BR0305019A - Interoperação baseada em corretor com emprego de certificados hierárquicos - Google Patents

Interoperação baseada em corretor com emprego de certificados hierárquicos

Info

Publication number
BR0305019A
BR0305019A BR0305019-0A BR0305019A BR0305019A BR 0305019 A BR0305019 A BR 0305019A BR 0305019 A BR0305019 A BR 0305019A BR 0305019 A BR0305019 A BR 0305019A
Authority
BR
Brazil
Prior art keywords
network
broker
user
key
certificate
Prior art date
Application number
BR0305019-0A
Other languages
English (en)
Inventor
Junbiao Zhang
Original Assignee
Thomson Licensing Sa
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Thomson Licensing Sa filed Critical Thomson Licensing Sa
Publication of BR0305019A publication Critical patent/BR0305019A/pt

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/062Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0892Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0825Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0431Key distribution or pre-distribution; Key agreement
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/02Terminal devices
    • H04W88/06Terminal devices adapted for operation in multiple networks or having at least two operational modes, e.g. multi-mode terminals
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W92/00Interfaces specially adapted for wireless communication networks
    • H04W92/02Inter-networking arrangements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/56Financial cryptography, e.g. electronic payment or e-cash
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Computer And Data Communications (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

"INTEROPERAçãO BASEADA EM CORRETOR COM EMPREGO DE CERTIFICADOS HIERáRQUICOS". Trata-se de um método para Autenticação, Autorização e Contabilidade (AAA) em uma interoperação entre pelo menos duas redes (210 e 220) . As pelo menos duas redes são capazes de comunicar-se com um corretor (230) e incluem um certificado de primeira rede e de segunda rede (220) para usuário de um dispositivo de usuário que corresponde ao usuário da primeira rede (210). O certificado de primeira rede para usuário é assinado por uma chave privada de primeira rede e inclui um certificado de corretor (230) para primeira rede e uma chave pública de usuário. O certificado de corretor (230) para primeira rede é assinado por uma chave privada de corretor (230) e indica uma chave pública de primeira rede (210). Uma chave de sessão é enviada da segunda rede (220) ao dispositivo de usuário quando se determina que o certificado de corretor (230) para primeira rede (210) e o certificado de primeira rede (210) para usuário são autênticos pela segunda rede (220) com base na chave pública de corretor (230) e na chave pública de primeira rede (210), respectivamente. A chave de sessão é criptografada com a chave pública de usuário. A chave de sessão é para permitir que o dispositivo de usuário acesse a segunda rede.
BR0305019-0A 2002-06-06 2003-05-27 Interoperação baseada em corretor com emprego de certificados hierárquicos BR0305019A (pt)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US38660302P 2002-06-06 2002-06-06
PCT/US2003/016546 WO2003105049A1 (en) 2002-06-06 2003-05-27 Broker-based interworking using hierarchical certificates

Publications (1)

Publication Number Publication Date
BR0305019A true BR0305019A (pt) 2004-11-09

Family

ID=29736185

Family Applications (1)

Application Number Title Priority Date Filing Date
BR0305019-0A BR0305019A (pt) 2002-06-06 2003-05-27 Interoperação baseada em corretor com emprego de certificados hierárquicos

Country Status (9)

Country Link
US (1) US8468354B2 (pt)
EP (1) EP1514208A4 (pt)
JP (1) JP4792221B2 (pt)
KR (1) KR101002471B1 (pt)
CN (1) CN1659558B (pt)
AU (1) AU2003237252A1 (pt)
BR (1) BR0305019A (pt)
MX (1) MXPA04012157A (pt)
WO (1) WO2003105049A1 (pt)

