会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 72. 发明申请
    • METHOD FOR ESTABLISHING TRUSTED NETWORK CONNECT FRAMEWORK OF TRI-ELEMENT PEER AUTHENTICATION
    • 建立三元网络认证网络连接框架的方法
    • US20120036553A1
    • 2012-02-09
    • US13264683
    • 2009-12-09
    • Yuelei XiaoJun CaoLi GeZhenhai Huang
    • Yuelei XiaoJun CaoLi GeZhenhai Huang
    • G06F21/20H04L29/06G06F15/16
    • H04L67/104G06F21/57H04L63/08H04L63/0876H04L63/105H04L63/20
    • The present invention provides a method for establishing the trusted network connect framework of tri-element peer authentication. The method includes: the implement of trusted network transport interface (IF-TNT); the implement of authentication policy service interface (IF-APS); the implement of trusted network connect (TNC) client-TNC access point interface (IF-TNCCAP); the implement of evaluation policy service interface (IF-EPS); the implement of integrity measurement collector interface (IF-IMC); the implement of integrity measurement verifier interface (IF-IMV); and the implement of integrity measurement (IF-IM). The embodiments of the present invention can establish the trust of the terminals, implement the trusted network connect of the terminals, implement the trusted authentication among the terminals, implement the trusted management of the terminals, and establish the TNC framework based on tri-element peer authentication (TePA) by defining the interfaces.
    • 本发明提供了一种建立三元对等认证的可信网络连接框架的方法。 该方法包括:实现可信网络传输接口(IF-TNT); 认证策略服务接口(IF-APS)的实现; 可信网络连接(TNC)客户端 - TNC接入点接口(IF-TNCCAP)的实现; 评估政策服务界面(IF-EPS)的实施; 完整性测量收集器接口(IF-IMC)的实现; 完整性测量验证器接口(IF-IMV)的实现; 和完整性测量(IF-IM)的实施。 本发明的实施例可以建立终端的信任,实现终端的可信网络连接,在终端之间实现可信认证,实现终端的可信管理,并建立基于三元对等体的TNC框架 认证(TePA)通过定义接口。
    • 73. 发明申请
    • AUTHENTICATION ASSOCIATED SUITE DISCOVERY AND NEGOTIATION METHOD
    • 认证相关的套装发现和谈判方法
    • US20110243330A1
    • 2011-10-06
    • US13133890
    • 2009-12-08
    • Yanan HuJun CaoYuelei XiaoManxia TieZhenhai HuangXiaolong Lai
    • Yanan HuJun CaoYuelei XiaoManxia TieZhenhai HuangXiaolong Lai
    • H04W12/06H04W12/04
    • H04W12/04H04W12/06
    • An authentication associated suite discovery and negotiation method for ultra wide band network. The method includes the following steps of: 1) adding a pairwise temporal key PTK establishment IE and a group temporal key GTK distribution IE in an information element IE list of an initiator and a responder, and setting a corresponding information element identifier ID, and 2) an authentication associated process based on the authentication associated suite discovery and negotiation method. The authentication associated suite discovery and negotiation method for ultra wide band network provided by the present invention can provide the discovery and negotiation functions of a security solution to the network so as to satisfy all kinds of application requirements better when multiple pairwise temporal key PTK establishing plans or multiple group temporal key GTK distributing plans co-exist.
    • 用于超宽带网络的认证相关套件发现和协商方法。 该方法包括以下步骤:1)在发起者和应答者的信息元素IE列表中添加成对的时间密钥PTK建立IE和组时间密钥GTK分布IE,并设置相应的信息元素标识符ID,2 )基于认证相关套件发现和协商方法的认证关联过程。 本发明提供的用于超宽带网络的认证相关套件发现和协商方法可以向网络提供安全解决方案的发现和协商功能,以便在多对成对临时密钥PTK建立计划时更好地满足各种应用需求 或多组时态密钥GTK分发计划并存。
    • 74. 发明申请
    • METHOD FOR MANAGING WIRELESS MULTI-HOP NETWORK KEY
    • 无线多路网络密钥管理方法
    • US20100299519A1
    • 2010-11-25
    • US12864317
    • 2009-01-21
    • Yuelei XiaoJun CaoXiaolong LaiZhenhai Huang
    • Yuelei XiaoJun CaoXiaolong LaiZhenhai Huang
    • H04L9/00
    • H04W12/04H04L9/083H04L9/0866H04L9/0891H04L63/061H04L2209/80H04L2463/061H04W84/18
    • A method for managing wireless multi-hop network key is applicable to a security application protocol when a WAPI frame method (TePA, an access control method based on the ternary peer-to-peer identification) is applied in a concrete network containing a Wireless Local Area Network, a Wireless Metropolitan Area Network AN and a Wireless Personal Area Network. The key management method of the present invention includes the steps of key generation, key distribution, key storage, key modification and key revocation. The present invention solves the technical problems that the prior pre-share-key based key management method is not suitable for larger networks and the PKI-based key management method is not suitable for wireless multi-hop networks; the public-key system and the ternary structure are adopted, thereby the security and the performance of the wireless multi-hop networks are improved.
