Broker-based interworking using hierarchical certificates
Abstract
A method for authentication, authorization and account management (AAA) in the interworking between at least two networks (210 and 220). The at least two networks can communicate with the mediator (230), and include a first network and a second network. The second network receives the mediator public key from the mediator, and receives the first network certificate for the user from the user device corresponding to the user of the first network. The first network certificate for the user is signed by the first network private key, and includes the mediator (230) certificate for the first network and the user public key. The certificate of the mediator (230) for the first network is signed by the mediator private key and includes the public key of the first network (210). When the second network (220) will use the intermediary (230) certificate for the first network (210) and the first network (230) for the user according to the public key of the intermediary (230) and the public key of the first network (210) respectively. 210) When the certificate is determined to be authentic, the session key is sent from the second network (220) to the user equipment. The user public key is used to encrypt the session key. The session key is used to enable the user equipment to access the second network.

Term
Term ended
Expired 27 May 2023, 3.3 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
14 claims: 4 independent, 10 dependent
- 1一种在具有交互工作功能的无线局域网与第二网络之间交互工作的方法,所述无线 局域网和第二网络能够与中介器通信,所述方法包括下列步骤: 从中介器接收第一密钥; 从用户设备接收对于用户的第二网络证书,它包括对于第二网络的中介器证书和第二 密钥; 使用第一密钥验证对于第二网络的中介器证书以得到第三密钥; 使用第三密钥来验证对于用户的第二网络证书以得到第二密钥; 产生会话密钥,使用第二密钥来加密所述会话密钥,并且向用户设备发送被加密的会 话密钥;以及 使用被加密的会话密钥来与用户设备通信。
- 2按照权利要求1的方法,其中对于用户的第二网络证书还包括用户预订级别,它指 示用户是否预订交互工作服务,并且响应于用户预订级别来执行产生步骤。
- 3按照权利要求1的方法,其中对于用户的第二网络证书还包括对于用户的第二网络 证书的期满时间,所述方法还包括:查看所述期满时间以确定对于用户的第二网络证书是 否已经过期。
- 4按照权利要求1的方法,还包括:产生使用第五密钥签字并且包括会话密钥的对于 用户的无线局域网证书,由此能够验证无线局域网。
- 5一种在具有交互工作功能的无线局域网与第二网络之间交互工作的方法,所述无线 局域网和第二网络能够与中介器通信,所述方法包括下列步骤: 从中介器接收中介器公共密钥; 从用户设备接收对于用户的第二网络证书,它使用第二网络私有密钥被签字,并且包 括对于第二网络的中介器证书和用户公共密钥,所述对于第二网络的中介器证书以中介器 私有密钥被签字,并且包括第二网络公共密钥; 使用中介器公共密钥来验证对于第二网络的中介器证书,并且得到第二网络公共密 钥; 使用第二网络公共密钥来验证对于用户的第二网络证书,并且得到用户公共密钥; 产生会话密钥,使用用户公共密钥来加密所述会话密钥,并且向用户设备发送被加密 的会话密钥;以及 使用被加密的会话密钥来与用户设备通信。
