Public access point
6 claims: 2 independent, 4 dependent
- 1ある端末を複数の端末から分離してある端末と複数の端末の間のネットワークトラフィックの分離をサポートするための、無線LAN用のアクセスポイント装置であって、 前記アクセスポイント装置は、前記無線LANにおける通信のための共通のアクセスポイントとして機能し、 前記アクセスポイント装置は、 アソシエーション要求またはプローブ要求である要求 であって、SSID(service set identifier)を含む要求 を 、クラス-1仮想ベーシック・サービス・セット(BSS)のメンバである 前記ある端末から受信し、 前記要求を、 前記アクセスポイント装置による前記要求の受信時に 前記クラス-1仮想BSSとは異なるクラス-3仮想 ベーシック・サービス・セット(BSS)を前記要求に対して判定し、 前記 クラス-3仮想 BSSを定義する少なくとも一つのパラメータを受信し、 前記少なくとも一つのパラメータに少なくとも基づいて前記 クラス-3仮想 BSSを確立し、 前記 クラス-3仮想 BSS内で前記ある端末とのセキュリティアソシエーションを確立し、 前記確立された クラス-3仮想 BSSのBSSIDを含む応答を前記ある端末に送信する ことによって処理する ように構成され、 前記セキュリティアソシエーションは、少なくとも二つのキーを含み、一方のキーは、暗号化のためのキーであり、他方のキーは、認証コードを計算するためのキーで あり、前記複数の端末は、前記確立されたクラス-3仮想BSSに属し、認証の後にグループセキュリティアソシエーションを共有する、 ことを特徴とするアクセスポイント装置。
- 2複数の別々のLANセグメントを供給しながら、前記LANセグメントのそれぞれに対して分離されたリンクプライバシーおよび完全性を提供するようにさらに構成されたことを特徴とする請求項1に記載のアクセスポイント装置。
- 3前記少なくとも一つのパラメータは、前記ある端末によって提供されることを特徴とする請求項1に記載のアクセスポイント装置。
- 4前記少なくとも一つのパラメータは、前記ある端末とは異なるソースによって提供されることを特徴とする請求項1に記載のアクセスポイント装置。
- 5前記少なくとも一つのパラメータは、前記SSIDに基づくことを特徴とする請求項1に記載のアクセスポイント装置。
- 6複数の局間でネットワークトラフィックの分離をサポートするための、セキュアな無線ネットワーク用のアクセスポイント装置で用いる方法であって、 前記局のそれぞれは、ハードウェア MAC アドレスを有し、 前記方法は、 アソシエーション要求またはプローブ要求 であって、SSID(service set identifier)を含む要求 を 、クラス-1仮想ベーシック・サービス・セット(BSS)のメンバである 第1の局から受信するステップと、 前記要求が前記アクセスポイント装置によって受信された時に 前記クラス-1仮想BSSとは異なるクラス-3仮想 ベーシック・サービス・セット(BSS)を前記要求に対して判定するステップと、 前記 クラス-3仮想 BSSを定義する少なくとも一つのパラメータを受信するステップと、 前記少なくとも一つのパラメータに少なくとも基づいて前記 クラス-3仮想 BSSを確立することにより、前記局のサブセットについて前記 クラス-3仮想 BSSを生成するステップと、 前記 クラス-3仮想 BSS内で前記局のそれぞれとのセキュリティアソシエーションを確立するステップであって、前記セキュリティアソシエーションは、少なくとも二つのキーを含み、一方のキーは、暗号化のためのキーであり、他方のキーは、認証コードを計算するためのキーである、ステップと、 前記確立された クラス-3仮想 BSSのBSSIDを含む応答を前記局に送信するステップと を備え、 前記サブセットの局は、前記確立された クラス-3仮想 BSSに属し、 認証の後に グループセキュリティアソシエーションを共有する、ことを特徴とする方法。
Independent claims6
52 paragraphs, as filed
Technical field<br /> This invention regards the wireless public access to electronic network. Especially, as for this invention, from while physical access pointing for electronic network it regards the architecture in order to try to be able to create virtuality BASIC service set.
