Distribution method of wireless local area network encrypted keys
Abstract
A method for distributing RAM cipher cryptographic key is the combined the distribution process of cryplographic key and mobile terminal certification to manage the cryptographic key distribution by certification server or wireless network gate, so, mobile terminal user can pan areas surpassing the cryptographic key management server. Since distribution of cryptographic key does not relate to thetransferred uncipher cryptographic keys in airborne interface, its safety is secured. The distribution method does not rely on specified certification way, it can be realized under different cerlification protocols and AP structure is simplified, since AP does not need to manage the user information.
Term
Term ended
Projected expiry passed 8 March 2022, 4.5 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
24 claims: 8 independent, 16 dependent
- 1The distributing method of wireless 1.1 encryption keys, wherein the wireless comprises an an (AP) and multiple unit for identity information the mobile terminal, the mobile terminal through a wireless channel and AND communication, AND a on the authentication device is of authentication and outer network and a terminal authentication, wherein the authentication memory device with the mobile terminals' identity information, the is characterised of the method comprises the following steps:(1) Mobile terminal comprises a authentication request of identity information to support according to the authentication device transmission and identity authentication to;a(2) Is identity information in the authentication device authentication to a request and authentication a mobile terminal, and authentication failure, ride-through AND a mobile terminal transmission rejection message access;And authentication successfully, and authentication device to the transmission AND a key related information M1, and containing licence the accessing broadcast message to the mobile terminal by transmission AND the information;and information comprises a key related information G/sq.m;and flowing encryption processing;(3) AP according to authenticating device for acquiring transmission the key in the key related information M1, the mobile terminal according to authenticating device for obtaining key wherein the transmission message AND a. 1.一种无线局域网加密密钥的分发方法,所述无线局域网包含一接入站(AP)和若干存储自身标识信息的移动终端,移动终端通过无线信道与AP通信,AP与外部网络和对移动终端身份进行认证的认证装置连接,所述认证装置存储有各移动终端的标识信息,其特征在于所述方法包含如下步骤:(1)移动终端向认证装置发送包含标识信息的认证请求以请求对其进行身份认证;(2)认证装置根据认证请求中包含的标识信息对移动终端进行认证,如果认证失败,则经AP向移动终端发送拒绝接入消息;如果认证成功,则认证装置向AP发送与密钥有关的信息M1,并且经AP向该移动终端发送包含允许接入通知信息的消息,如果该消息包含与密钥有关的信息M2,则必须经过加密处理;(3)AP根据认证装置向其发送的与密钥有关的信息M1获得密钥,移动终端根据认证装置经AP向其发送的消息获得密钥。
- 6The distribution method of wireless encryption key according to any claim any one of claims for is characterised is received is set with the data of key encrypting mobile terminal is a regular AP or non-periodically by comprising the following steps of updating key:(a1) AP with a random number and using any key generation algorithm from the generation of any of novel key;(b1) AP arranged on the conversion key informing to transmit to form of a mobile terminal,(c1) of the mobile terminal receiving to form the key informs, according to any number of the conversion key informing, comprising a use and step (a) and same key generation algorithm to generate the new key;(d1) of the mobile terminal to acquire output end of the encryption and a transmission AND a data AND a new key, mobile terminal and encryption engages the encryption to symbol and phase encryption mark the value configuration of a data packet is replaced by the communication key;Power and (e1) AP receiving data packet for mobile terminal, transmitting according to the value of encrypted mark as a live the key. 6.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于自AP接收到移动终端发送的用密钥加密的数据分组起定期或不定期地以包含如下步骤的方式更新密钥:(a1)AP产生一个随机数并利用任一密钥生成算法从该随机数生成新密钥;(b1)AP将该随机数放入改变密钥通知一起发送给移动终端;(c1)当移动终端收到改变密钥通知后,根据改变密钥通知中包含的随机数,利用与步骤(a)中所述相同的密钥生成算法产生新密钥;(d1)移动终端用新密钥对发送至AP的数据分组进行加密并向AP发送,在加密时移动终端在数据分组内加入加密标识并改变加密标识的数值以表示已经更换通信密钥;以及(e1)AP接收到移动终端发送的数据分组后,根据其中的加密标识的数值决定是否更换密钥。
