Method for providing fast secure handoff in a wireless mesh network
Claim Score by NHIP
Abstract
Disclosed is a method for providing fast secure handoff in a wireless mesh network. The method comprises configuring multiple first level key holders (R0KHs) within a radio access network to which supplicants within the multi-hop wireless mesh network are capable of establishing a security association, configuring a common mobility domain identifier within the first level key holders of a mobility domain, and propagating identity of a first level key holder and the mobility domain identifier through the wireless mesh network to enable the supplicants within the mobility domain to perform fast secure handoff.

Term
3.5 yearsto projected expiry
Projected expiry 11 April 2030, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
25 claims: 2 independent, 23 dependent
- 1A method for providing fast secure handoff in a wireless mesh network, comprising:configuring multiple first level key holders (R0KHs) within a radio access network to which supplicants within the wireless mesh network are capable of establishing a security association;configuring a common mobility domain identifier within the first level key holders of a mobility domain;and propagating identity of a first level key holder and the mobility domain identifier of the mobility domain through the wireless mesh network to enable the supplicants within the mobility domain to perform fast secure handoff.
- 20Broadest claimClaim Score 64, broad(NHIP)A system for providing fast secure handoff in a wireless mesh network, comprising:a plurality of first level key holders (R0KHs) configured within a radio access network of the mobility domain;and one or more supplicants capable of establishing security association with the first level key holders, wherein the first level key holders are configured with a common mobility domain identifier of a mobility domain, such that, the common mobility domain identifier and identity of the first level key holders are propagated through the wireless mesh network to enable the supplicants within the mobility domain to perform fast secure handoff.
Independent claims2
70 paragraphs in 4 sections, as filed
FIELD OF THE DISCLOSURE
p-0002The present disclosure relates generally to wireless communications and more particularly to a method for providing fast secure handoff in a wireless mesh network.
BACKGROUND
p-0003Mesh networks are self-forming, multi-hop networks including a number of nodes which can operate with or without any fixed infrastructure, and in some cases the mesh network is formed entirely of mobile nodes. A mesh network typically includes a number of geographically-distributed, potentially mobile nodes which are wirelessly connected to each other by one or more logical links (e.g., radio frequency communication channels). The nodes can be fixed or mobile and can communicate with each other over a wireless media with or without the support of an infrastructure-based or wired network. Logical links between these nodes can change dynamically in an arbitrary manner as existing nodes move within the mesh network, as new nodes join or enter the mesh network, or as existing nodes leave or exit the mesh network. A single-hop logical link can only exist between two nodes when they are within direct communication range. A multi-hop logical link can only exist between two nodes whenever a set of single-hop logical links can be used to construct a path between the nodes. Such multi-hop logical links are either instantaneously coherent (e.g. all single-hop links are present at the same time) or deferred coherent (e.g. all single-hop links are expected to be present or were present over a period of time).
p-0004A mesh node typically includes an interface such as an Institute of Electrical and Electronics Engineers (IEEE 802.11) interface which continuously scans for other nodes in the mesh network. (For all referenced IEEE standards herein, see: http://standards.ieee.org/getieee802/index.html or contact the IEEE at IEEE, 445 Hoes Lane, PO Box 1331, Piscataway, N.J. 08855-1331, USA) IEEE 802.11 communication systems allow for “proximity-based” communications. For example, when two nodes are mobile within a geographic area, those nodes can communicate within a range of each other, such as a range of fifty (50) meters or one hundred sixty five (165) feet of each other. Using mesh routing protocols, logical routes are established between the mesh nodes and the fixed infrastructure (using one or more wireless hops) for access to data networks and services provided within the fixed infrastructure. Security is also established within the mesh network to protect data content from eavesdropping, modification and masquerading threats common in wireless networks.
p-0005Wireless networks such as mesh based networks, particularly the municipal and public safety markets utilizing mesh based networks for wide area mobile broadband coverage, require secure, fast handoff solutions. Large wide area mesh networks are typically segmented into manageable domains. IEEE 802.11r refers to these manageable domains as mobility domains. Mobility domains are groupings of access points that together provide an opportunity for fast handoff due to hierarchical security architecture within the mobility domain. In some cases, each of the mobility domains is mapped to an Internet Protocol (IP) subnet.
p-0006Existing solutions for secure, fast handoff are defined in IEEE 802.11i and IEEE 802.11r. However, both of these standards are limited in scope to the indoor enterprise architecture, that is, limited to a wired access point communicating with an 802.11 STA. Further, the enterprise model assumes the access point is wired directly to an enterprise network. Both 802.11i and 802.11r standards have drawbacks to their centralized key hierarchy approach with respect to high availability and fast handoff.
p-0007The limitations in the existing standards result in potential single point of failure of the key-heirarchy within a mobility domain when a single key level holder (R0KH) component is servicing the entire mobility domain. Further, the single point of failure can result in non-availability of security services to new devices roaming into the mobility domain or to devices in which security associations expire. In such cases, the devices will not have access to the network. Another limitation with the current approach is that R0KH handoff is significantly diminished when the physical location of the R0KH is outside, or not in control of the radio access network. Therefore, there is a need for a solution which addresses the above limitations of the existing standards.
BRIEF DESCRIPTION OF THE FIGURES
p-0008The accompanying figures, where like reference numerals refer to identical or functionally similar elements throughout the separate views, together with the detailed description below, are incorporated in and form part of the specification, and serve to further illustrate embodiments of concepts that include the claimed invention, and explain various principles and advantages of those embodiments.
p-0009<figref idrefs="DRAWINGS">FIG. 1</figref> is a block diagram of a communication network in accordance with some embodiments of the present invention.
p-0010<figref idrefs="DRAWINGS">FIG. 2</figref> is a block diagram illustrating a node employed in the communication network shown in <figref idrefs="DRAWINGS">FIG. 1</figref>.
p-0011<figref idrefs="DRAWINGS">FIG. 3</figref> illustrates propagation of identity of first level key holders within an Intelligent Access Point (IAP) routing domain of a mobility domain in accordance with some embodiments of the present invention.
p-0012<figref idrefs="DRAWINGS">FIG. 4</figref> illustrates propagation of identity of first level key holders within an IAP routing domain of a mobility domain, wherein all the IAPs contain both R0KH and R1KH, in accordance with some embodiments of the present invention.
p-0013<figref idrefs="DRAWINGS">FIG. 5</figref> illustrates a frame structure of a mobility domain information element.
p-0014<figref idrefs="DRAWINGS">FIG. 6</figref> illustrates a frame structure of a fast transition information element.
