WO2004084458A3 - Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session - Google Patents

Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session Download PDF

Info

Publication number
WO2004084458A3
WO2004084458A3 PCT/US2004/007403 US2004007403W WO2004084458A3 WO 2004084458 A3 WO2004084458 A3 WO 2004084458A3 US 2004007403 W US2004007403 W US 2004007403W WO 2004084458 A3 WO2004084458 A3 WO 2004084458A3
Authority
WO
WIPO (PCT)
Prior art keywords
secure
logoff
session key
session management
management techniques
Prior art date
Application number
PCT/US2004/007403
Other languages
English (en)
Other versions
WO2004084458A2 (fr
Inventor
Junbiao Zhang
Saurabh Mathur
Sachin Mody
Original Assignee
Thomson Licensing Sa
Junbiao Zhang
Saurabh Mathur
Sachin Mody
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Thomson Licensing Sa, Junbiao Zhang, Saurabh Mathur, Sachin Mody filed Critical Thomson Licensing Sa
Priority to MXPA05009804A priority Critical patent/MXPA05009804A/es
Priority to US10/549,408 priority patent/US20060179305A1/en
Priority to JP2006507069A priority patent/JP2006520571A/ja
Priority to EP04719770A priority patent/EP1606899A4/fr
Publication of WO2004084458A2 publication Critical patent/WO2004084458A2/fr
Publication of WO2004084458A3 publication Critical patent/WO2004084458A3/fr
Priority to US11/371,662 priority patent/US20070189537A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0838Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
    • H04L9/0841Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols
    • H04L9/0844Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these involving Diffie-Hellman or related key agreement protocols with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0891Revocation or update of secret information, e.g. encryption key update or rekeying
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/30Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/35Protecting application or service provisioning, e.g. securing SIM application provisioning
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/061Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying further key derivation, e.g. deriving traffic keys from a pair-wise master key
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]

Abstract

L'invention porte sur un procédé visant à renforcer la sécurité d'un terminal mobile dans un environnement WLAN en installant deux clés secrètes partagées au lieu d'une seule, la clé de session initiale, sur la machine utilisateur sans fil et sur le point d'accès WLAN pendant la phase d'authentification utilisateur. L'une des clés secrètes partagées est utilisée comme la clé de session initiale et l'autre est utilisée comme noyau sécurisé. Du fait que l'authentification initiale est sécurisée, ces deux clés ne sont pas connues des pirates informatiques. Bien que la clé de session initiale puisse être éventuellement fracturée par un pirate informatique, le noyau sécurisé reste sécurisé puisqu'il n'était pas utilisé dans une communication quelconque non sécurisée.
PCT/US2004/007403 2003-03-14 2004-03-11 Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session WO2004084458A2 (fr)

Priority Applications (5)

Application Number Priority Date Filing Date Title
MXPA05009804A MXPA05009804A (es) 2003-03-14 2004-03-11 Tecnicas de manejo de sesion de red de area local inalambrica con claves dobles y salida de registro seguros.
US10/549,408 US20060179305A1 (en) 2004-03-11 2004-03-11 WLAN session management techniques with secure rekeying and logoff
JP2006507069A JP2006520571A (ja) 2003-03-14 2004-03-11 セキュア鍵及びログオフを用いるwlanセッション管理技術
EP04719770A EP1606899A4 (fr) 2003-03-14 2004-03-11 Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session
US11/371,662 US20070189537A1 (en) 2003-03-14 2006-03-09 WLAN session management techniques with secure rekeying and logoff

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US45454203P 2003-03-14 2003-03-14
US60/454,542 2003-03-14

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US11/371,662 Continuation US20070189537A1 (en) 2003-03-14 2006-03-09 WLAN session management techniques with secure rekeying and logoff

Publications (2)

Publication Number Publication Date
WO2004084458A2 WO2004084458A2 (fr) 2004-09-30
WO2004084458A3 true WO2004084458A3 (fr) 2004-11-18

Family

ID=33029889

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2004/007403 WO2004084458A2 (fr) 2003-03-14 2004-03-11 Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session