    • 一种用于管理无线多跳网络密钥的方法适用于安全应用协议,当WAPI帧方法(TePA,基于三进制对等体标识的访问控制方法)被应用于包含无线本地 区域网络,无线城域网AN和无线个域网。 本发明的密钥管理方法包括密钥生成,密钥分配,密钥存储,密钥修改,密钥撤销等步骤。 本发明解决了以前的基于共享密钥的密钥管理方法不适用于较大网络的技术问题,而基于PKI的密钥管理方法不适用于无线多跳网络; 采用公钥系统和三元结构,提高无线多跳网络的安全性和性能。
    • 75. 发明申请
    • ENTITY BIDIRECTIONAL AUTHENTICATION METHOD AND SYSTEM
    • 实体双向认证方法与系统
    • US20100262832A1
    • 2010-10-14
    • US12808049
    • 2008-12-09
    • Manxia TieJun CaoZhenhai HuangXiaolong Lai
    • Manxia TieJun CaoZhenhai HuangXiaolong Lai
    • H04L9/32
    • H04L9/321H04L9/3247
    • An entity bidirectional authentication method and system, the method involves: the first entity sends the first message; the second entity sends the second message to the credible third party after receiving the said first message; the said credible third party returns the third message after receiving the second message; the said second entity sends the fourth message after receiving the third message and verifying it; the said first entity receives the said fourth message and verifies it, completes the authentication. Compared with the conventional authentication mechanism, the invention defines an on-line retrieval and authentication mechanism of a public key, realizes the centralized management for it, simplifies the operating condition of the protocol, and facilitates the application and implement.
    • 一种实体双向认证方法和系统,该方法涉及:第一实体发送第一消息; 第二实体在接收到所述第一消息之后将第二消息发送到可信第三方; 所述可信第三方在接收到第二消息后返回第三消息; 所述第二实体在接收到第三消息并验证之后发送第四消息; 所述第一实体接收所述第四消息并对其进行验证,从而完成认证。 与常规认证机制相比,本发明定义了公钥的在线检索和认证机制,实现了集中管理,简化了协议的工作状态,便于应用和实现。
    • 78. 发明授权
    • Key management and node authentication method for sensor network
    • 传感器网络的密钥管理和节点认证方法
    • US08913751B2
    • 2014-12-16
    • US13503171
    • 2010-06-02
    • Zhiqiang DuJun CaoManxia TieZhenhai Huang
    • Zhiqiang DuJun CaoManxia TieZhenhai Huang
    • H04L9/08H04L29/06H04W12/04H04W84/18H04W12/06H04L29/08
    • H04L63/061H04L63/062H04L63/08H04L63/1441H04L67/12H04W12/04H04W12/06H04W84/18
    • A key management and node authentication method for a sensor network is disclosed. The method comprises the following steps of: 1) keys pre-distribution: before deploying the network, communication keys for establishing security connection between nodes are pre-distributed to all of nodes by a deployment server. 2) Keys establishment: after deploying the network, a pair key for the security connection is established between nodes, which includes the following steps of: 2.1) establishment of shared keys: the pair key is established between neighbor nodes in which the shared keys are existed; 2.2) path keys establishment: the pair key is established between the nodes in which there is no shared keys but there is a multi-hop security connection. 3) Node identity (ID) authentication: before formally communicating between nodes, the identity is authenticated so as to determine the legality and the validity of the identity of the other. It is possible for effectively resisting attacks such as wiretapping, tampering, and replaying and the like for the network communication, realizing the secret communication between the nodes, effectively saving resources of the nodes of the sensor network, and prolonging the service lift of the sensor network in the method.