- 6按照权利要求5的方法,其中对于用户的第二网络证书还包括用户的预订级别,它 指示用户是否预订交互工作服务,并且响应于预订级别来执行产生步骤。
- 7按照权利要求5的方法,其中对于用户的第二网络证书还包括对于用户的第二网络 证书的期满时间,所述方法还包括:查看所述期满时间以确定对于用户的第二网络证书是 否已经过期。 按照权利要求5的方法,还包括:向用户设备提供验证无线局域网的能力。 9.按照权利要求8的方法,其中提供步骤包括下列步骤: 接收对于无线局域网的中介器证书,它以中介器私有密钥被签字并且包括无线局域网 私有密钥; 产生对于用户的无线局域网证书,它以无线局域网私有密钥被签字,并且包括被加密 CN 1659558 Β 的会话密钥;和 发送对于用户的无线局域网证书。
- 810. 一种使用具有对第二网络的预订的用户设备与无线局域网通信的方法,所述第二 网络与所述无线局域网具有交互工作配置,所述无线局域网和第二网络能够与中介器通 信,所述方法包括下列步骤: 从第二网络接收对于用户的第二网络证书,它以第二网络私有密钥被签字,并且包括 对于网络的中介器证书和用户公共密钥; 向无线局域网发送对于用户设备的第二网络证书,其中无线局域网能够使用从中介器 接收的中介器公共密钥来得到用户公共密钥; 从无线局域网接收使用用户公共密钥加密的会话密钥; 使用用户私有密钥来解密所述会话密钥;以及 使用解密的会话密钥与无线局域网通信。
- 911. 按照权利要求10的方法,其中对于用户的第二网络证书还包括用户的预订级别, 它指示用户是否预订交互工作服务。
- 1012. 按照权利要求10的方法,其中对于用户的第二网络证书还包括对于用户的第二网 络证书的期满时间,如果期满时间还未过期则执行所述发送步骤。
- 1113. 按照权利要求10的方法,其中所述接收会话密钥的步骤包括接收以中介器私有密 钥签字并且包括会话密钥的对于用户的无线局域网证书,并且还包括:接收中介器公共密 钥,并且使用中介器公共密钥来验证对于用户的无线局域网证书和得到会话密钥。
- 1214. 一种在具有交互工作功能的无线局域网与第二网络之间交互工作的设备,所述无 线局域网和第二网络能够与中介器通信,该设备包括: 用于从中介器接收中介器公共密钥的部件; 用于从用户设备接收对于用户的第一网络证书的部件,所述第一网络证书使用第一网 络私有密钥被签字,并且包括对于第二网络的中介器证书和用户公共密钥,所述对于第二 网络的中介器证书以中介器私有密钥被签字,并且包括第二网络公共密钥; 用于使用中介器公共密钥来验证对于第二网络的中介器证书并且得到第二网络公共 密钥的部件; 用于使用第二网络公共密钥来验证对于用户的第二网络证书并且得到用户公共密钥 的部件; 用于产生会话密钥、使用用户公共密钥来加密所述会话密钥、以及向用户设备发送被 加密的会话密钥的部件;以及 用于使用被加密的会话密钥来与用户设备通信的部件。
- 1315. 按照权利要求14的设备,还包括: 用于接收对于无线局域网的中介器证书的部件,所述中介器证书以中介器私有密钥被 签字并且包括无线局域网私有密钥; 用于产生对于用户的无线局域网证书的部件,所述无线局域网证书以无线局域网私有 密钥被签字,并且包括被加密的会话密钥;和 用于发送对于用户的无线局域网证书的部件。
- 1416. 一种在具有交互工作功能的无线局域网与第二网络之间交互工作的设备,所述无 CN 1659558 Β 线局域网和第二网络能够与中介器通信,该设备包括: 用于从中介器接收第一密钥的部件; 用于从用户设备接收对于用户的第二网络证书的部件,所述对于用户的第二网络证书 包括对于第二网络的中介器证书和第二密钥; 用于使用第一密钥验证对于第二网络的中介器证书以得到第三密钥的部件; 用于使用第三密钥来验证对于用户的第二网络证书以得到第二密钥的部件; 用于产生会话密钥、使用第二密钥来加密所述会话密钥、以及向用户设备发送被加密 的会话密钥的部件;和 用于使用被加密的会话密钥来与用户设备通信的部件。 17.按照权利要求16的设备,其中所述第二网络是蜂窝网络。 CN 1659558 Β
Independent claims14
54 paragraphs in 2 sections, as filed
Intermediary-based interworking technology using hierarchical certificates
[0001] The present invention generally relates to interworking, and specifically to the authentication, authorization, and account management (AA) of interworking based on intermediary using hierarchical certificates.