p-0015<figref idrefs="DRAWINGS">FIG. 7</figref> is a flowchart illustrating a method for providing fast secure handoff in the communication network of <figref idrefs="DRAWINGS">FIG. 1</figref>.
p-0016<figref idrefs="DRAWINGS">FIG. 8</figref> is a flowchart illustrating example of operations performed by a supplicant for establishing security association with a mesh access point in accordance with some embodiments of the present invention.
p-0017<figref idrefs="DRAWINGS">FIG. 9</figref> is a flowchart illustrating ability of an R1KH to “attach” to a functioning R0KH when a “current” R0KH fails.
p-0018Skilled artisans will appreciate that elements in the figures are illustrated for simplicity and clarity and have not necessarily been drawn to scale. For example, the dimensions of some of the elements in the figures may be exaggerated relative to other elements to help to improve understanding of embodiments of the present invention.
p-0019The apparatus and method components have been represented where appropriate by conventional symbols in the drawings, showing only those specific details that are pertinent to understanding the embodiments of the present invention so as not to obscure the disclosure with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.
DETAILED DESCRIPTION
p-0020Before describing in detail embodiments that are in accordance with the present invention, it should be observed that the embodiments reside primarily in combinations of method steps and system components related to providing fast secure handoff in a wireless mesh network. Accordingly, the system components and method steps have been represented where appropriate by conventional symbols in the drawings, showing only those specific details that are pertinent to understanding the embodiments of the present invention so as not to obscure the disclosure with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.
p-0021In this document, relational terms such as first and second, top and bottom, and the like may be used solely to distinguish one module or action from another module or action without necessarily requiring or implying any actual such relationship or order between such modules or actions. The terms “comprises,” “comprising,” or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but may include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by “comprises . . . a” does not, without more constraints, preclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the element.
p-0022It will be appreciated that embodiments of the invention described herein may be comprised of one or more conventional processors and unique stored program instructions that control the one or more processors to implement, in conjunction with certain non-processor circuits, some, most, or all of the functions of providing fast secure handoff in a wireless mesh network. The non-processor circuits may include, but are not limited to, a radio receiver, a radio transmitter, signal drivers, clock circuits, power source circuits, and user input devices. Alternatively, some or all functions could be implemented by a state machine that has no stored program instructions, or in one or more application specific integrated circuits (ASICs), in which each function or some combinations of certain of the functions are implemented as custom logic. Of course, a combination of the two approaches could be used. Thus, methods and means for these functions have been described herein. Further, it is expected that one of ordinary skill, notwithstanding possibly significant effort and many design choices motivated by, for example, available time, current technology, and economic considerations, when guided by the concepts and principles disclosed herein will be readily capable of generating such software instructions and programs and ICs with minimal experimentation.
p-0023Any embodiment described herein is not necessarily to be construed as preferred or advantageous over other embodiments. All of the embodiments described in this Detailed Description are illustrative provided to enable persons skilled in the art to make or use the invention and not to limit the scope of the invention which is defined by the claims.
p-0024<figref idrefs="DRAWINGS">FIG. 1</figref> is a block diagram illustrating an example communication network employing a method in accordance with some embodiments. Specifically, illustrates a wireless mesh network <b>100</b>. The wireless mesh network <b>100</b>, for example, can be a mesh enabled architecture (MEA) network or an 802.11 network (i.e. 802.11a, 802.11b, 802.11g, or 802.11s). It will be appreciated by those of ordinary skill in the art that the wireless mesh network <b>100</b> in accordance with the present invention can alternatively comprise any packetized communication network where packets are forwarded across multiple wireless hops. For example, the wireless mesh network <b>100</b> can be a network utilizing packet data protocols such as OFDMA (orthogonal frequency division multiple access), TDMA (time division multiple access), GPRS (General Packet Radio Service) and EGPRS (Enhanced GPRS). Additionally, each wireless hop of the wireless mesh network <b>100</b> may either employ the same packet data protocol as the other hops, or a unique packet data protocol per hop.
p-0025Architecture of Wireless Mesh Network with Distributed R0KHs
p-0026As illustrated in <figref idrefs="DRAWINGS">FIG. 1</figref>, the wireless mesh network <b>100</b> includes one or more mesh access points <b>105</b>-<i>n </i>(for example, MAPs <b>105</b>-<b>1</b> through <b>105</b>-<b>6</b>) which are used to route data packets from one or more intelligent access points <b>110</b>-<i>n </i>(for example, IAPs <b>110</b>-<b>1</b> through <b>110</b>-<b>4</b>) to one or more wireless subscriber devices <b>105</b>-<i>n </i>or <b>115</b>-<i>n </i>(for example, STAs <b>115</b>-<b>1</b> through <b>115</b>-<b>9</b>, or MAPs <b>105</b>-<b>1</b> through <b>105</b>-<b>6</b>). It will be appreciated by those of ordinary skill in the art that any number of mesh access points <b>105</b>-<i>n</i>, intelligent access points <b>110</b>-<i>n</i>, and wireless subscriber devices <b>115</b>-<i>n </i>can be utilized within the wireless mesh network <b>100</b> in accordance with the embodiments of the present invention, and that the quantity of such devices in <figref idrefs="DRAWINGS">FIG. 1</figref> are for illustrative purposes only. The one or more IAPs <b>110</b>-<i>n </i>then route the packets to a central ethernet switch <b>120</b> communicatively coupled to a central router <b>125</b>. The central router <b>125</b> is coupled to via a wired backbone <b>130</b> to an authentication server <b>135</b>. Although only the paths from the subscriber devices <b>115</b>-<i>n </i>(STAs) to the wired network (i.e. central ethernet switch <b>120</b>) is shown, it will be appreciated by those of ordinary skill in the art that meshed connections can be established as long as two neighboring devices such as subscriber devices <b>115</b>-<i>n </i>can communicate with each other.
p-0027A mesh enabled access point refers to a mobile or fixed device provisioned with both mesh functionality and access point functionality, wherein the mesh functionality allows neighboring devices to join the mesh e.g. wireless mesh network <b>100</b> using mesh routing, and the access point functionality supports 802.11 STA access. As used herein, the term “intelligent access point” refers to a fixed mesh enabled access point that is wired to a distribution system (i.e. connected to the wired backhaul). In one embodiment, the IAPs <b>110</b> can be configured as an IEEE 802.11s mesh portal (MPP). The term “mesh access point” refers to a mobile or fixed device that does not have a wired connection to the distribution system. In other words, the mesh access point has only wireless connection to the distribution system via the IAPs.
