Methods and apparatus for solicited activation for protected wireless networking
13 claims: 5 independent, 8 dependent
- 1ワイヤレスネットワークを発見する方法において、 1つ以上の要求を送信 し、ワイヤレスネットワークへの懇請アクセス(SAW)のプロトコルのサポートを示す応答メッセージ内のSAW特有情報エレメントで設定された少なくとも1つのフラグを含む少なくとも1つの応答メッセージを受信 することにより1つ以上の許可されたチャンネルを能動的にスキャンする段階と、 SAWの前記プロトコルのサポートを示す前記応答メッセージ内のSAW特有情報エレメントで設定された少なくとも1つのフラグを識別するパラメータを含む 送信信号を聴取することにより1つ以上の禁止されたチャンネルを受動的にスキャンする段階と、 前記能動的スキャン又は受動的スキャンの少なくとも一方に少なくとも一部分基づいてチャンネルを発見する段階と、 SAWの前記プロトコルをサポートするように構成されたワイヤレスネットワークへ接続する要求を送信する段階であって、前記要求は帯域内コンフィギュレーションデータを含む、段階と、 を備えた方法。
- 2前記ワイヤレスネットワークは、IEEE規格802.11に準拠するネットワークを含み、前記1つ以上の要求は、プローブ要求であり、そして前記送信信号は、ビーコン信号を含む、請求項1に記載の方法。
- 3前記受動的スキャンは、1つ以上のダイナミック周波数スキャン(DFS)禁止チャンネルに対応する第1の周波数範囲サブセットをスキャンすることを含む、請求項2に記載の方法。
- 4前記能動的スキャンは、1つ以上のダイナミック周波数スキャン(DFS)許可チャンネルを経て要求を送信することを含む、請求項2に記載の方法。
- 5ワイヤレスネットワークに使用するための装置において、 1つ以上のコンピュータ実行可能なインストラクションを実行できるプロセッサと、 ワイヤレストランシーバと、 プロセッサにより実行可能なコンピュータプログラムを含むメモリと、を備え、前記コンピュータプログラムは、前記プロセッサにより実行されたときに、前記プロセッサが、 前記ワイヤレストランシーバを経て1つ以上のワイヤレスアクセスポイントを能動的にスキャンし、 ワイヤレス保護設定の懇請アクチベーション(SAW)のプロトコルのサポートを示す応答メッセージ内のSAW特有情報エレメントで設定された少なくとも1つのフラグを識別するパラメータを含む少なくとも1つの応答メッセージを受信し、 SAWの前記プロトコルのサポートを示す前記応答メッセージ内のSAW特有情報エレメントで設定された少なくとも1つのフラグを識別するパラメータを含む送信された信号を聴取することにより、 前記ワイヤレストランシーバを経て1つ以上のワイヤレスアクセスポイントを受動的にスキャンし、 前記パラメータに基づいて、 1つ以上の発見されたワイヤレスアクセスポイントが SAWの前記プロトコル をサポートするかどうか決定し、そして SAWの前記プロトコルをサポートするように構成されたワイヤレスネットワークへ接続する要求を送信し、前記要求は帯域内コンフィギュレーションデータを含む、 ようにさせる、装置。
- 6前記装置は、IEEE規格802.11に準拠し、前記能動的スキャンは、1つ以上のプローブ要求を送信することを含み、そして前記受動的スキャンは、1つ以上のビーコン信号を受信することを含む、請求項5に記載の装置。
- 7前記受動的スキャンは、送信が禁止された1つ以上の高周波チャンネルをスキャンすることを含み、そして前記能動的スキャンは、送信が禁止されない1つ以上のチャンネルを経て要求メッセージを送信することを含む、請求項5に記載の装置。
- 8前記受動的スキャン及び能動的スキャンは、実質的に同時に遂行される、請求項 7 に記載の装置。
- 9前記受動的スキャン及び能動的スキャンは、食い違い形態で遂行される、請求項 7 に記載の装置。
- 10前記1つ以上のIEは、タイプ・長さ・値(TLV)定義におけるマネージメントフレームの各々の中に埋め込まれる、請求項 5 に記載の装置。
- 11前記装置は、ネットワークセキュリティネゴシエーションパラメータの表示をサポートするユーザインターフェイスを備えていない、請求項5に記載の装置。
- 12前記装置は、ポータブルメディアケーパブル装置を含む、請求項5に記載の装置。
- 13前記受動的スキャン及び能動的スキャンは、実質的に同時に遂行される、請求項1に記載の方法。
Independent claims13
127 paragraphs, as filed
The present invention generally relates to the field of wireless communication. More specifically, in one exemplary embodiment, the invention relates to a method and device for Solicited Addition of a wireless device to a wireless network.
Part of the disclosure of this patent document includes material subject to copyright protection. The copyright owner does not object to anyone copying and reproducing the patent disclosure as it appears in the patent file or record of the Patent and Trademark Office, and all copyright rights shall be preserved. ..
Cross-reference to related applications: This application claims the priority of U.S. Patent Application No. 12 / 571,102 (agent control number 20750P-017800US) filed on September 30, 2009, all of which is inclusive. It is used here as a reference for the purpose of.
Wi-Fi® is an almost ubiquitous wireless network (WLAN) technology that enables devices to connect to the Internet and ad hoc networking of devices. Wi-Fi® networks have been widely deployed for residential and commercial use (eg, coffee shops, bookstores, hotels, etc.) due to their relatively easy setup and management and low cost.
According to hearing, existing wireless encryption methods are difficult to use for non-technical users and can quickly lead to insecure networks (eg, improperly configured or not configured at all). .. Subsequent standards for Wired Equivalent Privacy (WEP) and Wi-Fi Protected Access (WPA and WPA2) have become the current de facto standards for Wi-Fi network security. Wi-Fi Protection Settings (WPS) was introduced as a voluntary network security program by the Wi-Fi Alliance in early 2007. WPS provides an abbreviated network configuration solution that reduces the number of steps required to configure a protected Wi-Fi network. WPS requires support for Wi-Fi Protected Access (WPA) or WPA2. The WPS protocol targets non-technical users who are threatened by the available security configurations of WPA-type systems with little knowledge of wireless security.
<p> WPS shortens the process of adding equipment to a secure network, but can further improve the user's overall experience with additional improvements that have a significant impact on new WPS improvements. More specifically, improved equipment and methods are needed to solicited activation of wireless network security processes. Such devices and methods ideally allow the user or administrator to perform additional steps and currently required knowledge (select cryptographic protocol, give user identification, identify themselves, etc.). It allows you to decide whether to add a new device to your wireless network, even if you don't have one.</p><p> Moreover, such improved methods and devices ideally interface transparently with the constraints of existing networks and thus maintain full backward compatibility with existing networks and devices. Appropriate solutions must also take into account such network limitations (Wi-Fi dynamic frequency selection (DFS), etc.) and responsively change their behavior as needed.</p>
<p> The present invention satisfies the above requirements, among other things, by providing improved devices and methods for adding wireless devices to wireless networks.</p><p> In one aspect of the invention, a method of discovering a wireless network is disclosed. In one embodiment, the method actively scans one or more authorized channels by transmitting one or more requests and one or more prohibited channels by listening to the transmitted signal. Includes passively scanning and discovering channels based on at least a portion of active or passive scanning.</p><p> In one variant, the wireless network is an IEEE standard 802.11 compliant network, one or more requests are probe requests, and the transmit signal is a beacon signal. Passive scans include, for example, scanning a first frequency range subset corresponding to one or more Dynamic Frequency Scan (DFS) prohibited channels, and active scans include, for example, one or more dynamic frequency scans. (DFS) Includes sending a request over an authorized channel.</p><p> In the second aspect of the present invention, a device for use in a wireless network is disclosed. In one embodiment, the device comprises a processor capable of performing one or more computer-executable instructions, a wireless transceiver, and a memory containing computer programs executed by the processor. A computer program actively scans one or more wireless access points through a wireless transceiver and passively scans one or more wireless access points through a wireless transceiver when executed by a processor. It also determines whether one or more discovered wireless access points support operations based on secure protocols, and filters one or more discovered wireless access points that do not support secure protocols.</p><p> In one variant, the computer program also sends an information element (IE) at run time through a wireless transceiver to one or more wireless access points operating under a secure protocol.</p><p> In another variant, the device complies with IEEE Standard 802.11, active scanning involves sending one or more probe requests, and passive scanning receiving one or more beacon signals. including.</p><p> In yet another variant, passive scanning involves scanning one or more high frequency channels forbidden to transmit, and active scanning sends a request message over one or more channels for which transmission is not prohibited. Including doing. Passive and active scans can be performed substantially simultaneously, in a staggered form and / or using other schemes.</p><p> In yet another variant, the determination of whether one or more discovered wireless access points support operations based on secure protocols depends on the one or more security protocols supported by that discovered wireless access point. Includes receiving one or more information elements (IEs) that you specify. One or more IEs are embedded in each of the management frames in the type / length / value (TLV) definition, for example, or delivered using other solutions.</p><p> In yet another variant, the device does not have a user interface that supports the display of network security negotiation parameters.</p><p> In another variant, the device is a portable media capable device (eg, laptop computer, smartphone, personal media device, etc.). Apart from that, it is also a network access point, or non-portable device, such as a desktop computer or server.</p><p> In a third aspect of the invention, a method of publishing a new enrolly to a wireless network is disclosed. In one embodiment, this method receives a remote procedural call for a wireless configuration protocol, the remote procedural call is related to a new enrolly, and the addition of a new enrolly violates network operating standards. Includes deciding whether to do so, adding the new enrolly to the list if the addition of the new enrolly does not exceed the criteria, and publishing the service discovery record for the new enrolly to the wireless network.</p><p> In one variant, the wireless network complies with the IEEE standard 802.11, and the wireless configuration protocol is the Wireless Protection Configuration (WPS) protocol.</p><p> In another variant, the step of publishing a service discovery record for a new enrolly to a wireless network is at least publishing a subtype description through a service discovery protocol (eg, the exemplary Bonjour protocol developed by the transferee). Including doing. Also, such a service discovery protocol, optionally, allows searching for that record and other records by said subtype.