会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 6. 发明申请
    • Kerberized handover keying
    • Kerberized切换密钥
    • US20080175393A1
    • 2008-07-24
    • US11972450
    • 2008-01-10
    • Yoshihiro OBASubir DAS
    • Yoshihiro OBASubir DAS
    • H04L9/08H04L9/32
    • H04W12/06H04L63/062H04L63/0807H04L63/162H04W8/005H04W12/04H04W36/005H04W36/12
    • A media-independent handover key management architecture is disclosed that uses Kerberos for secure key distribution among a server, an authenticator, and a mobile node. In the preferred embodiments, signaling for key distribution is based on re-keying and is decoupled from re-authentication that requires EAP (Extensible Authentication Protocol) and AAA (Authentication, Authorization and Accounting) signaling similar to initial network access authentication. In this framework, the mobile node is able to obtain master session keys required for dynamically establishing the security associations with a set of authenticators without communicating with them before handover. By separating re-key operation from re-authentication, the proposed architecture is more optimized for a proactive mode of operation. It can also be optimized for reactive mode of operation by reversing the key distribution roles between the mobile node and the target access node.
    • 公开了一种媒体独立的切换密钥管理架构,其使用Kerberos在服务器,认证器和移动节点之间进行安全密钥分发。 在优选实施例中,用于密钥分发的信令基于重新键入,并且与需要与初始网络接入认证相似的EAP(可扩展认证协议)和AAA(认证,授权和计费)信令的再认证解耦。 在该框架中,移动节点能够获得主动会话密钥,用于在切换之前与一组认证者动态建立安全关联,而不与其进行通信。 通过将重新键入操作与重新认证分离,所提出的架构针对主动操作模式进行了更优化。 还可以通过反转移动节点和目标接入节点之间的密钥分发角色来优化用于反应的操作模式。
    • 10. 发明申请
    • COMMUNICATION APPARATUS AND COMPUTER PROGRAM PRODUCT
    • 通信设备和计算机程序产品
    • US20130073852A1
    • 2013-03-21
    • US13551352
    • 2012-07-17
    • Yoshihiro OBAMitsuru KandaYasuyuki TanakaSeijiro Yoneyama
    • Yoshihiro OBAMitsuru KandaYasuyuki TanakaSeijiro Yoneyama
    • H04L9/32
    • H04W12/06H04L9/0836H04L9/0866H04L9/3273H04L63/061H04L63/0884H04L63/123H04L63/162H04L67/12H04W12/04H04W12/10
    • According to an embodiment, a communication apparatus establishes communication with an external apparatus through a higher-level device. The communication apparatus includes a main processor and a key generator. The main processor receives a data authentication request including data to be authenticated, a first key specification, and a message authentication algorithm identifier from the higher-level device. The key generator retains a key hierarchy used by an authentication protocol that is used between the higher-level device and the external apparatus, and to generate a first key by use of the key hierarchy and the first key specification. The main processor generates a message authentication code for the data to be authenticated by use of the message authentication algorithm, which is identified by the message authentication algorithm identifier, and the first key, and transmits a data authentication response including the message authentication code to the higher-level device.
    • 根据实施例,通信装置通过较高级别的装置建立与外部装置的通信。 通信装置包括主处理器和密钥发生器。 主处理器从上级设备接收包括要认证的数据的数据认证请求,第一密钥规范和消息认证算法标识符。 密钥生成器保留由上级设备和外部设备之间使用的认证协议使用的密钥层级,并且通过使用密钥层次和第一密钥规范来生成第一密钥。 主处理器通过使用由消息认证算法标识符识别的消息认证算法和第一密钥来生成用于要认证的数据的消息认证码,并将包括消息认证码的数据认证响应发送到 更高级别的设备。