    • 公开了一种用于传感器网络的密钥管理和节点认证方法。 该方法包括以下步骤:1)密钥预分发:在部署网络之前,通过部署服务器将节点之间建立安全连接的通信密钥预分配给所有节点。 2)密钥建立:部署网络后,在节点之间建立安全连接对,包括以下步骤:2.1建立共享密钥:在共享密钥的邻居节点之间建立配对密钥 存在; 2.2)路径密钥建立:在没有共享密钥的节点之间建立配对密钥,但存在多跳安全连接。 3)节点身份(ID)认证:在节点之间正式通信之前,身份被认证,以确定其他身份的合法性和有效性。 有效抵御网络通信窃听,篡改,重放等攻击,实现节点之间的秘密通信,有效节省传感器网络节点的资源,延长传感器的业务提升 网络中的方法。
    • 79. 发明授权
    • Method for realizing convergent WAPI network architecture with split MAC mode
    • 用分割MAC模式实现融合WAPI网络架构的方法
    • US08855018B2
    • 2014-10-07
    • US13203643
    • 2009-12-14
    • Manxia TieJun CaoZhiqiang DuXiaolong LaiLi GeZhenhai Huang
    • Manxia TieJun CaoZhiqiang DuXiaolong LaiLi GeZhenhai Huang
    • H04L12/28H04W12/06H04W12/04H04W84/12
    • H04W12/06H04W12/04H04W84/12
    • A method for realizing a convergent Wireless Local Area Networks (WLAN) Authentication and Privacy Infrastructure (WAPI) network architecture with a split Medium Access Control (MAC) mode involves the steps: a split MAC mode for realizing WLAN Privacy Infrastructure (WPI) by a wireless terminal point is constructed through separating the MAC function and the WAPI function of the wireless access point apart to the wireless terminal point and an access controller; integration of a WAPI and a convergent WLAN network system architecture is realized under the split MAC mode that the wireless terminal point realizes WPI; the association connection process is performed among a station point, a wireless terminal point and an access controller; the process for announcing the start of performing the WLAN Authentication Infrastructure (WAI) protocol between the access controller and the wireless terminal point is performed; the process for performing the WAI protocol between the station point and the access controller is performed; the process for announcing the end of performing the WAI protocol between the access controller and the wireless terminal point is performed; the secret communication process is performed between the wireless terminal point and the station by using WPI.
    • 用于实现具有分离式媒体接入控制(MAC)模式的融合无线局域网(WLAN)认证和隐私基础设施(WAPI)网络架构的方法包括以下步骤:用于通过以下方式实现WLAN隐私基础设施(WPI)的分割MAC模式 无线终端通过将无线接入点的MAC功能和WAPI功能分离到无线终端点和接入控制器来构建; 在无线终端实现WPI的分割MAC模式下实现WAPI和融合WLAN网络系统架构的集成; 在站点,无线终端点和访问控制器之间执行关联连接处理; 执行在接入控制器和无线终端点之间通知执行WLAN认证基础设施(WAI)协议的开始的过程; 执行在站点和访问控制器之间执行WAI协议的过程; 执行用于在接入控制器和无线终端点之间通知执行WAI协议的结束的过程; 通过使用WPI在无线终端点和站之间执行秘密通信处理。
    • 80. 发明授权
    • Method for establishing trusted network connect framework of tri-element peer authentication
    • 建立三元对等认证可信网络连接框架的方法
    • US08789134B2
    • 2014-07-22
    • US13264683
    • 2009-12-09
    • Yuelei XiaoJun CaoLi GeZhenhai Huang
    • Yuelei XiaoJun CaoLi GeZhenhai Huang
    • H04L29/06
    • H04L67/104G06F21/57H04L63/08H04L63/0876H04L63/105H04L63/20
    • The present invention provides a method for establishing the trusted network connect framework of tri-element peer authentication. The method includes: the implement of trusted network transport interface (IF-TNT); the implement of authentication policy service interface (IF-APS); the implement of trusted network connect (TNC) client-TNC access point interface (IF-TNCCAP); the implement of evaluation policy service interface (IF-EPS); the implement of integrity measurement collector interface (IF-IMC); the implement of integrity measurement verifier interface (IF-IMV); and the implement of integrity measurement (IF-IM). The embodiments of the present invention can establish the trust of the terminals, implement the trusted network connect of the terminals, implement the trusted authentication among the terminals, implement the trusted management of the terminals, and establish the TNC framework based on tri-element peer authentication (TePA) by defining the interfaces.
    • 本发明提供了一种建立三元对等认证的可信网络连接框架的方法。 该方法包括:实现可信网络传输接口(IF-TNT); 认证策略服务接口(IF-APS)的实现; 可信网络连接(TNC)客户端 - TNC接入点接口(IF-TNCCAP)的实现; 评估政策服务界面(IF-EPS)的实施; 完整性测量采集器接口(IF-IMC)的实现; 完整性测量验证器接口(IF-IMV)的实现; 和完整性测量(IF-IM)的实施。 本发明的实施例可以建立终端的信任,实现终端的可信网络连接,在终端之间实现可信认证,实现终端的可信管理,并建立基于三元对等体的TNC框架 认证(TePA)通过定义接口。