Electronic devices, methods, and non-transitory computer-readable storage media
By employing encrypted computing and policy management in dynamic personal area networks (PANs), the problem of complex password management for electronic devices in multi-PAN environments is solved, achieving secure and flexible network access control and improving user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- RUCKUS IP HOLDINGS LLC
- Filing Date
- 2020-09-09
- Publication Date
- 2026-05-08
AI Technical Summary
In the prior art, when electronic devices establish a connection with a Dynamic Personal Area Network (PAN), password management is complex, cumbersome, and time-consuming, especially in a multi-PAN environment, making it difficult to achieve secure and efficient access control.
By selectively granting secure access to a second electronic device, and utilizing encrypted computation and policy management, dynamic access control to the network is achieved based on password parameters and virtual network identifiers, independent of the traffic of other PANs.
It simplifies the loading process for electronic devices, reduces complex password management, improves the flexibility and security of network access, and enhances the user experience.
Smart Images

Figure CN114667499B_ABST
Abstract
Description
Technical Field
[0001] The described embodiments relate to a technique for authenticating one or more devices to a Dynamic Personal Area Network (PAN) in a network based on passwords and network-associated policies, such as policies for the location associated with one or more devices. Background Technology
[0002] Many electronic devices are capable of communicating wirelessly with other electronic devices. Specifically, these devices may include network subsystems that implement network interfaces such as cellular networks (UMTS, LTE, etc.), wireless local area networks (e.g., wireless networks as described in the IEEE 802.11 standard or Bluetooth from the Bluetooth Special Interest Group in Kirkland, Washington), and / or another type of wireless network. For example, many electronic devices communicate with each other via a wireless local area network (WLAN) using IEEE 802.11-compliant communication protocols (sometimes collectively referred to as “Wi-Fi”). In a typical deployment, a Wi-Fi-based WLAN includes one or more access points (or basic service sets or BSSs) that use Wi-Fi to communicate wirelessly with each other and with other electronic devices, and access another network (e.g., the Internet) via IEEE 802.3 (sometimes referred to as “Ethernet”).
[0003] One challenge associated with Wi-Fi is how to allow electronic devices to establish connections with PANs implemented in a WLAN. It's worth noting that multiple overlapping PANs may exist in a WLAN, meaning that electronic devices outside a given PAN may be able to access content associated with other PANs (and vice versa).
[0004] In principle, this problem can be solved by establishing a secure PAN. It is worth noting that a given electronic device can establish a secure connection within a given PAN, preventing its communications (and therefore associated content) from being accessed by other PANs in the WLAN.
[0005] However, this approach presents other challenges, such as how to assign encrypted information (e.g., passwords, sometimes called dynamic pre-shared keys or DPSKs) to a given electronic device within a given PAN and use that encrypted information to enable the establishment of a secure connection. For example, in some existing methods, a given electronic device within the PAN has a separate password associated with that device, which can make loading the device cumbersome and time-consuming, or may require a complex registration process for the electronic device within the given PAN. Furthermore, password management can be complex in these methods. Summary of the Invention
[0006] In a first set of embodiments, an electronic device is described that selectively grants secure access to a network (e.g., a PAN in a WLAN, independent of traffic associated with other PANs in the WLAN). This electronic device may include: interface circuitry communicating with a computer (e.g., a computer network device in a WLAN, such as the controller of an access point or switch); a processor; and a memory storing program instructions, which, when executed by the processor, cause the electronic device to perform operations. It should be noted that during operation, the electronic device receives an access request associated with a computer, wherein the access request includes password parameters associated with a user corresponding to a password, and the password parameters include inputs and outputs of a cryptographic calculation. In response, the electronic device calculates one or more second outputs of the cryptographic calculation based at least in part on the inputs and one or more stored passwords. Furthermore, when a match exists between one or more of the second outputs and the output, the electronic device accesses a policy associated with the user. Then, when one or more criteria associated with the policy are met, the electronic device selectively provides an access acceptance message with an address pointing to a computer, wherein the access acceptance message is directed to the second electronic device and includes information for establishing secure access to the second electronic device.
[0007] Note that the electronic device may include an authentication, authorization, and accounting (AAA) server.
[0008] Furthermore, the password may include the user's DPSK. In some embodiments, the second electronic device is included in a set of electronic devices associated with the user and sharing the password. Therefore, the password may include a group DPSK used by that set of electronic devices. However, the password may not be included in the access request.
[0009] In addition, password parameters may include: a random number associated with a second electronic device, a random number associated with a computer network device, the output of an encrypted calculation, an identifier of the second electronic device (e.g., a media access control or MAC address) and / or an identifier of the computer network device (e.g., the MAC address of the computer network device).
[0010] Additionally, the policy may include a password validity period. In some embodiments, the policy may include a password-valid location (e.g., the location of a computer network device) or a network that allows user access. For example, interface circuitry may communicate with a second computer (e.g., a property management or PM server associated with an organization) to determine whether a second electronic device is associated with the location. When the second electronic device is associated with the location, it may selectively provide an access acceptance message. Note that the location may include: a room, a building, a communication port, a facility associated with an organization (e.g., a hotel or educational institution), etc.
[0011] Furthermore, the network may include a virtual network associated with the location (e.g., a virtual network for a PAN), and accessing information in the received message may allow the second electronic device to establish secure communication with the virtual network. This secure communication can be independent of traffic associated with other users on the network. For example, a computer network device may bridge traffic between a second electronic device in a virtual network and a group of electronic devices, where traffic in the virtual network is independent of other traffic associated with one or more different virtual networks within the network. Note that the virtual network may include a Virtual Local Area Network (VLAN) or a Virtual Extensible Local Area Network (VXLAN).
[0012] In some embodiments, virtual networks are specified by an identifier included in the access acceptance message. For example, the identifier may include a Virtual Local Area Network Identifier (VLAN ID) or a Virtual Network Identifier (VNI). Furthermore, the identifier may include information capable of specifying more than 4,096 virtual networks. Alternatively or additionally, virtual networks may include: QinQ, mobile tunneling (e.g., using Home Hub and group identifiers), and / or a MAC address mapping program.
[0013] Furthermore, the access request may include a Remote Authentication Dial-In User Service (RADIUS) access request, and the access acceptance message may include a RADIUS access acceptance message. Note that password parameters may be included in RADIUS attributes, such as Vendor-Specific Attributes (VSAs). Alternatively, in some embodiments, Hypertext Transfer Protocol (HTTP) or HTTP-based protocols (such as HTTPv2, WebSockets, or gRPC) may be used.
[0014] Additionally, the strategy can allow users to access multiple networks at different locations. In these embodiments, the inputs used to compute one or more second outputs of the cryptographic computation may include a given identifier of a given network. Furthermore, one or more stored passwords can be organized, at least in part, based on the identifiers of different networks. For example, a password pool can be bound to or associated with different networks to reduce computational workload.
[0015] Furthermore, the second electronic device may be pre-configured with a password. Note that the password may be independent of the identifier associated with the second electronic device, such as the MAC address of the second electronic device. More generally, the password may be independent of the second electronic device or the hardware within the second electronic device.
[0016] In some embodiments, the policy is accessed on a third computer, such as a property management or loyalty computer. Furthermore, the policy on the third computer can be used to enable or disable passwords when a customer checks in or leaves the hotel.
[0017] Furthermore, in some embodiments, the MAC address of the second electronic device is bound to or associated with a password within the electronic device, allowing the second electronic device to be authenticated by the electronic device in subsequent instances without the electronic device having to perform cryptographic calculations. However, in some embodiments, even when using such a MAC address cache, the electronic device can perform cryptographic calculations during instances of subsequent authentication requests to ensure that the password parameters and / or encrypted information remain unchanged and accurate. Note that when using a MAC address cache, it may only be necessary to perform a single cryptographic calculation on the second electronic device (as opposed to a brute-force search through a large set of possible passwords).
[0018] Another embodiment provides a second electronic device that performs at least some of the operations described above for the electronic device.
[0019] Another embodiment provides a computer network device that performs at least some of the operations described above as those of the electronic device.
[0020] Another embodiment provides a computer that performs at least some of the operations described above for an electronic device.
[0021] Another embodiment provides a second computer that performs at least some of the operations described above for the electronic device.
[0022] Another embodiment provides a system including a computer network device, a computer, an electronic device, and / or a second computer.
[0023] Another embodiment provides a computer-readable storage medium having program instructions for use with one of the foregoing components. When executed by said component, the program instructions cause said component to perform at least some of the foregoing operations in one or more of the foregoing embodiments.
[0024] Another embodiment provides a method that can be performed by one of the foregoing components. This method includes at least some of the foregoing operations in one or more of the foregoing embodiments.
[0025] The second set of embodiments describes a method for performing cloud-level group authentication. The method includes: receiving an authentication request at a DPSK server, wherein the authentication request is associated with the end device after an end device (e.g., a second electronic device) joins or is associated with the network via an access point; authenticating the end device; and, after authentication, determining whether encrypted information included in the authentication request and derived from a password can match a second password stored in the DPSK server (e.g., in non-transitory memory).
[0026] When the matching operation is successful, the DPSK server can obtain the End User Identifier (EUI) associated with the second password. The DPSK server can then append or include the EUI in the authentication request. Furthermore, the DPSK server can provide a positive affirmation or approval for authentication requests with EUI addresses pointing to the AAA server, provided that the password used by the end device is the same as the password configured in the DPSK server (i.e., the same as the second password).
[0027] Next, the AAA server can provide a name request for the end-user name to the user database (USER DB), where the name request includes the EUI. Furthermore, the AAA server can receive the end-user name associated with the USER DB in response to the name request. Additionally, the AAA server can provide a location request for the location of the end-user name assigned to the address pointing to the PM server, and can receive a location identifier message associated with the PM server. The AAA server can identify the policy assigned to the location identifier in the AAA server. The AAA server can then provide an access acceptance message pointing to the DPSK server, which can include the policy. Furthermore, the DPSK server can provide an access acceptance message pointing to an electronic device (e.g., an access point).
[0028] Another embodiment provides a computer-readable storage medium having program instructions that are used with an electronic device, a terminal device, a DPSK server, an AAA server, a user database, or a PM server. When executed by the electronic device, terminal device, DPSK server, AAA server, USER DB, or PM server, the program instructions cause the electronic device, terminal device, DPSK server, AAA server, USER DB, or PM server to perform at least some of the aforementioned operations of one or more of the foregoing embodiments.
[0029] Another embodiment provides an electronic device for performing at least some of the foregoing operations in the method.
[0030] Another embodiment provides an end device for performing at least some of the foregoing operations in the method.
[0031] Another embodiment provides a DPSK server that performs at least some of the foregoing operations in the method.
[0032] Another embodiment provides an AAA server that performs at least some of the foregoing operations in the method.
[0033] Another embodiment provides a USER DB that performs at least some of the foregoing operations in the method.
[0034] Another embodiment provides a PM server that performs at least some of the foregoing operations in the method.
[0035] Another embodiment provides a system that includes electronic devices, a switch, a DPSK server, an AAA server, a USER DB, and / or a PM server.
[0036] This invention is provided to illustrate some exemplary embodiments in order to provide a basic understanding of some aspects of the subject matter described herein. Therefore, it should be understood that the above features are exemplary and should not be construed as narrowing the scope or spirit of the subject matter described herein in any way. Other features, aspects, and advantages of the subject matter described herein will become apparent from the following detailed description, drawings, and claims. Attached Figure Description
[0037] Figure 1 This is a block diagram illustrating an example of communication between electronic devices according to embodiments of the present disclosure.
[0038] Figure 2 This describes the use of embodiments according to the present disclosure. Figure 1 A flowchart illustrating an example of a method for providing secure communication using electronic devices.
[0039] Figure 3 This describes the use of embodiments according to the present disclosure. Figure 1 A flowchart illustrating an example of a method for providing secure communication using electronic devices.
[0040] Figure 4 This describes the use of embodiments according to the present disclosure. Figure 1 A flowchart illustrating an example of a method for selectively granting secure access to electronic devices.
[0041] Figure 5 This describes an embodiment according to the present disclosure. Figure 1 An illustration of an example of communication between electronic devices.
[0042] Figure 6 This is a block diagram illustrating an example of a system according to an embodiment of the present disclosure, which implements a dynamic personal area network (PAN) that provides interconnection between a group of electronic devices and a network while isolating them from other electronic devices.
[0043] Figure 7 This is a flowchart illustrating an example of a method according to an embodiment of the present disclosure, which provides interconnection between electronic devices and a network while isolating them from interconnection with other electronic devices.
[0044] Figure 8This is a flowchart illustrating an example of a method according to an embodiment of the present disclosure, which provides interconnection between electronic devices and a network while isolating them from interconnection with other electronic devices.
[0045] Figure 9 This is a flowchart illustrating an example of a method according to an embodiment of the present disclosure, which provides interconnection between electronic devices and a network while isolating them from interconnection with other electronic devices.
[0046] Figure 10 This is a flowchart illustrating an example of a method according to an embodiment of the present disclosure, which provides interconnection between electronic devices and a network while isolating them from interconnection with other electronic devices.
[0047] Figure 11 This is a flowchart illustrating an example of a method according to an embodiment of the present disclosure, which provides interconnection between electronic devices and a network while isolating them from interconnection with other electronic devices.
[0048] Figure 12 This is a flowchart illustrating an example of a method according to an embodiment of the present disclosure, which provides interconnection between electronic devices and a network while isolating them from interconnection with other electronic devices.
[0049] Figure 13 This is a block diagram illustrating an example of an electronic device according to an embodiment of the present disclosure.
[0050] Note that the same reference numerals refer to the corresponding parts throughout the entire drawing. Furthermore, multiple instances of the same part are designated by a common prefix separated by a dash and the instance number. Detailed Implementation
[0051] An electronic device (e.g., an AAA server) is described that selectively grants secure access to a network for a second electronic device. This electronic device can receive an access request associated with a computer, wherein the access request includes password parameters associated with a user, and the password parameters include inputs and outputs of a cryptographic computation. In response, the electronic device can compute one or more second outputs of the cryptographic computation based at least in part on the inputs and one or more stored passwords. Furthermore, when a match exists between one or more of the second outputs and the specified output, the electronic device can access a policy associated with the user. Then, when one or more criteria associated with the policy are met, the electronic device can selectively provide an access acceptance message to the computer, the access acceptance message including information for establishing secure access to the second electronic device.
