Encryption key distribution method in radio network, and master unit and subunit
Abstract
Problem to be solved.To enable delivery of a different encryption key for each slave unit without limiting the number of connectable slave units, and to eliminate the need to connect to an authentication server each time an authentication process is performed. When a slave unit receives a beacon frame, the master unit address, master session key, expiration date, and encrypted master session key data block exist in the master unit database, and the expiration date is valid. Sends an authentication request frame containing an encrypted master session key data block to the master unit to start the authentication process, otherwise registers or updates the master unit address, and the slave unit is the authentication server. When the authentication server can access, the master session key corresponding to the master unit address registered in the master unit database, the expiration date of this master session key, and the encrypted master session key data block are acquired, and the parent is obtained. Register in the machine database. [Selection diagram] Fig. 4

Term
Term ended
Projected expiry passed 7 January 2025, 1.7 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
4 claims: 3 independent, 1 dependent
- 1少なくとも1台の子機が親機を介して外部ネットワークに接続し、前記親機が親機アドレスを含むビーコンフレームを定期的に送信する無線ネットワークにおける暗号鍵の配送方法において、 前記子機は、前記ビーコンフレームを受信したときに、前記親機アドレスと、この親機アドレスに対応するマスタセッション鍵と、このマスタセッション鍵の有効期限と、このマスタセッション鍵と有効期限を親機秘密鍵と暗号化アルゴリズムで暗号化した暗号化マスタセッション鍵データブロックが親機データベースに存在し、かつ前記有効期限が正当である場合は、前記暗号化マスタセッション鍵データブロックを含む認証要求フレームを前記親機に送信して認証処理を開始し、前記親機アドレスまたは親機アドレスに対応する暗号化マスタセッション鍵データブロックが親機データベースに存在しない場合あるいは前記有効期限が正当でない場合は、その親機アドレスを登録または更新し、 さらに、前記子機は、認証サーバへアクセス可能なときに前記認証サーバから、前記親機データベースに登録された親機アドレスに対応するマスタセッション鍵と、このマスタセッション鍵の有効期限と、前記暗号化マスタセッション鍵データブロックとを取得し、前記親機データベースに登録する ことを特徴とする無線ネットワークにおける暗号鍵の配送方法。
- 2請求項1に記載の無線ネットワークにおける暗号鍵の配送方法において、 前記親機は、前記子機から送信された前記認証要求フレームを受信し、認証要求フレームに含まれる暗号化マスタセッション鍵データブロックを復号し、それが正当である場合に、前記子機のアドレスとその内容を保存し、所定の疑似乱数値aを含めて暗号化した第1の認証応答フレームを送信し、 前記子機は、前記第1の認証応答フレームを受信し、その暗号化部分を共通鍵暗号アルゴリズムとマスタセッション鍵により復号して疑似乱数値a'を取得し、この疑似乱数値a'と所定の疑似乱数値bを含めて暗号化した第2の認証応答フレームを送信し、 前記親機は、前記第2の認証応答フレームを受信し、その暗号化部分を共通鍵暗号アルゴリズムと前記子機に対応するマスタセッション鍵により復号して疑似乱数値a',b'を取り出し、疑似乱数値a'と自己の生成した疑似乱数値aと比較して一致する場合に、疑似乱数値b'を含めて暗号化した第3の認証応答フレームを送信し、 前記子機は、前記第3の認証応答フレームを受信し、その暗号化部分を共通鍵暗号アルゴリズムとマスタセッション鍵により復号して疑似乱数値b'を取り出し、疑似乱数値b'と自己の生成した疑似乱数値bと比較して一致する場合に、疑似乱数値を含めて暗号化した第4の認証応答フレームを送信し、 前記親機は、前記第4の認証応答フレームを受信し、その暗号化部分を共通鍵暗号アルゴリズムと前記子機に対応するマスタセッション鍵により復号して親機と子機との間の相互認証を完了する ことを特徴とする無線ネットワークにおける暗号鍵の配送方法。
- 3少なくとも1台の子機が親機を介して外部ネットワークに接続し、前記親機が親機アドレスを含むビーコンフレームを定期的に送信する無線ネットワークの子機において、 前記ビーコンフレームを受信する手段と、 前記親機アドレスと、この親機アドレスに対応するマスタセッション鍵と、このマスタセッション鍵の有効期限と、このマスタセッション鍵と有効期限を親機秘密鍵と暗号化アルゴリズムで暗号化した暗号化マスタセッション鍵データブロックを登録可能な親機データベースと、 前記ビーコンフレームから前記親機アドレスを抽出し、前記親機データベースに前記親機アドレスが登録されていなれば登録する処理を行い、前記親機データベースに前記親機アドレスが登録され、かつ前記親機アドレスに対応する暗号化マスタセッション鍵データブロックが登録されていない場合あるいはマスタセッション鍵の有効期限が正当でない場合は前記親機アドレスを更新する処理を行い、前記親機データベースに前記親機アドレスに対応する暗号化マスタセッション鍵データブロックが登録され、かつマスタセッション鍵の有効期限が正当である場合は、この暗号化マスタセッション鍵データブロックを含む認証要求フレームを前記親機に送信する手段と を備えたことを特徴とする無線ネットワークの子機。
- 4少なくとも1台の子機が親機を介して外部ネットワークに接続し、前記親機が親機アドレスを含むビーコンフレームを定期的に送信する無線ネットワークの親機において、 前記ビーコンフレームを送信する手段と、 前記子機から送信された認証要求フレームを受信する手段と、 前記認証要求フレームに含まれる暗号化マスタセッション鍵データブロックを抽出し、復号する手段と、 復号されたマスタセッション鍵データブロックの正当性を検証し、正当である場合に認証処理を継続する手段と を備えたことを特徴とする無線ネットワークの親機。
Independent claims4
38 paragraphs, as filed
The present invention relates to a delivery method of an encryption key used for authentication or encryption between a master unit and a slave unit in a wireless network such as a wireless LAN, a master unit and a slave unit.
In recent years, a hotspot service has been provided in which users download electronic data such as news using wireless LAN in station premises. However, since wireless LAN is easy to spoof and eavesdrop due to the nature of the medium, other party authentication and communication data encryption are performed, and various key sharing means for that purpose have been proposed.
For example, in the WEP (Wired Equivalent Privacy) specification of the wireless LAN standard IEEE 802.11a / b / g, the master unit (AP: Access Point) and slave unit (STA: Station) manually set a fixed-length common encryption key in advance. Key sharing is performed by setting (Non-Patent Document 1). Since the master unit shares the same common encryption key among a plurality of slave units, it is possible for another slave unit to decrypt the communication data encrypted by one slave unit.