</p><p> In a fourth aspect of the present invention, a method of forming a wireless network having at least two wireless devices is disclosed. In one embodiment, the method uses a first device to perform a detection protocol to detect other devices available, and an individual one of the other devices is based on at least a portion of the detection protocol. Decide whether to support the specified security protocol, request the merger of the first device into a network that supports the security protocol, give information about the first device to at least one of the other devices according to the request, and Includes establishing operation between the first device and at least one other device under a security protocol.</p><p> In one variant, the first device is a client device, at least one other device is an access point (eg, conforms to IEEE standard 802.11), and the security protocol is WPS solicited. Activation (SAW). Alternatively, in another variant, the first device is an access point and at least one other device is a client device.</p><p> In yet another variant, using the first device to carry out the detection protocol to detect other available devices is permitted by sending one or more requests. It involves actively scanning channels and passively scanning one or more forbidden channels by listening to the transmitted signal.</p><p> In yet another variant, determining whether an individual one of other devices supports a defined security protocol based on at least a portion of the detection protocol involves receiving an information element as part of a probe response message. ..</p><p> In another variant, giving information about the first device to at least one of the other devices as required involves giving a human-designated, human-readable name or identifier.</p><p> This method can be performed substantially automatically without the intervention of the user, or can be performed with some degree of user involvement or desirable management.</p><p> Moreover, in another embodiment, at least one of the first device and at least one other device does not have a visual user interface and uses another device in the network to use the first device or at least one. Provides user interface capabilities for one other device.</p><p> In a fifth aspect of the present invention, a computer-readable device is disclosed. In one embodiment, the device comprises a storage medium having at least one computer program, and the detection protocol using the first wireless device when the at least one computer program is executed in the computerized device. To detect one or more available wireless devices and, based on at least a portion of the detection protocol, determine whether each individual one or more available devices supports a defined security protocol. Requests the merger of the first device into one or more available devices that support the security protocol, gives information about the first device to at least one of the one or more available devices according to the request, and It has multiple instructions to establish operation between the first device and at least one available device based on the security protocol.</p><p> Other features and effects of the present invention will be readily apparent to those skilled in the art from the accompanying drawings and the following detailed description of preferred embodiments.</p>
<figref num="1">It is a functional block diagram of an exemplary WLAN (eg, Wi-Fi) wireless network.</figref><figref num="2">It is a logical flowchart of an embodiment of a general process for soliciting access to a secure wireless network according to the principles of the present invention.</figref><figref num="3">It is a ladder diagram that embodies a general process for soliciting access to a secure wireless network in Figure 2, which is carried out between four individual entities.</figref><figref num="4">In particular, an embodiment of a vendor-specific information element (IE) that is directed to support solicited access according to the present invention is shown.</figref><figref num="4A">It is a graphic representation of one embodiment of IE in the context of exemplary EasyConnect implementation.</figref><figref num="4B">It is a graphic representation of an embodiment of the subIE format useful in the present invention.</figref><figref num="4C">It is a table which shows one Embodiment of the subIE element peculiar to realization.</figref><figref num="4D">It is a graphic representation of an embodiment of general WPS IE.</figref><figref num="5">In addition to the network that supports solicitation access, an embodiment of a vendor-specific message that is made to direct a request is shown, among other things.</figref><figref num="6">The present invention presents an embodiment of a portion of a vendor-specific message designed to improve "human" usefulness, including human readable text fields, service discovery protocol information and in-band configuration data.</figref><figref num="7">INDUSTRIAL APPLICABILITY According to the present invention, an embodiment of an application-specific text record for giving service discovery information to a member of a local area network is shown.</figref><figref num="7A">It is a graphic representation of an embodiment of a Bonjour-specific TXT record useful in the present invention.</figref><figref num="8">An embodiment of an enrollment process performed by a wireless media cableable accessory according to the present invention is shown.</figref><figref num="9">The present invention presents an exemplary embodiment of a registrar / authorizer / access point process performed by an exemplary wireless network mounted storage device.</figref><figref num="10">An embodiment of the access point function of the process of FIG. 9 is shown in detail.</figref><figref num="11">An embodiment of the registrar and authorizer point functions of the process of FIG. 9 is shown in detail.</figref><figref num="12">An embodiment of the registrar function of the process of FIG. 9 is shown in detail.</figref><figref num="13">An embodiment of starting Wi-Fi protection settings (WPS) for the process of FIG. 9 is shown in detail.</figref><figref num="14">It is a functional block diagram which shows one Embodiment of the wireless device which was made to embody the method of this invention.</figref>
Refer to the attached drawings in which the same parts are indicated by the same numbers throughout.
<u style="single">Outline</u> In one salient aspect, the invention provides a method and device for a device to freely solicit access from an existing wireless network. Existing wireless networks have complex protocols for determining and permitting such access, which is suitable for relatively high user error rates. In one embodiment, a wireless network is disclosed that reduces the number of steps required for all parties involved in such an access request, as well as the number of parties required. More specifically, a method and device for use in an enrolling device for soliciting access to a wireless network and a network device for responsively adding an enrolling device are disclosed.
In one exemplary embodiment, methods and devices are disclosed that enable discovery and operation of solitated activation (SAW) of Wi-Fi protection settings, which is EasyConnect in one variant throughout. Also called. The wireless device (enrolli) performs a combination of active and passive wireless scans. Enrolli actively scans or detects all channels not banned by dynamic frequency selection (DFS), and passively scans DFS banned channels. Enrolli checks each of the detected networks for EasyConnect support. Information elements describing EasyConnect support are also disclosed here for use in this process. For each EasyConnect support network found, Enrolli establishes a WPS connection. Enrolli initiates the WPS abbreviation procedure for the connection.
The process of requesting user input (such as authorization) is conveniently performed from any device on the network, including a "thin" client, by reducing all steps required for network management. Can be done. In one variant of the invention, enrollment in a wireless device can be completed completely automatically with the appropriate permission.
It also allows a variety of "interface-less" clients for network operation by minimizing user interface requirements for soliciting devices and / or using other devices as interface "proxy". Will be done. In some cases, such an interfaceless client is completely free of user interfaces and therefore can quickly and easily associate simple and low cost devices. This flexibility of networkable devices allows for a number of new and useful network structures and / or client device types that were not previously possible.
Also, the present invention can literally be conveniently used in functional situations, i.e., such that the "enrolly" described above functions as a proxy or peripheral device for a client device, access point, another device. Can be done.
<u style="single">Detailed description of exemplary embodiments</u> An exemplary embodiment of the present invention will be described in detail below. These embodiments will be described primarily in the context of wireless local area networks (WLANs) that comply with Wi-Fi standards, but those skilled in the art will appreciate that the invention is not limited thereto. In fact, various aspects of the invention are useful in wireless networks that benefit from the solicitation activation of protected wireless access disclosed herein. Therefore, the term "wireless" as used herein is not limited to, but is limited to Bluetooth, 3G (eg, 3GPP, 3GPP2 and UMTS), HSDPA / HSUPA, TDMA, CDMA (eg, IS-95A, WCDMA, etc.). ), FHSS, DSSS, GSM®, PAN / 802.11, Wi-Fi (IEEE standard 802.11x including 802.11n and 802.11 VHT), WiMAX® (802.16), MWBA / 802.11, narrowband / FDMA, 802.11, PCS / DCS, Analog Cellular, CDPD, Satellite Systems, Millimeter or Microwave Systems, Acoustic, and Infrared (ie IrDA), IMT Advanced, IMT2000, and 3GPP LTE (Long-Term Evolution) / LTE Advances Means a wireless signal, data, communication, or other interface, including type.