- 7The distribution method of wireless encryption key according to any claim any one of claims a characterised is made from AND received is set with the data of key encrypting mobile terminal is rectangular or non-periodically by comprising the following steps of updating communication key to achieve the coded communication the novel key:(a2) AP generating novel key and a key of new generation and encryption and current of the key of a random groove;the b2 (AP) encrypt when the key is mounted on the conversion key informing substrate-processing to form a mobile terminal,(c2) of the mobile terminal receiving to form the key informs, and key of a current is comprises a conversion key informing novel key, wherein obtaining novel key;(d2) of the mobile terminal to acquire output end of the encryption and a transmission AND a data AND a new key, mobile terminal and encryption engages the encryption to symbol and phase encryption mark the value configuration of a data packet is replaced by the communication key;Power and (e2) AP receiving data packet for mobile terminal, transmitting according to the value of encrypted mark as a live the key. 7.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于自AP接收到移动终端发送的用密钥加密的数据分组起定期或不定期地以包含如下步骤的方式更新通信密钥以完成新密钥下的加密通信:(a2)AP以任意方式生成新的密钥并用当前使用的密钥对新生成的密钥进行加密;(b2)AP将加密后的密钥放入改变密钥通知一起发送给移动终端;(c2)当移动终端收到改变密钥通知后,用当前使用的密钥解密包含在改变密钥通知中的新密钥从而获得新密钥;(d2)移动终端用新密钥对发送至AP的数据分组进行加密并向AP发送,在加密时移动终端在数据分组内加入加密标识并改变加密标识的数值以表示已经更换通信密钥;以及(e2)AP接收到移动终端发送的数据分组后,根据其中的加密标识的数值决定是否更换密钥。
- 8The distribution method of wireless encryption key according to any claim any one of claims for is characterised is received is set with the data of key encrypting mobile terminal is a regular AP or non-periodically by comprising the following steps of updating key:(a3) authentication device first with a random for using the key generation algorithm from the generation of any of novel key, then transmits the new key, AND further transmitting AND a random of the mobile terminal,(b3) AP after receiving the new structure to form the key informing to send a mobile terminal,(c3) of the mobile terminal receiving to the authenticate device for transmitting the conversion key of any number and AND transmission according informs, phone according to any of;the utilization and step (a) and same key generation algorithm to generate the new key;(d3) mobile terminal to acquire output end of the encryption and a transmission AND a data AND a new key, mobile terminal and encryption engages the encryption to symbol and phase encryption mark the value configuration of a data packet is replaced by the communication key;Power and (e3) AP receiving data packet for mobile terminal, transmitting according to the value of encrypted mark as a live the key. 8.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于自AP接收到移动终端发送的用密钥加密的数据分组起定期或不定期地以包含如下步骤的方式更新密钥:(a3)认证装置首先产生一个随机数以利用密钥生成算法从该随机数生成新密钥,然后将新密钥发送给AP而将随机数经AP发送给移动终端;(b3)AP在接收到新密钥之后将改变密钥通知发送给移动终端;(c3)当移动终端收到认证装置发送的随机数和AP发送的改变密钥通知后,根据随机数,利用与步骤(a)中所述相同的密钥生成算法产生新密钥;(d3)移动终端用新密钥对发送至AP的数据分组进行加密并向AP发送,在加密时移动终端在数据分组内加入加密标识并改变加密标识的数值以表示已经更换通信密钥;以及(e3)AP接收到移动终端发送的数据分组后,根据其中的加密标识的数值决定是否更换密钥。
- 9The distribution method of wireless encryption key to any one of claims a characterised is made from AND received is set with the data of key encrypting mobile terminal is rectangular or non-periodically by comprising the following steps of updating communication key to achieve the coded communication the novel key:(a4) authentication device of the new key and a key of new generation and encryption and current of the key of a random manner, comprising a new key is transmitted AND encrypt to the new key is transmitted by AND a mobile terminal,(b4) AP receiving the new key backward mobile terminal transmission conversion key;informing(c3) of the mobile terminal receiving to the authenticate device for transmitting the encryption key and switching key of AP of transmission informs, a key encryption and decryption key of a current, wherein obtaining novel key;() to the mobile terminal to acquire output end of the encryption and a transmission AND a data AND a new key, mobile terminal and encryption engages the encryption to symbol and phase encryption mark the value configuration of a data packet is replaced by the communication key;Power and (e4) AP receiving data packet for mobile terminal, transmitting according to the value of encrypted mark as a live the key. 9.如权利要求1-5任意一项所述的无线局域网加密密钥的分发方法,其特征在于自AP接收到移动终端发送的用密钥加密的数据分组起定期或不定期地以包含如下步骤的方式更新通信密钥以完成新密钥下的加密通信:(a4)认证装置以任意方式生成新的密钥并用当前使用的密钥对新生成的密钥进行加密,新密钥被发送给AP而加密后的新密钥经AP被发送给移动终端;(b4)AP接收到新密钥后向移动终端发送改变密钥通知;(c4)当移动终端收到认证装置发送的加密密钥和AP发送的改变密钥通知后,用当前使用的密钥解密加密密钥从而获得新密钥;(d4)移动终端用新密钥对发送至AP的数据分组进行加密并向AP发送,在加密时移动终端在数据分组内加入加密标识并改变加密标识的数值以表示已经更换通信密钥;以及(e4)AP接收到移动终端发送的数据分组后,根据其中的加密标识的数值决定是否更换密钥。