[0052] These communication technologies enable conditional access to a network by selectively granting secure access to a second electronic device. For example, communication technologies can allow secure access to a second electronic device based at least in part on passwords (e.g., DPSK) and policies. This allows for dynamic secure access to the network, such as access at one or more locations and / or at different times. Furthermore, policies can be updated or modified, allowing organizations the flexibility to change secure access to the network. In addition, in response to an access acceptance message, access points, radio nodes, or switches can bridge traffic in virtual networks (e.g., secure PANs) within the network, thereby separating the traffic of the second electronic device (or a group of electronic devices) from the traffic associated with other users. Therefore, communication technologies can simplify and reduce the time required for onboarding, and can eliminate the need for complex registration processes for second electronic devices or the cumbersome management of multiple passwords. Thus, communication technologies can enhance the user experience when communicating within a network.
[0053] In the following discussion, electronic devices or components in the system transmit packets according to a wireless communication protocol, such as a wireless communication protocol compatible with the IEEE 802.11 standard (sometimes referred to as "Wi-Fi"). ®The IEEE 802.11 standard may include one or more of the following: IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, IEEE 802.11-2007, IEEE 802.11n, IEEE 802.11-2012, IEEE 802.11-2016, IEEE 802.11ac, IEEE 802.11ax, IEEE 802.11ba, ...b, IEEE 802.11a, IEEE 802.11b, IEEE 802.11c, IEEE 802.11a, IEEE 802.11b, IEEE 802.11a, IEEE 802.11b, IEEE 802.11c, IEEE 8 802.11be, or other current or future IEEE 802.11 technologies. Furthermore, access points, radio nodes, base stations, or switches in a wireless network can use wired communication protocols, such as wired communication protocols compatible with the IEEE 802.3 standard (sometimes referred to as "Ethernet") (e.g., the Ethernet II standard), to communicate with locally or remotely located computers (e.g., controllers). However, various communication protocols, including wired and / or wireless communications, can be used in a system. In the following discussion, Wi-Fi, LTE, and Ethernet are used as illustrative examples.
[0054] We will now describe some embodiments of communication technology. Figure 1A block diagram is provided illustrating an example of communication between one or more electronic devices 110 (e.g., cellular phones, portable electronic devices, sites or clients, other types of electronic devices, etc.) in environment 106 via cellular phone network 114 (which may include base station 108), one or more access points 116 in a WLAN (which may communicate using Wi-Fi), and / or one or more radio nodes 118 in a small-scale network (e.g., a small cell) (which may communicate using LTE). For example, one or more radio nodes 118 may include: evolved Node B (eNodeB), Universal Mobile Telecommunications System (UMTS) NodeB and Radio Network Controller (RNC), New Radio (NR) gNB or gNodeB (which communicates with the network using cellular phone communication protocols other than LTE), etc. In the following discussion, access points, radio nodes, or base stations are sometimes commonly referred to as "communication devices". Furthermore, as previously described, one or more base stations (e.g., base station 108), access points 116, and / or radio nodes 118 may be included in one or more wireless networks, such as WLAN, small cells, and / or cellular phone networks. In some embodiments, access point 116 may include physical access points and / or virtual access points, the virtual access points being implemented in software within an environment of electronic devices or computers.
[0055] Note that access point 116 and / or radio node 118 may communicate with each other and / or with computer 112 (which may be a cloud-based controller that manages or configures access point 116, radio node 118, and / or switch 128, or provides cloud-based storage and / or analytics services) via networks 120 and / or 122 using wired communication protocols (e.g., Ethernet) and / or networks 120 and 122. Note that networks 120 and 122 may be the same or different networks. For example, networks 120 and / or 122 may be a LAN, intranet, or the Internet. In some embodiments, network 120 may include one or more routers and / or switches (e.g., switch 128).
[0056] See below for reference Figure 13Further described, electronic device 110, computer 112, access point 116, radio node 118, and switch 128 may include subsystems, such as a network subsystem, a memory subsystem, and a processor subsystem. Additionally, electronic device 110, access point 116, and radio node 118 may include radio device 124 within the network subsystem. More generally, electronic device 110, access point 116, and radio node 118 may include any electronic device having a network subsystem (or may be included within any electronic device having a network subsystem) that enables electronic device 110, access point 116, and radio node 118 to wirelessly communicate with one or more other electronic devices. Such wireless communication may include transmitting access over a wireless channel to enable electronic devices to make initial contact or detection with each other, subsequently exchanging subsequent data / management frames (e.g., connection requests and responses) to establish a connection, configure security options, send and receive frames or packets over the connection, and so on.
[0057] exist Figure 1 During communication, access point 116 and / or radio node 118 and electronic device 110 can communicate wirelessly, while: sending access requests and receiving access responses on the wireless channel, detecting each other by scanning the wireless channel, establishing a connection (e.g., by sending a connection request and receiving a connection response), and / or sending and receiving frames or packets (which may include information as a payload).
[0058] like Figure 1 As can be seen, wireless signal 126 (represented by the sawtooth lines) can be transmitted by, for example, wireless devices 124 in access point 116 and / or radio node 118 and electronic device 110. For example, wireless device 124-1 in access point 116-1 can use wireless signal 126 to transmit information (e.g., one or more packets or frames). These wireless signals are received by wireless devices 124 in one or more other electronic devices (e.g., wireless device 124-2 in electronic device 110-1). This allows access point 116-1 to transmit information to other access points 116 and / or electronic devices 110-1. Note that wireless signal 126 can transmit one or more packets or frames.
[0059] In the described embodiments, processing packets or frames in access point 116 and / or radio node 118 and electronic device 110 may include: receiving a radio signal having packets or frames; decoding / extracting packets or frames from the received radio signal to obtain packets or frames; and processing packets or frames to determine information contained in the payload of the packets or frames.
[0060] Notice, Figure 1Wireless communication can be characterized by various performance metrics, such as: the data rate of successful communication (sometimes called "throughput"), error rate (e.g., retry or retransmission rate), the mean square error of the equalized signal relative to the equalization target, inter-symbol interference, multipath interference, signal-to-noise ratio, eye diagram width, the ratio of the number of bytes successfully transmitted within a time interval (e.g., 1-10 seconds) to the estimated maximum number of bytes that can be transmitted within that time interval (the latter sometimes called the "capacity" of the communication channel or link), and / or the ratio of the actual data rate to the estimated data rate (sometimes called "utilization"). Although in Figure 1 Examples of radio device 124 are shown in the components, but one or more of these examples may differ from other examples of radio device 124.
[0061] In some embodiments, Figure 1 Wireless communication between components may use one or more frequency bands, such as 900 MHz, 2.4 GHz, 5 GHz, 6 GHz, 60 GHz, the citizen broadband radio spectrum, or CBRS (e.g., a band close to 3.5 GHz), and / or a frequency band used by LTE or another cellular telephone communication protocol or data communication protocol. Note that communication between electronic devices may use multi-user transmission (e.g., Orthogonal Frequency Division Multiple Access or OFDMA).
[0062] Although we will Figure 1 The network environment shown is described as an example, but in alternative embodiments, there may be different numbers or types of electronic devices. For example, some embodiments include more or fewer electronic devices. As another example, in another embodiment, different electronic devices are sending and / or receiving packets or frames.
[0063] As previously mentioned, establishing secure communication within a PAN can be difficult, for example. When each electronic device 110 has a separate password, a complex and time-consuming loading process and password management may be required. Furthermore, it may be difficult to adjust or change the access criteria for one or more electronic devices 110.
[0064] See below for reference Figure 2-5 Furthermore, to address these issues, electronic devices (e.g., access point 116-1, radio node 118-1, or switch 128) can provide secure communication to one or more electronic devices (e.g., electronic device 110-1 or electronic devices 110-1 and 110-2), which may have associated passwords (or may share a common password). In the following discussion, access point 116-1 is used to illustrate communication techniques.
[0065] During operation, electronic device 110-1 can discover and associate with access point 116-1 (and therefore with the network provided by access point 116-1, such as a WLAN and / or network 120). For example, electronic device 110-1 can provide an authentication request to access point 116-1. Access point 116-1 can then provide a user equipment context request to computer 112. As further described below, computer 112 can subsequently provide a user equipment context response to access point 116-1, which can confirm that no existing context or association of electronic device 110-1 exists in the WLAN.
[0066] Furthermore, access point 116-1 can provide an authentication response to electronic device 110-1. Next, electronic device 110-1 can provide an association request to access point 116-1, which can respond by providing an association response to electronic device 110-1. Note that at this time, a connection exists between electronic device 110-1 and access point 116-1, but the communication is not encrypted. Additionally, computer 112 can provide user equipment context responses to access point 116-1, such as negative acknowledgments or NACKs.
[0067] After associating with electronic device 110-1, access point 116-1 may provide a first message in the four-way handshake with electronic device 110-1. This first message may include a random number (sometimes referred to as "ANonce") associated with access point 116-1. In response, electronic device 110-1 may construct, derive, or generate a pairwise transient key (PTK). For example, the PTK may be constructed or generated using cryptographic computation (e.g., a pseudo-random function) and a pre-shared key (e.g., a password, such as DPSK or other types of digital certificates), ANonce, a second random number (sometimes referred to as "SNonce") associated with electronic device 110-1, an identifier of access point 116-1 (e.g., the MAC address of access point 116-1), and / or an identifier of electronic device 110-1 (e.g., the MAC address of electronic device 110-1). The password may be pre-installed or pre-configured on electronic device 110-1 and may be stored in memory accessible by AAA server 130. In some embodiments, a user of electronic device 110-1 may receive a password and install it on electronic device 110-1 using a portal (e.g., a website or webpage), email, SMS message, etc.
[0068] Note that the password can be independent of the identifier associated with electronic device 110-1, such as the MAC address of electronic device 110-1. More generally, the password can be independent of electronic device 110-1 or the hardware within electronic device 110-1. The password can be associated with a location, such as a room, building, communication port (e.g., a specific Ethernet port), etc. (Generally, in this discussion, "location" can be limited to a physical location but can be abstracted to include objects or entities associated with a physical location, such as a specific room or building.) Alternatively or additionally, the password can be associated with one or more users, such as guests or family members in a hotel. Thus, as previously described, in some embodiments, the password includes a common password shared by a group of electronic devices (e.g., the common password could be a group DPSK).
[0069] Furthermore, electronic device 110-1 may provide a second message to access point 116-1 during the four-way handshake. The second message may include a SNonce and a Message Integrity Check (MIC) for access point 116-1. In some embodiments, the second message includes: input to the cryptographic calculation and output of the cryptographic calculation.
[0070] Additionally, access point 116-1 can provide access requests (e.g., RADIUS access requests) to computer 112, and computer 112 can provide access requests (e.g., RADIUS access requests) to AAA server 130. In some embodiments, the access request includes password parameters associated with a user. (Therefore, in some embodiments, the password parameters may be included in RADIUS attributes, such as VSAs, like Ruckus VSA 153.) The password parameters may include: inputs and outputs of encrypted computations. For example, the password parameters may include: ANonce, SNonce, MIC, the MAC address of electronic device 110-1, and / or the MAC address of access point 116-1. Furthermore, the access request may include other information such as: cluster name, area name, WLAN service set identifier (SSID), access point 116-1 basic service set identifier (BSSID), and the user's username.
[0071] Based at least in part on password parameters, AAA server 130 can perform authentication and authorization, including comparing encrypted information specified in the password with stored information (e.g., DPSK or other types of digital certificates) for electronic device 110-1. More generally, AAA server 130 can use the information specified in the password to determine whether electronic device 110-1 is authorized to access network 120 and / or network 122. In some embodiments, AAA server 130 implements or uses the RADIUS protocol. Alternatively, in some embodiments, HTTP or HTTP-based protocols (e.g., HTTPv2, WebSockets, or gRPC) may be used.
[0072] It is worth noting that the AAA server 130 can perform brute-force computation of the output of the encrypted computation, at least in part, based on the input of the encrypted computation and different stored passwords. When one of these computed outputs matches an output received from the electronic device 110-1, it can be confirmed that the AAA server 130 is able to construct, derive, or generate the same PTK as the electronic device 110-1, enabling the electronic device 110-1 and the access point 116-1 to encrypt and decrypt their communication with each other.
[0073] The AAA server 130 can then access policies associated with the user (e.g., by performing a lookup at least partially based on the user's username) that govern access to the WLAN (and more generally, to network 120 and / or network 122). For example, the policy may include time intervals when a password is valid. Furthermore, the policy may include the location where the password is valid (e.g., the location of access point 116-1) or the network that the user is allowed to access. In some embodiments, the AAA server 130 may communicate with a property management (PM) server 132 associated with the organization to determine whether the electronic device 110-1 is associated with a location (e.g., whether the user of electronic device 110-1 is staying in or associated with the room where access point 116-1 is located). Note that a location may include: a room, a building, a communication port, a facility associated with the organization (e.g., a hotel or educational institution), etc. More generally, the AAA server 130 may optionally communicate with the PM server 132 to determine whether one or more criteria associated with the policy are met.
[0074] Then, when one or more criteria associated with the policy are met, the AAA server 130 may selectively provide an access acceptance message (e.g., a RADIUS access acceptance message) to the computer 112. This access acceptance message may be intended for electronic device 110-1 and may include information for establishing secure access to electronic device 110-1. For example, the access acceptance message may include: an identifier for electronic device 110-1, a tunnel type, a tunnel media type, a tunnel permission group identifier, a filter identifier, and a username.
[0075] In response, computer 112 may provide an access acceptance message (e.g., a RADIUS access acceptance message) to access point 116-1. Next, access point 116-1 may provide a third message to electronic device 110-1 in a four-way handshake. Furthermore, electronic device 110-1 may provide a fourth message, such as an acknowledgment, to access point 116-1 in the four-way handshake. At this point, access point 116-1 can establish secure access to the WLAN for electronic device 110-1 (and more generally, secure access to network 120 and / or network 122, such as an intranet or the Internet). It is noteworthy that secure access can be within a PAN in the WLAN, independent of traffic associated with other PANs in the WLAN.