Also, although the situation of a single wireless network (eg, WiMAX, LTE, WLAN, etc.) will be mainly described, the methods and devices of the present invention have two or more of different properties (eg, different air interfaces, etc.). It is also clear that it can be applied to WiMAX networks to improve overall connectivity.
FIG. 1 shows an exemplary WLAN (eg, Wi-Fi) system 100. The Wi-Fi system 100 includes one or more wireless clients 104 and network 102 of access points (APs) 106. In other Wi-Fi configurations, network 102 consists only of wireless clients 104 participating in ad hoc peer-to-peer (P2P) networks (no access points). The terms "client," "client device," and "access point" used herein refer to Wi-Fi cableable devices, phones (eg, iPhone®), personal computers (PCs), and, for example, wireless enabled iMacs. (Registered Trademark), Mac Pro (Registered Trademark), Mac Mini®, or MacBook®, desktops, laptops, or other minicomputers, as well as mobile devices such as handheld computers, PDAs, camcorders, set-top boxes, personal media devices. (PMD), eg, iPod®, or a combination thereof, but not limited to.
As illustrated, the first wireless client 104A is a designated "authorizer" of network 102 that serves to authorize additions to network 102. Also shown is a wireless access point 1068 that acts as a "registrar". The registrar of this embodiment maintains membership in network 102. Authorizers and registrars are shown as separate elements, but may be the same network element (eg, a single entity performs both authorization and registration actions), and such capabilities are client 104 or access. It will be clear that it is not limited to point 106. For example, a proxy device (not shown) may act as an authorizer and registrar for other devices.
FIG. 1 also shows a first wireless client 104E that is not currently enrolled in network 102 (ie, not registered with the registrar). The "enrolli" requests access to join the wireless network 102.
With reference to the Wi-Fi system 100 in Figure 1, the existing WPS standard describes various interchangeable variants and scenarios for adding the Enrolli 104E to the WPS wireless network 102. The WPS standard has four authorization methods: (i) PIN access, (ii) Pushbutton control (PBC) access, (iii) Near field communication (NFC) access, or (iv) Universal serial bus (USB) access. To identify. These methods will be described in detail below.
<u style="single">Wi-Fi protection settings (WPS) permission method</u> In each of the following access methods specified in WPS, one or more user actions must be performed by both the enroller and the authorizer, among other things, to prevent accidental additions and malicious network activity. (i) The WPS PIN (Personal Identification Number) access method uses a PIN to verify the enrollment. A PIN (read from, for example, a sticker, display, etc.) is entered into a representative portion of the network, such as the network's wireless access point 106 or registrar. (ii) The PBC (push button control) access method is for the user (s) to press a button (real or virtual) on both the typical part (wireless access point or registrar of the network) and the enrollment device. Needs. Support for PBC access is mandatory for wireless access points (APs) and optional for wireless client devices. (iii) The NFC (Near Field Communication) access method uses RFID (Radio Frequency Identification) passive radio equipment to verify the Enrolly equipment. Enrolles are transported within the RFID cable representative portion to allow RFID signaling. NFC forum compliant RFID tags are used. NFC is considered an "out-of-band" permission method. This is because RFID devices (rather than Wi-Fi type devices) carry out permits through different high frequencies. NFC access is arbitrarily embodied within the WPS standard. "EPC Radio Frequency Identity Protocols Class 1 Generation-2 UHF RFID Protocol for Communications at 860MHz-960MHz Version 1.0.9" (generally called "EPC Gen2") dated January 2005, which is used as it is for reference. See also. (iv) The USB (Universal Serial Bus) access method allows enrollment based on the insertion of a USB stick or "dongle". Like NFC, USB is considered an out-of-band permission procedure. Support for USB access is also optional under the WPS standard.
<u style="single">Wi-Fi Protection Settings (WPS) Allowed Scenario</u> The WPS standard also identifies at least three basic scenarios for adding WPS users: 1) Wireless Access Point Registrar 106<sub>R</sub>Is an enrolled client device 104<sub>E</sub>And 2) registrar client device 104<sub>R</sub>Enrolli Wireless Access Point 106<sub>E</sub>And 3) registrar client device 104<sub>R</sub>Enrolled client device 104 via intermediate wireless access point 106<sub>E</sub>To add. More specifically, 1) In the first usage scenario specified for WPS, a wireless access point with internal registrar capability adds an Enrolli wireless client device. In this scenario, the session contains a set of extensible authentication protocol (EAP) request and response messages. The session ends with the registrar access point dissociating from the enrollment device. Enrolli reconnects to the network with a secure configuration. 2) In the second usage scenario, the registrar wireless client device configures the wireless access point as an enroller. The configuration state of the wireless access point is set by the registrar (client device). The registrar may or may not configure a wireless access point (enrolly). 3) In the third usage scenario, the registrar wireless client device configures the enrolly wireless client device as a wireless access point. The wireless access point acts as any authenticator and / or mediator between the two wireless devices.
<u style="single">Method</u> The following description enhances the various authorization methods and scenarios described above with solicitation activation capabilities and improves the user experience.
An embodiment of a general solicitation activation method or procedure 200 for adding a device to an existing protected wireless network according to the present invention will be described with reference to FIG. The situation in which the client device 104 solicits access to the AP 106 will be described, but the method of the present invention is not limited thereto.
The main operating elements described for the method of FIG. 2 are one or more existing wireless networks and wireless devices that seek access to those one or more existing wireless networks without being networked. Wireless networks have at least two functional elements: authorizers and registrars. In some embodiments, the authorizer and registrar are the same device. In another embodiment, the authorizer and registrar are two (or more) separate devices. A device that seeks network access without being networked is called an enrolly. In certain embodiments, the enrolli still needs to be successfully authenticated to the network. Thus, in certain embodiments, the network further comprises an authenticator. It will be readily apparent that the function of the authenticator may be performed by an authorizer or registrar.
In step 202 of method 200, device 104 scans one or more wireless networks. The scan may be active, passive, or a combination thereof. The device 104 may scan only a subset of all resources, or may perform a full scan of all resources. Moreover, in multimode clients, scanning extends to resources associated with multiple different networks (eg, Wi-Fi, WiMAX, etc.). The scan may be automatic, periodic, or triggered. For example, in one embodiment, the scan is automatically started at power-up or reset. In another embodiment, the scan periodically refreshes the available network on a reasonably frequent base (eg, hourly, daily, etc.). In yet another embodiment, the scan is a loss of reception (eg, caused by one device moving to another, etc.) or user interface interaction (eg, pressing a button, selecting a function, etc.). Etc.) may be triggered by one or more events.
In an exemplary Wi-Fi embodiment, the scanning procedure is separated into two parts. In this embodiment, the scanning procedure is performed during device power-up (during initialization) and includes a passive scan of the first channel subset and an active scan of the second channel subset.
More specifically, during the first part, device 104 passively scans the first frequency range subset corresponding to the Dynamic Frequency Scan (DFS) "prohibited" channel. DFS is a channel allocation scheme used for IEEE 802.11 Wi-Fi networks. DFS allows a large number of adjacent wireless networks to coexist without central control. DFS enforces bandwidth constraints for each wireless network. Therefore, scanning the first frequency range subset is blind or semi-blind detection of "beacons" for DFS networks. Wi-Fi beacons are special data transmissions from wireless access points (APs) 106. The beacon signal includes the AP's service set identifier (SSID), its active channel number (s), and one or more information elements (IE) that specify the active security protocol. The transmit beacon can be received by the client device 104 (ie, unencrypted).
During the second part of the two parts described above, device 104 transmits the probe signal in the second frequency range subset corresponding to the DFS "allowed" (ie, not prohibited) channel. A nearby Wi-Fi AP106 or other enabled device responds by sending a probe response or associated request / response message. Both responses carry a service set identifier (SSID) and one or more information elements (IE) that specify an active security protocol. In certain embodiments, it is clear that both the first and second parts of the scan may be performed simultaneously or sequentially in any order.
It is clear that active / passive scans can be performed in a variety of patterns. For example, in one variant, the scans are staggered in time and are virtually non-overlapping. In another variant, the scans are staggered in time, but superimposed to some extent. In yet another variant, the scan is temporal and / or other parameters (eg, when it is a priori known or expected that the passive scan produces better results than the active scan, for example. Frequency bandwidth) is asymmetric (or vice versa). Scans may be interleaved or multiplexed if high frequency interference is not an issue (ie, active scans on one channel do not unduly interfere with passive scans on another channel). It may be done at the same time.
Also, if a beacon or other signal is received during the "passive" scan of the banned channel, the probe signal can be transmitted to the banned channel (ie, the previously banned channel is for transmission. Also note that it is no longer banned).
In step 204, device 104 identifies one or more wireless networks 102 that support solicitation activation. The determination is made, for example, based on an embedded information element or based on information locally stored in the wireless device 104. For example, the device maintains an internal database that identifies solicitation activation capabilities based on received identifiers (eg, SSIDs). Yet another solution will be readily apparent to those skilled in the art.