- 10The distribution method of wireless encryption key according to any claim any one of claims for is characterised of the authentication device for authentication server for external a network. 10.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于所述认证装置为外部网络内部设置的认证服务器。
- 15The distribution method of wireless encryption key according to any claim any one of claims for is characterised of the authentication device for wireless gateway for external network and AND connected. 15.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于所述认证装置为将外部网络与AP连接起来的无线网关。
- 20The distribution method of wireless encryption key according to any claim any one of claims for is characterised of the authentication device comprises a authentication server for wireless gateway and are arranged network. 20.如权利要求1-5中任意一项所述的无线局域网加密密钥的分发方法,其特征在于所述认证装置包括无线网关和外部网络内部设置的认证服务器。
Independent claims8
33 paragraphs, as filed
The distributing method of wireless encryption key
The invention wherein the invention relates to wireless communication connected between an (AP) and mobile terminal, referring to the distribution method for encrypting key special.
background technology
Wireless with the aid of wireless channel data transmission unit, and video signals. To the traditional wiring network, wireless with which is convenient; and is flexible, economy saving with a easy and other merits, wherein is attached to importance antenna of antenna.
Wireless local area network and area of called service area, generally is divided into primary service area (BasicService Area, the following of called BSA) and an service area (Of Service Area, the following of called ESA), the BSA shape of the units' the wireless transceiver and a geographic environments determining the communication cover area of the wireless local area network, normally of called cell (cell), a range is generally; aA command to the wireless local area network cover area, usually using the method according shown and a digital 1, wherein the is connected with the Access Point; the following of called AND) is usually wired local area network) is BSA and backbone network by the wireless gateway, so mobile terminal MH multiple BSA and wireless gateway and a backbone network connection via AP, wherein a telescopic service area.
Compares the transmission line, the wireless transmission's secrecy is sides; therefore ensuring consistency between datum to the cell safety communication between AND and mobile terminal, the information flowing through the key encryption and sending. The mobile terminal cross-region mobile or heating starting, the first searching for cell according oneself, a register to the cell, AND and obtaining the cell related information, therefore comprising a layer is printed with the coded of communication AND. Specifically talk-back, which is of mobile terminal MH12 from the cell 1 and cell 2:00; and AP11 and AP21 and covering area of the key management server, and coded communication of mobile terminal MH12 and AP11 can be not affected with a coded communication AP21 of the smooth transition to wherein, and a AP11 and AP21 belong to different key management server, wherein AP21 is to learn the mobile terminal MH12 communication key, therefore is of 2 to realize the coded communication of mobile terminal MH12 and AP21 the cell by. And a transmitting key of the non-encryption method via the wireless channel of mobile terminal MH12 to AP21 realizing coded communication, wherein the key is intercepted easily and can the code, therefore the system is very high safety danger.
