Abstract:
Systems, methods, and devices for broadcast wireless local area network messages with message authentication are contained herein. The method includes determining a digital signature for a broadcast packet to be transmitted to a plurality of devices on a wireless local area network, the digital signature encrypted using asymmetric cryptography to enable each of the plurality of devices to verify an identity of a device transmitting the broadcast packet. The method further includes transmitting the broadcast packet on the network, the broadcast packet including the digital signature.
Abstract:
A particular method includes generating, at a mobile station, a probe request frame and a service discovery request. At least a first portion of the service discovery request may be encapsulated within the probe request frame to form a modified probe request frame. The modified probe request frame may be wirelessly transmitted, for example, to a particular access point or to all access points with range of the mobile station.
Abstract:
Systems, methods, and computer readable mediums for authenticating a device perform a method of receiving, at a second device, a first authentication protocol reauthentication response for the device, the authentication response including a reauthentication master session key (rMSK), transmitting, at the second device, a second first authentication protocol reauthentication response to a first access point based on the reauthentication master session key, generating, at the second device, a first pairwise master key (PMK) based on the reauthentication master session key, generating, at the second device, a key message to include the first pairwise master key, and transmitting, at the second device, the key message to the second access point.
Abstract:
In a particular embodiment, a method includes scanning, by a mobile device, for a first wireless communication channel that is reserved for device authentication and association. The mobile device sends an authentication request to an access point via the first wireless communication channel. The method further includes receiving a reply to the authentication request from the access point.
Abstract:
A method includes, prior to authenticating a mobile device, receiving by an access point a first message from the mobile device, determining that the mobile device is to be authenticated prior to responding to the first message, and sending to an authentication server a second message that includes an authentication request and the first message. The method also includes receiving from the authentication server a third message that includes a response to the authentication request and that further includes the first message.
Abstract:
One feature pertains to a method for secure wireless communication at an apparatus of a network. The method includes receiving a user equipment identifier identifying a user equipment and a cryptographic key from a wireless wide area network node, and using the cryptographic key as a pairwise master key (PMK). A PMK identifier (PKMID) is generated based on the PMK and the two are stored at the network. A PMK security association is initialized by associating the PMK with at least the PMKID and an access point identifier identifying an access point of the apparatus. An association request is received that includes a PMKID from the user equipment, and it's determined that the PMKID received from the user equipment matches the PMKID stored. A key exchange is initiated with the user equipment based on the PMK to establish a wireless local area network security association with the user equipment.
Abstract:
A wireless communication device includes a memory and a processor coupled to the memory. The processor is configured to set a packet number to a particular value in accordance with a packet number initialization scheme associated with a data link group of a neighbor aware network (NAN). The processor is further configured to generate a packet based on the packet number.
Abstract:
Certain aspects of the present disclosure generally relate to wireless communications and, more particularly, to protecting control frames with power-related subfields. One example apparatus for wireless communications generally includes a processing system configured to generate a control frame comprising one or more power-related subfields and an integrity check value calculated based, at least in part, on the one or more power-related subfields and a transmitter configured to transmit the control frame. In aspects, a power management (PM) subfield, an end-of-service-period (EOSP) subfield, a more data (MD) subfield, or a traffic identifier (TID) subfield can be added to a group of additional authentication data (AAD) and the integrity check value is calculated based on the group of AAD.
Abstract:
Systems, methods, and devices for multicast wireless local area network messages with message authentication are contained herein. The method includes determining a message integrity check value for each of a plurality of wireless devices. The method further includes transmitting a multicast packet to each of the plurality of devices on a wireless local area network, the multicast packet including an indication of each of the plurality of devices and the message integrity check value for each of the plurality of devices.
Abstract:
During uplink traffic, a map is formed between the MAC address and an upper layer identifier of each station of a communications network. When a downlink unicast packet is received, the identifier is compared to the map to select a corresponding MAC address. The packet having the selected MAC address is delivered to the station. During uplink, the MAC address of the station generating the packet is replaced with the MAC address of the relay receiving the packet. A device receiving an uplink multicast packet is assigned a temporary MAC address which remains valid during a known period. The device replaces the MAC address of the station generating the multicast packet with the temporary MAC address to generate a new packet that is transferred up the link. A downlink packet that includes the temporary MAC address and is received during the first time period is delivered as a response packet.