Systems and methods for encoding exchanges with a set of shared ephemeral key data
Abstract
A procedure comprising: generating a shared master secret, in which the shared master secret comprises a peer master key, PMK; generate a shared ephemeral key data set, in which the shared ephemeral key data set is generated independent of the shared master secret, and in which a validity duration of the shared ephemeral key data set is less than a duration validity of the shared master secret; obtain a transient peer key, PTK, based on the shared master secret; and encrypt at least one message to be transmitted to at least one station (118, 120) based on at least the shared master secret, the PTK and the shared ephemeral key data set.
Term
6 yearsto projected expiry
Projected expiry 12 September 2032, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
15 claims: 3 independent, 12 dependent
- 1ES 2 621 990 T3 REIVINDICACIONES 1. Un procedimiento que comprende:5 generar un secreto maestro compartido, en el que el secreto maestro compartido comprende una clave maestra por pares, PMK;generar un conjunto de datos de clave efímera compartida, en el que el conjunto de datos de clave efímera compartida se genera independiente del secreto maestro compartido, y en el que una duración de 10 validez del conjunto de datos de clave efímera compartida es menor que una duración de validez del secreto maestro compartido;obtener una clave transitoria por pares, PTK, basada en el secreto maestro compartido;y 15 cifrar al menos un mensaje que se va a transmitir a al menos una estación (118, 120) en base al menos al secreto maestro compartido, a la PTK y al conjunto de datos de clave efímera compartida.
- 2El procedimiento de la reivindicación 1, en el que el conjunto de datos de clave efímera compartida permite un intercambio de claves de Diffie-Hellman, DH, asociado a un punto de acceso y a la al menos una estación.
- 3El procedimiento de la reivindicación 2, en el que el intercambio de claves de DH utiliza un conjunto de claves seleccionadas de una lista de grupos de DH, especificada por el punto de acceso.
- 4El procedimiento de la reivindicación 3, en el que el intercambio de claves de DH utiliza un conjunto de claves 25 generadas en base a la aritmética de campo finito.
- 5El procedimiento de la reivindicación 1, en el que el conjunto de datos de clave efímera compartida está asociado con un intercambio de coloquios iniciales, asociado con un punto de acceso y la al menos una estación, con el intercambio de coloquios iniciales realizado para autentificar las comunicaciones asociadas 30 con el punto de acceso y la al menos una estación.
- 6El procedimiento de la reivindicación 5, en el que el intercambio de coloquios iniciales, asociado con el punto de acceso y la al menos una estación, comprende un intercambio de coloquios iniciales utilizando un protocolo de Wi-Fi.
- 7El procedimiento de la reivindicación 1, en el que el cifrado del al menos un mensaje asociado con el punto de acceso y la al menos una estación implementa la confidencialidad directa perfecta, PFS.
- 8Un programa informático que comprende instrucciones para realizar un procedimiento de acuerdo con 40 cualquiera de las reivindicaciones 1 a 7.
- 9Un aparato (108, 124), que comprende:medios para comunicarse con al menos una estación mediante una interfaz de red inalámbrica;medios para procesamiento configurados para: generar un secreto maestro compartido, en el que el secreto maestro compartido comprende una clave maestra por pares, 50 generar un conjunto de datos de clave efímera compartida, en el que el conjunto de datos de clave efímera compartida se genera independiente del secreto maestro compartido, y en el que una duración de validez del conjunto de datos de clave efímera compartida es menor que una duración de validez del secreto maestro compartido, obtener una clave transitoria por pares, PTK, en base al secreto maestro compartido, y cifrar al menos un mensaje que se va a transmitir a la al menos una estación (118, 120) en base al menos al secreto maestro compartido, a la PTK y al conjunto de datos de clave efímera compartida.
- 10El aparato de la reivindicación 9, en el que el conjunto de datos de clave efímera compartida permite un 60 intercambio de claves de Diffie-Hellman, DH.
- 11El aparato de la reivindicación 10, en el que el intercambio de claves de DH utiliza un conjunto de claves seleccionadas de una lista de grupos de DH, especificada mediante un punto de acceso. 65
- 12El aparato de la reivindicación 11, en el que el intercambio de claves de DH utiliza un conjunto de claves generadas en base a aritmética de campo finito. ES 2 621 990 T3
- 13El aparato de la reivindicación 9, en el que el conjunto de datos de clave efímera compartida está asociado con un intercambio de coloquios iniciales, asociado con un punto de acceso y la al menos una estación, con el intercambio de coloquios iniciales realizado para autentificar las comunicaciones asociadas con el punto de 5 acceso y la al menos una estación.
- 14El aparato de la reivindicación 13, en el que el intercambio de coloquios iniciales está asociado con un sistema de punto de acceso y la al menos una estación y el intercambio de coloquios iniciales utiliza un protocolo de Wi-Fi.
- 15El aparato de la reivindicación 9, en el que el cifrado del al menos un mensaje asociado con la al menos una estación implementa la confidencialidad directa perfecta, PFS.
Independent claims15
72 paragraphs in 10 sections, as filed
ES 2 621 990 T3
DESCRIPTION
System and procedures for encrypting exchanges with a shared ephemeral key data set
CROSS REFERENCE TO RELATED REQUESTS
The present application claims priority from Commonly Provisional U.S. Patent Application No. 61 / 533,627 (Qualcomm File Number 113346P1) filed on September 12, 2011, U.S. Provisional Patent Application No. 61 / 535,234 (No. Qualcomm file 113346P2) filed on September 15, 2011, US Provisional Patent Application No. 61 / 583,052 (Qualcomm File Number 113346P3) filed on January 4, 2012, US Provisional Patent Application No. 61 / 606,794 (Qualcomm File Number 121585P1) filed March 5, 2012 and US Provisional Patent Application No. 61 / 645,987 (Qualcomm File Number 121585P2) filed March 11, 2012. May 2012 and U.S. Provisional Patent Application No. 61 / 611,553 (Qualcomm File Number 121602P1) filed on March 15, 2012. In addition, the content of the non-provisional application with the Qualcomm file number 113,346, entitled: WIRELESS COMMUNICATION USING RE-AUTHENTIFICATION CONFIGURATION AND CONCURRENT CONNECTION, filed on September 11, 2012, and the non-provisional application with file number of Qualcomm 121585, entitled: SYSTEMS AND PROCEDURES FOR CONDUCTING THE CONFIGURATION AND AUTHENTIFICATION OF LINKS, filed on September 11, 2012, are relevant to this application.