And seen above; and when the existing technology for distributing method of encrypted key and mobile terminal cross-region roaming the coded communication is restricted the shortcoming.
invention content
In aggregate of the ACK/NAK, the invention claims a distribution method for wireless novel encryption key.
The invention claims a distribution method of wireless encryption key, wherein the wireless comprises a an (AP) and multiple for saving identity information the mobile terminal, the mobile terminal through a wireless channel and AND communication, AND and authentication device is of authentication and outer network and a terminal authentication, wherein the authentication memory device with the mobile terminals' identity information, wherein the method comprises the following steps: (1) Mobile terminal comprises a authentication request of identity information to support according to the authentication device transmission and identity authentication to; a(2) Is identity information in the authentication device authentication to a request and authentication a mobile terminal, and authentication failure, ride-through AND a mobile terminal transmission rejection message access; And authentication successfully, and authentication device to the transmission AND a key related information M1, and containing licence the accessing broadcast message to the mobile terminal by transmission AND the information; and information comprises a key related information G/sq.m; and flowing encryption processing; (3) AP according to authenticating device for acquiring transmission the key in the key related information M1, the mobile terminal according to authenticating device for obtaining key wherein the transmission message AND a.
And seen, wherein the invention the communication method using the key distribution the certification process for producing and mobile terminal key of hanging, for managing to the key distribution of the authentication device, therefore, the user terminal capable is greater than the key management server covering area cross-region roaming. Wherein the distribution of key without involve through the key in the containing a connector is not encrypted, therefore with assured the key safety. In addition, the key distributing method without rely on the authentication method for fixing Jyriki, wherein capable of the lower wireless protocol. Finally, wherein AND no need to manage the user information, simplified AND the structure, wherein reduced the charging.
Brief description for drawings
By the following connecting figure attached to the description of this invention embodiment, and further understand the invention merits the characteristic, and: Digital 1 is a wireless of the schematic drawing of AP and wireless gateway and a backbone network connection,Image edge is a defer to the invention embodiment wireless for encrypting communication method schematic drawing; Image 2b according to defer to the invention In one embodiment wireless for encrypting communication method schematic drawing; Image 2c according to defer to the invention In one embodiment wireless for encrypting communication method schematic drawing; The position is a defer to the invention In one embodiment wireless for encrypting communication method schematic drawing; Image 3a in wireless of the process of dynamic consultative key; Image 3b in wireless of the process of dynamic consultative key; Image 3c in wireless of the process of dynamic consultative key; 3d Image in of wireless of the process of dynamic consultative key; And
detailed description of illustrated embodiments
The following a first supporting a digital 1, image 2a-2d description the distribution method for encrypting key according to the invention embodiment wireless.
Shown and a digital 1, 1~3 cell comprises a an AP11, AP21 and AP31 and multiple mobile terminal MH12~MH33; each mobile terminal saving with symbol wherein the working state information I and information P, the mobile terminal through wireless channel and a a communication AND a cell, AND the wireless gateway 51-53 with the wired network backbone 4), a authentication server on backbone network (is not drawn) while the plots the state information of the mobile terminals' I and information P, the authentication server is a straight to save each terminal identity information from the external equipment I and user list of the P-TYPE information, Therefore of a memory wherein the state information IN pairs of any user terminal state according or a user list providing realizes the data. Made of chip layer, a mobile terminal state information I and information of P-TYPE is a wireless gateway 51-53 memory or a management, capable of a wireless gateway from to the terminal user identity authentication function. Additionally, further - realizing and authentication server and wireless gateway with a terminal user identity authentication function. , And a a a provide the field, and user terminal the manner of identity authentication function of the male knowledge is provided with multiple, and authentication server and/or a wireless network is only multiple manner, for indicating hole, the following fixed with a user terminal state to confirm of functions device of called to authenticate device.
The edge position mobile of terminal MH12 1 to flow cell 2 him corresponding to from the cell uses the first time distribution method and coded communication process of pressing and AP21.
