Schedule selection and connection setup between devices participating in a nan data link
US-2016286574-A1 · Sep 29, 2016 · US
US2016150412A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016150412-A1 |
| Application number | US-201514947782-A |
| Country | US |
| Kind code | A1 |
| Filing date | Nov 20, 2015 |
| Priority date | Nov 21, 2014 |
| Publication date | May 26, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
The disclosed embodiments provide a system that provides wireless service groups. During operation, a wireless device's advertising mechanism advertises a service group over Wi-Fi, wherein the service group comprises at least the wireless device and wherein the service group's security requirements regulate multicast protection within the service group. In response to receiving a request from a second device to be admitted into the service group, the wireless device's security mechanism admits the second device into the service group and sends the service group's security requirements to the second device, thereby enabling the second device to initialize multicast protection in accordance with the service group's security requirements.
Opening claim text (preview).
What is claimed is: 1 . A wireless device, the device comprising: a processor; a memory coupled to the processor; a Wi-Fi transceiver coupled to the processor; an advertising mechanism, configured to advertise a service group over Wi-Fi, wherein the service group comprises at least the device and wherein the service group's security requirements regulate multicast protection within the service group; and a security mechanism, configured to admit a second device into the service group and send the service group's security requirements to the second device, thereby enabling the second device to initialize multicast protection in accordance with the service group's security requirements. 2 . The device of claim 1 , wherein the device further comprises a local service endpoint configured to send the local service endpoint's security requirements to the security mechanism; and wherein the service group's security requirements accommodate the local service endpoint's security requirements. 3 . The device of claim 2 , wherein the security mechanism is further configured to form the service group in response to the establishment of a Wi-Fi connection between the device and a third device; and wherein, in addition to accommodating the local service endpoint's security requirements, the service group's security requirements accommodate security requirements obtained from the third device. 4 . The device of claim 1 , wherein the security mechanism is further configured to designate the second device as an authorized member, thereby enabling the second device to perform at least one of the following: advertise the service group to a new device; admit the new device into the service group; and deliver security information to the new device. 5 . The device of claim 4 , wherein the second device is further enabled to perform at least one of the following to facilitate pairwise authentication between the new device and other members of the service group: deliver a group shared key to the new device; and deliver authentication material to the new device. 6 . The device of claim 1 , wherein in addition to regulating multicasting within the service group, the service group's security requirements regulate security configurations of Wi-Fi connections within the service group. 7 . The device of claim 6 , wherein the security mechanism is further configured to prevent a fourth device from being admitted into the service group in response to determining that security requirements obtained from the fourth device are incompatible with the service group's security requirements. 8 . A computer-implemented method for managing a service group from a first device: advertising the service group over Wi-Fi, wherein the service group comprises at least the first device and wherein the service group's security requirements regulate multicast protection within the service group; and admitting a second device into the service group and sending the service group's security requirements to the second device, thereby enabling the second device to initialize multicast protection in accordance with the service group's security requirements. 9 . The computer-implemented method of claim 8 , wherein the service group's security requirements accommodate security requirements of a service endpoint that runs on the first device. 10 . The computer-implemented method of claim 9 , further comprising, prior to advertising the service group, forming the service group in response to the establishment of a Wi-Fi connection between the first device and a third device; and wherein, in addition to accommodating the service endpoint's security requirements, the service group's security requirements accommodate security requirements obtained from the third device. 11 . The computer-implemented method of claim 8 , further comprising designating the second device as an authorized member, thereby enabling the second device to perform at least one of the following: advertise the service group to a new device; admit the new device into the service group; and deliver security information to the new device. 12 . The computer-implemented method of claim 11 , wherein the second device is further enabled to perform at least one of the following to facilitate pairwise authentication between the new device and other members of the service group: deliver a group shared key to the new device; and deliver authentication material to the new device. 13 . The computer-implemented method of claim 8 , wherein in addition to regulating multicasting within the service group, the service group's security requirements regulate security configurations of Wi-Fi connections within the service group. 14 . The computer-implemented method of claim 13 , further comprising preventing a fourth device from being admitted into the service group in response to determining that security requirements obtained from the fourth device are incompatible with the service group's security requirements. 15 . A non-transitory computer-readable medium storing instructions that, when executed by a computer, cause the computer to perform a method for managing a service group from a first device, the method comprising: advertising the service group over Wi-Fi, wherein the service group comprises at least the first device and wherein the service group's security requirements regulate multicast protection within the service group; and admitting a second device into the service group and sending the service group's security requirements to the second device, thereby enabling the second device to initialize multicast protection in accordance with the service group's security requirements. 16 . The non-transitory computer-readable medium of claim 15 , wherein the service group's security requirements accommodate security requirements of a service endpoint that runs on the first device. 17 . The non-transitory computer-readable medium of claim 16 , wherein the method further comprises, prior to advertising the service group, forming the service group in response to the establishment of a Wi-Fi connection between the first device and a third device; and wherein, in addition to accommodating the service endpoint's security requirements, the service group's security requirements accommodate security requirements obtained from the third device. 18 . The non-transitory computer-readable medium of claim 15 , wherein the method further comprises designating the second device as an authorized member, thereby enabling the second device to perform at least one of the following: advertise the service group to a new device; admit the new device into the service group; and deliver security information to the new device. 19 . The non-transitory computer-readable medium of claim 18 , wherein the second device is further enabled to perform at least one of the following to facilitate pairwise authentication between the new device and other members of the service group: deliver a group shared key to the new device; and deliver authentication material to the new device. 20 . The non-transitory computer-readable medium of claim 15 , wherein in addition to regulating multicasting within the service group, the service group's security requirements regulate security configurations of Wi-Fi connections within the service group.
Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title
WLAN [Wireless Local Area Networks] · CPC title
for group communications (cryptographic mechanisms or cryptographic arrangements for key management involving conference or group key H04L9/0833) · CPC title
Access security · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.