As for the public WiFi hot spot, as for several exceptions it is, but using the access point of former IEEE canonical 802.11 conformity, it is disposed. But, architecture and the security model of IEEE canonical 802.11 are inadequate in the one for public. The station where in access point (AP) relation it is attached shares 802.11 BASIC service set (BSS) or the wireless LAN. If all members of BSS, are not worthy of to reliance, every station in BSS, is not safe vis-a-vis the attack which is started by the other member. It seems like the password and credit card information in attack of this genus, BASIC service and the optional classified information which are offered in order to obtain service by the subscriber stealing is included. Integrity of network and disturbance of service quality are included in the attack of other things. Public BSS, in other words, public AP and relation it is not realistic to think that all members of those which are constituted from the station where it is attached, are worthy of to reliance. Therefore, as for station, it is frangible bullet in public BSS.
To share public BSS, it means also to give other threat. The member of BSS are times when other member station is made to contaminate with the Trojan horse the worm or. DCOM RPC attack, the MS blaster and the Welchia worm which are based on the port are the good example. This threat becomes more serious is electronic depending upon the public BSS who cesspit. How it can cope station, probably is vis-a-vis these threats?<br /> Perhaps the station in BSS, you protect your own body with the defense like the private fire wall. Vis-a-vis this, perhaps the public WiFi provider, it disposes the security model conservation the subscriber from each other. One approach is to inhibit the communication between stations. As for this approach, but, they are the settlement means which cannot be supported. The station where you rely on mutually, even at the time of public configurating, should authorize the fact that it communicates in at those themselves time. For example, as for station, it must be possible to access the file server on identical local LAN in meeting which is opened at convention center. For example, this is to be run normal in the meeting of canonical. Share of this genus is permitted, temporarily, if is, the intruder, under IEEE canonical 802.11, the whole BSS as for making inoperative becomes easy. This was validated with the Las Vegas of the yusenitsukusu security conference and 2001 2001 DEFCON conference. Leading vulnerability support the share of this genus of dying it is not possible either the security model for present some wireless LAN.
It probably is profitable to supply the security model for the wireless LAN which can support the share of single physics BSS without compromising security between the stations where BSS is used without leading vulnerability, or.
<p> As for this invention, the security model for the wireless LAN which can support the share of single physical BSS without leading vulnerability, or without it compromises converting security of station, depending upon station is offered. This way, the access point of new type is provided. And, that is named the public access point (PAP) in this bill. PAP those which are stipulated by IEEE canonical 802.11 has the security architecture which differs. PAP architecture from inside single physical AP virtuality makes the creation of BASIC sabisusetsuto possible. It is possible to create the virtuality service set of optional number, and, to make virtuality revert BSS it is possible terminals of the quantity of every. PAP, one, multiple physical 802.11 accesses points is visible in the terminal vis-a-vis each virtuality BSS. Therefore, as for PAP, also what 802.11 terminals are interoperation possible completely. </p><p> As an example of the use of PAP, of convention center will be thought. The meeting which differs, are times when 802.11 standard projectors are used. PAP offering link privacy and the integrity which are separated vis-a-vis each, makes that it offers the separate LAN segment to each meeting possible. When you use only IEEE canonical 802.11 for substituting, all stations which can project making use of the projector of meeting and that must use private access point or ad hoc WLAN and the WLAN member ship, must manage authentication and the key conversion material (keying material). Otherwise, project to do, it will be possible anyone making use of the projector or furthermore in bad thing, before that is displayed, intercept it will do the traffic of the effective projector, that it will be monitored by the public person, could be a possibility of being altered. </p><p> Until recently rather than the planner of meeting installs their themselves access points every opening area in addition to burden of the security management which it is related to the approach of technology being too large, configurating the fact that the margin local access point which is rubbed is utilized is liked. To manage all securities it is possible PAP. With that, the virtuality 802.11 access point for that meeting efficiently the association all terminals which include the shared projector and the optional local file server, in each meeting, and all virtuality beshitsukuakusesu points, occur from the same physics PAP. </p><p> This invention offers also the location update protocol in order to update the transfer table of the bridge which joints the public access point together. </p><p> This invention, furthermore, is called fine bridging, from it offers also the manner for the bridging which is controlled. </p>
