Patents by Inventor Jouni Malinen
Jouni Malinen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 10856143Abstract: A method includes, prior to authenticating a mobile device, receiving by an access point a first message from the mobile device, determining that the mobile device is to be authenticated prior to responding to the first message, and sending to an authentication server a second message that includes an authentication request and the first message. The method also includes receiving from the authentication server a third message that includes a response to the authentication request and that further includes the first message.Type: GrantFiled: June 3, 2015Date of Patent: December 1, 2020Assignee: QUALCOMM IncorporatedInventors: George Cherian, Santosh Paul Abraham, Jouni Malinen, Hemanth Sampath
-
Patent number: 10623951Abstract: One feature pertains to a method for secure wireless communication at an apparatus of a network. The method includes receiving a user equipment identifier identifying a user equipment and a cryptographic key from a wireless wide area network node, and using the cryptographic key as a pairwise master key (PMK). A PMK identifier (PKMID) is generated based on the PMK and the two are stored at the network. A PMK security association is initialized by associating the PMK with at least the PMKID and an access point identifier identifying an access point of the apparatus. An association request is received that includes a PMKID from the user equipment, and it's determined that the PMKID received from the user equipment matches the PMKID stored. A key exchange is initiated with the user equipment based on the PMK to establish a wireless local area network security association with the user equipment.Type: GrantFiled: September 30, 2016Date of Patent: April 14, 2020Assignee: Qualcomm IncorporatedInventors: Anand Palanigounder, Jouni Malinen
-
Publication number: 20200015164Abstract: Methods, systems, and devices for wireless communications are described. A station (STA) may receive a wakeup radio (WUR) frame for the STA at a WUR. The STA may identify, from a number of packet number generation schemes, a scheme that the STA is to use to construct a packet number for the WUR frame. Following the scheme identification, the STA may generate a packet number for the received WUR frame using the identified scheme and determine whether to discard the WUR frame based on the generated packet number. In some implementations, the STA may determine whether the STA is to use, for communications received from an access point (AP) to the WUR, a same key or a second key, the second key being different from a first key used by the STA to receive protected communications from the AP to a primary radio of the STA.Type: ApplicationFiled: June 27, 2019Publication date: January 9, 2020Inventors: Alfred Asterjadhi, George Cherian, Soo Bum Lee, Jouni Malinen, Maarten Menzo Wentink
-
Publication number: 20190380094Abstract: Methods, systems, and devices for wireless communications are described. A wireless device may receive, via a management frame, a set of wakeup tokens for activating a main radio of the wireless device. The wakeup tokens may be unique to the wireless device and may be transmitted over a secure connection. An access point (AP) wishing to activate a main radio (e.g., for high throughput communications) may transmit a wakeup radio (WUR) frame, including a wakeup token from the set of wakeup tokens, to a secondary radio of the wireless device. The wireless device may, upon reception of the WUR frame, activate the main radio and transmit a wakeup acknowledgement (ACK) to the AP. The AP may then communicate with the wireless device via the main radio.Type: ApplicationFiled: June 5, 2019Publication date: December 12, 2019Inventors: Maarten Menzo Wentink, Albert Van Zelst, Jouni Malinen, George Cherian, Alfred Asterjadhi
-
Publication number: 20190132128Abstract: Certain aspects relate to an apparatus includes an interface configured to obtain a first frame including a first information element (IE) indicating a list of encoding algorithms and a processing system configured to generate a second frame including a second IE indicating at least one of an encoding algorithm from the list or the list. The interface is further configured to output the second frame for transmission to a device and obtain a first random number from the device and the processing system is further configured to generate a code based on the first random number, a second random number and a master key and generate a third frame comprising the second IE, the second random number and an integrity protected IE generated based on the second IE and the code. Furthermore, the interface is configured to output the third frame for transmission to the device.Type: ApplicationFiled: November 1, 2018Publication date: May 2, 2019Inventors: Rosario CAMMAROTA, Jouni MALINEN
-
Patent number: 10129930Abstract: This disclosure provides systems, methods and apparatuses for enabling Multiple BSSID functionality. In some implementations, each BSS of the multi-BSS AP may transmit management frames with a Multiple BSSID element (MBE). Multiple BSSID-capable STAs may interpret the MBE information and implement corresponding Multiple BSSID functionality, whereas legacy STAs may ignore the MBE and interpret such frames as legacy management frames. In some other implementations, a multi-BSS AP may configure one or more of its BSSs to transmit management frames without the MBE. These legacy management frames may include a multi-BSS indicator (MBID) to advertise that the corresponding AP is a multi-BSS AP. The MBID also may provide information regarding a transmitted BSS of the multi-BSS AP. Multiple BSSID-capable STAs may search for a transmitted BSS based on the presence of the MBID, whereas legacy STAs may ignore the MBID and interpret such frames as legacy management frames.Type: GrantFiled: September 5, 2017Date of Patent: November 13, 2018Assignee: QUALCOMM IncorporatedInventors: Abhishek Pramod Patil, George Cherian, Jouni Malinen, Alfred Asterjadhi
-
