Method and apparatus for providing wireless service groups

US2016150412A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016150412-A1
Application numberUS-201514947782-A
CountryUS
Kind codeA1
Filing dateNov 20, 2015
Priority dateNov 21, 2014
Publication dateMay 26, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The disclosed embodiments provide a system that provides wireless service groups. During operation, a wireless device's advertising mechanism advertises a service group over Wi-Fi, wherein the service group comprises at least the wireless device and wherein the service group's security requirements regulate multicast protection within the service group. In response to receiving a request from a second device to be admitted into the service group, the wireless device's security mechanism admits the second device into the service group and sends the service group's security requirements to the second device, thereby enabling the second device to initialize multicast protection in accordance with the service group's security requirements.

First claim

Opening claim text (preview).

What is claimed is: 1 . A wireless device, the device comprising: a processor; a memory coupled to the processor; a Wi-Fi transceiver coupled to the processor; an advertising mechanism, configured to advertise a service group over Wi-Fi, wherein the service group comprises at least the device and wherein the service group's security requirements regulate multicast protection within the service group; and a security mechanism, configured to admit a second device into the service group and send the service group's security requirements to the second device, thereby enabling the second device to initialize multicast protection in accordance with the service group's security requirements. 2 . The device of claim 1 , wherein the device further comprises a local service endpoint configured to send the local service endpoint's security requirements to the security mechanism; and wherein the service group's security requirements accommodate the local service endpoint's security requirements. 3 . The device of claim 2 , wherein the security mechanism is further configured to form the service group in response to the establishment of a Wi-Fi connection between the device and a third device; and wherein, in addition to accommodating the local service endpoint's security requirements, the service group's security requirements accommodate security requirements obtained from the third device. 4 . The device of claim 1 , wherein the security mechanism is further configured to designate the second device as an authorized member, thereby enabling the second device to perform at least one of the following: advertise the service group to a new device; admit the new device into the service group; and deliver security information to the new device. 5 . The device of claim 4 , wherein the second device is further enabled to perform at least one of the following to facilitate pairwise authentication between the new device and other members of the service group: deliver a group shared key to the new device; and deliver authentication material to the new device. 6 . The device of claim 1 , wherein in addition to regulating multicasting within the service group, the service group's security requirements regulate security configurations of Wi-Fi connections within the service group. 7 . The device of claim 6 , wherein the security mechanism is further configured to prevent a fourth device from being admitted into the service group in response to determining that security requirements obtained from the fourth device are incompatible with the service group's security requirements. 8 . A computer-implemented method for managing a service group from a first device: advertising the service group over Wi-Fi, wherein the service group comprises at least the first device and wherein the service group's security requirements regulate multicast protection within the service group; and admitting a second device into the service group and sending the service group's security requirements to the second device, thereby enabling the second device to initialize multicast protection in accordance with the service group's security requirements. 9 . The computer-implemented method of claim 8 , wherein the service group's security requirements accommodate security requirements of a service endpoint that runs on the first device. 10 . The computer-implemented method of claim 9 , further comprising, prior to advertising the service group, forming the service group in response to the establishment of a Wi-Fi connection between the first device and a third device; and wherein, in addition to accommodating the service endpoint's security requirements, the service group's security requirements accommodate security requirements obtained from the third device. 11 . The computer-implemented method of claim 8 , further comprising designating the second device as an authorized member, thereby enabling the second device to perform at least one of the following: advertise the service group to a new device; admit the new device into the service group; and deliver security information to the new device. 12 . The computer-implemented method of claim 11 , wherein the second device is further enabled to perform at least one of the following to facilitate pairwise authentication between the new device and other members of the service group: deliver a group shared key to the new device; and deliver authentication material to the new device. 13 . The computer-implemented method of claim 8 , wherein in addition to regulating multicasting within the service group, the service group's security requirements regulate security configurations of Wi-Fi connections within the service group. 14 . The computer-implemented method of claim 13 , further comprising preventing a fourth device from being admitted into the service group in response to determining that security requirements obtained from the fourth device are incompatible with the service group's security requirements. 15 . A non-transitory computer-readable medium storing instructions that, when executed by a computer, cause the computer to perform a method for managing a service group from a first device, the method comprising: advertising the service group over Wi-Fi, wherein the service group comprises at least the first device and wherein the service group's security requirements regulate multicast protection within the service group; and admitting a second device into the service group and sending the service group's security requirements to the second device, thereby enabling the second device to initialize multicast protection in accordance with the service group's security requirements. 16 . The non-transitory computer-readable medium of claim 15 , wherein the service group's security requirements accommodate security requirements of a service endpoint that runs on the first device. 17 . The non-transitory computer-readable medium of claim 16 , wherein the method further comprises, prior to advertising the service group, forming the service group in response to the establishment of a Wi-Fi connection between the first device and a third device; and wherein, in addition to accommodating the service endpoint's security requirements, the service group's security requirements accommodate security requirements obtained from the third device. 18 . The non-transitory computer-readable medium of claim 15 , wherein the method further comprises designating the second device as an authorized member, thereby enabling the second device to perform at least one of the following: advertise the service group to a new device; admit the new device into the service group; and deliver security information to the new device. 19 . The non-transitory computer-readable medium of claim 18 , wherein the second device is further enabled to perform at least one of the following to facilitate pairwise authentication between the new device and other members of the service group: deliver a group shared key to the new device; and deliver authentication material to the new device. 20 . The non-transitory computer-readable medium of claim 15 , wherein in addition to regulating multicasting within the service group, the service group's security requirements regulate security configurations of Wi-Fi connections within the service group.

Assignees

Inventors

Classifications

  • Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

  • WLAN [Wireless Local Area Networks] · CPC title

  • for group communications (cryptographic mechanisms or cryptographic arrangements for key management involving conference or group key H04L9/0833) · CPC title

  • H04W12/08Primary

    Access security · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016150412A1 cover?
The disclosed embodiments provide a system that provides wireless service groups. During operation, a wireless device's advertising mechanism advertises a service group over Wi-Fi, wherein the service group comprises at least the wireless device and wherein the service group's security requirements regulate multicast protection within the service group. In response to receiving a request from a…
Who is the assignee on this patent?
Apple Inc
What technology area does this patent fall under?
Primary CPC classification H04W12/08. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu May 26 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).