Wireless extender secure discovery and provisioning
Claim Score by NHIP
Abstract
According to embodiments of the invention, a first wireless access point discovers a second wireless access point, the first wireless access point tunes its radio and privacy settings, without user input, based upon parameters automatically exchanged in response to the discovery of the second wireless access point, and a secure direct wireless connection is established between the first and second wireless access points using the radio and privacy settings. Adding the first wireless to an existing mesh network includes a determination of the best available direct wireless connection.

Term
3.5 yearsto projected expiry
Projected expiry 15 March 2030, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
20 claims: 2 independent, 18 dependent
- 1Broadest claimClaim Score 31, narrow(NHIP)A method for an additional wireless access point to wirelessly connect to a best candidate wireless access point, the method comprising:receiving a plurality of individual broadcast beacons by an additional wireless access point from a plurality of individual wireless access points, wherein each of the plurality of individual wireless access points transmits a unique beacon;authenticating by the additional wireless access point advertisement information in each unique beacon;transmitting a probe request from the additional access point to each of the plurality of individual wireless access points by the additional wireless access point;receiving a probe response by the additional wireless access point from each of the plurality of individual wireless access points;measuring a mean received signal strength of each of the plurality of individual wireless access points;calculating a weight for each of the plurality of individual wireless access points, wherein the calculation of the weight of any particular wireless access point includes the measured mean received signal strength from that particular wireless access point;selecting the wireless access point with a largest weight as the best candidate wireless access point;and connecting to the best candidate wireless access point with the largest weight by the additional wireless access point.
- 11A non-transitory computer storage medium embodied thereon a program executable to perform a method for an additional wireless access point to wirelessly connect to a best candidate wireless access point, the method comprising:receiving a plurality of individual broadcast beacons by an additional wireless access point from a plurality of individual wireless access points, wherein each of the plurality of individual wireless access points transmits a unique beacon;authenticating by the additional wireless access point advertisement information in each unique beacon;transmitting a probe request from the additional access point to each of the plurality of individual wireless access points by the additional wireless access point;receiving a probe response by the additional wireless access point from each of the plurality of individual wireless access points;measuring a mean received signal strength of each of the plurality of individual wireless access points;calculating a weight for each of the plurality of individual wireless access points, wherein the calculation of the weight of any particular wireless access point includes the measured mean received signal strength from that particular wireless access point;selecting the wireless access point with a largest weight as the best candidate wireless access point;and connecting to the best candidate wireless access point with the largest weight by the additional wireless access point.
Independent claims2
55 paragraphs in 4 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATIONS
0001The present application is a continuation and claims the priority benefit of U.S. patent application Ser. No. 13/478,003 filed May 22, 2012, which will issue as U.S. Pat. No. 8,594,109 on Nov. 26, 2013, which is a continuation and claims the priority benefit of U.S. patent application Ser. No. 12/724,363 filed Mar. 15, 2010, now U.S. Pat. No. 8,189,608, which claims priority benefit of U.S. provisional application 61/291,790 filed Dec. 31, 2009, the disclosures of which are incorporated herein by reference.
BACKGROUND OF THE INVENTION
00021. Field of the Invention
0003Embodiments of the present invention relate generally to wireless networks. More particularly, these embodiments relate to products, systems, and methods for automatic discovery and provisioning of a wireless connection between access points.
00042. Description of the Related Art
0005A local area network (“LAN”) typically employs one of two connection arrangements: full mesh topology or partial mesh topology. In the full mesh topology, each mesh node (e.g., an access point or station) is connected directly to each of the others. In the partial mesh topology, one or more mesh nodes may be connected to all the others, but some of the mesh nodes are connected only to some of the other mesh nodes (e.g., those other mesh nodes with which they exchange the most data).
0006In a wireless LAN (“WLAN”), one or more of the connections between the mesh nodes is facilitated wirelessly. In order to extend the range of a WLAN, system administrators (or users) often connect a new wireless access point (wireless extender) to the network by connecting the wireless extender to another wireless access point (wireless root access point). There may be, however, multiple wireless root access points to which the wireless extender may wirelessly connect. Existing networks may provide no means by which to determine which wireless root access point in a network would provide the best connection for the wireless extender. Furthermore, the need for a user to input radio settings (e.g., channel, service set identifier, etc.) and privacy settings (e.g., authentication data, cipher data, key data, etc.) into the wireless extender increases the complexity and difficulty in extending the WLAN.