[0076] In some embodiments, a location-associated virtual network (e.g., a virtual network of a PAN) can be used to implement secure access, and information in the access acceptance message can allow electronic device 110-1 to establish secure communication with the virtual network. This secure communication can be independent of traffic associated with other users in the WLAN. For example, access point 116-1 can bridge traffic between electronic device 110-1 in a virtual network within the WLAN and another member of a group of electronic devices (e.g., electronic device 110-2), where traffic in the virtual network is independent of other traffic associated with one or more different virtual networks in the network. Note that the virtual network may include a VLAN. Alternatively, when the aforementioned operations of access point 116-1 are performed by switch 128, the virtual network may include a VXLAN. In these embodiments, switch 128 can bridge wired traffic (e.g., Ethernet frames) associated with electronic device 110-1 in the virtual network.
[0077] Furthermore, virtual networks can be specified by an identifier included in the access acceptance message. For example, the identifier may include a VLAN ID (used with access point 116-1) or a VNI (used with switch 128). Additionally, the identifier may include information capable of specifying more than 4,096 virtual networks. In some embodiments, the identifier may include 24 bits, which can be used to specify up to 16 million virtual networks.
[0078] In some embodiments, the virtual network is implemented in a virtual data plane within access point 116-1 (e.g., using generic route encapsulation or GRE tunneling). Note that the data plane is typically responsible for moving data around transport paths, while the control plane is typically responsible for determining and setting these transport paths. The data plane can be implemented using virtual machines executed by multiple cores in one or more processors (sometimes referred to as the "virtual data plane"), which allows for flexible scaling and dynamic reconfiguration of the data plane. In this discussion, a virtual machine is an operating system or application environment implemented using software that mimics or emulates dedicated hardware or specific functions of dedicated hardware.
[0079] Additionally, in some embodiments, the policy allows users to access multiple networks at different locations (e.g., different geographic locations, such as different hotels of a hotel brand or chain). In these embodiments, the input for calculating one or more second outputs of the cryptographic computation may include a given identifier of a given network (e.g., a given SSID). Furthermore, passwords for one or more stores can be organized at least in part based on the identifiers of the different networks. In these embodiments, passwords for related stores can be grouped at least in part based on the given network to which the user requests to join, which can reduce the time required for the AAA server 130 to calculate the outputs of passwords for different stores.
[0080] In this way, the communication technology allows the AAA server 130 to selectively approve network access by electronic device 110-1. It should be noted that the communication technology can allow secure access to electronic device 110-1 at least in part based on passwords and policies. This allows for dynamic secure access to the network, such as access from one or more locations and / or at different times. These capabilities allow access point 116-1 to provide secure communication to one or more of electronic devices 110 without requiring complex and time-consuming loading processes or difficult password management. Therefore, the communication technology can improve the user experience when using electronic device 110-1, access point 116-1, and communicating via the network.
[0081] While the foregoing discussion has described the communication techniques used for communication between access point 116-1 (and more generally, computer network devices) and AAA server 130 mediated by computer 112, in other embodiments, computer 112 may be excluded. Therefore, in some embodiments, access point 116-1 can communicate with AAA server 130 without computer 112. Furthermore, although the foregoing discussion has described the communication techniques used for communication between AAA server 130 and PM server 132, in other embodiments, information stored in PM server 132 is included in AAA server 130, thus excluding PM server 132.
[0082] We will now describe an embodiment of the method. Figure 2 A flowchart is provided illustrating an example of a method 200 for providing secure communication, which can be provided by, for example... Figure 1 This is performed by a computer network device, one of access points 116, radio nodes 118, or switches 128. During operation, the computer network device may receive messages from the electronic device (operation 210). These messages may include: a random number associated with the electronic device, a random number associated with the computer network device, the output of a cryptographic calculation, an identifier of the electronic device (e.g., a MAC address), and / or an identifier of the computer network device (e.g., the MAC address of the computer network device).
[0083] The computer network device may then provide an access request to the computer (e.g., the controller of the computer network device) (operation 212). This access request may include password parameters, such as inputs and outputs of the encrypted computation. For example, the password parameters may include: a random number associated with an electronic device, a random number associated with the computer network device, the output of the encrypted computation, an identifier of the electronic device, and / or an identifier of the computer network device. In some embodiments, the access request includes a RADIUS access request.
[0084] In addition, the computer network device can receive an access acceptance message from the computer (operation 214). This access acceptance message may include information used to establish secure access to the network for the electronic device. For example, the electronic device and the computer network device can use this information to encrypt / decrypt communications and / or establish tunnels.
[0085] Next, the computer network device can provide the second message along with the information to the electronic device (operation 216). Furthermore, the computer network device can bridge traffic associated with the electronic device in a virtual network within the network (operation 218), wherein the traffic in the virtual network is independent of other traffic associated with one or more different virtual networks within the network.
[0086] Figure 3 A flowchart is provided illustrating an example of a method 200 for providing secure communication, which can be provided by, for example... Figure 1The computer 112 in the system executes the operation. During operation, the computer may receive an access request from a computer network device (e.g., an access point, radio node, or switch) (operation 310). This access request may include password parameters, such as inputs and outputs of encrypted computations. For example, password parameters may include: a random number associated with an electronic device, a random number associated with a computer network device, the output of an encrypted computation, an identifier of the electronic device, and / or an identifier of the computer network device. In some embodiments, the access request includes a RADIUS access request.
[0087] The computer can then provide the access request to a second computer (e.g., an AAA server) (operation 312). Additionally, the computer can receive an access acceptance message from the second computer (operation 314). This access acceptance message may include information for establishing secure access to the network for the electronic device. Note that in some embodiments, the access acceptance message includes a RADIUS access acceptance message. Next, the computer can provide the access acceptance message to the computer network device (operation 316).
[0088] Figure 4 A flowchart is provided illustrating an example of a method 400 for selectively approving secure access, said method may be provided by, for example... Figure 1 The electronic device of the AAA server 130 performs the operation. During operation, the electronic device may receive an access request associated with the computer (operation 410), wherein the access request includes a password parameter associated with a user corresponding to a password, and the password parameter includes input and output of the encrypted calculation.
[0089] In addition, password parameters may include: a random number associated with a second electronic device, a random number associated with a computer network device, the output of an encrypted calculation, an identifier of the electronic device (e.g., a MAC address), and / or an identifier of the computer network device (e.g., a MAC address).
[0090] In response, the electronic device may compute one or more second outputs of the encrypted computation, at least in part, based on the input and one or more stored passwords (operation 412). Note that the password and stored passwords may include the user's DPSK. In some embodiments, the second electronic device is included in a group of electronic devices associated with the user and sharing the password. Therefore, the password and stored passwords may include a group DPSK used by that group of electronic devices. However, the password itself may not be included in the access request.
[0091] Furthermore, when a match exists between one or more second outputs and the output (operation 414), the electronic device may access the policy associated with the user (operation 416). Otherwise, the electronic device may deny secure access (operation 418).
[0092] Then, when one or more criteria associated with the policy are met (operation 420), the electronic device may selectively provide an access acceptance message to the computer (operation 422), wherein the access acceptance message is directed to the second electronic device and includes information for establishing secure access to the network for the second electronic device. For example, the second electronic device may use the information at least in part to encrypt / decrypt communications and / or establish a tunnel. Otherwise, the electronic device may not grant secure access (operation 418).
[0093] In some embodiments, the policy may include a password validity period. In some embodiments, the policy may include the location where the password is valid (e.g., the location of a computer network device) or a network that allows the user access. For example, interface circuitry may communicate with a second computer (e.g., a PM server associated with an organization) to determine whether a second electronic device is associated with the location. When the second electronic device is associated with the location, the electronic device may selectively provide an access acceptance message (operation 422). Note that the location may include: a room, a building, a communication port, a facility associated with an organization (e.g., a hotel or educational institution), etc. Alternatively or additionally, the password may identify a user known to be assigned to a location (e.g., a hotel room), and based at least in part on the known location, the second computer may know the identifier of the network on which the electronic device is placed.
[0094] Furthermore, the network may include virtual networks associated with the location (e.g., virtual networks for PANs), and accessing information in the received message can allow a second electronic device to establish secure communication with the virtual network. This secure communication can be independent of traffic associated with other users on the network. For example, a computer network device can bridge traffic between a second electronic device in a virtual network and a group of electronic devices, where traffic in the virtual network is independent of other traffic associated with one or more different virtual networks within the network. Note that virtual networks may include VLANs or VXLANs.
[0095] Furthermore, virtual networks can be specified by identifiers included in the access acceptance message. For example, the identifier may include a VLAN ID or VNI. Alternatively or additionally, virtual networks may include: QinQ, mobile tunnels (e.g., using Home Hub and group identifiers), and / or MAC address mapping programs. Furthermore, the identifier may include information capable of specifying more than 4,096 virtual networks.
[0096] Additionally, the access request may include a RADIUS access request, and the access acceptance message may include a RADIUS access acceptance message. Note that the password parameter may be included in a RADIUS attribute, such as a VSA. Alternatively, in some embodiments, Hypertext Transfer Protocol (HTTP) or an HTTP-based protocol (such as HTTPv2, WebSockets, or gRPC) may be used.
[0097] In some embodiments, the policy may allow a user to access multiple networks at different locations. In these embodiments, the input for calculating one or more second outputs of the cryptographic computation may include a given identifier of a given network. Furthermore, one or more stored passwords may be organized at least in part based on the identifiers of the different networks.
[0098] Furthermore, the second electronic device may be pre-configured with a password. Note that the password may be independent of the identifier associated with the second electronic device, such as the MAC address of the second electronic device. More generally, the password may be independent of the second electronic device or the hardware within the second electronic device.
[0099] In method 200 ( Figure 2 ), 300 Figure 3 In some embodiments of 400 and / or 400, there may be additional or fewer operations. Furthermore, the order of operations may be changed, and / or two or more operations may be combined into a single operation.
[0100] exist Figure 5 The figure further illustrates an embodiment of the communication technology, providing a diagram illustrating an example of communication between electronic device 110-1, access point 116-1, computer 112, AAA server 130, and PM server 132. Figure 5 In the electronic device 110-1, the interface circuit can discover and associate with the access point 116-1 via the interface circuit in the access point 116-1 510.
[0101] Then, the interface circuitry in access point 116-1 can provide message 512 with a random number (e.g., ANonce) associated with access point 116-1. Upon receiving message 512, electronic device 110-1 (e.g., a processor within electronic device 110-1) can perform a cryptographic calculation (CC) 514 using a password (e.g., DPSK), a random number from access point 116-1, a random number associated with electronic device 110-1 (e.g., SNonce), an identifier of access point 116-1 (e.g., a MAC address), and / or an identifier of electronic device 110-1 (e.g., a MAC address). Furthermore, the interface circuitry in electronic device 110-1 can provide message 516 with the input and output of the cryptographic calculation 514. For example, message 516 may include a random number associated with electronic device 110-1 and a MIC.
[0102] Upon receiving message 516, the interface circuitry in access point 116-1 can provide access request (AR) 518 to computer 112. This access request may include password parameters (PP) 520 corresponding to the password associated with the user of electronic device 110-1. For example, password parameters 520 may include: input and output of encrypted calculation 514. Furthermore, upon receiving access request 518, the interface circuitry in computer 112 can provide access request 518 to AAA server 112.
[0103] Furthermore, upon receiving access request 518, interface circuitry 522 in AAA server 130 can provide password parameter 520 to processor 524 in AAA server 130. Processor 524 can use password parameter 520 and password 526 stored in memory 528 in AAA server 130 to perform calculations on the output 530 of encrypted calculation 514.
[0104] When a match exists between one of the calculated outputs 530 and the output received from electronic device 110-1, processor 524 can access policy 532 in memory 528. For example, policy 532 may indicate that secure access to the network is permitted when a user is at location 534. In these embodiments, the processor can instruct interface circuitry 522 536 to confirm that electronic device 110-1 is at location 534 by providing request 538 to PM server 132. After the interface circuitry in PM server 132 receives request 538, the processor in PM server 132 can determine that electronic device 110-1 is at location 534. For example, access point 116-1 or a communication port may be associated with location 534, and / or a user may be associated with location 534 (e.g., a hotel room or a dormitory room in a college or university), and the processor in PM server 132 can determine that electronic device 110-1 is at location 534 by performing a lookup in the memory of PM server 132. The interface circuitry in PM server 132 can then provide a response 540 with confirmation.
[0105] After interface circuitry 522 receives response 540 and provides information about location 534 to processor 524, processor 524 can instruct interface circuitry 522 to provide access acceptance message (AAM) 544 to electronic device 110-1. This access acceptance message carries confidence for establishing secure access to the network for electronic device 110-1. Then, upon receiving access acceptance message 544, interface circuitry in computer 112 can provide access acceptance message 544 to access point 116-1. Furthermore, upon receiving access acceptance message 544, interface circuitry in access point 116-1 and interface circuitry in electronic device 110-1 can exchange additional messages 546 to complete a four-way handshake. Additionally, based at least in part on the information in access acceptance message 544, access point 116-1 and electronic device 110-1 can establish secure access to the network for electronic device 110-1.
[0106] Although Figure 5 Communication between components using unidirectional or bidirectional communication is illustrated using lines with single or double arrows; however, typically, communication in a given operation in this diagram can involve either unidirectional or bidirectional communication. Furthermore, although... Figure 5 The examples illustrate operations performed sequentially or at different times, but in other embodiments, at least some of these operations may be performed at least partially simultaneously or in parallel.
[0107] Figure 6 A block diagram of an example system for a PAN is presented, which provides interconnection between electronic devices and to a network (e.g., the Internet), while isolating them from interconnection with other electronic devices. Figure 6As shown, the system may include: a DPSK server 610; an AAA server 612; a property management (PM) server 614; and a user database (user DB) 616. Additionally, the system may include a network of one or more access points (APs) 618 and end devices (EDs) 620 and a switch 624 at a specific location 622. In some embodiments, the system may include one or more set-top boxes (STBs) 626 and televisions (TVs) 628. When referring to a specific access point, end device, location, set-top box, or television in the following description, only one of these specific components may be listed as an example of how all components operate. When describing how multiple instances of each component operate together, several components may be indicated by numbers with dashes.
[0108] The following text is in Figure 13 The discussion provides Figure 6 The illustrations illustrate exemplary internal components of access point 618, terminal device 620, and DPSK server 610, AAA server 612, and PM server 614. However, in general, this disclosure contemplates that access point 618, terminal device 620, user DB (or data structure) 616, and DPSK server 610, AAA server 612, and PM server 614 include electronic components or electronic computing devices operable to receive, transmit, process, store, and / or manage data and information associated with the system, encompassing any suitable processing means adapted to perform computational tasks consistent with the execution of computer-readable instructions stored in memory or a computer-readable storage medium.
