EP1484856A1

Method for distributing encryption keys in wireless lan

Abstract

A method for distributing encryption keys in WLAN, said method combines key distribution process with authentication process of the mobile hosts and utilizes an authentication server or a wireless gateway to manage key distribution, so that mobile hosts can roam in a scope larger than the coverage area of the key management server. Because the key distribution doesn't involve transmitting the key, which is not encrypted via the air interface, the method ensures the key is safe. In addition, said method doesn't depend on specific authentication modes, so it can be used under different kinds of WLAN protocols. Finally, because AP doesn't need to manage user information, the method simplifies AP structure, and thus lowers the cost.

EP1484856A1, drawing sheet 1
Sheet 1 of 10

Term

Term ended

Projected expiry passed 30 January 2023, 3.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

24 claims: 1 independent, 23 dependent

  1. 1
    A method for distributing encryption keys in WLAN, said WLAN comprising an AP and a plurality of mobile hosts storing identification information, said mobile hosts communicating with said AP through wireless channels, said AP and the external network connecting with the authentication device which authenticates said mobile hosts; said authentication device storing identification information of all mobile hosts, said method comprising the following steps:(1) a mobile host sending an authentication request containing identification information to the authentication device for identity authentication;(2) the authentication device authenticating the mobile host according to identification information contained in the authentication request, if the authentication fails, the authentication device sending an ACCEPT_REJECT message to the mobile host via the AP;if the authentication succeeds, the authentication device sending key-related information M1 to AP and sending an message comprising ACCESS_ACCEPT information to the mobile host via the AP;if containing key-related information M2, said message being encrypted;(3) AP obtaining the key from the key-related information M1 sent from the authentication device, and the mobile host obtaining the key from said message sent from the authentication device via the AP.