<figref num="1">It is the outline figure of IEEE canonical 802.11 protocol entity. </figref><figref num="2">It is the block figure of the configuration below structure of IEEE canonical 802.11. </figref><figref num="3">It is the outline figure of the public access point architecture by this invention. </figref><figref num="4">It is due to this invention, it is the block figure of the policy for the accessibility inside the range of virtuality BSS of three stations where one is AP. </figref><figref num="5">It is due to this invention, station A and B, share server station S and D, but A and B are the block figure of policy between four stations where it is not permitted that it accesses each. </figref><figref num="6">In order for the edge to A to be added to the policy which is due to this invention, in drawing 3 from B, it is the block figure of the policy which was adjusted. </figref><figref num="7">The VLAN allotment which is based on the port, through exit filtering and shared VLAN study (SVL), direct communication between the edge hosts which are jointed vis-a-vis the below structure system is removed, it is the block figure of the IEEE canonical 802.1Q bridge.</figref>
The American patent application No. The terminal, existing VLAN the tag is done to attach to 10/057,566, the protocol which can create the virtual bridge LAN (VLAN) which makes the clone of existing VLAN and by duplicating the member set which the tag is not done to attach, is stated. Furthermore, this new VLAN is converted specifically for that specific security association. This association private puts the packet which belongs to VLAN in state, offers the cryptography key conversion material which makes that you verify cryptography at the same time with MAC which the member ship of VLAN, to key is converted possible. That implementor owns this new VLAN. Some station be able to join this owner, and some station can discover VLAN, and the continuance period of VLAN is controlled. Therefore, VLAN is called personal virtual bridge LAN (PVLAN).
One example of this invention IEEE canonical 802.11-1999 only the canonical element offers the improved of PVLAN which is not used. (11th section look-up: Wireless LAN media access control (MAC) and physical layer (PHY) specification, ISO/IEC 8802-11: 1999(E) ANSI/IEEE canonical 802.11 and 1999 edition, and 11th section look-up: Wireless LAN media access control (MAC) and the physical layer (PHY) specification, the drafting plan amendment manual for media access control (MAC) security strengthening, IEEE canonical 802.11i/D7.0 and ISO/IEC 8802-11,1999(E), ANSI/IEEE canonical. 802.11 and 1999 edition.)The drawing 1 which is the block figure of IEEE canonical 802.11 protocol entity and, each BSS (BSS-A and BSS-B), the access point (AP-A and AP-B) of each one, relation we would like to access the drawing 2 which is the block figure of the IEEE canonical 802.11 configuration below structure which has with the station (A1/A2 and B1/B2) where it is attached. Adjustment of operation of the terminal of every 802.11 standard conformity which do not work as an access point, is unnecessary at the time of this inventing. PVLAN to instance it converts the revised dot, vis-a-vis BSS of virtuality, 802.11 and exerts influence to only the access point.
Drawing 3 is the block figure of the public access point architecture by this invention. Virtuality 802.11 BSS, for example BSS-1 or BSS-2 is called the group security association, the specific security association is shared, it possesses the station of the deck, each one has hardware (MAC) address (you access drawing 1,). The security association, consists of the encryption key and the authentication code key.
Just one among stations, is public access point 31 (PAP) in virtuality BSS. That 802.11 wireless media (WM) 32 and the bridge does 802.11 distribution system media (DSM) 33.
The specific uni- cast security association, it exists vis-a-vis all stations in virtuality BSS. That is shared station of the virtuality BSS and between PAP.
Each virtuality BSS, for example, BSS-1 or BSS-2, that itself identifier, in other words has BSSID. That is the virtual MAC address of PAP which has reverted to the BSS. PAP receives the optional frame from WM which is directed to one among the virtual MAC addresses, and uses one among that virtual MAC addresses transmits the frame to WM as source MAC address of the frame and.