In addition, there is an IEEE 802.1X standard as a conventional example in which a different encryption key is shared by each slave unit. In this method, each time authentication is performed, the authentication server (AS: Authentication Server) is connected, and the authentication server issues a different key for each slave unit to share the key (Non-Patent Document 1).<nplcit num="1"><text>Supervision: Hideaki Matsue, Masahiro Morikura, IDG Information and Communication Series 802.11 High Speed Wireless LAN Textbook, IDG Japan, published March 28, 2003</text></nplcit>
<p> By the way, although the WEP specification enables high-speed authentication processing, other slave units cannot be authenticated / encrypted because the master unit uses the same common encryption key among multiple slave units. There is an inconvenience that "spoofing" can be done by. In addition, in the self-evident solution in which the master unit manually sets a different common encryption key for each slave unit, the number of slave units that can be connected is limited due to the memory limitation of the master unit.</p><p> Further, in the authentication using the IEEE 802.1X standard, since it is necessary to connect to the authentication server every time the authentication process is performed, the authentication process is delayed due to the processing delay of the authentication server and the transmission delay in the transit network. In that case, it is not possible to sufficiently meet the demand that users who do not have time to spare, such as during commuting, want to download electronic data promptly. In addition, the hotspot service provided in the station yard often connects to the same base unit as the previously connected base unit during commuting, but the authentication procedure does not change even in such a usage environment.</p><p> In consideration of such a situation, the present invention does not limit the number of slave units that can be connected, enables delivery of a different encryption key for each slave unit, and does not require connection to an authentication server each time an authentication process is performed. It is an object of the present invention to provide a delivery method, a master unit and a slave unit of an encryption key in a wireless network.</p>
<p> The present invention relates to a method of delivering an encryption key in a wireless network in which at least one slave unit connects to an external network via the master unit and the master unit periodically transmits a beacon frame including the master unit address. When the beacon frame is received, the master unit address, the master session key corresponding to this master unit address, the expiration date of this master session key, and this master session key and expiration date are encrypted with the master unit private key. If the encrypted master session key data block encrypted by the encryption algorithm exists in the master unit database and the expiration date is valid, an authentication request frame containing the encrypted master session key data block is sent to the master unit. The authentication process is started, and if the master unit address or the encrypted master session key data block corresponding to the master unit address does not exist in the master unit database or the expiration date is not valid, the master unit address is registered or updated, and the master unit address is registered or updated. Furthermore, when the slave unit can access the authentication server, the master session key corresponding to the master unit address registered in the master unit database from the authentication server, the expiration date of this master session key, and the encrypted master session key Acquire the data block and register it in the master unit database.