network.
Note that in some implementations, the wireless communication system 200 may not have a central AP204 and may act as a peer-to-peer network between STA206s. Therefore, the functions of AP204 described herein may be performed by one or more of the STA206s in an alternative manner. Also, as mentioned above, repeaters can incorporate at least some of the AP and STA functions.
[0090] Next, with reference to FIGS. 3-15, three techniques for supporting repeater authentication and other repeater-related operations will be described. Specifically, FIGS. 3 to 7 show the first technique, FIGS. 8 to 11 show the second technique, and FIGS. 12 to 15 show the third technique.
[0091] In some embodiments, these techniques can advantageously be used in situations where repeaters are deployed ad hoc to extend the services of access points (eg, hotspots). For example, repeaters can be deployed by hotspot users (eg, business owners) rather than network operators. For illustration purposes, these techniques can be explained in the context of an 802.1x-based system where the authenticator is a RADIUS server, the authenticator is an access point (AP) or repeater, and the supplicant is STA. .. However, it should be appreciated that the teachings herein can be implemented using other types of components and / or using other types of communication technology.
First referring to FIG. 3, a wireless network 300 is shown in which the repeater 302 contains an authentication client (eg, a RADIUS client) 314. Therefore, the repeater 302 can be an authenticator under 802.1x for any STA within the coverage of the repeater 302. Similar to FIG. 1, a simplified example of FIG. 3 shows AP304, STA306, network 308, and authentication server 310. According to conventional practice, the AP304 includes an authentication client (eg, a RADIUS client) 312 for authenticating any STA in direct communication with the AP304 (eg, within the coverage of the AP304).
[0093] In a RADIUS environment, in such a repeater-host RADIUS server implementation, the repeater is approved as a RADIUS client. Traditionally, RADIUS sessions are set up between two trusted entities. The teachings herein provide a mechanism for allowing a RADIUS server to "trust a repeater" before establishing a RADIUS session with the repeater.
[0094] Figure 4 shows an example of a message flow that can be used in connection with a repeater to host a RADIUS server implementation. Assume that the AP is already approved as a RADIUS client. At some point, the repeater is associated with the AP (for example, by an association request and response). The repeater is then authenticated by the AP. As shown in Figure 4, APs and repeaters establish secure communication through a four-way handshake procedure.
[0095] In addition, signaling message 402 is defined between the AP and the RADIUS server to approve the repeater as a new RADIUS client. For example, an AP can send a RADIUS message requesting a RADIUS server to allow a repeater as a RADIUS client. In response to this message, the RADIUS server sends a RADIUS authentication certificate to the AP to set up a session between the RADIUS server and the repeater. The AP forwards this certificate of authentication to the repeater, as shown by line 404 in Figure 4. Therefore, at this point, the RADIUS server recognizes the new RADIUS client (repeater) and the RADIUS server allows the RADIUS session 406 to be set up between the RADIUS server and the repeater.
[0096] The repeater then acts as an 802.1x authenticator when the STA is associated with the repeater (eg, by an association request and response). Therefore, the STA may establish a RADIUS session with the RADIUS server via the repeater. As shown in Figure 4, in this case the STA and repeater can perform a four-way handshake procedure to establish secure communication over wireless channels (eg 802.11-based channels).
[0097] In some implementations, information about all of the repeaters in the system, which could potentially be RADIUS clients, is stored in a database associated with the RADIUS server (eg, AAA database). In this case, the RADIUS server may use this information to approve the repeater as a new client (eg, with or without the assistance of the AP described herein).
[0098] Examples of authentication-related and / or repeater-related operations that can be performed according to the first technique are described in more detail with reference to FIGS. 5-7. For illustration purposes, these operations (or other operations described herein) may be described as being performed by a particular device. However, it should be understood that these operations can be performed by different types of equipment in different implementations.
[0099] First referring to FIG. 5, in some embodiments, this flowchart is performed by the first device in connection with allowing the second device to be approved as a client to the server. An exemplary operation that can be performed will be described. In some implementations, the first device may include an access point or some other suitable type of node (eg, a repeater), while the second device may be a repeater or some other suitable type. Can have nodes.
[00100] Because the first device (eg, the access point) authenticates the first device to the server (eg, the first device is connected to the server), as represented by block 502. To communicate with a server (for example, a RADIUS or DIAMETER authentication server).
[00101] As represented by block 504, the first device has a second device (eg, by an association request and response) to associate the second device (eg, a repeater) with the first device. Communicate with the device. For example, when associated, the second device can be serviced by the first device and / or connected to the first device.
[00102] As represented by block 506, the first device sends a message to the server to authorize the second device as an authenticator (eg, a RADIUS or DIAMETER message), thereby a second. The device is allowed to set up a session with the server. In some embodiments, the message may comprise a request to approve the second device as a client of the server.
[00103] As a result of sending the message, as represented by block 508, the first device receives an authentication certificate (eg, RADIUS or DIAMETER authentication certificate) from the server, where the authentication certificate is , To set up a session between the server and the second device.
[00104] As represented by block 510, the first device sends the authentication certificate to the second device (for example, the first device sends an EAP message using EAPOL).
[00105] With reference to FIG. 6, in some embodiments, this flowchart is exemplary which can be performed by a server in connection with allowing a second device to be approved as a client to the server. The operation will be described. In some implementations, the second device may include a repeater or some other suitable type of node (eg, an access point). In some implementations, the server may have some other suitable type of node (eg, a network entity).
[00106] As represented by block 602, the server (eg RADIUS or DIAMETER authentication server) authenticates the first device (eg access point) to the server (eg the first access point). Communicate with the first device to be connected to the server).
[00107] As represented by block 604, the server receives a message from the first device (eg, a RADIUS or DIAMETER message), where the message is associated with a second device. Identify the device (for example, a repeater) (for example, this message contains a request to approve the second device as a client of the server).
[00108] As represented by block 606, the server optionally accesses the database associated with the server to obtain information about the second device.
[00109] As represented by block 608, the server sends an authentication certificate (eg, RADIUS or DIAMETER authentication certificate) to the first device as a result of receiving the message, where the authentication certificate. Is to set up a session between the server and the second device.
[00110] As represented by block 610, the server communicates with the second device as a result of receiving the message to authorize the second device as an authenticator, thereby the second device. The device is allowed to set up a session with the server. In some embodiments, the authenticator authorization of the second device comprises accessing the database associated with the server.
[00111] As represented by block 612, the server establishes a session with a third device (eg, an access terminal) associated with the second device.
[00112] As represented by block 614, the server obtains (eg, derives) the encryption key (eg, PMK) associated with that session.
[00113] As represented by block 616, the server uses a second device with an encryption key to allow the second and third devices to establish secure communication over the wireless channel. Send to.
[00114] With reference to FIG. 7, in some embodiments, this flowchart may be performed by the second device in connection with allowing the second device to be approved as a client to the server. An exemplary operation will be described. In some implementations, the second device may include a repeater or some other suitable type of node (eg, an access point).
[00115] As represented by block 702, the second device (eg, repeater) associates the second device (eg, by association request and response) with the first device (eg, access point). To communicate with the first device, where the first device is connected to the server. In some implementations, the server comprises a RADIUS or DIAMETER authentication server. Therefore, it is possible to use a RADIUS message or a DIAMETER message for communication with the server.
[00116] As represented by block 704, the second device optionally broadcasts the service set identifier (SSID) of the first device (for example, to enhance repeater operation).
[00117] As represented by block 706, the second device has a third device (eg, a first device) to associate the third device with the second device (eg, by an association request and response). (Access terminal not associated with the device) communicates with.
[00118] As represented by block 708, the second device receives an authentication certificate (eg, RADIUS or DIAMETER certificate) from the first device to set up a session with the server (eg, RADIUS or DIAMETER authentication certificate) ( For example, the second device is authorized as an authenticator, which allows the second device to set up a session with the server).
[00119] As represented by block 710, the second device uses its authentication certificate to set up a session with the server.
[00120] As represented by block 712, the second device communicates with the server through a session to authenticate the server and the third device.
[00121] As represented by block 714, the second device receives an encryption key (eg, PMK) from its server.
[00122] As represented by block 716, the second device uses an encryption key to establish secure communication with the third device over the wireless channel.
[00123] Next, a second technique that supports repeater authentication and other repeater-related operations will be described with reference to FIGS. 8-11.
[00124] Figure 8 shows a wireless network 800 where authentication messages are tunneled through repeater 802. Similar to FIG. 1, a simplified example of FIG. 8 shows AP804, STA806, network 808, and authentication server 810. The AP804 includes an authentication client (eg, a RADIUS client) 812 for authenticating any STA that is in direct communication with the AP804 and / or in direct communication with the repeater 802.
[00125] Traditionally, Extensible Authentication Protocol over Local Area Network (RAPOL) frames running on a local area network are not allowed to propagate beyond one hop. According to the teachings herein, the AP804 is configured as an 802.1x authenticator for the STA806, while the repeater 802 is configured to tunnel EAPOL frames between the AP804 and the STA806. This four-way handshake to establish a secure wireless channel is based on the STA806 and AP804 medium access control (MAC) addresses. Therefore, encryption and decryption is performed between AP804 and STA806. As a result, repeater 802 is generally not capable of decoding tunneled MAC packets.
