Method and system of secured direct link set-up (DLS) for wireless networks
First Claim
Patent Images
1. A method, comprising:
- setting up a robust security network association (RSNA) by an access point (AP) in a network with a first station (STA) and a second STAreceiving a direct link setup (DLS) request from the first STA, wherein the DLS request comprises a media access control (MAC) address of the second STA, a MAC address of the first STA, and capability information of the first STA;
receiving a DLS response from the second STA, wherein the DLS response comprises MAC address of the second STA, the MAC address of the first STA, and capability information of the second STA;
receiving a message from the first STA to deploy security measures between the first STA and the second STA;
generating a symmetric session key;
generating a key name identifier for the symmetric session key based on a hash of a first random number from the first STA, a second random number from the second STA, the MAC address of the first STA, and the MAC address of the second STA;
performing a 4-way handshake between the first STA and the second STA using the symmetric session key as a pairwise master key (PMK); and
transmitting a first security string to the first STA and a second security string to the second STA from the AP, the first and second security strings comprising the symmetric session key and the key name identifier, wherein a pairwise DLS transient key (PDTK) is derived from the PMK during the 4-way handshake by the first STA to provide a secure station-to-station link between the first STA and the second STA.
0 Assignments
0 Petitions
Accused Products
Abstract
Method and system of secured direct link set-up (DLS) for wireless networks. In accordance with aspects of the method, techniques are disclosed for setting up computationally secure direct links between stations in a wireless network in a manner that is computationally secure.
33 Citations
20 Claims
-
1. A method, comprising:
-
setting up a robust security network association (RSNA) by an access point (AP) in a network with a first station (STA) and a second STA receiving a direct link setup (DLS) request from the first STA, wherein the DLS request comprises a media access control (MAC) address of the second STA, a MAC address of the first STA, and capability information of the first STA; receiving a DLS response from the second STA, wherein the DLS response comprises MAC address of the second STA, the MAC address of the first STA, and capability information of the second STA; receiving a message from the first STA to deploy security measures between the first STA and the second STA; generating a symmetric session key; generating a key name identifier for the symmetric session key based on a hash of a first random number from the first STA, a second random number from the second STA, the MAC address of the first STA, and the MAC address of the second STA; performing a 4-way handshake between the first STA and the second STA using the symmetric session key as a pairwise master key (PMK); and transmitting a first security string to the first STA and a second security string to the second STA from the AP, the first and second security strings comprising the symmetric session key and the key name identifier, wherein a pairwise DLS transient key (PDTK) is derived from the PMK during the 4-way handshake by the first STA to provide a secure station-to-station link between the first STA and the second STA. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A method, comprising:
-
receiving, by a first station (STA), a request from an access point (AP) to setup up a robust security network association (RSNA) with a second STA in a network; sending a station-to-station direct link setup (DLS) request to the AP, wherein the DLS request comprises a media access control (MAC) address of the second STA, a MAC address of the first STA, and capability information of the first STA; receiving a DLS response from the AP, wherein the DLS response comprises the MAC address of the second STA, the MAC address of the first STA, and capability information of the second STA; receiving a security string, by the first STA from the AP, after initiating a request to deploy security measures between the first STA and the second STA for a station-to-station link, the security string comprising a symmetric session key and a key name identifier for the symmetric session key, the key name identifier comprising a hash of a first random number from the first STA, a second random number from the second STA, the MAC address of the first STA, and the MAC address of the second STA; and initiating a 4-Way Handshake between the first STA and the second STA using the symmetric session key as a pairwise master key (PMK), wherein a pairwise DLS transient key (PDTK) is derived from the PMK by the first STA to implement a secure station-to-station link. - View Dependent Claims (8, 9, 10, 11, 12)
-
-
13. An access point (AP), comprising:
-
a radio frequency (RF) interface to transmit and receive RF signals corresponding to a wireless communications protocol; a processor coupled to the RF interface; and logic executed by the processor to perform operations including; setting up a robust security network association (RSNA) in a network with a first station (STA) and a second STA receiving a direct link setup (DLS) request from the first STA to provide a station-to-station link between the first STA and the second STA; receiving a DLS response from the second STA in response to the DLS request made by the first STA; receiving a message from the first STA to deploy security measures between the first STA and the second STA generating a symmetric session key; generating a key name identifier for the symmetric session key based on a hash of a first random number from the first STA, a second random number from the second STA, a MAC address of the first STA, and a MAC address of the second STA; performing a 4-way handshake between the first STA and the second STA using the symmetric session key as a pairwise master key (PMK); and transmitting a first security string to the first STA and a second security string to the second STA from the AP, the first and second security strings comprising the symmetric session key and the key name identifier, wherein a pairwise DLS transient key (PDTK) is derived from the PMK to provide a secure station-to-station link between the first STA and the second STA. - View Dependent Claims (14, 15, 16, 17)
-
-
18. A first station (STA) configured to:
-
receive a request from an access point (AP) to setup up a robust security network association (RSNA) with a second STA in a network, send a direct link setup (DLS) request to the AP, wherein the DLS request comprises a media access control (MAC) address of the second STA, a MAC address of the first STA, and capability information of the first STA, receive a DLS response from the AP, wherein the DLS response comprises the MAC address of the second STA, the MAC address of the first STA, and capability information of the second STA, receive a security string from the AP by the first STA after initiating a request to deploy security measures between the first STA and the second STA, the security string comprising a symmetric session key and a key name identifier for the symmetric session key, the key name identifier comprising a hash of a first random number from the first STA, a second random number from the second STA, the MAC address of the first STA, and the MAC address of the second STA, and initiate a 4-Way Handshake between the first STA and the second STA using the symmetric session key as a pairwise master key (PMK), wherein a pairwise DLS transient key (PDTK) is derived from the PMK by the first STA for the 4-Way Handshake. - View Dependent Claims (19, 20)
-
Specification