Wireless network fast authentication / association using re-association object

US2016295409A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016295409-A1
Application numberUS-201514680023-A
CountryUS
Kind codeA1
Filing dateApr 6, 2015
Priority dateApr 6, 2015
Publication dateOct 6, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method, an apparatus, and a computer program product for wireless communication are provided. The apparatus may be a STA. The STA sends, in a re-association procedure, a re-association object to a first AP to establish a first security association with the first AP. The re-association object is encrypted by using a first key unknown to the STA. The re-association object includes a second key derived from a second security association in a previous association procedure between the STA and a second AP. The STA receives a response from the first AP indicating that the first security association has been successfully established. The STA authenticates the response.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method of wireless communication at a station (STA), comprising: sending, in a re-association procedure, a re-association object to a first access point (AP) to establish a first security association with the first AP, wherein the re-association object is encrypted by using a first key unknown to the STA, and wherein the re-association object includes a second key derived from a second security association in a previous association procedure between the STA and a second AP; receiving a response from the first AP indicating that the first security association has been successfully established; and authenticating the response. 2 . The method of claim 1 , comprising: deriving, in the previous association procedure, the second key with the second AP; establishing the second security association with the second AP corresponding to the second key; and receiving the re-association object from the second AP. 3 . The method of claim 2 , wherein the second security association is a robust security network association (RSNA). 4 . The method of claim 2 , wherein the second key is a pairwise transient key (PTK), wherein the second security association is a PTK security association, and wherein the re-association object includes information specifying the PTK security association including the PTK. 5 . The method of claim 1 , wherein the re-association object includes first device specific information, wherein the re-association object is included in a re-association request message sent from the STA to the first AP, and wherein the re-association request message further includes second device specific information associated with the STA. 6 . The method of claim 5 , wherein the first and second device specific information each include a media access control (MAC) address. 7 . The method of claim 1 , wherein the first AP and the second AP are a same AP. 8 . The method of claim 1 , comprising: receiving a re-association identifier associated with the first key from the first AP; and determining that the re-association identifier received from the first AP matches a re-association identifier of the re-association object, wherein the sending the re-association object to the first AP is in response to determining that the re-association identifier received from the first AP matches the re-association identifier of re-association object. 9 . The method of claim 1 , wherein the response is encrypted by using the second key, wherein the authenticating the response includes decrypting the re-association response message by using the second key. 10 . The method of claim 1 , comprising: deriving, in the re-association procedure, a third key with the first AP; establishing the first security association with the first AP corresponding to the third key, wherein the response is encrypted by using the third key, and wherein the authenticating the response includes decrypting the re-association response message by using the third key. 11 . A method of wireless communication at an access point (AP), comprising: receiving, in a re-association procedure, a re-association object from a station (STA) for establishing a first security association with the AP, wherein the re-association object is encrypted by using a first key unknown to the STA, and wherein the re-association object includes a second key derived from a second security association in a previous association procedure between the STA and an AP; authenticating the re-association object based on the first key and the second key; establishing, in response to successfully authenticating the re-association object, the first security association with the STA; and sending a response to the STA indicating the established first security association. 12 . The method of claim 11 , comprising: deriving, in the previous association procedure, the second key with the STA; establishing the second security association with the STA corresponding to the second key; generating the re-association object; encrypting the re-association object by using the first key; and sending the re-association object to the STA. 13 . The method of claim 12 , wherein the second key is a pairwise transient key (PTK), wherein the second security association is a PTK security association, the method further comprising: including in the re-association object information specifying the PTK security association. 14 . The method of claim 12 , comprising: obtaining, in the previous association procedure, a pairwise master key (PMK); establishing a PMK security association with the STA corresponding to the PMK; and including in the re-association object information specifying the PMK security association. 15 . The method of claim 12 , comprising: receiving, in the previous association procedure, first device specific information from the STA and including the first device specific information in the re-association object; obtaining an internet protocol (IP) address for the STA and including the IP address in the re-association object; generating an integrity code of data of the re-association object by using the first key; and including the integrity code in the re-association object. 16 . The method of claim 11 , wherein the re-association object includes first device specific information, wherein the re-association object is included in a re-association request message received from the STA, and wherein the re-association request message further includes second device specific information associated with the STA, the method further comprising: authenticating, in the re-association procedure, the re-association object based on matching the first device specific information with the second device specific information. 17 . The method of claim 11 , comprising: retrieving, in the re-association procedure, the second key from the re-association object, wherein the first security association is established according to the second key; and encrypting the response by using the second key. 18 . The method of claim 11 , comprising: deriving, in the re-association procedure, a third key with the STA, wherein the first security association is established according to the third key; and encrypting the response by using the third key. 19 . The method of claim 11 , comprising: retrieving, in the re-association procedure, an integrity code from the re-association object; and verifying integrity of data of the re-association object by using the first key and the integrity code. 20 . The method of claim 11 , comprising: retrieving, in the re-association procedure, an indication of time from the re-association object; and determining whether the re-association object is expired based on the retrieved indication of time. 21 . An apparatus for wireless communication, the apparatus being a station (STA), comprising: means for sending, in a re-association procedure, a re-association object to a first access point (AP) to establish a first security association with the first AP, wherein the re-association object is encrypted by using a first key unknown to the STA, and wherein the re-association object includes a second key derived from a second security association in a previous association procedure between the STA and a second AP; means for receiving a response from the first AP indicating that the first security association has been successfully established; and means for authenticating the response.

Assignees

Inventors

Classifications

  • Access point devices · CPC title

  • H04W12/06Primary

    Authentication · CPC title

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • H04W12/04Primary

    Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

  • WLAN [Wireless Local Area Networks] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016295409A1 cover?
A method, an apparatus, and a computer program product for wireless communication are provided. The apparatus may be a STA. The STA sends, in a re-association procedure, a re-association object to a first AP to establish a first security association with the first AP. The re-association object is encrypted by using a first key unknown to the STA. The re-association object includes a second key …
Who is the assignee on this patent?
Qualcomm Inc
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Oct 06 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).