[00126] Figure 9 shows an example of a message flow that can be used in connection with such a tunneling scheme. As shown, repeaters are associated with APs and these nodes establish secure communication over wireless channels. In addition, the STA (not associated with the AP) associates with the repeater. In this case, the repeater tunnels the EAPOL frame 902 between the STA and AP (eg, by tunneling 814 as shown in FIG. 8). Figure 9 also shows the tunneling of the 4-way handshake message 904 (tunneled EAPOL frame) between the STA and AP.
[00127] In some embodiments, the tunneled EAPOL frame has the following characteristics: For each hop, the 4-address format is used if the address includes a destination address (DA), a source address (SA), a transmitter address (TA), and a receiver address (RA). This 4-address format stores the MAC address of the terminating STA, even if there is a repeater between the AP and the STA. For uplinks, DA is set to the AP's MAC address and SA is set to the STA's MAC address. As discussed below, the TA can be set to the STA's MAC address or the repeater's MAC address, depending on whether the message is being received or transmitted by the repeater. In addition, the RA can be set to the MAC address of the repeater or the MAC address of the AP, depending on whether the message is being received or transmitted by the repeater. Conversely, for downlinks, the DA is set to the STA's MAC address and the SA is set to the AP's MAC address. The TA can be set to the MAC address of the AP or the MAC address of the repeater, depending on whether the message is being received or transmitted by the repeater. In addition, the RA can be set to the MAC address of the repeater or the MAC address of the STA, depending on whether the message is being received or transmitted by the repeater. In some implementations, repeaters will forward EAPOL packets received over 802.1x uncontrolled ports.
[00128] With reference to FIG. 10, in some embodiments, the flowchart is a third device via a second device (for example, tunneling a message between a first device and a third device). Illustrative actions that can be performed by the first device in connection with communicating with the device are described. In some embodiments, the first device may include an access point or some other suitable type of node (eg, an access terminal or repeater) and the second device may be a repeater or some other suitable type. The third device may be equipped with an access terminal or some other suitable type of node (eg, repeater or access point).
[00129] As represented by block 1002, the first device (eg, access point or access terminal) makes the second device (eg, repeater) the first device (eg, by association request and response). Communicate with a second device to associate with the device.
[00130] As represented by block 1004, the first device initiates communication with a third device (eg, an access terminal or access point) via the second device, where the third device The device is associated with the second device, but not with the first device.
[00131] As represented by block 1006, the first device uses a message with a source address, a destination address, a transmitter address, and a receiver address (eg, an EAPOL frame) to use a second device. Communicates with a third device via. For example, the downlink message was associated with the source address associated with the first device, the destination address associated with the third device, the transmitter address associated with the first device, and the second device. It may have a receiver address. In addition, the uplink message was associated with the source address associated with the third device, the destination address associated with the first device, the transmitter address associated with the second device, and the first device. It may have a receiver address. In some embodiments, the address may comprise a MAC address.
[00132] As represented by block 1008, the first device obtains an encryption key (eg, pairwise transient key (PTK)) as a result of communicating with the third device (eg, pairwise transient key). , Derived), where the acquisition of the encryption key is based on the source address, the destination address, the nonce selected by the first device, and the nonce selected by the third device.
[00133] As represented by block 1010, the first device uses an encryption key to establish secure communication with the third device over the wireless channel.
[00134] With reference to FIG. 11, in some embodiments, this flowchart illustrates an exemplary operation that can be performed by a second device that tunnels a message between a first device and a third device. To do. In some embodiments, the first device may include an access point or some other suitable type of node (eg, an access terminal or repeater) and the second device may be a repeater or some other suitable type. The third device may be equipped with an access terminal or some other suitable type of node (eg, repeater or access point).
[00135] As represented by block 1102, the second device (eg, by association request and response) associates the second device with the first device (eg, access point). To communicate with the first device.
[00136] As represented by block 1104, the second device broadcasts the SSID of the first device as an option.
[00137] As represented by block 1106, the second device communicates with the third device in order to associate the third device (eg, the access terminal) with the second device, where the third device. The third device is not associated with the first device.
[00138] As represented by block 1108, the second device initiates the transfer of messages between the first and third devices.
[00139] As represented by block 1110, the second device forwards the messages, where each message (eg, an EAPOL frame) is a source address, a destination address, a transmitter address, and a receiver address. To be equipped. For example, the downlink message received by the second device is the source address associated with the first device, the destination address associated with the third device, the transmitter address associated with the first device, and It may have a receiver address associated with a second device. In addition, the downlink messages sent by the second device include the source address associated with the first device, the destination address associated with the third device, the transmitter address associated with the second device, and It may have a receiver address associated with a third device. Also, the uplink messages received by the second device are the source address associated with the third device, the destination address associated with the first device, the transmitter address associated with the third device, and It may have a receiver address associated with a second device. In addition, the uplink messages sent by the second device include the source address associated with the third device, the destination address associated with the first device, the transmitter address associated with the second device, and It may have a receiver address associated with the first device. In some embodiments, the address may comprise a MAC address. In some embodiments, message forwarding may comprise receiving a message over an IEEE 802.1x uncontrolled port.
[00140] Next, a third technique for supporting repeater authentication and other repeater-related operations will be described with reference to FIGS. 12-15.
[00141] FIG. 12 shows a wireless network 1200 with a hybrid implementation in which the repeater 1202 is the authenticator 1214, but the AP1204 is the termination point for the authentication server 1210 (eg, a RADIUS server). That is, the AP1204 authentication client 1212 communicates with the authentication server 1210 (for example, to obtain a pairwise master key to communicate with the STA1206). In this case, the repeater does not include the authentication client. However, signaling is defined between AP1204 and repeater 1202 to carry authentication (eg RADIUS) messages between AP1204 and STA1206. Therefore, repeater 1202 can act as an authenticator for STA1206 without using a full authentication client in repeater 1202 (eg, to access network 1208).
[00142] This implementation can be used, for example, in scenarios where it is desirable for repeaters to decrypt packets. For example, if the data packet is destined for a repeater, the repeater will preferably be able to decrypt the packet. If that is not possible, the packet will instead be forwarded to the AP, which will then send the (decrypted) packet back to the repeater. According to the teachings herein, this additional traversal can be avoided by allowing the repeater to decipher packets sent by the STA or other device. This has the additional advantage that the repeater does not have to host the RADIUS client software, thereby freeing up memory resources at the repeater. Moreover, the structure of the EAPOL frame is not modified in this implementation.
[00143] As shown in the message flow of Figure 13, message 1302 (with a frame, for example) repeats the pairwise master key (PMK) associated with the STA (which the RADIUS server has already sent to the AP) from the AP. Transport to. In this case, it can be understood that the repeater processes two different types of EAPOL messages. First, the repeater tunnels an EAPOL frame (with an EAP message) between the AP and the STA. In addition, the repeater receives an EAPOL message with PMK from the AP.
[00144] With reference to FIG. 14, in some embodiments, this flowchart illustrates an exemplary operation that can be performed by the first device in connection with communicating the encryption key to the second device. .. In some implementations, the first device may include an access point or some other suitable type of node (eg, a repeater), while the second device may be a repeater or some other suitable type. Can have nodes.
[00145] As represented by block 1402, the first device (eg, the access point) authenticates the first device (eg, the first device) to the server (eg, RADIUS or DIAMETER authentication server). Communicate with the server in order for the device to be connected to the server).
[00146] As represented by block 1404, the first device has a second device (eg, by an association request and response) to associate the second device (eg, a repeater) with the first device. Communicate with the device.
[00147] As represented by block 1406, the first device receives a cryptographic master key (eg, PMK) from the server.
[00148] As represented by block 1408, the first device sends the cryptographic master key to the second device. In some embodiments, the cryptographic master key can be sent to a second device via an EAPOL message.
[00149] As represented by block 1410, the first device communicates with a third device (eg, an access terminal) via a message tunneled by the second device (eg, an EAPOL frame). Here, the third device is associated with the second device, but not with the first device.
[00150] With reference to FIG. 15, in some embodiments, this flowchart illustrates an exemplary operation that can be performed by a second device in connection with receiving an encryption key from the first device. .. In some implementations, the first device may include an access point or some other suitable type of node (eg, a repeater), while the second device may be a repeater or some other suitable type. Can have nodes.
[00151] As represented by block 1502, the second device (eg, repeater) communicates with the first device to associate the second device with the first device (eg, access point). Here, the first device is connected to a server (eg, a RADIUS or DIAMETER authentication server).
[00152] As represented by block 1504, the second device broadcasts the SSID of the first device as an option.
[00153] As represented by block 1506, the second device (eg, by an association request and response) turns the third device (eg, an access terminal that is not associated with an access point) into the second device. Communicate with a third device to associate.
[00154] As represented by block 1508, the second device receives a cryptographic master key (eg, PMK) from the first device, where the cryptographic master key is from the server. In some embodiments, the cryptographic master key can be received via an EAPOL message.
[00155] As represented by block 1510, the second device uses a cryptographic master key to establish secure communication with the third device over the wireless channel. For example, the second device encrypts using the MAC address of the second device, the MAC address of the third device, the nonce selected by the second device, and the nonce selected by the third device. It is possible to obtain (eg, derive) a second encryption key (eg, PTK) from the master key. In some embodiments, EAPOL can be used to communicate with the third device.
[00156] As represented by block 1512, the second device tunnels a message (eg, an EAPOL message) between the first device and the third device.