Virtuality BASIC of one group sabisusetsuto is support with PCF (point adjustment function) in single PAP, sharing TSF (timing synchronization function), as DCF (distributed adjustment function) and option. In each PAP, single NAV (network allocation vector) and PC (point controller), exist. In order 802.11 virtuality carrier detection and media reservation mechanism, the multiple BASIC service sets which use overwrapping of the same channel to cooperate, because it is designed, share of this genus, is possible. Overwrapping of this genus the virtuality are times when it occurs between BASIC which is support with single channel PAP sabisusetsuto. Because can virtuality service set, use one channel, it is possible to overwrap in PAP.
To revert to the virtuality BSS of one or more it is possible PAP. We would like to access BSS-1 and BSS-2 on drawing 1. Being many, to revert to one virtuality BSS it is possible every station which is not PAP.
Virtuality BSS of other things and the bridge it is possible BSS of virtuality 802.11, due to virtual bridge LAN through the joint of those public access points to do. PAP of each virtuality BSS was done the trunk of the VLAN- bridge, or through the port which the tag is not done to attach, you joint to the distribution system (DS). As for the frame which is transmitted to DS, to support it is possible the VLAN tag which is known to DSM. PAP the VLAN tag to virtuality BSSID may maintain the DSM VLAN mapping which the map is done.
Presently, virtuality BSS of 2 types: Class - 1 and class - 3 virtuality BSS exists. PAP one class - 1 virtuality BSS and the multiplex class - 3 virtuality support BASIC of one or more sabisusetsuto (multiple Class-3 virtual basic service set) precisely. In order to be managed by PAP, class - 1 virtuality BSS while station is in 802.11 states 1 or 2, are the only virtuality BSS where it is permitted that it occupies. When is state 3, as for station, it is permitted that it joins in class - 3 virtuality BSS. As for class - 3 virtuality BSS, for example, it is used in order to authenticate station, it is possible to decide with the authentication for example like the open system or the shared key.
Class - 1 virtuality BSSID all classes are BSSID field of 1 which possess the field of this genus and the class 2 frame. That, in appropriate case, in class confronts 1 and the class 2 frame, it is receiver or transmitter address field.
All virtuality BSS has the identical beacon frame contents time stamp and beacon interval, the capacity information privacy (conservation) bit, service set identifier (SSID), excluding the security capacity element, and traffic specification map (TIM) element field.
As for PAP, if it is not support PS (power source saving) mode vis-a-vis the terminal in the BSS, it is not necessary to send the beacon vis-a-vis class - 3 virtuality BSS. If that, sends the beacon to class - 3 virtuality BSS, the SSID element of all beacons, specifies broadcast SSID. These steps every class - 3 virtuality BSS, prevent the fact that it is identified by the beacon.
Just the class - 1 virtual BSS beacons, have the SSID element which possesses non broadcast SSID field. As for station, just class - 1 virtuality BSS relation it can attach. As for this station, the association or the non broadcast SSID in the SSID element of the re-asoshieshiyonrikuesuto frame is used.
The American patent application No. 10/057566 specifies PVLAN joining and heuristic step. These steps, like below to instance are converted as virtuality BSS by PVLAN which is displayed.
Joining<br /> All stations, with default, are the member of class - 1 virtuality BSS with PAP. As for PAP, the user of the station in class - 1 virtuality BSS or it can authenticate either of stations itself. When it succeeds, station enters into 802.11 states 2 in the PAP. This time, PAP and station while being in class - 1 virtuality BSS, class may exchange the frame of 1 and class 2.
The class 1 frame is not conservation with cryptography. If authentication, after succeeding, station and PAP, shares the uni- cast security association, conservation cryptography it is possible the class 2 frame. PAP and station, after the authentication, can also share the group security association. As for the group security association, if PAP and 802.11 associations are completed, it is for the class - 3 virtuality BSS to which station reverts.
Station and PAP, before being possible, to exchange the class 3 frame, as for station,<br /> 1) to request the association of class - 1 virtuality BSS from state 2, and<br /> 2) you must change to class - 3 virtuality BSS.