Country Status (7)

Country Link
EP (1) EP1606899A4 (fr)
JP (2) JP2006520571A (fr)
KR (2) KR20050116821A (fr)
CN (2) CN1874222A (fr)
MX (1) MXPA05009804A (fr)
MY (1) MY135833A (fr)
WO (1) WO2004084458A2 (fr)

Families Citing this family (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20050116821A (ko) * 2003-03-14 2005-12-13 톰슨 라이센싱 보안 리키잉과 로그 오프를 이용한 wlan 세션 관리기술
US7142851B2 (en) * 2003-04-28 2006-11-28 Thomson Licensing Technique for secure wireless LAN access
CN102752309A (zh) * 2005-04-22 2012-10-24 汤姆森特许公司 用于移动设备对无线局域网的安全匿名接入的方法
MX2007013117A (es) * 2005-04-22 2008-01-14 Thomson Licensing Metodo y aparato para el acceso anonimo, seguro a una red de area local inalambrica (wlan).
CN103441984B (zh) * 2006-04-24 2017-09-05 鲁库斯无线公司 安全无线网络中的动态认证
CN101454767B (zh) * 2006-04-24 2013-08-14 鲁库斯无线公司 安全无线网络中的动态认证
JP4924608B2 (ja) 2006-06-30 2012-04-25 株式会社ニコン デジタルカメラ
WO2008152533A2 (fr) * 2007-06-11 2008-12-18 Nxp B.V. Procédé d'authentification et dispositif électronique pour la réalisation de cette authentification
KR101016277B1 (ko) * 2007-12-20 2011-02-22 건국대학교 산학협력단 보안성이 강화된 sⅰp 등록 및 sⅰp 세션 설정 방법 및장치
US8756668B2 (en) 2012-02-09 2014-06-17 Ruckus Wireless, Inc. Dynamic PSK for hotspots
US10576256B2 (en) 2016-12-13 2020-03-03 Becton, Dickinson And Company Antiseptic applicator
US11689925B2 (en) 2017-09-29 2023-06-27 Plume Design, Inc. Controlled guest access to Wi-Fi networks
US11496902B2 (en) 2017-09-29 2022-11-08 Plume Design, Inc. Access to Wi-Fi networks via two-step and two-party control
CN111404666A (zh) * 2019-01-02 2020-07-10 中国移动通信有限公司研究院 一种密钥生成方法、终端设备及网络设备

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6151677A (en) * 1998-10-06 2000-11-21 L-3 Communications Corporation Programmable telecommunications security module for key encryption adaptable for tokenless use
US6304658B1 (en) * 1998-01-02 2001-10-16 Cryptography Research, Inc. Leak-resistant cryptographic method and apparatus
EP1178644A2 (fr) * 2000-02-11 2002-02-06 Nokia Inc. Procédés de gestion de clé pour réseaux locaux sans fil

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP0966813A2 (fr) * 1997-03-10 1999-12-29 Guy L. Fielder Systeme et procede bilateraux d'authentification et de chiffrage
FI113119B (fi) * 1997-09-15 2004-02-27 Nokia Corp Menetelmä tietoliikenneverkkojen lähetysten turvaamiseksi
JP2002077129A (ja) * 2000-08-24 2002-03-15 Nissin Electric Co Ltd 暗号通信方法
KR20050116821A (ko) * 2003-03-14 2005-12-13 톰슨 라이센싱 보안 리키잉과 로그 오프를 이용한 wlan 세션 관리기술

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6304658B1 (en) * 1998-01-02 2001-10-16 Cryptography Research, Inc. Leak-resistant cryptographic method and apparatus
US6151677A (en) * 1998-10-06 2000-11-21 L-3 Communications Corporation Programmable telecommunications security module for key encryption adaptable for tokenless use
EP1178644A2 (fr) * 2000-02-11 2002-02-06 Nokia Inc. Procédés de gestion de clé pour réseaux locaux sans fil