BRIEF DESCRIPTION OF THE DRAWINGS
0007The present invention is illustrated by way of example and not limitation in the figures of the accompanying drawings, in which like references indicate similar elements, and in which:
0008<figref idref="DRAWINGS">FIG. 1</figref> illustrates an exemplary mesh network in which embodiments of the Wireless Extender Secure Discovery and Provisioning may be implemented;
0009<figref idref="DRAWINGS">FIG. 2</figref> illustrates an exemplary mesh network in which a wireless extender may perform the dual roles of managing a basic service set and relaying traffic to a wireless root access point;
0010<figref idref="DRAWINGS">FIG. 3</figref> illustrates an exemplary wireless access point in which an embodiment of secure discovery and provisioning is implemented;
0011<figref idref="DRAWINGS">FIG. 4</figref> illustrates an exemplary exchange between a wireless extender and a wireless root access point according to an embodiment of secure discovery and provisioning;
0012<figref idref="DRAWINGS">FIG. 5</figref> is a flow chart illustrating an exemplary exchange between a wireless extender and a wireless root access point according to an embodiment of secure discovery and provisioning;
0013<figref idref="DRAWINGS">FIG. 6</figref> is an exemplary beacon frame format;
0014<figref idref="DRAWINGS">FIG. 7</figref> is an exemplary probe request frame format; and
0015<figref idref="DRAWINGS">FIG. 8</figref> is an exemplary probe response frame format.
DETAILED DESCRIPTION
0016In the following description, numerous specific details are set forth. However, it is understood that embodiments of the invention may be practiced without these specific details. In other instances, well-known circuits, structures and techniques have not been shown in detail in order not to obscure the understanding of this description.
0017References in the specification to “one embodiment,” “an embodiment,” “an example embodiment,” etc., indicate that the embodiment described may include a particular feature, structure, or characteristic, but every embodiment may not necessarily include the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to effect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
0018In the following description and claims, the terms “coupled” and “connected,” along with their derivatives, may be used. It should be understood that these terms are not intended as synonyms for each other. “Coupled” is used to indicate that two or more elements, which may or may not be in direct physical or electrical contact with each other, co-operate or interact with each other. “Connected” is used to indicate the establishment of communication between two or more elements that are coupled with each other. “Directly connected” is used to indicate the establishment of communication between two or more elements that are coupled with each other without an intervening node (e.g., two wireless access points in wireless communication without an intervening wireless access point).
0019According to an embodiment of the invention a first wireless access point (wireless extender) discovers a second wireless access point (wireless root access point); automatically, in response to the discovery of the second wireless access point, the first and second wireless access points exchange parameters; the first wireless access point tunes its radio and privacy settings, without user input, based upon the exchanged parameters; and a secure direct wireless connection is established between the first and second wireless access points using the radio and privacy settings. For one embodiment, wireless discovery and provisioning includes a determination of the best available wireless connection (e.g., signal strength, hop count, number of wireless stations already in the BSS of wireless root access point, etc.) to one of a number of wireless access points available for direct wireless connection. For one embodiment, the first wireless access point manages a basic service set and relays traffic from the basic service set to the second wireless access point.
0020As used herein, a basic service set (“BSS”) refers to a wireless access point and all stations associated with that access point. “Station” or “wireless station” is used herein to refer to a device that has the capability to connect for wireless and/or wired connection to the network via a wireless access point. For example, a station may be a laptop, a desktop computer, personal digital assistant (“PDA”), a phone, etc. As used herein, a mesh node refers to either a wireless access point or a station connected to a full or partial mesh network. “Wireless root access point” is used herein to refer to a wireless access point to which a wireless extender may establish a direct wireless connection (i.e., a wireless extender joins the BSS of the wireless root access point, and thus the wireless extender and wireless root access point are respectively a child mesh node and a parent mesh node). While the topmost node in a tree data structure is commonly referred to as the “root” node (i.e., it will not have a parent node), the use of the term “root” in “wireless root access point” herein is not so limited. There may be multiple wireless root access points in a network, a wireless root access point does not need to be the topmost node of the WLAN (e.g., a border mesh node as described below), and a wireless root access point may have a parent mesh node.
0021<figref idref="DRAWINGS">FIG. 1</figref> illustrates an exemplary partial mesh network in which embodiments of the Wireless Extender Secure Discovery and Provisioning are implemented. Embodiments discussed herein organize mesh nodes as a tree hierarchy (alternate embodiments may organize mesh nodes differently—e.g., graph, star, etc.).
0022For one embodiment, only one active border mesh node is present in this mesh network to connect all mesh nodes to an external environment (e.g., another LAN or WAN). This model simplifies the relationship among all mesh nodes in at least two aspects. First, routing will be very straightforward, only the route between child mesh node and parent mesh node will be allowed, and all outgoing traffic will be eventually forwarded to the active border mesh node for the data exchange with external networks. Second, only one active border mesh node is delegated to handle traffic exchange with the outer environment. As a result, gateway functionality such as network address translation (“NAT”) and bandwidth management can be easily deployed in the active border mesh node to control traffic. Additionally, for one embodiment, one or more other mesh nodes are appointed as standby border mesh nodes to switch over in case the active border mesh node loses power or does not function properly. In alternate embodiments, more than one active border mesh node is present.