As for PAP, the source address (address 2 field) or BSSID (address 3 field), changes station to class - 3 virtuality BSS by responding to the association request of station with the association response MMPDU which is the class - 3 virtuality BSSID for the virtuality BSS. Capacity information field of association response may configurate the privacy (conservation) bit to 1.
Class - 3 virtuality BSS are decided with one manner among three manners:<br /> 1) the authentication server in DS, specifies DSM VLAN vis-a-vis the user, and, PAP, uses the DSM VLAN mapping, that the map does in class - 3 virtuality BSSID.<br /> 2) the authentication server in DS, specifies class - 3 virtuality BSS vis-a-vis the user, or,<br /> 3) PAP, creates new class - 3 virtuality BSS vis-a-vis the user. PAP informs about the virtuality BSS where is new in the authentication server, and other station, can offer the rule which makes that in new BSS it joins possible to that.
Discovery<br /> Class - 1 virtuality BSS are discovered by 802.11 beacons or the probe response management frame. Here, BSSID field (address 3 field) and source address field (address 2 field), are set respectively vis-a-vis class 1 virtuality BSSID. The privacy (conservation) bit of capacity information of these frames is set to zero. The TIM element of the beacon is applied to class - 1 virtuality BSS. Only class - 1 virtuality BSS, through the beacon frame, it is announced.
Data frame (MPDU) distribution<br /> PAP executes MAC protocol data unit (MPDU) bridge protocol. Vis-a-vis MPDU which is received from DSM or WM protocol is defined by two cases below:<br /> 1. MPDU which is received from DSM. There are two sub cases. (Note: Two sub cases confront the local LLC of PAP, the transmission of MPDU which is received is handled, because the station of all PAP, reverts to one virtuality BSS at least because.):<br /> a. The VLAN tag the possession it does not do MPDU which is received, or, possesses the VLAN tag of the nul. Temporarily to be address of the station where it reverts to BSS, and station, it can connect intended address, to PAP, if is, MPDU from DSM is relayed to virtuality BSS, or, intended address, is group address, is, virtuality BSS has the station where it belongs to the group, that station relation is attached to PAP. All stations belong to the broadcast group.<br /> b. MPDU which is received has the VLAN tag of the non nul. As for the virtuality BSS where MPDU is relayed, the VLAN tag of the non nul, is identified by BSSID which the map is done under the DSM VLAN mapping of PAP. Mapping, it is undefined vis-a-vis the tag which is given, if is, MPDU is not relayed.<br /> Every virtuality BSS where MPDU which is received is relayed, has BSSID which forms the source address (address 2 field) of 802.11 MPDU which are relayed in that virtuality BSS.<br /> 2. MPDU which is received from WM. 802.11 MPDU which are received are address of the station where it reverts to the virtuality BSS where that intended address (the address 3 field of MPDU), is identified to the virtuality BSS which is identified by the address 1 field of MPDU, and, that station, relation is attached to PAP, or or, that intended address, is group address, if is, it is relayed. So if is not, the frame is not relayed in every virtuality BSS. The address 1 field of 802.11 MPDU which are received is the source address (address 2 field) of 802.11 MPDU which are relayed in the virtuality BSS which is identified by address 1 field.<br /> Intended address (the address 3 field of MPDU), PAP and relation is address of the station where it is not attached, or or, intended address, is group address, if is, MPDU which is received is relayed even in DSM. DS, has recognized VLAN, if is, MPDU which is relayed in DSM has the VLAN tag, and so is not, the tag is not attached. The VLAN tag is pre- image of the address 1 field of MPDU where in the origin of the DSM VLAN mapping of PAP is received.
Cryptography and decoding process<br /> Cryptography and decoding, subtype association request/response, re-association request/response and deisuasoshieshiyon and apply 802.11 data frame and the management frame of deviation from authentication (Deauthentication).
Before sending 802.11 data or the management frame vis-a-vis WM, the encryption process which is used by PAP includes two principal steps:<br /> - Identifying the security association vis-a-vis the frame and,<br /> - Following to several encryptions (encipherment) and authentication code protocol making use of that association, construct the frame which for transmitting is expanded.<br /> The encryption and authentication code protocol which differs can use, for broadcasting and the multi cast traffic which are during virtuality BASIC service setting and, the encryption and authentication code protocol which differs, because of the traffic where between of the stations in single virtuality BSS is specified (uni- cast) use can.