p-0028The radio access network (RAN) forming the MAPs <b>105</b>, IAPs <b>110</b> and STAs <b>115</b> of the wireless mesh network <b>100</b> is configured with multiple R0KHs <b>140</b>-<i>n </i>(also referred to as first level key holders or top level key holders or level zero key holders). In the present invention, each of the IAPs <b>110</b>-<b>1</b> through <b>110</b>-<b>4</b> is associated with one of the R0KHs <b>140</b>-<i>n </i>(R0KHs <b>140</b>-<b>1</b> through <b>140</b>-<b>4</b>) as shown in <figref idrefs="DRAWINGS">FIG. 1</figref>. The present invention adapts the 802.11r key heirarchy into the wireless mesh network <b>100</b>. As it will be appreciated by a person skilled in the art, the first level key holder <b>140</b>-<i>n </i>derives and holds the top pairwise master key (PMK<sub>—</sub>0) for each supplicant wireless device (MAPs <b>105</b> or STAs <b>115</b>) after the authentication process. In the present invention, all the MAPs <b>105</b>-<i>n </i>take the role of second level key holders (R1KHs) <b>145</b>-<i>n </i>(for example R1KHs <b>145</b>-<b>1</b> through <b>145</b>-<b>6</b>) and receive the next level key holder pairwise master key (PMK<sub>—</sub>1) from the first level key holder <b>140</b>. The link level data protection key can be derived from PMK<sub>—</sub>1 via a 4-way handshaking such as an 802.11 four-way handshaking. It will be appreciated by those of ordinary skill in the art that any number of key holders and levels of key holders can be utilized within the radio access network (RAN) in accordance with the embodiments of the present invention, and that the quantity of such devices in <figref idrefs="DRAWINGS">FIG. 1</figref> are for illustrative purposes only.
p-0029In the present invention, as shown in <figref idrefs="DRAWINGS">FIG. 1</figref>, some of the R0KHs <b>140</b>-<i>n</i>, for example R0KH <b>140</b>-<b>1</b> through <b>140</b>-<b>3</b> within the wireless mesh network <b>100</b> are configured with a common mobility domain identifier to constitute a mobility domain (shown as mobility domain A). For example, the wireless mesh network <b>100</b> of <figref idrefs="DRAWINGS">FIG. 1</figref> comprises mobility domain A including IAPs <b>110</b>-<b>1</b> through <b>110</b>-<b>3</b>, MAPs <b>105</b>-<b>1</b> through <b>105</b>-<b>5</b> and STAs <b>115</b>-<b>1</b> through <b>115</b>-<b>8</b>, and mobility domain B (shown as adjacent mobility domain B) including IAP <b>110</b>-<b>4</b>, MAP <b>105</b>-<b>6</b> and STA <b>115</b>-<b>9</b>. It is important to note that each of the MAPs <b>105</b> and IAPs <b>110</b> that is configured with a common mobility domain identifier propagates the common mobility domain identifier to enable wireless subscribes devices <b>115</b> or mobile MAPs <b>105</b> moving within the mobility domain to establish security association with the mobility domain.
p-0030The authentication server <b>135</b> works to provide authentication services to the R0KHs <b>140</b> and will be described hereinafter. In general, the authentication server <b>135</b> performs the authentication function necessary to check the credentials of a supplicant device on behalf of the authenticator and indicates whether the supplicant is authorized to access the authenticator's services. In one embodiment of the present invention, the authentication server <b>135</b> is located in a wired network section where physical security of the host can be provided. For example, the authentication server <b>135</b> can be an extensible authentication protocol-Tunneled Transport Layer Security/extensible authentication protocol-transport layer protocol (EAP-TTLS/EAP-TLS) enabled remote authentications dial-in user service (RADIUS) server providing centralized authentication.
p-0031The subscriber devices <b>115</b>-<i>n </i>or <b>105</b>-<i>n </i>in the wireless mesh network <b>100</b> may be required to send and receive encrypted data. Any device within the wireless mesh network <b>100</b> requiring/desiring access to the services offered by the authenticator's system is referred to as a supplicant. In one example, as shown in <figref idrefs="DRAWINGS">FIG. 1</figref>, the MAP <b>105</b>-<b>5</b> acts as a supplicant. A device that authenticates another device (supplicant) which requires/desires using the services protected by the authenticator is referred to as an authenticator. The authenticator enforces access control based on the authentication result.
p-0032Each node (MAPs <b>105</b>-<i>n</i>, IAPs <b>110</b>-<i>n</i>, and STAs <b>115</b>-<i>n</i>) in the wireless mesh network <b>100</b> is authenticated to the wireless mesh network <b>100</b> before it joins the wireless mesh network <b>100</b>. The credentials for the authentication can be based on, for example, public key technologies, shared key technologies, a password, a subscriber identity module (SIM) card identification (I.D.) or other I.D. which is unique to the particular node and is stored at the authentication server <b>135</b>. Each node uses this relationship with the authentication server <b>135</b> to authenticate to a one-hop secured meshed MAP <b>105</b> or IAP <b>110</b> which has established a secure connection to the R0KH <b>140</b>. The R0KH <b>140</b> will use the authentication services provided by the authentication server <b>135</b>. The authentication server <b>135</b> also assists the particular node that is authenticating to establish a trust relationship with its neighbor nodes by distributing a session master key material that is encrypted to the R0KHs <b>140</b>. The R0KHs <b>140</b> derive level zero and level one Pairwise Master Keys (PMK<sub>—</sub>0, PMK<sub>—</sub>1). The R0KH <b>140</b> also keeps PMK<sub>—</sub>0 and sends PMK<sub>—</sub>1 to the authenticator MAP <b>105</b> or IAP <b>110</b> which is taking the role of a level one key holder. In some deployments of the present invention, when the IP layer communication channels are used for the R0KHs <b>140</b>-<i>n </i>and R1KH <b>145</b>-<i>n</i>, the R0KHs <b>140</b>-<i>n </i>and R1KHs <b>145</b>-<i>n </i>can be located in different layer 2 segments.
p-0033In one embodiment of the present invention, the wireless mesh network <b>100</b> incorporates IEEE 802.11r operability. 802.11r provides for fast BSS (“Basic Service Set”) transitions (FT). 802.11r thus facilitates connectivity aboard vehicles in motion, with fast handoffs from one base station to another managed in a seamless manner. The primary application currently envisioned for the 802.11r standard is VoIP (“voice over IP”, or Internet-based telephony) via mobile telephones designed to work with wireless Internet networks, instead of (or in addition to) standard cellular networks. 802.11r refines the transition process of a mobile client as it moves between access points (MAPs <b>105</b> or IAPs <b>110</b>). The protocol allows a wireless client (MAPs <b>105</b> or STAs <b>115</b>) to establish a security and quality of service (QoS) state at a new access point before making a transition, which leads to minimal connectivity loss and application disruption. The overall changes to the protocol do not introduce any new security vulnerabilities. This preserves the behavior of current stations and access points. 802.11r provides mechanisms for roaming mobile clients to communicate with candidate access points, establish security associations and reserve QoS resources.