Background technique
[0002] Generally, authentication, authorization, and account management (ΑΑΑ) are required to access and utilize networks, such as cellular networks and wireless local area networks (WLAN). In an environment where mobile terminals have multiple network access mechanisms, among these networks It is important to provide ΑΑΑ interactive work. However, it is generally the case that the involved networks do not belong to the same administrative domain and do not share the same AAA scheme. Moreover, it is difficult for cellular operators to establish a contractual relationship with each wireless LAN operator, and vice versa. Moreover, mobile users who have signed up for interworking should not be aware of any third parties involved in the interworking, that is, they only need to maintain a single account, that is, their own cellular account.
[0003] There are two main types of interworking between cellular networks and WLANs: tightly coupled and loosely coupled. In the case of loose coupling, WLAN and cellular network have independent data paths, but AAA for WLAN users relies on the cellular network AAA function. However, the cellular network AAA protocol (MAP/SS7) is not compatible with the Internet Protocol (IP)-based protocol used by WLAN users.
[0004] In order to solve the problem of networks that do not belong to the same administrative domain and do not share the same AAA scheme, special interworking functions or gateways have been proposed to bridge the cellular network and the WLAN AAA scheme. Some of these special functions need to be adapted to the Home Location Register (HLR) of the cellular network; however, this is not desirable for many reasons, especially from the perspective of a cellular operator.
[0005] The traditional mediator model for the problem of establishing a contract between each WLAN and cellular network operator requires: the mediator deploys the AAA engine involved in real-time mobile user authentication; this easily establishes a single point of failure . Some of these mediator models also require that mobile users use mediators to establish independent accounts; this is very inconvenient for users.
[0006] Therefore, an interworking AAA scheme that overcomes the above-mentioned problems of the prior art interworking AAA scheme is required and very beneficial.
Summary of the invention
[0007] The above-mentioned problems of the prior art and other related problems are solved through the present invention, that is, the authentication, authorization and account management (AAA) based on the interworking of the intermediary using hierarchical certificates.
[0008] The present invention is particularly beneficial, but not limited to, loose coupling in the interworking of a cellular data network and a WLAN. By deploying a mediator, cellular operators do not need to establish a contractual relationship with each wireless LAN operator to interact with each other. Therefore, it is more scalable than the existing technology. Moreover, by using hierarchical certificates, the intermediary does not have to retain any mobile user information. Mobile users can simply use their cellular account to gain access to a wireless LAN that has a contract with their cellular operator.
[0009] According to one aspect of the present invention, a method for authentication, authorization and account management (AAA) in interworking between at least two networks is provided. The at least two networks can communicate with the intermediary, and include a first network
CN 1659558 Β
Network and second network. The second network receives the mediator public key from the mediator, and receives the first network certificate for the user from the user equipment corresponding to the user of the first network. The first network certificate for the user is signed by the first network private key, and includes the mediator certificate for the first network and the user public key. The mediator certificate for the first network is signed by the mediator private key and includes the first network public key. When the second network determines that the intermediary certificate for the first network and the first network certificate for the user are authentic according to the intermediary public key and the first network public key, respectively, the session is sent from the second network to the user equipment Key. The user public key is used to encrypt the session key. The session key is used to enable the user equipment to access the second network.
[0010] According to a method and device for interworking between a wireless local area network with an interworking function and a second network according to the present invention, the wireless local area network and the second network can communicate with a mediator, and the method includes the following steps : Receive the first key from the intermediary; receive the second network certificate for the user from the user equipment, which includes the intermediary certificate for the second network and the second key; use the first key to verify the intermediary for the second network Use the third key to verify the second network certificate for the user to obtain the second key; generate a session key, use the second key to encrypt the session key, and send The user equipment sends the encrypted session key; and uses the encrypted session key to communicate with the user equipment.
[0011] According to a method and device for interworking between a wireless local area network with an interworking function and a second network according to the present invention, the wireless local area network and the second network can communicate with an intermediary, and the method includes the following steps : Receive the mediator public key from the mediator; receive the second network certificate for the user from the user device, which is signed using the second network private key, and includes the mediator certificate for the second network and the user public key, The mediator certificate for the second network is signed with the mediator private key and includes the second network public key; the mediator certificate for the second network is verified by the mediator public key, and the second network is obtained Public key; use the second network public key to verify the second network certificate for the user, and obtain the user public key; generate a session key, use the user public key to encrypt the session key, and send it to the user device Send the encrypted session key; and use the encrypted session key to communicate with the user device.