When frame intended address (address 1 field), it is address of station, that station and the uni- cast security association which is shared between PAP are used at the time of expanding. This frame, is the data frame, and, the intended address, is group address, if is, MPDU bridge protocol identifies the intended virtuality BSS for the frame. The group security association for BSS which is identified, is used for expansion.
As for non PAP station, PAP that in the BSS using the uni- cast security association which is shared, it transmits type data or 802.11 MPDU of management vis-a-vis DS.
When receiving 802.11 data or the management frame from WM, using the uni- cast security association for the station where it is identified by the source address (address 2 field) of MPDU, it decodes PAP, it tries the fact that integrity of the frame is verified.
When receiving type data or 802.11 MPDU of management from PAP, if fault - as for PAP station, if intended address (address 1 field) of the frame, is address of station, that PAP using the uni- cast security association which is shared, and, if intended address of the frame, is group address, using the group security association of the class 3 virtuality BSS, it decodes, it tries the fact that integrity of the frame is verified.
Location update protocol<br /> This invention, location update protocol in order to update the transfer table of the bridge, or, joints the public access point together, also other interconnect media has.
In the supanningu tree of bridge LAN, attaching to the bridge which differs, when those one and relation you attach to the multiple public access points, and each other, and new PAP re-relation you think of the terminal which is attached, as for new PAP, the bridge protocol data unit (BPDU) which (being called relocation PDU,) is specified station relation sends to PAP which is attached in the past. The intended address of BPDU is present AP address of the re-asoshieshiyonrikuesuto frame, that is class - 3 virtuality BSSID. Source address is hardware address of station.
When relocation MPDU is received in the specific port, the bridge updates that transfer table with the entry which binds the reception port in the source address of MPDU.
As for the reception bridge, that in the root port which is specified relocation MPDU, if MPDU does not arrive at that port, if or the reception bridge is not the root of the subaningu tree, it transfers. If that, is received in the root port where the bridge is specified, or, by the root bridge, that is transferred following to the transfer table where the bridge was studied, that includes the fact that it makes MPDU OVERFLOW vis-a-vis all ports which exclude the reception port.
Fine bridging<br /> One example of this invention which is argued at on squeezes PVLAN vis-a-vis virtuality BSS. Under MPDU bridge protocol, to the other every station in the frame which every station in virtuality BSS, was specified and or to group address is converted that virtuality BSS it can send. Without being desirable, there probably is this. As for the meeting in conference center, for example, it is possible to have possessed that itself virtuality BSS, but all attendees, are not the case that you rely on each. As for a certain attendee, it is possible by sharing the same virtuality BSS, to throw the worm or the virus. As for it tries to obstructing these attacks by allocating each attendee to specific virtuality BSS, the attendee, it means not to be able share the server. Ideally, as for the server, it is shared by all meeting participants, but every participant, accesses the other participant, in other words as for sending the frame that we should try it is not possible. As for the above-mentioned public access point, it is not possible to offer the access control of this level. To offer that it is possible AP which is support fine bridging.
We would like to access also the drawing 7 which is the block figure of IEEE canonical 802.1.Q. The 802.1Q bridge has jointed the edge host of the deck vis-a-vis the below structure system like LAN. The tag which arrives from the edge host as for the frame which is not done to attach, it is allocated to VLAN A by the port based VLAN allotment (PVID A), and, the tag which arrives from the below structure system as for the frame which is not done to attach, it is allocated to VLAN B (PVID B). Although the frame which has reverted to A or B with the output rule which is described, keeps appearing in the below structure is allowed only the frame which is generic to B, is allowed the fact that it keeps appearing in the edge host. With this kind of manner, the edge host is prevented the fact that directly, it communicates mutually.
Fine bridging separates broadcast or the identification of multi cast domain which possesses BSS (decouple).