[00157] With the above in mind, FIGS. 16-22 show exemplary operations that can be performed by various devices as taught herein.
[00158] First referring to FIG. 16, in some embodiments, this flowchart is performed by the first device in connection with allowing the second device to be approved as a client to the server. An exemplary operation that can be performed will be described. In some implementations, the first device may include an access point or some other suitable type of node (eg, a repeater), while the second device may be a repeater or some other suitable type. Can have nodes.
[00159] The first device (eg, an access point) authenticates to the server, as represented by block 1602. In some embodiments, the message may comprise a request to approve the second device as a client of the server.
[00160] In some embodiments, the server may include an authentication server, such as a RADIUS server or a DIAMETER server. Therefore, the message may include a RADIUS message or a DIAMETER message.
[00161] The first device may receive an authentication certificate from the server as a result of sending the message. In some embodiments, this certificate of authentication may be for setting up a session between the server and a second device. In some embodiments, the certificate of authentication may comprise a RADIUS or DIAMETER certificate of authentication.
[00162] As represented by block 1604, the first device sends a message (eg, a RADIUS or DIAMETER message) to the server to authorize the second device (eg, a repeater) as an authenticator. For example, the first device can send the authentication certificate received from the server to the second device.
[00163] As represented by optional block 1606, the first device may receive an authentication certificate from the server as a result of sending a message in block 1602.
[00164] As represented by optional block 1608, the first device is capable of sending an authentication certificate to the second device.
[00165] In addition to the above, the first device may receive the cryptographic master key from the server. In this case, the first device can send the cryptographic master key to the second device. In some embodiments, the cryptographic master key may comprise a pairwise master key.
[00166] With reference to FIG. 17, in some embodiments, this flowchart may be performed by the first device in connection with allowing the first device to be approved as a client to the server. An exemplary operation will be described. In some implementations, the first device may include a repeater or some other suitable type of node (eg, an access point).
[00167] As represented by block 1702, the first device (eg repeater) receives an authentication certificate from the second device (eg access point) to set up a session with the server. .. In some embodiments, the certificate of authentication may comprise a RADIUS or DIAMETER certificate of authentication.
[00168] In some embodiments, the server may include an authentication server, such as a RADIUS server or a DIAMETER server. Therefore, it is possible to use a RADIUS message or a DIAMETER message for communication with the server.
[00169] As represented by block 1704, the first device uses its authentication certificate to set up a session with the server.
[00170] As represented by block 1706, the first device communicates with the server through a session to authenticate the server with the third device (eg, STA).
[00171] As represented by block 1708, the first device may receive an encryption key from the server.
[00172] As represented by block 1710, the first device may use an encryption key to establish secure communication with the third device over the wireless channel.
[00173] In addition to the above, the first device is capable of receiving the cryptographic master key from the second device, in which case the key is generated by the server with respect to the second device. In this case, the first device may use the cryptographic master key to establish secure communication with the third device over the wireless channel. In some embodiments, the cryptographic master key may comprise a pairwise master key.
[00174] With reference to FIG. 18, in some embodiments, this flowchart may be performed by the first device in connection with allowing the third device to be approved as a client to the server. An exemplary operation will be described. In some implementations, the first device may include a server (eg, an authentication server). In some implementations, the third device may include a repeater or some other suitable type of node (eg, an access point).
[00175] As represented by block 1802, the first device receives a message (eg, a RADIUS or DIAMETER message) from a second device (eg, AP). This message identifies a third device (eg, a repeater) associated with the second device. In some embodiments, the message may comprise a request to approve the second device as a client of the first device (eg, a server).
[00176] As represented by block 1804, the first device allows the third device as an authenticator as a result of receiving a message in block 1802.
[00177] As represented by block 1806, the first device can send an authentication certificate to the second device as a result of receiving the message. In some embodiments, this certificate of authentication may be for setting up a session between a first device and a third device.
[00178] In addition to the above, the first device may establish a session with a fourth device (eg, STA) associated with the third device. In this case, the first device obtains the encryption key associated with the session and allows the third and fourth devices to establish secure communication over the wireless channel. Can be sent to a third device.
[00179] With reference to FIG. 19, in some embodiments, the flowchart is a third device via a second device (for example, tunneling a message between a first device and a third device). Illustrative actions that can be performed by the first device in connection with communicating with the device are described. In some implementations, the first device may include an access point or some other suitable type of node, the second device may include a repeater or some other suitable type of node, and the first The device of 3 may be equipped with an access terminal or some other suitable type of node.
[00180] As represented by block 1902, the first device initiates communication with the third device via the second device. Here, the third device is associated with the second device, but not with the first device.
[00181] As represented by block 1904, the first device uses a message with a source address, a destination address, a transmitter address, and a receiver address, and a third device is used through the second device. Communicate with the device. For example, the downlink message was associated with the source address associated with the first device, the destination address associated with the third device, the transmitter address associated with the first device, and the second device. It may have a receiver address. In addition, the uplink message was associated with the source address associated with the third device, the destination address associated with the first device, the transmitter address associated with the second device, and the first device. It may have a receiver address. In some embodiments, the message may comprise an EAPOL frame. In some embodiments, the address may comprise a medium access control (MAC) address.
[00182] In addition to the above, the first device may obtain an encryption key as a result of communication with the third device. Here, the acquisition of the encryption key is based on the source address, the destination address, the nonce selected by the first device, and the nonce selected by the third device. In this case, the first device may use the encryption key to establish secure communication with the third device over the wireless channel.
[00183] With reference to FIG. 20, in some embodiments, this flowchart illustrates an exemplary operation that can be performed by a first device that tunnels a message between a second device and a third device. To do. In some implementations, the first device may include a repeater or any other suitable type of node, the second device may include an access point or some other suitable type of node, the first. The device of 3 may be equipped with an access terminal or some other suitable type of node.
[00184] As represented by block 2002, the first device initiates the transfer of messages between the second device and the third device. In some embodiments, the message may comprise an Extensible Authentication Protocol (EAPOL) frame running on a local area network. In some embodiments, message forwarding may comprise receiving a message over an IEEE 802.1x uncontrolled port.
[00185] As represented by block 2004, the first device forwards messages, where each message comprises a source address, a destination address, a transmitter address, and a receiver address. For example, the downlink message received by the second device is the source address of the downlink message associated with the first device, the destination address of the downlink message associated with the third device, and the first device. It may include the transmitter address of the associated downlink message and the receiver address of the downlink message associated with the second device. In addition, the downlink message sent by the second device goes to the source address of the downlink message associated with the first device, the destination address of the downlink message associated with the third device, and the second device. It may include the transmitter address of the associated downlink message and the receiver address of the downlink message associated with the third device. Also, the uplink message received by the second device is the source address of the uplink message associated with the third device, the destination address of the uplink message associated with the first device, and the second device. It may include the transmitter address of the associated uplink message and the receiver address of the uplink message associated with the first device. In addition, the uplink message sent by the second device is to the source address of the uplink message associated with the third device, the destination address of the uplink message associated with the first device, and the third device. It may include the transmitter address of the associated uplink message and the receiver address of the uplink message associated with the second device.
[00186] With reference to FIG. 21, in some embodiments, this flowchart illustrates an exemplary operation that can be performed by the first device in connection with communicating the encryption key to the second device. .. In some implementations, the first device may include an access point or some other suitable type of node (eg, a repeater), while the second device may be a repeater or some other suitable type. Can have nodes.
[00187] As represented by block 2102, the first device receives a cryptographic master key (eg, PMK) from the server. In some embodiments, the server may include a RADIUS server or a DIAMETER server.
[00188] As represented by block 2104, the first device sends the cryptographic master key to the second device. In some embodiments, the cryptographic master key can be sent to a second device via an EAPOL message.
[00189] As represented by optional block 2106, the first device communicates with a third device (eg, an access terminal) via a message tunneled by the second device (eg, an EAPOL frame). Can be done. Here, the third device is associated with the second device, but not with the first device.
[00190] With reference to FIG. 22, in some embodiments, this flowchart illustrates an exemplary operation that can be performed by the first device in connection with receiving an encryption key from the second device. .. In some implementations, the first device may include a repeater or some other suitable type of node, while the second device is an access point or some other suitable type of node (eg, relay). Can be equipped with a vessel).
[00191] As represented by block 2202, the first device receives a cryptographic master key (eg, PMK) from the second device. In some embodiments, the cryptographic master key may initially be generated by the server. In some embodiments, the server may include a RADIUS server or a DIAMETER server.
[00192] As represented by block 2204, the first device uses a cryptographic master key to establish secure communication with a third device (eg, an access terminal) over a wireless channel. In some embodiments, communication with the third device uses EAPOL.
[00193] As represented by optional block 2206, the first device may obtain (eg, derive) a second cryptographic key (eg, PTK) from the cryptographic master key. For example, the second encryption key is derived based on the MAC address of the first device, the MAC address of the third device, the nonce selected by the first device, and the nonce selected by the third device. obtain.
[00194] As represented by block 2208, the first device may tunnel a message (eg, an EAPOL message) between the second device and the third device.
[00195] FIG. 23 shows various components that can be used in device 2302 (eg, a wireless device) that can be used within the wireless communication system 200. Device 2302 is an example of a device that may be configured to implement the various methods described herein. For example, device 2302 may include one of AP204, repeater 206d, or STA206 in FIG.