Families Citing this family (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1215386C (zh) * 2002-04-26 2005-08-17 St微电子公司 根据量子软计算控制过程或处理数据的方法和硬件体系结构
US8468354B2 (en) 2002-06-06 2013-06-18 Thomson Licensing Broker-based interworking using hierarchical certificates
KR20050012257A (ko) * 2002-06-06 2005-01-31 톰슨 라이센싱 에스.에이. Wlan과 이동 통신 네트워크 간의 연동의 혼성 결합을위한 논리 무선 네트워크 제어기(rnc)로서의 연동기능(iwf)
JP2006139747A (ja) * 2004-08-30 2006-06-01 Kddi Corp 通信システムおよび安全性保証装置
DE102004045147A1 (de) * 2004-09-17 2006-03-23 Fujitsu Ltd., Kawasaki Einstellungsinformations-Verteilungsvorrichtung, Verfahren, Programm und Medium, Authentifizierungseinstellungs-Transfervorrichtung, Verfahren, Programm und Medium und Einstellungsinformations-Empfangsprogramm
US7614080B2 (en) * 2005-12-28 2009-11-03 Panasonic Electric Works Co., Ltd. Systems and methods for providing secure access to embedded devices using a trust manager and a security broker
US7908292B2 (en) * 2006-12-05 2011-03-15 Nokia Corporation Metadata broker
US20090259851A1 (en) 2008-04-10 2009-10-15 Igor Faynberg Methods and Apparatus for Authentication and Identity Management Using a Public Key Infrastructure (PKI) in an IP-Based Telephony Environment
KR101527999B1 (ko) * 2009-06-10 2015-06-10 애플 인크. 제 2 액세스 네트워크와 인터워킹할 수 있는 제 1 액세스 네트워크의 존재의 인디케이터의 제공
US8914628B2 (en) * 2009-11-16 2014-12-16 At&T Intellectual Property I, L.P. Method and apparatus for providing radio communication with an object in a local environment
US9215220B2 (en) 2010-06-21 2015-12-15 Nokia Solutions And Networks Oy Remote verification of attributes in a communication network
EP2617223B1 (en) * 2010-09-17 2020-10-21 Nokia Solutions and Networks Oy Remote verification of attributes in a communication network
US10205598B2 (en) 2015-05-03 2019-02-12 Ronald Francis Sulpizio, JR. Temporal key generation and PKI gateway
US10687212B2 (en) * 2017-04-07 2020-06-16 At&T Mobility Ii Llc Mobile network core component for managing security keys
US10959167B1 (en) * 2020-05-06 2021-03-23 Verizon Patent And Licensing Inc. System and method for 5G service icon display and quality of service enforcement

