IP Library Granted Patent US 9,954,687
Granted Patent B2
US 9,954,687 · App. 14/921,204 · Granted Apr 24, 2018

Establishing a wireless connection to a wireless access point

Inventors: Thomas J. Cross (Atlanta, GA); David B. Dewey (Milton, GA); Takehiro Takahashi (Seattle, WA)
Assignee: International Business Machines Corporation
H04L9/3268H04L9/3247H04L9/3263H04L63/0428H04L63/06H04L63/0823H04W12/04H04W12/06H04L2209/80H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,954,687
App. No.
14/921,204
Granted
Apr 24, 2018
Kind
B2
Abstract

A method and apparatus for establishing a wireless connection. A digital certificate having a second name is obtained by a processor unit in response to receiving a selection of a network using a first name broadcast by a wireless access point. A determination is made by the processor unit as to whether the digital certificate is valid. A determination is made by the processor unit as to whether the second name in the digital certificate matches the first name broadcast by the wireless access point. The processor unit establishes the wireless connection to the wireless access point in response to the digital certificate being valid and the second name in the digital certificate matching the first name broadcast by the wireless access point.

Claims (38)

1. A method for establishing a wireless connection, the method comprising:

receiving a selection of a network using a first name broadcast by a wireless access point;

obtaining, by a processor unit, a digital certificate having a second name from the wireless access point;

determining, by the processor unit, whether the digital certificate is valid by determining whether the digital certificate matches one of a number of digital certificates previously identified by the processor unit as being valid, and responsive to determining that the digital certificate does not match one of the number of digital certificates previously identified as being valid, requesting a user input as to whether to trust the digital certificate;

determining, by the processor unit, whether the second name in the digital certificate matches the first name broadcast by the wireless access point; and

responsive to the digital certificate being valid and the second name in the digital certificate matching the first name broadcast by the wireless access point, establishing, by the processor unit, the wireless connection to the wireless access point, wherein the step of establishing, by the processor unit, the wireless connection to the wireless access point comprises:

generating, by the processor unit, a session key for the wireless connection using the digital certificate responsive to the digital certificate being valid and the second name in the digital certificate matching the first name broadcast by the wireless access point; and

exchanging, by the processor unit, information with a server using the session key to encrypt and decrypt the information.

2. The method of claim 1 further comprising:

exchanging, by the processor unit, information with the network using the wireless connection established with the wireless access point.

3. The method of claim 1 , wherein the step of determining, by the processor unit, whether the digital certificate is valid comprises:

determining, by the processor unit, whether a digital signature in the digital certificate is signed by a trusted certificate authority.

4. The method of claim 1 , wherein the first name is a service set identifier and is broadcast using a frame extension that provides an extension to the service set identifier and includes element identifier, length and extended service set identifier fields.

5. The method of claim 3 , wherein the second name is a domain name of an entity that requested the digital certificate from the trusted certificate authority.

6. The method of claim 1 , wherein the wireless connection is an encrypted wireless connection.

7. The method of claim 1 , wherein the network is a wireless network specified by IEEE 802.11 standards.

8. A computer comprising:

a bus;

a storage device connected to the bus;

a processor unit connected to the bus; and

program code stored on the storage device, for execution by the processor to receive a selection of a network using a first name broadcast by a wireless access point, obtain a digital certificate having a second name from the wireless access point, determine whether the digital certificate is valid by determining whether the digital certificate matches one of a number of digital certificates previously identified by the processor unit as being valid, and requesting a user input as to whether to trust the digital certificate responsive to determining that the digital certificate does not match one of the number of digital certificates previously identified as being valid, determine whether the second name in the digital certificate matches the first name broadcast by the wireless access point in response to determining that the digital certification is valid, and establish a wireless connection to the wireless access point using the digital certificate in response to the digital certificate being valid and the second name in the digital certificate matching the first name broadcast by the wireless access point by generating a session key for the wireless connection using the digital certificate responsive to the digital certificate being valid and the second name in the digital certificate matching the first name broadcast by the wireless access point, and exchanging information with a server using the session key to encrypt and decrypt the information.

9. The computer of claim 8 , wherein the program code is also executable by the processor to exchange information with the network using the wireless connection established with the wireless access point.

10. The computer of claim 8 , wherein the program code determines whether the digital certificate is valid by determining whether a digital signature in the digital certificate is signed by a trusted certificate authority to determine whether the digital certificate is valid.

11. The computer of claim 8 , wherein the first name is a service set identifier.

12. The computer of claim 8 , wherein the second name is a domain name.

13. A computer program product comprising:

a non-transitory computer readable storage medium;

first program code, stored on the non-transitory computer readable storage medium, responsive to receiving a selection of a network using a first name broadcast by a wireless access point, for obtaining a digital certificate having a second name from the wireless access point;

second program code, stored on the non-transitory computer readable storage medium, for determining whether the digital certificate is valid by determining whether the digital certificate matches one of a number of digital certificates previously identified by the processor unit as being valid, and requesting a user input as to whether to trust the digital certificate responsive to determining that the digital certificate does not match one of the number of digital certificates previously identified as being valid;

third program code, stored on the non-transitory computer readable storage medium, for determining whether the second name in the digital certificate matches the first name broadcast by the wireless access point in response to determining that the digital certification is valid; and

fourth program code, stored on the non-transitory computer readable storage medium, responsive to the digital certificate being valid and the second name in the digital certificate matching the first name broadcast by the wireless access point, for establishing a wireless connection to the wireless access point using the digital certificate by generating a session key for the wireless connection using the digital certificate responsive to the digital certificate being valid and the second name in the digital certificate matching the first name broadcast by the wireless access point, and exchanging information with a server using the session key to encrypt and decrypt the information.

14. The computer program product of claim 13 further comprising:

fifth program code, stored on the non-transitory computer readable storage medium, for exchanging information with the network using the wireless connection established with the wireless access point.

15. The computer program product of claim 13 , wherein the second program code comprises:

program code, stored on the non-transitory computer readable storage medium, for determining whether a digital signature in the digital certificate is signed by a trusted certificate authority to determine whether the digital certificate is valid.

16. The method of claim 1 , wherein the step of obtaining, by the processor unit, a digital certificate comprises:

sending, by the processor unit, an authentication request for network authentication to the wireless access point.

17. The method of claim 1 , wherein the digital certificate is used to authenticate an identity of a network and comprises a digital signature, a public key and the second name.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: KYNDRYL, INC.
Reel/Frame 057885/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2017
From: CROSS, THOMAS J.; DEWEY, DAVID B.; TAKAHASHI, TAKEHIRO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044803/0922 →
Continuity (2)
Continuation 12652973 · Jan 6, 2010
Related Publication 20160043871A1 · Feb 11, 2016