[0012] A method for communicating with a wireless local area network using a user equipment with a subscription to a second network according to the present invention, the second network and the wireless local area network having an interworking configuration, the wireless local area network and the second network Capable of communicating with the mediator, the method includes the following steps: receiving a second network certificate for the user from the second network, which is signed with the second network private key, and including the mediator certificate for the network and the user public key ; Send the second network certificate for the user equipment to the wireless local area network, where the wireless local area network can use the mediator public key received from the mediator to obtain the user public key; receive the session key encrypted using the user public key from the wireless local area network ; Use the user private key to decrypt the session key; and use the decrypted session key to communicate with the wireless local area network.
[0013] These and other aspects, features, and advantages of the present invention will become clear by describing the preferred embodiments in detail below with reference to the accompanying drawings.
Description of the drawings
[0014] FIG. 1 is a block diagram illustrating a computer system 100 to which the present invention can be applied according to an illustrative embodiment of the present invention;
[0015] FIG. 2 is a block diagram illustrating a communication structure to which the present invention can be applied according to an illustrative embodiment of the present invention;
[0016] FIG. 3 is a diagram illustrating a loosely coupled interaction between access networks according to an illustrative embodiment of the present invention
CN 1659558 Β
Flow chart of a mediator-based method of authentication, authorization and account management (ΑΑΑ) of mobile users at work;
[0017] FIG. 4 is a diagram illustrating a certificate-based method for authentication, authorization, and account management (ΑΑΑ) of mobile users in loosely coupled interworking between access networks according to an illustrative embodiment of the present invention flow chart.
Detailed ways
[0018] The present invention relates to authentication, authorization and account management (AAA) based on interworking of intermediaries using hierarchical certificates. It should be understood that the present invention is applicable to any combination of access networks. However, the present invention is particularly suitable for interworking between cellular networks and wireless local area networks (WLAN).
[0019] It should be understood that the present invention can be implemented in various forms of hardware, software, firmware, dedicated processors, or a combination thereof. Preferably, the present invention is implemented as a combination of hardware and software. Moreover, the software is preferably implemented as an application program explicitly contained on a program memory. The application program can be uploaded to and executed by a machine including any suitable architecture. Preferably, the machine is implemented on a computer platform having hardware such as one or more central processing units (CPU), random access memory (RAM) and input/output interfaces. The computer platform also includes an operating system and microinstruction code. The various processes and functions described herein may be part of the microinstruction code or part of the application program (or a combination thereof) that is executed via the operating system. In addition, various other peripheral devices can be connected to the computer platform, such as additional data storage and printing devices.
[0020] It can also be understood that because some of the system components and method steps described in the drawings are best implemented in software, the actual connection between system components (or processing steps) may depend on the present invention being The way of programming is different. With the teaching provided here, those of ordinary skill in the art can consider these and similar implementations or configurations of the present invention.
[0021] FIG. 1 is a block diagram illustrating a computer system 100 to which the present invention can be applied according to an illustrative embodiment of the present invention. By including necessary communication interface elements and processing elements known in the art, the computer system 100 can be implemented in, for example, a mobile device for accessing a wireless LAN or a cellular network or an access point for implementing a wireless LAN. In the case of mobile user equipment, the computer system 100 will include, for example, the necessary wireless interfaces for communicating with the required wireless access network, and processing elements for encoding and decoding messages according to applicable standards. The computer processing system 100 includes at least one processor (CPU) 102 for operatively coupling to other components via a system bus 104. Read only memory (ROM) 106, random access memory (RAM) 108, display adapter 110, input/output adapter 112, user interface adapter 114, sound adapter 199, and network adapter 198 are operatively coupled to system bus 104.
[0022] The display 116 is operatively coupled to the system bus 104 through the display adapter 110. Disk storage (eg, magnetic disk or optical disk storage) 118 is operatively coupled to the system bus 104 through an input/output adapter 112. The mouse 120 and the keyboard 122 are operatively coupled to the system bus 104 through the user interface adapter 114. The mouse 120 and the keyboard 122 are used to input information to and output information from the system 100.