0023Each leaf mesh node has at least one direct connection to communicate with its parent mesh node. <figref idref="DRAWINGS">FIG. 1</figref> illustrates a single pair of wireless access points in direct connection and implementing an embodiment of secure discovery and provisioning (“Secure D&P”). Secure D&P, however, may be implemented in one or more pairs of child and parent mesh nodes.
0024In a mesh network, in addition to having the capability of direct wired connections, a wireless access point may perform dual roles. First, the access point may manage a BSS as a regular wireless access point. If the wireless access point has the capability of establishing a direct wireless connection with a wireless extender such that the wireless access point's BSS includes the wireless extender (i.e., another wireless access point), the wireless access point managing the BSS acts as a wireless root access point. Second, the access point may act as a wireless extender and relay traffic (e.g., from its BSS or from another wireless access point) to a parent mesh node (e.g, another wireless root access point). As a result of these dual roles, multiple wireless access points are able to be wirelessly chained to extend the reach of a WLAN. Discovering and provisioning a secure direct connection between wireless access points in such a wireless chain will be addressed herein.
0025<figref idref="DRAWINGS">FIG. 2</figref> illustrates the dual actor mode of a wireless access point. Wireless access point AP<b>1</b> is acting as the parent mesh node of wireless access point AP<b>2</b>, and thus they are respectively a root wireless access point and a wireless extender. Wireless station STA<b>3</b> can either connect to wireless access point AP<b>1</b> or wireless access point AP<b>2</b> to join the network. For one embodiment, the determination of which wireless access point's BSS to join depends on the respective signal strength and/or other parameters (e.g., hop count, number of wireless stations already in the BSS, etc.) of their direct wireless connections. If wireless station STA<b>3</b> associates with wireless access point AP<b>1</b> (not shown), wireless access point AP<b>1</b> acts as a regular wireless access point to relay traffic to the external network LAN A. If wireless station STA<b>3</b> associates with wireless access point AP<b>2</b>, as illustrated, wireless access point AP<b>2</b> will relay data between wireless access point AP<b>2</b> and wireless access point AP<b>1</b>. Therefore, from the point view of wireless station STA<b>3</b>, wireless access point AP<b>1</b> has extended its radio coverage via relaying traffic from wireless access point AP<b>2</b>. In this scenario, wireless access point AP<b>1</b> is referred to as a wireless root access point and wireless access point AP<b>2</b> is referred to as a wireless extender. Thus, as used herein, a wireless extender refers to a wireless access point that, in this dual actor mode, is a member of the BSS of a wireless root access point and relays wireless traffic between its own BSS and the wireless root access point.
0026For example, wireless access point AP<b>1</b> and wireless access point AP<b>2</b> both manage respective BSS's. In the illustrated example wireless station STA<b>2</b> and wireless access point AP<b>2</b> are a part of wireless access point AP<b>1</b>'s BSS, and wireless station STA<b>3</b> is a part of wireless access point AP<b>2</b>'s BSS. Each wireless access point may have more or less wireless stations connected to its BSS and, as described below, wireless stations are able to roam between BSS's.
0027Embodiments of the wireless extender secure discovery and provisioning disclosed herein are implemented in the mesh nodes as illustrated in <figref idref="DRAWINGS">FIGS. 1 and 2</figref>. The wireless extender secure discovery and provisioning is responsible for discovery of a wireless root access point and self-tuning the wireless extender to establish a secure wireless connection with the wireless root access point. Additionally, a management channel can also be built on this wireless link to support administration, monitoring, and other management operations. For one embodiment, the discovery and provisioning is implemented in the IEEE 802.11 Media Access Control (“MAC”) layer and utilizes the IEEE 802.11 Management Frame to convey discovery and simple provisioning handshake information between the wireless extender and its wireless root access point (as described later herein). As used herein, IEEE 802.11 refers to all applicable protocols within the IEEE 802.11 family—e.g., IEEE 802.11a, 802.11b, 802.11g, 802.11i, 802.11n, etc.
0028For one embodiment, a network implements only one level of repeating. In other words, in a network that contains multiple wireless root access points R<sub>i </sub>(i=1 . . . M) and multiple wireless extenders X<sub>j </sub>(j=1 . . . N), any wireless extender X<sub>i </sub>joins the BSS of a wireless root access point R<sub>i </sub>instead of any other wireless extenders. Utilizing a single level repeating relationship, the R-X model, when more levels of repeating deployment is required, a user can easily replicate the functionality of this R-X model to form an R-X chain.