FIELD OF DISCLOSURE
The present teachings relate to systems and procedures for encoding exchanges with a shared ephemeral key data set.
BACKGROUND
In Wi-Fi network applications, security features have gradually evolved to provide more robust and better-integrated security tools. In the 802.11i EAP (Extensible Authentication Protocol) standard, promulgated by the Institute of Electrical and Electronics Engineers (IEEE), an authentication technique can be used that includes a mechanism called 4-way initial colloquium. In the initial 4-way talk mechanism, a client device, such as a laptop, smartphone, or other client device, generally referred to as a station, negotiates with a wireless router or other device, generally referred to as an access point, to establish a secure network session. During the session, the station can search for a connection to the Internet or other networks.
In the initial 4-way colloquium approach, the station and the access point exchange a series of four defined messages, based on which mutual authentication can take place. The access point can interact with a Remote Authentication Telephone User Service (RADIUS) server or other authentication server, platform, or service to establish a series of shared secrets and / or public and private keys, which are used by station and access point to run the 4-way initial discussion procedure. As part of the initial 4-way colloquium procedure, the station and access point may have access to a shared secret, which may include a peer-to-peer master key (PMK). Messages exchanged between the station and the access point can be encrypted using additional sets of public and private keys, including a transient peer key (PTK), which can be constructed using the peer master key as a generator for subsequent key layers. encryption.
However, in existing embodiments of the initial 4-way colloquy, an attacker who is able to successfully intercept and decode the master key in pairs may then be able to use that higher-level key to generate and possibly intercept and decode. the traffic between the access point and one or more stations, generating or deducing the respective transient keys by pairs or other encryption information, because once a pairwise master key is established, the additional session keys obtained from that pairwise master key remain valid and work for as long as the original pairwise master key remains valid. As a result, a successful attacker who captures the master key in pairs may be able to decrypt the flows between the access point and any one or more stations communicating with the access point during the effective lifetime of the master key per pairs.
The article XP031072092, by FANG-CHUN KUO ET AL: Comparison studies between pre-shared and public key exchange mechanisms for transport layer security, discloses that the DHE_PSK, which uses the pre-shared and ephemeral key exchange of Diffie -Hellman, can provide Perfect Forward Confidentiality, PFS, to ensure that a new DH private key is generated for each initial colloquium.
KRAWCZYK H Article XP010158990: SKEME: A Versatile and Secure Key Exchange Mechanism for the Internet, discloses the SKEME protocol that provides perfect direct confidentiality; a session key is obtained for the parties through the Diffie-Hellman exchange; long shared keys can be used
ES 2 621 990 T3 term (as a manually installed master key).
RESUME
The present invention is defined by the subject matter of the appended claims. In the following description, the term embodiment is to be construed as an example, while the scope of protection is defined only by the subject matter of the appended claims.
The apparatus and procedure for providing perfect direct confidentiality in Wi-Fi network sessions are disclosed. Perfect Forward Confidentiality (PFS) is an approach to security. PFS can refer to a property of a key obtain, such that if a main secret is exposed by an attacker, then the attacker cannot determine past or future keys obtained from the main secret.
When a customer device is conducting an initial 4-way colloquium with an Access Point (AP), a Paired Master Key (PMK) is generated and additional keys are obtained, such as a Peer Transient Key (PTK), from the PMK. The PTK remains valid for as long as the PMK remains valid; thus, without added security (eg, the PFS), an attacker can obtain the PTK of a compromised PMK to decode the transmissions between the client device and the AP for an effective lifetime of the compromised PMK. Rather than relying on obtained keys that can remain valid for as long as the PMK can remain valid, the techniques described provide improved security by implementing PFS in the initial 4-way discussion.
When the client device performs the initial 4-way talk with the AP, the AP can generate and transmit an occasional access point message (occasional-A) to the client device. The client device can obtain a PMK and generate an occasional station message (occasional-S). Customer can obtain PTK, Key Confirmation Key (KCK), and Key Encryption Key (KEK) based on PMK, Occasional-A, Occasional-S, and / or other information.
To implement PFS in the initial 4-way talk, the client device can transmit an association request that can include a station (STA) Diffie-Hellman ephemeral public key (SDHEPubKey) to the AP. The AP gets the PMK and gets the PTK from the PMK.
To implement PFS in the initial 4-way discussion, the AP can obtain a shared ephemeral Diffie-Hellman key (SharedDHEKey) from the SDHEPubKey and an access point Diffie-Hellman ephemeral private key (ADHEPrivKey), which it is known by the access point. The SDHEPubKey and ADHEPrivKey can be pre-generated by the client device and the AP before engaging in the initial 4-way discussion, respectively. On the other hand, the AP can obtain a Perfect Direct Confidentiality Peer Transient Key (PFS-PTK), a Perfect Direct Confidentiality Key Confirmation Key (PFS-KCK), and a Perfect Direct Confidentiality Key Encryption Key ( PFS-KEK), based on the SharedDHEKey and the PTK. The AP can transmit an Access Point Diffie-Hellman Ephemeral Public Key (ADHEPubKey) to the client device. The client device can obtain the SharedDHEKey based on a station DiffieHellman ephemeral private key (SDHEPrivKey), which is known to the client device, and the ADHEPubKey. The ADHEPubKey and SDHEPrivKey can be pre-generated by the AP and the client device before engaging in the initial 4-way discussion, respectively. The client device can get the PFS-PTK, PFS-KCK, and PFS-KEK based on the PTK and SharedDHEKey.
The AP and the client device can clear the ADHEPrivKey and SDHEPrivKey after obtaining the SharedDHEKey, respectively. The client device and the AP can decrypt the respective received transmissions based on the PFS-KEK, the PFS-KCK, the SharedDHEKey and / or another key obtained from the PMK.
In a particular embodiment, a method is provided according to independent claim 1.
In another particular embodiment, an apparatus is provided according to independent claim 9
A particular advantage provided by at least one of the disclosed embodiments is the ability of a first device (eg, a mobile station) to implement PFS with a second device (eg, an access point) in a network of Wifi.
Other aspects, advantages, and features of the present disclosure will become apparent upon review of the entire application, including the following sections: Brief Description of the Drawings, Detailed Description, and Claims.
