IP Library Granted Patent US 12,284,520
Granted Patent B2
US 12,284,520 · App. 17/556,568 · Granted Apr 22, 2025

Access point verification using crowd-sourcing

Inventors: Jerome Henry (Pittsboro, NC); Robert E. Barton (Richmond, CA); Stephen Michael Orr (Wallkill, NY)
Assignee: CISCO TECHNOLOGY, INC.
H04W12/08H04W12/03H04W48/16H04W76/10H04W12/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,520
App. No.
17/556,568
Granted
Apr 22, 2025
Kind
B2
Abstract

Techniques are provided for verifying Access Points (APs) using crowd sourcing. In one example, a STA establishes a first non-verified connection, based on security material, with a source AP in a wireless infrastructure. A target AP in a wireless infrastructure obtains an indication that the STA is attempting to establish a second non-verified connection with the target AP. In response, the target AP establishes the second non-verified connection based on the security material.

Claims (49)

1. A method comprising:

at a target Access Point (AP) in a wireless infrastructure:

obtaining an indication that a station having a first non-verified connection with a source AP in the wireless infrastructure is attempting to establish a second non-verified connection with the target AP, wherein the station established the first non-verified connection based on security material; and

in response to obtaining the indication that the station is attempting to establish the second non-verified connection with the target AP, establishing the second non-verified connection based on the security material,

wherein the first non-verified connection is established before performing reciprocal identity validation between the station and the source AP, and the second non-verified connection is established before performing reciprocal identity validation between the station and the target AP, and wherein the source AP and the target AP are APs in a same Extended Service Set (ESS).

2. The method of claim 1 , further comprising:

at the target AP:

obtaining the indication that the station is attempting to establish the second non-verified connection from the source AP.

3. The method of claim 1 , wherein the station established the first non-verified connection using a first Media Access Control (MAC) address of the station and is attempting to establish the second non-verified connection using a second MAC address of the station.

4. The method of claim 1 , further comprising:

at the target AP:

obtaining the indication that the station is attempting to establish the second non-verified connection from the station.

5. The method of claim 1 , further comprising:

at the target AP:

obtaining the security material from the source AP.

6. The method of claim 1 , further comprising:

at the target AP:

obtaining the security material from a management device or process associated with the wireless infrastructure.

7. The method of claim 1 , wherein the security material includes one or more of a key or a key name.

8. The method of claim 1 , wherein the first non-verified connection is a first Pre-Association Security Negotiation (PASN) connection, and wherein:

obtaining the indication that the station is attempting to establish the second non-verified connection includes obtaining an indication that the station is attempting to establish a second PASN connection.

9. The method of claim 1 , wherein the first non-verified connection is a first Opportunistic Wireless Encryption (OWE) connection, and wherein:

obtaining the indication that the station is attempting to establish the second non-verified connection includes obtaining an indication that the station is attempting to establish a second OWE connection.

10. An apparatus comprising:

an interface configured to obtain or provide network communications; and

one or more controllers coupled to the interface, wherein the one or more controllers are configured to:

obtain an indication that a station having a first non-verified connection with a source AP in a wireless infrastructure is attempting to establish a second non-verified connection with the apparatus in the wireless infrastructure, wherein the station established the first non-verified connection based on security material; and

in response to obtaining the indication that the station is attempting to establish the second non-verified connection with the apparatus, establish the second non-verified connection based on the security material,

wherein the first non-verified connection is established before performing reciprocal identity validation between the station and the source AP, and the second non-verified connection is established before performing reciprocal identity validation between the station and the apparatus, and wherein the source AP and the apparatus are APs in a same Extended Service Set (ESS).

11. The apparatus of claim 10 , wherein the one or more controllers are further configured to:

obtain the indication that the station is attempting to establish the second non-verified connection from the source AP.

12. The apparatus of claim 10 , wherein the station established the first non-verified connection using a first Media Access Control (MAC) address of the station and is attempting to establish the second non-verified connection using a second MAC address of the station.

13. The apparatus of claim 10 , wherein the one or more controllers are further configured to:

obtain the indication that the station is attempting to establish the second non-verified connection from the station.