Node Components
p-0034<figref idrefs="DRAWINGS">FIG. 2</figref> is a block diagram of a node <b>200</b> according to one implementation of the present invention. The node <b>200</b> can be implemented in MAPs <b>105</b> and IAPs <b>110</b>. The node <b>200</b> comprises a processor <b>201</b>, a transceiver <b>202</b> including a transmitter circuitry <b>203</b> and a receiver circuitry <b>205</b>, an antenna <b>206</b>, a program memory <b>209</b> for storing operating instructions that are executed by the processor <b>201</b>, a buffer memory <b>210</b>, and one or more communication interfaces including a communication interface <b>213</b> comprising a routing module <b>207</b> and a security module <b>208</b>. Although not shown, the node <b>200</b> also can include an antenna switch, duplexer, circulator, or other highly isolative means (not shown) for intermittently providing information packets from the transmitter circuitry <b>203</b> to the antenna <b>206</b> and from the antenna <b>206</b> to the receiver circuitry <b>205</b>. The node <b>200</b> is an integrated unit containing at least all the elements depicted in <figref idrefs="DRAWINGS">FIG. 2</figref>, as well as any other elements necessary for the node <b>200</b> to perform its particular electronic function. Alternatively, the node <b>200</b> can comprise a collection of appropriately interconnected units or devices, wherein such units or devices perform functions that are equivalent to the functions performed by the elements of the node <b>200</b>.
p-0035The processor <b>201</b> includes one or more microprocessors, microcontrollers, DSPs (digital signal processors), state machines, logic circuitry, or any other device or devices that process information based on operational or programming instructions. Such operational or programming instructions are stored in the program memory <b>209</b>. The program memory <b>209</b> can be an IC (integrated circuit) memory chip containing any form of RAM (random-access memory) or ROM (read-only memory), a floppy disk, a CD-ROM (compact disk read-only memory), a hard disk drive, a DVD (digital video disc), a flash memory card, external subscriber identity module (SIM) card or any other medium for storing digital information. One of ordinary skill in the art will recognize that when the processor <b>201</b> has one or more of its functions performed by a state machine or logic circuitry, the program memory <b>209</b> containing the corresponding operational instructions can be embedded within the state machine or logic circuitry. The operations performed by the processor <b>201</b> and the other elements of the node <b>200</b> are described in detail below.
p-0036The transmitter circuitry <b>203</b> and the receiver circuitry <b>205</b> enable the node <b>200</b> to communicate information packets to and acquire information packets from the other nodes. In this regard, the transmitter circuitry <b>203</b> and the receiver circuitry <b>205</b> include appropriate, conventional circuitry to enable digital or analog transmissions over a wireless communication channel. The transmitter circuitry <b>203</b> and the receiver circuitry <b>205</b> can operate over an ad hoc networking air interface (e.g., Bluetooth, IEEE 802.11, IEEE 802.15, and the like).
p-0037The implementations of the transmitter circuitry <b>203</b> and the receiver circuitry <b>205</b> depend on the implementation of the node <b>200</b>. For example, the transmitter circuitry <b>203</b> and the receiver circuitry <b>205</b> can be implemented as an appropriate wireless modem, or as conventional transmitting and receiving components of two-way wireless communication devices. In the event that the transmitter circuitry <b>203</b> and the receiver circuitry <b>205</b> are implemented as a wireless modem, the modem can be internal to the node <b>200</b> or insertable into the node <b>200</b> (e.g., embodied in a wireless radio frequency (RF) modem implemented on a Personal Computer Memory Card International Association (PCMCIA) card). For a wireless communication device, the transmitter circuitry <b>203</b> and the receiver circuitry <b>205</b> are preferably implemented as part of the wireless device hardware and software architecture in accordance with known techniques. One of ordinary skill in the art will recognize that most, if not all, of the functions of the transmitter circuitry <b>203</b> and/or the receiver circuitry <b>205</b> can be implemented in a processor, such as the processor <b>201</b>. However, the processor <b>201</b>, the transmitter circuitry <b>203</b>, and the receiver circuitry <b>205</b> have been artificially partitioned herein to facilitate a better understanding.
p-0038The receiver circuitry <b>205</b> is capable of receiving radio frequency (RF) signals from at least one frequency band and optionally multiple frequency bands, when, for example, the communications with a proximate device are in a frequency band other than that of the network communications. The receiver circuitry <b>205</b> can optionally comprise a first receiver and a second receiver, or one receiver capable of receiving in two or more frequency bands. The receiver <b>205</b>, depending on the mode of operation, can be tuned to receive, for example, Bluetooth or wireless local area network (WLAN), such as IEEE 802.11, communication signals. The transceiver <b>202</b> includes at least one set of transmitter circuitry <b>203</b>. The at least one transmitter <b>203</b> can be capable of transmitting to multiple devices potentially in multiple frequency bands.
p-0039The antenna <b>206</b> comprises any known or developed structure for radiating and receiving electromagnetic energy in the frequency range containing the wireless carrier frequencies.
p-0040The buffer memory <b>210</b> can be any form of volatile memory, such as random access memory (RAM), and is used for temporarily storing received information packets in accordance with the present invention.
p-0041As illustrated in <figref idrefs="DRAWINGS">FIG. 2</figref>, a communication interface <b>213</b> includes a routing module <b>207</b> and a security module <b>208</b>. The routing module <b>207</b> and the security module <b>208</b> are communicatively coupled. The routing module <b>207</b> triggers establishment of security associations based on attributes in a neighbor node table. Depending upon the implementation, some examples of some of the attributes stored in the neighbor node table include a neighbor node list, an active route list and a proxy list, and parameters such as Link Quality Measurements (LQMs) (which account for the quality of a wireless link with the particular neighbor node), routing metrics (which account for metrics along a route to the particular neighbor node), mobility domain information comprising a mobility domain identifier, for example mobility domain identifier of mobility domain A in the wireless mesh network <b>100</b> of <figref idrefs="DRAWINGS">FIG. 1</figref>, advertised by the particular neighbor node, mobility information about the particular neighbor node; and security association state information. The routing module <b>207</b> controls which neighbor nodes the security module <b>208</b> establishes security associations with. Instead of using a MAC Layer Management Entity (MLME) to establish security associations, the establishment of security associations (to specific neighbor nodes in a mesh network) can be triggered based on the routing module's observation of a set of attributes in a neighbor node table. For example, in one implementation, the routing module <b>207</b> triggers the security module <b>208</b> to establish security associations to specific neighbors based on attributes such as Link Quality Measurements (LQMs), routing metrics, mobility domain information, mobility information about the pair of peer nodes (e.g., fixed or mobile) and whether or not a security association is already established with a neighbor node. Thus, these security association establishment techniques are not dependent on the MLME or its association and open authentication states.