[0109] Furthermore, any, all, or some of the computing devices in access point 618, terminal device 620, user DB 616, and DPSK server 610, AAA server 612, and PM server 614 may be adapted to run any operating system, including Linux, UNIX, Windows Server, etc., and virtual machines suitable for virtualizing the execution of a particular operating system, including custom and proprietary operating systems, and virtual containers, including Docker and LXC (Linux containers). Access point 618, terminal device 620, user DB 616, and DPSK server 610, AAA server 612, and PM server 614 may be further equipped with components to facilitate communication with other computing devices via one or more network connections (NC) 630. Network connections 630 may include connections to local area networks and wide area networks, wireless and wired networks, public and private networks, and / or any other communication networks that enable communication within the system.
[0110] exist Figure 6In this context, the end device 620 may include a personal computer, laptop computer, smartphone, tablet computer, personal digital assistant, set-top box, in-vehicle computing system, Internet of Things (IoT) device, and / or other similar computing device. Furthermore, the end device 620 may include one or more memories or memory locations for storing software components. The one or more memories in the end device 620 may include, but are not limited to, random access memory (RAM), dynamic random access memory (DRAM), read-only memory (ROM), logic blocks of a field-programmable gate array (FPGA), erasable programmable read-only memory (EPROM), and electrically erasable programmable ROM (EEPROM).
[0111] Furthermore, the terminal device 620 may include: a user interface (e.g., a keyboard, mouse, touch-sensitive display, etc.); and a network connection between the user and access point 618, set-top box 626, and / or television 628, etc., to allow the user to view and interact with applications, tools, services, and other software of the terminal device 620. This disclosure contemplates that more than one of the terminal devices 620 may be as follows: Figure 6 Part of the system shown.
[0112] Note that DPSK server 610 may be a web server providing authentication services. DPSK server 610 can use DPSK authentication to authenticate a given end device in end device 620. Furthermore, DPSK server 610 may include a data structure or database in which user identifiers and their DPSK passwords are stored. DPSK server 610 can communicate with access point 618 and AAA server 612 using network connection 630-1. Additionally, DPSK server 610 may use techniques to provide authentication of information provided from end device 620-1.
[0113] Additionally, the AAA server 612 may be a web server communicating with the DPSK server 610, PM server 614, and user DB 616 via network connection 630-2. The AAA server 612 may authorize the end device 620 and select the policy to be applied to the network access server (NAS) (in this case, the access point). In some embodiments, the AAA server 612 may have access to user accounts, the PM server 614, and / or the user DB 616. Note that the PM server 614 may include a database or data structure that includes location information (e.g., room number in a hotel) assigned to each customer.
[0114] Furthermore, user DB 616 can be a database of loyal customers. These loyal customers may come from loyalty programs of organizations, groups, etc. User DB 616 can be able to continuously store DPSK passwords, as well as information about end devices 620 connected to loyal customers and their family members.
[0115] Furthermore, access point 618 may include access points implementing WLAN protocol interfaces and Ethernet interfaces. Access point 618 can be understood as referring to an access point connected to a WLAN controller (e.g., Figure 1 Access point 618 is an access point that operates together with or in coordination with computer 112 in the computer. Additionally, access point 618 can be configured to broadcast a Service Specific Set Identifier (SSID). This disclosure envisions more than one of access points 618 being such as... Figure 6 Part of the system shown.
[0116] To provide a PAN that allows interconnection between customer devices and with a network (such as the Internet) while isolating them from interconnections with other customers, it is necessary to identify or group the end devices that should be grouped together to form the PAN. Additionally, forwarding policies need to be implemented on access point 618 and the Ethernet infrastructure (which may include switches and routers) to ensure that only members of the shared PAN can forward traffic between them. The PAN can be maintained regardless of where the end user carries their end device 620 within the entire area of the access point 618's radio or wireless range.
[0117] It should be noted that each end user or customer in a given group can be equipped with DPSK (e.g., a group DPSK password) or a password only. One or more of the end devices 620 of customers in a given group can be configured with the exact same password (sometimes referred to as a "public password"). All end devices 620 authenticating to the WLAN using the same password can receive the same services from the network. For example, all end devices 620 can be placed on the same VLAN, gain the same access to certain servers on the local area network (LAN), and be deprived of access to other servers and / or have the right to access the network (e.g., the Internet) at a certain maximum speed (in bits per second). Instead of putting all passwords into a single pool, DPSK authentication can be divided into sets (or groups) of smaller computational workloads, with a database or data structure binding between the WLAN and pool identifiers. This can provide efficient cloud-level computing, where compute nodes can be easily removed / added as the number of pools and / or WLANs served by the DPSK authentication service decreases / increases. Note that each password can be in a separate DPSK pool, and / or each DPSK pool can be used for authentication on one or more WLANs.
[0118] A single password can be provided to an end user, customer, or loyal customer, and that individual can provide the password to all end devices they carry or plan to carry to a specific location. Through this system, the infrastructure may not need to know the MAC address of the end device 620-1 to which the password is provided. This can lead to several problems. First, the end user does not need to provide the MAC address of their end device 620 to a specific location, organization, etc. This is beneficial to the end user because many end users are unfamiliar with the details of the network and may not know what a MAC address is or where it can be found on a given end device.
[0119] Additionally, the lack of a MAC address may make password authentication more computationally difficult, as infrastructure such as an AAA server (612) may not be able to simply use the MAC address as a key to look up the password in the database. Figure 6 The infrastructure within the system can employ encryption techniques to find matching passwords from a password pool or DPSK pool. Each DPSK pool can be identified by a pool identifier and can have a separate policy. Those skilled in the art will understand that alternative authentication techniques can replace DPSK. For example, IEEE 802.1X authentication is another technique used for authentication. Both techniques are secure and difficult to spoof (e.g., by impersonating the other to gain an illicit advantage through falsified data).
[0120] Traditionally, on WPA / WPA2 personal networks, all electronic devices are provided with the same password, thus preventing unique authentication. As described below, each end device 620 with a unique password can be uniquely authenticated. Furthermore, if end devices 620 are provided with a group DPSK password, they can be authenticated as belonging to that unique group. Therefore, the network can apply policies (such as VLAN assignment) suitable for each end device 620 or that group of electronic or end devices, as appropriate. This policy can be a set of conditions, constraints, and settings (or rules) that allow specifying who is authorized to connect to the network and the conditions under which they can connect.
[0121] Note that the specifications under the IEEE 802.11 standard describe the cryptographic calculation of PSK in detail, and PSK can be part of the DPSK password.
[0122] Figure 7-12 A flowchart is presented illustrating an embodiment of the present disclosure for use. Figure 6 An example of method 700, in which one or more electronic devices in a system initiate the implementation of cloud-level group authentication. Figure 7In operation 710, the terminal device 620-1 can be connected (or the terminal device 620-1 may already be in operation) and brought into the radio range of location 622-1. The terminal device 620-1 may discover that the WLAN is being broadcast by access point 618-1, recognize that it has been configured with a password for that SSID or WLAN, and join the network through access point 618-1. After joining the network, the terminal device 620-1 can begin password authentication.
[0123] Then, in operation 712, as part of the authentication exchange, access point 618-1, which can be configured to provide DPSK authentication for this WLAN, can send authentication requests to the DPSK server 610. In the following description, the RADIUS protocol is used as an illustrative example. However, it should be understood that other protocols can also be used for authentication requests, such as the Representational State Transition (REST) protocol, DIAMETER, etc.
[0124] exist Figure 8 In operation 714, DPSK server 610 can receive a request from end device 620-1 via access point 618-1. Furthermore, in operation 716, DPSK server 610 can check whether end device 620-1 is using the same password configured in DPSK server 610. If it is determined that the password does not match, authentication can be rejected in operation 718. Alternatively, if DPSK server 610 successfully authenticates end device 620-1, DPSK server 610 can obtain the EUI associated with that specific password in operation 720. Note that authentication can refer to encrypted information provided by end device 620-1 and derived from the password.
[0125] exist Figure 9 In operation 722, the DPSK server 610 can forward the authentication request and EUI to the AAA server 612 with a positive confirmation or approval, i.e., the end device 620-1 uses the same password configured in the DPSK server.
[0126] exist Figure 10 In operation 724, AAA server 612 can use EUI to transmit a name request for the end-user name to user DB 616. The name request can be anything shared by user DB 616 and PM server 614. Note that in operation 726, user DB 616 can respond with the end-user name returned to AAA server 612.
[0127] exist Figure 11In operation 728, AAA server 612 may transmit a location request to PM server 614 for a location assigned to an end-user name (e.g., a room number in a hotel). In operation 730, AAA server 612 may receive a location identifier message from PM server 614 as a response.
[0128] exist Figure 12 Prior to operation 732, AAA server 612 can look up the policy assigned to the location identifier (received from PM server 614) and other policies to be applied to the network connection of end device 620-1 in its internal database or data structure. In operation 732, AAA server 612 can transmit an access acceptance message including the policy to DPSK server 610. Then, in operation 734, DPSK server 610 can transmit the access acceptance message to access point 618-1.
[0129] The location identifiers and policies in operations 730 and 732 can take different forms depending on the embodiment. In some embodiments, the policy may be a VLAN identifier. In these embodiments, PM server 614 may maintain a mapping between locations and VLAN identifiers assigned to those locations, or another network device (e.g., AAA server 612 or a WLAN controller) may maintain the mapping between locations and VLAN identifiers assigned to those locations. After successful authentication with AAA server 612, end device 620-1 may be assigned to a VLAN. The VLAN identifier may be assigned to end device 620-1 by AAA server 612 and communicated to the NAS (e.g., access point 618-1) in the authentication response. Subsequently, frames and / or digital data transmission units transmitted to or received from end device 620-1 may be forwarded on the assigned VLAN.
[0130] exist Figure 7-12 In some embodiments of method 700, there may be additional or fewer operations. Furthermore, the order of operations may be changed, and / or two or more operations may be combined into a single operation.
[0131] In an environment where Method 700 can be deployed, such as a reception area in a hotel chain, it might be necessary to configure as many VLANs in the hotel network as customer rooms. Therefore, each customer room can have its own VLAN, thus providing a PAN for the customer assigned to that room. When a customer checks into the hotel, a VLAN / VLAN identifier can be assigned to them for their stay. Furthermore, in this particular environment, VLANs can be relayed between Ethernet switches, thereby extending VLANs throughout the network. In this scenario, the PAN can "roam" with the end device 620 (e.g., the PAN can remain unchanged when the end device 620 roams from one access point in the access points 618 to another).
[0132] In other embodiments, the customer can bring their own set-top box, which serves as a client device and is provided with the customer's DPSK password. When joining a WLAN, the client device can also join the customer's PAN. Alternative embodiments of this architecture are described below.
[0133] In some embodiments, the identifier may include two parameters: a home hub identifier and a group identifier. The home hub identifier may identify the access point 618-1 to which the set-top box 626-1 is connected. Note that the group identifier may be a PAN identifier assigned to at least a subset of the end devices 620.
[0134] Figure 6 An example of an embodiment is shown, in which the identifier includes a home hub identifier and a group identifier. End devices 620-1 and 620-2 in location 622-1 are both associated with access point 618-1. As a result of DPSK authentication, AAA server 612 can notify access point 618-1 that access point 618-1 is a home hub and that end devices 620-1 and 620-2 are both members of group identifier 1. Access point 618-1 can locally forward frames between 620-1 and 620-2. End device 620-3 belonging to an end user assigned to location 622-2 can connect to or be associated with access point 618-2. Through DPSK authentication, access point 618-2 can be notified that end device 620-3 is in group identifier 1 and that the home hub is access point 618-1. Since access point 618-2 has information that it is not the home hub of end device 620-3, access point 618-2 can forward frames from end device 620-3 toward its home hub. For example, access point 618-2 can use a mobile tunnel to forward frames to access point 618-1.
[0135] To establish a mobile tunnel, a home hub identifier (access point 618-1 in the previous example) can be used to determine how to reach the destination. When the home hub terminates the mobile tunnel, it can cache the Internet Protocol (IP) address of the tunnel initiator. Therefore, when a PAN member has data to send to another member of a PAN connected via the mobile tunnel, the home hub access point knows where to send the frame.
[0136] In some embodiments, one or more tunneling protocols may be used for mobile tunneling, such as, but not limited to, Ethernet IP (EoIP), GRE, VXLAN, or other mobile tunneling technologies or protocols.
[0137] When the tunnel termination home hub receives a frame encapsulated in a mobile tunnel, it can use a tunneling protocol that provides mutual authentication to verify the authenticity of the tunnel initiator. Another way to verify authenticity is to verify that the source IP address is bound to an authorized tunnel initiator (by the network administrator). This verification can be performed by querying the WLAN controller through access point 618-1 to see if the source IP address belongs to access point 618-2, or by verifying that access point 618-2 has at least one associated end device 620 belonging to a customer assigned to the home hub.
[0138] In some embodiments, the identifier may include two parameters: a group identifier and a device identifier. An example of an embodiment with this identifier would be when end devices 620-1 and 620-2 are associated with access point 618-1. AAA server 612 can notify access point 618-1, after DPSK authentication, that end devices 620-1 and 620-2 are members of group identifier 1. During association, access point 618-1 can receive the MAC addresses of end devices 620-1 and 620-2. Before forwarding a frame from a given end device, the MAC address of that end device (the source MAC address in the Ethernet frame) can be replaced with a MAC address that includes both the group identifier and the device identifier (examples shown in Table 1). After the MAC address is mapped, the frame can be forwarded into the network. Furthermore, once the MAC address is mapped, the frame can be forwarded to a wired network that can be bridged / routed as usual.
[0139]
[0140] Table 1.
[0141] Note that a MAC organizational unique identifier can have 2 24A range of MAC addresses. To ensure no conflict with any other MAC addresses existing on the network, a new organizationally unique MAC identifier can be obtained, for example, from IEEE and used for MAC mapping purposes. For example, as discussed above, two bytes can be reserved for the group identifier and one byte for the device identifier. However, other mapped MAC address formats are also possible. Another example of how this mapping can be illustrated is that if the organizationally unique MAC identifier is f0:b0:52, and then if the end device 620-1 is assigned to position 622-1 and the device identifier is 9, the mapped MAC address would be f0:b0:52:00:01:09.
