METHOD AND APPARATUS FOR MoCA NETWORK WITH PROTECTED SET-UP
Systems and methods for securing a network, for admitting new nodes into an existing network, and/or securely forming a new network. As a non-limiting example, an existing node may be triggered by a user, in response to which the existing node communicates with a network controller node. Thereafter, if a new node attempts to enter the network, and also for example has been triggered by a user, the network controller may determine, based at least in part on parameters within the new node and the network controller, whether the new node can enter the network.
1 - 21 . (canceled)
22 . A network comprising:
a first node; and
a second node, wherein:
the first node comprises a user-actuated trigger and at least one circuit operable to, at least:
receive a trigger indication that a user has actuated the user-actuated trigger;
in response to the received trigger indication, send a first message comprising an information element indicating that the first node has been triggered by a user; and
the second node comprises at least one circuit operable to, at least:
receive the first message;
in response to the received first message, at least:
operate a timer, the expiration of which will result in cancellation of a protected set-up session; and
set a local state variable, separate from the operation of the timer, to indicate that the protected set-up session is in progress;
while the protected set-up session is in progress, receive a second message from a third node that is not a member of the network, the second message comprising an information element indicating a plurality of protected set-up parameters, different from encryption information, of the third node; and
determine, based at least in part on protected set-up parameters of the second node and on the protected set-up parameters of the third node, whether to share security information with the third node; and
if it is determined, based at least in part on protected set-up parameters of the second node and on the protected set-up parameters of the third node, to share security information with the third node, then share security information with the third node.
23 . The network of claim 22 , wherein the protected set-up parameters of the second message received from the third node comprise:
a first parameter that indicates whether the third node has been admitted to a network;
a second parameter indicating whether privacy is enabled in the node; and
a third parameter indicating whether the node is allowed to accept a privacy downgrade
24 . The network of claim 22 , wherein the first message is a reservation request message, and the second message is a discovery request message communicated prior to the communication of encryption information from the third node.
25 . A network node, the node comprising:
at least one circuit operable to, at least:
receive a first message from a first other node that is a member of a network, the first message comprising an information element indicating that the first other node has been triggered by a user;
in response to the received first message, at least:
operate a timer, the expiration of which will result in cancellation of a protected set-up session; and
set a local state variable, separate from the operation of the timer, to indicate that the protected set-up session is in progress;
while the protected set-up session is in progress, receive a second message from a second other node that is not a member of the network, the second message comprising an information element indicating a plurality of protected set-up parameters, different from encryption information, of the second other node; and
determine, based at least in part on protected set-up parameters of the node and on the protected set-up parameters of the second other node, whether to share security information with the second other node; and
if it is determined, based at least in part on protected set-up parameters of the node and on the protected set-up parameters of the second other node, to share security information with the second other node, then share security information with the second other node.
26 . The node of claim 25 , wherein the at least one circuit is operable to, in response to the received second message and prior to encryption key information being exchanged between the second other node and the node, transmit a third message to the second other node comprising information indicating that a protected set-up session is in progress.
27 . The node of claim 25 , wherein the first message is a reservation request message, and the second message is a discovery request message.
28 . The node of claim 25 , wherein the first message is a reservation request message, the second message is a discovery request message, and the third message is a discovery response message, wherein the first, second, and third messages are communicated prior to the node sending encrypted information to the second other node.
29 . The node of claim 25 , wherein the protected set-up parameters of the second message received from the second other node comprise:
a first parameter that indicates whether the third node has been admitted to a network;
a second parameter indicating whether privacy is enabled in the node; and
a third parameter indicating whether the node is allowed to accept a privacy downgrade.
30 . The node of claim 25 , wherein the at least one circuit is operable to, in response to the received first message, determine whether a protected set-up session is already in progress.
31 . The node of claim 30 , wherein the at least one circuit is operable to, if it is determined that a protected set-up session is already in progress, then:
determine if the first other node initiated the protected set-up session that is already in progress; and
if it is determined that the first other node initiated the protected set-up session that is already in progress, then ignore the received first message.
32 . The node of claim 31 , wherein the at least one circuit is operable to, if it is determined that a protected set-up session is already in progress, then:
if it is determined that the first other node did not initiate the protected set-up session that is already in progress, then cancel the protected set-up session that is already in progress.
33 . The node of claim 25 , wherein the protected set-up parameters of the second other node comprise a parameter indicating whether the second other node is allowed to receive a network password from another node.
34 . The node of claim 25 , wherein the protected set-up parameters of the second other node comprise a single-bit parameter indicating whether privacy is enabled at the second other node.
35 . The node of claim 25 , wherein the protected set-up parameters of the second other node comprise a parameter indicating whether the second other node is allowed to accept a privacy downgrade.
36 . The node of claim 25 , wherein the at least one circuit is operable to, if it is determined to share security information with the second other node, then determine whether to send password information to the second other node or whether to receive password information from the second other node.
37 . A network node, the node comprising:
a user-actuated trigger; and
at least one circuit operable to, at least:
receive a trigger indication that a user has actuated the user-actuated trigger; and
in response to the received trigger indication:
determine, based at least in part on a single-bit state parameter maintained by the node, whether to send a message to a second node, the message comprising an information element indicating that the node has been triggered by a user, wherein the single-bit state parameter indicates whether the node has been admitted to a network; and
if it is determined to send the message, then send the message to the second node.
38 . The node of claim 37 , wherein the second node is a network controller node.
39 . The node of claim 37 , wherein the message is a discovery request message that is free of encryption key information.
40 . The node of claim 37 , wherein the at least one circuit is operable to, in response to the received trigger indication, set a second single-bit parameter variable, different from a timer variable, to indicate that a protected set-up session is in progress.
41 . The node of claim 37 , wherein the message comprises:
a second single-bit information element indicating whether privacy is enabled in the node; and
a third single-bit information element indicating whether the node is allowed to accept a privacy downgrade.