</p><p> The slave unit of the wireless network in the present invention has a means for receiving a beacon frame, a master unit address, a master session key corresponding to this master unit address, an expiration date of this master session key, and this master session key and validity. The master unit database that can register the encrypted master session key data block whose expiration date is encrypted with the master unit private key and the encryption algorithm, and the master unit address is extracted from the beacon frame and the master unit address is registered in the master unit database. If not, the process of registration is performed, and if the master unit address is registered in the master unit database and the encrypted master session key data block corresponding to the master unit address is not registered, or the expiration date of the master session key is not valid. In this case, the process of updating the master unit address is performed, and if the encrypted master session key data block corresponding to the master unit address is registered in the master unit database and the expiration date of the master session key is valid, this encryption is performed. A means for transmitting an authentication request frame including a master session key data block to a master unit is provided.</p><p> The master unit of the wireless network in the present invention extracts the means for transmitting the beacon frame, the means for receiving the authentication request frame transmitted from the slave unit, and the encrypted master session key data block included in the authentication request frame. It is provided with a means for decrypting and a means for verifying the validity of the decrypted master session key data block and continuing the authentication process when it is valid.</p>
<p> In the present invention, when the slave unit performs the authentication request operation, the slave unit receives the beacon frame transmitted by the master unit, acquires the master unit address included in the beacon frame, and the master unit address and the corresponding master session key are the master unit. If it is in the database and the expiration date of the master session key is valid, the authentication request operation is started. If not, only the master unit address is registered or updated.</p><p> On the other hand, when the master unit performs the authentication request operation, it receives the authentication request frame sent by the slave unit, acquires the encrypted master session key data block included in the authentication request frame, decrypts it, and verifies its validity. If this is valid, the authentication process is continued, and if it is not valid, the authentication process is stopped.</p><p> This makes it difficult to spoof by another slave unit while reducing the memory capacity of the master unit in an environment where there are many opportunities to connect to the previously connected master unit or slave unit, and realizes high-speed authentication processing. Can be done.</p>
FIG. 1 shows a configuration example of a wireless network to which the present invention is applied. Here, a wireless LAN consisting of a master unit (AP) 10, a slave unit (STA) 20, and an authentication server 30 is assumed. The master unit 10 is provided with a wireless communication interface for wireless communication with the slave unit 20, and further has a wired communication interface for connecting to the Internet 40, and controls access of the slave unit 20 to the authentication server 30 via the Internet 40. It is a composition.
FIG. 2 shows a configuration example of the master unit 10. In the figure, the master unit 10 includes a wired communication unit 11 including a wired communication interface and a wireless communication unit 12 including a wireless communication interface, and further performs control processing including authentication processing via the wired communication unit 11 and the wireless communication unit 12. It is provided with a control unit 13 for performing operation and a non-volatile memory 14 for holding a master unit private key used for authentication. The master unit private key is distributed from the authentication server and differs for each master unit. Therefore, it is difficult for another master unit or slave unit to decrypt the data encrypted by the master unit private key. The wireless communication unit 12 performs wireless communication with the slave unit based on, for example, the modulation method (CCK method) of IEEE802.1b, but other modulation methods may be used.