Also Published As

Publication number Publication date
EP1606899A4 (fr) 2011-11-02
JP2006520571A (ja) 2006-09-07
CN1874222A (zh) 2006-12-06
WO2004084458A2 (fr) 2004-09-30
MXPA05009804A (es) 2006-05-19
JP2006180561A (ja) 2006-07-06
KR20060053003A (ko) 2006-05-19
MY135833A (en) 2008-07-31
KR20050116821A (ko) 2005-12-13
CN1759550A (zh) 2006-04-12
EP1606899A2 (fr) 2005-12-21

Similar Documents

Publication Publication Date Title
WO2004084458A3 (fr) Techniques de gestion de session wlan avec rechriffrement securise et fermeture de session
WO2005006629A3 (fr) Authentification de terminal dans un reseau sans fil
WO2009048574A3 (fr) Communication sans fil sécurisée
PL354839A1 (en) Method and apparatus for initializing secure communications among, and for exclusively pairing wireless devices
WO2005067685A3 (fr) Activation de secrets prepartages bases sur un serveur sans etat
MY142729A (en) Bootstrapping authentication using distinguished random challenges
WO2003032126A3 (fr) Systeme d'authentification multifactorielle
WO2004034213A3 (fr) Securite et authentification reseau localise a l'aide de cles inviolables
WO2007040664A3 (fr) Chiffrement partage de cles au moyen de sequences de cles longues
WO2005052754A3 (fr) Dispositifs d'accès réseau sécurisé à chiffrement de données
WO2002093824A3 (fr) Procede d'authentification
WO2006119184A3 (fr) Protection de mots de passe a utilisation unique contre des attaques par tiers interpose
WO2009026049A3 (fr) Appareil et procédé pour authentifier un dispositif réseau
WO2014083335A3 (fr) Procédé et système d'authentification d'accès utilisateur d'une ressource informatique par l'intermédiaire d'un dispositif mobile, qui utilisent de multiples facteurs de sécurité séparés
WO2004051964A3 (fr) Protocole d'authentification tunnellise empechant les attaques de l'intermediaire cache
WO2005114897A3 (fr) Authentification prealable de clients mobiles par partage d'une cle maitresse entre des authentificateurs securises
WO2005043281A3 (fr) Procede, appareil et programme destines a etablir une voie de communication chiffree entre appareils
WO2010025280A3 (fr) Protection d'intégrité et/ou chiffrement pour l'inscription d'un équipement utilisateur auprès d'un réseau sans fil
WO2004091176A3 (fr) Chiffrement entre un reseau cdma et un reseau gsm
WO2016144257A3 (fr) Procédé et système permettant de faciliter une authentification
TW200719662A (en) Login method for establishing a wireless local area network connection with a keeping-secret function and its system thereof
CA2579272A1 (fr) Procede et appareil permettant la generation d'une cle pseudo-secrete afin de generer une reponse a une demande d'acces provenant d'un fournisseur de service
JP2006180561A5 (fr)
WO2005029213A3 (fr) Procede et systeme permettant la gestion sans fil du fonctionnement d'un appareil de reseau sur une distance limitee
WO2008031926A3 (fr) Authentification de station mobile

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A2

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW

AL Designated countries for regional patents

Kind code of ref document: A2

Designated state(s): BW GH GM KE LS MW MZ SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LU MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
WWE Wipo information: entry into national phase

Ref document number: 20048063151

Country of ref document: CN

WWE Wipo information: entry into national phase

Ref document number: 2006507069

Country of ref document: JP

WWE Wipo information: entry into national phase

Ref document number: PA/a/2005/009804

Country of ref document: MX

Ref document number: 1020057017159

Country of ref document: KR

ENP Entry into the national phase

Ref document number: 2006179305

Country of ref document: US

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 10549408

Country of ref document: US

WWE Wipo information: entry into national phase

Ref document number: 2004719770

Country of ref document: EP

WWP Wipo information: published in national office

Ref document number: 1020057017159

Country of ref document: KR

WWP Wipo information: published in national office

Ref document number: 2004719770

Country of ref document: EP

DPEN Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed from 20040101)
WWP Wipo information: published in national office

Ref document number: 10549408

Country of ref document: US