Method and apparatus for gaining access in wireless lan system
US-2015230245-A1 · Aug 13, 2015 · US
US2016295409A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016295409-A1 |
| Application number | US-201514680023-A |
| Country | US |
| Kind code | A1 |
| Filing date | Apr 6, 2015 |
| Priority date | Apr 6, 2015 |
| Publication date | Oct 6, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method, an apparatus, and a computer program product for wireless communication are provided. The apparatus may be a STA. The STA sends, in a re-association procedure, a re-association object to a first AP to establish a first security association with the first AP. The re-association object is encrypted by using a first key unknown to the STA. The re-association object includes a second key derived from a second security association in a previous association procedure between the STA and a second AP. The STA receives a response from the first AP indicating that the first security association has been successfully established. The STA authenticates the response.
Opening claim text (preview).
What is claimed is: 1 . A method of wireless communication at a station (STA), comprising: sending, in a re-association procedure, a re-association object to a first access point (AP) to establish a first security association with the first AP, wherein the re-association object is encrypted by using a first key unknown to the STA, and wherein the re-association object includes a second key derived from a second security association in a previous association procedure between the STA and a second AP; receiving a response from the first AP indicating that the first security association has been successfully established; and authenticating the response. 2 . The method of claim 1 , comprising: deriving, in the previous association procedure, the second key with the second AP; establishing the second security association with the second AP corresponding to the second key; and receiving the re-association object from the second AP. 3 . The method of claim 2 , wherein the second security association is a robust security network association (RSNA). 4 . The method of claim 2 , wherein the second key is a pairwise transient key (PTK), wherein the second security association is a PTK security association, and wherein the re-association object includes information specifying the PTK security association including the PTK. 5 . The method of claim 1 , wherein the re-association object includes first device specific information, wherein the re-association object is included in a re-association request message sent from the STA to the first AP, and wherein the re-association request message further includes second device specific information associated with the STA. 6 . The method of claim 5 , wherein the first and second device specific information each include a media access control (MAC) address. 7 . The method of claim 1 , wherein the first AP and the second AP are a same AP. 8 . The method of claim 1 , comprising: receiving a re-association identifier associated with the first key from the first AP; and determining that the re-association identifier received from the first AP matches a re-association identifier of the re-association object, wherein the sending the re-association object to the first AP is in response to determining that the re-association identifier received from the first AP matches the re-association identifier of re-association object. 9 . The method of claim 1 , wherein the response is encrypted by using the second key, wherein the authenticating the response includes decrypting the re-association response message by using the second key. 10 . The method of claim 1 , comprising: deriving, in the re-association procedure, a third key with the first AP; establishing the first security association with the first AP corresponding to the third key, wherein the response is encrypted by using the third key, and wherein the authenticating the response includes decrypting the re-association response message by using the third key. 11 . A method of wireless communication at an access point (AP), comprising: receiving, in a re-association procedure, a re-association object from a station (STA) for establishing a first security association with the AP, wherein the re-association object is encrypted by using a first key unknown to the STA, and wherein the re-association object includes a second key derived from a second security association in a previous association procedure between the STA and an AP; authenticating the re-association object based on the first key and the second key; establishing, in response to successfully authenticating the re-association object, the first security association with the STA; and sending a response to the STA indicating the established first security association. 12 . The method of claim 11 , comprising: deriving, in the previous association procedure, the second key with the STA; establishing the second security association with the STA corresponding to the second key; generating the re-association object; encrypting the re-association object by using the first key; and sending the re-association object to the STA. 13 . The method of claim 12 , wherein the second key is a pairwise transient key (PTK), wherein the second security association is a PTK security association, the method further comprising: including in the re-association object information specifying the PTK security association. 14 . The method of claim 12 , comprising: obtaining, in the previous association procedure, a pairwise master key (PMK); establishing a PMK security association with the STA corresponding to the PMK; and including in the re-association object information specifying the PMK security association. 15 . The method of claim 12 , comprising: receiving, in the previous association procedure, first device specific information from the STA and including the first device specific information in the re-association object; obtaining an internet protocol (IP) address for the STA and including the IP address in the re-association object; generating an integrity code of data of the re-association object by using the first key; and including the integrity code in the re-association object. 16 . The method of claim 11 , wherein the re-association object includes first device specific information, wherein the re-association object is included in a re-association request message received from the STA, and wherein the re-association request message further includes second device specific information associated with the STA, the method further comprising: authenticating, in the re-association procedure, the re-association object based on matching the first device specific information with the second device specific information. 17 . The method of claim 11 , comprising: retrieving, in the re-association procedure, the second key from the re-association object, wherein the first security association is established according to the second key; and encrypting the response by using the second key. 18 . The method of claim 11 , comprising: deriving, in the re-association procedure, a third key with the STA, wherein the first security association is established according to the third key; and encrypting the response by using the third key. 19 . The method of claim 11 , comprising: retrieving, in the re-association procedure, an integrity code from the re-association object; and verifying integrity of data of the re-association object by using the first key and the integrity code. 20 . The method of claim 11 , comprising: retrieving, in the re-association procedure, an indication of time from the re-association object; and determining whether the re-association object is expired based on the retrieved indication of time. 21 . An apparatus for wireless communication, the apparatus being a station (STA), comprising: means for sending, in a re-association procedure, a re-association object to a first access point (AP) to establish a first security association with the first AP, wherein the re-association object is encrypted by using a first key unknown to the STA, and wherein the re-association object includes a second key derived from a second security association in a previous association procedure between the STA and a second AP; means for receiving a response from the first AP indicating that the first security association has been successfully established; and means for authenticating the response.
Access point devices · CPC title
Authentication · CPC title
wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title
Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title
WLAN [Wireless Local Area Networks] · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.