FIG. 3 shows a configuration example of the slave unit 20. In the figure, the slave unit 20 includes a wired communication unit 21 including a wired communication interface and a wireless communication unit 22 including a wireless communication interface, and further performs control processing including authentication processing via the wired communication unit 21 and the wireless communication unit 22. It is provided with a control unit 23 for performing operation, a non-volatile memory 24 for holding a master database (APDB) used for authentication, and a magnetic disk 25 for storing received data. The wireless communication unit 22 performs wireless communication with each master unit, and the master unit ID included in the received beacon frame is processed by the control unit 23 and registered in the master unit database. The wired communication unit 21 is used for connecting to an authentication server and a wired LAN.
<Authentication sequence> Regarding the authentication sequence in the master unit (AP) 10, slave unit (STA) 20, and authentication server 30, the slave unit authentication flowchart shown in FIG. 4, the master unit authentication flowchart shown in FIG. 5, and the authentication in FIG. 6 This will be described with reference to the sequence. Figure 7 shows the format of the MAC frame related to the authentication process. This MAC frame format is almost the same as the MAC frame format used in IEEE 802.11. Figure 8 shows the format of the encrypted master session key data block (MSK block).
The master unit (AP) periodically transmits a beacon frame (indicator signal) and waits for an authentication request frame transmitted from the slave unit (STA) (Fig. 5: S51). The header of the beacon frame contains the MAC address of the master unit as shown in FIG.
When the slave unit (STA) receives the beacon frame from the reception waiting state of the beacon frame (Fig. 4: S41, S42), it refers to the source address field included in the beacon frame and acquires the MAC address of the master unit (Fig. 4: S41, S42). Figure 4: S43). Next, it is determined whether or not the MAC address and the MSK block corresponding to this MAC address exist in the master database (Fig. 4: S44). Here, if the MAC address or the MSK block corresponding to the MAC address does not exist in the base unit database, the process of registering / updating the MAC address in the base unit database is performed, and the procedure of the authentication process is stopped (Fig. 4). : S45). The same applies when the expiration date of the master session key corresponding to the MAC address is not valid.
On the other hand, if the MAC address, the master session key corresponding to this MAC address, the expiration date of this master session key, and the MSK block are all present in the master database and the expiration date is valid, authentication processing is performed. Is started and an authentication request frame is sent to the master unit (Fig. 4: S46). The validity of the expiration date means that the timer value provided in the slave unit is equal to or greater than the value indicating the start of the expiration date and equal to or less than the value indicating the end of the expiration date.
As shown in FIG. 7, this authentication request frame includes an MSK block in addition to a header, an authentication algorithm number, an authentication processing sequence number (atsn: Authentication Transaction Sequence Number = 1), and a status code. As shown in Fig. 8, this MSK block has the master session key, expiration date, and MAC address of the slave unit as the common key cryptographic algorithm Fe and the master unit private key K.<u style="single"></u>It is encrypted by ap.
When the master unit (AP) receives the authentication request frame transmitted from the slave unit (STA) (Fig. 5: S52), it acquires the MSK block included in the authentication request frame and uses the MSK block as the common key decryption algorithm Fd. Master unit private key K<u style="single"></u>Decrypt by ap (Fig. 5: S53). Examples of the common key encryption / decryption algorithm include AES and Triple-DES. Next, the validity of the obtained MSK block is verified (Fig. 5: S54), and if this is valid, the authentication process is continued (Fig. 5: S55), and if it is not valid, the authentication process is stopped. ..
Here, the validity of the MSK block is determined by the following conditions. (1) The slave unit MAC address of the MSK block matches the slave unit MAC address in the source address field included in the header of the authentication request frame, and (2) the timer value provided by the master unit indicates the start of the expiration date. It is greater than or equal to the value and less than or equal to the value indicating the end of the expiration date.
When the master unit (AP) determines that the MSK block included in the authentication request frame satisfies the above conditions and is valid, the master unit (AP) retains the contents of the MSK block together with the MAC address of the slave unit in the authentication slave unit database and makes an authentication response. Generate a frame (atsn = 2). As shown in Fig. 7, the authentication response frame (atsn = 2) includes the initialization vector (IV: Initialization Vector), authentication algorithm number, authentication processing sequence number, status code, and challenge text 1 generated by the master unit. Includes (pseudo-random numbers). The range from this initialization vector to the challenge text 1 is the range to be encrypted, which is encrypted by the common key encryption algorithm and the master session key, and sent to the slave unit. In FIG. 7, this encryption range is shown by hatching.
