Mobile Application DevelopmentUnit 610 min read
Wireless Networks, Protocols & Mobile App Integration
Unit 6 of Mobile Application Development explores wireless communication technologies (Wi-Fi, Bluetooth, cellular networks), their protocols (TCP/IP, HTTP/HTTPS, MQTT), security mechanisms (WPA3, TLS), and how mobile apps interact with these systems. Covers real-world implementations like eSewa’s secure transactions, P
TAKEAWAYS:
- Wireless connectivity relies on radio waves (Wi-Fi), microwaves (cellular), or infrared/Bluetooth (short-range), each with distinct speed, range, and power constraints.
- TCP/IP and HTTP/HTTPS are the backbone of mobile app communication, while MQTT enables lightweight IoT/mobile messaging.
- Security protocols (WPA3, TLS) protect data in transit, but mobile apps must handle offline scenarios and reconnection logic.
- Latency and bandwidth directly impact app performance (e.g., video streaming vs. chat apps).
- Nepali examples: eSewa uses HTTPS + OAuth for secure payments; Pathao relies on GPS + cellular data for ride tracking; Ncell’s 4G/LTE network manages voice/data traffic via SIP for VoIP.
- Exam focus: Compare protocols (Wi-Fi vs. Bluetooth vs. cellular), trace packet flows, and explain how apps handle disconnections/reconnections.
Wireless Communication Technologies
Wireless connectivity enables mobile apps to interact with networks without physical cables. The three primary technologies are:
1. Wi-Fi (IEEE 802.11 Standards)
- Uses radio waves (2.4 GHz or 5 GHz) for short-to-medium range (up to 100 meters indoors).
- Standards:
- 802.11n (Wi-Fi 4): Up to 600 Mbps, MIMO technology.
- 802.11ac (Wi-Fi 5): Up to 3.5 Gbps, wider channels.
- 802.11ax (Wi-Fi 6): Improved efficiency in crowded networks (e.g., airports).
- Security: WPA3 (replaces WPA2) uses SAE (Simultaneous Authentication of Equals) to prevent brute-force attacks.
- Use in Nepal:
- eSewa app uses Wi-Fi for secure transactions when users are at home/businesses.
- NTC’s public Wi-Fi hotspots (e.g., in Kathmandu) rely on 802.11ac for high-speed internet.
Figure 1: Wi-Fi communication flow (eSewa transaction example).
2. Bluetooth (IEEE 802.15.1)
- Uses short-range radio waves (2.4 GHz), ideal for device pairing (e.g., headphones, printers).
- Versions:
- Bluetooth Classic: Low speed (up to 24 Mbps), used in audio devices.
- Bluetooth Low Energy (BLE): Optimized for low power (e.g., fitness trackers, beacons).
- Use in Nepal:
- Khalti’s POS machines use BLE for contactless payments.
- Health apps (e.g., pulse oximeters) connect via BLE to smartphones.
Figure 2: BLE connection steps (Khalti POS example).
3. Cellular Networks (3G/4G/5G)
- Uses microwaves for long-range communication via base stations (cell towers).
- Generations:
- 3G: Up to 42 Mbps (e.g., Ncell’s early 3G).
- 4G/LTE: Up to 1 Gbps (Nepal’s current standard).
- 5G: Ultra-low latency (<1 ms), higher bandwidth (Ncell testing in Kathmandu).
- Protocols:
- SIP (Session Initiation Protocol): Used for VoIP (e.g., Ncell’s internet calling).
- MQTT: Lightweight protocol for IoT/mobile messaging (e.g., Daraz’s inventory updates).
Figure 3: 4G VoIP call flow (Ncell internet calling).
Wireless Protocols for Mobile Apps
Mobile apps use protocols to communicate over wireless networks. Key protocols include:
1. TCP/IP Suite
- TCP (Transmission Control Protocol): Reliable, connection-oriented (e.g., web browsing, emails).
- UDP (User Datagram Protocol): Faster, connectionless (e.g., video streaming, online games).
- IP (Internet Protocol): Addresses packets for routing (IPv4 vs. IPv6).
Comparison Table:
| Feature | TCP | UDP |
|---|---|---|
| Reliability | Guaranteed delivery | No guarantee |
| Speed | Slower (handshakes) | Faster |
| Use Case | Web (HTTP), emails | Video calls, gaming |
| Header Size | 20 bytes | 8 bytes |
Example: eSewa uses TCP for secure transactions (reliable data transfer) but may use UDP for real-time chat notifications.
2. HTTP/HTTPS
- HTTP (Hypertext Transfer Protocol): Stateless protocol for web requests (e.g., loading Daraz product pages).
- HTTPS: Secure HTTP with TLS/SSL encryption (used by all banking apps like NMB Bank).
- Methods:
GET: Retrieve data (e.g., fetching stock prices from NEPSE).POST: Send data (e.g., submitting a Pathao ride request).PUT/DELETE: Update/delete resources.
sequenceDiagram participant User participant App participant Server User->>App: Clicks "Book Ride" (Pathao) App->>Server: POST /rides (HTTPS) Server-->>App: 201 Created (Ride ID) App-->>User: Displays "Ride Confirmed"
Figure 4: HTTPS request flow (Pathao ride booking).
