US2018084416A1PendingUtilityA1

Methods and systems for authentic interoperability

Assignee: QUALCOMM INCPriority: Oct 21, 2014Filed: Nov 15, 2017Published: Mar 22, 2018
Est. expiryOct 21, 2034(~8.2 yrs left)· nominal 20-yr term from priority
H04W 12/06H04L 63/08H04L 63/061H04W 12/04H04W 12/041H04L 63/164H04W 12/50
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems, methods, and computer readable mediums for authenticating a device perform a method of receiving, at a second device, a first authentication protocol reauthentication response for the device, the authentication response including a reauthentication master session key (rMSK), transmitting, at the second device, a second first authentication protocol reauthentication response to a first access point based on the reauthentication master session key, generating, at the second device, a first pairwise master key (PMK) based on the reauthentication master session key, generating, at the second device, a key message to include the first pairwise master key, and transmitting, at the second device, the key message to the second access point.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of authenticating over a network including a first access point and a second access point by a station, comprising:
 receiving a network message, at the station, from the first access point;   determining, at the station, based on the network message, whether to authenticate with the first access point via extensible authentication protocol or fast basic service set transition authentication protocol; and   authenticating with the first access point, at the station, using the determined authentication protocol.   
     
     
         2 . The method of  claim 1 , wherein the network message includes a mobility domain identifier and the determining whether to authenticate with the first access point via the extensible authentication protocol or fast basic service set transition authentication protocol is based on the mobility domain identifier. 
     
     
         3 . The method of  claim 1 , wherein the network message includes one or more indicators of authentication protocols supported by the first access point, and the determining whether to authenticate with the first access point via the extensible authentication protocol or the fast basic service set transition authentication protocol is based on the one or more indicators. 
     
     
         4 . The method of  claim 1 , further comprising:
 receiving a message from the first access point indicating a first mobility domain identifier for the first access point;   authenticating with the second access point having a second mobility domain identifier; and   authenticating with the first access point using the extensible authentication protocol-reauthentication protocol in response to the first mobility domain identifier being different than the second mobility domain identifier.   
     
     
         5 . The method of  claim 4 , further comprising authenticating with the first access point using the fast basic service set transition authentication protocol in response to the first mobility domain identifier matching the second mobility domain identifier. 
     
     
         6 . The method of  claim 4 , wherein the authentication with the second access point uses the extensible authentication protocol reauthentication protocol, the method further comprising:
 determining a reauthentication master session key based on the extensible authentication protocol reauthentication protocol with the second access point;   deriving a fast basic service set transition first level pairwise master key from the reauthentication master session key;   deriving a fast basic service set transition second level pairwise master key based on the fast basic service set transition first level pairwise master key and one or more properties of the second access point; and   communicating with the second access point based on the fast basic service set transition second level pairwise master key.   
     
     
         7 . The method of  claim 6 , further comprising:
 deriving a second fast basic service set transition second level pairwise master key based on the fast basic service set transition first level pairwise master key and one or more properties of the first access point; and   communicating with the first access point based on the derived second fast basic service set transition second level pairwise master key.   
     
     
         8 . The method of  claim 7 , further comprising:
 performing a diffie-hellman key exchange with the first access point;   deriving a pairwise transient key based on the diffie-hellman key exchange and the second fast basic service set transition second level pairwise master key; and   communicating with the first access point based on the derived pairwise transient key.   
     
     
         9 . A station for authenticating over a network, comprising:
 a receiver configured to receive a network message from a first access point;   a processor, configured to:
 determine, based on the network message, whether to authenticate with the first access point via extensible authentication protocol or fast basic service set transition authentication protocol, and 
 authenticate with the first access point using the determined authentication protocol. 
   
     
     
         10 . The station of  claim 9 , wherein the network message includes a mobility domain identifier, and the processor is further configured to determine whether to authenticate with the first access point via extensible authentication protocol or fast basic service set transition authentication protocol based on the mobility domain identifier. 
     
     
         11 . The station of  claim 9 , wherein the network message includes one or more indicators of authentication protocols supported by the first access point, and the processor is further configured to determine whether to authenticate with the first access point via extensible authentication protocol or fast basic service set authentication protocol based on the one or more indicators. 
     
     
         12 . The station of  claim 9 , wherein the processor is further configured to:
 receive a message from the first access point indicating a first mobility domain identifier for the first access point; and   authenticate with a second access point having a second mobility domain identifier, and authenticate with the first access point using extensible authentication protocol-reauthentication protocol in response to the first mobility domain identifier being different than the second mobility domain identifier.   
     
     
         13 . The station of  claim 12 , wherein the processor is further configured to authenticate with the first access point using the fast basic service set transition authentication protocol in response to the first mobility domain identifier matching the second mobility domain identifier. 
     