When the slave unit (STA) receives the authentication response frame (atsn = 2), it decrypts the encrypted part of the authentication response frame (atsn = 2) using the common key cryptographic algorithm and the master session key, and outputs the challenge text 1'. After getting it, generate an authentication response frame (atsn = 3). The authentication response frame (atsn = 3) includes the challenge text 1'and the challenge text 2 (pseudo-random number) generated by the slave unit, and is transmitted to the master unit. The range from the initialization vector to the challenge text 2 is encrypted, and is encrypted by the common key encryption algorithm and the master session key extracted from the master database.
When the master unit (AP) receives the authentication response frame (atsn = 3), the encrypted part of the authentication response frame (atsn = 3) is subjected to the common key encryption algorithm and the master session key (MSK) corresponding to the slave unit. Decrypt, extract challenge text 1'and compare it with self-generated challenge text 1. If they do not match, the slave unit is regarded as invalid and the authentication process is stopped. If they match, the challenge text 2'included in the authentication response frame (atsn = 3) is included in the authentication response frame (atsn = 4), encrypted by the common key cryptographic algorithm and the master session key (MSK), and sent to the slave unit. Send.
When the slave unit (STA) receives the authentication response frame (atsn = 4), it decrypts the encrypted part of the authentication response frame (atsn = 4) using the common key cryptographic algorithm and the master session key, and outputs the challenge text 2'. Take it out and compare it with the self-generated challenge text 2. If they do not match, the master unit is regarded as invalid and the authentication process is stopped. If they match, an authentication response frame (atsn = 5) including a seed value that is a pseudo-random number is generated, encrypted by the common key cryptographic algorithm and the master session key, and sent to the master unit.
When the master unit (AP) receives the authentication response frame (atsn = 5), it decrypts the encrypted part of the authentication response frame (atsn = 5) using the common key encryption algorithm and the master session key corresponding to the slave unit. As a result, it is assumed that mutual authentication has been completed between the master unit and the slave unit, and the authentication completed slave unit registration request signal and the authentication completed slave unit registration response signal are transmitted and received between the master unit and the authentication server for data communication. To start. For this data communication, the Seed value obtained from the authentication response frame (atsn = 5) and the result of performing an operation on it are used as the encryption key K.<u style="single"></u>Used as tmp.
<Connection between the slave unit and the authentication server> The connection method between the slave unit 20 and the authentication server 30 will be described with reference to FIG. The slave unit 20 makes an HTTP connection from the wired connection unit to the authentication server 30 on the Internet 40 via a wired LAN (Ethernet (registered trademark)) 41 and a router 42. The authentication server 30 displays the authentication screen on the web browser and requests the user name and password from the slave unit 20. When the authentication server 30 determines that the user name and password are valid, it requests the slave unit 20 for the slave unit MAC address and the master unit MAC address existing in the master unit database. When the slave unit 20 receives the request, the slave unit 20 transmits the master unit MAC address to the authentication server 30.
The authentication server 30 generates a master session key corresponding to each master unit MAC address existing in the master unit database. Further, the authentication server 30 generates an MSK block (encrypted master session key data block) encrypted with each master unit private key, and sets the master session key and the MSK block corresponding to each master unit MAC address to the slave unit 20 respectively. Send to. The slave unit 20 registers each received MSK block in the master unit database, and updates the master session key column and the expiration date column. The connection method between the authentication server 30 and the slave unit 20 is not limited to this example, and the authentication server 30 may have some means for authenticating the slave unit 20.
<Master unit database> The details of the master unit database held by the slave unit 20 will be described with reference to FIG. The master database contains each master for each master MAC address, master session key, expiration date (start, end), encrypted master session key data block (MSK block), number of accesses, total communication time, and beacon reception time. Each machine has a field to hold. The maximum number of master units that can be registered (Nreg max) is, for example, 16. The number of master units that can be registered depends on the non-volatile memory capacity of the slave unit, and may be another finite value. Further, when a large-capacity magnetic disk is used as the non-volatile memory, the number of master units that can be registered can be very large.
Here, the meaning of each column of the master unit database will be described. The base unit MAC address field holds the base unit address (source address) included in the beacon frame.
The master session key column and expiration date column hold the master session key and expiration date (start, end) included in the encrypted master session key data block (MSK block) acquired by the slave unit from the authentication server.