3. MQTT (Message Queuing Telemetry Transport)
- Lightweight protocol for IoT/mobile messaging (e.g., Daraz’s warehouse inventory updates).
- Uses publish-subscribe model:
- Broker: Middleman (e.g., Mosquitto).
- Topics: Channels (e.g.,
daraz/inventory/books).
- QoS Levels:
- 0: Fire-and-forget (e.g., sensor data).
- 1: At least once delivery (e.g., order confirmations).
- 2: Exactly once (critical updates).
Example: A Daraz app subscribes to daraz/inventory/books to update stock levels in real time.
Security in Wireless Communication
Wireless networks are vulnerable to attacks (e.g., man-in-the-middle, eavesdropping). Security measures include:
1. Wi-Fi Security: WPA3
- Replaces WPA2 with stronger encryption (SAE instead of PSK).
- Features:
- Forward Secrecy: Past sessions can’t be decrypted if a key is stolen.
- Protected Management Frames: Prevents deauthentication attacks.
- Use in Nepal: NTC’s public Wi-Fi now uses WPA3 in major cities.
2. TLS/SSL for HTTPS
- Encrypts data between app and server (e.g., Khalti payments).
- Handshake Process:
- Client sends supported cipher suites.
- Server responds with its digital certificate.
- Client verifies certificate (via CA like Let’s Encrypt).
- Symmetric key exchange (e.g., AES).
flowchart TD A["Client"] -->|"Hello"| B["Server"] B -->|"Certificate"| A A -->|"Key Exchange"| B B -->|"Encrypted Data"| A
Figure 5: TLS handshake (Khalti payment example).
3. Mobile App Security Best Practices
- Certificate Pinning: Bind app to a specific server certificate (prevents MITM).
- Data Encryption: Use SQLCipher for local databases (e.g., eSewa’s offline transactions).
- Secure Authentication: OAuth 2.0 (e.g., eSewa login via Facebook/Google).
Handling Network Disconnections in Mobile Apps
Mobile networks are unreliable (e.g., Kathmandu traffic jams drop 4G signals). Apps must handle:
Offline-First Design:
- Store data locally (e.g., Room Database in Android) and sync later.
- Example: Pathao app caches ride history for offline access.
Reconnection Logic:
- Use exponential backoff to retry failed requests.
- Example: Daraz app retries failed order placements every 5 seconds (then 10, 20, etc.).
Conflict Resolution:
- Last-write-wins: For non-critical data (e.g., chat messages).
- Merge strategies: For critical data (e.g., banking transactions).
// Pseudocode for offline-first sync (Android) public void syncData() { if (isOnline()) { uploadLocalChanges(); } else { scheduleRetry(); // Exponential backoff } }Trace:
Step Network Status Action 1 Online Uploads 3 pending orders 2 Offline Schedules retry in 5 seconds 3 Online (later) Retries, uploads remaining 1
Real-World Applications in Nepal
eSewa App:
- Technology: HTTPS (TLS 1.3) + OAuth for authentication.
- Wireless Use: Wi-Fi for home transactions, 4G for mobile payments.
- Challenge: Handles disconnections by caching transactions and syncing later.
Pathao Ride-Hailing:
- Technology: GPS (via cellular data) + WebSockets for real-time driver tracking.
- Protocol: MQTT for lightweight driver location updates.
- Example: When a user books a ride, the app:
- Sends a
POST /ridesrequest (HTTPS). - Subscribes to
pathao/ride/{id}/updates(MQTT) for ETA changes.
- Sends a
Ncell’s 4G Network:
- Protocol: SIP for VoIP calls (e.g., Ncell’s internet calling).
- Optimization: Uses load balancing to distribute traffic across cell towers during peak hours (e.g., 7–9 PM in Kathmandu).
Daraz Marketplace:
- Wireless Stack: HTTP/2 for product pages, MQTT for inventory updates.
- Offline Handling: Caches product listings; syncs when back online.
Exam Tip
- Diagrams Are Key:
- Draw OSI vs. TCP/IP model comparisons.
- Trace TLS handshake or MQTT publish-subscribe flows.
- Compare Protocols:
- Wi-Fi vs. Bluetooth vs. Cellular (speed, range, power).
- TCP vs. UDP (reliability vs. speed).
- Real-World Scenarios:
- Explain how eSewa uses HTTPS + OAuth or Pathao uses MQTT for GPS.
- Describe offline-first sync with a trace table.
- Security Focus:
- Differentiate WPA2 vs. WPA3 and TLS 1.2 vs. 1.3.
- Mention certificate pinning and OAuth 2.0 in app security.
- Common Pitfalls:
- Don’t confuse HTTP (stateless) with WebSockets (persistent).
- Remember: MQTT is for IoT/mobile messaging, not general web requests.
Visual Summary:
Based on the TU BIT syllabus for Mobile Application Development, unit 6.
Discussion
Loading…