Under fine bridging, behavior of the bridging of AP is decided as the digraph by the policy which is displayed. The node in the graph is station, and station A, the edge to station B exists from station A only when it is possible to access station B. If you rephrase, station B, station A was specified or receiving the group frame must be possible.
Itself and that must access broadcast domain, vis-a-vis the policy of given, vis-a-vis a certain node, they are all nodes. Broadcast domeinsetsuto of policy is broadcast domain of the deck for that node.
At the time of executing the policy, there is a group security association in every broadcast domain. Furthermore, as for each station (node), the broadcast domain for that itself in policy, and, the group security association of all other broadcast domains in the policy where that is the member is owned. The association of former, can in order to transmit the group frame, and because the latter association receives the group frame, use depending upon station.
The accessibility in during 3 station virtuality BSS where the one of them is AP is captured by the policy which is shown in drawing 2. Each node in policy, {has A, B and AP} as the broadcast domain. This way, there being only one broadcast domain vis-a-vis policy, this when you think of that policy reflects virtuality BSS is to be expected. As for each station, knowing the group security association for domain, to transmit and to receive the group frame and it is possible in the origin of that association.
As for drawing 3, station A and B, share server station S and D, but A and B capture the policy between four stations where it is not permitted that it accesses each.
As for this policy, broadcast domain B1: {A, S and D}, B2: {B, S and D} and B3: {It has possessed D, A, S and B}. Station A in order to send the group frame, informing the group security association for B1, in order to receive the group frame which is sent by S and D, has known the group security association for B3. Station D transmits the group frame, in order to receive those from S, knowing the group security association for B3, in order to receive the group frame respectively from A and B, knows the group security association for B1 and B2 both.
The policy in drawing 3, for example, as the edge to A, in order to be added vis-a-vis policy, when it is adjusted, illustrated to drawing 4 from B, domain B2 will be removed, just B1 and B3 probably will remain.
From A the edge to B, when it is added to the policy in drawing 4, it probably will reduce domain B1, B2 and B3, in single domain B3 vis-a-vis this policy.
As for offer of the other policy variation, it is inside the range of capacity of this trader.
This invention is stated in the long-cherished desire bill in regard to the desirable example, but this trader when it is good displacement to those which are stated application of other things, without gist of this invention and deviating from the range, in the long-cherished desire bill probably will understand thing at once. Therefore, as for this invention, we should restrict only with the patent claim of attachment.
31 public access point<br /> 32 radio media<br /> 33 distribution system media<br /> 33 distribution system media
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| WO2003055151A1 | Cites | World Intellectual Property Organization (WIPO) |
| WO02058336A2 | Cites | World Intellectual Property Organization (WIPO) |
| US20030037169A1 | Cites | United States of America |
| US20030227893A1 | Cites | United States of America |
84 members in 8 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10754402 | United States of America | – | |
| 75440204 | United States of America | A | |
| 75440204 | United States of America | A | |
| 2004754402 | – | – | – |
| US20040754402 | – | – | – |
Members84
| Document | Office | Kind | |
|---|---|---|---|
| US2003120763A1 | United States of America | A1 | |
| WO03055151A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002240211A1 | Australia | A1 | |
| US2003145118A1 | United States of America | A1 | |
| WO2004042984A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003294242A1 | Australia | A1 | |