Mobile terminal MH12 first a initial connected with AP21 51, comprising a authentication request of identity information to support according to the backbone network 4 in authentication server transmission of AP21 and wireless gateway and authentication to a. Authentication server after receiving authentication request, second and authentication according to the state information IN pair of mobile terminal state of the authentication request, comprising a discovered state information of a I with a memory without having; and output user terminal is a illegal user, the authentication request invalid, therefore 51 and AP21 rejected the access message to the mobile terminal MH11 transmission from the wireless gateway. A discovered state information of authentication request) comprises a matching shell of the memory, and output user terminal is a validated user, the authentication request effectively, therefore to edge position of the P-TYPE information of identity information IN search mobile communication terminal MH12 the information P-TYPE for authentication server to) and a search 51 transmitted to the wireless gateway to AP21. The P-TYPE information according AP21 after receiving the authentication server is transmitted to the data to the receiving information the P-TYPE data message to the authentication server through a wireless gateway and automatically according to the key generation algorithm of the information the P-TYPE key generation. The key generation algorithm can be a random the algorithm, and length of button is any. The data information of the authentication server for receiving AP21 for plugged the wireless gateway 51 and AP21 is an access report to the mobile terminal MH21 transmission. When the mobile terminal MH21 receiving is access reporting, according to AP21 with key generation when the same algorithm used, from which the information the P-TYPE production keys of memory is the key to acquire output end of the encryption and a AP21 transmission to a AP21 data, mobile terminal MH21 to the data output end of the encryption a data packet is related encryption mark. AP21 after receiving data packet of mobile terminal MH21 transmission, the first encryption mark is a data packets, and detecting to encryption mark, which uses according to the key generation algorithm of the key according the P-TYPE information obtaining for data packet and wireless gateway 51 repeaters to the external network 4, otherwise 51 retransmits of the gateway wireless data packet by the external 4 network.
Image 2b according to defer to the invention In one embodiment wireless for encrypting communication method schematic drawing. The embodiment and image edge as the difference of embodiment to bottom; and way of communication, the keys are used to key generation algorithm generating and after the key encrypts transmitting with the information of P-TYPE AP21 of mobile terminal MH21. Key of mobile terminal MH21 after receiving AP21 transmitting; and decryption to the key in which the memory information P; and key is a to acquire the data AND output end of the encryption and a AND transmission, the mobile terminal is a data output end of the encryption a data packet is further lapping encryption mark. The case; each mobile terminal respectively no need the key generation algorithm of knows AP21 is.
Image 2c according to defer to the invention In one embodiment wireless for encrypting communication method schematic drawing. The embodiment and image edge as the difference of embodiment to bottom; and authentication is successful, authentication server and according to the key generation algorithm of the search to the information the P-TYPE production key is AP21, and it does not sending information the P-TYPE to AP21 supply wherein key generation.
The position is a defer to the invention In one embodiment wireless for encrypting communication method schematic drawing. The embodiment and image 2c as the difference of embodiment to bottom; and authentication is successful, authentication server and according to the key generation algorithm for key and electrically connected with AP21; at the same time authentication server is the mobile terminal MH21 transmission of key of the P-TYPE information encryption.
Made of chip embedding part; the backbone network 4 in a comprises multiple authentication servers; a connecting them mobile terminal identity information according with multiple communication protocol Enhanced Clearing Switching saving, therefore of the further expansion service area.
The embodiment, and user terminal status's authentication function 51-53 is implemented as a wireless gateway cable, the functions according and authentication server and realizes is realized by the wireless gateway, a invention can 51-53 licence the access informing to the mobile terminal MH21 transmission a wireless gateway, generating key and a AP21 transmission the information P-TYPE equal. Similar, a confirmed by the function is implemented as a authentication server and wireless gateway with, the functions according and authentication server realizes capable of a authentication server and wireless with gateway. The brief; the alarm function for and authentication server and capable of authenticating the device for realizing.
The wireless local area network is in coded communication method, and further enhance security system, communication between key AND and mobile terminal capable is a regular or non-periodical dynamic updating. The invention claims a plurality of handling of the lower dynamic consultative key on the aid of image 3a-3d.
Image 3a, as to be a key, a first with a random of a AP, and using any key generation algorithm from the generation of any number key, AND arranged on the conversion key informing to transmit to the is then to the mobile terminal. The mobile terminal receiving to form the key informs, according to any number of the conversion key comprises informing, using the same key generation algorithm to generate a key, wherein then to acquire output end of the encryption and a transmission AND a data AND when the key, a mobile terminal with a data output end of the encryption a data packet is related for encrypting to symbol and phase encryption mark the value configuration with replaced the key communication.