BRIEF DESCRIPTION OF THE DRAWINGS
The accompanying drawings, which are incorporated in, and which form a part of, this specification illustrate
ES 2 621 990 T3 embodiments of the present teachings and, together with the description, serve to explain the principles of the present teachings. In the figures:
FIG. 1 illustrates a general network that can be used in systems and procedures to provide perfect direct confidentiality in Wi-Fi network sessions, according to various embodiments;
FIG. 2 illustrates the hardware, software and other resources that can be used in an access point that can be configured to use the systems and procedures to provide perfect direct confidentiality in Wi-Fi network sessions, according to various modes of access. realization;
FIGs. 3A and 3B illustrate an exemplary call flow sequence for executing the configuration and operation of an encryption arrangement between an access point and a station, in accordance with various embodiments of the present teachings;
FIG. 4 illustrates another exemplary call flow sequence for executing the setup and operation of an encryption arrangement between an access point and a station, in accordance with various embodiments of the present teachings; and FIG. 5 illustrates exemplary hardware, software, and other resources that can be used in providing perfect direct confidentiality in Wi-Fi network sessions, in accordance with various embodiments.
DETAILED DESCRIPTION
The embodiments of the present teachings relate to systems and procedures to provide perfect direct confidentiality in Wi-Fi network sessions. More particularly, the embodiments refer to the platforms and techniques for introducing mechanisms to create or enable Perfect Direct Confidentiality (PFS) to be applied to Wi-Fi sessions using the initial 4-way discussion. to establish communications between an access point and a station. The access point and station can perform an initial 4-way talk operation, using a peer-to-peer master key, an authentication server, a message integrity check (MIC), and other procedures and resources specified by the standard. 802.11i and / or other protocols. In systems and procedures to provide perfect direct confidentiality in Wi-Fi network sessions, the access point and station can apply additional layers of cryptographic protection, including the generation of an additional set of ad hoc keys that are inserted into the initial 4-way colloquium structure. The additional set of ad hoc keys can include a data set of public and private keys that is generated using Diffie-Hellman (DH) calculations, which can be or include the generation of public and private key pairs, using field arithmetic finite, elliptical and / or other arithmetic. Diffie-Hellman keys and related information can be generated based on, or using, randomized number generators.
After the corresponding Diffie-Hellman shared keys are generated and / or extracted, both on the access point side and on the station side, the private part of that Diffie-Hellman shared key can be erased or destroyed, either by the access point as well as by the station units. Since those private keys (for example, the ADHEPrivKey and SDHEPrivKey) have been erased or destroyed, an attacker who captures the message flows between the access point and the station cannot compromise other flows before or after a current session, even if the attacker later succeeds in recovering the pairwise master key used during the current session. The attacker cannot compromise other flows because independent sessions that are encrypted according to systems and procedures to provide perfect direct confidentiality in Wi-Fi network sessions will have different DiffieHellman key data, generated separately during each session, the decoding of which would require the acquisition of other private and public key information from Diffie-Hellman. According to these and other aspects, the security of Wi-Fi sessions can be improved, and Perfect Direct Confidentiality (PFS) can be incorporated into the security scheme of the initial 4-way colloquium.
In a particular embodiment, a procedure includes the generation of a shared master secret. The procedure also includes the generation of a shared ephemeral key data set, to encode the exchanges associated with an access point and at least one station, where the shared ephemeral key data set is based on the content of an exchange of initial colloquia, associated with the access point and the at least one station, performed to authenticate the communications associated with the access point and the at least one station. The shared ephemeral key data set is generated, independent of the shared master secret, and a validity duration of the shared ephemeral key data set is less than a validity duration of the shared master secret. The method further includes encoding at least one message based on at least the shared master secret and the shared ephemeral key data set.
In another particular embodiment, an apparatus includes a wireless network interface with at least one station. The apparatus also includes a processor configured to communicate with the at least one station through a network interface, the processor being configured to generate a shared master secret and to
ES 2 621 990 T3 generating a shared ephemeral key data set to encrypt the Exchanges associated with an access point system and the at least one station. The shared ephemeral key data set is based on the content of an initial colloquia exchange, associated with the access point system and at least one station, conducted to authenticate communications associated with the access point system and the network. minus one station. The ephemeral key data set is generated independently of the shared master secret, and a validity duration of the shared ephemeral key data set is less than a validity duration of the shared master secret. The processor is further configured to encrypt at least one message associated with the access point system and the at least one station, using at least the shared master secret and the shared ephemeral key data set.
Reference is made to exemplary embodiments of the present teachings, which are illustrated in the accompanying drawings. Wherever possible, the same reference numerals are used throughout the drawings to refer to the same or similar parts.
FIG. 1 illustrates a global network 100 in which systems and procedures can operate to provide perfect direct confidentiality in Wi-Fi network sessions. As shown, an access point 108 can broadcast a wireless network signal to a set of stations 102 within its range. Access point 108 may include a wireless router and / or other network access point and may be configured to operate using the Wi-Fi wireless standard, specified by the IEEE specification 802.11b, 802.11g, 802.11n, and / or or other standards. When operating as a Wi-Fi access point, the access point 108 can, for example, operate in the 2.4 GHz frequency band. It will be appreciated however, that in other embodiments, other wireless access standards, channels and / or frequencies may be used. As described in more detail below, at least one of the sets of stations 102 may participate in a data exchange 114 that implements perfect forward confidentiality (PFS) with the access point 108 over a Wi-Fi network.