[00196] Device 2302 may include a processing system 2304 that controls the operation of device 2302. The processing system 2304 is sometimes referred to as a central processing unit (CPU). Memory component 2306, which can include both read-only memory (ROM) and random access memory (RAM) (eg, includes memory devices), provides instructions and data to processing system 2304. Some of the memory components 2306 may also include non-volatile random access memory (NVRAM). The processing system 2304 normally executes logical operations and arithmetic operations based on program instructions stored in the memory component 2306. The instructions in memory component 2306 may be executable to implement the methods described herein.
[00197] When device 2302 is implemented or used as a transmit node, processing system 2304 selects one of multiple medium access control (MAC) header types and produces packets with that MAC header type. Can be configured as For example, processing system 2304 may be configured to generate a packet with a MAC header and payload to determine what type of MAC header to use.
[00198] When device 2302 is implemented or used as a receiving node, processing system 2304 may be configured to process packets of a plurality of different MAC header types. For example, processing system 2304 may be configured to determine the type of MAC header used within a packet and process the packet and / or MAC header fields.
[00199] Processing system 2304 may include or be a component of a larger processing system implemented with one or more processors. One or more processors include general purpose microprocessors, microcontrollers, digital signal processors (DSPs), field programmable gate arrays (FPGAs), programmable logic devices (PLDs), controllers, state machines, gate logic, and separate hardware configurations. It may be implemented with any combination of elements, dedicated hardware finite state machines, or any other suitable entity capable of computing information or performing other operations.
[00200] The processing system may also include a machine-readable medium for storing software. Software means any type of instruction, whether called software, firmware, middleware, microcode, hardware description language, or otherwise. It should be widely interpreted. The instruction may include code (for example, in source code format, binary code format, executable code format, or any other suitable form of code). Instructions, when executed by one or more processors, cause the processing system to perform the various functions described herein.
[00201] Device 2302 may also include housing 2308, which may include transmitter 2310 and receiver 2312 to allow transmission and reception of data between device 2302 and remote locations. The transmitter 2310 and receiver 2312 may be combined into a single communication device (eg, transceiver 2314). The antenna 2316 may be mounted on the housing 2308 and electrically coupled to the transceiver 2314. Device 2302 may also include multiple transmitters, multiple receivers, multiple transceivers, and / or multiple antennas (not shown). The transmitter 2310 and receiver 2312 may include integrated devices (eg, incorporated as transmitter and receiver circuits of a single communication device) in some implementations, and separately in some implementations. Transmitter device and separate receiver device may be provided, or may be incorporated in other ways in other implementations.
[00202] Transmitter 2310 may be configured to wirelessly transmit packets with different MAC header types. For example, transmitter 2310 may be configured to send packets with different types of headers generated by the processing system 2304 discussed above.
[00203] Receiver 2312 may be configured to wirelessly receive packets with different MAC header types. In some embodiments, the receiver 2312 is configured to detect the type of MAC header used and process the packet accordingly.
[00204] Receiver 2312 can be used to detect and quantize the level of the signal received by transceiver 2314. Receiver 2312 can detect signals such as total energy, energy per symbol per subcarrier, power spectral density, and other signals. Device 2302 may also include a digital signal processor (DSP) 2320 for use in processing the signal. The DSP2320 may be configured to generate a data unit for transmission. In some embodiments, the data unit may comprise a physical layer data unit (PPDU). In some embodiments, the PPDU is referred to as a packet.
[00205] The device 2302 may further comprise a user interface 2322 in some embodiments. The user interface 2322 may include a keypad, microphone, speaker, and / or display. The user interface 2322 may include any element or component that conveys information to the user of device 2302 and / or receives input from the user.
[00206] Various components of device 2302 may be coupled together by bus system 2326. The bus system 2326 may include, for example, a data bus and, in addition to the data bus, a power bus, a control signal bus, and a status signal bus. Those skilled in the art will appreciate that the components of device 2302 may be coupled to each other or accept or give inputs to each other using some other mechanism.
[00207] Several separate components are shown in FIG. 23, but one or more of those components may be combined or implemented in common. For example, the processing system 2304 can be used not only to implement the functionality described above for the processing system 2304, but also to implement the functionality described above for the transceiver 2314 and / or DSP2320. In addition, each of the components shown in FIG. 23 may be implemented using a plurality of separate elements. Further, the processing system 2304 may be used to implement any of the components, modules, circuits, etc. described below, or each may be implemented using a plurality of separate elements.
[00208] For ease of reference, when device 2302 is configured as a transmit node, it will be referred to below as device 2302t. Similarly, when device 2302 is configured as a receiving node, it will be referred to below as device 2302r. The device in the wireless communication system 200 may implement only the function of the transmitting node, only the function of the receiving node, or the function of both the transmitting node and the receiving node.
As discussed above, device 2302 may include AP204 or STA206 and may be used to transmit and / or receive communications with multiple MAC header types.
[00210] The components of FIG. 23 can be implemented in a variety of ways. In some implementations, the components of FIG. 23 are one or more processors, for example one or more processors, and / or one or more ASICs (which may include one or more processors). Can be implemented in a circuit. Here, each circuit may use and / or incorporate at least one memory component to store the information or executable code used by the circuit to provide this functionality. For example, some or all of the functionality represented by the blocks in Figure 23 is implemented by the processor and memory components of the device (eg, by executing the appropriate code and / or by the appropriate components of the processor components). obtain. It should be appreciated that these components can be implemented in different types of equipment in different implementations (eg, in ASICs, in system-on-chip (SoC), etc.).
[00211] As discussed above, device 2302 can include AP204 or STA206, repeaters, or any other type of device and can be used to transmit and / or receive communications. FIG. 24 shows various components that can be used in device 2302t to transmit wireless communications. The components shown in FIG. 24 can be used, for example, to transmit OFDM communications. In some embodiments, the components shown in FIG. 24 are used to generate and transmit packets that are sent with a bandwidth of 1 MHz or less.
[00212] The device 2302t of FIG. 24 may include a modulator 2402 configured to modulate the bits for transmission. For example, the modulator 2402 determines multiple symbols from the bits received from processing system 2304 (Fig. 23) or user interface 2322 (Fig. 23), for example by mapping bits to multiple symbols according to constellation. Can be done. Those bits may correspond to user data or control information. In some embodiments, those bits are received in codeword. In one aspect, the modulator 2402 comprises a QAM (quadrature amplitude modulation) modulator, such as a 16QAM modulator or a 64QAM modulator. In another aspect, the modulator 2402 comprises a two-phase shift keying (BPSK) modulator or a four phase shift keying (QPSK) modulator.
[00213] Device 2302t may further include a conversion module 2404 configured to convert symbols from modulator 2402, or otherwise modulated bits, into the time domain. In FIG. 24, the transform module 2404 is shown as being implemented by an inverse fast Fourier transform (IFFT) module. In some implementations, there may be multiple conversion modules (not shown) that convert units of data of different sizes. In some implementations, the conversion module 2404 may itself be configured to convert units of data of different sizes. For example, the conversion module 2404 may consist of multiple modes and may use different numbers of points to convert symbols in each mode. For example, IFFT has a mode in which 32 points are used to transform symbols transmitted in 32 tones (ie, subcarriers) into the time domain, and symbols transmitted in 64 tones in time. It may have a mode in which 64 points are used to transform into a region. The number of points used by conversion module 2404 is sometimes referred to as the size of conversion module 2404.
[00214] FIG. 24 shows the modulator 2402 and the conversion module 2404 as being implemented within the DSP 2420. However, in some embodiments, one or both of the modulator 2402 and the conversion module 2404 are implemented within the processing system 2304 or within another element of the apparatus 2302t (see, eg, the description above with respect to FIG. 23).
[00215] As discussed above, the DSP2420 may be configured to generate data units for transmission. In some embodiments, the modulator 2402 and the conversion module 2404 may be configured to generate a data unit with multiple fields containing control information and multiple data symbols.
Returning to the description of FIG. 24, the apparatus 2302t may further include a digital-to-analog converter 2406 configured to convert the output of the conversion module into an analog signal. For example, the time domain output of the conversion module 2406 can be converted to a baseband OFDM signal by the digital-to-analog converter 2406. The digital-to-analog converter 2406 may be implemented within the processing system 2304 or within another element of device 2302 in FIG. In some embodiments, the digital-to-analog converter 2406 is implemented within the transceiver 2314 (Figure 23) or within the data transmission processor.
[00217] The analog signal may be transmitted wirelessly by transmitter 2410. The analog signal can be further processed, for example, by filtering or up-converting to an intermediate or carrier frequency before being transmitted by transmitter 2410. In the embodiment shown in FIG. 24, the transmitter 2410 includes a transmitter amplifier 2408. Before being transmitted, the analog signal can be amplified by the transmit amplifier 2408. In some embodiments, the amplifier 2408 comprises a low noise amplifier (LNA).
[00218] Transmitter 2410 is configured to transmit one or more packets or data units within a wireless signal based on an analog signal. Those data units can be generated using the processing system 2304 (Figure 23) and / or DSP2420, for example using the modulator 2402 and the conversion module 2404 as discussed above. The data units that can be generated and transmitted as described above will be described in more detail below.
[00219] FIG. 25 shows various components that may be utilized in device 2302 of FIG. 23 to receive wireless communications. The components shown in FIG. 25 can be used, for example, to receive OFDM communications. For example, the components shown in FIG. 25 can be used to receive the data units transmitted by the components described above with respect to FIG. 24.