Propagation of R0KHs
p-0042<figref idrefs="DRAWINGS">FIG. 3</figref> illustrates propagation of identity of R0KHs within an IAP routing domain of a mobility domain, for example mobility domain A of the wireless mesh network <b>100</b> of <figref idrefs="DRAWINGS">FIG. 1</figref>. As shown in <figref idrefs="DRAWINGS">FIG. 3</figref>, the identity of the R0KHs <b>140</b>-<i>n </i>is configured in IAPs <b>110</b>-<i>n</i>. In another embodiment, the identity of the R0KHs <b>140</b>-<i>n </i>is configured in a central server (not shown) within the RAN.
p-0043Now referring to <figref idrefs="DRAWINGS">FIG. 4</figref>, according to one implementation of the present invention, all the IAPs <b>110</b>-<b>1</b> through <b>110</b>-<b>3</b> within the mobility domain A can contain both R0KH (R0KHs <b>140</b>-<b>1</b> through <b>140</b>-<b>3</b>) and R1KH (R1KH <b>145</b>-<b>7</b> through <b>145</b>-<b>9</b>). Further, each R1KH component <b>145</b> can have multiple R0KH parents <b>140</b> i.e. during a fast handoff, an R1KH <b>145</b> can communicate with any R0KH <b>140</b> within the mobility domain A.
p-0044Now referring back to <figref idrefs="DRAWINGS">FIG. 3</figref>, the identity of each of the first level key holders <b>140</b>-<i>n </i>and the mobility domain identifier is propagated through the wireless mesh network <b>100</b> to enable the supplicants within the mobility domain A to perform fast secure handoff. In one embodiment, the propagation of the R0KH identifiers <b>140</b>-<i>n </i>is limited to a mesh routing domain within the RAN. For example, when the first level key holders <b>140</b>-<i>n </i>are located in the IAPs <b>110</b>-<i>n</i>, the propagation of the R0KH identifiers <b>140</b>-<i>n </i>is limited to the mesh routing domain (illustrated as shaded triangle in <figref idrefs="DRAWINGS">FIG. 3</figref>) of a single IAP <b>110</b> (referred to as IAP routing domain). For example, as shown in <figref idrefs="DRAWINGS">FIG. 3</figref>, the propagation of R0KH identifier <b>140</b>-<b>1</b> is limited to the routing domain of IAP <b>110</b>-<b>1</b>, the propagation of R0KH-2 identifier is limited to the routing domain of IAP <b>110</b>-<b>2</b>, and the propagation of R0KH-3 identifier is limited to the routing domain of IAP <b>110</b>-<b>3</b>.
p-0045Each of the IAPs <b>110</b>-<i>n </i>can propagate the mobility domain identifier and the identity of R0KH <b>140</b> with which it is associated by advertising the mobility domain identifier and identity of the R0KHs within beacons per 802.11r. One or more of the MAPs <b>105</b>-<i>n </i>may receive the mobility domain identifier and the identity of R0KHs <b>140</b>-<i>n </i>and propagate the mobility domain identifier and identity of the first level key holders <b>140</b>-<i>n </i>after establishing security association with the R0KHs <b>140</b>-<i>n</i>. In one embodiment, the mobility domain identifier of the mobility domain is propagated using a mobility domain information element (MDIE) and the identity of the R0KH is propagated using a fast transition information element (FTIE).
Mobility Domain Information Element
p-0046Referring to <figref idrefs="DRAWINGS">FIG. 5</figref>, a frame structure of the mobility domain information element (MDIE) <b>500</b> is shown. The MAPs <b>105</b> or IAPs <b>110</b> use the MDIE <b>500</b> to advertise that it is included in the group of MAPs <b>105</b> and/or IAPs <b>110</b> that constitute the mobility domain A, to advertise its support for Fast BSS transition capability. According to one implementation of the present invention, the MDIE <b>500</b> contains an element identifier <b>510</b>, a length <b>520</b>, a mobility domain identifier <b>530</b>, and a fast BSS transition capability <b>540</b>. The element identifier <b>510</b> identifies the MDIE <b>500</b>. The length field <b>520</b> defines the length of the MDIE <b>500</b>. The mobility domain identifier <b>530</b> identifies the mobility domain A with which the MAPs <b>105</b> or IAPs <b>110</b> are currently associated with. The Fast BSS transition capability field <b>540</b> defines whether the MAPs <b>105</b> or IAPs <b>110</b> support fast BSS transition within the mobility domain A.
Fast Transition Information Element
p-0047Referring to <figref idrefs="DRAWINGS">FIG. 6</figref>, a frame structure of the fast transition information element (FTIE) <b>600</b> is shown. According to one implementation of the present invention, the FTIE <b>600</b> includes an element identifier <b>610</b>, a length <b>620</b>, a R0KH identifier <b>630</b>, and a R1KH identifier <b>640</b>. The element identifier <b>610</b> identifies the FTIE <b>600</b>. The length field <b>620</b> defines the length of the FTIE <b>600</b>. The R0KH identifier <b>630</b> indicates the PMK-R0 key holder that will be utilized by the supplicants. The R1KH identifier <b>640</b> is optional and indicates the MAPs <b>105</b> or IAPs <b>110</b> key holder identity which will be used by the supplicants.
p-0048Now referring to <figref idrefs="DRAWINGS">FIG. 7</figref>, a flowchart illustrating a method <b>700</b> for providing fast secure handoff in a wireless mesh network <b>100</b> of <figref idrefs="DRAWINGS">FIG. 1</figref>, according to one implementation of the present invention is shown. The method <b>700</b> begins with configuring multiple R0KHs <b>140</b> within a RAN, at step <b>705</b>. In one embodiment, configuring the R0KHs <b>140</b> within the RAN comprises configuring the identity of each of the R0KHs <b>140</b> in IAPs <b>110</b> of the wireless mesh network <b>100</b>. In another embodiment, configuring the R0KHs <b>140</b> within the RAN comprises configuring the identity of each of R0KHs <b>140</b> in the central server within the RAN of the wireless mesh network <b>100</b>.