Family Cites Families (56)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5455863A (en) 1993-06-29 1995-10-03 Motorola, Inc. Method and apparatus for efficient real-time authentication and encryption in a communication system
US5371794A (en) 1993-11-02 1994-12-06 Sun Microsystems, Inc. Method and apparatus for privacy and authentication in wireless networks
EP0658021B1 (en) 1993-12-08 2001-03-28 International Business Machines Corporation A method and system for key distribution and authentication in a data communication network
JP3453944B2 (ja) 1995-09-04 2003-10-06 日本電信電話株式会社 秘話通信方法
KR20000004913A (ko) 1996-04-10 2000-01-25 히라따 다다시 저급올레핀의 이량화법
US5850444A (en) 1996-09-09 1998-12-15 Telefonaktienbolaget L/M Ericsson (Publ) Method and apparatus for encrypting radio traffic in a telecommunications network
US6009173A (en) * 1997-01-31 1999-12-28 Motorola, Inc. Encryption and decryption method and apparatus
US20010010046A1 (en) * 1997-09-11 2001-07-26 Muyres Matthew R. Client content management and distribution system
US6393482B1 (en) 1997-10-14 2002-05-21 Lucent Technologies Inc. Inter-working function selection system in a network
FI974341A (fi) 1997-11-26 1999-05-27 Nokia Telecommunications Oy Datayhteyksien tietosuoja
US6069947A (en) 1997-12-16 2000-05-30 Nortel Networks Corporation Communication system architecture and operating protocol therefor
US6535493B1 (en) 1998-01-15 2003-03-18 Symbol Technologies, Inc. Mobile internet communication protocol
US6233577B1 (en) 1998-02-17 2001-05-15 Phone.Com, Inc. Centralized certificate management system for two-way interactive communication devices in data networks
US6553493B1 (en) 1998-04-28 2003-04-22 Verisign, Inc. Secure mapping and aliasing of private keys used in public key cryptography
FI105965B (fi) 1998-07-07 2000-10-31 Nokia Networks Oy Autentikointi tietoliikenneverkosssa
BR9815908A (pt) * 1998-07-15 2001-10-09 Ibm Processo de estabelecer o nìvel de confiabilidade de um participante em uma conexão de comunicação
US6115699A (en) 1998-12-03 2000-09-05 Nortel Networks Corporation System for mediating delivery of a document between two network sites
JP2000244547A (ja) * 1999-02-17 2000-09-08 Nippon Telegr & Teleph Corp <Ntt> 認証方法
US6463534B1 (en) 1999-03-26 2002-10-08 Motorola, Inc. Secure wireless electronic-commerce system with wireless network domain
KR100415022B1 (ko) 1999-05-21 2004-01-13 인터내셔널 비지네스 머신즈 코포레이션 무선 장치들 사이에서 보안 통신을 초기화하고 이들 무선장치들을 배타적으로 페어링하기 위한 방법 및 장치
US6772331B1 (en) 1999-05-21 2004-08-03 International Business Machines Corporation Method and apparatus for exclusively pairing wireless devices
FI107486B (fi) 1999-06-04 2001-08-15 Nokia Networks Oy Autentikaation ja salauksen järjestäminen matkaviestinjärjestelmässä
US7174018B1 (en) 1999-06-24 2007-02-06 Nortel Networks Limited Security framework for an IP mobility system using variable-based security associations and broker redirection
US7028186B1 (en) 2000-02-11 2006-04-11 Nokia, Inc. Key management methods for wireless LANs
FI20000761A0 (fi) 2000-03-31 2000-03-31 Nokia Mobile Phones Ltd Laskutus pakettidataverkossa
US6766160B1 (en) 2000-04-11 2004-07-20 Nokia Corporation Apparatus, and associated method, for facilitating authentication of communication stations in a mobile communication system
US6451295B1 (en) * 2000-08-31 2002-09-17 Colgate-Palmolive Company Clear antiperspirants and deodorants made with siloxane-based polyamides
GB2367213B (en) 2000-09-22 2004-02-11 Roke Manor Research Access authentication system
US6915345B1 (en) 2000-10-02 2005-07-05 Nortel Networks Limited AAA broker specification and protocol
GB2369530A (en) 2000-11-24 2002-05-29 Ericsson Telefon Ab L M IP security connections for wireless authentication
US6961776B1 (en) * 2000-12-22 2005-11-01 Nortel Networks Limited Architecture for multiple channel access to applications
FI110977B (fi) 2001-02-09 2003-04-30 Nokia Oyj Mekanismi palvelujen mainostamista ja käyttäjän auktorisointia varten
SE0100474D0 (sv) 2001-02-14 2001-02-14 Ericsson Telefon Ab L M A security architecture
US6879690B2 (en) 2001-02-21 2005-04-12 Nokia Corporation Method and system for delegation of security procedures to a visited domain
US20020120536A1 (en) 2001-02-23 2002-08-29 David Maung Financial institution wireless internet system and method
US20020174335A1 (en) 2001-03-30 2002-11-21 Junbiao Zhang IP-based AAA scheme for wireless LAN virtual operators
US7921290B2 (en) * 2001-04-18 2011-04-05 Ipass Inc. Method and system for securely authenticating network access credentials for users
JP4042344B2 (ja) * 2001-04-25 2008-02-06 松下電工株式会社 ウォールウォッシャー型照明器具
US6856800B1 (en) 2001-05-14 2005-02-15 At&T Corp. Fast authentication and access control system for mobile networking
CN1653459B (zh) 2001-06-12 2010-12-15 捷讯研究有限公司 处理与移动数据通信设备交换的编码消息的系统和方法
US7389412B2 (en) 2001-08-10 2008-06-17 Interactive Technology Limited Of Hk System and method for secure network roaming
US7207060B2 (en) * 2001-10-18 2007-04-17 Nokia Corporation Method, system and computer program product for secure ticketing in a communications device
IL162011A0 (en) 2001-11-29 2005-11-20 Siemens Ag Use of a public key pair in the terminal for authentication and authorisation of the telecommunication user with the network op
SE0104325D0 (sv) 2001-12-20 2001-12-20 Ericsson Telefon Ab L M A method and apparatus for switching access between mobile networks
US20030139180A1 (en) 2002-01-24 2003-07-24 Mcintosh Chris P. Private cellular network with a public network interface and a wireless local area network extension
US20030211842A1 (en) 2002-02-19 2003-11-13 James Kempf Securing binding update using address based keys
US6792534B2 (en) 2002-03-22 2004-09-14 General Instrument Corporation End-to end protection of media stream encryption keys for voice-over-IP systems
KR101013523B1 (ko) 2002-04-26 2011-02-10 톰슨 라이센싱 액세스 네트워크 사이의 연동에서의 과도적인 인증 공인 계정
KR100427551B1 (ko) * 2002-05-14 2004-04-28 에스케이 텔레콤주식회사 공중 무선랜과 셀룰러망 간의 로밍 방법
US8468354B2 (en) 2002-06-06 2013-06-18 Thomson Licensing Broker-based interworking using hierarchical certificates
US7764660B2 (en) * 2002-06-21 2010-07-27 Thomson Licensing Registration of a WLAN as a UMTS routing area for WLAN-UMTS interworking
WO2004062114A2 (en) * 2002-06-21 2004-07-22 Thomson Licensing S.A. Multimedia content delivery through wlan coverage area
US7581095B2 (en) 2002-07-17 2009-08-25 Harris Corporation Mobile-ad-hoc network including node authentication features and related methods
ITRM20030100A1 (it) * 2003-03-06 2004-09-07 Telecom Italia Mobile Spa Tecnica di accesso multiplo alla rete, da parte di terminale di utente interconnesso ad una lan e relativa architettura di riferimento.
GB2402842B (en) 2003-06-12 2005-06-08 Nec Technologies Mobile radio communications device
ES2297531T3 (es) 2003-08-29 2008-05-01 Thomson Licensing Metodo y aparato para moldear modelos de grano de pelicula en el dominio de la frecuencia.