[00220] The receiver 2512 of device 2302r is configured to receive one or more packets or data units in a wireless signal. Data units that can be received, decrypted, or otherwise processed are described below.
[00221] In the embodiment shown in FIG. 25, the receiver 2512 includes a receive amplifier 2501. The receiving amplifier 2501 may be configured to amplify the wireless signal received by the receiver 2512. In some embodiments, the receiver 2512 is configured to use automatic gain control (AGC) procedures to adjust the gain of the receive amplifier 2501. In some embodiments, automatic gain control uses information in one or more received training fields, such as a received short training field (STF), to adjust the gain, for example. Those skilled in the art will understand how to implement AGC. In some embodiments, the amplifier 2501 comprises an LNA.
[00222] Device 2302r may include an analog-to-digital converter 2510 configured to convert the amplified wireless signal from receiver 2512 into its digital representation. In addition to being amplified, the wireless signal is processed, for example, by filtering or down-converting to intermediate or baseband frequencies before being converted by the digital-to-analog converter 2510. obtain. The analog-to-digital converter 2510 may be implemented within the processing system 2304 (FIG. 23) or within another element of device 2302r. In some embodiments, the analog-to-digital converter 2510 is implemented within the transceiver 2314 (Figure 23) or within the data receiving processor.
[00223] The device 2302r may further include a conversion module 2504 configured to convert the representation of the wireless signal into a frequency spectrum. In Figure 25, the transform module 2504 is shown as being implemented by a Fast Fourier Transform (FFT) module. In some embodiments, the transform module can identify a symbol for each point it uses. As described above with respect to FIG. 24, the conversion module 2504 may be configured in multiple modes and may use a different number of points to convert the signal in each mode. The number of points used by the conversion module 2504 is sometimes referred to as the size of the conversion module 2504. In some embodiments, the conversion module 2504 may identify a symbol for each point it uses.
[00224] The device 2302r is configured to allow the data unit to form an estimate of the channel received through it and to remove some influence of the channel based on the channel estimate. It may further be equipped with a channel estimator and equalizer 2505. For example, the channel estimator 2505 may be configured to approximate the function of the channel, and the channel equalizer may be configured to apply the inverse of that function to the data in the frequency spectrum.
[00225] The device 2302r may further include a demodulator 2506 configured to demodulate the equalized data. For example, the demodulator 2506 can determine multiple bits from the symbols output by the conversion module 2504 and the channel estimator and equalizer 2505, for example by reversing the bit-symbol mapping in the constellation. .. These bits can be processed or evaluated by processing system 2304 (FIG. 23) or used to display or otherwise output information in user interface 2322 (FIG. 23). In this way, the data and / or information can be decrypted. In some embodiments, those bits correspond to codewords. In one aspect, the demodulator 2506 comprises a QAM (quadrature amplitude modulation) demodulator, such as a 16QAM demodulator or a 64QAM demodulator. In another aspect, the demodulator 2506 comprises a two-phase shift keying (BPSK) demodulator or a four phase shift keying (QPSK) demodulator.
[00226] In Figure 25, the conversion module 2504, channel estimator and equalizer 2505, and demodulator 2506 are shown as being implemented within DSP2520. However, in some embodiments, one or more of the conversion module 2504, the channel estimator and equalizer 2505, and the demodulator 2506 are in the processing system 2304 (FIG. 23) or in the apparatus 2302 (FIG. 23). Implemented within another element.
[00227] As described above, the wireless signal received at receiver 2312 comprises one or more data units. Using the features or components described above, the data unit or data symbols within it may be decoded and evaluated, or otherwise evaluated or processed. For example, the processing system 2304 (Figure 23) and / or DSP2520 uses the conversion module 2504, the channel estimator and equalizer 2505, and the demodulator 2506 to decode the data symbols in the data unit. Can be used.
[00228] The data units exchanged by AP204 and STA206 may contain control information or data as described above. At the physical (PHY) layer, these data units are sometimes referred to as physical layer protocol data units (PPDUs). In some embodiments, the PPDU may be referred to as a packet or physical layer packet. Each PPDU may include a preamble and a payload. The preamble can include a training field and a SIG field. The payload may include, for example, media access control (MAC) headers or data for other layers, and / or user data. The payload can be transmitted using one or more data symbols. The systems, methods, and devices herein can utilize data units with training fields with minimal peak-to-power ratios.
The device 2302t shown in FIG. 24 shows an example of a single transmit chain transmitted through an antenna. The device 2302r shown in FIG. 25 shows an example of a single receive chain received via an antenna. In some implementations, the device 2302t or 2302r may implement a portion of a MIMO system using multiple antennas to transmit data simultaneously.
The wireless network 200 can use methods to allow efficient access to wireless media based on unpredictable data transmission while avoiding collisions. Therefore, according to various aspects, the wireless network 200 performs carrier sense multiple access / collision avoidance (CSMA / CA), which is sometimes referred to as discounted capitalization (DCF). More generally, the device 2302, which has the data for transmission, senses the wireless medium to determine if the channel is already occupied. If device 2302 senses that its channel is idle, device 2302 sends the prepared data. Otherwise, device 2302 may be postponed for some period of time before redetermining whether the wireless medium is free to transmit. Methods for performing CSMA can use various gaps between continuous transmissions to avoid collisions. In one aspect, the transmission is sometimes referred to as a frame and the gap between frames is referred to as an interframe space (IFS). The frame can be any one of user data, control frames, management frames, and so on.
[00231] The IFS time duration can vary depending on the type of time gap provided. Some examples of IFS are short interframe space (SIFS), point interframe space (PIFS), and DCF interframe space (DIFS), where SIFS is shorter than PIFS, which is shorter than DIFS. .. Transmissions that last for a shorter duration will have a higher priority than transmissions that have to wait longer before attempting to access the channel.
The wireless device may include various components that perform functions based on signals transmitted by or received by the wireless device. For example, in some implementations, as taught herein, the wireless device comprises a user interface configured to output a display based on the received signal.
[00233] The wireless device taught herein may communicate over one or more wireless communication links based on or otherwise support appropriate wireless communication techniques. For example, in some embodiments, the wireless device may be associated with a network, such as a local area network (eg, a Wi-Fi network) or a wide area network. To this end, wireless devices support one or more of various wireless communication technologies, protocols, or standards, such as Wi-Fi, WiMAX®, CDMA, TDMA, OFDM, and OFDMA. Or it can be used otherwise. Also, the wireless device may support or otherwise use one or more of a variety of corresponding modulation or multiplexing schemes. Thus, wireless devices may include suitable components (eg, air interfaces) for establishing one or more wireless communication links using the above or other wireless communication technologies and communicating through them. .. For example, a device may include various components (eg, a signal generator and a signal processor) that facilitate communication over a wireless medium, wireless transmission / reception with associated transmitter and receiver components. Can be equipped with a machine.
[00234] The teachings herein can be incorporated into various devices (eg, nodes) (eg, can be implemented within or performed by those devices). In some embodiments, the device implemented according to the teachings herein (eg, a wireless device) may include an access point, repeater, or access terminal.
[00235] Does the access terminal include a user device, a subscriber station, a subscriber unit, a mobile station, a mobile, a mobile node, a remote station, a remote terminal, a user terminal, a user agent, a user device, or some other term? It may be implemented as one of them or known as one of them. In some embodiments, the access terminal is a cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless connectivity, or wireless. It may have some other suitable processing device connected to the modem. Accordingly, one or more aspects taught herein include telephones (eg, cellular phones or smartphones), computers (eg, laptops), portable communication devices, portable computing devices (eg, personal digital assistants), and more. It can be incorporated into an entertainment device (eg, a music device, video device, or satellite radio), a Global Positioning System device, or any other suitable device configured to communicate via a wireless medium.
[00236] Access points include node B, e-node B, wireless network controller (RNC), base station (BS), wireless base station (RBS), base station controller (BSC), transmit / receive base station (BTS), transmitter / receiver. Features (TF), wireless transmitter / receiver, wireless router, basic service set (BSS), extended service set (ESS), macrocell, macronode, home eNB (HeNB), femtocell, femtonode, piconode, or anything else It is possible to include the terms, can be implemented as any of them, or may be known as any of them.
[00237] Repeaters can include, can include, or can be implemented as repeater nodes, repeater devices, repeater stations, repeater devices, or some other similar terminology. Sometimes known as them. As discussed above, in some embodiments, the repeater may have some access terminal function and some access point function.
[00238] In some embodiments, the wireless device comprises an access device (eg, an access point) for the communication system. Such access devices provide connectivity to another network (eg, a wide area network, such as the Internet or a cellular network), for example, over a wired or wireless communication link. Therefore, the access device allows another device (eg, a wireless station) to access another network or some other function. Furthermore, it should be appreciated that one or both of those devices can be portable or, in some cases, relatively non-portable. It should also be appreciated that wireless devices may also be able to transmit and / or receive information in a non-wireless manner (eg, via a wired connection) via a suitable communication interface.