0029In an exemplary network deployment, radio and privacy settings include, for example, a service set identifier (“SSID”), authentication data, cipher data, key data, etc. Provisioning, as used herein, includes exchanging parameters over a direct secure channel and setting X<sub>j</sub>'s radio and privacy settings in order to establish a secure direct wireless connection between R<sub>i </sub>and X<sub>j </sub>based on these settings. In order to secure the channel between X<sub>j </sub>and R<sub>i </sub>and prevent versatile attacks, such as eavesdropping, man-in-the-middle, impersonating, replay, database reading, and many other known security holes, an embodiment of secure discovery and provisioning utilizes public-private key pairs to perform mutual authentication and to encrypt the communication channel using strong dynamic session key. Both parties have a public-private key pair <E, D>. Public key E will be used for encryption and private key D will be used for decryption, respectively. For one embodiment, for a given public-private key pair, it is relatively difficult to decrypt data encrypted with E without having D. Once the X<sub>j </sub>tunes itself to R<sub>i</sub>'s transmitted radio and privacy settings, a secure direct wireless connection is established and a wireless station can benefit from smooth roaming among BSS's of X<sub>j </sub>and R<sub>i </sub>without changing the wireless station's radio and privacy settings.
0030<figref idref="DRAWINGS">FIG. 3</figref> illustrates an exemplary wireless access point <b>300</b> in which an embodiment of secure discovery and provisioning is implemented. Wireless access point <b>300</b> is a dual actor, as described above, and can serve as either (or both) a wireless extender and wireless root access point (e.g., by having the capability of managing a BSS that includes another wireless extender). While wireless access point <b>300</b> may include additional/or different items, in the illustrated embodiment of wireless access point <b>300</b> includes one or more processors <b>305</b>, a memory <b>310</b>, and a wireless interface <b>315</b>, all coupled to one or more buses. Processor(s) <b>305</b> may be implemented in a variety of ways, including a single processor, multiple processors, a single processor including multiple functional processor cores (e.g., a multi-core processor), or a combination thereof. For one embodiment, memory <b>310</b> includes a machine-readable storage medium on which is stored one or more sets of instructions (e.g., software) embodying one or more methodologies or functions of the secure discovery and provisioning described herein, which is implemented by the processor(s) <b>305</b> executing the instructions stored in the memory <b>310</b>.
0031The processor <b>305</b> is illustrated as including multiple subcomponents, including the crypto engine <b>320</b>, routing engine <b>325</b>, discovery and provisioning engine <b>330</b>, and administration, management, and provisioning (“AM&P”) interface <b>335</b>, each of which will be described further below. Additionally, the processor <b>305</b> is further illustrated to include a protocol stack <b>340</b>, which interacts with the AM&P interface <b>335</b>. Each component has been illustrated as a separate functional block for ease of explanation of functionality of embodiments of the invention and not intended to be limiting—i.e., components could be combined or further separated, implemented in hardware and/or software, etc (e.g., as indicated above, one or more components may be implemented as instructions stored in memory <b>310</b> and executed by the processor(s) <b>305</b>). Alternatively, one or more of the components could be implemented separate from the processor(s) <b>305</b>. Also, additional components would normally be present but are not illustrated so as not to obscure one of ordinary skill in the art from understanding.
0032The crypto engine <b>320</b> provides random number generation, hashing, encryption, decryption, and other cryptography related functions. The routing engine <b>325</b> determines the best available wireless root access point when wireless access point <b>300</b> is acting as a wireless extender. The discovery and provisioning engine <b>330</b> manages the discovery of potential wireless root access points and provisioning of the wireless extender to establish a secure direct wireless connection with a wireless root access point. The AM&P interface <b>335</b> provides the interface to configure and monitor the protocol stack <b>340</b> (e.g., application programming interface (API) utilizing input/output control (“IOCTL”) commands to set parameters in an IEEE 802.11 management stack). The functionalities of crypto engine <b>320</b>, routing engine <b>325</b>, and discovery and provisioning engine <b>330</b>, as they relate to secure discovery and provisioning, will be further described below.
0033<figref idref="DRAWINGS">FIGS. 4 and 5</figref> illustrate an exemplary exchange between a wireless extender and a wireless root access point and corresponding method <b>500</b> according to an embodiment of secure discovery and provisioning. While <figref idref="DRAWINGS">FIGS. 4 and 5</figref> include a particular series of steps, alternate embodiments of the invention may implement fewer or more steps and/or perform one or more steps in a different order.
0034Wireless root access point R broadcasts beacon frames including an advertisement. Exemplary advertisement parameters include a protocol, software, and/or hardware version Vr for the wireless root access point, a hop count Hr, nonce Nr, client number (i.e, number of wireless stations already in the BSS) Cr, mean received signal strength indication (“RSSI”) value Mr, and the wireless root access point's public key Er.