Publication number: 20180270049Abstract: Aspects of the present disclosure implement techniques that allow an enrollee (e.g., DPP-AP or other DPP devices) to be informed of the bootstrapping method selected by a device (e.g., STA) when initiating onboarding. As such, in one example, authentication requests from the device may additionally carry information that inform the network of the bootstrapping method (e.g., QR-code, NFC, Wi-Fi Aware, Wi-Fi Direct) selected by the device. Each bootstrapping method may correspond to an authentication key. Accordingly, based on the exchange of bootstrapping information, the enrollee (e.g., network device) may verify the authenticity of the device by calculating an authentication key that unlocks additional sensitive information that may be included in the authentication request.Type: ApplicationFiled: March 14, 2018Publication date: September 20, 2018Inventors: Rosario CAMMAROTA, Jouni MALINEN, Shivraj Singh SANDHU
-
Patent number: 10057766Abstract: Systems, methods, and computer readable mediums for authenticating a device perform a method of receiving, at a second device, a first authentication protocol reauthentication response for the device, the authentication response including a reauthentication master session key (rMSK), transmitting, at the second device, a second first authentication protocol reauthentication response to a first access point based on the reauthentication master session key, generating, at the second device, a first pairwise master key (PMK) based on the reauthentication master session key, generating, at the second device, a key message to include the first pairwise master key, and transmitting, at the second device, the key message to the second access point.Type: GrantFiled: October 20, 2015Date of Patent: August 21, 2018Inventors: Soo Bum Lee, George Cherian, Abhishek Pramod Patil, Santosh Paul Abraham, Jouni Malinen
-
Patent number: 9961170Abstract: Apparatuses and methods are disclosed that may allow a wireless device to process an Ethertype data packet encapsulated in a frame based on whether the frame contains an Ethertype Packet Discrimination (EPD) indicator. The wireless device may receive the frame from another wireless device over a wireless network, and may detect a presence of the EPD indicator in the received frame. Then, the wireless device may identify a protocol type of the Ethertype data packet according to an EPD operation based on the presence of the EPD indicator, or may identify the protocol type of the Ethertype data packet according to an LPD operation based on an absence of the EPD indicator.Type: GrantFiled: November 24, 2015Date of Patent: May 1, 2018Assignee: QUALCOMM IncorporatedInventors: Maarten Menzo Wentink, Alfred Asterjadhi, Simone Merlin, Jouni Malinen
-
Publication number: 20180098378Abstract: This disclosure provides systems, methods and apparatuses for enabling Multiple BSSID functionality. In some implementations, each BSS of the multi-BSS AP may transmit management frames with a Multiple BSSID element (MBE). Multiple BSSID-capable STAs may interpret the MBE information and implement corresponding Multiple BSSID functionality, whereas legacy STAs may ignore the MBE and interpret such frames as legacy management frames. In some other implementations, a multi-BSS AP may configure one or more of its BSSs to transmit management frames without the MBE. These legacy management frames may include a multi-BSS indicator (MBID) to advertise that the corresponding AP is a multi-BSS AP. The MBID also may provide information regarding a transmitted BSS of the multi-BSS AP. Multiple BSSID-capable STAs may search for a transmitted BSS based on the presence of the MBID, whereas legacy STAs may ignore the MBID and interpret such frames as legacy management frames.Type: ApplicationFiled: September 5, 2017Publication date: April 5, 2018Inventors: Abhishek Pramod Patil, George Cherian, Jouni Malinen, Alfred Asterjadhi
-
Publication number: 20180084416Abstract: Systems, methods, and computer readable mediums for authenticating a device perform a method of receiving, at a second device, a first authentication protocol reauthentication response for the device, the authentication response including a reauthentication master session key (rMSK), transmitting, at the second device, a second first authentication protocol reauthentication response to a first access point based on the reauthentication master session key, generating, at the second device, a first pairwise master key (PMK) based on the reauthentication master session key, generating, at the second device, a key message to include the first pairwise master key, and transmitting, at the second device, the key message to the second access point.Type: ApplicationFiled: November 15, 2017Publication date: March 22, 2018Inventors: Soo Bum Lee, George Cherian, Abhishek Pramod Patil, Santosh Paul Abraham, Jouni Malinen
-
Publication number: 20180049027Abstract: A method for wireless communication may include receiving a communication and determining an acknowledgement signature for an acknowledgment in response to the communication. The acknowledgment signature may allow for authentication with the transmitting wireless device. The acknowledgment signature may be based on a key shared with the wireless device. An acknowledgement frame (e.g., acknowledging reception of the communication) may then be sent to the transmitting wireless device. The content of the acknowledgement may be based on the acknowledgement signature. For example, the signature may be included in a frame control, duration, or address field. Determining the acknowledgement signature may include determining a unique signature based on information from the received communication (e.g., a cyclic redundancy check (CRC)), the shared key, and/or a hash function.Type: ApplicationFiled: August 9, 2017Publication date: February 15, 2018Inventors: Santosh Paul Abraham, George Cherian, Alireza Raissinia, Abhishek Pramod Patil, Naveen Kumar Kakani, James Simon Cho, Jouni Malinen
-
