CN1444362A

Distribution method of wireless local area network encrypted keys

Abstract

A method for distributing RAM cipher cryptographic key is the combined the distribution process of cryplographic key and mobile terminal certification to manage the cryptographic key distribution by certification server or wireless network gate, so, mobile terminal user can pan areas surpassing the cryptographic key management server. Since distribution of cryptographic key does not relate to thetransferred uncipher cryptographic keys in airborne interface, its safety is secured. The distribution method does not rely on specified certification way, it can be realized under different cerlification protocols and AP structure is simplified, since AP does not need to manage the user information.

Term

Term ended

Projected expiry passed 8 March 2022, 4.5 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

24 claims: 8 independent, 16 dependent

  1. 1
    The distributing method of wireless 1.1 encryption keys, wherein the wireless comprises an an (AP) and multiple unit for identity information the mobile terminal, the mobile terminal through a wireless channel and AND communication, AND a on the authentication device is of authentication and outer network and a terminal authentication, wherein the authentication memory device with the mobile terminals' identity information, the is characterised of the method comprises the following steps:(1) Mobile terminal comprises a authentication request of identity information to support according to the authentication device transmission and identity authentication to;a(2) Is identity information in the authentication device authentication to a request and authentication a mobile terminal, and authentication failure, ride-through AND a mobile terminal transmission rejection message access;And authentication successfully, and authentication device to the transmission AND a key related information M1, and containing licence the accessing broadcast message to the mobile terminal by transmission AND the information;and information comprises a key related information G/sq.m;and flowing encryption processing;(3) AP according to authenticating device for acquiring transmission the key in the key related information M1, the mobile terminal according to authenticating device for obtaining key wherein the transmission message AND a. 1.一种无线局域网加密密钥的分发方法,所述无线局域网包含一接入站(AP)和若干存储自身标识信息的移动终端,移动终端通过无线信道与AP通信,AP与外部网络和对移动终端身份进行认证的认证装置连接,所述认证装置存储有各移动终端的标识信息,其特征在于所述方法包含如下步骤:(1)移动终端向认证装置发送包含标识信息的认证请求以请求对其进行身份认证;(2)认证装置根据认证请求中包含的标识信息对移动终端进行认证,如果认证失败,则经AP向移动终端发送拒绝接入消息;如果认证成功,则认证装置向AP发送与密钥有关的信息M1,并且经AP向该移动终端发送包含允许接入通知信息的消息,如果该消息包含与密钥有关的信息M2,则必须经过加密处理;(3)AP根据认证装置向其发送的与密钥有关的信息M1获得密钥,移动终端根据认证装置经AP向其发送的消息获得密钥。
  2. 6
    The distribution method of wireless encryption key according to any claim any one of claims for is characterised is received is set with the data of key encrypting mobile terminal is a regular AP or non-periodically by comprising the following steps of updating key:(a1) AP with a random number and using any key generation algorithm from the generation of any of novel key;(b1) AP arranged on the conversion key informing to transmit to form of a mobile terminal,(c1) of the mobile terminal receiving to form the key informs, according to any number of the conversion key informing, comprising a use and step (a) and same key generation algorithm to generate the new key;(d1) of the mobile terminal to acquire output end of the encryption and a transmission AND a data AND a new key, mobile terminal and encryption engages the encryption to symbol and phase encryption mark the value configuration of a data packet is replaced by the communication key;Power and (e1) AP receiving data packet for mobile terminal, transmitting according to the value of encrypted mark as a live the key. 6.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于自AP接收到移动终端发送的用密钥加密的数据分组起定期或不定期地以包含如下步骤的方式更新密钥:(a1)AP产生一个随机数并利用任一密钥生成算法从该随机数生成新密钥;(b1)AP将该随机数放入改变密钥通知一起发送给移动终端;(c1)当移动终端收到改变密钥通知后,根据改变密钥通知中包含的随机数,利用与步骤(a)中所述相同的密钥生成算法产生新密钥;(d1)移动终端用新密钥对发送至AP的数据分组进行加密并向AP发送,在加密时移动终端在数据分组内加入加密标识并改变加密标识的数值以表示已经更换通信密钥;以及(e1)AP接收到移动终端发送的数据分组后,根据其中的加密标识的数值决定是否更换密钥。
  3. 7
    The distribution method of wireless encryption key according to any claim any one of claims a characterised is made from AND received is set with the data of key encrypting mobile terminal is rectangular or non-periodically by comprising the following steps of updating communication key to achieve the coded communication the novel key:(a2) AP generating novel key and a key of new generation and encryption and current of the key of a random groove;the b2 (AP) encrypt when the key is mounted on the conversion key informing substrate-processing to form a mobile terminal,(c2) of the mobile terminal receiving to form the key informs, and key of a current is comprises a conversion key informing novel key, wherein obtaining novel key;(d2) of the mobile terminal to acquire output end of the encryption and a transmission AND a data AND a new key, mobile terminal and encryption engages the encryption to symbol and phase encryption mark the value configuration of a data packet is replaced by the communication key;Power and (e2) AP receiving data packet for mobile terminal, transmitting according to the value of encrypted mark as a live the key. 7.