[0142] Furthermore, if end device 620-1 has a frame to be sent to end device 620-2, access point 618-1 can receive the frame, map the source MAC address of the frame as previously described, and determine that the frame is destined for end device 620-2 by checking the destination MAC address in the frame. Because access point 618-1 knows from DPSK authentication that end device 620-1 is a member of group identifier 1, and because the mapped source MAC address has a matching group identifier, access point 618-1 can forward the frame to end device 620-1. However, if the group identifier in the mapped MAC address does not match the group identifier of the destination device, access point 618-1 will filter or discard the frame.
[0143] To further illustrate the operation of the customer's PAN, the end device 620-3 belonging to the customer assigned to location 622-2 can be connected to or associated with access point 618-2. As a result of DPSK authentication, access point 618-2 can be notified that end device 620-3 is in group identifier 1, which is the group assigned to the customer staying at location 622-1. End device 620-3 may have frames to be sent to end device 620-1. Access point 618-2 can receive the frame, map the source MAC address of the frame, and determine that the frame is addressed to an end device other than the end device wirelessly associated with access point 618-2 by checking the destination MAC address. Therefore, access point 618-2 can rely on the wired network in the hotel to forward the frame from its Ethernet interface to ensure that the frame reaches the correct access point. When access point 618-1 receives the frame, by checking the destination MAC address, access point 618-1 can recognize that the frame is addressed to end device 620-1. Because access point 618-1 knows that end device 620-1 is a member of group identifier 1, and that group identifier 1 is the group identifier in the source (mapped) MAC address, access point 618-1 can forward the frame to end device 620-1. If the group identifier extracted from the source (mapped) MAC address of the frame is not group identifier 1, then access point 618-1 has already filtered the frame.
[0144] Furthermore, to understand frame forwarding, in alternative embodiments, it may be important to understand how the Address Resolution Protocol (ARP) works when used with mapped MAC addresses. Consider the above-described scenario where end device 620-3 has a frame to send to end device 620-1. End device 620-3 knows the IP address of end device 620-1, but does not know its MAC address at the start of the process. Therefore, end device 620-3 can send an ARP request, requesting the network to provide the MAC address corresponding to the IP address of end device 620-1. When the ARP request reaches end device 620-1, end device 620-1 will send an ARP reply containing its MAC address.
[0145] Since network forwarding is at least partially based on the mapped MAC address of end device 620-1, access point 618-1 can replace the MAC address of end device 620-1 in the ARP response payload with its mapped MAC address. Therefore, end device 620-3 now has the mapped MAC address of end device 620-1. Once the ARP exchange is complete, end device 620-3 can send its message in a frame with its own MAC address as the source MAC address and the mapped MAC address of end device 620-1 as the destination MAC address. End device 620-3 sending the frame, and the network, know the destination device through its mapped MAC address rather than its native MAC address. Therefore, when a frame arrives at access point 618-1, access point 618-1 can know that end device 620-1 is a member of Group Identifier 1 and can replace the destination MAC address in the frame with the native MAC address of end device 620-1. Otherwise, end device 620-1 will filter the frame.
[0146] In the foregoing embodiment, the end device 620-1 sends an ARP reply; however, as a proxy ARP service, the ARP reply can be sent by the access point 618-1. The mapped MAC address option works in a similar manner with IPv6 neighbor requests.
[0147] Furthermore, in the aforementioned embodiments with mapped MAC addresses, the device identifier can be determined as follows: Since the MAC address of the end device 620 on the network must be unique, the entity providing the device identifier must ensure a unique mapping from the native MAC address of a given end device to its mapped MAC address. Additionally, since the group identifier will be unique for each end user or customer, a unique device identifier value can be provided to each end device of the user, thereby ensuring that no device identifier is duplicated. This can be handled in several ways.
[0148] AAA server 612 can maintain a list of each user's end devices 620 (which can be persistently stored in user DB 616 or AAA server 612). This list can include a unique device identifier for each MAC address. This works well as long as a single end user does not have, for example, more than 256 end devices. If there are more than 256 end devices, AAA server 612 can remove end devices from the list that have the earliest date / time of their last authentication to the network (and therefore the user may no longer be using them).
[0149] Furthermore, the AAA server 612 can maintain a list of active sessions for each user. There will be active sessions corresponding to each end device that the user has joined the network. Because standard practice limits the maximum number of end devices for a particular user, the AAA server 612 can ensure that the number of sessions is always less than the number of end devices allowed by the device identifier (256 devices in this example). If an end device is unassociated from the network, its session will also be deleted, and the previously used device identifier can now be reused for different end devices.
[0150] In some embodiments, it should be noted that the WLAN controller may perform the functions described in the preceding discussion, rather than the functions of the AAA server 612.
[0151] Furthermore, in some embodiments, the identifier may include a VLAN identifier. However, when access point 618-1 receives a VLAN identifier, it can be interpreted by access point 618-1 as a customer VLAN (C-VLAN) identifier. Additionally, a single VLAN can be configured on Ethernet switch 624 and relayed throughout the network. In some embodiments, access point 618 in the network can be configured to use IEEE 802.1ad (sometimes referred to as QinQ). Notably, external VLANs or service VLANs (S-VLANs) can be configured to have the same VLAN identifier as the Ethernet switched network. AAA server 612 can dynamically assign internal VLANs or C-VLANs. Each PAN can have a uniquely assigned C-VLAN identifier. The sequence of events can be the same as the VLAN identifier. Access point 618-1 can forward frames from end device 620-1 and can take one of two actions, at least in part, based on the destination MAC address of a given frame. If the MAC address is the MAC address of a PAN member, access point 618-1 can add C-VLAN and S-VLAN tags to the frame and can forward the frame upstream. If the destination MAC address is the same as the default router's MAC address, then only an S-VLAN tag needs to be added. Upon receiving a frame, the switching / routing infrastructure can forward the frame toward its destination.
[0152] In some embodiments, DPSK server 610, AAA server 612, PM server 614, and / or user DB 616 may be part of a single server. However, there are at least several reasons why the servers may remain separate. Keeping DPSK server 610 as a separate network entity can help support service scaling. Furthermore, the larger the user DB 616, the larger the DPSK pool. Additionally, when many DPSKs need to be checked, the computational load for finding matching passwords for authentication devices increases. With DPSK server 610 implemented in the cloud, the number of servers handling the computational workload can be dynamically increased or decreased as needed. When DPSK server 610 is implemented in the same network device as AAA server 612, the server cannot scale individually based on its own computational workload. However, in other embodiments, combining DPSK authentication and authorization into a single network device may be advantageous, and if implemented, it can be referred to as an AAA server.
[0153] An example of an environment that can handle method 700 is the reception area of a chain hotel. Some chain hotels have hundreds of locations, providing food, lodging, and entertainment services to tens of thousands of customers simultaneously. A cloud-based system can provide authentication capabilities for customers whenever they choose to join the hotel's network. Additionally, customers, including entire families, can share the same PAN, but the network can prevent children from accessing adult content, for example, by applying different policies to children than to parents. Customers can bring their end devices 620 to the hotel. If they are part of a loyalty program, their information can be included in the user database 616. Once a room is assigned to a customer (e.g., location 622-1), their end devices 620 can connect to the Internet and join the network connected via an access point assigned to that particular room (e.g., access point 618-1). One of the set-top boxes 626 and / or one of the televisions 628 can also be part of the space allocated to their PAN. The customer can then project from their end device onto the television, for example, without worrying that it will be playing on another television in another room. When using a set-top box, the set-top box 626 at location 622 can be used, or the customer can provide one or more set-top boxes 626 along with the terminal device 620. Note that the set-top box 626 can be connected to a corresponding television 628.
[0154] Please note that new services may become feasible with a system that configures multiple DPSK pools with different policies. For example, as previously mentioned, when customers (e.g., families) check into a hotel, parents may be given DPSK passwords with different policies than those given to children. The entire family can share a PAN because the system tracks both passwords as belonging to members of a single family, but the PAN prevents children from accessing adult content. Passwords used by parents and children can be generated in advance and persistently stored in the user's DB 616.
[0155] In some embodiments, one of the set-top boxes 626 (e.g., set-top box 626-1) may be connected to an Ethernet port on one of the access points 618 (e.g., access point 618-1) at location 622-1 and one of the televisions 628 (e.g., television 628-1). At another location 622-2, set-top box 626-2 may be connected to an Ethernet port on access point 618-2 and also to television 628-2, continuing at each additional location within the network. In other words, the disclosed communication technology can be used with wired and / or wireless electronic devices.
[0156] In some embodiments, Figure 6 The system may have fewer or additional electronic devices or components, two or more electronic devices or components may be combined into a single electronic device or component, a single electronic device or component may be divided into two or more electronic devices or components, and / or the position or location of a given electronic device or component may be changed.
[0157] In some embodiments, this communication technology can be used to provide secure communication, for example, in accommodation and entertainment services and / or other market segments. In this communication technology, PANs are dynamically created to provide interconnectivity between customers' electronic devices and a network (e.g., the Internet), while isolating them from communications associated with other customers. Furthermore, this communication technology identifies which electronic devices should be grouped together to form PANs. Forwarding policies are then enforced on access points and Ethernet infrastructure (e.g., switches and routers) to ensure that only members of a shared PAN can forward traffic between them.
[0158] To identify which electronic devices should form a single PAN, a password (such as a PSK, DPSK, or another type of digital certificate) can be provided to each hotel guest. For example, the password could include a group DPSK password or a group password. Note that each device with a DPSK password (or a group of electronic devices sharing a group DPSK password) can be uniquely authenticated. Because they can be authenticated, the network can apply policies (such as VLAN assignment) suitable for that electronic device (or group of electronic devices, depending on the situation). This differs from WPA / WPA2 personal networks, where all electronic devices on the network are given the same password, making unique authentication impossible.
[0159] Using group passwords, one or more electronic devices (groups) can receive the exact same password. All electronic devices authenticating to the WLAN using the same group password can receive the same services from the network. For example, all electronic devices can be placed on the same VLAN, gaining access to certain servers on the LAN, being deprived of access to other servers, and / or having access to the Internet at a certain maximum speed (in bits per second). Group passwords can be convenient and easy to use because a single password can be given or provided to a hotel customer (e.g., a loyalty customer), who can then provide the password to all electronic devices they bring (or plan to bring) to the hotel. Note that the infrastructure typically does not know the MAC address of the electronic device that has been provided with the group password. This means that customers do not need to tell the hotel the MAC address of their electronic devices. In fact, many customers do not even know what a MAC address is or where to find it on the device. Secondly, the lack of MAC addresses often makes group password authentication more computationally difficult because the infrastructure (e.g., an AAA server) cannot simply use the MAC address as a database key to look up the password in a database or data structure. Instead, the infrastructure can employ encryption to find a matching password from a set of passwords (sometimes called a "pool"). However, a variety of authentication technologies can be used.
[0160] For example, while DPSK authentication is one method where a single electronic device can be identified, subsequently authorized, and placed on a shared PAN, another authentication technology is IEEE 802.1X authentication (which uses several different scalable authentication protocol technologies). Both of these authentication technologies are secure and difficult to spoof if implemented / deployed correctly. Another authentication technology is MAC address authentication. In this technology, an electronic device is considered authenticated when it provides a known MAC address to the network. However, this authentication technology is insecure because MAC addresses are easily spoofed. Therefore, MAC address authentication is not used in many use cases, even though it can be used to apply common policies to a group of electronic devices, such as placing these devices on a shared PAN.
[0161] Another aspect of communications technology is cloud-level operation. This disclosure acknowledges that DPSK passwords are indeed authentication credentials. In existing methods, they have been used as so-called "Type II" credentials, which are useful for authentication on a single WLAN (or SSID). However, there is no reason to limit them in this way. If properly implemented by network infrastructure components, DPSK passwords can be used to authenticate electronic devices on any number of SSIDs.
[0162] In this communication technology, by forming DPSK passwords with shared public policies into DPSK pools (identified by pool identifiers), the application of user policies in WLANs can be simplified. This makes DPSK passwords easier to use as authentication credentials for multiple WLANs.
[0163] Furthermore, by creating a database or data structure binding between WLANs and pool identifiers, infrastructure can divide DPSK authentication problems (such as determining the password used by a specific end device from a set of provided passwords) into sets of smaller computational workloads. This enables highly efficient cloud-level computing, where compute nodes can be easily added / removed as the number of pools and / or WLANs served by the DPSK authentication service increases / decreases. Generally, this is more efficient than putting all passwords into a single large pool.
[0164] Furthermore, with a system where configuring multiple DPSK pools with different policies is straightforward, the deployment of new services can become feasible. For example, when a customer and their family check into a hotel, the parent might be given a DPSK password with a different policy than the one given to the child. This allows the entire family to share the same PAN (because infrastructure tracking identifies both passwords as belonging to members of the same family), but the network prevents the child from accessing adult content (e.g., the network could apply different policies to the child than to the parent). Alternatively, the passwords for parents and children could be pre-computed and persistently stored in a loyalty customer or user database.
[0165] Furthermore, some large hotel chains own hundreds of locations, providing accommodation and entertainment services to tens of thousands of customers, and there are many different hotel chains worldwide. Therefore, a cloud-based system can provide superior (secondary) authentication performance for all its customers whenever they choose to join the hotel's network.
[0166] For large hotel chains, the size of their loyalty customer database (i.e., the number of loyal customers) can be quite enormous (millions of users). To reduce the computational workload of DSPK authentication, the DPSK pool can be segmented. For example, a DPSK pool could exist that includes passwords from customers who only stay at specific hotel locations (e.g., only hotels in San Francisco). This would significantly reduce the number of passwords searched to find a match. Such a DPSK pool can be dynamically updated when a customer checks in or checks out of the hotel, or when a customer makes a reservation.
[0167] To further reduce the computational workload of DPSK authentication, MAC addresses can be stored in the loyalty database along with DPSK password bindings. For example, when a customer's electronic device joins a hotel's WLAN, the network can perform DPSK authentication on that device. After successful authentication, the DPSK server may already know the device's MAC address and password. For subsequent device authentications, whether at the same or different accommodations or hotels, the DPSK server can attempt to find a matching MAC address and a previously matched password stored in the loyalty database. In most cases, the device can continue to use the same password. Therefore, the computational workload of DPSK authentication requests is reduced from performing cryptographic calculations on a large password table (to find a matching password) to a database lookup followed by a single password verification (to confirm that the same password is still being used for the current authentication request). Using the loyalty database in this way can significantly improve system performance.
