EP1606899A2 - Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session - Google Patents

Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session

Info

Publication number
EP1606899A2
EP1606899A2 EP04719770A EP04719770A EP1606899A2 EP 1606899 A2 EP1606899 A2 EP 1606899A2 EP 04719770 A EP04719770 A EP 04719770A EP 04719770 A EP04719770 A EP 04719770A EP 1606899 A2 EP1606899 A2 EP 1606899A2
Authority
EP
European Patent Office
Prior art keywords
key
secure
mobile terminal
session key
session
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP04719770A
Other languages
German (de)
English (en)
Other versions
EP1606899A4 (fr
Inventor
Junbiao Zhang
Saurabh Mathur
Sachin Mody
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
THOMSON LICENSING
Original Assignee
Thomson Licensing SAS
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Thomson Licensing SAS filed Critical Thomson Licensing SAS
Publication of EP1606899A2 publication Critical patent/EP1606899A2/fr
Publication of EP1606899A4 publication Critical patent/EP1606899A4/fr
Withdrawn legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0838Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
    • H04L9/0841Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
    • H04L9/0844Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0891Revocation or update of secret information, e.g. encryption key update or rekeying
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/30Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/35Protecting application or service provisioning, e.g. securing SIM application provisioning
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/061Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying further key derivation, e.g. deriving traffic keys from a pair-wise master key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computing Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Small-Scale Networks (AREA)

Abstract

L'invention porte sur un procédé visant à renforcer la sécurité d'un terminal mobile dans un environnement WLAN en installant deux clés secrètes partagées au lieu d'une seule, la clé de session initiale, sur la machine utilisateur sans fil et sur le point d'accès WLAN pendant la phase d'authentification utilisateur. L'une des clés secrètes partagées est utilisée comme la clé de session initiale et l'autre est utilisée comme noyau sécurisé. Du fait que l'authentification initiale est sécurisée, ces deux clés ne sont pas connues des pirates informatiques. Bien que la clé de session initiale puisse être éventuellement fracturée par un pirate informatique, le noyau sécurisé reste sécurisé puisqu'il n'était pas utilisé dans une communication quelconque non sécurisée.
EP04719770A 2003-03-14 2004-03-11 Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session Withdrawn EP1606899A4 (fr)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
US45454203P 2003-03-14 2003-03-14
US454542P 2003-03-14
PCT/US2004/007403 WO2004084458A2 (fr) 2003-03-14 2004-03-11 Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session

Publications (2)

Publication Number Publication Date
EP1606899A2 true EP1606899A2 (fr) 2005-12-21
EP1606899A4 EP1606899A4 (fr) 2011-11-02

Family

ID=33029889

Family Applications (1)

Application Number Title Priority Date Filing Date
EP04719770A Withdrawn EP1606899A4 (fr) 2003-03-14 2004-03-11 Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session

Country Status (7)

Country Link
EP (1) EP1606899A4 (fr)
JP (2) JP2006520571A (fr)
KR (2) KR20060053003A (fr)
CN (2) CN1759550A (fr)
MX (1) MXPA05009804A (fr)
MY (1) MY135833A (fr)
WO (1) WO2004084458A2 (fr)

Families Citing this family (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20060053003A (ko) * 2003-03-14 2006-05-19 톰슨 라이센싱 보안 리키잉과 로그 오프를 이용한 wlan 세션 관리기술
US7142851B2 (en) * 2003-04-28 2006-11-28 Thomson Licensing Technique for secure wireless LAN access
CN102752309A (zh) * 2005-04-22 2012-10-24 汤姆森特许公司 用于移动设备对无线局域网的安全匿名接入的方法
EP3021553A1 (fr) * 2005-04-22 2016-05-18 Thomson Licensing Méthode et appareils d'accès à un réseau local sans fil (wlan) anonyme et sécurisé
CN101454767B (zh) * 2006-04-24 2013-08-14 鲁库斯无线公司 安全无线网络中的动态认证
EP2013758B1 (fr) * 2006-04-24 2016-08-03 Ruckus Wireless, Inc. Authentification dynamique dans des reseaux sans fil securises
WO2008001904A1 (fr) 2006-06-30 2008-01-03 Nikon Corporation Appareil photo numérique
CN101682513A (zh) * 2007-06-11 2010-03-24 Nxp股份有限公司 认证方法以及用于执行认证的电子装置
KR101016277B1 (ko) * 2007-12-20 2011-02-22 건국대학교 산학협력단 보안성이 강화된 sⅰp 등록 및 sⅰp 세션 설정 방법 및장치
US8756668B2 (en) 2012-02-09 2014-06-17 Ruckus Wireless, Inc. Dynamic PSK for hotspots
US10576256B2 (en) 2016-12-13 2020-03-03 Becton, Dickinson And Company Antiseptic applicator
US11689925B2 (en) * 2017-09-29 2023-06-27 Plume Design, Inc. Controlled guest access to Wi-Fi networks
US11496902B2 (en) 2017-09-29 2022-11-08 Plume Design, Inc. Access to Wi-Fi networks via two-step and two-party control
CN111404666A (zh) * 2019-01-02 2020-07-10 中国移动通信有限公司研究院 一种密钥生成方法、终端设备及网络设备