| AU2003294242A8 | Australia | A8 | |
| US2004141617A1 | United States of America | A1 | |
| KR20040066902A | Republic of Korea | A | |
| EP1457004A1 | European Patent Office (EPO) | A1 | |
| WO2004042984A3 | World Intellectual Property Organization (WIPO) | A3 | |
| CN1606849A | China | A | |
| JP2005513915A | Japan | A | |
| EP1556990A2 | European Patent Office (EPO) | A2 | |
| WO2005069784A2 | World Intellectual Property Organization (WIPO) | A2 | |
| CN1708940A | China | A | |
| JP2006505222A | Japan | A | |
| WO2005069784A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2006206944A1 | United States of America | A1 | |
| EP1702434A2 | European Patent Office (EPO) | A2 | |
| US7120791B2 | United States of America | B2 | |
| KR20060129005A | Republic of Korea | A | |
| CN1910861A | China | A | |
| US7188364B2 | United States of America | B2 | |
| CN1976317A | China | A | |
| JP2007518356A | Japan | A | |
| HK1100111A1 | Hong Kong, China | A1 | |
| US2008022390A1 | United States of America | A1 | |
| US2008198821A1 | United States of America | A1 | |
| US2008198863A1 | United States of America | A1 | |
| JP4190421B2 | Japan | B2 | |
| US2008301442A1 | United States of America | A1 | |
| KR100891041B1 | Republic of Korea | B1 | |
| KR20090081006A | Republic of Korea | A | |
| KR100933097B1 | Republic of Korea | B1 | |
| US7644437B2 | United States of America | B2 | |
| KR20100002283A | Republic of Korea | A | |
| JP4447463B2 | Japan | B2 | |
| US7703132B2 | United States of America | B2 | |
| CN101707596A | China | A | |
| EP1702434A4 | European Patent Office (EPO) | A4 | |
| CN1976317B | China | B | |
| JP2010178356A | Japan | A | |
| JP2010178357A | Japan | A | |
| JP2010183610A | Japan | A | |
| US7818796B2 | United States of America | B2 | |
| CN1910861B | China | B | |
| KR101002448B1 | Republic of Korea | B1 | |
| US7877080B2 | United States of America | B2 | |
| US7886354B2 | United States of America | B2 | |
| US2011033047A1 | United States of America | A1 | |
| EP1457004A4 | European Patent Office (EPO) | A4 | |
| US2011126278A1 | United States of America | A1 | |
| CN1606849B | China | B | |
| CN102130919A | China | A | |
| US7986937B2 | United States of America | B2 | |
| EP1556990A4 | European Patent Office (EPO) | A4 | |
| CN1708940B | China | B | |
| US2011310872A1 | United States of America | A1 | |
| US2011321128A1 | United States of America | A1 | |
| EP2469772A2 | European Patent Office (EPO) | A2 | |
| EP2479936A1 | European Patent Office (EPO) | A1 | |
| US8276198B2 | United States of America | B2 | |
| US8347377B2 | United States of America | B2 | |
| US2013024692A1 | United States of America | A1 | |
| KR101260100B1 | Republic of Korea | B1 | |
| KR20130049812A | Republic of Korea | A | |
| CN102130919B | China | B | |
| JP5253442B2 | Japan | B2 | |
| EP2640008A2 | European Patent Office (EPO) | A2 | |
| CN101707596B | China | B | |
| JP5330298B2This record | Japan | B2 | |
| EP2469772A3 | European Patent Office (EPO) | A3 | |
| KR101365830B1 | Republic of Korea | B1 | |
| US8675559B2 | United States of America | B2 | |
| US8767623B2 | United States of America | B2 | |
| US2014337966A1 | United States of America | A1 | |
| EP2640008A3 | European Patent Office (EPO) | A3 | |
| US8966611B2 | United States of America | B2 | |
| JP5865578B2 | Japan | B2 | |
| EP1556990B1 | European Patent Office (EPO) | B1 | |
| EP2640008B1 | European Patent Office (EPO) | B1 | |
| US9730070B2 | United States of America | B2 | |
| EP1457004B1 | European Patent Office (EPO) | B1 |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 5330298
- Publication, DOCDB
- 5330298
- Publication, EPODOC
- JP5330298B
- Application
- 62701
- Application, DOCDB
- 2010062701
- Application, EPODOC
- JP20100062701
Titles2
- Japanese
- 公衆アクセス・ポイント
- English
- Public access point
Classification
- CPC, 13
- H04W12/08
- H04L12/4625
- H04L12/4641
- H04L12/4645
- H04L63/0272
- H04L63/08
- H04L63/105
- H04L63/123
- H04W64/00
- H04W84/12
- H04W88/10
- H04W92/02
- H04W40/023
- IPC, 8
- H04W12 06
- H04W84 12
- H04W80 02
- H04W88 08
- H04L12 56
- H04L12 28
- H04L12 46
- H04L29 06