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于自AP接收到移动终端发送的用密钥加密的数据分组起定期或不定期地以包含如下步骤的方式更新通信密钥以完成新密钥下的加密通信:(a2)AP以任意方式生成新的密钥并用当前使用的密钥对新生成的密钥进行加密;(b2)AP将加密后的密钥放入改变密钥通知一起发送给移动终端;(c2)当移动终端收到改变密钥通知后,用当前使用的密钥解密包含在改变密钥通知中的新密钥从而获得新密钥;(d2)移动终端用新密钥对发送至AP的数据分组进行加密并向AP发送,在加密时移动终端在数据分组内加入加密标识并改变加密标识的数值以表示已经更换通信密钥;以及(e2)AP接收到移动终端发送的数据分组后,根据其中的加密标识的数值决定是否更换密钥。
  4. 8
    The distribution method of wireless encryption key according to any claim any one of claims for is characterised is received is set with the data of key encrypting mobile terminal is a regular AP or non-periodically by comprising the following steps of updating key:(a3) authentication device first with a random for using the key generation algorithm from the generation of any of novel key, then transmits the new key, AND further transmitting AND a random of the mobile terminal,(b3) AP after receiving the new structure to form the key informing to send a mobile terminal,(c3) of the mobile terminal receiving to the authenticate device for transmitting the conversion key of any number and AND transmission according informs, phone according to any of;the utilization and step (a) and same key generation algorithm to generate the new key;(d3) mobile terminal to acquire output end of the encryption and a transmission AND a data AND a new key, mobile terminal and encryption engages the encryption to symbol and phase encryption mark the value configuration of a data packet is replaced by the communication key;Power and (e3) AP receiving data packet for mobile terminal, transmitting according to the value of encrypted mark as a live the key. 8.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于自AP接收到移动终端发送的用密钥加密的数据分组起定期或不定期地以包含如下步骤的方式更新密钥:(a3)认证装置首先产生一个随机数以利用密钥生成算法从该随机数生成新密钥,然后将新密钥发送给AP而将随机数经AP发送给移动终端;(b3)AP在接收到新密钥之后将改变密钥通知发送给移动终端;(c3)当移动终端收到认证装置发送的随机数和AP发送的改变密钥通知后,根据随机数,利用与步骤(a)中所述相同的密钥生成算法产生新密钥;(d3)移动终端用新密钥对发送至AP的数据分组进行加密并向AP发送,在加密时移动终端在数据分组内加入加密标识并改变加密标识的数值以表示已经更换通信密钥;以及(e3)AP接收到移动终端发送的数据分组后,根据其中的加密标识的数值决定是否更换密钥。
  5. 9
    The distribution method of wireless encryption key to any one of claims a characterised is made from AND received is set with the data of key encrypting mobile terminal is rectangular or non-periodically by comprising the following steps of updating communication key to achieve the coded communication the novel key:(a4) authentication device of the new key and a key of new generation and encryption and current of the key of a random manner, comprising a new key is transmitted AND encrypt to the new key is transmitted by AND a mobile terminal,(b4) AP receiving the new key backward mobile terminal transmission conversion key;informing(c3) of the mobile terminal receiving to the authenticate device for transmitting the encryption key and switching key of AP of transmission informs, a key encryption and decryption key of a current, wherein obtaining novel key;() to the mobile terminal to acquire output end of the encryption and a transmission AND a data AND a new key, mobile terminal and encryption engages the encryption to symbol and phase encryption mark the value configuration of a data packet is replaced by the communication key;Power and (e4) AP receiving data packet for mobile terminal, transmitting according to the value of encrypted mark as a live the key. 9.如权利要求1-5任意一项所述的无线局域网加密密钥的分发方法,其特征在于自AP接收到移动终端发送的用密钥加密的数据分组起定期或不定期地以包含如下步骤的方式更新通信密钥以完成新密钥下的加密通信:(a4)认证装置以任意方式生成新的密钥并用当前使用的密钥对新生成的密钥进行加密,新密钥被发送给AP而加密后的新密钥经AP被发送给移动终端;(b4)AP接收到新密钥后向移动终端发送改变密钥通知;(c4)当移动终端收到认证装置发送的加密密钥和AP发送的改变密钥通知后,用当前使用的密钥解密加密密钥从而获得新密钥;(d4)移动终端用新密钥对发送至AP的数据分组进行加密并向AP发送,在加密时移动终端在数据分组内加入加密标识并改变加密标识的数值以表示已经更换通信密钥;以及(e4)AP接收到移动终端发送的数据分组后,根据其中的加密标识的数值决定是否更换密钥。
  6. 10
    The distribution method of wireless encryption key according to any claim any one of claims for is characterised of the authentication device for authentication server for external a network. 10.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于所述认证装置为外部网络内部设置的认证服务器。
  7. 15
    The distribution method of wireless encryption key according to any claim any one of claims for is characterised of the authentication device for wireless gateway for external network and AND connected. 15.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于所述认证装置为将外部网络与AP连接起来的无线网关。
  8. 20
    The distribution method of wireless encryption key according to any claim any one of claims for is characterised of the authentication device comprises a authentication server for wireless gateway and are arranged network. 20.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于所述认证装置包括无线网关和外部网络内部设置的认证服务器。