Each device or station in the set of stations 102 can include any wireless network-enabled device, such as a Wi-Fi equipped smartphone, a touch panel device, and / or other device or platform. As shown in FIG. 2, an individual station 118 in the set of stations 102 may be configured with one or more hardware, software, and / or other resources. A station 118 may comprise a variety of hardware, software, and other resources, including an operating system 112, a screen 110 that may, for example, display a graphical user interface (GUI) of operating system 112, and a radio frequency antenna 150. (or multiple antennas). The operating system 112 may comprise a mobile device operating system, such as the Android ™ operating system available from Google Inc., Mountain View, California, United States, or others. Operating system 112, as noted, may comprise a graphical user interface (GUI), as well as file management, power management, communications, and / or other logic, services, and / or resources to operate the station 118. Operating system 112 may include computer instructions 116. Computer instructions 116 may cause a processor to implement PFS for data exchange over a Wi-Fi network. Station 118 can host applications, services, logic and / or other logic, other services, and / or other modules, which can be used to establish connections to access points and / or other channels. Any one, or more, of the set of stations 102 may connect to the access point 108 at the same time. As shown in FIG. 2, the access point 108 can broadcast beacon information 104 for the set of stations 102. Beacon information 104 may include a Service Set Identification Information (IE) Element (SSID), indicating the name, connection type, available channels, and other network information and services provided by access point 108 to any station within its wireless connection range. FIG. 3 illustrates a call sequence that can be used to establish a connection according to the Wi-Fi standard, with enhancements, features, extensions and / or benefits according to the systems and procedures to provide perfect direct confidentiality in network sessions of Wi-Fi, including the provision of Perfect Forward Confidentiality (PFS) on individual network sessions. Generally speaking, the sequence of call flows can take place between two or more platforms, systems, nodes, devices, and / or other hardware, including, as illustrated, station 120, first access point 122, second access point 124, an authentication server 126, and a Dynamic Host Configuration Protocol (DHCP) server 128. While those individual platforms, systems, nodes, devices and / or hardware are illustrated, it will be appreciated that, in other embodiments, alternative or additional hardware platforms, systems, nodes, devices and / or hardware may be used. As shown in 0002, a station 120 can approach and enter the wireless range of a first access point 122 (labeled API), such as, for example, a Wi-Fi wireless router and / or other device, platform or access headquarters. At 1002, station 120 may drift out of range of first access point 122 and into wireless range of second access point 124 (labeled AP2). The second access point 124 may also include a Wi-Fi wireless router and / or other access device or site. In 2002, the second access point 124 may generate an occasional access point message (occasional-A), which may include a one-time message, a sequence, data, and / or a code to announce the presence of the second point. access code 124, and can be used in the generation of key codes. The occasional access point message (occasional-A) may include a randomly or pseudo-randomly generated number and / or other data. The occasional access point message (occasional-A) can be inserted into the beacon message broadcast by the second access point 124.
At 3002, station 120 can obtain a Pairwise Master Key (PMK), to be used to establish a
ES 2 621 990 T3 secure communication with the second access point 124. To obtain the PMK, the station 120 may generate information including, for example, a SEQ or data message, an rMSK or data message, and an occasional data message. station (occasional-S) or data. If a pre-established pairwise master key is used, station 120 can retrieve that pairwise master key. At 3004, the second access point 124 may obtain additional information including, for example, a transient peer key (PTK), a Strong Authentication Protocol over LAN (EAPOL) Key Confirmation Key (KCK), and an EAPOL key. EAPOL Key Encryption Key (KEK), using the pairwise master key, an occasional access point message (occasional-A), an occasional station message (occasional-S), and / or other information.
At 4002, station 120 may generate an association request (Sol. Associate) and transmit that request to the second access point 124. In connection with the request, station 120 may perform calculations to generate additional keys and related data, including a Diffie-Hellman ephemeral private key (SDHEPrivKey) and a Diffie-Hellman ephemeral public key (SDHEPubKey). The Station Diffie-Hellman Ephemeral Private Key (SDHEPrivKey) and Station Diffie-Hellman Ephemeral Public Key (SDHEPubKey) can be generated using Diffie-Hellman cryptographic approaches, which may include elliptical or other arithmetic.
It can be seen that one of the stations 120, or both, and the second access point 124 can access, store and / or pre-compute the same Diffie-Hellman data and retrieve that data when needed, which can reduce the calculation load during the execution of the modified initial 4-way talk protocol. The Station Diffie-Hellman Ephemeral Public Key (SDHEPubKey) can be embedded in the parameters or fields of the association request (Sol. Associate) and can be sent to the second access point 124. At 4004, the second access point 124 may receive the association request (Sol. Associate), but can discard that request if the occasional access point message (occasional -A) is not current, valid, or new.
At 5002, the second access point 124 may transmit an EAP AAA request to the authentication server 126. As illustrated, the EAP AAA request may include a number of parameters or fields, some or all of which , can be used to authenticate station 120 and / or data or credentials associated with station 120. At 6002, the authentication server 126 can verify the authentication tag (Aut. Tag) and obtain the rMSK key or data. At 7002, the authentication server 126 may transmit an AAA response from the EAP to the second access point 124, which response may include a number of parameters or fields, as illustrated. At 8002, the second access point 124 can assign the master key in pairs to match the rMSK returned in the AAA response from the EAP. In other embodiments that use a stored peer-to-peer key, the second access point 124 may instead retrieve the peer-to-peer master key from storage.
At 9002, the second access point 124 can obtain a peer-to-peer transient key (PTK) from the peer-to-peer master key, the occasional station message (occasional-S), and the occasional access point message (occasional-A ). At 10002, the second access point 124 can verify the DHCP-Discover with Quick Commit message and the EAPOL-Key_F message, using KCK and KEK data and / or other information. At 11002, the second access point 124 can transmit a DHCP-Discover with Fast Commit () message to the DHCP server 128. At 12002, the second access point 124 can obtain a shared DiffieHellman ephemeral key (SharedDHEKey) or ad hoc , from the ADHEPivKey and the SDHEPubKey, and / or other information or data. At 12004, the second access point 124 can obtain the Perfect Direct Confidentiality Transient Peer Key (PFS-PTK), as well as other information or data including a Perfect Direct Confidentiality Key Confirmation Key (PFS-KCK) and an EAPOL Perfect Direct Confidentiality Key (PFS-KEK) encryption key, using the peer-to-peer transient key, the shared Diffie-Hellman ephemeral key (SharedDHEKey), and / or other information.
At 13002, the second access point 124 may generate a group temporary key (GTK) and an integrity group temporary key (IGTK), as required. It should be noted that after generating the shared Diffie-Hellman ephemeral key (SharedDHEKey) and / or at other times, the station 120 and the second access point 124 can, respectively, delete, discard, overwrite and / or erase or destroy. otherwise their respective Diffie-Hellman ephemeral private keys (that is, the corresponding SDHEPrivKey and ADHEPrivKey). By deleting, overwriting and / or erasing or otherwise destroying the ephemeral DiffieHellman private keys belonging to station 120 and second access point 124, station 120 and second access point 120 can ensure that no attacker can compromise the network. stored message traffic. This is the case even if the attacker gains possession of the peer-to-peer master key and the unaltered peer-to-peer key, as the shared Diffie-Hellman ephemeral key (SharedDHEKey) would still be required to decrypt that traffic, but the ephemeral key Shared Diffie-Hellman Keys (SharedDHEKey) is unrecoverable once the respective private Diffie-Hellman keys (SDHEPrivKey and ADHEPrivKey) are cleared. At 14002, the DHCP server 128 can generate a DHCP-Ack message with Fast Commit (IP address) and transmit that message to the second access point 124. That message can include an IP address assigned to station 120. It should be Note that while 11.002 to 14.002 are illustrated as taking place in a certain order, those processing steps, messages, decision logic, and / or other actions, as well as others shown in FIGs. 3A and 3B and elsewhere, may occur in various other sequences or orders, depending on the configuration of station 120 and second access point 124 and / or other factors.