In one exemplary Wi-Fi embodiment, the solicitation activation support decision is at least partially performed by decoding the IE received in step 202. In this exemplary embodiment, the AP106 has three bits that identify i) Wi-Fi protection settings (WPS) support, ii) WPS solicitation activation (SAW) support, and iii) current WPS mode. Broadcast a signal containing (ie, AP accepts EasyConnect request). The realization-specific IE and its component bits are described in detail below.
In another exemplary embodiment (based on EasyConnect described below in one embodiment), solicitation activation support decisions are at least partially executed by decoding a single IE received in step 202. To. In this embodiment, the AP 106 broadcasts a signal that includes the "AP Capable" flag. The realization-specific IE and its component bits are described in detail below.
In step 206, the device seeking access (eg, Wi-Fi "enrolli") requests access to one or more identified wireless networks that support solicitation activation. The request embodies one or more security features. The request may include additional configuration information as requested or required. Such additional configuration information includes one of a number of supplementary information. Typical examples of configurations are specific sets of security modes supported by Enrolli, human-recognizable identifiers, software application-specific identifiers (eg, Bonjour® device types, Bonjour TXT records, etc .; by the transferee. Includes in-band configuration data (eg, printer toner settings, audio settings, etc.), as described below for an exemplary Bonjour protocol developed.
In one embodiment, when multiple conformable networks are in the vicinity, the enroller sends multiple simultaneous probe requests in parallel to save time. In another embodiment, steps 204 and 206 combine discovery and access requests, for example, when Enrolli performs its initial scan with the participation request flag already set.
In step 208, the device seeking access is authorized by an existing device on the wireless network. Existing devices (eg, authorizers) are, of course, different from enrollies, but authorizers in exemplary Wi-Fi situations may be combined with other devices, such as registrars, authenticators, and the like. Alternatively, the authorizer may be a separate device connected to a protected wireless network.
In certain embodiments, the configuration information identified in step 206 is used by the authorizer, if any, or is displayed to a human user via the authorizer (eg, on the configuration display via the GUI). To). In other embodiments, the authorizer also responds with its own configuration data, which may or may not be of type symmetrical to that sent by the requester. For example, such additional configuration information includes selection of a set of security modes to be used, human-recognizable identifiers, software application-specific identifiers (eg, media access control (MAC) addresses), and in-band. Contains configuration data (eg, printer settings, audio settings, etc.).
At step 208A, the enrolle is optionally authenticated by the authenticator device on the wireless network. Authenticators are, of course, different from enrollies, but authenticators may be combined with either an authorizer or a registrar device, or contain individual entities together and / or via a proxy device or process. It may work. In certain embodiments, the configuration information identified in step 206 is used to authenticate the enrolle, and the authenticator further responds with the credentials (eg, to support two-way authentication). ). Common examples of authentication processes and security solutions used consistently with the present invention are public / private key pair exchange, MD5 (Message Digest Algorithm 5), SHA (Secure Hashing Algorithm), AES (Advanced Encryption Standard), Stream ciphers, etc. are included. Wi-Fi-specific authentication realizations include, for example, WEP, WPA and WPA2. In one exemplary embodiment, the authenticator is the same entity as the authorizer and uses HTTPS (Hypertext Transfer Protocol Secure). Standard SSL (Secure Socket Layer) / TLS (Transport Layer Security) is used for encryption, and HTTP Digest authentication is used for authentication.
At step 210, the enrolle is added to one or more identified wireless networks. During this step, Enrolli further configures one or more internal device settings based on the configuration information extracted from steps 206 and / or 208.
In one exemplary Wi-Fi based embodiment, the authorization and authentication steps are separate. In one variant, if Wi-Fi enrollment is allowed, it proceeds to execute the WPS authentication sequence. Once authenticated, the wireless network updates the registrar. Also, the new membership is propagated to other network devices. The newly added member further configures its internal device settings 20 as appropriate (eg, update its namespace, set its MAC address, etc.).
FIG. 3 is a ladder diagram of one exemplary embodiment of the solicitation activation method 200 of FIG. The following examples mainly describe Wi-Fi enable devices and exemplary Bonjour protocols developed by the transferee, but these situations are merely exemplary, and the present invention relates to other WLANs and. It will be clear that it can be widely applied to wireless technology and / or other embodied protocols.
The main operating elements described for the method of FIG. 3 are one or more existing wireless networks 102 and unnetworked wireless devices (ie, Enrolli 104).<sub>E</sub>) And. The existing wireless network 102 can include one (degree) entity that acts as an access point, authorizer, and registrar device. For clarity, the wireless network 102 in the example of FIG. 3 has three separate entities, the first device (ie, the authorizer 104).<sub>A</sub>), Second device (ie, registrar 104)<sub>R</sub>), And as access point 106. A third device that is not networked (ie, Enrolli 104)<sub>E</sub>) Identifies the network 102 in its vicinity and requests access to it. Transactions with wireless network 102 are "protected" using one or more cryptographic protocols (eg, WPS). In one exemplary embodiment, registrar 104<sub>R</sub>Is the access point 106 of the device giving access. Authorizer 104<sub>A</sub>Is an external entity that communicates with the registrar to allow Enrolli to join the network. For example, the printer attempts to join the wireless network provided by the access point (eg, "My Network").<sub>E</sub>Is. Computers that have already joined the wireless network act as authorizers to "tell" the access point that printers should be allowed to join the network.
At the first time 302, Enrolli 104<sub>E</sub>Scans one or more wireless networks and identifies nearby wireless networks 102 served by AP106. Enrolli 104<sub>E</sub>Requests access to wireless network 102. As shown in FIG. 3, the initial detection of a nearby wireless network is accomplished in this embodiment by passively scanning the network and actively transmitting probes. AP106 responds to the probe, which carries one or more parameters that identify support for solicited access to the network. Based on this parameter, Enrolli 104<sub>E</sub>Determines the connection to the network. Enrolli 104<sub>E</sub>Sends a request to AP106 to connect to network 102.
More specifically, in the scan against a WPS-based system, Enrolli 104<sub>E</sub>Passively scans DFS prohibited channels for beacons. When this passive scan is complete, Enrolli 104<sub>E</sub>Performs an active scan on all channels not prohibited by dynamic frequency selection (DFS) (eg, sending probe requests).
Illustrative Enrolli 104<sub>E</sub>Determines all EasyConnect available networks by reading one or more information elements (IE). Information elements (IE) are specified within the IEEE 802.11 wireless LAN protocol. IE gives descriptive information and is embedded within the management frame of the type / length / value (TLV) definition. The IEEE 802.11 standard also provides vendor-specific TLV definitions.
In an exemplary Wi-Fi embodiment, the EasyConnect Capable Network is a general or vendor-specific EasyConnect Capable within IE that is broadcast for passive reception or actively transmitted in response to a probe. Set the bit. FIG. 4 shows an embodiment of a vendor-specific IE400 useful in the present invention. The vendor-specific IEs shown include a set of unsigned integers representing element identification, TLV length, organizationally unique identifier (OUI), type, product identification reservation bit, and flag bit, but others. It is clear that the information and sequences of can be used with equal success.
Networks that support WPS identify such support by setting two flag bits: WPS Capable (0x20) and EasyConnect Capable (0x80). In addition, a third flag bit, WPS active (0x40), is also conceivable during the solicitation activation process. In some embodiments, the presence of WPS capabilities is assumed (eg, only the EasyConnect bit is used). All other networks are Enrolli 104<sub>E</sub>Ignored by. Further, the TLV described above is a vendor-specific embodiment of general IE, but in another embodiment such bits are generally standardized and enrolled devices 104.<sub>E</sub>It is clear that it is understood by. Moreover, in certain embodiments, information related to EasyConnect and WPS is disseminated through multiple TLV exchanges. Alternatively, solicitation activation support and other methods for identifying activities may be used within other network technologies. For example, in another system, such parameters are broadcast via control channels such as those used for UMTS femtocells or cellular networks.
In one embodiment of the invention, the SAW Capable Network sets the "APCapable" flag in EasyConnect-specific IE. Figure 4A shows an exemplary EasyConnect-specific IE. This EasyConnect-specific IE contains a set of unsigned integers representing (i) element identification, (ii) length, (iii) organization-specific identifier, (iv) type, and (v) one or more subIEs.
FIG. 4B shows an embodiment of the subIE format. Each subIE contains the element ID, length and payload.
Figure 4C is a table of subIE elements specific to realization. In addition to EasyConnectIE, general WPS IE (shown in Figure 4D) is also required for EasyConnect operations to specify the configuration methods supported by Enrolly. In other embodiments, general WPS IE is not required, as EasyConnect operations mean WPS support.