Patent number: 9894599Abstract: In a particular embodiment, a method includes scanning, by a mobile device, for a first wireless communication channel that is reserved for device authentication and association. The mobile device sends an authentication request to an access point via the first wireless communication channel. The method further includes receiving a reply to the authentication request from the access point.Type: GrantFiled: March 15, 2013Date of Patent: February 13, 2018Assignee: QUALCOMM, IncorporatedInventors: George Cherian, Santosh Paul Abraham, Jouni Malinen, Hemanth Sampath
-
Publication number: 20170367033Abstract: A method includes, prior to authenticating a mobile device, receiving by an access point a first message from the mobile device, determining that the mobile device is to be authenticated prior to responding to the first message, and sending to an authentication server a second message that includes an authentication request and the first message. The method also includes receiving from the authentication server a third message that includes a response to the authentication request and that further includes the first message.Type: ApplicationFiled: June 3, 2015Publication date: December 21, 2017Inventors: George Cherian, Santosh Paul Abraham, Jouni Malinen, Hemanth Sampath
-
Publication number: 20170265069Abstract: One feature pertains to a method for secure wireless communication at an apparatus of a network. The method includes receiving a user equipment identifier identifying a user equipment and a cryptographic key from a wireless wide area network node, and using the cryptographic key as a pairwise master key (PMK). A PMK identifier (PKMID) is generated based on the PMK and the two are stored at the network. A PMK security association is initialized by associating the PMK with at least the PMKID and an access point identifier identifying an access point of the apparatus. An association request is received that includes a PMKID from the user equipment, and it's determined that the PMKID received from the user equipment matches the PMKID stored. A key exchange is initiated with the user equipment based on the PMK to establish a wireless local area network security association with the user equipment.Type: ApplicationFiled: September 30, 2016Publication date: September 14, 2017Inventors: Anand Palanigounder, Jouni Malinen
-
Publication number: 20170171169Abstract: A wireless communication device includes a memory and a processor coupled to the memory. The processor is configured to set a packet number to a particular value in accordance with a packet number initialization scheme associated with a data link group of a neighbor aware network (NAN). The processor is further configured to generate a packet based on the packet number.Type: ApplicationFiled: December 13, 2016Publication date: June 15, 2017Inventors: Soo Bum Lee, Santosh Abraham, Abhishek Pramod Patil, Jouni Malinen, George Cherian
-
Patent number: 9614935Abstract: Certain aspects of the present disclosure generally relate to wireless communications and, more particularly, to protecting control frames with power-related subfields. One example apparatus for wireless communications generally includes a processing system configured to generate a control frame comprising one or more power-related subfields and an integrity check value calculated based, at least in part, on the one or more power-related subfields and a transmitter configured to transmit the control frame. In aspects, a power management (PM) subfield, an end-of-service-period (EOSP) subfield, a more data (MD) subfield, or a traffic identifier (TID) subfield can be added to a group of additional authentication data (AAD) and the integrity check value is calculated based on the group of AAD.Type: GrantFiled: March 12, 2014Date of Patent: April 4, 2017Assignee: QUALCOMM INCORPORATEDInventors: Maarten Menzo Wentink, Alfred Asterjadhi, Jouni Malinen
-
Publication number: 20160360472Abstract: A method includes, prior to authenticating a mobile device, receiving by an access point a first message from the mobile device, determining that the mobile device is to be authenticated prior to responding to the first message, and sending to an authentication server a second message that includes an authentication request and the first message. The method also includes receiving from the authentication server a third message that includes a response to the authentication request and that further includes the first message.Type: ApplicationFiled: June 3, 2015Publication date: December 8, 2016Inventors: George Cherian, Santosh Paul Abraham, Jouni Malinen, Hemanth Sampath
-
Patent number: 9462005Abstract: Systems, methods, and devices for multicast wireless local area network messages with message authentication are contained herein. The method includes determining a message integrity check value for each of a plurality of wireless devices. The method further includes transmitting a multicast packet to each of the plurality of devices on a wireless local area network, the multicast packet including an indication of each of the plurality of devices and the message integrity check value for each of the plurality of devices.Type: GrantFiled: May 22, 2014Date of Patent: October 4, 2016Assignee: QUALCOMM IncorporatedInventors: Santosh Paul Abraham, George Cherian, Jouni Malinen
-
Publication number: 20160150058Abstract: Apparatuses and methods are disclosed that may allow a wireless device to process an Ethertype data packet encapsulated in a frame based on whether the frame contains an Ethertype Packet Discrimination (EPD) indicator. The wireless device may receive the frame from another wireless device over a wireless network, and may detect a presence of the EPD indicator in the received frame. Then, the wireless device may identify a protocol type of the Ethertype data packet according to an EPD operation based on the presence of the EPD indicator, or may identify the protocol type of the Ethertype data packet according to an LPD operation based on an absence of the EPD indicator.Type: ApplicationFiled: November 24, 2015Publication date: May 26, 2016Inventors: Maarten Menzo Wentink, Alfred Asterjadhi, Simone Merlin, Jouni Malinen