[0168] In some embodiments, different hotel operators may use different solutions, at least in part, based on their network designs. For example, a hotel operator may provide a set-top box that connects an in-room WLAN / LAN to a television. In this case, when a guest checks into the hotel and is assigned to a specific room, the guest's PAN may include the set-top box in that room, rather than in other rooms (e.g., it may be interconnected with it). This ensures that the video sent to the television originates from the guest's electronic device, and not from a different guest's electronic device (otherwise, adult content from different guests' electronic devices might be unintentionally displayed).
[0169] In another deployment scenario, hotel operators may not need to provide set-top boxes. Instead, customers can bring their own (e.g., Apple TV) and connect them to the TV. In this scenario, the customer's PAN may not need to be tied to their room assignment.
[0170] Furthermore, in some embodiments, dynamic VLAN allocation can be used to implement dynamic PAN. In dynamic VLAN allocation, after successful authentication with the WLAN (or more precisely, with the AAA server), the end device can be assigned to a VLAN. The VLAN identifier can then be assigned by the AAA server and transmitted to the NAS (e.g., access point) in the authentication response. Thereafter, all frames transmitted to or received from this device can be forwarded on the assigned VLAN.
[0171] Hotel operators may need to configure as many VLANs as guest rooms in their network. Each guest room can have its own VLAN, which facilitates the assignment of a PAN to the guest in that room. When a guest checks in, they can be assigned a VLAN or VLAN identifier for use during their stay. Note that this VLAN may not need to be bound to the room (unless the room includes a set-top box), but the hotel's network administrator can still use the binding (e.g., for convenience).
[0172] If hotel operators wish to use this communication technology, their network administrators may have to configure numerous VLANs throughout the hotel and relay them across the network. These VLANs may need to be relayed anywhere so that their PANs can "roam" with guests wherever they move within the hotel (so that the PAN remains unchanged as their mobile electronic devices roam from one access point to another). Furthermore, hotel operators may configure their infrastructure to support extensive VLAN configurations, configure a DHCP server to assign IP addresses to each VLAN / IP subnet, configure a default router for each VLAN, and so on.
[0173] Due to the complexity of configuring VLANs throughout the site, this communication technology can include alternatives to VLANs that are easier to deploy. It's worth noting that the network can use mobile tunneling and network modification of the MAC address of end devices (mapping to a new MAC address). However, these methods cannot require changes to the end devices.
[0174] In systems that implement communication technologies (e.g.) Figure 6In this system, the DPSK server can use DPSK authentication to authenticate end devices. The DPSK server may have a database that stores user identifiers and their DPSK passwords. Additionally, the AAA server can authorize end devices and select the policies to be applied to the NAS. The AAA server has access to user accounts, the PM server, and the loyalty customer database.
[0175] In addition to performing other functions, hotel operators can use PM servers to maintain a database or data structure containing the room number assigned to each customer. Additionally, a loyalty customer database can include a database of the hotel's loyal / frequent customers (such as customers registered for a hotel loyalty program). This loyalty customer database may be able to persistently store DPSK passwords and the MAC addresses of electronic devices or endpoints used by loyal customers and their family members.
[0176] Additionally, as previously discussed, access points can implement IEEE 802.11 wireless interfaces and Ethernet (Ethernet, Ethernet II, or wired IEEE 802.3) interfaces. In this discussion, "access point" can be understood as referring to an access point that may or may not operate with a WLAN controller.
[0177] During system operation, the access point may have been configured through its controller to broadcast the hotel's SSID. Over the air, the advertised security can be WPA Personal or WPA2 Personal.
[0178] Guests can then turn on their wireless electronic devices, or bring already operational electronic devices into their rooms, thus entering the radio range of one of the hotel's access points. The wireless electronic devices can discover the WLAN being broadcast by the access point, recognize that they are already configured with a PSK (or password) for that SSID, and can join the network. After joining the network, the electronic device can begin PSK authentication.
[0179] As part of the authentication exchange, access points configured to provide DPSK authentication for this WLAN can send authentication requests to the DPSK server. Note that while the RADIUS protocol can be used for this communication, it should be understood that other protocols, such as DIAMETER, Hypertext Transfer Protocol, or HTTP (e.g., REST protocol), can also be used for authentication requests. Authentication request messages in RADIUS can be referred to as access request messages, and responses can be referred to as access accepted (permission) or access denied (deny) messages. If the DPSK server successfully authenticates the electronic device or end device (e.g., the DPSK server is equipped with the same DPSK password used by the electronic device), the DPSK server can look up the end-user identifier associated with this password. The DPSK server can then forward the authentication request, which may include the end-user identifier, to the AAA server.
[0180] The AAA server can query a loyalty customer or user database to provide user identifiers. The loyalty customer database can be responded to using the customer's name.
[0181] Please note that in some deployments, an AAA server may already exist. When adding DPSK authentication, if implemented as a separate network entity (e.g., a server), it can minimize any changes to the AAA server. The AAA server can continue to be responsible for authorization and can decide whether to accept successfully authenticated electronic devices and select appropriate policies for them.
[0182] Another reason for maintaining the DPSK server as a separate network entity is service scaling. For large hotel chains with very large loyalty customer databases, the DPSK pool is often also very large. This means the computational workload for finding matching passwords to authenticate electronic devices can be considerable. When implementing DPSK services in the cloud, the number of servers handling the computational workload can be dynamically increased (or decreased) as needed. If the DPSK service is implemented in the same network appliance as the AAA server, the server cannot scale individually based on its own computational workload.
[0183] In some deployments, it may be advantageous to combine DPSK authentication and authorization into a single network device, which can be referred to as an AAA server.
[0184] Next, the AAA server can query the PM server to obtain the room number assigned to the customer. In some deployments, the PM server may maintain a mapping between room numbers and the VLAN identifiers assigned to that room (e.g., VLAN identifier 10). In this case, the PM server may return the VLAN identifier instead of the room number. In other deployments, another network device (e.g., the AAA server or controller) may maintain the mapping from room numbers to VLAN identifiers. If the mapping is in the AAA server, the AAA server can look up the VLAN identifier based at least in part on the room number provided by the PM server. Note that if the hotel operator provides in-room set-top boxes to its customers, the PM server may maintain a mapping from room numbers to VLAN identifiers, where the VLAN (of a specific VLAN identifier) can access the in-room TV but not the TVs in other rooms. However, if the hotel operator does not provide in-room set-top boxes, the PM server may only need to maintain the binding of the VLAN identifier assigned to each customer. In some embodiments, there may be up to 4,096 VLAN identifiers, so this table may need to be updated continuously, periodically, or as needed.
[0185] In addition, the AAA server can send an access acceptance message to the access point that includes the VLAN identifier of the customer's room. In some embodiments, the AAA server may use one or more RADIUS tunneling attributes according to RFC-3580 to transmit the assigned VLAN identifier.
[0186] Please note that the access point may be configured for dynamic VLANs (for example, the access point may accept a VLAN identifier from the AAA server and use this label to tag frames from authenticated electronic devices), and the Ethernet switch may be configured to allow VLANs used in the hotel to be relayed on the switch port (this ensures that regardless of which access point a customer's electronic device authenticates with, the access point can use the VLAN identifier and the switch port to which the access point is connected to to tag frames, so that the switch will accept the tagged frames and forward them within the VLAN).
[0187] Furthermore, the first end device in Room 1 can be placed on a specific VLAN (such as VLAN 10) after authenticating to the hotel's Wi-Fi network. When a second end device belonging to a customer in Room 1 is associated with another access point in Room 2 and connects to the Wi-Fi network, it can also be placed on VLAN 10, thus forming a PAN. Therefore, this PAN can be maintained regardless of where the customer carries the end device within the hotel's Wi-Fi network.
[0188] Additionally, the first set-top box can be connected to an Ethernet port on an access point in room 1, or to the first television in that room (typically via HDMI). This Ethernet port can be configured as a port-based member of VLAN 10. Therefore, frames sent to the first set-top box can only be forwarded from VLAN identifier 10 and can only be accessed by end devices of customers also on VLAN identifier 10. Note that it is not always necessary for the set-top box to stream video to the television. For example, in some deployments, the television may be DLNA compliant, and DLNA-compliant video sources can stream video (e.g., Ethernet frames) directly to the television. Therefore, it should be understood that the use of the set-top box is for illustrative purposes only.
[0189] Although the communication technology is described as having the AAA server, PM server, and loyalty customer database as separate components, it should be understood that the loyalty customer database can be integrated into the AAA server or PM server.
[0190] In some deployments, configuring Ethernet switches for numerous VLANs across the entire asset can be considered an excessive burden on network administrators. Therefore, several alternatives can be used, including some that do not include VLANs.
[0191] The first alternative is called the tunneled PAN alternative. As previously mentioned, VLANs are not used in this alternative. The sequence of events is the same as described above; however, the AAA server can return two parameters: a home hub identifier and a group identifier, instead of a VLAN identifier. The home hub identifier can be an identifier used by the home hub. Notably, the home hub can be the access point to which the set-top box is connected. The role of the home hub can be to forward frames from one of the customer's end devices to one or more other end devices in the customer's PAN, and to filter (or discard) frames sent from devices not in the customer's PAN. As previously mentioned, if the hotel operator provides set-top boxes, the customer's end devices can be assigned to a home hub serving the room to which the customer is assigned.
[0192] The binding of the home hub identifier to the room number is typically maintained by the PM server (as discussed earlier, it can also be maintained by the AAA server or controller). If the hotel operator has deployed an access point for each room, the home hub identifier can refer to the access point in the room. However, if several rooms share an access point, then the home hub identifier is likely the one closest (measured in hop count) to the shared access point for a given room. It's likely to be the closest access point to that room because most traffic within the PAN likely originates indoors and heads towards the destination end device, which is also in the room. By keeping the access point close to the room, traffic in the distribution layer of the hotel's network can be reduced or minimized (e.g., this keeps traffic within the access layer). Note that this is an optimization, as the home hub can, in principle, be any access point in the hotel's network. Therefore, for example, if the access point closest to the guest's room fails, another nearby access point can be designated as the home hub.
[0193] The AAA server can also return a group identifier. This group identifier can be the PAN identifier assigned to the customer's end device. The network can forward frames simply from one group member to another or towards the Internet. Note that if the first set-top box connects wirelessly (instead of using Ethernet) to the access point in room 1, it can also use DPSK authentication and, in a similar manner, a group identifier can be assigned to this room by the AAA server. Therefore, it will be a member of the PAN assigned to the customer in that room.
[0194] For example, suppose the first and second end devices in room 1 are associated with this access point. As a result of DPSK authentication, the AAA server can inform the access point that it is a home hub and that both end devices are members of group identifier 1. In this way, the access point can locally forward frames between the first and second end devices. Now, suppose the third end device (belonging to a customer assigned to room 1) is connected to the access point in room 2. As a result of DPSK authentication, this access point can be informed that the third end device is in group identifier 1 and that the home hub is the access point in room 1. Since the access point in room 2 now knows it is not the home hub of the third end device, it can forward frames from the third end device to the home hub. Once the home hub receives the frame, it can either forward the frame to the destination end device in the group (for unicast frames) or flood (copy) the frame to all group members (for broadcast and multicast frames).
[0195] The access point in room 2 can use a mobile tunnel to forward frames to the access point in room 1. Frames received in the mobile tunnel can be decapsulated by the access point in room 1 (to obtain the original Ethernet frame transmitted by the access point in room 2) and then forwarded to the destination end device.
[0196] To establish a mobile tunnel, the tunnel initiator (in this example, the access point in room 2) needs to know how to reach the tunnel destination (in this example, the access point in room 1). The home hub identifier can be used to determine this. There are several options for the home hub identifier. For example, the home hub identifier can be set to the IP address of the access point in room 1. In this case, upon receiving the home hub identifier, the tunnel initiator knows the tunnel destination. Other examples could include setting the home hub identifier to the name of the access point or the NAS identifier of the access point. If one of these options is used, the access point can use the home hub identifier as a query parameter to query the controller to find or obtain the access point's IP address. Alternatively, if the controller is acting as a RADIUS agent, it can insert the home hub access point's IP address as an attribute into the access acceptance message and then forward it to the NAS client / home hub (in this example, the access point in room 2).
[0197] When a home hub terminates a mobile tunnel, it can cache (or remember) the tunnel initiator. Therefore, when a PAN member has data to send to another PAN member connected via a mobile tunnel, the home hub access point can know where to send the frame (e.g., it must use the mobile tunnel, and if more than one mobile tunnel is currently established, which one to use).
[0198] Many tunneling protocols can be used for mobile tunneling. For example, a tunneling protocol may include EoIP. In this protocol, Ethernet frames received by the tunnel initiator (the access point in room 2) can be embedded within IP packets as defined in RFC-2784, GRE. Alternatively, a proprietary version of GRE can be used. In some embodiments, the tunneling protocol may include VXLAN according to RFC-7348.
[0199] When the tunnel termination device receives a frame encapsulated within a mobile tunnel, it can verify the authenticity of the tunnel initiator (for security reasons, such as ensuring an attacker doesn't attempt to breach PAN restrictions). There are several ways to achieve this. One way is to use a tunneling protocol that provides mutual authentication. Another way is for the tunnel termination device to verify that the source IP address is bound to a tunnel initiator authorized (by the network administrator). In this case, the tunnel termination device (access point in room 1) can query the controller to see if the source IP address belongs to the tunnel initiator (access point in room 2). A more robust check is to verify that the tunnel initiator possesses the associated end device belonging to the customer assigned to that home hub.
[0200] A variant of the tunneled PAN alternative uses Layer-3 routing instead of switching and operates in a similar manner. In this case, each access point / home hub can combine the functions of a default router and a Dynamic Host Control Protocol (DHCP) server. When a first end device joins, it can notify the access point it serves (in room 1) via a RADIUS access accept message that it is the home hub for this end device. Therefore, when it receives a DHCP request from the first end device, it can assign an IP address. When a third end device joins the access point in room 2, it can notify this access point that the access point in room 1 is the home hub. Therefore, the access point in room 2 can create a Proxy Mobile IP (PMIP) tunnel (or another IP-in-IP tunnel) to the access point in room 1 and can tunnel packets or frames from the first end device to access point 1. Thus, from the perspective of the first end device, it may appear to be located in an IP subnet served by the default router of the access point in room 1.