Enrolli 104<sub>E</sub>When you select an available SAW network, Enrolli 104<sub>E</sub>Requests access to the selected SAW network. In general Wi-Fi realization, Enrolli 104<sub>E</sub>Sends a special IEEE 802.11 action frame or probe request that directs an EasyConnect request. FIG. 5 shows an embodiment of a vendor-specific action frame or probe request 500 according to the present invention. The action frame or probe request 500 of this embodiment includes a general IEEE 802.11 header, a SAW specific header, and a SAW specific body, but it will be clear that other information can be used with equal success.
The exemplary SAW-specific header in Figure 5 includes categories, organizationally unique identifiers (OUIs), types, subtypes, and versions. In some other embodiments, the version field is not required. SAW-specific headers are used internally by the registrar (ie, the intended recipient) 1048 to aid in the organization and efficiency of the software.
In one embodiment, the exemplary SAW-specific body comprises a vendor-specific TLV. For example, vendor data is formatted as a WPS-style TLV, that is, WPS vendor-specific TLVs are partitioned into sub-TLVs. See FIG. 6, which shows an embodiment of the vendor-specific TLV600. The vendor-specific TLV600 contains text-readable names, Bonjour subtypes, Bonjour TXT records, and configuration data. These sub-TLVs are described in detail below.
Enrolli 104<sub>E</sub>The text name (ie, human readable) is AP106, registrar 104<sub>R</sub>Or Authorizer 104<sub>A</sub>Enrolled to the user via GUI or other mechanism 104<sub>E</sub>Allows you to view the name of. In the current WPS standard, existing descriptor fields (eg Device Names) are too short (32 bytes) to accept useful human-readable names. Therefore, in an exemplary vendor-specific TLV, a text-readable name field is provided for display, for example, in the user interface. In another embodiment, UTF-8 friendly names with no fixed length limit (or at least moderate limits such as 255 bytes) are systematized as general WPS attributes (ie, additional text reading). Possible fields are not required). In one exemplary embodiment, the authorizer and AP / registrar use the UTF-8 name from EasyConnect IE. The AP / registrar uses the UTF-8 name from EasyConnect IE to publish Bonjour. Similarly, the authorizer requests Bonjour text information from the UI display to authorize the user.
Configuration data is Enrolli 104<sub>E</sub>Enrolli 104 to use when is accepted by the network<sub>E</sub>Gives unique configuration data. The in-band configuration of the device is described in detail below (see "In-band configuration" below).
Configuration mode is Enrolli 104<sub>E</sub>Identify the modes that is supported by. This is Enrolli 104<sub>E</sub>Supports PIN mode or push button mode Typical parts (eg AP106 or registrar 104)<sub>R</sub>). AP106 publishes this information, and registrar 104<sub>R</sub>Use it, Enrolli 104<sub>E</sub>Customize the user interface to get you into the network.
<u style="single">Bonjour service discovery</u> In one embodiment, a TLV is provided that has a significant effect on existing service discovery programs (eg, the Bonjour protocol developed by the Transferee). More generally, other service discovery protocols exist and are clearly interchangeable. However, Bonjour is already in use, especially for the Mac OS X operating system (version 10.2 and later), Microsoft. Can be used with the Windows® operating system (when installed). The exemplary Bonjour protocol is intended to be used, among other things, for local area networks (LANs) to explore devices such as printers, other computers and file sharing servers, and the services they provide. Also, among other uses, content services for finding shared music (eg iTunes®), iPhoto for finding shared photos, iChat for finding other users on your local network. Also used by TiVo Desktop to find digital video recorders and shared media libraries. Therefore, Bonjour is one particularly useful protocol for discovering services in local area networks. Bonjour subtype is Enrolli 104<sub>E</sub>Identify one or more device subtypes to use when registering with the local area network. Bonjour subtypes are described in detail below.
The BonjourTXT record identifies the BonjourTXT record entry that should be added to the text record when registering the enrolly on the LAN. For example, the printer wants to identify some features required for the configuration.
In one embodiment, the solicitation activation request is made by sending a probe request containing EasyConnect IE with the "Join Wanted" flag set in the "flag" subIE. Enrolli contains information about itself in EasyConnect IE (eg, name, model, Bonjour TXT record, etc.).
Members can search for available Bonjour entries, for example by subtype. Bonjour subtypes are used to further identify the type of device. Bonjour allows multiple subtypes to be used at the same time attributed. For example, a given type of device (eg, the type of AirPort Express® device manufactured by the Transferee) may be simultaneously referred to as a "subtype" such as an AP, remote speaker and remote printer. .. As a result, this device can itself be listed as a combination of device attributes (eg, _EasyConnect, _tcp, _ap, _printer, speaker).
Returning to the solicitation activation process of FIG. 3, upon completion of step 302, Enrolli sends the action frame 500 or probe request to one or more SAW compliant networks.
At the second time 304, AP106, registrar 104<sub>R</sub>And authorizer 104<sub>A</sub>Forward the request to. Authorizer 104<sub>A</sub>Performs access control based on one or more inputs from the user (received via a user interface such as a keypad, touch screen, mouse, etc.) and Enrolli 104, for example.<sub>E</sub>Accept or reject. Authorizer response registrar 104<sub>R</sub>Will be returned to.
More specifically, in a Wi-Fi embodiment, AP106 receives an action frame or probe request and Enrolli 104<sub>E</sub>If you want to accept it, publish the Bonjour service to that LAN and ask the members of the LAN Enrolli 104<sub>E</sub>Notify. Bonjour conveniently provides high-level applications that do not require additional IEEE 802.11 support for members already on the network. The authorizer browses the Bonjour proxy service published by the AP.
In the embodiment illustrated herein, by publishing the device, the Enrolli 104<sub>E</sub>Present a text-readable name (for example, "living room") for display in the authorizer's GUI. Also, by publishing the device, Enrolli 104 can be added to the wireless network.<sub>E</sub>Registrar 104 to forgive<sub>R</sub>Identify the available port numbers in the service record (eg SRV) (eg Airport Configuration Protocol (ACP) port 5009). In addition, a text record key is defined as additional information about the enrolly. FIG. 7 shows an embodiment of the vendor-specific text record 700 according to the present invention.
In one embodiment, the exemplary text record 700 is the registrar's identification, one or more flags indicating the state of the enrolly, the enrolly 104.<sub>E</sub>Includes unique directives (eg MAC addresses) and / or crypto seeds. In one variant, a nonce is further given as a unique number to aid in detecting changes (ie, as the nonce changes, the network state changes and requires an update). One variant uses the MAC address to uniquely identify the enrolly.
The vendor-specific text record 700 is described within the framework of the present invention, but it will be clear that another method of allowing the network to enroll can be defined as well. For example, the protocol available for the AP can be identified in another text record via the Bonjour® TXT record, including at least one configuration protocol such as HTTP.
Figure 7A shows one embodiment of the Bonjour-specific TXT record. In one embodiment, the Bonjour TXT record key directs additional state information about the enrolly derived from one or more elements of EasyConnect IE. The Bonjour implementation of the TXT record gives the authorizer flag, authorizer UUID, configuration method, error code, enroller MAC address, enroller device model, and change nonce.
In one embodiment, the AP publishes a Bonjour TXT record to its LAN to represent an enrollment. Publish TXT records to allow AP members to discover Enrolli.
Ideally, Enrolli 104<sub>E</sub>Is detected, the user is notified (Registror 104).<sub>R</sub>Or authorizer 104<sub>A</sub>By any of). In one exemplary notification process, notifications are not intended to grab or steal focus from what the user is currently doing, or are expected to annoy the user by popping up a window in a non-solicited form. not. For example, one non-intrusive notification indicator according to the invention is the "device" section of an existing window or sidebar (eg, iTunes sidebar or Mac OS X Finder® sidebar). Includes small icons and labels displayed on. User enrolling device 104<sub>E</sub>Select Enrolli 104, including any configuration information settings.<sub>E</sub>Is started to add to the network.
Ideally, measurements should be made to ensure that the enroller (rather than the unwanted enroller, such as an adjacent device) is actually desired by the authorizer. In an exemplary embodiment, the user probably expects a notification from Enrolli. However, in other situations, it is clear that unexpected notifications are still a problem for the user. For example, a user may "stumbl" across advertising services, etc.
In an exemplary embodiment, user input is selected from the WPS access methods described above. Authorizer 104<sub>A</sub>Presents a UI for entering a PIN (for example, whether it is printed on the Enrolli case, randomly generated and displayed on the Enrolli, selected by the user himself, etc.) is there). Authorizer 104 when user enters PIN<sub>A</sub>Communicates with the TCP server (of the AP) identified by the Bonjour service in the embodiments shown here. Then registrar 104<sub>R</sub>Allows enrollment for the network.