0035At block <b>505</b>, a wireless extender X seeking to join a network will receive the broadcasted beacon. At block <b>510</b>, upon receipt of the beacon frame from R, if the discovery and provisioning engine <b>330</b> in X can successfully locate the advertisement, X will process the advertisement parameters. For example, X automatically performs, without user input, one or more of the following: verifying authenticity of public key Er and checking if version Vr in the advertisement is compatible with its own. For one embodiment, the crypto engine <b>320</b> utilizes a certificate authority installed within the wireless extender (e.g., when manufactured, prior to sale, etc.) or another authentication algorithm installed within the wireless extender to authenticate the public key Er. If the advertisement parameters are successfully processed (e.g., authenticated/compatible), X will assume R is a wireless root access point candidate and keep it in candidate list—e.g., stored in the memory <b>310</b>.
0036Upon determination that R is a candidate, the discovery and provisioning engine <b>330</b> in X will transmit a probe request including discovery parameters from the wireless extender at block <b>515</b>. Exemplary discovery parameters include protocol, software, and/or hardware version Vx for the wireless extender, a configuration checksum Sx, nonce Nx, the wireless extender's public key Ex, as well as a secret key K generated for session key computation. For one embodiment, the discovery parameters will be encrypted with public key Er. The generation of Nx and encryption of the discovery parameters are performed by crypto engine <b>320</b>.
0037Once R receives the probe request from X, R locates and decrypts the discovery parameters using its private key Dr (e.g., using its own crypto engine <b>320</b>). Wireless root access point R automatically, without user input, performs its own verification—e.g., verifying the authenticity of public key Ex, determining that version Vx in the discovery parameters is compatible with R's version Vr, and/or determining if checksum Cx is the same as a cached value (e.g., a checksum from a previously connected wireless extender). Similar to X, R may have a certificate authority or other known authentication algorithm installed within R (e.g., when manufactured, prior to sale, etc.) to verify the authenticity of Ex. For one embodiment, if checksum Cx is the same as the cached value, R will determine that X has been previously tuned to connect with R and is attempting to reassociate with R. In the case of reassociation, R sends the original/previously sent probe response management frame back to X. Otherwise, if checksum Cx is not the same as the cached value, R will compute a session key based on the discovery parameters from X (as described with reference to block <b>520</b> below).
0038Both wireless extender X and wireless root access point R compute a session key S based on the same function at block <b>520</b>—e.g., both wireless access points are programmed, prior to the discovery process (e.g., when manufactured, prior to sale, etc.), to utilize the same function or formula to compute the session key. For one embodiment, each wireless access point's crypto engine <b>320</b> computes the session key using the function S=PRF(Nr, Br, Nx, Bx, K). For one embodiment, pseudorandom function PRF is any industrial encryption method, such as Data Encryption Standard (“DES”), Triple DES, Advanced Encryption Standard (“AES”), etc. Br and Bx are SSID's for R and X respectively, which can be collected from the beacon and probe request. K is the secret key generated by X. For one embodiment, K includes a random number and the wireless root access point protocol, software, and/or hardware version version Vr.
0039After computing the session key S, R transmits a probe response. The payload of the probe response is an offer O, which includes offer parameters for the configuration of radio and privacy settings for X. Alternatively, parameters for the configuration of radio and privacy settings may be included in separate transmissions. For example, radio settings, e.g., the SSID for R, may be included in the beacon while the privacy settings, e.g., authentication data, cipher data, key data, etc., may be included in the probe response.
0040For one embodiment, the offer O is encrypted with wireless extender X public key Ex and then encrypted with the session key S. For one embodiment, the offer is encrypted only with the session key S. For one embodiment, a Message Integrity Check (“MIC”) is appended to the offer to prevent inadvertent modification to the data. For one embodiment, MIC=HMAC−MD5(O, S). Alternatively, MIC implements another hash function or cryptographic hash function for message authentication. At block <b>525</b>, X receives the probe response.
0041If there are multiple candidate wireless root access points, the routing engine <b>325</b> in X determines that R is the best of multiple candidates with which to establish a wireless connection at block <b>530</b>. For one embodiment, X will traverse its candidate list to select the best candidate to join after X receives the probe response from R and other wireless root access points. Alternatively, the determination of which candidate to join is made at an earlier stage—e.g., after receiving the beacon. The determination of the best candidate is based on one or more of the following: peer signal strength Rr/Mr, hop count Hr, or client number Cr. For example, each retransmission (hop) can equate to a reduction in the maximum wireless effective throughput as well as a time delay. Additionally, the number of clients already associated with R provides an indication of the amount of bandwidth currently consumed in R's BSS.