Image 3b of the process of the dynamic consultative key, a position, 3b to be a key, a first state the new key a any one of AP, AND then and encryption of the key of new generation with a current key and a encrypt the key is mounted on the conversion key informing to send a to the mobile terminal. The mobile terminal receiving to form the key informs, a current a key comprises a conversion key informing the new key, wherein then to acquire output end of the encryption and a transmission AND a data AND when with the novel key, a mobile terminal with a data output end of the encryption a data packet is related for encrypting to symbol and phase encryption mark the value configuration with replaced the key communication.
Image 3c of the process of the dynamic consultative key, a position, 3c to be a key, a first authenticating device is a random number, and using any key generation algorithm from the generation of any number key, a authenticated device for sending the number of the then key for mobile terminal and will generate substrate-processing AND. Power AND receiving to authenticate the key for transmitting device, a mobile terminal transmission conversion key informing. The mobile terminal receiving conversion key informing and are arranged, and same key generation algorithm to generate a key, wherein then to acquire output end of the encryption and a transmission AND a data AND when the key, a mobile terminal with a data output end of the encryption a data packet is related for encrypting to symbol and phase encryption mark the value configuration with replaced the key communication.
3d Image a of process of the dynamic consultative key, a position, a to be a key, a first authenticating the state the new key of random manner, then authenticated the device to transmit the key AND and after the key of new generation disposed on the encryption transmitting with a current key the mobile terminal. AND is receiving to authenticate un-encryption key backward mobile terminal transmission conversion key informing for transmitting device. The mobile terminal receives the key of switching key informing and encryption, wherein when with a current key encryption and decryption key of obtaining the new key, then to acquire output end of the encryption and a transmission AND a data AND and novel key, a mobile terminal with a data output end of the encryption a data packet is related for encrypting to symbol and phase encryption mark the value configuration with replaced the key communication.
The upper dynamic consultative key processing, and AND a issuing conversion key informing, discovered a data packet of the mobile terminal transmits the value of encrypted mark is not made of changing, then transmits the new key of switching key informing and any of encrypted or more once, begins by the novel key end of the corresponding is a mobile terminal.
And seen, wherein the key distributing method without involve the wireless local area network is as a particular model of management, authentication and managing mobility management, capable of the lower wireless local area network protocol system configured of, comprising PPPoE and IEEE 802.1x protocol. To it further understand the base, and volume the invention, the following with the IEEE 802.1x protocol and invention claims a hash key distributing method of dynamically switching path specifically.
IEEE 802.1x is a common for wireless local area network protocol system, involved MAC layer and physical layer Biao Standard, and data AND and mobile terminal groups to the RECEIVED frame and unit, 4 shape as the type MAC frame structure. IEEE 802.1x protocol message mainly comprising EAP_START, EAP_LOGOOF, EAP_REQUEST, EAP_RESPONSE, EAP_SUCCESS, EAP_FAIL and EAP_KEY; the texts for special MAC frame, and RECEIVED frame type domain to receive Biao Quantum.