For example, in one such embodiment, the authorization device (eg, iPhone, Mac, Windows computer, or other device) has a dialog box for entering the Enrolli PIN, and an "Authorize" button or Present the interface. The user "permits" new additions by reading the Enrolli PIN from the device and pressing a button. In response, the authorization device communicates with the registrar and allows enrollment to the network. The authorizer initiates communication with the TCP server that previously advertised itself in the an_easyconnect._tcpBonjour service. The AP enters WPS mode. The authorized device updates the AP's Bonjour TXT record with a UUID (universally unique ID), PIN (optional), configuration data, and enrolly MAC address. The AP uses this information to allow enrollment to the network.
When the authorization process begins on the AP, the AP updates the Enrolli Bonjour proxy to set the "Authorized" flag (ie, "af") on the TXT record item to reflect the current authorization state. Other authorization devices that monitor the AP ignore the presence of new enrollies (ie, to prevent double authorization). The AP adds the authorizer's UUID to the Bonjour proxy's TXT record via the "au" (ie, authorizer ID) key. Therefore, other permitting devices are notified which permitting device has allowed a new enrollment. In one example, other authorization devices mirror the authorization process, but in other implementations, authorization devices prefer to ignore messages from new enrollies.
In addition, registrar 104<sub>R</sub>Which member is Enrolli 104<sub>E</sub>Authorizer 104<sub>A</sub>Has a configuration option to control. For example, registrar 104<sub>R</sub>Authorizes any member of that LAN 104<sub>A</sub>You may choose to allow as, or conversely, you may request the admin password and / or privilege. Registrar 104 in one variant<sub>R</sub>Never allows permission from a non-member device (ie, a device other than its LAN) without some form of authentication and cryptography (eg password protection, crypto VPN tunnel).
Finally, at the third time 306 in Figure 3, the registrar 104<sub>R</sub>Is Enrolli 104<sub>E</sub>To the network. Enrolli 104<sub>E</sub>The addition of is dependent on one or more supplementary actions. For example, in one embodiment, Enrolli 104<sub>E</sub>Is further required to perform multiple authentication responses. In another example, Enrolli 104<sub>E</sub>Is also required to set one or more parameters for device operation.
In the exemplary embodiment described above, when the access point 106 enters WPS mode, the access point 106 enrolls 104 that it has enabled WPS.<sub>E</sub>Set the vendor-specific IE WPS active bit to instruct. In addition, Enrolli 104<sub>E</sub>MAC address in IE, therefore Enrolli 104<sub>E</sub>Clearly identify. This activates WPS or a different Enrolli 104<sub>E</sub>Enroll other access points that are active about 104<sub>E</sub>Allows to ignore.
Enrolli 104 that AP106 activated WPS<sub>E</sub>When you see and advertise the MAC address of Enrolli, Enrolli 104<sub>E</sub>Attempts to join the network via WPS. If successful, AP106 turns off WPS, returns to normal operation, and Enrolli 104<sub>E</sub>Update the Bonjour TXT record to indicate that has joined successfully.
Enrolli 104<sub>E</sub>AP106 unregisters the Bonjour service after it successfully joins. In one embodiment, the Bonjour service is Enrolli 104.<sub>E</sub>Remains active for a short time (eg 1 minute) after being added. This is the registrar 104 (unlike the access point)<sub>R</sub>But Enrolli 104<sub>E</sub>Allows you to detect that you have successfully joined.
Upon failure to join, access point 106 updates the Bonjour TXT record (ie, the err TXT record) to include the error code and is used to prevent cryptographic elements such as nonce (eg, replay attacks). Cryptographic seed) is incremented and returned to the "unauthorized" state (ie, the default "af"). This registrar 104 failed to join<sub>R</sub>To be able to detect.
The following description describes additional matters relating to one or more aspects of the invention and examples thereof.
<u style="single">Security and access restrictions</u> There is no completely secure wireless access protocol. In fact, the security system is described in response to a brute force attack (eg, a repetitive attempt). This is because such metrics are easy to compare. Therefore, there are numerous schemes for implementing network security. They are well known throughout the technique, but generally increase the time interval between subsequent retries, limit the number of retries, and (PIN, authentication, key pair requirements). Including (but not limited to) limiting network membership (via, etc.). All of these methods are readily applicable and, either alone or in combination, are readily apparent to be useful in the present invention described herein. The user must not be allowed unlimited access for repeated retries, but one scenario is deliberately configured to be overlooked over the other.
For example, in the exemplary embodiment described above for Figure 2-3, the Wi-Fi system is intended for use by non-technical customers, so the enrolli is not unreasonably many times (eg, about 5 times). Must be allowed to try again. One of the most common causes of failure is the user entering the wrong PIN. Therefore, the registrar chooses to prompt the user for the PIN again. The registrar needs to re-permit Enrolli to try another participation. Attempts must be taken to prevent the "brute force" attack. As a result, defensive measures can be taken if Enrolli repeatedly fails.
In one exemplary embodiment, Enrolli can simply "wait" and retry a failed connection several times. For example, if Enrolli fails to join the network (for example, if the user accidentally enters a PIN), Enrolli must wait at an exponentially increasing interval between retries. Such "delayed" type schemes grow beyond practical limits to the failure of repeated attempts and become frustrated by eye-catching access attempts. When a request is received from Enrolli, additional requests are dropped to increase the time cycle to 2 seconds, 4 seconds, 8 seconds, and so on.
In yet another exemplary embodiment, the enrolle can continuously retry a failed connection for a limited number of specified thresholds, eg, up to three times. Use a "lock" type scheme to quietly deny access attempts when a lock threshold is reached. Keep track of the number of failed connections with a simple counter so that the counter is incremented each time a connection attempt fails. In some embodiments, the counter resets when the connection is successful. Upon reaching the rock threshold, Enrolli is forced to seek outside assistance. For example, a network member (eg, an authorizer) is required to reset the connection failure counter.
In yet another exemplary embodiment, the registrar is limited to a set number of active enrollies at a time. For example, in one embodiment, there may be at most five active enrollies at any time. If there are 5 active recent enrollies, and another enrolly requests access, the new enrolly will be quietly dropped (ie, the authorizer will not be notified of the enrollment request). In this embodiment, the enrolle is considered "active" if the AP receives an EasyConnect action frame or probe request from the device within a specified time interval (eg, 3 minutes). Therefore, within this system, the enroller is required to periodically send EasyConnect action frames or probe requests to remain active.
In addition, other variants within the membership-based scheme are possible. For example, various gradations or categorizations are useful. In one scenario, the enrolle is considered "recent" if the first EasyConnect action frame or probe request received by the AP from the enrolly is within the last n minutes (eg, 3 minutes). If there are 5 active enrollies, but only 4 recent enrollies, the AP can drop "quiet" enrollies to make room for new enrollies.
In addition, there are clients that have a certain priority and are never "kicked". For example, the user determines that a particular client is always allowed, even when used infrequently. Such designations are useful for entities such as network-based storage devices or media servers.
<u style="single">In-band configuration</u> An important factor in embodying the present invention is an improvement in the user's experience (including the ease and speed with which the desired device connection can be established). One notable problem with existing methods of wireless discovery and management is the lack of user input in the network setup process. More specifically, solicitation activation allows user-interface-less clients to be added to wireless networks.
Therefore, the in-band configuration provided by the present invention allows the user to form some minimal configuration as part of the WPS negotiation process. For example, this allows the registrar to let the user choose the name of the device and give it an administration password and other utility options. The device configuration is generally handled via existing device-specific software, and therefore the device configuration according to the invention is not intended to be a complete configuration protocol. Rather, it enhances existing device configuration methods and improves the overall user experience by reducing the number of user interfaces required for users to interact.
For example, when a customer first receives a device, the device generally has a factory setting, which in some cases is undesirable or inapplicable to its intended use. Factory-programmed device names are typically confusing, and device passwords are usually not perceptible or easily remembered by a given user. The methods of the present invention make network setup much easier, but the device itself is a poor name (eg, "device 001122"). Thus, in one variant of the invention, the EasyConnect method provides an in-band configuration menu or other user interface that can improve user input and experience. In-band configuration data is provided or generated by the authorizer, registrar and / or enrolly. The format of the configuration data is flexible for multiple uses, but remains within the constraints of EasyConnect. For one exemplary use, the access point delivers one or more user configurations to Enrolli as part of the "encryption settings" section of message M8 (see §7.3.9 in [1] for details). reference). In one exemplary embodiment, the in-band configuration parameters include the device name and password. In other exemplary embodiments, in-band configuration parameters are used to replace device-specific parameters (such as the text name of the printer's print queue).
<u style="single">Example of operation scenario</u> The following examples show one or more aspects of the invention disclosed herein.
In one scenario example, the customer powers on a wireless network device with audio speaker capability (eg, an Airport Express device manufactured by the Transferee). This device does not have a unique user interface. Rather, device authorization is performed by a customer with a concurrent solicitation activation Wi-Fi (SAW) registrar application running on a PDA or smartphone (eg, iPhone). The PDA or smartphone displays a list of SAW compliant neighbors (including wireless audio equipment). The customer allows wireless audio equipment to join the network via the PDA / smart phone user interface. The wireless audio device is connected to the network and is represented as a remote audio speaker within a host software application (eg, an iTune application running on a PDA or smartphone or nearby laptop computer).