0042For another embodiment, the determination of the best candidate is based upon signal strength alone (e.g., strongest RSSI value). Alternatively, the following equation provides an exemplary method by which X chooses the best root access point: <ul id="ul0001" list-style="none"><li id="ul0001-0001" num="0043">Ri: RSSI value measured from wireless root access point i</li><li id="ul0001-0002" num="0044">Ci: Client number (i.e., number of wireless stations already in the BSS of wireless root access point i)</li><li id="ul0001-0003" num="0045">Hi: Hop count of wireless root access point i</li><li id="ul0001-0004" num="0046">Mi: Mean RSSI value from wireless root access point i</li><li id="ul0001-0005" num="0047">Pi: Weight of Client number associated with wireless root access point i</li></ul>
0000<maths id="MATH-US-00001" num="00001"><math overflow="scroll"><mrow><mi>Pi</mi><mo>=</mo><mrow><mi>Ci</mi><mo>/</mo><mrow><munderover><mo>∑</mo><mrow><mi>j</mi><mo>=</mo><mn>0</mn></mrow><mi>n</mi></munderover><mo></mo><mstyle><mspace width="0.3em" height="0.3ex" /></mstyle><mo></mo><mrow><mi>Cj</mi><mo></mo><mstyle><mspace width="0.6em" height="0.6ex" /></mstyle><mo></mo><mrow><mo>(</mo><mstyle><mspace width="0.em" height="0.ex" /></mstyle><mo></mo><mrow><mi>n</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>is</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>the</mi><mo></mo><mrow><mstyle><mspace width="0.6em" height="0.6ex" /></mstyle><mo></mo><mstyle><mspace width="0.3em" height="0.3ex" /></mstyle></mrow><mo></mo><mi>total</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>number</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>of</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>wireless</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>root</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>access</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>points</mi></mrow><mo>)</mo></mrow></mrow></mrow></mrow></mrow></math></maths><img file="US2014086215A1_D0001.tif" /><ul id="ul0002" list-style="none"><li id="ul0002-0001" num="0048">Qi: Weight of Hop Count of wireless root Access Point</li></ul>
0000<maths id="MATH-US-00002" num="00002"><math overflow="scroll"><mrow><mi>Qi</mi><mo>=</mo><mrow><mi>Hi</mi><mo>/</mo><mrow><munderover><mo>∑</mo><mrow><mi>j</mi><mo>=</mo><mn>0</mn></mrow><mi>n</mi></munderover><mo></mo><mstyle><mspace width="0.3em" height="0.3ex" /></mstyle><mo></mo><mrow><mi>Hj</mi><mo></mo><mstyle><mspace width="0.6em" height="0.6ex" /></mstyle><mo></mo><mrow><mo>(</mo><mstyle><mspace width="0.em" height="0.ex" /></mstyle><mo></mo><mrow><mi>n</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>is</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>the</mi><mo></mo><mrow><mstyle><mspace width="0.6em" height="0.6ex" /></mstyle><mo></mo><mstyle><mspace width="0.3em" height="0.3ex" /></mstyle></mrow><mo></mo><mi>total</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>number</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>of</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>wireless</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>root</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>access</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mi>points</mi></mrow><mo>)</mo></mrow></mrow></mrow></mrow></mrow></math></maths><img file="US2014086215A1_D0002.tif" /><ul id="ul0003" list-style="none"><li id="ul0003-0001" num="0049">Di and Wi: Weight of signal strength of wireless root access point</li><li id="ul0003-0002" num="0050">Di=Mi−Ri</li><li id="ul0003-0003" num="0051">Wi=1+Mi/Ri (if Di>=0)</li><li id="ul0003-0004" num="0052">Wi=1+Mi/Ri (if Di<=0)</li><li id="ul0003-0005" num="0053">Si: Weight of candidate (selection)</li><li id="ul0003-0006" num="0054">Si=Di*Wi*Pi*Qi</li></ul>
0055Wireless extender X will use the equation above to determine that the wireless root access point R has the largest weight Si (or similar determination) and, therefore, is the best candidate.
0056Upon selecting R, the crypto engine <b>320</b> in X decrypts R's offer parameters using the session key S computed by X at block <b>535</b>. Additionally, if utilizing multiple layers of encryption (e.g. the offer is encrypted with both S and Ex), X also decrypts the offer parameters using private key Dx.
0057Wireless extender X computes MIC, using the same formula as R, to check the integrity of the data sent from wireless root access point R. If the received MIC is verified, X will tune itself using the privacy settings embedded in the offer parameters at block <b>540</b>. The privacy settings enable X to be a valid wireless client to continue authentication and association/reassociation with R. Additionally, the privacy settings enable wireless stations to roam between the BSS of R and the BSS of X (as well as other wireless access points within the network that share the same privacy settings).