p-0049The method <b>700</b> further comprises configuring a common mobility domain identifier within the R0KHs <b>140</b> of a mobility domain A as shown in step <b>710</b> i.e. all the R0KHs <b>140</b> that constitute the mobility domain A is configured with the common mobility domain identifier. At step <b>715</b>, propagating identity of a R0KH <b>140</b>, for example via FTIE <b>600</b>, and the mobility domain identifier, for example via MDIE <b>500</b> through the wireless mesh network <b>100</b>. When the IAPs <b>110</b> are configured with R0KHs <b>140</b>, the IAPs <b>110</b> can propagate the mobility domain identifier and identity of their respective R0KHs <b>140</b>. In this case, the propagation of the R0KH identifier is limited to the mesh routing domain. At step <b>720</b>, a supplicant, for example, mobile MAPs <b>105</b> or STAs <b>115</b> belonging to an adjacent mobility domain B of the wireless mesh network <b>100</b> receives the propagated MDIE, and subsequently identity of the R0KH <b>140</b> at step <b>725</b>.
p-0050At step <b>730</b>, the supplicant determines whether to establish security association with the mobility domain A based on the received mobility domain information. If the supplicant decides to not establish the security association with the mobility domain A, then at step <b>735</b>, the supplicant continues to propagate adjacent mobility domain information i.e. the mobility domain B with which the supplicant is currently associated with. In one embodiment, the supplicant can decide not to establish security association with the mobility domain A when the mobility domain A does not support the fast BSS transition.
p-0051Referring back to step <b>730</b>, in one embodiment, the supplicant determines whether to establish security association with the mobility domain based on the fast BSS transition capability of the mobility domain, and if the mobility domain A supports the fast BSS transition, then at step <b>740</b>, the supplicant establishes an initial security association with the mobility domain A and stops propagating the mobility domain information of its previously associated adjacent mobility domain B. Next at step <b>745</b>, the supplicant stores or saves the R0KH <b>140</b> as “root” R0KH. As used herein, the term “root” R0KH indicates identity of the R0KH within a mobility domain that a client initially establishes security association with. In addition, the supplicant stores or saves the R0KH <b>140</b> as “current” R0KH. As used herein, the term “current” R0KH indicates the identity of the R0KH security domain that a client currently resides within. Next, at step <b>750</b>, the supplicant (MAP <b>105</b>) starts propagating the mobility domain information (MDIE) of the mobility domain A and identity (FTIE) of the R0KH <b>140</b> with which the supplicant is currently associated to enable other supplicants moving within the mobility domain A to perform fast secure handoff. As it will be appreciated by a person skilled in the art, the step <b>750</b> can be periodically repeated to propagate the mobility domain information in order to enable supplicants moving within the mobility domain to perform fast secure handoff at different points of time.
p-0052<figref idrefs="DRAWINGS">FIG. 8</figref> illustrates an example of operations <b>800</b> performed by a supplicant, for example, a supplicant MAP <b>105</b>-<b>5</b> to establish security association with a MAP <b>105</b>-<i>n </i>within the mobility domain A of the wireless mesh network <b>100</b>. At step <b>805</b>, the supplicant MAP <b>105</b>-<b>5</b> receives MDIE <b>500</b> containing the mobility domain identifier from the MAP <b>105</b> e.g. MAP <b>105</b>-<b>1</b>. At step <b>810</b>, the supplicant MAP <b>105</b>-<b>5</b> determines whether the MAP <b>105</b>-<b>1</b> supports fast BSS transition (FT) based on the received MDIE <b>500</b>. If the MAP <b>105</b>-<b>1</b> does not support fast BSS transition, the supplicant MAP <b>105</b>-<b>5</b> continues to listen for mobility domain identifiers from other MAPs <b>105</b>-<b>2</b> through <b>105</b>-<i>n </i>as shown in step <b>815</b>. Referring back to step <b>810</b>, if the supplicant MAP <b>105</b>-<b>5</b> determines that the MAP <b>105</b>-<b>1</b> supports fast BSS transition, then at step <b>820</b>, the supplicant MAP <b>105</b>-<b>5</b> checks whether it has already been associated with a “root” R0KH in mobility domain A, e.g. R0KH <b>140</b>-<b>2</b>. When the supplicant is not already associated with a “root” R0KH in mobility domain A, then at step <b>825</b>, the supplicant performs FT initial security association with the MAP <b>105</b>-<b>1</b> establishing R0KH-1 as its “root” and “current” R0KH for mobility domain A and starts propagating the mobility domain information (MDIE) and key holder information (FTIE) at step <b>830</b>.
p-0053Referring back to step <b>820</b>, when the supplicant MAP <b>105</b>-<b>5</b> determines that it is already associated with a “root” R0KH in Mobility Domain A, e.g. R0KH <b>140</b>-<b>2</b>, then at step <b>835</b>, the supplicant sends a FT re-association request including identity of the “root” R0KH <b>140</b>-<b>2</b> to the MAP <b>105</b>-<b>1</b>. As it will be appreciated by a person skilled in the art, the MAP <b>105</b>-<b>1</b> can access the “root” R0KH <b>140</b>-<b>2</b> and obtain the PMK-R1 to enable the supplicant to complete the FT handoff (as describe in subsequent step <b>845</b>). Next, at step <b>840</b>, the supplicant MAP <b>105</b>-<b>5</b> receives a FT re-association response including the identity of R0KH <b>140</b>-<b>1</b> with which the MAP <b>105</b>-<b>1</b> is currently associated. At step <b>845</b>, the MAP <b>105</b>-<b>1</b> receives PMK-R1 from the “root” R0KH <b>140</b>-<b>2</b> during FT handoff. After receiving the PMK-R1 key, the MAP <b>105</b>-<b>1</b> establishes security association with the supplicant MAP <b>105</b>-<b>5</b> by performing 4-way handshake with the supplicant MAP <b>105</b>-<b>5</b> as shown in step <b>850</b>.
p-0054After the supplicant MAP <b>105</b>-<b>5</b> establishes security association with the MAP <b>105</b>-<b>1</b>, at step <b>855</b>, the supplicant MAP <b>105</b>-<b>5</b> stores the identity of the R0KH <b>140</b>-<b>1</b> being advertised by MAP <b>105</b>-<b>1</b> with which the supplicant MAP <b>105</b>-<b>5</b> is currently associated as “current” R0KH. At step <b>860</b>, the supplicant MAP <b>105</b>-<b>5</b> starts propagating the mobility domain information (MDIE) and the “current” R0KH (FTIE) throughout its routing domain. As it will be appreciated by a person skilled in the art, the supplicant MAP <b>105</b>-<b>5</b> can periodically propagate the “current” R0KH to enable other supplicants e.g. STAs <b>115</b>-<b>2</b> through <b>115</b>-<i>n </i>to join the wireless mesh network <b>100</b>.