     
         14 . The station of  claim 12 , wherein the authentication with the second access point uses the extensible authentication protocol reauthentication protocol, and the processor is further configured to:
 determine a reauthentication master session key based on the extensible authentication protocol reauthentication protocol with the second access point;   derive a fast basic service set transition first level pairwise master key from the reauthentication master session key;   derive a fast basic service set transition second level pairwise master key based on the fast basic service set transition first level pairwise master key and one or more properties of the second access point; and   communicate with the second access point based on the fast basic service set transition second level pairwise master key.   
     
     
         15 . The station of  claim 14 , wherein the processor is further configured to:
 derive a second fast basic service set transition second level pairwise master key based on the fast basic service set transition first level pairwise master key and one or more properties of the first access point; and   communicate with the first access point based on the derived second fast basic service set transition second level pairwise master key.   
     
     
         16 . The station of  claim 15 , wherein the processor is further configured to:
 perform a diffie-hellman key exchange with the first access point;   derive a pairwise transient key based on the diffie-hellman key exchange and the second fast basic service set transition second level pairwise master key; and   communicate with the first access point based on the derived pairwise transient key.   
     
     
         17 . A tangible computer readable storage medium comprising non-transitory instructions that when executed cause a processor to perform a method of:
 receiving a network message, at a station, from a first access point;   determining, at the station, based on the network message, whether to authenticate with the first access point via extensible authentication protocol or fast basic service set transition authentication protocol; and   authenticating with the first access point, at the station, using the determined authentication protocol.   
     
     
         18 . The medium of  claim 17 , wherein the network message includes a mobility domain identifier and the determining whether to authenticate with the first access point via the extensible authentication protocol or fast basic service set transition authentication protocol is based on the mobility domain identifier. 
     
     
         19 . The medium of  claim 17 , wherein the network message includes one or more indicators of authentication protocols supported by the first access point, and the determining whether to authenticate with the first access point via the extensible authentication protocol or the fast basic service set transition authentication protocol is based on the one or more indicators. 
     
     
         20 . The medium of  claim 17 , the method further comprising:
 receiving a message from the first access point indicating a first mobility domain identifier for the first access point;   authenticating with a second access point having a second mobility domain identifier; and   authenticating with the first access point using the extensible authentication protocol-reauthentication protocol in response to the first mobility domain identifier being different than the second mobility domain identifier.   
     
     
         21 . The medium of  claim 20 , wherein the authentication with the second access point uses the extensible authentication protocol reauthentication protocol, and the method further comprises:
 determining a reauthentication master session key based on the extensible authentication protocol reauthentication protocol with the second access point;   deriving a fast basic service set transition first level pairwise master key from the reauthentication master session key;   deriving a fast basic service set transition second level pairwise master key based on the fast basic service set transition first level pairwise master key and one or more properties of the second access point; and   communicating with the second access point based on the fast basic service set transition second level pairwise master key.   
     
     
         22 . An apparatus for authenticating over a network including a first access point and a second access point, the apparatus comprising:
 means for receiving a network message from a first access point;   means for determining, based on the network message, whether to authenticate with the first access point via extensible authentication protocol or fast basic service set transition authentication protocol; and   means for authenticating with the first access point using the determined authentication protocol.   
     
     
         23 . The apparatus of  claim 22 , wherein the network message includes a mobility domain identifier, and the apparatus further comprises means for determining whether to authenticate with the first access point via extensible authentication protocol or fast basic service set transition authentication protocol based on the mobility domain identifier. 
     
     
         24 . The apparatus of  claim 22 , wherein the network message includes one or more indicators of authentication protocols supported by the first access point, and the means for determining whether to authenticate with the first access point via extensible authentication protocol or fast basic service set authentication protocol is based on the one or more indicators. 
     
     
         25 . The apparatus of  claim 22 , further comprising:
 means for receiving a message from the first access point indicating a first mobility domain identifier for the first access point;   means for authenticating with the second access point having a second mobility domain identifier; and   means for authenticating with the first access point using extensible authentication protocol-reauthentication protocol in response to the first mobility domain identifier being different than the second mobility domain identifier.   
     
     
         26 . The apparatus of  claim 25 , wherein the means for authenticating with the second access point uses the extensible authentication protocol reauthentication protocol, and the apparatus further comprises:
 means for determining a reauthentication master session key based on the extensible authentication protocol reauthentication protocol with the second access point;   means for deriving a fast basic service set transition first level pairwise master key from the reauthentication master session key;   means for deriving a fast basic service set transition second level pairwise master key based on the fast basic service set transition first level pairwise master key and one or more properties of the second access point; and   means for communicating with the second access point based on the fast basic service set transition second level pairwise master key.

Join the waitlist — get patent alerts

Track US2018084416A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.