0058For one embodiment, the rest of the management frames (e.g., according to IEEE 802.11), including Authentication and Association/Reassociation, are kept intact. Once the association request and response are completed, the secure direct wireless connection is established between R and X, and X can begin to relay traffic to R at block <b>545</b>. If the privacy settings include Wi-Fi Protected Access (“WPA/WPA2”) encryption, the WPA/WPA2 handshake will continue to play until the wireless link is established.
0059For one embodiment, R will continue to listen to the probe request from X, and once it determines that the configuration checksum Cx does not match the cached value within R, R will send out a probe response with an offer to provision extender X again. This ensures the extender X can continue to synchronize with the radio and privacy settings from R to maintain a valid and secure direct wireless connection with R.
0060For an embodiment utilizing IEEE 802.11, element ID's 7-15 and 32-255 are reserved for vendors to implement proprietary features. For one embodiment, element ID <b>7</b> is utilized for the beacon, element ID <b>8</b> is utilized for probe request, and element ID <b>9</b> is utilized for the probe response. Alternatively, various other arrangements of the beacon, probe request, and probe response within the proprietary element ID's are utilized. For one embodiment, an Organizationally Unique Identifier (“OUI”) or other unique identifier is included in the information elements to distinguish each of the wireless access points from others. <figref idref="DRAWINGS">FIGS. 6-8</figref> illustrate exemplary formats for each of these three elements.
0061<figref idref="DRAWINGS">FIG. 6</figref> is an exemplary format of an beacon frame as described above with reference to block <b>505</b> of <figref idref="DRAWINGS">FIG. 5</figref>. The advertisement is concatenated to the regular 802.11 beacon field(s). The advertisement parameters include element ID (1 byte), Length (1 byte) to indicate the length of total advertisement, OUI (3 bytes) to specify vendor ID, and a payload field. The payload includes fields for protocol, software, and/or hardware version (1 byte), hop count (1 byte), nonce (4 bytes), number of wireless stations already in the BSS (“Client Count”) (1 byte), mean RSSI (1 byte) and the wireless root access point's public key (48 bytes).
0062<figref idref="DRAWINGS">FIG. 7</figref> is an exemplary format of a probe request frame as described above with reference to block <b>515</b> of <figref idref="DRAWINGS">FIG. 5</figref>. The discovery is concatenated to the regular 802.11 probe request field(s). The discovery parameters include element ID (1 byte), Length (1 byte) to indicate the length of total discovery, OUI (3 bytes) to specify vendor ID, and an encrypted payload field. The payload includes fields for protocol, software, and/or hardware version (1 byte), configuration checksum (4 bytes), nonce (4 bytes), the wireless extender's public key (48 bytes), and the secret key K (48 bytes).
0063<figref idref="DRAWINGS">FIG. 8</figref> is an exemplary format of a probe response frame as described above with reference to block <b>525</b> of <figref idref="DRAWINGS">FIG. 5</figref>. The offer is concatenated to the regular 802.11 probe response field(s). The offer parameters include Element ID (1 byte), Length (1 byte) to indicate the length of total offer, OUI (3 bytes) to specify vendor ID, an encrypted payload field, and a MIC (8 bytes). The payload includes a privacy settings field, which includes fields for authentication (e.g., open, shared, both, WPA-PSK, WPA-EAP) (4 bits), cipher (e.g., WEP, TKIP, AES) (4 bits), WEP key index (2 bits), active WEP key value (128 bits), WPA pass key (320 bits), Remote Authentication Dial In User Service (“RADIUS”) server IP address (32 bits), RADIUS server port (16 bits) and RADIUS server secret (64 bytes).
0064In the foregoing specification, the invention has been described with reference to specific exemplary embodiments thereof. It will be evident that various modifications may be made thereto without departing from the broader spirit and scope of the invention as set forth in the following claims. For example, different byte lengths and ordering of the frame formats described above can be implemented. Additionally, while the description above is focused on secure discovery and provisioning among access points, embodiments of the secure discovery and provisioning described herein applies to discovery and provisioning of a secure connection between other wireless devices as well.
0065An article of manufacture may be used to store program code providing at least some of the functionality of the embodiments described above. An article of manufacture that stores program code (i.e., a computer-readable storage medium or machine-readable storage medium) may be embodied as, but is not limited to, one or more memories (e.g., one or more flash memories, random access memories—static, dynamic, or other), optical disks, CD-ROMs, DVD-ROMs, EPROMs, EEPROMs, magnetic or optical cards or other type of machine-readable storage media suitable for storing electronic instructions. A machine-readable storage medium, as used herein, refers to a tangible device and not to a carrier wave. Additionally, embodiments of the invention may be implemented in, but not limited to, hardware or firmware utilizing an FPGA, ASIC, a processor, a computer, or a computer system including a network. Modules and components of hardware or software implementations can be divided or combined without significantly altering embodiments of the invention. The specification and drawings are, accordingly, to be regarded in an illustrative sense rather than a restrictive sense.