p-0055Referring to <figref idrefs="DRAWINGS">FIG. 9</figref>, a flowchart illustrating example of operations <b>900</b> associated with ability of R1KH to “attach” to a functioning R0KH when the R1KH detects a failure in current “R0KH”. At Step <b>905</b>, a supplicant performs FT handoff with another MAP <b>105</b> or IAP <b>110</b> within the mobility domain. After establishing security association, at step <b>910</b>, the supplicant marks the initially contacted R0KH as “root” R0KH and currently associated R0KH as “current” R0KH. Next, at step <b>915</b>, the supplicant determines whether the IAP of the “current” R0KH has failed. When the supplicant determines that the “current” R0KH is functioning, the supplicant proceeds to step <b>920</b> to determine whether the IAP of the “root” R0KH within the mobility domain has failed. When the supplicant detects a failure of the IAP of the “root” R0KH, the supplicant marks “current” R0KH as “root” R0KH as shown in step <b>925</b>. Then, during periodic refresh of the security association the supplicant will use the new root R0KH rather than the failed R0KH. When the supplicant determines that the IAP of the “root” R0KH is functioning, the supplicant proceeds to step <b>915</b> and periodically checks for the functioning of the IAP of the “current” R0KH.
p-0056Referring back to step <b>915</b>, when the supplicant detects the failure of the IAP associated with the current R0KH, at step <b>930</b>, the supplicant determines a functioning IAP within the mobility domain and communicates with the R0KH of the functioning IAP and establishes security association with the functioning IAP as shown in step <b>935</b>. After the supplicant establishes security association with the functioning IAP, the supplicant discontinues the propagation of identity of R0KH of the failed IAP as shown in step <b>940</b>, and proceeds to step <b>945</b> to mark R0KH of the functioning IAP with which the MAP is currently associated as “current” R0KH at step <b>945</b>. Next, at step <b>950</b>, the supplicant propagates R0KH of the functioning IAP throughout the mesh routing domain. As it will be appreciated by a person skilled in the art, the supplicant can periodically propagate the R0KH of the functioning IAP to enable other supplicants to join the wireless mesh network <b>100</b>.
Applications
p-0057Some of the applications of the present invention are described below.
p-0058The present invention provides for the applying of mobility domains to a mesh network and defines propagation of a mobility domain identifier of the mobility domain within an IAP routing domain, thereby extending IEEE 802.11r concepts to wide area mesh networks. Some of the basic functions that can be augmented for mesh networks using the teachings of the present invention are a) a mechanism to detect when a mobile device hands off to a new IP subnet. This is necessary so that the mobile device knows when it should use Dynamic Host Configuration Protocol (DHCP) to acquire a new topologically correct Internet Protocol (IP) address. The propagation of mobility domain information via MDIE can be used for this purpose; b) a mechanism to establish a security association with the new access point based on the propagation of identity of the first level key holders via FTIE in accordance with some embodiments of the present invention, which allows new security associations to be established without communicating all the way back to the authentication server, e.g. RADIUS (Remote Authentication Dial In User Service) server; and c) a mechanism to minimize the opportunity for a single point of failure, especially in public safety systems (e.g. systems operating at 4.9 GHz spectrum that allows high power devices with ranges much greater than 50 meters e.g. 300 meters) based on the distributed R0KHs among all the IAPs according to the implementations of the present invention.
p-0059The present invention further improves the system availability as described below.
p-0060For example, whenever an IAP fails, the wireless mesh network <b>100</b> self-heals creating routes around the failed IAP to a functioning IAP as described by the flowchart of <figref idrefs="DRAWINGS">FIG. 9</figref>. Thus during a R0KH failure, any new client that is attempting to access to the wireless mesh network will automatically be routed around the failed IAP-R0KH to a functioning IAP-R0KH. The functioning IAP-R0KH will become the clients “root” R0KH.
p-0061In another scenario, whenever an R0KH fails, the wireless mesh network <b>100</b> self heals by creating a route around the failed IAP. The consequence of the failure occurs when a client performs a handoff to a newly visited R0KH. If the R1KH does not have cached keying material from a previous client visit, the R1KH will attempt to communicate with the R0KH to obtain the proper security information. Unfortunately, if the R0KH is nonfunctioning, then the communication will fail in which case the handoff will be denied due to inability to reach the R0KH. However because R0KHs are distributed and advertised within a routing domain, the client can adopt the “current” R0KH as its “root” R0KH and then re-authenticate to the network via its new R0KH. Though there may be a delay in this handoff, the client and system quickly and smoothly recover from the failed R0KH. A similar scenario can occur for devices whose security associations expire. For example, if a security association is about to expire and communication to the failed R0KH is necessary to refresh the security association, the refresh will fail. This results in the selection of a new R0KH in accordance with the present invention. Thus the present invention improves the system availability in mesh networks.
p-0062In the foregoing specification, specific embodiments have been described. However, one of ordinary skill in the art appreciates that various modifications and changes can be made without departing from the scope of the invention as set forth in the claims below. Accordingly, the specification and figures are to be regarded in an illustrative rather than a restrictive sense, and all such modifications are intended to be included within the scope of present teachings. The benefits, advantages, solutions to problems, and any element(s) that may cause any benefit, advantage, or solution to occur or become more pronounced are not to be construed as a critical, required, or essential features or elements of any or all the claims. The invention is defined solely by the appended claims including any amendments made during the pendency of this application and all equivalents of those claims as issued.
p-0063Moreover in this document, relational terms such as first and second, top and bottom, and the like may be used solely to distinguish one entity or action from another entity or action without necessarily requiring or implying any actual such relationship or order between such entities or actions. The terms “comprises,” “comprising,” “has”, “having,” “includes”, “including,” “contains”, “containing” or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises, has, includes, contains a list of elements does not include only those elements but may include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by “comprises . . . a”, “has . . . a”, “includes . . . a”, “contains . . . a” does not, without more constraints, preclude the existence of additional identical elements in the process, method, article, or apparatus that comprises, has, includes, contains the element. The terms “a” and “an” are defined as one or more unless explicitly stated otherwise herein. The terms “substantially”, “essentially”, “approximately”, “about” or any other version thereof, are defined as being close to as understood by one of ordinary skill in the art, and in one non-limiting embodiment the term is defined to be within 10%, in another embodiment within 5%, in another embodiment within 1% and in another embodiment within 0.5%. The term “coupled” as used herein is defined as connected, although not necessarily directly and not necessarily mechanically. A device or structure that is “configured” in a certain way is configured in at least that way, but may also be configured in ways that are not listed.