Also Published As

Publication number Publication date
US8468354B2 (en) 2013-06-18
US20050240760A1 (en) 2005-10-27
CN1659558A (zh) 2005-08-24
JP2005529525A (ja) 2005-09-29
EP1514208A1 (en) 2005-03-16
MXPA04012157A (es) 2005-04-19
KR101002471B1 (ko) 2010-12-17
AU2003237252A1 (en) 2003-12-22
WO2003105049A1 (en) 2003-12-18
KR20050010859A (ko) 2005-01-28
EP1514208A4 (en) 2010-11-17
CN1659558B (zh) 2010-09-22
JP4792221B2 (ja) 2011-10-12

Similar Documents

Publication Publication Date Title
BR0305019A (pt) Interoperação baseada em corretor com emprego de certificados hierárquicos
BR0309523A (pt) Autenticação, autorização, contabilidade transitiva na inter-operação entre redes de acesso
BR0309437A (pt) Esquema de autenticação, autorização e contabilidade baseado em certificado para interação de acoplamento livre
BR0311994A (pt) geração de chave em um sistema de comunicação
BR0203323A (pt) Aperfeiçoamento introduzido em sistema de terminal de comunicação
BRPI0520722A2 (pt) método para prover automaticamente o solicitante de acesso de rede com credenciais de acesso de serviço para acessar um serviço on-line, sistema para prover automaticamente a um terminal de comunicação, adaptado ao uso em uma rede de comunicações, credenciais de acesso de serviço para acessar um serviço on-line, entidade de autenticação, provedor de serviço on-line, e, terminal de comunicação
BRPI0417840A (pt) sistema, método e dispositivos para autenticação em uma rede de área local sem fio (wlan)
BRPI0412772A (pt) método e aparelho para o controle de acesso com base em crédito (pré-pago) a uma rede sem fio
BRPI0519184A2 (pt) mÉtodos para autenticar um serviÇo remoto para um usuÁrio, e para autenticar mutuamente um usuÁrio de serviÇo remoto e um serviÇo remoto, arquitetura de software, dispositivo de autenticaÇço, e, mÉtodos para autenticar a identidade e/ou credenciais de um segundo usuÁrio para um primeiro usuÁrio, para criar um dispositivo de autenticaÇço, e, para autenticar um usuÁrio para um serviÇo remoto
WO2007087298A3 (en) Method and apparatus for accessing web services and url resources
ZA200609164B (en) Certificate validity checking
AU2003222104A1 (en) Validation of inclusion of a platform within a data center
BRPI0415916A (pt) método e equipamento para prover credenciais de aplicativo
EP1363424A3 (en) Authentication method and system encrypting a ticket with an symmetric key, said symmetric key being encrypted with an asymmetric key
TW200509637A (en) Method to create and manage a local network
EP1643677A3 (en) Method of authenticating device using broadcast cryptography
BR0305273A (pt) Sistema e método para transmitir informação reduzida de um certificado para executar operações de criptografia
BR0317482A (pt) Geração e distribuição de visualização de conteúdo digital entre dispositivos pares
WO2008121157A3 (en) Cryptographic key management system facilitating secure access of data portions to corresponding groups of users
BR0309974A (pt) Autenticação sem restrição de usuário de rede de área local pública sem fio
BR9917545A (pt) Processo para o estabelecimento de uma chave utilizando comunicação por ar e protocolo de senha e protocolo de senha
BRPI0413462A (pt) método e dispositivo para proteger distribuição de conteúdo por uma rede de comunicação por meio de chaves de conteúdo
BRPI0501429A (pt) Criação de conta via um dispositivo móvel
WO2008154154A3 (en) Secure mobile ipv6 registration
BRPI0412397A (pt) equipamento e método para um sistema de broadcast seguro

Legal Events

Date Code Title Description
B08F Application fees: application dismissed [chapter 8.6 patent gazette]

Free format text: REFERENTE A 7A E 8A ANUIDADE(S).

B08K Patent lapsed as no evidence of payment of the annual fee has been furnished to inpi [chapter 8.11 patent gazette]

Free format text: NAO APRESENTADA A GUIA DE CUMPRIMENTO DE EXIGENCIA. REFERENTE AS 7A E 8A ANUIDADES.

B15K Others concerning applications: alteration of classification

Ipc: H04W 12/06 (2009.01), H04L 9/08 (2006.01), H04L 9/