The teachings herein can be incorporated into various types of communication systems and / or system components. In some embodiments, the teachings herein are by sharing available system resources (eg, by specifying one or more of bandwidth, transmit power, coding, interleaving, etc.). , Can be used in multiple access systems capable of supporting communication with multiple users. For example, the teachings herein may apply to any one or a combination of the following techniques: That is, Code Division Multiple Access (CDMA) Systems, Multiple Carrier CDMA (MCCDMA), Broadband CDMA (W-CDMA®), High Speed Packet Access (HSPA, HSPA +) Systems, Time Division Multiple Access (TDMA) Systems, Frequency It is a technique of split frequency division multiple access (FDMA) systems, single carrier FDMA (SC-FDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, or other multiple connection techniques. Wireless communication systems using the teachings herein may be designed to implement one or more standards, including IS-95, cdma2000, IS-856, W-CDMA, TDSCDMA, and other standards. CDMA networks may implement wireless technologies such as Universal Terrestrial Radio Access (UTRA), cdma2000, or some other technology. UTRA includes W-CDMA and Low Chip Rate (LCR). cdma2000 technology covers IS-2000, IS-95 and IS-856 standards. The TDMA network may implement wireless technologies such as Global System for Mobile Communications (GSM®). OFDMA networks include advanced UTRA (E-UTRA), IEEE 802.11, IEEE 802.16, and IEEE 802.11. 20, Wireless technology such as Flash-OFDM® can be implemented. UTRA, E-UTRA, and GSM are part of the Universal Mobile Telecommunications System (UMTS). The teachings herein may be implemented in 3GPP Long Term Evolution (LTE) systems, Ultra Mobile Broadband (UMB) systems, and other types of systems. LTE is a release of UMTS that uses E-UTRA. UTRA, E-UTRA, GSM, UMTS and LTE are listed in a document from an organization called "3rd Generation Partnership Project" (3GPP), and cdma2000 is referred to as "3rd Generation Partnership Project 2" (3GPP2). It is described in a document from the calling organization. Although some aspects of the disclosure may be described using 3GPP terminology, the teachings herein are 3GPP (eg, Rel99, Rel5, Rel6, Rel7) techniques, as well as 3GPP2 (eg, 1xRTT). , 1xEV-DO Rel0, RevA, RevB) It should be understood that it can be applied to technology and other technologies.
[00240] Figure 26 of device 2602, device 2604, and device 2606 (corresponding to, for example, an access terminal, an access point or repeater, and a server, respectively) to perform the communication operations taught herein. Here are some exemplary components (represented by the corresponding blocks) that can be incorporated into them. It should be appreciated that these components can be implemented in different types of equipment in different implementations (eg, in ASICs, in system-on-chip (SoC), etc.). The components described may also be incorporated into other devices within the communication system. For example, other devices in the system may include components similar to those described to provide similar functionality. Also, a given device may include one or more of the components described. For example, a device may include multiple transmitter / receiver components that allow the device to operate on multiple carriers and / or communicate by different technologies.
[00241] Device 2602 and Device 2604 communicate with other nodes via at least one designated wireless access technology (communication devices 2608 and 2614 (and, if device 2604 is a repeater)). Includes at least one wireless communication device (represented by device 2620). Each communication device 2608 has at least one transmitter (represented by transmitter 2610) for transmitting and encoding signals (eg, messages, displays, information, etc.) and signals (eg, messages, displays, information, etc.). , Pilot, etc.) includes at least one receiver (represented by receiver 2612) for receiving and decoding. Similarly, each communication device 2614 has at least one transmitter (represented by transmitter 2616) for transmitting a signal (eg, message, display, information, pilot, etc.) and a signal (eg, message, display). Includes at least one receiver (represented by receiver 2618) for receiving information, etc.). When device 2604 is a repeater, each communication device 2620 has at least one transmitter (represented by transmitter 2622) for transmitting signals (eg, messages, displays, information, pilots, etc.) and signals. Includes at least one receiver (represented by receiver 2624) for receiving (eg, messages, displays, information, etc.).
[00242] Transmitters and receivers may include integrated devices (eg, incorporated as transmitter and receiver circuits of a single communication device) in some implementations, and in some implementations. It may include separate transmitter devices and separate receiver devices, or, in other implementations, may be incorporated in other ways. In some embodiments, the wireless communication device of device 2604 (eg, one of a plurality of wireless communication devices) comprises a network listen module.
[00243] Device 2606 (and, if it is an access point, device 2604) is at least one communication device (represented by communication device 2626 and, optionally, 2620) for communicating with other nodes. including. For example, the communication device 2626 may include a network interface configured to communicate with one or more network entities via a wire-based or wireless backhaul. In some embodiments, the communication device 2626 may be implemented as a transceiver configured to support wire-based or wireless signal communication. This communication may involve, for example, sending and receiving messages, parameters, or other types of information. Therefore, in the example of FIG. 26, the communication device 2626 is shown to include a transmitter 2628 and a receiver 2630. Similarly, if device 2604 is an access point, communication device 2620 may include a network interface configured to communicate with one or more network entities via a wire-based or wireless backhaul. Like the communication device 2626, the communication device 2620 is shown to include a transmitter 2622 and a receiver 2624.
[00244] Devices 2602, 2604, and 2606 also include other components that may be used in conjunction with the communication operations taught herein. Devices 2602, 2604, and 2606 include processing systems 2632, 2634, and 2636, respectively, to provide repeater authentication functions and related repeater-related operations and to provide other processing functions. Devices 2602, 2604, and 2606 include memory devices 2638, 2640, and 2642, respectively, to maintain information (eg, thresholds, parameters, mapping information, etc.), respectively. .. In addition, devices 2602, 2604, and 2606 activate a sensing device such as a keypad, touch screen, or microphone to provide a display (eg, audible and / or visual display) to the user and / or (eg, a keypad, touch screen, microphone, etc.). Includes user interface devices 2644, 2646 and 2648 for receiving user input, respectively.
[00245] For convenience, device 2602 is shown in FIG. 26 as including components that may be used in the various examples described herein. In practice, the illustrated blocks may have different functions in different embodiments. For example, the functionality of block 2634 to provide the functionality of FIG. 4 may differ compared to the functionality of block 2634 to provide the functionality of FIG.
[00246] The components of FIG. 26 can be implemented in a variety of ways. In some implementations, the components of FIG. 26 are one or more processors, for example one or more processors, and / or one or more ASICs (which may include one or more processors). Can be implemented in a circuit. Here, each circuit may use and / or incorporate at least one memory component to store the information or executable code used by the circuit to provide this functionality. For example, some or all of the functionality represented by blocks 2608, 2632, 2638, and 2644 is by the processor and memory components of device 2602 (eg, by executing the appropriate code and / or by the appropriate processor components). Can be implemented by any configuration). Similarly, some or all of the functionality represented by blocks 2614, 2620, 2634, 2640, and 2646 is by the processor and memory components of device 2604 (for example, by executing appropriate code and / or processor configuration). Can be implemented (with proper configuration of elements). Also, some or all of the functionality represented by blocks 2626, 2636, 2642, and 2648 is by the processor and memory components of device 2606 (eg, by executing the appropriate code and / or by the appropriate processor components). Can be implemented by any configuration).
[00247] The components described herein can be implemented in various ways. With reference to FIGS. 27, 28, 29, 30, 31, 32, and 33, the devices 2700, 2800, 2900, 3000, 3100, 3200, and 3300 are, for example, one or more implementations. Represented as a set of interrelated functional blocks that represent functionality implemented by a circuit (eg, an ASIC) or implemented in some other way as taught herein. As discussed herein, integrated circuits can include processors, software, other components, or any combination thereof.
[00248] Device 2700 includes one or more modules capable of performing one or more of the functions described above with respect to various figures. For example, the ASIC2702 for authentication may correspond, for example, to the processing systems discussed herein. The ASIC2704 for sending to a server may correspond, for example, to the communication devices discussed herein. The ASIC2706 for receiving may correspond, for example, to the communication devices discussed herein. The ASIC 2708 for sending to a second device may correspond, for example, to the transmitters discussed herein.
[00249] Device 2800 includes one or more modules capable of performing one or more of the functions described above with respect to various figures. For example, the ASIC2802 for receiving may correspond, for example, to the communication devices discussed herein. The ASIC2804 for authorization may correspond, for example, to the processing systems discussed herein. The ASIC2806 for sending may correspond, for example, to the communication devices discussed herein. The ASIC2808 for establishing a session may correspond, for example, to the processing systems discussed herein. The ASIC 2810 for obtaining the encryption key may correspond to, for example, the processing system discussed herein.
[00250] Device 2900 includes one or more modules capable of performing one or more of the functions described above with respect to various figures. For example, the ASIC2902 for receiving may correspond, for example, to the communication devices discussed herein. The ASIC2904 for setting up a session may correspond, for example, to the processing systems discussed herein. The ASIC2906 for communication may correspond, for example, to the communication devices discussed herein. The ASIC2908 for using cryptographic keys may correspond, for example, to the processing systems discussed herein. The ASIC2910 for broadcasting may correspond, for example, to the transmitters discussed herein.
[00251] Device 3000 includes one or more modules capable of performing one or more of the functions described above with respect to various figures. For example, the ASIC 3002 for initiating communication may correspond, for example, to the processing systems discussed herein. The ASIC 3004 for communication may correspond, for example, to the communication devices discussed herein. The ASIC3006 for obtaining the encryption key may correspond to, for example, the processing system discussed herein. The ASIC 3008 for using cryptographic keys may correspond, for example, to the processing systems discussed herein.