[0023] At least one speaker (hereinafter referred to as "speaker") 197 is operatively coupled to the system bus 104 through a sound adapter 199.
[0024] The (digital and/or analog) modem 196 is operatively connected to the system bus 104 through a network adapter 198.
[0025] The present invention provides an AAA approach in which a mediator is used. The mediator is used as a certificate authority rather than a real-time verification engine. Therefore, the intermediary is no longer a single point of failure. The mediator issues certificates to the wireless network, which in turn issues their own certificates to independent mobile users who subscribe to the interworking service.
CN 1659558 Β
[0026] FIG. 2 is a block diagram illustrating a communication structure to which the present invention can be applied according to an illustrative embodiment of the present invention. In the illustrative embodiment of FIG. 2, the communication structure includes a cellular network 210, a wireless local area network (WLAN) 220, an intermediary 230 and a mobile user 240. The present invention provides a certificate-based solution to provide AAA services to WLAN users. As mentioned above, the present invention can be applied to any combination of networks including different numbers and different types of networks.
[0027] FIG. 3 is a diagram illustrating a mediator-based method for authentication, authorization, and account management (AAA) of mobile users in loosely coupled interworking between access networks according to an illustrative embodiment of the present invention Flow chart. The access network includes a cellular network and a wireless local area network (WLAN). The cellular network is associated with at least one mobile user. It should be understood that although the illustrative embodiment of FIG. 3 (and the illustrative embodiment of FIG. 4 below) is described with reference to cellular networks and WLANs, the network can be easily used in accordance with the present invention while maintaining the spirit and scope of the present invention. Any combination of previous and other types of networks and different numbers of networks (for example, one cellular network and three WLANs, two cellular networks and two WLANs, etc.). It should also be understood that in the preferred embodiment of the present invention, there may be a single cellular network with which the mobile user has initially contracted for service and multiple WLANs with which the single cellular network has an interworking contract. Various well-known communication methods between the WLAN and the cellular network can be used to implement the interworking contract.
[0028] Send the mediators public key K from the mediator to the WLAN<sub>pub b</sub>, The latter has an interworking contract with the cellular network (step 305). In the case that the cellular network has an interworking contract with more than one WLAN, the intermediary may send the public key Kpuz to all these WLANs. Preferably, but not mandatory, the public key K of the intermediary is sent via a secure channel<sub>pub b</sub>, So that WLAN can guarantee the public key K<sub>pub</sub>_<sub>b</sub>It is indeed the public key of the intermediary.
[0029] The mediator certificate for the cellular network is issued to the cellular network by the mediator (step 310). The intermediary certificate for the cellular network includes but is not limited to the following: the public key Kpuz of the cellular network; and the ID of the cellular network. Use the private key K of the mediator<sub>pri</sub>_<sub>b</sub>Come to sign the intermediary certificate for the cellular network.
[0030] When the mobile user signs a contract with the cellular network for the WLAN interworking service, the cellular network issues a cellular network certificate for the mobile user to the mobile user (step 315). The cellular network certificate for mobile users includes but is not limited to the following: the intermediary certificate for the cellular network; the public key Kg of the mobile user; the mobile user subscription level (whether the mobile user subscribes to the WLAN interactive work service); for the mobile user The expiration time of your cellular network certificate. The private key of the cellular network is used to sign the cellular network certificate for the mobile user.