When the mobile terminal and initial AND connected; the first mobile terminal for transferring message EAP_START to AP, AND is receiving the backward mobile terminal to transmit the EAP_REQUEST/IDENTITY message, the other user input user server and password. User input user server and password, mobile terminal sealed them in EAP_RESPONSE/IDENTITY message and returning to powering AND. AND the Access_Request message transmitting user server and a cryptographic information is a user providing a authentication server, AND and communication between the identity servers follows the Radius protocol. The authentication server first verifying the user server and a password distribution, and is matched; and charging authentication failure and is the Accept-Reject message AND loop. The receiving AND transmitting; the EAP_FAIL message to electrically connected with the mobile terminal, rejects the mobile terminal access. And authentication successfully, and authentication server for transferring message Access_Accept, simultaneously same corresponding user information P-TYPE the text's data field. The receiving AND the information; and key distributing method of which is shaft according to all key generation and algorithm for transferring message EAP_SUCCESS is electrically connected with the mobile terminal from the second P-TYPE information generation key, which can be support from the EAP_KEY message to send a key of information corresponding P-TYPE encryption production to the mobile terminal. , Mobile terminal capable shaft according to the same key generation algorithm from the corresponding information P-TYPE substrate or key in the key according oneself save the corresponding information P-TYPE a receiving. , And the mobile terminal key is time to encrypt and sending to MAC frame data to AP, simultaneously power encryption mark of MAC frame. Shown and a digital 4, the frame body area composed of IV domain, a data fields and ICV domain, wherein the Bits's 2 KeyID domain in IV receiving and synchronous code. Made of with good, wherein the RECEIVED frame is not encrypted, KeyID=0, while starting the communication coded; the conversion key, KeyID gain progressively each time 1, wherein KeyID=KeyID+1. A KeyID=3, wherein upgrades key once more KeyID reset is 1, which is not 0. Therefore when of the first time encrypting data RECEIVED, and KeyID=1 on MAC frame the mobile terminal by a. AND the receiving the KeyID=1 MAC frame, a determining mobile terminal with begun by the novel distribution the key, therefore for production of the key is a MAC data, and converting into the Ethernet format to the wireline network transmission. And AND a transmitting the EAP_KEY message, discovered of the mobile terminal uploaded the KeyID domain in MAC frame is located 0, which reissued the EAP_SUCCESS message or EAP_KEY.
For dynamic upgrading communication key, AND is made from a mobile terminal, regular (e.g. each other 10 minutes) or sending the EAP_KEY message non-periodically, inform the mobile terminal to use the key. The transmission EAP_KEY, a second comprises of random number or with novel structure of the key in the key current encrypts. Mobile terminal for receiving the message, and deciphers the new key from the generation of any of novel key or a current key on the same key generation method. , And the mobile terminal with the new key encrypting data RECEIVED, simultaneously with the KeyID value of KeyID=2. AND detecting uploaded MAC frame KeyID domain, a KeyID of invariable, and continuously is a current key is a MAC data, reissues of the EAP_KEY message. A KeyID exchange, which uses the new key is a MAC data.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN100366015C | Cited by | China | Search report |
| CN1331322C | Cited by | China | Search report |
| WO2011022963A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN100466805C | Cited by | China | Search report |
| CN100452697C | Cited by | China | Search report |
| CN108777843A | Cited by | China | Search report |
| CN102404132A | Cited by | China | Search report |
| WO2006024216A1 | Cited by | World Intellectual Property Organization (WIPO) | Search report |
| CN102244861A | Cited by | China | Search report |
| WO2009155812A1 | Cited by | World Intellectual Property Organization (WIPO) | Search report |
| CN112702776A | Cited by | China | Search report |
| WO2015123953A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN102202301A | Cited by | China | Search report |
| US10869250B2 | Cited by | United States of America | Applicant |
| CN102523199A | Cited by | China | Search report |
| WO2008043289A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
10 members in 7 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 02110974 | China | A | |
| CN2002110974 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| WO03077467A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003252824A1 | Australia | A1 | |
| CN1444362AThis record | China | A | |
| EP1484856A1 | European Patent Office (EPO) | A1 | |
| US2005226423A1 | United States of America | A1 | |
| CN1268093C | China | C | |
| EP1484856A4 | European Patent Office (EPO) | A4 | |
| AT411690T | Austria | T | |
| EP1484856B1 | European Patent Office (EPO) | B1 | |
| DE60324109D1 | Germany | D1 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 | |
| Entry into substantive examinationC10 | C10 |
Numbers
- Publication
- 1444362
- Publication, DOCDB
- 1444362
- Publication, EPODOC
- CN1444362
- Application
- 2110974
- Application, DOCDB
- 02110974
- Application, EPODOC
- CN2002110974
Titles2
- Chinese
- 无线局域网加密密钥的分发方法
- English
- Distribution method of wireless local area network encrypted keys
Classification
- CPC, 10
- H04L63/062
- H04L9/0891
- H04L63/08
- H04W8/26
- H04W12/04031
- H04W12/06
- H04W84/12
- H04W88/08
- H04W88/14
- H04W88/16
- IPC, 7
- H04L12 28
- H04L29 06
- H04W8 26
- H04W84 12
- H04W88 08
- H04W88 14
- H04W88 16