[0201] The second alternative is called the mapped MAC address alternative. As discussed earlier, VLANs are not used in this alternative. The AAA server may return a group identifier and, optionally, a device identifier, but not a VLAN identifier. Note that the device identifier may or may not be provided by the AAA server. For example, the controller may provide the device identifier as an attribute in the access acceptance message before forwarding it to the NAS client / access point.
[0202] For example, suppose a first end device and a second end device are associated with an access point in room 1. As a result of DPSK authentication, the AAA server can notify the access point in room 1 that both end devices are members of group identifier 1. During the association process, the access point can learn the MAC addresses of the first and second end devices. In this alternative, when the access point associated with the customer's end device (the access point in room 1) receives a frame from the customer's end device, it can replace the MAC address of the end device (the source MAC address in the Ethernet frame) with a different MAC address before forwarding the frame. This different MAC address may partially include the group identifier and the device identifier. After such mapping (or replacement or modification) of the MAC address, the frame can be forwarded in the wired network where it is bridged or routed as usual.
[0203] As shown in Table 1, the mapped MAC address can include a MAC organizational unique identifier, a group identifier, and a device identifier. Note that the MAC organizational unique identifier has 2... 24 A range of MAC addresses. To ensure no conflict with any other MAC addresses existing on the hotel's network, a new organizationally unique MAC identifier can be obtained (e.g., from IEEE) and used for MAC mapping purposes. In this example, two bytes have been reserved for the group identifier (accommodating up to 65,535 rooms in the hotel), and one byte has been reserved for the device identifier (accommodating 256 end devices per customer). However, other mapped MAC address formats are possible. In some embodiments, if the organizationally unique MAC identifier is f0:b0:52, the first end device is assigned to room 1 (group identifier 1), and the device identifier is 9, whose mapped MAC address could be f0:b0:52:00:01:09.
[0204] Suppose a first end device has a frame to be sent to a second end device. An access point can receive this frame, map its source MAC address as previously described, and determine that the frame is destined for the second end device by examining the destination MAC address within the frame. Because the access point (from DPSK authentication) knows that the end device is a member of Group Identifier 1, and because the mapped source MAC address has a matching group identifier, the access point can forward the frame to the second end device. However, if the group identifier in the mapped MAC address does not match the group identifier of the destination device, the access point will filter (or discard) the frame.
[0205] To further illustrate the operation of the customer's PAN, assume a third end device (belonging to the customer assigned to room 2) is connected to the access point in room 2. As a result of DPSK authentication, the access point in room 2 can be notified that the third end device is in group identifier 1 (the group assigned to the customer staying in room 1). Now assume the third end device has a frame to send to the first end device. The access point in room 2 can receive this frame, map the source MAC address of the frame, and determine, by checking the destination MAC address, that the frame is directed to an end device other than the one wirelessly associated with the access point in room 2. Therefore, the access point in room 2 can rely on the hotel's wired network to forward the frame from its Ethernet interface so that the frame reaches the correct access point (the access point associated with the first end device). When the access point in room 1 receives the frame, by checking the destination MAC address, the access point in room 1 can recognize that the frame is directed to the first end device. Because the access point in room 1 knows that the first end device is a member of group identifier 1, and group identifier 1 is the group identifier in the source (mapped) MAC address, the access point in room 1 can forward the frame to the first end device. However, if the group identifier extracted from the source (mapped) MAC address of the frame is not group identifier 1, then the access point in room 1 has filtered the frame.
[0206] To complete the explanation of frame forwarding, it may be helpful to understand how ARP works when used with mapped MAC address substitutions. Consider again the case where a third-end device has a frame to send to a first-end device. At the start of this process, the third-end device may know the first-end device's IP address but not its MAC address. Therefore, the third-end device can send an ARP request requesting the network to provide the MAC address corresponding to the first-end device's IP address. When the ARP request reaches the first-end device, the first-end device can send an ARP reply containing its MAC address. As previously stated, because network forwarding can be based at least in part on the first-end device's mapped MAC address, the access point in room 1 can replace the first-end device's MAC address in the ARP response payload with the mapped MAC address. Therefore, the third-end device can now have the first-end device's mapped MAC address. Now that the ARP exchange has been completed, the third-end device can send its message in a frame with its own MAC address as the source MAC address and the first-end device's mapped MAC address as the destination MAC address. Thus, both the sending end device and the network know the destination device through its mapped MAC address instead of its native MAC address. Therefore, when a frame arrives at the access point in room 1, the access point in room 1 knows that the first end device is a member of group identifier 1, and can replace the destination MAC address in the frame with the native MAC address of the first end device (otherwise, the first end device will filter the frame).
[0207] In the preceding discussion, the first end device sent an ARP reply. Alternatively, the ARP reply may have already been sent by the access point in room 1 (e.g., using a proxy ARP service). In this case, the access point in room 1 will generate the ARP reply payload using the mapped MAC address of the first end device. In some embodiments, an IPv6 neighbor request can be used in a similar manner.
[0208] Furthermore, to complete the explanation of the MAC address mapping alternatives, we discuss how device identifiers can be determined. Since the MAC addresses of electronic devices on a network must be unique, the entity providing the device identifier can ensure a unique mapping from the electronic device's native MAC address to its mapped MAC address. Additionally, since group identifiers are unique for each guest staying at a hotel, a unique device identifier value can be provided to each guest's electronic device, thus ensuring that no device identifier is duplicated. There are several methods to achieve this.
[0209] It's worth noting that the AAA server can maintain a list of end devices for each customer (persistently stored in the loyalty card database or the AAA server). In this list, each MAC address may have a unique device identifier. This method works as long as a single customer doesn't have more than 256 end devices. However, if more than 256 end devices are found, the server can remove end devices from the list that have the earliest date / time of their last authentication to the network (and therefore, the user may no longer be using them).
[0210] Alternatively, the AAA server can maintain a list of active sessions for each customer. There will be active sessions corresponding to each end device the customer has joined the network. Furthermore, because the maximum number of end devices for a particular customer can be limited, the AAA server can ensure that the number of sessions is always less than the number of end devices allowed by the device identifier (256 end devices in the previous example). If a customer's end device is unassociated from the network, its session may also be deleted, and the previously used device identifier can now be reused for different end devices. In some embodiments, the controller can perform these operations on behalf of the AAA server.
[0211] The third alternative is called the QinQ alternative. This alternative can use VLANs, but it offers a different VLAN usage than those described previously. In the QinQ alternative, a single VLAN can be configured on the Ethernet switch and relayed throughout the hotel's network. Access points in the network can be configured to use QinQ. Notably, external VLANs or S-VLANs can be configured to have the same VLAN identifier as the Ethernet switched network. The AAA server can dynamically assign internal VLANs or C-VLANs.
[0212] In the QinQ alternative, the sequence of events can be the same as previously described. However, the VLAN identifier returned by the AAA server can be interpreted by the access point as a C-VLAN identifier. Because the PAN is interconnected with the customer's wireless end device, a unique C-VLAN identifier can be assigned to each customer's PAN. When the access point forwards a frame from the end device, it can act at least in part based on the frame's destination MAC address. If the MAC address is that of a PAN member, the access point can add both C-VLAN and S-VLAN tags to the frame and forward the frame upstream. Alternatively, if the MAC address is that of the default router (e.g., the frame is directed to a host on the Internet), the access point can add only the S-VLAN tag. Upon receiving a frame, the switching infrastructure can forward the frame toward its destination.
[0213] In some embodiments, at least some operations of the access point can be implemented by one or more switches in the network. For example, if the authentication protocol is IEEE 802.1X or Extensible Authentication Protocol, the switch will communicate with the AAA server and may directly receive group identifiers, VLAN identifiers, or other policies. Alternatively, if the switch is notified, for example, by an access point that is a member of a PAN group, the switch may implement home hub functionality.
[0214] In some embodiments of this communication technology, a public password is shared with as many electronic devices as needed. A back-end comparison (e.g., performed by an AAA server or another computer) can be used to determine whether a given electronic device is allowed to access the network. This AAA server (or other computer) may store policies (or permissions for the electronic device), passwords, and / or authentication information for the electronic device.
[0215] In this communication technology, hotel users can select a wireless network on their cellular phone and then enter their password (such as PSK or DPSK). Initially, users may not be allowed access to the hotel's network. Instead, they can have an encrypted connection to an access point that can perform at least some of the operations required by this communication technology.
[0216] As previously mentioned, passwords can be shared or used by a group of electronic devices. Typically, multiple groups of electronic devices may join the same network, and each group of devices may have different passwords.
[0217] After receiving the password from the access point, the AAA server can look up or access the policy to be applied to the user. For example, the policy could place the user's electronic devices on a separate virtual network (or VLAN).
[0218] Note that the password can be provided to the user via email or SMS (text) message. Alternatively, the user can receive the password via an application associated with the venue or location (such as a hotel or university residence).
[0219] In some embodiments, this communication technique uses microsegmentation to allow more than 4,096 virtual networks. For example, a virtual data plane can be used to implement virtual networks (for a given PAN). Access points can be connected to the virtual data plane.
[0220] It is worth noting that a virtual network can be specified, for example, using a 24-bit identifier in the GRE header (sometimes called the VNI). This can be useful in embodiments or applications with a large number of users, such as in university buildings. With more students, there can be more VLANs. However, in some architectures, it is not possible to have more than 4,096 VLANs. 24 bits can overcome this limitation, allowing up to 16 million VLANs for micro-segmentation. In some embodiments, QinQ is used instead of the VNI.
[0221] When an electronic device authenticates (using DPSK or other types of authentication), the AAA server can look up or access the VNI and can forward it back to the access point in response to a request from the access point. The virtual data plane can use this VNI, allowing it to bridge traffic within this virtual network. Therefore, all packets or frames with the same VNI can be bridged together (instead of using VLANs).
[0222] In embodiments where electronic devices are connected via Ethernet jacks or ports, this communication technology ensures that these electronic devices and wireless electronic devices are on the same VNI. For example, a switch can capture Ethernet frames entering your room and place them into a VXLAN. These packets or frames can also enter a virtual data plane, and the VNI can be placed in the packet or frame header. Therefore, a given student's electronic devices can connect to the same VNI.
[0223] Note that the switch can know the VNI to which an electronic device belongs, at least in part, based on the location of the Ethernet or communication port (e.g., at least in part, based on the static assignment of a room number). Alternatively, students can use a forced portal window in which they provide the identifier that is returned to the switch.
[0224] For example, in a hotel room, a set-top box can be connected to a wired Ethernet port. During installation, a copy of the port's MAC address can be placed in an AAA server (e.g., the set-top box is in room 1). Then, when the set-top box begins communication, the AAA server will recognize it.
[0225] In some embodiments, a RADIUS attribute or VSA, such as Ruckus VSA 153 (which is a DPSK VSA), is used to transmit the password. Furthermore, in some embodiments, the password may be encrypted during at least a portion of the communication. In these embodiments, the access point may optionally provide a decryption key, enabling the password to be decrypted.
[0226] Furthermore, a password can be provided during the four-way handshake. For example, frames 1 and 2 can provide encrypted information sent in the RADIUS access request. This information enables the access point to subsequently receive the password from the electronic device.
[0227] We now describe embodiments of electronic devices that may perform at least some of the operations in communication technologies. Figure 13 A block diagram illustrating an example of an electronic device 1300 according to some embodiments is presented, said electronic device being, for example, one of the following: base station 108, one of electronic devices 110, computer 112, one of access points 116, one of radio nodes 118, switch 128, AAA server 130, DPSK server 610, AAA server 612, PM server 614, user database 616, one of access points 618, and / or one of end devices 620. This electronic device includes a processing subsystem 1310, a memory subsystem 1312, and a network subsystem 1314. The processing subsystem 1310 includes one or more devices configured to perform computational operations. For example, the processing subsystem 1310 may include one or more microprocessors, graphics processing unit (GPU), ASIC, microcontroller, programmable logic device, and / or one or more digital signal processors (DSPs).
[0228] Memory subsystem 1312 includes one or more means for storing data and / or instructions for processing subsystem 1310 and network subsystem 1314. For example, memory subsystem 1312 may include DRAM, static random access memory (SRAM), and / or other types of memory. In some embodiments, instructions in memory subsystem 1312 for processing subsystem 1310 include one or more program modules or instruction sets (e.g., program instructions 1322 or operating system 1324, such as Linux, UNIX, Windows Server, or another custom and proprietary operating system) that can be executed by processing subsystem 1310. Note that one or more computer programs, program modules, or instructions may constitute a computer program mechanism. Furthermore, instructions in various modules within memory subsystem 1312 may be implemented in a high-level programming language, an object-oriented programming language, and / or assembly or machine language. Additionally, the programming language may be compiled or interpreted, for example, configurable or customizable (used interchangeably in this discussion), for execution by processing subsystem 1310.
[0229] Additionally, the memory subsystem 1312 may include mechanisms for controlling access to the memory. In some embodiments, the memory subsystem 1312 includes a memory hierarchy that includes one or more caches of memory coupled to the electronic device 1300. In some of these embodiments, the one or more caches are located within the processing subsystem 1310.
[0230] In some embodiments, the memory subsystem 1312 is coupled to one or more high-capacity mass storage devices (not shown). For example, the memory subsystem 1312 may be coupled to a magnetic or optical driver, a solid-state driver, or another type of mass storage device. In these embodiments, the memory subsystem 1312 may be used by the electronic device 1300 as a fast-access memory for frequently used data, while the mass storage device is used to store data that is not frequently used.