[0031] When a mobile user moves into an area covered by a WLAN, the mobile user sends his/her certificate (ie, a cellular network certificate for the mobile user) to the WLAN (such as an access point (AP) or other entity of the WLAN) ( Step 320). WLAN uses the public key K of the mediator (sent to WLAN in step 305)<sub>pub b</sub>It is determined whether the intermediary certificate for the cellular network (included in the cellular network certificate for the mobile user) is authentic (step 325). If the mediator certificate for the cellular network is not trusted, the method terminates. However, if the intermediary certificate for the cellular network is trusted, the WLAN (from the intermediary certificate for the cellular network included in the cellular network certificate for the mobile user) extracts the public key K of the cellular network<sub>pub cn</sub>(Step 330). Use the public key K of the cellular network<sub>pub cn</sub>WLAN determines whether the cellular network certificate for the mobile user is credible (step 335) [0032] If the cellular network certificate for the mobile user is not credible, the method terminates. However, if the cellular network certificate for the mobile user is credible, the WLAN extracts the mobile users public key Kpuz from the mobile users cellular network certificate, and sends it to the mobile user who is encrypted with the mobile users public key Kgs. Issue the session key (step 340). The session key may be, but is not limited to, each user's Wired Equivalent Private (WEP) key.
CN 1659558 Β
[0033] The mobile user uses his/her private key K<sub>pri m</sub>To decrypt the encrypted session key (step 345). The mobile user and the WLAN use the session key to communicate (ie, use the session key to encrypt all subsequent communications between the mobile user and the WLAN) (step 350). The mobile user is authenticated by the WLAN because only a specific mobile user has the necessary private key K to decrypt the session key<sub>pri m</sub>o
[0034] FIG. 4 is a diagram illustrating a certificate-based method for authentication, authorization, and account management (AAA) of mobile users in loosely coupled interworking between access networks according to an illustrative embodiment of the present invention flow chart. The access network includes a cellular network and a wireless local area network (WLAN). The cellular network is associated with at least one mobile user. The method of FIG. 4 allows mutual authentication between the mobile user and the WLAN, so that the mobile user can also verify that he/she is indeed talking with a legitimate WLAN (to prevent, for example, messages from being snooped).
[0035] Send the mediators public key K from the mediator to the WLAN<sub>pub b</sub>And for the WLAN mediator certificate, the latter has an interworking contract with the cellular network (step 405). The mediator certificate for WLAN includes but is not limited to the following: WLAN public key K<sub>pub</sub>_<sub>w</sub> ; WLAN ID. Use the private key K of the mediator<sub>pri b</sub>Come to sign the intermediary certificate for the WLAN.
[0036] When the cellular network has an interworking contract with more than one WLAN, the mediator may send the public key Kpg to all these WLANs. It is preferable but not mandatory that the public key K of the intermediary<sub>pub b</sub>Is sent via a secure channel so that WLAN can guarantee the public key K<sub>pub</sub>_<sub>b</sub>It is indeed the public key of the intermediary.
[0037] The mediator issues a mediator certificate for the cellular network to the cellular network (step 410). The intermediary certificate for the cellular network includes but is not limited to the following: the public key K of the cellular network<sub>pub cn</sub> ; The ID of the cellular network; The public key Kpuz of the intermediary. Use the private key K of the mediator<sub>pri b</sub>Come to sign the intermediary certificate for the cellular network.
[0038] When the mobile user signs a contract with the cellular network for the WLAN interworking service, the cellular network issues a cellular network certificate for the mobile user to the mobile user (step 415). The cellular network certificates for mobile users include but are not limited to the following: mediator certificates for cellular networks; public key Kg for mobile users; mobile user subscription level (whether the mobile user subscribes to WLAN interactive work services); for mobile users The expiration time of your cellular network certificate. The private key of the cellular network is used to sign the cellular network certificate for the mobile user. The public key K of the intermediary<sub>pub</sub>_<sub>b</sub>It is also sent to the mobile user (step 417).
[0039] When a mobile user moves into an area covered by a WLAN, the mobile user sends his/her certificate (that is, a cellular network certificate for the mobile user) to the WLAN (for example, an access point (AP) or other entity of the WLAN) ( Step 420). WLAN uses the public key K of the mediator (sent to WLAN in step 405)<sub>pub b</sub>It is determined whether the intermediary certificate for the cellular network (included in the cellular network certificate for the mobile user) is authentic (step 425). If the mediator certificate for the cellular network is not trusted, the method terminates. However, if the intermediary certificate for the cellular network is trusted, the WLAN (from the intermediary certificate for the cellular network included in the cellular network certificate for the mobile user) extracts the public key K of the cellular network<sub>pub cn</sub>(Step 430). Use the public key K of the cellular network<sub>pub cn</sub>, WLAN determines whether the cellular network certificate for the mobile user is trustworthy (step 435).