ES 2 621 990 T3
At 15002, the second access point 124 may form an association response (Resp. Associate) with various fields or components. The various fields or components may include an EAP authentication related message, that is, an EAP-End message or data received from the authentication server at 7002. The EAP-End message or data may be an EAP-End message. EAP-End Re-Aut or data. The association response may also include a DHCP related message with various options which, as illustrated, may consist of a DHCP-Ack message with Quick Commit or data and / or other messages or data received from the DHCP server at 14002 The AP2 can apply encryption and / or integrity protection to these messages or data. Encryption can use the KEK or the PFS-KEK, or another key obtained from the PMK and the PTK and the SharedDHEKey. Integrity protection can use the KCK or the PFS-KCK or another key obtained from the PMK and / or the PTK and / or the SharedDHEKey. The association response may further include a message related to an EAPOL key message which, as illustrated, may include options for encryption, authentication, and / or integrity checking using the transient peer-to-peer confidentiality key. direct perfect (PFS-PTK) and / or other keys or data. This EAPOL key related message may include the ADHEPubKey. This EAPOL key related message may include a message integrity check (MIC), calculated on the message or data related to the EAPOL key, using the KCK. The AP2 122 can calculate a Perfect Forward Confidentiality Message Integrity Check (PFS-MIC) using the PFS KCK and / or other data, messages or information. The PFS-MIC can provide integrity protection for all or part of the combination of Sol. Asoc. 4002 and Resp. Asoc. 15002. The integrity-protected part may correspond to the message or data related to the EAPOL key in Resp. Assoc. 15002. PFS-MIC can be transmitted internally to EAPOL key related messages or data, EAP-End Re-Aut or DHCP. The PFS-MIC can be part of the Resp. Associated, but outside of EAPOL, EAP-End Re-Aut, or DHCP key related messages or data.
At 16002, station 120 may verify the EAP-End Re-Aut message using the rIK and / or other information. At 17002, station 120 can verify the EAPOL key message integrity check (MIC) using the KCK. In 18002, station 120 can generate a shared Diffie-Hellman ephemeral key (SharedDHEKey) from the SDHEPrivKey and ADHEPubKey located in the EAPOL key message, as generated or presented in 15002, and / or other data or information. In 18004, station 120 can obtain the PFS-PTK, PFS-KCK, and PFS-KEK information using the peer-to-peer transient key and the shared Diffie-Hellman ephemeral key (SharedDHEKey) and / or other data or information . In 18006, station 120 can verify the PFS-MIC using the PFS-KCK and / or other data, messages, or information.
In 19002, station 120 can verify and / or decrypt the DHCP confirmation message. Decryption can use the KEK or the PFS-KEK or another key obtained from the PMK and / or the PTK and / or the SharedDHEKey. Verification can use the KCK or the PFS-KCK or another key obtained from the PMK and / or the PTK and / or the SharedDHEKey. In 20002, station 120 may transmit an authorization confirmation message (Confirm-Aut) to second access point 124, including a set of parameters or fields, as illustrated. The Confirm-Aut message can include a message or data related to an EAPOL key message. This message or data related to an EAPOL key may include a message integrity check (MIC), calculated on the message or data related to the EAPOL key, using the KCK. When perfect direct confidentiality (PFS) is used in accordance with the present teachings, the integrity check of the perfect direct confidentiality message (PFS-MIC) can be incorporated into the authorization message (Confirm-Aut). The PFS-MIC can be calculated using the PFS KCK and / or other data, messages or information. The PFS-MIC can provide integrity protection for all or part of the combination of Sol. Asoc. 4002 and Resp. Asoc. 15002 and Confirm-Aut 20002. The part with protected integrity can correspond to the message or messages. data related to the EAPOL key in Confirm-Aut 20002. The PFS-MIC can be internal to the EAPOL, EAP-End Re-Aut, or DHCP key related messages or data. The PFS-MIC can be part of the ConfirmAut, but outside the messages or data related to the EAPOL key, EAP-End Re-Aut or DHCP.
In 21002, station 120 can install keys or data including PFS-TK, GTK, and IGTK. In 21004, the station 120 can install the IP (Internet Protocol) address generated by the Dynamic Host Configuration Protocol (DHCP) 128 through the authentication process.
At 22002, the second access point 124 can verify the message integrity check (MIC) using the key confirmation key (KCK). At 2302, the second access point 124 can verify the PFS-MIC using the PFS-KCK data and / or other data, messages or information. At 2402, the second access point 124 can install keys or data including the PFS-TK, GTK, and IGTK. At 24004, the second access point 124 can set the IP (Internet Protocol) address for station 120. After 24004, station 120 can access the Internet and / or other public or private networks through the second access point. access 124, using the assigned IP (Internet Protocol) address. It can be seen that while the encryption and related processing shown in FIGs. 3A and 3B illustrate exchanges between station 120 and second access point 124 toward which station 120 is moving, the same or similar processing may be applied between station 120 and first access point 122, the station 120 and a third access point (not shown) and / or other network configurations.
ES 2 621 990 T3
It can also be seen that after completion of the enhanced authentication process illustrated in FIG. 2, the session carried out between the station 120 and the second access point 124 is protected by the master peer key (PMK), the transient peer key (PTK) and / or other security features of the extensible authentication protocol. (EAP), including the initial 4-way discussion. However, in accordance with the aspects of the present teachings, the addition of features related to Perfect Forward Confidentiality (PFS) and the use of public / private key sets based on Diffie-Hellman generators allow greater security in Comparison with a flat 4-way initial discussion protocol. In accordance with aspects of the present teachings, an attacker who captures and stores message flows between station 120 and second access point 120 (or any comparable access point), including the peer-to-peer master key (PMK) and the peer-to-peer transient key (PTK), still cannot violate the integrity of those streams, since re-creation of the shared Diffie-Hellman ephemeral key (SharedDHEKey), required to complete the violation, it is not possible without private Diffie-Hellman ephemeral keys belonging to the station (SDHEPrivKey) and / or access point (ADHEPrivKey), which have been discarded in a relatively short time after the session was established.