14. The apparatus of claim 10 , wherein the one or more controllers are further configured to:

obtain the security material from the source AP.

15. The apparatus of claim 10 , wherein the one or more controllers are further configured to:

obtain the security material from a management device or process associated with the wireless infrastructure.

16. One or more non-transitory computer readable storage media encoded with instructions that, when executed by a controller of a target Access Point (AP) in a wireless infrastructure, cause the controller to:

obtain an indication that a station having a first non-verified connection with a source AP in the wireless infrastructure is attempting to establish a second non-verified connection with the target AP, wherein the station established the first non-verified connection based on security material; and

in response to obtaining the indication that the station is attempting to establish the second non-verified connection with the target AP, establish the second non-verified connection based on the security material,

wherein the first non-verified connection is established before performing reciprocal identity validation between the station and the source AP, and the second non-verified connection is established before performing reciprocal identity validation between the station and the target AP, and wherein the source AP and the target AP are APs in a same Extended Service Set (ESS).

17. The one or more non-transitory computer readable storage media of claim 16 , wherein the instructions further cause the controller to:

obtain the indication that the station is attempting to establish the second non-verified connection from the source AP.

18. The one or more non-transitory computer readable storage media of claim 16 , wherein the station established the first non-verified connection using a first Media Access Control (MAC) address of the station and is attempting to establish the second non-verified connection using a second MAC address of the station.

19. The one or more non-transitory computer readable storage media of claim 16 , wherein the instructions further cause the controller to:

obtain the indication that the station is attempting to establish the second non-verified connection from the station.

20. The one or more non-transitory computer readable storage media of claim 16 , wherein the instructions further cause the controller to:

obtain the security material from the source AP or from a management device or process associated with the wireless infrastructure.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2021
From: HENRY, JEROME; BARTON, ROBERT E.; ORR, STEPHEN MICHAEL
To: CISCO TECHNOLOGY, INC.
Reel/Frame 058448/0994 →
Continuity (2)
Provisional Application 63190381 · May 19, 2021
Related Publication 20220377554A1 · Nov 24, 2022
References Cited (37)
US 20050113090A1 · Sharony · 2005 [cited by examiner]
US 20060067526A1 · Faccin · 2006 [cited by examiner]
US 20150040195A1 · Park et al. · 2015 [cited by applicant]
US 20150117420A1 · Raman · 2015 [cited by examiner]
US 20150172997A1 · Griot et al. · 2015 [cited by applicant]
US 20150365885A1 · Yang · 2015 [cited by examiner]
US 20160135041A1 · Lee et al. · 2016 [cited by applicant]
US 20160295409A1 · Lee · 2016 [cited by examiner]
US 20220256350A1 · Bernsen · 2022 [cited by examiner]
US 20220264668A1 · Lumbatis · 2022 [cited by examiner]
WO 2017078657A1 · 2017 [cited by applicant]
IEEE, “IEEE Standard for Information technology—Telecommunications and information exchange between systems Local and metropolitan area networks—Specific requirements Part 11: Wireless LAN Medium Access Control (MAC) an… [cited by applicant]
IEEE, “IEEE Standard for Information technology—Telecommunications and information exchange between systems—Local and metropolitan area networks—Specific requirements Part 11: Wireless LAN Medium Access Control (MAC) an… [cited by applicant]
Evgeny Khorov et al., “Current Status and Directions of IEEE 802.11be, the Future Wi-Fi 7”, IEEE Access, Digital Object Identifier 10.1109/ACCESS.2020.2993448, May 21, 2020, 25 pages. [cited by applicant]
Wikipedia, “IEEE 802.11r-2008”, May 11, 2021, 4 pages. [cited by applicant]
Wikipedia, “IEEE 802.11”, May 1, 2021, 15 pages. [cited by applicant]
Wikipedia, “IEEE 802.11k-2008”, Sep. 27, 2020, 3 pages. [cited by applicant]
IEEE, “Standard for Information technology—Telecommunications and information exchange between systems Local and metropolitan area networks—Specific requirements—Part 11: Wireless LAN Medium Access Control (MAC) and Phy… [cited by applicant]
Carol Ansley et al., “IEEE P802.11 Wireless LANs”, doc.: IEEE 802.11-19/0151r4, 802.11bc Functional Requirements Document, Jun. 12, 2019, 5 pages. [cited by applicant]
IEEE Standard Association, “IEEE Standard for Information technology—Telecommunications and information exchange between systems Local and metropolitan area networks—Specific requirements Part 11: Wireless LAN Medium Ac… [cited by applicant]
IEEE Standard Association, “IEEE Standard for Information technology—Telecommunications and information exchange between systems Local and metropolitan area networks—Specific requirements Part 11: Wireless LAN Medium Ac… [cited by applicant]
IEEE Standard Association, “IEEE Standard for Information Technology—Telecommunications and Information Exchange between Systems Local and Metropolitan Area Networks—Specific Requirements Part 11: Wireless LAN Medium Ac… [cited by applicant]
IEEE Standard Association, “IEEE Standard for Information Technology—Telecommunications and Information Exchange between Systems Local and Metropolitan Area Networks—Specific Requirements Part 11: Wireless LAN Medium Ac… [cited by applicant]
Jouni Malinen, “IEEE P802.11 Wireless LANs”, RSNXE interoperability issue, doc.: IEEE 802.11-20/332r1, Feb. 19, 2020, 11 pages. [cited by applicant]
Mohamed Ibrahim et al., “Verification: Accuracy Evaluation of WiFi Fine Time Measurements on an Open Platform”, MobiCom'18, Session: Where are U Now? Localization and Motion Tracking, DOI: 10.1145/3241539.3241555, Oct. … [cited by applicant]
D. Harkins, Ed. et al., “Opportunistic Wireless Encryption”, Internet Engineering Task Force (IETF), Request for Comments: 8110, ISSN: 2070-1721, Mar. 2017, 12 pages. [cited by applicant]
Craig Mathias, “Wireless LANs: Is 802.11ax Enough?”, IT Pro Today, Jun. 30, 2019, 9 pages. [cited by applicant]
Takamochi Kanda et al., “ACK-Less Rate Adaptation for IEEE 802.11bc Enhanced Broadcast Services Using Sim-to-Real Deep Reinforcement Learning”, arXiv:2104.11811v1 [cs.NI], Apr. 23, 2021, 5 pages. [cited by applicant]
Monica Alleven, “IEEE releases 802.11aq to better detect WLAN availability”, Fierce Wireless, Sep. 19, 2018, 12 pages. [cited by applicant]
Cisco Meraki, “802.11k and 802.11r Overview”, Apr. 20, 2021, 4 pages. [cited by applicant]
Wi-Fi Alliance, “Wi-Fi CERTIFIED Optimized Connectivity™ enhances Wi-Fi® roaming experience”, Feb. 19, 2018, 2 pages; https://www.wi-fi.org/news-events/newsroom/wi-fi-certified-optimized-connectivity-enhances-wi-fi-roam… [cited by applicant]
RF Wireless World, “What is IEEE 802.11az | Advantages of 802.11az WiFi Standard”, 2012, 6 pages; https://www.fwireless-world.com/Terminology/Benefits-or-Advantages-of-802-11az.html. [cited by applicant]
Cisco, “Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE Gibraltar 16.12.x”, Jul. 31, 2019, 1346 pages. [cited by applicant]
Jeremy Martin et al., “A Study of MAC Address Randomization in Mobile Devices and When it Fails”, arXiv:1703.02874v2 [cs.CR], Mar. 31, 2017, 23 pages. [cited by applicant]
CWNP , “802.11 Fast BSS Transition (FT) Part 2 of 2”, Aug. 22, 2007, 4 pages; https://www.cwnp.com/802-11-fast-bss-transition-ft-part-2-of-2/. [cited by applicant]
CWNP, “802.11i Authentication and Key Management (AKM)”, White Paper, Planet3 Wireless, Inc., May 2005, 10 pages. [cited by applicant]
Cisco Meraki, “802.11 Association Process Explained”, retrieved Dec. 10, 2021, 2 pages. [cited by applicant]