In another example scenario, the user wants to add a printer that supports Wi-Fi to a wireless local area network (WLAN). When the printer is powered on, it searches nearby EasyConnect enabled wireless networks. The user runs the configuration utility on a networked personal computer or laptop computer. The PC or laptop displays the printer for authorization and configuration, even if the printer is not itself "networked". The user selects and configures it via a graphic user interface or menu structure (eg, give it a recognizable name and set printer-specific options such as toner level). After the configuration, the user says "Add Printer) is selected. The printer uses the EasyConnect procedure described here to automatically and securely exchange wireless certificates and in-band configuration information. The printer joins the wireless network and prints from a computer (PC or laptop, etc.) on the network, or at the behest of another device designated by the user as having such control. Ready.
The user in the above scenario does not have to perform all the steps normally associated with adding a wireless network device (eg, switching or reconfiguring a wireless network, giving a password, entering a network address, etc.) and therefore. The remarkable effect of the present invention is emphasized.
The operation of the present invention applied to the first operation scenario will be described in detail with reference to FIG. 8-14. More specifically, in this example, the user enrolls in a wireless network formed by an access point (eg, a Time Capsule® device manufactured by the Transferee) performing a registrar function (eg, AirPort). Express) is added. AirPort Express executes the first enrollment process 800 shown in FIG. Time Capsule runs the hot access point daemon process 900, shown in Figure 9, and the AirPort Configuration Protocol (ACP) daemon process (Figure 10-13).
Referring to FIG. 8, at step 802 the AirPort Express is removed from the box and at step 804 plugged into a wall outlet or other power source. At step 806, AirPort Express is powered on and initiates a series of active and passive scans for the SAW Capable AP. AirPort Express identifies all SAW Capable APs and, in step 808, filters out all non-SAW Capable APs. If AirPort Express cannot identify the SAW Capable AP, AirPort Express will continue to scan.
For each SAW Capable Network found by AirPort Express, in step 810, an EasyConnect action frame or probe request is sent to the access point. In response to the action frame or probe request, the identified nearby SAW Capable AP identifies itself with the WPS active flag and the MAC address corresponding to AirPort Express. This process is described in the Time Capsule description below.
At step 812, AirPort Express waits for a response. AirPort Express initiates active and passive scans on WPS active APs enabled for that MAC address. In step 184, if the WPS active network is not found by AirPort Express, AirPort Express must assume that it is unacceptable. Therefore, restart the discovery process (ie, rescan all SAW available networks). If a WPS active network is found, AirPort Express will join the network.
The Time Capsule device in this example includes two separate entities: hostapd (host access point daemon) and ACPD (AirPort configuration protocol daemon).
Figure 9 shows the Time Capsule hostapd process 900. The hostapd process constantly monitors EasyConnect action frames or probe requests (902). When an EasyConnect action frame or probe request is received, hostapd sends a saw.register remote procedure call (RPC) to ACPd with enrollment details.
Figure 10 shows the Time Capsule ACPd process 1000. When this ACPd process receives a saw.register RPC, the Time Capsule will have a new enrollment (ie, AirPort). Decide whether to allow Express) to the network. First, in step 1002, the ACPd determines if it already has the maximum number of enrollies. ACPd attempts to cut out the old enrolly in step 1004 if it has extra enrolly. If ACPd determines in step 1006 that the maximum number of enrolles has been reached, the register request is ignored in step 1008. Otherwise, ACPd adds a new enrolly to the list in step 1010, and publishes the enrolly to the Bonjour service discovery list on the LAN in step 1012. In certain embodiments, the rejection of Enrolli is either logged internally or dictated externally. In embodiments where enrollment rejection is likely to occur, logs or instructions are suppressed. In one variant, no logs or instructions are given, and log space is reserved for more important messages.
Time Capsule ACPd waits for a response from an authorized LAN member after initiating a Bonjour listing. Time Capsule ACPd monitors valid saw.authorize requests from existing LAN members (eg, authorizers). If enrollment is allowed, the method shown in Figure 11 is called. FIG. 11 shows one embodiment in which the WPS process 1020 is started. In step 1022, the AirPort Express saw.authorize request is received from the authorized LAN member. The Time Capsule saves the enrolly, PIN (or other access method identification) and permissions to its registry at steps 1024 and 1026, respectively. After updating its internal registry, Time Capsule initiates the WPS procedure in Enrolly with the specified PIN in step 1028.
In Figure 12, the Time Capsule waits for new members to join the network (1040). At step 1042, the Time Capsule receives the WPS participation request RPC. When Time Capsule receives the participation request RPC from Enrolli, it checks in step 1044 that Enrolli is properly authorized in its internal registry. For allowed enrollies, Time Capsule returns in step 1046 that the enrolles were allowed, and the corresponding PIN (step 1048) is read from the internal registry (ie, from the saw.authorize request for this enrolly). PIN is searched). If Enrolli is neither listed nor allowed, Time Capsule rejects Enrolli.
Finally, Figure 13 shows an exemplary WPS negotiation process 1060. Upon successful WPS negotiation (step 1062), Time Capsule deregisters Enrolli from SAW after a specified amount of time, eg, 1 minute (step 1068). If WPS negotiation fails, WPS is aborted (step 1064), and Enrolli is republished via Bonjour with an error code (step 1066). In one embodiment, the nonce element is modified to prevent a "regeneration" attack (ie, a network attack in which valid data transmission is maliciously or fraudulently repeated).
<u style="single">Fully automated enrollment</u> In another embodiment of the invention, enrollment in a wireless device can be completed completely automatically with the appropriate permission. For example, an enrolly or client device may be programmed from a manufacturer or distributor (or from a manufacturer or distributor) to include user-specific information by programming through a type of RFID or near field communication (NFC) device programmer or interlogator well known in RF technology. Traditional Mobil for use in gas stations that can be configured (via other means) Similar to programming portable RFID devices such as Speedpass). Programmed user-specific data (eg, username, PIN, device name, etc.) is available at the time of purchase (eg, via an online web device, then a POS device). You can enter it (and so on, etc.), or you can withdraw it from an existing credit card, smart card, or other device. This information is stored in the non-volatile storage device of the Enrolly device and accessed at the time of enrollment. (Eg, when the user puts the device in the network). For example, when plugging in or turning on, the programmed enrolly device is an exemplary protocol 200 (eg, active) in Figure 2 above. / Passive scan) is initiated, and the negotiation process is initiated based on the detection of AP106 or other network device, however, unlike the method described above, pre-obtained programmed into the AP and / or Enrolly device. "Allow" automatically puts an RFID device on the network that displays the appropriate certificate (eg username = X, PIN = Y, and supported security protocols = Z, etc.) without user intervention. Be able to associate. This solution conveniently gives a completely seamless user experience.
<u style="single">apparatus</u> An embodiment of an exemplary device (eg, client 104) useful for embodying the methods of the invention will be described with reference to FIG. This exemplary wireless device comprises a wireless modem subsystem 1402, a processing subsystem 1404, a memory subsystem 1406, and a power subsystem 1408, which are mounted on one or more boards 1410.
The wireless modem subsystem 1402 includes a radio unit 1402A and a modem 1402B. The wireless modem subsystem 1402 provides data transmission and reception capabilities for the wireless device 104. Although the above description refers to a wireless modem subsystem compliant with IEEE 802.11, it is readily apparent that other wireless and wired implementations can be used consistently with the present invention.
The processing subsystem 1404 of device 104 comprises a digital signal processor, a microprocessor, a field programmable gate array, or a plurality of processing components. The processing subsystem can run a software application that contains a set of computer-readable instructions. The processing subsystem is operably coupled to the memory subsystem 1406. This exemplary device uses software (ie, a series of human or machine recognizable steps to perform functions such as computer programs), but in other embodiments, the techniques described above are performed in firmware. It may be systematized directly by hardware (eg, logic gates, sequential memory, etc.).
The memory subsystem 1406 includes, for example, RAM, ROM, flash, and / or disk drive components. The memory subsystem 1406 embodies one or more direct memory access (DMA) type hardware to facilitate data access, as is well known in processor technology . The memory subsystem stores the computer-readable instructions described above. The memory subsystem also holds transitive data or instructions useful for intermediate processing operations of the processing subsystem 1404 (eg, software stack, etc.). The term "memory" as used herein includes any type of integrated circuit or other storage device for storing digital data, including ROM, PROM, EEPROM, DRAM, SDRAM, DDR / 2 SDRAM, EDO. Includes, but is not limited to, / FPMS, RLDRAM, SRAM, FLASH memory (eg NAND / NOR), and SPRAM.
