Wireless network authentication using isolated security key
Abstract
A method includes generating, at a first station, a security key that is usable for authentication with an access point associated with a wireless network. The method includes switching from an infrastructure mode to an ad hoc communication mode, and while in the ad hoc communication mode, broadcasting a beacon frame and receiving a request, from a second station, to join the wireless network. The method includes determining that the second station is an approved device and sending a first authentication request to the access point on behalf of the second station. The method includes receiving a first authentication response, including challenge text, from the access point. The method includes encrypting the challenge text based on the security key and sending the encrypted challenge text as part of a second authentication request to the access point to authenticate the second station with the access point.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of station authentication, the method comprising:
generating, at a first station, a security key that is usable for authentication with an access point associated with a wireless network; receiving, at the first station and from a second station, a request to join the wireless network, the request including device information associated with the second station; determining, at the first station and based on the device information associated with the second station, whether the second station is an approved device; and performing, at the first station and on behalf of the second station, a handshake with the access point to authenticate the second station with the access point in response to a determination that the second station is an approved device, the handshake based on the security key and the device information associated with the second station.
2 . The method of claim 1 , wherein performing the handshake comprises:
sending a first authentication request to the access point on behalf of the second station, the first authentication request including the device information associated with the second station; receiving a first authentication response from the access point in response to sending the first authentication request, the first authentication response including challenge text; encrypting the challenge text based on the security key to generate encrypted challenge text, the security key isolated from the second station; and sending the encrypted challenge text as part of a second authentication request to the access point to authenticate the second station with the access point.
3 . The method of claim 1 , wherein, prior to receiving the request to join the wireless network, the method comprises sending a frame to the second station, the frame including network information associated with the wireless network.
4 . The method of claim 3 , wherein the frame corresponds to a beacon frame, and wherein sending the frame comprises broadcasting the beacon frame.
5 . The method of claim 3 , wherein the request is received in response to sending the frame to the second station.
6 . The method of claim 2 , wherein, prior to sending the first authentication request to the access point, the method comprises:
determining an address of the second station based on the device information associated with the second station; populating a source address field in the first authentication request with the address of the second station to send the first authentication request on behalf of the second station; and populating a transmitter address field in the first authentication request with an address of the first station to promote the access point to relay the first authentication response to the second station by way of the first station.
7 . The method of claim 6 , wherein a destination address of the first authentication response is the address of the first station in response to populating the transmitter address field in the first authentication request with the address of the first station, and further comprising:
bypassing the relay of the first authentication response to the second station after receiving the first authentication response to isolate the second station from the challenge text.
8 . The method of claim 2 , wherein, prior to sending the second authentication request to the access point, the method comprises:
populating a source address field in the second authentication request and a transmitter address field in the second authentication request with an address of the second station to promote the access point to send an authentication message to the second station.
9 . The method of claim 2 , wherein, prior to sending the second authentication request to the access point, the method comprises:
populating a transmitter address field in the second authentication request with an address of the first station to promote the access point to send an authentication message to the first station; receiving the authentication message from the access point; and relaying the authentication message to the second station.
10 . The method of claim 1 , further comprising:
receiving, at the first station and from a third station, a second request to join the wireless network, the second request including device information associated with the third station; determining, based on the device information associated with the third station, whether the third station is an approved device; and sending an exclusion frame to the access point in response to a determination that the third station is not an approved device, the exclusion frame including the device information associated with the third station, wherein the access point rejects authentication requests from the third station in response to receiving the exclusion frame.
11 . The method of claim 1 , further comprising, prior to receiving the request to join the wireless network, switching from an infrastructure mode to an ad hoc communication mode for a particular time period, wherein the request to join the wireless network is received while in the ad hoc communication mode.
12 . The method of claim 11 , wherein switching from the infrastructure mode to the ad hoc communication mode comprises:
monitoring an amount of data transfer associated with the wireless network while operating in the infrastructure mode; and switching from the infrastructure mode to the ad hoc communication mode in response to a determination that the amount of data transfer fails to satisfy a data transfer threshold.
13 . The method of claim 11 , wherein switching from the infrastructure mode to the ad hoc communication mode is periodically initiated by the first station.
14 . The method of claim 11 , wherein a frequency at which the first station initiates a periodic switch from the infrastructure mode to the ad hoc communication mode is dependent on a historical number of stations that have been authenticated with the access point.
15 . The method of claim 11 , wherein switching from the infrastructure mode to the ad hoc communication mode is initiated by a user request.
16 . The method of claim 1 , wherein determining whether the second station is an approved device comprises:
accessing a list of stations that have previously been granted permission to join the wireless network; and comparing the device information associated with the second station to device information associated with stations in the list of stations, wherein the second station is an approved device if the device information associated with the second station matches device information of a station in the list of stations, and wherein the second station is not an approved device if the device information associated with the second station fails to match device information of a station in the list of stations.
17 . The method of claim 1 , wherein the wireless network comprises an Institute of Electrical and Electronics Engineers (IEEE) 802.11 wireless network or a wireless local area network (WLAN).
18 . The method of claim 1 , wherein the device information associated with the second station includes an address of the second station.
19 . A station comprising:
a memory; a processor coupled to the memory, the processor configured to generate a security key that is usable for authentication with an access point associated with a wireless network; and a receiver coupled to the processor, the receiver configured to receive, from a second station, a request to join the wireless network, the request including device information associated with the second station; wherein the processor is further configured to:
determine, based on the device information associated with the second station, whether the second station is an approved device; and
initiate performance of a handshake with the access point on behalf of the second station to authenticate the second station with the access point in response to a determination that the second station is an approved device, the handshake based on the security key and the device information associated with the second station.
20 . A non-transitory computer-readable medium comprising instructions for station authentication, the instructions, when executed by a processor in a station, cause the processor to perform operations comprising:
generating a security key that is usable for authentication with an access point associated with a wireless network; processing a received request, from a second station, to join the wireless network, the request including device information associated with the second station; determining, based on the device information associated with the second station, whether the second station is an approved device; and performing, on behalf of the second station, a handshake with the access point to authenticate the second station with the access point in response to a determination that the second station is an approved device, the handshake based on the security key and the device information associated with the second station.Join the waitlist — get patent alerts
Track US2023037386A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.