Security processing in accordance with systems and procedures to provide perfect direct confidentiality in Wi-Fi network sessions can be implemented in various network environments, including, for example, a Wi-Fi network environment in which Quick Initial Link Configuration (FILS) capability is incorporated. The Rapid Initial Link Configuration (FILS) comprises a set of communication protocols issued by the 802.11ai standard of the Institute of Electrical and Electronics Engineers (IEEE), which is conceived to address scenarios where the approach and registration of a station for a access point takes place transiently, such as a wireless smartphone or laptop traversing a public airport, bus terminal and / or other environment, where the speed with which wireless connections can be established is at a premium. It will be appreciated, however, that the platforms and techniques in accordance with the present teachings can be integrated into other network configurations, either using the Quick Initial Link Configuration (FILS) protocol, or not.
In accordance with aspects of the present teachings in other matters, station 120 and second access point 124 (or other access point or node) may each store the generated shared Diffie-Hellman ephemeral key (SharedDHEKey). during one session, to be reused during a second later session, between the same two devices. When the shared Diffie-Hellman ephemeral key (SharedDHEKey) is retrieved rather than generated, a significant amount of computation can be saved at both ends. According to such embodiments, each between station 120 and second access point 124 (or other access point or node) may, for example, associate an identifier with the shared Diffie-Hellman ephemeral key (SharedDHEKey) , for example, by generating a hash function output, based on one of its respective public Diffie-Hellman ephemeral keys (SDHEPubKey and ADHEPubKey), or both, or otherwise. In additional embodiments, station 120 and access point 124 do not need to create an explicit identifier for the shared Diffie-Hellman ephemeral key (SharedDHEKey), but can instead be configured to associate and retrieve that key automatically when the same station or access point is found or identified as in a previous session.
FIG. 4 illustrates a particular call flow sequence for executing a configuration and operation of the encryption arrangement of FIGS. 3A and 3B with an occasional delayed A-message, and is generally designated 400.
For example, instead of transmitting the occasional-A message from the second access point 124 via the beacon message to station 120, as in FIG. 3A, the second access point 124 may transmit the occasional-A message in a different message. In a particular embodiment, the second access point 124 transmits the occasional-A message after the generation of the PTK in the second access point 124. To illustrate this, prior to transmitting the occasional-A message to station 120, the second access point 124 may receive an authorization message from station 120, at 402. The authorization message may include the occasional-S message, the SDHEPubKey and the EAP-Re-aut-start message. The second access point 124 can generate the SharedDHEKey and obtain the PTK from the rMSK, the occasional-S message, and the occasional-A message, at 404. In addition, the second station 124 can also generate the GTK and IGTK, at 404.
The second access point 124 may transmit the occasional-A message to station 120 in an authorization response message, at 406. The authorization response message may include the occasional-A message, the EAP-End Re information element. -aut and the ADHEPubKey. Station 120 may generate the SharedDHEKey and PTK after receiving the authorization response message, at 408. Station 120 may transmit an association request to second access point 124, at 410. The association request may include the DHCP-Discover with Quick Commit message and a password confirmation. Second access point 124 may transmit an association response to station 120, at 412. The association response may include the DHCP-Ack message with Fast Commit (IP-address), the GTK, and the IGTK.
FIG. 5 illustrates a variety of hardware, software and other resources that can be used in the embodiments to provide perfect direct confidentiality in Wi-Fi network sessions, in accordance with the
ES 2 621 990 T3 embodiments. In the embodiments shown, access point 108 may comprise features of a processor 142 that communicates with memory 144, such as an electronic random access memory, as well as a network interface, such as an Ethernet and / or or other wired or wireless connection to the Internet and / or other networks. Processor 140 may be programmed or configured to perform character set encoding operations, network connectivity operations, and other operations in accordance with the present teachings. Processor 140 can also communicate with a local data store 146, such as a local hard drive and / or other storage media, as well as with a wireless interface 148, such as a Wi-Fi compatible chipset, including the Radio frequency chipset (s) and associated hardware and software, which may be connected to a radio frequency antenna 152 (or multiple antennas). Memory 144 may include instructions 154. Instructions 154 can cause a processor (eg, processor 140) to implement PFS for a data exchange over a Wi-Fi network.
In conjunction with the described embodiments, an apparatus may include means for communicating with at least one station via a wireless network interface. For example, the means for communicating may include one or more components (eg, a transmitter, a receiver, an antenna) of station 102 of FIG. 1, one or more components (eg, a transmitter, a receiver, an antenna) of the access point 108 of FIG. 1, the radio frequency antenna 150 of FIG. 2, one or more components (eg, a transmitter, a receiver, an antenna) of station 120 of FIGS. 3A, 3B and 4, one or more components (eg, a transmitter, a receiver, an antenna) of the first access point 120 of FIGS. 3A, 3B and 4, one or more components (eg, a transmitter, a receiver, an antenna) of the second access point 124 of FIGS. 3A, 3B and 4, the wireless interface 148 of FIG. 5, the radio frequency antenna 152 of FIG. 5, one or more other devices configured to communicate data wirelessly, or any combination thereof. The apparatus may also include means for processing, the processing means being configured to generate a shared master secret and generate a shared ephemeral key data set. The shared ephemeral key data set is generated independent of the shared master key. A validity duration of the shared ephemeral key data set is less than a validity duration of the shared master secret. The means for processing is also configured to encrypt at least one message to be transmitted to the at least one station, based on at least the shared master secret and the shared ephemeral key data set. For example, the means for processing may include one or more components (eg, a processor) of station 102 of FIG. 1, one or more components (eg, a processor) of the access point 108 of FIG. 1, operating system 112, and instructions 116 of FIG. 2, one or more components (eg, a processor) of station 120 of FIGS. 3A, 3B, and 4, one or more components (eg, a processor) of the first access point 120 of FIGS. 3A, 3B and 4, one or more components (eg, a processor) of the second access point 124 of FIGS. 3A, 3B, and 4, processor 142, and instructions 154 of FIG. 5, one or more other devices configured to process the data, or any combination thereof.
The above description is illustrative, and variations in configuration and implementation may occur to those skilled in the art. For example, although embodiments in which station 120 approaches second access point 124 for Perfect Forward Confidentiality (PFS) registration and enforcement have been described and illustrated, in other embodiments, it is possible to have multiple stations connected to an access point, for example, using a group master key, a group Diffie-Heilman ephemeral key (DHESharedKey), and / or other keys or data. Alternatively, in other embodiments, each station that approaches and registers with an access point may exchange individual ad hoc, or ephemeral Diffie-Hellman Shared Keys (DHESharedKeys), with the station, in a manner individual.