The illustrated power management subsystem (PMS) 1408 powers the device and includes an integrated circuit (IC) and / or a plurality of individual electrical components. In the exemplary portable client device 104, the power management subsystem interfaces with the battery (which is supplemented by recharging capacity, solar cells, or other generator devices not shown). In another non-portable device (eg, fixed AP, etc.) or semi-portable device, the power management subsystem receives external power (eg, using a wall outlet, car adapter, etc.), and power conditioning capability (eg, using a wall outlet, car adapter, etc.). For example, surge protection, power failure or UPS function, etc.).
In one embodiment of the wireless device 104, the power management subsystem 1408 powers the processing subsystem 1404 and the memory subsystem 1406. The processing subsystem 1404 actively interfaces with the memory subsystem 1406 to perform multiple initialization processes (eg, booting, etc.). When the processing subsystem 1404 completes the internal initialization, it initializes a peripheral subsystem, for example, the wireless modem subsystem 1406. The wireless device then executes a software application that performs one or more steps of the solicitation activation procedure 200 (FIG. 2 et seq.) Described above.
As mentioned above, the solicitation activation procedure uses the involvement of three or more individual functional elements: enrolli, authorizer, and registrar. Optionally, an authenticator is additionally required. The following description outlines a portion of the procedure when performed within the wireless device of FIG.
In one exemplary embodiment, the wireless device executes a software application that performs an enrollment function. Therefore, Enrolli is one or more functions selected from scanning the SAW Capable Network 202, identifying the SAW Capable Network 204, requesting access 206, and client step 208A (eg, WPS) of any authentication procedure. To carry out.
Furthermore, it should be noted that the device of FIG. 14 can have many configurations. For example, conventional enrollment devices range from handheld PDAs, smartphones and computers to network equipment such as printers, copiers and media servers. Therefore, many enrollment devices also include a number of other application-specific subsystems such as user interfaces, a wider range of memory subsystems, specialized devices (eg, printer devices), audiovisual components, and so on.
The enrollment device is adapted to scan one or more wireless networks by active probes, passive scans, or a combination thereof. In one embodiment, the wireless modem 1402 actively transmits an access probe. Also, the wireless modem 1402 is configured to tune to one or more physical resources such as time, frequency, code or combination thereof. In yet another embodiment, the wireless modem 1402 actively sends the probe through a selected first subset of resources and passively scans the second subset of resources. Therefore, the wireless modem subsystem 1402 can selectively change its operation. For example, in a normal Wi-Fi transceiver, the first set of resources is designated as available for active probing, and the second set of resources is designated as prohibited for probing. Within Wi-Fi, one or more parameters of dynamic frequency selection (DFS) identify channels that are prohibited from active probing.
Another exemplary embodiment of the wireless device runs software to perform one or more authorizer functions (see, eg, step 208 in FIG. 2). During the execution of the authorization software application, the wireless device determines from user input whether enrolly should be authorizationd. Therefore, the wireless device is further provided with a user interface to facilitate this function. Such user interfaces include, but are not limited to, keypads, touch screens, LCD displays, backlights, speakers and / or microphones (with optional speech recognition capabilities). In one explanatory example, a smartphone (eg, an iPhone) displays a user dialog by its display unit and provides a touch screen input "button" for user response.
In another exemplary embodiment, the software application of the wireless device is adapted to perform one or more registrar functions. In one such embodiment, the registrar maintains a centralized database of devices currently registered and addressed within the protected wireless network. Such wireless devices also require one or more memory devices and interfaces for database operation. In addition, such wireless devices additionally include a secondary interface (wired or wireless) connected to a comprehensive external database. For example, large networks (eg, cellular, cables, etc.) usually embody local and remode databases.
The wireless device also includes one or more subsections specifically for authentication (step 208A in Figure 2). In one embodiment, such authentication is performed in software. Alternatively, in other implementations, a dedicated hardware authentication engine or other security device (eg, a security processor) may be used.
The above device architecture has been described with reference to the embodiments shown in FIG. 14, but in one embodiment various parts may be removed or otherwise combined with another component ( For example, a multi-mode or single-chip solution) will be readily apparent to those skilled in the art.
<u style="single">How to do business</u> In another aspect of the invention, an exemplary method of doing business in connection with said wireless network management capability is disclosed.
In one embodiment, the wireless network management capabilities enabled by the present invention can be put on the market and exert influence. For example, equipment manufacturers or service providers can distinguish their products or services from others based on ease of use, connectivity flexibility, and general robustness. Also, in some applications (such as home networks), a system for dynamically adding and subtracting network elements of different quality and characteristics as a basis for differentiation or to support higher product or service prices. The flexibility of is also available. By giving consumers the ability to control wireless LANs without necessarily having to understand the concepts of security and networking, customers are apparently willing to pay more for upfront costs or contract fees. It is clear that such a device is superior from the consumer or end user's point of view. This is because it is only necessary to turn on the power of the device, and management can be easily performed on the device pre-connected to the LAN. The system of the present invention is presented to the user in one simple and straightforward interface.
In one example, a home user can easily configure or reconfigure a home office (eg, speakers, printers, etc.) by adding more elements that he or she likes. In addition, the overall user experience will be qualitatively superior. This is because new technologies "work" transparently, rather than requiring extensive, potentially difficult restructuring and / or consultation with online or service call professionals. For example, a home user buys and plugs in a speaker. The user sees the notification that appears immediately on their laptop. When the user clicks on the notification, the music starts playing.
In another example, a home user is listening to music on his or her personal media device (eg, an iPod Touch). He walks into his house, where an inconspicuous icon appears on his device. When he taps the icon with his finger, he plays his music through a living room Wi-Fi enabled audio device (eg, AirPort Express) that is streamed from his media device.
Although some aspects of the invention have been described for a particular set of method steps, it is recognized that these descriptions merely illustrate a wide range of methods of the invention and can be modified as required by a particular application. Will be done. A step may be unnecessary or optional under certain circumstances. Furthermore, certain steps or functions may be added to the embodiments disclosed herein, or the execution order of two or more steps may be interchanged. All such changes are believed to be within the scope of the invention disclosed and claimed herein.
Although the above description has shown, stated and pointed out novel features of the invention that apply to various embodiments, those skilled in the art will illustrate here without departing from the scope of the invention. It should be understood that various omissions, replacements and changes may be made to the forms and details of the devices or processes made. The above description is considered to be the best mode at present in carrying out the present invention. This description does not imply a limitation, but merely illustrates the general principles of the present invention. The scope of the present invention is determined by the claims.
100: Wi-Fi system 102: Network 104: Wireless client 104<sub>A</sub>: Authorizer 104<sub>E</sub>: Enrolli 104<sub>R</sub>: Registrar 106: Access point (AP) 1402: Wireless modem subsystem 1402A: Wireless section 1402B: Modem 1404: Processing subsystem 1406: Memory subsystem 1408: Power subsystem 1410: Substrate
19 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US20090052382A1 | Cites | United States of America |
| EP01950987A1 | Cites | European Patent Office (EPO) |
| EP01983778A1 | Cites | European Patent Office (EPO) |
| WO2008008987A2 | Cites | World Intellectual Property Organization (WIPO) |
18 members in 8 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 12571102 | United States of America | – | |
| 57110209 | United States of America | A | |
| 57110209 | United States of America | A | |
| 2010049663 | United States of America | W | |
| 2010049663 | United States of America | W | |
| 2009571102 | – | – | – |
| 2010049663 | – | – | – |
| US20090571102 | – | – | – |
| WO2010US49663 | – | – | – |
Members18
| Document | Office | Kind | |
|---|---|---|---|
| GB201016004D0 | United Kingdom | D0 | |
| US2011075589A1 | United States of America | A1 | |
| GB2474111A | United Kingdom | A | |
| WO2011041171A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2011041171A4 | World Intellectual Property Organization (WIPO) | A4 | |
| US2011211219A1 | United States of America | A1 | |
| TW201132171A | Taiwan Province of China | A | |
| GB2474111B | United Kingdom | B | |
| CN102577525A | China | A | |
| EP2484155A1 | European Patent Office (EPO) | A1 | |
| KR20120093236A | Republic of Korea | A | |
| JP2013507049A | Japan | A | |
| JP5437496B2This record | Japan | B2 | |
| TWI449449B | Taiwan Province of China | B | |
| US8830866B2 | United States of America | B2 | |
| US8873523B2 | United States of America | B2 | |
| KR101481873B1 | Republic of Korea | B1 | |
| CN102577525B | China | B |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 5437496
- Publication, DOCDB
- 5437496
- Publication, EPODOC
- JP5437496B
- Application
- 2012532189
- Application, DOCDB
- 2012532189
- Application, EPODOC
- JP20120532189
Titles2
- Japanese
- 保護されたワイヤレスネットワークの懇請アクチベーション方法及び装置
- English
- Protected Wireless Network Solicitation Activation Methods and Devices
Classification
- CPC, 3
- H04W48/16
- H04L67/51
- H04W60/00
- IPC, 3
- H04W12 00
- H04W48 16
- H04W84 12