[00252] The device 3100 includes one or more modules capable of performing one or more of the functions described above with respect to the various figures. For example, the ASIC 3102 for initiating a transfer may correspond, for example, to the processing systems discussed herein. The ASIC3104 for transfer may correspond, for example, to the communication devices discussed herein. The ASIC3106 for broadcasting may correspond, for example, to the communication devices discussed herein.
[00253] The apparatus 3200 includes one or more modules capable of performing one or more of the functions described above with respect to various figures. For example, the ASIC 3203 for receiving from a server may correspond, for example, to the communication devices discussed herein. The ASIC3204 for sending may correspond, for example, to the transmitters discussed herein. The ASIC3206 for communicating over tunneled messages may correspond, for example, to the communication devices discussed herein.
[00254] Device 3300 includes one or more modules capable of performing one or more of the functions described above with respect to various figures. For example, the ASIC 3302 for receiving may correspond, for example, to the communication devices discussed herein. ASIC3304 for using cryptographic keys may correspond, for example, to the processing systems discussed herein. The ASIC3306 for obtaining the encryption key may correspond to, for example, the processing system discussed herein. The ASIC3308 for tunneling may correspond, for example, to the communication devices discussed herein. The ASIC3310 for broadcasting may correspond, for example, to the communication devices discussed herein.
[00255] As mentioned above, in some embodiments, these modules may be implemented with the appropriate processor components. These processor components may be implemented in some embodiments, at least in part, using the structures taught herein. In some embodiments, the processor may be configured to implement some or all of the functionality of one or more of these modules. Thus, the functionality of different modules can be implemented, for example, as different subsets of integrated circuits, as different subsets of a set of software modules, or as a combination thereof. It should also be appreciated that a given subset (eg, of an integrated circuit and / or set of software modules) can provide at least a portion of its functionality to more than one module. In some embodiments, one or more of any component represented by the dotted box is optional.
[00256] As described above, in some implementations, the devices 2700-3300 include one or more integrated circuits. For example, in some embodiments, a single integrated circuit implements the function of one or more of the components shown, while in other embodiments, two or more integrated circuits show the components. Implement one or more of the features. As one particular example, device 2700 may include a single device (eg, with different sections of the ASIC with components 2702-2708). As another specific example, device 2700 may have several devices (for example, component 2702 has one ASIC, components 2704 and 2706 have different ASICs, and component 2708 has another ASIC). Prepare).
[00257] Further, the components and functions represented by FIGS. 27-33 and the other components and functions described herein may be implemented using any suitable means. Such means are implemented, at least in part, using the corresponding structures taught herein. For example, the components described above in relation to the component "ASIC for" of FIGS. 27-33 correspond to the similarly specified function "means for". Therefore, in some implementations, one or more of such means uses one or more of the processor components, integrated circuits, or other suitable structures taught herein. Is implemented. Some examples are shown below. In some embodiments, the means for receiving comprises a receiver. In some embodiments, the means for detection comprises a processing system. In some embodiments, the means for producing comprises a processing system. In some embodiments, the means for transmitting comprises a transmitter. In some embodiments, the means for identification comprises a processing system. In some embodiments, the means for determining comprises a processing system.
[00258] In some implementations, a communication device structure, such as a transceiver, is configured to embody the function of a means for receiving. For example, this structure may be programmed or designed to invoke a receive operation. In addition, this structure may be programmed or designed to process (eg, demodulate and decode) any signal received as a result of the receiving operation. In addition, this structure may be programmed or designed to output data extracted from the signal received as a result of processing (eg, data units, authentication information, displays, or other information). Typically, the communication device structure comprises a wireless-based transceiver device or a wire-based transceiver device.
[00259] In some embodiments, the communication device structure, such as a transceiver, is configured to embody the function of a means for sending. For example, this structure may be programmed or designed to retrieve the data to be transmitted (eg, data units, credentials, displays, or other information). In addition, this structure can be programmed or designed to process (eg, modulate and code) the acquired data. In addition, this structure can be programmed or designed to couple the processed data to one or more antennas for transmission. Typically, the communication device structure comprises a wireless-based transceiver device or a wire-based transceiver device.
[00260] In some implementations, a communication device structure, such as a transceiver, is configured to embody the functionality of a means for broadcasting. For example, this structure may be programmed or designed to retrieve data to be broadcast (eg, data units, credentials, displays, or other information). In addition, this structure can be programmed or designed to process (eg, modulate and code) the acquired data. In addition, this structure can be programmed or designed to couple the processed data to one or more antennas for transmission. Typically, the communication device structure comprises a wireless-based transceiver device or a wire-based transceiver device.
[00261] In some implementations, a communication device structure, such as a transceiver, is configured to embody the functionality of a means for communication or a means for transfer. For example, this structure may be programmed or designed to retrieve data to be communicated (eg, data units, credentials, displays, or other information). In addition, this structure can be programmed or designed to process (eg, modulate and code) the acquired data. In addition, this structure can be programmed or designed to output data. Complementary actions can be performed to receive the data. Generally, the communication device structure comprises a wireless-based transceiver device or a wire-based transceiver device.
[00262] In some implementations, processing system structures such as ASICs or programmable processors are configured to embody the functionality of the means for authentication. This structure can be programmed or designed to receive messages. This structure may be programmed or designed to process the received message to authenticate the device identified by the message. This structure can then be programmed or designed to output a display showing the results of the process.
[00263] In some implementations, processing system structures, such as ASICs or programmable processors, are configured to embody the functionality of the means for establishing. This structure can be programmed or designed to receive information (eg, credentials). This structure can be programmed or designed to process the information received to establish a session (eg, identify another party to the session, identify session parameters). This structure can then be programmed or designed to output a display (eg, session parameters) showing the result of the process.
[00264] In some implementations, processing system structures such as ASICs or programmable processors are configured to embody the functionality of the means for setting up a session. This structure can be programmed or designed to receive information (eg, credentials). This structure can be programmed or designed to process the information received to set up the session (eg, identify another party to the session, identify session parameters). This structure can then be programmed or designed to output a display (eg, session parameters) showing the result of the process.
[00265] In some implementations, processing system structures such as ASICs or programmable processors are configured to embody the functionality of the means for obtaining cryptographic keys. This structure can be programmed or designed to acquire cryptographic key input parameters. This structure can be programmed or designed to process input parameters to generate cryptographic keys. This structure can then be programmed or designed to output the generated cryptographic key.
[00266] In some implementations, processing system structures such as ASICs or programmable processors are configured to embody the functionality of the means for using cryptographic keys. This structure can be programmed or designed to receive encryption keys. This structure can be programmed or designed to process cryptographic keys received to set up a communication channel (eg, identify another party to a communication, authenticate information received from another party). .. This structure can then be programmed or designed to output a display showing the result of the process (eg, send the credentials to another party).
[00267] In some implementations, processing system structures, such as ASICs or programmable processors, are configured to embody the functionality of means for initiating communication or means for initiating transfer. This structure may be programmed or designed to receive an indication that communication should be established. This structure can be programmed or designed to trigger a communication component to initiate communication with another device.
[00268] In some implementations, processing system structures such as ASICs or programmable processors are configured to embody the functionality of the means for tunneling. This structure may be programmed or designed to receive an indication that the tunnel should be established. This structure can be programmed or designed to trigger a communication component to initiate communication (eg, source and destination address exchange) with another device to establish a tunnel.
[00269] In some implementations, processing system structures, such as ASICs or programmable processors, are configured to embody the functionality of the means for authorization. This structure can be programmed or designed to receive messages (eg, identify entities that should be allowed). This structure can be programmed or designed to process incoming messages to allow the entity identified by the message as an authenticator (eg, by authenticating the sender of the message). This structure can then be programmed or designed to output an indication of the result of the operation (eg, an indication that the entity is allowed).
[00270] In some embodiments, the device or components of the device may be configured (or be able to operate or be adapted to do so) to provide the functions taught herein. This can be done, for example, by manufacturing (eg, making) a device or component to provide that function, by programming the device or component to provide that function, or by some other suitable. It can be achieved by using various mounting techniques. As an example, integrated circuits can be made to provide essential functionality. As another example, an integrated circuit can be constructed to support essential functionality and then be configured to provide essential functionality (eg, by programming). As another example, a processor circuit may execute code to provide essential functionality.
[00271] It should also be understood that references to elements using names such as "first" and "second" herein do not generally limit the quantity or order of those elements. .. Rather, these names are generally used herein as a convenient way to distinguish between two or more elements or multiple examples of an element. Therefore, references to the first and second elements mean that only two elements can be used there, or that the first element must somehow precede the second element. It's not a thing. Also, unless otherwise stated, a set of elements comprises one or more elements. In addition, "at least one of A, B, or C" or "one or more of A, B, or C" or "A, B, and" as used in the specification or claims. The term "at least one of the group consisting of C" means "A or B or C or any combination of these elements". For example, the term may include A, or B, or C, or A and B, or A and C, or A and B and C, or 2A, or 2B, or 2C.
[00272] The term "determine" as used herein includes a wide variety of activities. For example, "deciding" means calculating, calculating, processing, deriving, investigating, exploring (for example, exploring in a table, database, or another data structure). ), Confirmation, etc. may be included. Also, "deciding" may include receiving (eg, receiving information), accessing (eg, accessing data in memory), and the like. Also, "deciding" may include solving, selecting, selecting, establishing, and the like.