p-0064It will be appreciated that some embodiments may be comprised of one or more generic or specialized processors (or “processing devices”) such as microprocessors, digital signal processors, customized processors and field programmable gate arrays (FPGAs) and unique stored program instructions (including both software and firmware) that control the one or more processors to implement, in conjunction with certain non-processor circuits, some, most, or all of the functions of the method and/or apparatus described herein. Alternatively, some or all functions could be implemented by a state machine that has no stored program instructions, or in one or more application specific integrated circuits (ASICs), in which each function or some combinations of certain of the functions are implemented as custom logic. Of course, a combination of the two approaches could be used.
p-0065Moreover, an embodiment can be implemented as a computer-readable storage medium having computer readable code stored thereon for programming a computer (e.g., comprising a processor) to perform a method as described and claimed herein. Examples of such computer-readable storage mediums include, but are not limited to, a hard disk, a CD-ROM, an optical storage device, a magnetic storage device, a ROM (Read Only Memory), a PROM (Programmable Read Only Memory), an EPROM (Erasable Programmable Read Only Memory), an EEPROM (Electrically Erasable Programmable Read Only Memory) and a Flash memory. Further, it is expected that one of ordinary skill, notwithstanding possibly significant effort and many design choices motivated by, for example, available time, current technology, and economic considerations, when guided by the concepts and principles disclosed herein will be readily capable of generating such software instructions and programs and ICs with minimal experimentation.
p-0066The Abstract of the Disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the foregoing Detailed Description, it can be seen that various features are grouped together in various embodiments for the purpose of streamlining the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed embodiments require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter lies in less than all features of a single disclosed embodiment. Thus the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separately claimed subject matter.
Contents4
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11240655B2 | Cited by | United States of America | Applicant |
| US11405215B2 | Cited by | United States of America | Search report |
| US11895575B2 | Cited by | United States of America | Applicant |
| US11546137B2 | Cited by | United States of America | Applicant |
| US2013196708A1 | Cited by | United States of America | Pre-grant |
| US10893442B2 | Cited by | United States of America | Applicant |
| US2024406721A1 | Cited by | United States of America | Search report |
| US2013305332A1 | Cited by | United States of America | Pre-grant |
| US11652616B2 | Cited by | United States of America | Applicant |
| US9084111B2 | Cited by | United States of America | Applicant |
| US9860220B2 | Cited by | United States of America | Search report |
| US11824974B2 | Cited by | United States of America | Applicant |
| US12047871B2 | Cited by | United States of America | Applicant |
| US10356662B2 | Cited by | United States of America | Applicant |
| US10349321B2 | Cited by | United States of America | Search report |
| WO2011134608A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10270747B2 | Cited by | United States of America | Applicant |
| DE102010018285A1 | Cited by | Germany | Search report |
| US10812964B2 | Cited by | United States of America | Applicant |
| US10470086B2 | Cited by | United States of America | Search report |
| US2009136036A1 | Cited by | United States of America | Pre-grant |
| CN102474522A | Cited by | China | Search report |
| US11956678B2 | Cited by | United States of America | Applicant |
| US11405857B2 | Cited by | United States of America | Applicant |
| WO2017171835A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US11489821B2 | Cited by | United States of America | Applicant |
| US11368880B2 | Cited by | United States of America | Applicant |
| US12294939B2 | Cited by | United States of America | Applicant |
| US12284599B2 | Cited by | United States of America | Applicant |
| US10736020B2 | Cited by | United States of America | Applicant |
| US2016014102A1 | Cited by | United States of America | Pre-grant |
| US10200941B2 | Cited by | United States of America | Applicant |
| US11502834B2 | Cited by | United States of America | Applicant |
| US11166226B2 | Cited by | United States of America | Applicant |
| US12395899B2 | Cited by | United States of America | Applicant |
| US11153078B2 | Cited by | United States of America | Search report |
| US11310036B2 | Cited by | United States of America | Applicant |
| US2006067526A1 | Cites | United States of America | Pre-grant |
| US2007206537A1 | Cites | United States of America | Pre-grant |
| US2007250713A1 | Cites | United States of America | Pre-grant |
| US2008065884A1 | Cites | United States of America | Pre-grant |
| US2008072047A1 | Cites | United States of America | Pre-grant |
| US7499547B2 | Cites | United States of America | Pre-grant |
| US7787627B2 | Cites | United States of America | Pre-grant |
| US8023478B2 | Cites | United States of America | Pre-grant |
| US8037305B2 | Cites | United States of America | Pre-grant |
9 members in 4 offices; this record represents the family
Members9
| Document | Office | Kind | |
|---|---|---|---|
| US2009116647A1 | United States of America | A1 | |
| WO2009061591A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2009061591A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2009061591A4 | World Intellectual Property Organization (WIPO) | A4 | |
| EP2210438A2 | European Patent Office (EPO) | A2 | |
| KR20100089870A | Republic of Korea | A | |
| KR101149101B1 | Republic of Korea | B1 | |
| US8249256B2 | United States of America | B2 | |
| EP2210438B1 | European Patent Office (EPO) | B1 |
62 transactions on the USPTO file
Allowed after 2 non-final rejections, 1 final rejection and 1 RCE.
- Non-final rejections
- 2
- Final rejections
- 1
- RCEs
- 1
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 12th Year, Large EntityM1553 | M1553 | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Interview Summary - Examiner InitiatedEXIE | EXIE | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Response after Non-Final ActionA... | A... | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Correspondence Address ChangeC.ADB | C.ADB | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Email NotificationEML_NTR | EML_NTR | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Sent to Classification ContractorPGPC | PGPC | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Cleared by OIPE CSRL194 | L194 | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
19 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee paymentFPAY | FPAY | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Application
- 93551307
Titles
- English
- METHOD FOR PROVIDING FAST SECURE HANDOFF IN A WIRELESS MESH NETWORK
Patent term adjustment
- A delay
- +722 daysthe office missed an examination deadline
- B delay
- +165 dayspendency past three years
- Net adjustment
- 887 days
Classification
- CPC, 7
- H04L63/064
- H04W36/08
- H04W36/14
- H04W84/18
- H04W12/041
- H04W12/04
- H04W12/06
- IPC, 1
- H04K1 00