Although embodiments in which Perfect Forward Confidentiality (PFS) can be employed in network scenarios that also employ the Fast Initial Link Configuration (FILS) standard according to the IEEE 802.11ai standard have been described and illustrated, Direct Confidentiality Perfect (PFS) according to the present teachings can be applied in environments that do not incorporate the Quick Initial Link Configuration (FILS). Similarly, although embodiments have been described in which an authentication server 126 functions to support the provision of keys and the establishment of encrypted message flows, in other embodiments, multiple servers and / or services may be used. authentication. Other resources, described as singular or integrated, in other embodiments can be plural or distributed, and resources described as multiple or distributed, in other embodiments can be combined. In addition, although the embodiments have been described as operating on Wi-Fi networks that are configured in an access point / station arrangement, in other embodiments, the teachings can be applied to incorporate perfect direct confidentiality ( PFS) and other features also to point-to-point, or other, Wi-Fi network configurations. Furthermore, although embodiments using Wi-Fi wireless network standards have been described, Perfect Forward Confidentiality (PFS) provision in accordance with the present teachings can also be applied to networks other than Wi-Fi networks. Fi.
One or more of the disclosed embodiments may be implemented in a system or apparatus that may include a communications device, a fixed location data unit, a mobile location data unit, a mobile phone, a cell phone, a computer, tablet, laptop or desktop computer. In addition, the system or apparatus may include a decoder, a recording unit,
ES 2 621 990 T3 entertainment, a navigation device, a personal digital assistant (PDA), a monitor, a computer monitor, a television, a tuner, a radio, a satellite radio, a music player, a music player digital music, a portable music player, a video player, a digital video player, a digital video disc (DVD) player, a portable digital video player, any other device that stores or retrieves computer data or instructions, or a combination thereof. As another illustrative, non-limiting example, the system or apparatus may include remote units, such as mobile phones, handheld personal communication system (PCS) units, portable data units such as personal data assistants, computer-enabled devices, global positioning system (GPS), navigation devices, fixed location data units, such as meter reading equipment, or any other device that stores or retrieves computer data or instructions, or any combination thereof. Although one or more of FIGs. 1-5 may illustrate systems, apparatus and / or procedures in accordance with the teachings of the disclosure, the disclosure is not limited to these illustrated systems, apparatus and / or procedures. The embodiments of the disclosure can be suitably employed in any device that includes integrated circuits including memory, a processor, and circuits on a chip.
It should be understood that any reference to an item herein using a designation such as "first," second, etc., does not generally limit the number or order of those items. Instead, these designations may be used herein as a convenient way to distinguish between two or more items or instances of an item. Therefore, a reference to first and second elements does not mean that only two elements can be used or that the first element must precede the second element in some way. In addition, unless otherwise indicated, an item set may comprise one or more items. Furthermore, the expression of the form of at least one of: A, B or C ", used in the description or in the claims, means" A or B or C or any combination of these elements ".
As used herein, the term determine encompasses a wide variety of actions. For example, determine can include calculate, compute, process, obtain, investigate, query (for example, query a table, database, or other data structure), inquire, and the like. Determining can also include receiving (eg, receiving information), accessing (eg, accessing data in a memory), and the like. Determine can also include solve, select, choose, set, and the like. Furthermore, a channel width, as used herein, may also include or may be referred to as a bandwidth in certain respects.
As used herein, a phrase that refers to at least one of a list of items refers to any combination of those items, including individual items. As an example, "at least one of: a, boc" is intended to encompass: a, b, c, ab, ac, bc, and abc.
The various illustrative components, blocks, configurations, modules, circuits, and steps have been described above, generally, with respect to their functionality. Whether such functionality is implemented as hardware or processor executable instructions depends on the particular application and design limitations imposed on the entire system. Furthermore, the various operations of the procedures described above may be carried out by any suitable means capable of performing the operations, such as various hardware and / or software components, circuits and / or modules. In general, any operation illustrated in FIGs. 1 to 5 can be carried out by corresponding functional means, capable of carrying out the operations. Those skilled in the art may implement the described functionality in different ways for each particular application, but such implementation decisions should not be construed as departing from the scope of the present disclosure.
Those skilled in the art will further appreciate that the various illustrative logic blocks, configurations, modules, circuits, and algorithm stages, described in connection with the present disclosure, may be implemented or realized with a general purpose processor, a digital signal processor (DSP). ), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device (PLD), discrete transistor or gate logic, discrete hardware components (eg, electronic hardware), computer software run by a processor, or any combination thereof designed to perform the functions described herein. A general purpose processor can be a microprocessor but, alternatively, the processor can be any commercially available processor, controller, microcontroller, or state machine. A processor can also be implemented as a combination of computing devices, for example, a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors together with a DSP core, or any other such configuration.
In one or more aspects, the functions described can be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions can be stored as one or more instructions or code on a computer-readable medium. Computer-readable media includes computer-readable storage media and communication media, including any medium that facilitates the transfer of a computer program from one location to another. A storage medium can be any available medium that can be accessed by a computer. By way of example, and not by way of limitation,
ES 2 621 990 T3 such computer-readable storage media may include random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable PROM (EPROM), electrically erasable PRoM (EEPROM). ), one or more registers, a hard disk, a removable disk, a compact disk read-only memory (CD-ROM), other optical disk storage, magnetic disk storage, magnetic storage devices, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer. Alternatively, the computer-readable medium (eg, storage medium) can be integrated into the processor. The processor and storage medium can reside in an application-specific integrated circuit (ASIC). The ASIC can reside in a computing device or a user terminal. Alternatively, the processor and storage medium can reside as discrete components in a computing device or user terminal.
Furthermore, any connection can be appropriately called a computer-readable medium. For example, if the software is transmitted from a Web site, server, or other remote source, using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL or wireless technologies such as infrared, radio and microwave, are included in the definition of medium. Discs, as used herein, include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disc, and Blu-ray® disc, where Some discs normally reproduce data magnetically, while other discs reproduce data optically with lasers. Thus, in some aspects, the computer-readable medium may comprise a non-transitory computer-readable medium (eg, tangible media). Furthermore, in some aspects, the computer-readable medium may comprise a transient computer-readable medium (eg, a sign). Combinations of the above should also be included within the scope of computer-readable media.