[0040] If the cellular network certificate for the mobile user is not trusted, the method terminates. However, if the cellular network certificate for the mobile user is credible, the WLAN extracts the mobile users public key Kg" and sends the mobile users public key K<sub>pub m</sub>Encrypted and passed WLAN private key K<sub>pri</sub>_<sub>w</sub>The signed mobile user issues a session key, and also sends to the mobile user the mediator certificate for the WLAN signed by the private key K"" of the mediator (step 440). For the WLAN mediator certificate includes the WLAN public key K<sub>pub wO</sub>The session key can be, but is not limited to, each user's Wired Equivalent Private (WEP) key.
CN 1659558 Β
[0041] The mobile user uses the public key Kpuz of the mediator to determine whether the mediator certificate for the WLAN is authentic (step 442). If the mediator certificate for the WLAN is not trusted, the method terminates. However, if the mediator certificate for the WLAN is trusted, the mobile user obtains the public key Kpum of the WLAN from the mediator certificate for the WLAN. The mobile user uses the public key Kpuz of the WLAN to determine whether the session key is authentic (step 444). If the session key is not trusted, the method terminates.
[0042] However, if the session key is trusted, the mobile user uses his/her private key K<sub>pri ffl</sub>To decrypt the encrypted session key (step 445). The mobile user and the WLAN communicate using the session key (ie, use the session key to encrypt all subsequent communications between the mobile user and the WLAN) (step 450).
[0043] Although illustrative embodiments have been described herein with reference to the accompanying drawings, it should be understood that the present invention is not limited to those precise embodiments, and can be implemented by those skilled in the art without departing from the scope and spirit of the present invention. Various other changes and modifications are made therein. All such changes and modifications are intended to be included within the scope of the invention as defined by the appended claims.
O
L
Contents2
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US20010010046A1 | Cites | United States of America | Search report |
| CN1299544A | Cites | China | Search report |
| WO9639765A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| CN1249096A | Cites | China | Search report |
14 members in 9 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 38660302 | United States of America | P | |
| 38660302 | United States of America | P | |
| 60386603 | United States of America | – | |
| 0316546 | United States of America | W | |
| 0316546 | United States of America | W | |
| 60386603 | – | – | – |
| PCTUS2003016546 | – | – | – |
| US20020386603P | – | – | – |
| WO2003US16546 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| WO03105049A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003237252A1 | Australia | A1 | |
| BR0305019A | Brazil | A | |
| KR20050010859A | Republic of Korea | A | |
| EP1514208A1 | European Patent Office (EPO) | A1 | |
| MXPA04012157A | Mexico | A | |
| CN1659558A | China | A | |
| JP2005529525A | Japan | A | |
| US2005240760A1 | United States of America | A1 | |
| CN1659558BThis record | China | B | |
| EP1514208A4 | European Patent Office (EPO) | A4 | |
| KR101002471B1 | Republic of Korea | B1 | |
| JP4792221B2 | Japan | B2 | |
| US8468354B2 | United States of America | B2 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cessation of patent rightC17 | C17 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 1659558
- Publication, DOCDB
- 1659558
- Publication, EPODOC
- CN1659558B
- Application
- 38129906
- Application, DOCDB
- 03812990
- Application, EPODOC
- CN2003812990
Titles2
- Chinese
- 使用分层证书的基于中介器的交互工作
- English
- Intermediary-based interworking using hierarchical certificates
Classification
- CPC, 12
- H04W12/06
- H04L9/0825
- H04L9/3263
- H04L63/062
- H04L63/0823
- H04L63/0892
- H04L2209/56
- H04L2209/80
- H04W84/12
- H04W88/06
- H04W92/02
- H04W12/0431
- IPC, 8
- H04L9 00
- H04W12 06
- G06F21 35
- H04L9 08
- H04L9 30
- H04L9 32
- H04L29 06
- H04L29 08