IP Library Granted Patent US 9,445,273
Granted Patent B2
US 9,445,273 · App. 14/648,166 · Granted Sep 13, 2016

Establishing WLAN association

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,445,273
App. No.
14/648,166
Granted
Sep 13, 2016
Kind
B2
Abstract

A method of establishing network connection between a network device and a WLAN is disclosed. The method includes: determining whether there is previous security association between the network device and the WLAN at the time of requesting for network association, and establishing a new security association between the network device and the WLAN using security data generated in the course of establishing the previous security association if there is the previous security association.

Claims (17)

1. A network admission apparatus comprising a processor to identify existence of previous security association between a client device and a wireless network (WLAN) upon receipt of a request for association with said WLAN, wherein the apparatus is to generate a set of new transient cryptographic keys to facilitate a data communication session between the client device and the WLAN using data generated in the course of establishing said previous security association upon identification of said previous security association.

2. A network admission apparatus according to claim 1 , wherein the apparatus is to generate said set of new transient cryptographic keys for a new data communication session using data contained in EAPOL-key (Extensible Authentication Protocol on LAN-key) frames generated in the course of establishing said previous security association, said set of new transient cryptographic keys including a pairwise transient key (PTK) and a group temporal key (GTK).

3. A network admission apparatus according to claim 1 , wherein said previous security association is by way of pairwise master key security association (PMKSA) and the apparatus is to send an authentication message including the first EAPOL-key (Extensible Authentication Protocol on LAN-key) frame generated in the course of establishing said previous security association in response to said request for association with the WLAN.

4. A network admission apparatus according to claim 3 , wherein said apparatus is to perform a 4-way handshake as stipulated in IEEE 802.11i or equivalent to establish new security association upon failure to identify a valid previous security association with said client device.

5. A network admission apparatus according to claim 3 , wherein said EAPOL-key frame includes pairwise master key identifier (PMKID) of said PMKSA.

6. A network admission apparatus according to claim 5 , wherein the apparatus is to generate a transient key in the form of pairwise transient key (PTK) upon receipt of a response for the client device after receiving said PMKID.

7. A network admission apparatus according to claim 6 , wherein the apparatus is to establish security association in the form of PTKSA (pairwise transient key security association) with said client device if the MIC (message integrity code) of the client device is correct.

8. A network device comprising a processor, a memory and a wireless frontend for associating with a wireless network (WLAN), wherein the network device is to identity previous security association with said WLAN and to generate new transient cryptographic keys to facilitate a new communication session with the WLAN using data generated in the course of establishing said previous security association upon identification of said previous security association.

9. A network device according to claim 8 , wherein the processor is to identity said previous security association with said WLAN by comparing cached security data due to said previous security association and security data received from said WLAN in response to a new request for association with the WLAN.

10. A network device according to claim 9 , wherein the processor is to compared pairwise master key identifier (PMKID) cached in the memory of said network device with PMKID received from said WLAN and to generate a pairwise transient key (PTK) upon satisfactory outcome of comparison.

11. A method of establishing network connection between a network device and a WLAN, the method comprising:

determining whether there is previous security association between the network device and the WLAN at the time of requesting for network association, and

establishing a new security association between the client device and the WLAN using security data generated in the course of establishing said previous security association if there is said previous security association.

12. A method according to claim 11 , wherein the method includes generating new transient cryptographic keys to facilitate a new data communication session between the client device and the WLAN using data generated in the course of establishing said previous security association upon identification of said previous security association.

13. A method according to claim 12 , wherein the method includes the WLAN generating said new transient cryptographic keys for a new data communication session using data contained in EAPOL-key (Extensible Authentication Protocol on LAN-key) frames generated in the course of establishing said previous security association.

14. A method according to claim 11 , wherein said previous security association is by way of pairwise master key security association (PMKSA) and the apparatus is to send an authentication message including the first EAPOL-key (Extensible Authentication Protocol on LAN-key) frame generated in the course of establishing said previous security association in response to said request for association with the WLAN.

15. A method according to claim 14 , wherein the method includes performing a 4-way handshake as stipulated in IEEE 802.11i or equivalent to establish new security association upon failure to identify a valid previous security association with said network device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2016
From: H3C TECHNOLOGIES CO., LTD.; HANGZHOU H3C TECHNOLOGIES CO., LTD.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 039767/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2015
From: XU, GUOXIANG
To: HANGZHOU H3C TECHNOLOGIES CO., LTD.
Reel/Frame 035793/0071 →