Those skilled in the art will appreciate that information and signals can be represented using any of a variety of different techniques and techniques. For example, the data, instructions, commands, information, signals, bits, symbols, and chips referred to throughout the above description may be voltage, current, electromagnetic waves, magnetic or magnetic particles, light fields or optical particles, or any of them. It can be represented by a combination.
[00274] In addition, any of the various exemplary logical blocks, modules, processors, means, circuits, and algorithm steps described with respect to the embodiments disclosed herein are electronic hardware (eg, source coding or some other). Various forms of programming or design code incorporating instructions (for convenience, "software" or "software modules" herein), digital implementations, analog implementations, or a combination of the two, which can be designed using techniques. It will be appreciated by those skilled in the art that it can be implemented as a combination of (sometimes called) or both. To articulate this compatibility of hardware and software, various exemplary components, blocks, modules, circuits, and steps have been described above in general with respect to their functionality. Whether such functionality is implemented as hardware or software depends on the specific application and the design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in various ways for each particular application, but the determination of such implementation should not be construed as causing a deviation from the scope of the present disclosure.
[00275] The various exemplary logical blocks, modules, and circuits described with respect to aspects disclosed herein may be implemented within a processing system, integrated circuit (IC), access terminal, or access point. Or can be performed by them. The processing system can be implemented using one or more ICs, or can be implemented within an IC (eg, as part of a system on a chip). ICs are general purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, individual gate or transistor logic, individual hardware components, electronic. It can be a component, an optical component, a mechanical component, or any combination thereof designed to perform the functions described herein, inside the IC, outside the IC, or any combination thereof. It can execute code or instructions that exist in both. The general purpose processor can be a microprocessor, but as an alternative, the processor can be any conventional processor, controller, microcontroller, or state machine. Processors can also be implemented as a combination of computing devices, such as a combination of DSPs and microprocessors, multiple microprocessors, one or more microprocessors working with DSP cores, or any other such configuration. ..
It should be understood that the particular order or hierarchy of steps in the disclosed process is an example of an exemplary approach. It should be understood that, based on design preferences, the particular order or hierarchy of steps in the process can be reconstructed within the scope of this disclosure. The attached method claims present the elements of the various steps in an exemplary order and are not limited to the particular order or hierarchy presented.
[00277] The steps of the method or algorithm described with respect to the aspects disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or a combination of the two. Can be embodied. Software modules and other data (including, for example, executable instructions and related data) include RAM memory, flash memory, ROM memory, EPROM memory, EEPROM® memory, registers, hard disks, removable disks, CD- It may reside in memory, such as ROM, or any other form of computer-readable storage medium known in the art. An exemplary storage medium is, for example, a computer / processor (for convenience, referred to herein as a "processor"" so that a processor can read information (eg, a code) from the storage medium and write the information to the storage medium. Can be coupled to machines such as). An exemplary storage medium can be integrated into the processor. Processors and storage media can reside within the ASIC. The ASIC can be in the user equipment. Alternatively, the processor and storage medium can exist as individual components within the user equipment. Further, in some embodiments, any suitable computer program product is executable (eg, executable by at least one computer) to provide functionality relating to one or more of the aspects of the present disclosure. ) Can be equipped with a computer-readable medium with code. In some embodiments, the computer program product may comprise packaging material.
[00278] In one or more exemplary embodiments, the features described may be implemented in hardware, software, firmware, or any combination thereof. When implemented in software, a function may be stored on or transmitted on a computer-readable medium as one or more instructions or codes. Computer-readable media include both computer storage media and communication media, including any medium that facilitates the transfer of computer programs from one location to another. The computer-readable medium can be any available medium that can be accessed by a computer. By way of example, but not by limitation, such computer-readable media are RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or desired programs in the form of instructions or data structures. It can include any other medium that can be used to carry or store the code and can be accessed by a computer. Also, any connection is properly referred to as a computer-readable medium. For example, software sends from a website, server, or other remote source using coaxial cable, fiber optic cable, twist pair, digital subscriber line (DSL), or wireless technology such as infrared, wireless, and microwave. Where so, coaxial cables, fiber optic cables, twisted pairs, DSL, or wireless technologies such as infrared, wireless, and microwave are included in the definition of medium. The discs and discs used herein are compact discs (CDs), laser discs (registered trademarks) (discs), optical discs, and digital versatile discs (discs). Includes DVD), floppy (registered trademark) disc (disk) and Blu-ray (registered trademark) disc (disc), which usually magnetizes data. It regenerates aerial, and the disc reproduces the data optically with a laser. Thus, in some embodiments, the computer-readable medium may include a non-transitory computer-readable medium (eg, a tangible medium, a computer-readable storage medium, a computer-readable storage device, etc.). Such non-transitory computer-readable media (eg, computer-readable storage devices) are any of the tangible forms of media described herein or otherwise known (eg, memory devices, media disks, etc.). Can be equipped. Moreover, in some embodiments, the computer-readable medium may comprise a temporary computer-readable medium (eg, including a signal). The above combinations should also be included within the scope of computer readable media. It should be understood that computer-readable media can be implemented within any suitable computer program product. Although specific embodiments are described herein, many variants and substitutions of these embodiments fall within the scope of the present disclosure.
[00279] Although some benefits and benefits of preferred embodiments have been mentioned, the scope of this disclosure is not limited to any particular benefit, use, or purpose. Rather, aspects of the disclosure are broadly applicable to a variety of wireless technologies, system configurations, networks, and transmission protocols, some of which are illustrated and illustrated by way of example.
[00280] The above description of the disclosed embodiments has been given to those skilled in the art so that they can carry out or use the present disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other embodiments without departing from the scope of the present disclosure. Therefore, the disclosure is not limited to the embodiments presented herein, but should be given the broadest scope consistent with the principles and novel features disclosed herein.
34 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2006521055A | Cites | Japan | Search report |
| JP2006521055A | Cites | Japan | Search report |
| JP2007532043A | Cites | Japan | Search report |
| JP2008028892A | Cites | Japan | Search report |
| JP2008518566A | Cites | Japan | Search report |
| JP2008518566A | Cites | Japan | Search report |
| US2009164785A1 | Cites | United States of America | Search report |
| US2009164785A1 | Cites | United States of America | Search report |
| JP2009505610A | Cites | Japan | Search report |
| JP2010503330A | Cites | Japan | Search report |
| JP2010503330A | Cites | Japan | Search report |
| WO2011064868A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| JP4223058B2 | Cites | Japan | Search report |
| JP4223058B2 | Cites | Japan | Search report |
| JP4804454B2 | Cites | Japan | Search report |
| JP4804454B2 | Cites | Japan | Search report |
21 members in 6 offices
Priority claims11
| Document | Office | Kind | Date |
|---|---|---|---|
| 201361789915 | United States of America | P | |
| 61789915 | United States of America | – | |
| 14207463 | United States of America | – | |
| 201414207463 | United States of America | A | |
| 2014026769 | United States of America | W | |
| 14207463 | – | – | – |
| 61789915 | – | – | – |
| US201361789915P | – | – | – |
| US2014026769 | – | – | – |
| US201414207463 | – | – | – |
| WO2014US26769 | – | – | – |
Members21
| Document | Office | Kind | |
|---|---|---|---|
| US2014281541A1 | United States of America | A1 | |
| US2014282909A1 | United States of America | A1 | |
| WO2014143636A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2014151979A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20150130514A | Republic of Korea | A | |
| KR20150130515A | Republic of Korea | A | |
| CN105191372A | China | A | |
| CN105191373A | China | A | |
| EP2974415A1 | European Patent Office (EPO) | A1 | |
| EP2974419A1 | European Patent Office (EPO) | A1 | |
| JP2016515369A | Japan | A | |
| US9363671B2 | United States of America | B2 | |
| JP2016518742AThis record | Japan | A | |
| US9392458B2 | United States of America | B2 | |
| US2016269183A1 | United States of America | A1 | |
| US9531543B2 | United States of America | B2 | |
| KR101699807B1 | Republic of Korea | B1 | |
| KR101715134B1 | Republic of Korea | B1 | |
| JP6105150B2 | Japan | B2 | |
| JP2017184241A | Japan | A | |
| CN105191372B | China | B |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Written measure of dismissal of application [lapsed due to lack of payment]LapsedJAPANESE INTERMEDIATE CODE: A045A045 | A045 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Re-examination (zenchi) completed and case transferred to appeal boardAppealJAPANESE INTERMEDIATE CODE: A912A912 | A912 | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on accelerated examinationJAPANESE INTERMEDIATE CODE: A971005A975 | A975 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 | |
| Explanation of circumstances concerning accelerated examinationJAPANESE INTERMEDIATE CODE: A871A871 | A871 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 |
Numbers
- Publication
- 2016518742
- Publication, DOCDB
- 2016518742
- Publication, EPODOC
- JP2016518742
- Application
- 2016502237
- Application, DOCDB
- 2016502237
- Application, EPODOC
- JP20160502237
Titles2
- Japanese
- 中継器展開のための認証
- English
- Certification for repeater deployment
Classification
- CPC, 14
- H04L63/06
- H04L63/029
- H04L63/0884
- H04L63/0892
- H04L63/10
- H04L63/162
- H04W12/0401
- H04W12/0609
- H04W84/047
- H04L9/3242
- H04L63/083
- H04L63/0876
- H04L2209/80
- H04W88/08
- IPC, 4
- H04L9 08
- H04W12 04
- H04W12 06
- H04W16 26
Designated states5
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo
- National, 1
- United States of America