Contents4
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2014282909A1 | Cited by | United States of America | Pre-grant |
| US2017272273A1 | Cited by | United States of America | Pre-grant |
| US9531543B2 | Cited by | United States of America | Applicant |
| US2015334598A1 | Cited by | United States of America | Search report |
| US9510271B2 | Cited by | United States of America | Applicant |
| US9392458B2 | Cited by | United States of America | Search report |
| US11159941B2 | Cited by | United States of America | Applicant |
| KR20170012373A | Cited by | Republic of Korea | Search report |
| US2023299954A1 | Cited by | United States of America | Search report |
| US11871295B2 | Cited by | United States of America | Applicant |
| US9668200B2 | Cited by | United States of America | Applicant |
| US11146910B2 | Cited by | United States of America | Applicant |
| US2015334598A1 | Cited by | United States of America | Pre-grant |
| US10504148B2 | Cited by | United States of America | Applicant |
| US10931477B2 | Cited by | United States of America | Search report |
| US12302189B2 | Cited by | United States of America | Applicant |
| US2011274029A1 | Cited by | United States of America | Pre-grant |
| US10123257B2 | Cited by | United States of America | Applicant |
| US11562397B2 | Cited by | United States of America | Applicant |
| CN106465125A | Cited by | China | Search report |
| US2013235792A1 | Cited by | United States of America | Pre-grant |
| US2015341794A1 | Cited by | United States of America | Pre-grant |
| US9066287B2 | Cited by | United States of America | Applicant |
| US9794796B2 | Cited by | United States of America | Applicant |
| US9363671B2 | Cited by | United States of America | Applicant |
| US9071993B1 | Cited by | United States of America | Search report |
| CN106507346A | Cited by | China | Search report |
| US10880675B2 | Cited by | United States of America | Search report |
| US10142847B2 | Cited by | United States of America | Search report |
| US2004246922A1 | Cites | United States of America | Pre-grant |
| US2007091864A1 | Cites | United States of America | Pre-grant |
| US2008266160A1 | Cites | United States of America | Pre-grant |
| US8363617B2 | Cites | United States of America | Pre-grant |
10 members in 1 office
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 29179009 | United States of America | P | |
| 72436310 | United States of America | A | |
| 201213478003 | United States of America | A |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| US2011158127A1 | United States of America | A1 | |
| US8189608B2 | United States of America | B2 | |
| US2012230491A1 | United States of America | A1 | |
| US8594109B2 | United States of America | B2 | |
| US2014086215A1 | United States of America | A1 | |
| US8908706B2 | United States of America | B2 | |
| US2015055501A1 | United States of America | A1 | |
| US9668200B2 | United States of America | B2 | |
| US2017257818A1 | United States of America | A1 | |
| US10123257B2 | United States of America | B2 |
49 transactions on the USPTO file
Allowed without a rejection on record.
- Non-final rejections
- 0
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Maintenance Fee Reminder MailedREM. | REM. | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| 7.5 yr surcharge - late pmt w/in 6 mo, Large EntityM1555 | M1555 | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Maintenance Fee Reminder MailedREM. | REM. | |
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.ADB | C.ADB | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Email NotificationEML_NTR | EML_NTR | |
| Printer Rush- No mailingTCPB | TCPB | |
| Mail Response to 312 Amendment (PTO-271)MN271 | MN271 | |
| Response to Amendment under Rule 312N271 | N271 | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Amendment after Notice of Allowance (Rule 312)AllowedA.NA | A.NA | |
| Supplemental Papers - Oath or DeclarationC600 | C600 | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Reasons for AllowanceEX.R | EX.R | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| FITF set to NO - revise initial settingFTFI | FTFI | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Application Is Now CompleteCOMP | COMP | |
| Sent to Classification ContractorPGPC | PGPC | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Entity status set to undiscounted (initial default setting or status change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
64 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee payment procedure7.5 YR SURCHARGE - LATE PMT W/IN 6 MO, LARGE ENTITY (ORIGINAL EVENT CODE: M1555); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Maintenance fee paymentMAFP | MAFP | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 20140086215
- Application
- 14089593
Titles
- English
- WIRELESS EXTENDER SECURE DISCOVERY AND PROVISIONING
Patent term adjustment
- Applicant delay
- −67 days
- Net adjustment
- 0 days
Classification
- CPC, 11
- H04W48/20
- H04W48/16
- H04W48/10
- H04L63/061
- H04W24/02
- H04W36/30
- H04W84/12
- H04W92/20
- H04W12/50
- H04W12/04
- H04W24/08
- IPC, 2
- H04W48 20
- H04W36 30