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2002508892A (ja) * 1997-03-10 2002-03-19 ガイ・エル・フィールダー 双方向認証および暗号化システム
FI113119B (fi) * 1997-09-15 2004-02-27 Nokia Corp Menetelmä tietoliikenneverkkojen lähetysten turvaamiseksi
DE69834431T3 (de) * 1998-01-02 2009-09-10 Cryptography Research Inc., San Francisco Leckresistentes kryptographisches verfahren und vorrichtung
US6151677A (en) * 1998-10-06 2000-11-21 L-3 Communications Corporation Programmable telecommunications security module for key encryption adaptable for tokenless use
US7028186B1 (en) * 2000-02-11 2006-04-11 Nokia, Inc. Key management methods for wireless LANs
JP2002077129A (ja) * 2000-08-24 2002-03-15 Nissin Electric Co Ltd 暗号通信方法
KR20060053003A (ko) * 2003-03-14 2006-05-19 톰슨 라이센싱 보안 리키잉과 로그 오프를 이용한 wlan 세션 관리기술

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
"An initial Security Analysis of the IEEE 802.1X Standard", , 1 January 2002 (2002-01-01), XP55007968, Retrieved from the Internet: URL:http://www.cs.umd.edu/~waa/1x.pdf [retrieved on 2011-09-23] *
SALOWEY CISCO P ERONEN NOKIA J: "EAP Key Derivation for Multiple Applications; draft-salowey-eap-key-deriv-00.txt", IETF STANDARD-WORKING-DRAFT, INTERNET ENGINEERING TASK FORCE, IETF, CH, 1 February 2003 (2003-02-01), XP015005137, ISSN: 0000-0004 *
See also references of WO2004084458A2 *

Also Published As

Publication number Publication date
KR20060053003A (ko) 2006-05-19
KR20050116821A (ko) 2005-12-13
MY135833A (en) 2008-07-31
MXPA05009804A (es) 2006-05-19
CN1874222A (zh) 2006-12-06
WO2004084458A2 (fr) 2004-09-30
JP2006180561A (ja) 2006-07-06
JP2006520571A (ja) 2006-09-07
CN1759550A (zh) 2006-04-12
EP1606899A4 (fr) 2011-11-02
WO2004084458A3 (fr) 2004-11-18

Similar Documents

Publication Publication Date Title
US20070189537A1 (en) WLAN session management techniques with secure rekeying and logoff
KR100832893B1 (ko) 무선 근거리 통신망으로 이동 단말의 보안 접근 방법 및 무선 링크를 통한 보안 데이터 통신 방법
JP3863852B2 (ja) 無線環境におけるネットワークへのアクセス制御方法及びこれを記録した記録媒体
EP1422875B1 (fr) Clef de transfert pour réseau sans fil
US8635456B2 (en) Remote secure authorization
US8161278B2 (en) System and method for distributing keys in a wireless network
EP1484856B1 (fr) Procede de distribution de cles de chiffrage dans un reseau lan sans fil
JP5597676B2 (ja) 鍵マテリアルの交換
JP2006180561A (ja) セキュア鍵及びログオフを用いるwlanセッション管理技術
US9392453B2 (en) Authentication
KR101309426B1 (ko) 모바일 네트워크에서 재귀 인증을 위한 방법 및 시스템
US20060059344A1 (en) Service authentication
EP1933498B1 (fr) Procede, systeme et dispositif de negociation a propos d'une cle de chiffrement partagee par equipement utilisateur et equipement externe
JP2006524017A (ja) 公的認証サーバで無線lanアクセスを制御するidマッピング機構
JP2006109449A (ja) 認証された無線局に暗号化キーを無線で提供するアクセスポイント
JP2007506329A (ja) Wlanセキュリティを向上させる方法
US20090028335A1 (en) System and method for secure access control in a wireless network
US7784086B2 (en) Method for secure packet identification
Sorman et al. Implementing improved WLAN security
Bakirdan et al. Security algorithms in wireless LAN: proprietary or nonproprietary
US20060173981A1 (en) Secure web browser based system administration for embedded platforms
EP1604294A2 (fr) Gestion de systeme par navigateur web securise pour plates-formes imbriquees
KR100924315B1 (ko) 보안성이 강화된 무선랜 인증 시스템 및 그 방법
Nagesha et al. A Survey on Wireless Security Standards and Future Scope.
Rincon et al. On Securing Wireless LANs and Supporting Nomadic Users with Microsoft’s IPSec Implementation

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20050928

AK Designated contracting states

Kind code of ref document: A2

Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LI LU MC NL PL PT RO SE SI SK TR

AX Request for extension of the european patent

Extension state: AL LT LV MK

DAX Request for extension of the european patent (deleted)
RBV Designated contracting states (corrected)

Designated state(s): DE FR GB IT

RAP1 Party data changed (applicant data changed or rights of an application transferred)

Owner name: THOMSON LICENSING

A4 Supplementary search report drawn up and despatched

Effective date: 20111005

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20120105