The procedures disclosed herein include one or more steps or actions to perform the described procedure. The steps and / or actions of the method can be interchanged without departing from the scope of the claims. In other words, unless a specific order of steps or actions is specified, the order and / or use of specific steps and / or actions can be modified without departing from the scope of the claims.
Therefore, certain aspects may include a computer program product to perform the operations presented herein. For example, such a computer program product may include a computer-readable storage medium that has instructions stored (and / or encoded) therein, the instructions being executable by one or more processors to perform the operations described in the present document. In certain respects, the computer program product may include packaging material.
Software or instructions can also be transmitted via a transmission medium. For example, if the software is transmitted from a network site, server, or other remote source, using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL or wireless technologies such as infrared, radio and microwave are included in the definition of transmission medium.
Furthermore, it should be appreciated that modules and / or other means suitable for carrying out the procedures and techniques described herein can be downloaded and / or otherwise obtained by a user terminal and / or a base station, depending on corresponds. Alternatively, various methods described herein may be provided by storage media (eg, RAM, ROM, a physical storage medium such as a compact disk (CD) or floppy disk, etc.). In addition, any other suitable technique may be used to provide the procedures and techniques described herein to a device.
It should be understood that the claims are not limited to the precise configuration and components illustrated above. The above description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the disclosed embodiments. Although the foregoing is focused on aspects of the present disclosure, different and additional aspects of the disclosure can be envisaged without departing from the basic scope thereof, and the scope is determined by the following claims. Various modifications, changes, and variations may be made in the arrangement, operation, and details of the embodiments described herein without departing from the scope of the disclosure or claims.
Contents10
70 members in 13 offices
Priority claims15
| Document | Office | Kind | Date |
|---|---|---|---|
| 201161533627 | United States of America | P | |
| 201161533627P | United States of America | – | |
| 201161535234 | United States of America | P | |
| 201161535234P | United States of America | – | |
| 201261583052 | United States of America | P | |
| 201261583052P | United States of America | – | |
| 201261606794 | United States of America | P | |
| 201261606794P | United States of America | – | |
| 201261611553 | United States of America | P | |
| 201261611553P | United States of America | – | |
| 201261645987 | United States of America | P | |
| 201261645987P | United States of America | – | |
| 201213610738 | United States of America | A | |
| 201213610738 | United States of America | – | |
| 2012054879 | United States of America | W |
Members70
| Document | Office | Kind | |
|---|---|---|---|
| CA2846239A1 | Canada | A1 | |
| WO2013040039A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013040042A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013040046A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013040042A9 | World Intellectual Property Organization (WIPO) | A9 | |
| US2013243194A1 | United States of America | A1 | |
| US2013247150A1 | United States of America | A1 | |
| US2013263223A1 | United States of America | A1 | |
| CN103797830A | China | A | |
| CN103797831A | China | A | |
| CN103797832A | China | A | |
| KR20140066230A | Republic of Korea | A | |
| KR20140066231A | Republic of Korea | A | |
| KR20140066232A | Republic of Korea | A | |
| US2014162606A1 | United States of America | A1 | |
| US2014164763A1 | United States of America | A1 | |
| EP2756696A1 | European Patent Office (EPO) | A1 | |
| EP2756699A1 | European Patent Office (EPO) | A1 | |
| EP2756700A1 | European Patent Office (EPO) | A1 | |
| US8837741B2 | United States of America | B2 | |
| JP2014526841A | Japan | A | |
| JP2014527379A | Japan | A | |
| JP2014531812A | Japan | A | |
| EP2827527A1 | European Patent Office (EPO) | A1 | |
| EP2827630A1 | European Patent Office (EPO) | A1 | |
| KR101490214B1 | Republic of Korea | B1 | |
| IN1532CHN2014A | India | A | |
| JP5739072B2 | Japan | B2 | |
| US9143937B2 | United States of America | B2 | |
| RU2014114503A | Russian Federation | A | |
| CN103797830B | China | B | |
| US9226144B2 | United States of America | B2 | |
| KR20160012245A | Republic of Korea | A | |
| KR20160012246A | Republic of Korea | A | |
| JP5882474B2 | Japan | B2 | |
| RU2583722C2 | Russian Federation | C2 | |
| KR101631269B1 | Republic of Korea | B1 | |
| JP2016136723A | Japan | A | |
| JP2016136724A | Japan | A | |
| KR101648158B1 | Republic of Korea | B1 | |
| US9426648B2 | United States of America | B2 | |
| US9439067B2 | United States of America | B2 | |
| EP2756696B1 | European Patent Office (EPO) | B1 | |
| JP2017055407A | Japan | A | |
| BR112014005631A2 | Brazil | A2 | |
| BR112014005438A2 | Brazil | A2 | |
| EP2827630B1 | European Patent Office (EPO) | B1 | |
| ES2621990T3This record | Spain | T3 | |
| HUE031473T2 | Hungary | T2 | |
| CN107071771A | China | A | |
| KR101780252B1 | Republic of Korea | B1 | |
| KR101780290B1 | Republic of Korea | B1 | |
| ES2643290T3 | Spain | T3 | |
| CN107425961A | China | A | |
| JP6262308B2 | Japan | B2 | |
| CN103797831B | China | B | |
| CA2846239C | Canada | C | |
| JP6293800B2 | Japan | B2 | |
| HUE035780T2 | Hungary | T2 | |
| CN103797832B | China | B | |
| JP6382241B2 | Japan | B2 | |
| EP2756700B1 | European Patent Office (EPO) | B1 | |
| MY169634A | Malaysia | A | |
| BR122015024135A2 | Brazil | A2 | |
| BR122015024143A2 | Brazil | A2 | |
| EP2756699B1 | European Patent Office (EPO) | B1 | |
| HUE049022T2 | Hungary | T2 | |
| CN107071771B | China | B | |
| ES2802153T3 | Spain | T3 | |
| CN107425961B | China | B |
Numbers
- Publication
- 2621990
- Application
- 12766259
Titles2
- Spanish
- Sistema y procedimientos para codificar intercambios con un conjunto de datos de clave efímera compartida
- English
- System and procedures for coding exchanges with a shared ephemeral key data set
Classification
- CPC, 7
- H04L9/0841
- H04W12/04
- H04L63/067
- H04L2209/80
- H04W12/041
- H04W12/0471
- H04L9/0838
- IPC, 3
- H04L29 06
- H04L9 08
- H04W12 04