会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 6. 发明申请
    • METHOD AND APPARATUS FOR PROVIDING AUTHENTICATION, AUTHORIZATION AND ACCOUNTING ROAMING NODES
    • 提供认证,授权和会计通知的方法和装置
    • WO2004036823A1
    • 2004-04-29
    • PCT/US2003/032498
    • 2003-10-14
    • FLARION TECHNOLOGIES, INC.O'NEILL, AlanVANDERVEEN, MichaelaTSIRTSIS, GeorgePARK, Vincent
    • O'NEILL, AlanVANDERVEEN, MichaelaTSIRTSIS, GeorgePARK, Vincent
    • H04L9/00
    • H04W12/06H04L63/061H04L63/08H04L63/0869H04L63/0892H04W12/04
    • The invention proposes an integrated process of authorizing and securing at layer 2 (L2) followed by layer 3 (L3). The L3 process treats the wireless link as any normal IP access link, and the L3 authorisation provides L3 processing, but also includes the L2 terminal authentication identifiers so that the L2 security parameters can also be returned. This means that the wireless link and the IP layer are not secured until after the L3 authorisation has completed and therefore the first IP messages that trigger authorisation are sent insecurely. This invention also provides methods to avoid these insecure messages presenting any opportunities to an attack. This inventions include methods to enable L3 before L2 authorisation when a user is roaming in a foreign network (480). These enable different types of AAA servers (450) in the foreign domain (480) to work with different types of AAA servers (460) in the home domain (470) to provide dynamic assignment of foreign mobility agents and the associated security associations between home and foreign mobility agents, as well a temporary account in the foreign domain (480). These methods apply both to standard MIP as well as Nested MIP, and to different types of Mobile Node apparatus and a range of user, host and terminal authentication models.
    • 本发明提出了在层2(L2)和层3(L3)之间授权和保护的综合过程。 L3过程将无线链路视为任何正常的IP接入链路,L3授权提供L3处理,但也包括L2终端认证标识符,从而也可以返回L2安全参数。 这意味着在L3授权完成之后,无线链路和IP层不被保护,因此触发授权的第一个IP消息被不安全地发送。 本发明还提供了避免这些不安全的消息呈现攻击机会的方法。 本发明包括当用户在外部网络漫游时在L2授权之前启用L3的方法(480)。 这些使得国外域(480)中的不同类型的AAA服务器(450)能够与归属域(470)中的不同类型的AAA服务器(460)一起工作,以提供外部移动代理的动态分配以及家庭之间的相关联的安全关联 和国外移动代理,以及外国的临时帐户(480)。 这些方法既适用于标准MIP以及嵌套MIP,也适用于不同类型的移动节点设备和一系列用户,主机和终端认证模型。
    • 8. 发明申请
    • METHODS AND APPARATUS FOR EXTENDING MOBILE IP
    • 扩展移动IP的方法和设备
    • WO2004098113A2
    • 2004-11-11
    • PCT/US2003/032884
    • 2003-10-15
    • FLARION TECHNOLOGIES, INC.O'NEILL, Alan
    • O'NEILL, Alan
    • H04L
    • H04L63/0281H04L63/0227H04L63/04H04L63/123H04L67/14H04L67/325H04L67/327H04L69/329H04W4/16H04W8/26H04W12/02H04W64/00H04W68/00H04W80/04
    • Methods and apparatus facilitating mobile node paging in a system where a mobile node is able to hand off application processing to an application proxy are described. Paging determinations are made based on application processing results corresponding to processing the content of multiple packet payloads. In some cases paging determinations are made based on processing the payload of a single packet in conjunction with information received from a mobile node, e.g., intermediate application processing results, mobile node state information, etc. To facilitate application processing handoffs in a manner that is transparent to a peer node involved in an ongoing communications session with the mobile node, security information may be passed between the mobile node and the application proxy node in a manner that is transparent to the peer node allowing an end to end security association to be maintained throughout the communications session with the peer node.
    • 描述了在移动节点能够将应用处理切换到应​​用代理的系统中促进移动节点寻呼的方法和装置。 基于对应于处理多个分组有效载荷的内容的应用处理结果进行寻呼确定。 在一些情况下,通过结合从移动节点接收的信息(例如,中间应用处理结果,移动节点状态信息等),处理单个分组的有效载荷来进行寻呼确定。为了便于应用处理切换 对涉及与移动节点的正在进行的通信会话中的对等节点透明的安全信息可以以对对等节点透明的方式在移动节点和应用代理节点之间传递,允许保持端到端的安全关联 在与对等节点的通信会话中。