[0231] Network subsystem 1314 includes one or more means configured to couple to and communicate (i.e., perform network operations) on wired and / or wireless networks, including: control logic 1316, interface circuitry 1318, and one or more antennas 1320 (or antenna elements). (Although) Figure 13 While including one or more antennas 1320, in some embodiments, electronic device 1300 includes one or more nodes, such as antenna node 1308, such as a metal plate or connector, which can be coupled to one or more antennas 1320 or nodes 1306, said one or more antennas or nodes can be coupled to wired or optical connections or links. Therefore, electronic device 1300 may or may not include one or more antennas 1320. Note that one or more nodes 1306 and / or antenna node 1308 can constitute inputs and / or outputs of electronic device 1300. For example, network subsystem 1314 may include Bluetooth. TM Network systems, cellular network systems (e.g., 3G / 4G / 5G networks, such as UMTS, LTE, etc.), Universal Serial Bus (USB) network systems, coaxial cable interfaces, High Definition Multimedia Interface (HDMI), and network systems based on standards described in IEEE 802.11 (e.g., Wi-Fi). ® Network system), Ethernet network system, and / or another network system.
[0232] Note that pattern shapers (e.g., directional or reflectors) and / or one or more antennas 1320 (or antenna elements) can be used to adapt or alter the transmitting or receiving antenna pattern (or antenna radiation pattern) of the electronic device 1300. These pattern shapers and / or one or more antennas can be independently and selectively electrically coupled to the ground to manipulate the transmitting antenna pattern in different directions. Therefore, if one or more antennas 1320 include N antenna pattern shapers, then the one or more antennas can have 2 N Different antenna pattern configurations. More generally, a given antenna pattern may include the amplitude and / or phase of a signal that specifies the direction of the main lobe or main lobe of the given antenna pattern, as well as so-called "exclusion regions" or "exclusion areas" (sometimes referred to as "notches" or "invalid regions"). Note that the exclusion region of a given antenna pattern includes low-intensity areas of the given antenna pattern. While the intensity in the exclusion region is not necessarily zero, it may be below a threshold, such as 3 dB, or below the peak gain of the given antenna pattern. Therefore, a given antenna pattern may include local maxima (e.g., primary beam) that guide gain in the direction of the electronic device of interest 1300, and one or more local minima that reduce gain in the direction of other electronic devices of no interest. In this way, a given antenna pattern can be selected such that unwanted communication (e.g., with other electronic devices) is avoided to reduce or eliminate adverse effects, such as interference or crosstalk.
[0233] Network subsystem 1314 includes a processor, controller, radio / antenna, socket / plug, and / or other means for coupling with each supported network system, communicating on each supported network system, and processing data and events of each supported network system. Note that the means for coupling with, communicating with, and processing data and events of each network system are sometimes collectively referred to as the “network interface” of the network system. Furthermore, in some embodiments, a “network” or “connection” between the electronic devices does not yet exist. Therefore, electronic device 1300 can use the mechanisms in network subsystem 1314 to perform simple wireless communication between electronic devices, such as transmitting advertising or beacon frames and / or scanning advertising frames transmitted by other electronic devices, as previously described.
[0234] Within electronic device 1300, a processing subsystem 1310, a memory subsystem 1312, and a network subsystem 1314 are coupled together using a bus 1328. The bus 1328 may include electrical, optical, and / or electro-optical connections that the subsystems can use to transmit commands and data between each other. Although only one bus 1328 is shown for clarity, different embodiments may include different numbers or configurations of electrical, optical, and / or electro-optical connections between the subsystems.
[0235] In some embodiments, the electronic device 1300 includes a display subsystem 1326 for displaying information on a display, the display subsystem including a display driver and a display, such as a liquid crystal display, a multi-touch screen, etc.
[0236] In addition, the electronic device 1300 may include a user interface subsystem 1330, such as a mouse, keyboard, touchpad, stylus, voice recognition interface, and / or another human-machine interface. In some embodiments, the user interface subsystem 1330 may include or be able to interact with a touch-sensitive display in the display subsystem 1326.
[0237] Electronic device 1300 can be any electronic device having at least one network interface (or can be included in any such electronic device). For example, electronic device 1300 can be (or can be included in): desktop computer, notebook computer, small notebook computer / netbook, server, tablet computer, cloud-based computing system, smartphone, cellular phone, smartwatch, wearable electronic device, consumer electronic device, portable computing device, access point, transceiver, router, switch, communication equipment, eNodeB, controller, test equipment, and / or another electronic device.
[0238] Although specific components are used to describe electronic device 1300, in alternative embodiments, different components and / or subsystems may be present in electronic device 1300. For example, electronic device 1300 may include one or more additional processing subsystems, memory subsystems, network subsystems, and / or display subsystems. Additionally, one or more of these subsystems may not be present in electronic device 1300. Furthermore, in some embodiments, electronic device 1300 may include... Figure 13 One or more additional subsystems not shown. Additionally, although... Figure 13 While individual subsystems are shown, in some embodiments, some or all of a given subsystem or component may be integrated into one or more other subsystems or components in electronic device 1300. For example, in some embodiments, instructions 1322 are included in operating system 1324, and / or control logic 1316 is included in interface circuitry 1318.
[0239] Furthermore, the circuits and components in the electronic device 1300 can be implemented using any combination of analog and / or digital circuits, including bipolar, PMOS, and / or NMOS gates or transistors. Additionally, the signals in these embodiments can include digital signals with approximately discrete values and / or analog signals with continuous values. Furthermore, the components and circuits can be single-ended or differential, and the power supply can be unipolar or bipolar.
[0240] Integrated circuits (sometimes referred to as "communication circuits") can implement some or all of the functions of network subsystem 1314 and / or electronic device 1300. Integrated circuits may include hardware and / or software mechanisms for transmitting wireless signals from electronic device 1300 and receiving signals from other electronic devices at electronic device 1300. In addition to the mechanisms described herein, wireless devices are generally known in the art and therefore not described in detail. Generally, network subsystem 1314 and / or integrated circuits may include any number of wireless devices. Note that the wireless devices in the multi-wireless device embodiment function in a similar manner to the described single-wireless device embodiment.
[0241] In some embodiments, the network subsystem 1314 and / or integrated circuit include a configuration mechanism (e.g., one or more hardware and / or software mechanisms) that configures the radio device to transmit and / or receive on a given communication channel (e.g., a given carrier frequency). For example, in some embodiments, the configuration mechanism may be used to switch the radio device from monitoring and / or transmitting on a given communication channel to monitoring and / or transmitting on a different communication channel. (Note that, as used herein, "monitoring" includes receiving signals from other electronic devices and possibly performing one or more processing operations on the received signals.)
[0242] In some embodiments, the output of the process for designing an integrated circuit or a portion thereof (including one or more circuits described herein) may be a computer-readable medium, such as magnetic tape, optical disc, or magnetic disk. The computer-readable medium may be encoded with data structures or other information describing the circuit, which may be physically instantiated as an integrated circuit or a portion thereof. Although various formats may be used for such encoding, these data structures are typically written in Caltech Intermediate Format (CIF), Calma GDS II Stream Format (GDSII), or Electronic Design Exchange Format (EDIF). Those skilled in the art of integrated circuit design can develop such data structures from schematic diagrams and corresponding descriptions of the types detailed above, and encode data structures on computer-readable media. Those skilled in the art of integrated circuit manufacturing can use such encoded data to manufacture integrated circuits including one or more circuits described herein.
[0243] While the foregoing discussion uses Wi-Fi and / or Ethernet communication protocols as illustrative examples, a wide variety of communication protocols and more generally, communication technologies can be used in other embodiments. Therefore, communication technologies can be used in a variety of network interfaces. Furthermore, although some operations in the foregoing embodiments are implemented in hardware or software, in general, the operations in the foregoing embodiments can be implemented in a wide variety of configurations and architectures. Therefore, some or all of the operations in the foregoing embodiments can be performed in hardware, in software, or both. For example, at least some operations in the communication technology can be implemented using program instructions 1322, operating system 1324 (e.g., a driver for interface circuit 1318), or in the firmware of interface circuit 1318. Alternatively or additionally, at least some operations in the communication technology can be implemented at the physical layer (e.g., the hardware in interface circuit 1318).
[0244] Note that in one or more embodiments, the phrases “capable,” “can,” “operable to,” or “configured to” refer to devices, logic, hardware, and / or elements being designed to enable the use of said devices, logic, hardware, and / or elements in a specified manner.
[0245] Although numerical examples have been provided in the preceding discussion, different numerical values have been used in other embodiments. Therefore, the numerical values provided are not intended to be limiting.
[0246] In the preceding description, we have referred to "some embodiments". Note that "some embodiments" describes a subset of all possible embodiments, but does not always specify the same subset of embodiments.
[0247] The foregoing description is intended to enable those skilled in the art to make and use this disclosure, and is provided in the context of a particular application and its requirements. Moreover, the foregoing description of embodiments of this disclosure has been presented solely for illustrative and descriptive purposes. It is not intended to be exhaustive or to limit this disclosure to the forms disclosed. Therefore, many modifications and variations will be apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and applications without departing from the spirit and scope of this disclosure. Furthermore, the discussion of the foregoing embodiments is not intended to limit this disclosure. Therefore, this disclosure is not intended to be limited to the embodiments shown, but is accorded the widest scope consistent with the principles and features disclosed herein.
Claims
1. An electronic device comprising: An interface circuit configured to communicate with a computer and a second computer; A processor, the processor being coupled to the interface circuitry; as well as A memory coupled to the processor, the memory being configured to store program instructions, wherein, when executed by the processor, the program instructions cause the electronic device to perform operations, the operations including: Receive an access request associated with the computer, wherein the access request includes a password parameter associated with a user corresponding to a password, and the password parameter includes input to the cryptographic calculation and output of the cryptographic calculation; One or more second outputs of the cryptographic computation are calculated at least in part based on the input and one or more stored passwords; When a match exists between one or more of the second outputs and the output, access is made to a policy associated with the user, wherein accessing the policy includes second computer communications associated with property management of a hotel or educational institution; and When one or more criteria associated with the policy are met, an access acceptance message is selectively provided with an address pointing to the computer, wherein the access acceptance message is directed to a second electronic device associated with the user and includes information for establishing secure access of the second electronic device to the network, and wherein the second electronic device is included in a group of electronic devices associated with the user and sharing the password, and communication between electronic devices in the group of electronic devices is isolated from communication with other electronic devices.
2. The electronic device according to claim 1, wherein, The electronic device includes an authentication, authorization, and billing (AAA) server.
3. The electronic device according to claim 1, wherein, The password includes the user's Dynamic Pre-Shared Key (DPSK).
4. The electronic device according to claim 1, wherein, The password parameters include: a random number associated with the second electronic device, a random number associated with the computer network device, the output of the encrypted calculation, the identifier of the second electronic device, and the identifier of the computer network device.
5. The electronic device according to claim 1, wherein, The strategy includes the time interval during which the password is valid.
6. The electronic device according to claim 1, wherein, The policy includes the location where the password is valid or the network that the user is allowed to access.
7. The electronic device according to claim 6, in, The operation includes communicating with the second computer to determine whether the second electronic device is associated with the location; and When the second electronic device is associated with the location, the access acceptance message is selectively provided.
8. The electronic device according to claim 1, wherein, The network includes a location-associated virtual network, and the information in the access acceptance message allows the second electronic device to establish secure communication with the virtual network.
9. The electronic device according to claim 8, wherein, The virtual network includes: Virtual Local Area Network (VLAN) or Virtual Scalable Local Area Network (VXLAN).
10. The electronic device according to claim 8, wherein, The access acceptance message includes the identifier of the virtual network; and The identifiers include Virtual Local Area Network Identifier (VLANID) or Virtual Network Identifier (VNI).
11. The electronic device according to claim 10, wherein, The identifier includes information that designates one of more than 4,096 virtual networks.
12. The electronic device according to claim 8, wherein, The secure communication is independent of traffic associated with other users on the network.
13. The electronic device according to claim 1, wherein, The access request includes a Remote Authentication Dial-In User Service (RADIUS) access request, and the access acceptance message includes a RADIUS access acceptance message.
14. The electronic device according to claim 1, wherein, The policy allows the user to access multiple networks at different locations.
15. The electronic device according to claim 14, wherein, The inputs used to calculate the one or more second outputs include a given identifier for the given network.
16. The electronic device according to claim 4, wherein, The passwords for the one or more stores are organized, at least in part, based on identifiers of different networks.
17. The electronic device according to claim 1, wherein, The password is independent of the identifier associated with the second electronic device.
18. The electronic device according to claim 1, wherein, The password is independent of the second electronic device or the hardware in the second electronic device.
19. A non-transitory computer-readable storage medium for use in conjunction with an electronic device, the computer-readable storage medium storing program instructions that, when executed by the electronic device, cause the electronic device to perform operations, the operations including: Receive an access request associated with a computer, wherein the access request includes a password parameter associated with a user and corresponding to a password, and the password parameter includes input to the cryptographic calculation and output of the cryptographic calculation; One or more second outputs of the cryptographic computation are calculated at least in part based on the input and one or more stored passwords; When a match exists between one or more of the second outputs and the output, access is made to a policy associated with the user, wherein accessing the policy includes second computer communications associated with property management of a hotel or educational institution; and When one or more criteria associated with the policy are met, an access acceptance message is selectively provided with an address pointing to the computer, wherein the access acceptance message is directed to a second electronic device associated with the user and includes information for establishing secure access of the second electronic device to the network, and wherein the second electronic device is included in a group of electronic devices associated with the user and sharing the password, and communication between electronic devices in the group of electronic devices is isolated from communication with other electronic devices.
20. A method for selectively approving secure access to a network, comprising: By electronic devices: Receive an access request associated with a computer, wherein the access request includes a password parameter associated with a user and corresponding to a password, and the password parameter includes input to the cryptographic calculation and output of the cryptographic calculation; One or more second outputs of the cryptographic computation are calculated at least in part based on the input and one or more stored passwords; When a match exists between one or more of the second outputs and the output, access is made to a policy associated with the user, wherein accessing the policy includes second computer communications associated with property management of a hotel or educational institution; and When one or more criteria associated with the policy are met, an access acceptance message is selectively provided with an address pointing to the computer, wherein the access acceptance message is directed to a second electronic device associated with the user and includes information for establishing secure access of the second electronic device to the network, and wherein the second electronic device is included in a group of electronic devices associated with the user and sharing the password, and communication between electronic devices in the group of electronic devices is isolated from communication with other electronic devices.
Citation Information
Patent Citations
Enabling secured wireless access at hotspot by providing user-specific access credential for secure SSID during sign-up process conducted over open wireless network
US10299126B2
Username based authentication and key generation
US20100131756A1
Key assignment for a brand
US20150257009A1
Authorizing secured wireless access at hotspot having open wireless network and secure wireless network
US9161219B2