Similarly, the encrypted master session key data block (MSK block) field holds the MSK block acquired from the authentication server.
The access count column records the number of times the slave unit has completed mutual authentication with the master unit. That is, when transmitting the authentication response frame (atsn = 5), the value in the access count column corresponding to the corresponding master unit is incremented by 1.
The total communication time column holds the total number of beacon frames received by the slave unit from the master unit. Increases by 1 each time a beacon frame is received from the corresponding master unit.
The beacon reception time column records the time when the beacon frame of the corresponding master unit is received. This time is the timer value of the timer provided in the slave unit. Also, it is updated every time a beacon frame is received.
Next, the conditions for the slave unit to perform the master unit MAC address registration / update determination process will be described. (1) If the base unit MAC address (MAC now) is already registered in the base unit database, update processing is performed. (2) The master unit MAC address (MAC now) is not registered in the master unit database, and the total number of master units (Nreg) registered in the master unit database is smaller than the maximum number of master units that can be registered (Nreg max). When, the master unit MAC address (MAC now) is newly registered in the master unit database. (3) If the base unit MAC address (MAC now) is not registered in the base unit database and Nreg = Nreg max, select one base unit arbitrarily and delete the base unit from the base unit database. , Register the base unit MAC address (MAC now) in the base unit database.
For new registration, enter invalid values in the master session key column, expiration date column, and MSK block column, and set the address count column and total communication time column to 0.
In addition, the conditions for the slave unit to perform the MAC address registration / update determination process of the master unit are not limited to the above, and for example, by using the following conditions (3) to (5) for (3) above, the parent unit It is possible to improve the retention efficiency of the machine MAC address.
(3) When the base unit MAC address (MAC now) is not registered in the base unit database and Nreg = Nreg max, the base unit group (TtcMinAP Group) with the smallest total communication time column is extracted, and the TtcMinAP Group If the number of components is 1, after deleting the master unit from the master unit database, the master unit MAC address (MAC now) is newly registered in the master unit database. (4) When the number of components of TtcMinAP Group is 2 or more, the master unit group (TtcMinAndNaMinAP Group) with the smallest number of accesses is extracted, and when the number of components of TtcMinAndNaMinAP Group is 1, that master unit is used as the master unit. After deleting from the database, newly register the master unit MAC address (MAC now) in the master unit database. (5) When the number of components of TtcMinAndNaMinAP Group is 2 or more, arbitrarily select one master unit from them, delete the master unit from the master unit database, and then set the master unit MAC address (MAC now). Newly register in the base unit database.
<figref num="1">The figure which shows the configuration example of a wireless network.</figref><figref num="2">The figure which shows the configuration example of the master unit 10.</figref><figref num="3">The figure which shows the configuration example of the slave unit 20.</figref><figref num="4">A flowchart showing the authentication processing procedure of the slave unit.</figref><figref num="5">A flowchart showing the authentication processing procedure of the master unit.</figref><figref num="6">The figure which shows the authentication sequence.</figref><figref num="7">The figure which shows the format of the authentication frame.</figref><figref num="8">The figure which shows the format of the master session key data block.</figref><figref num="9">The figure which shows the connection example of a slave unit and an authentication server.</figref><figref num="10">The figure which shows the content example of the master unit database.</figref>
Code description
10 Master unit (AP) 11 Wired connection unit 12 Wireless connection unit 13 Control unit 14 Non-volatile memory 20 Slave unit (STA) 21 Wired connection unit 22 Wireless connection unit 23 Control unit 24 Non-volatile memory (APDB) 25 Magnetic disk 30 Authentication server 41 Wired LAN 42 Router 40 Internet
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2018026733A | Cited by | Japan | Search report |
| JPWO2016043054A1 | Cited by | Japan | Search report |
| WO2015121988A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JPWO2015121988A1 | Cited by | Japan | Search report |
| WO2016043054A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2006211588A | Cited by | Japan | Examiner |
| US10506430B2 | Cited by | United States of America | Applicant |
2 members in 1 office
Members2
| Document | Office | Kind | |
|---|---|---|---|
| JP2006191452AThis record | Japan | A | |
| JP4071774B2 | Japan | B2 |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 2006191452
- Application
- 2527
Titles2
- Japanese
- 無線ネットワークにおける暗号鍵の配送方法、親機および子機
- English
- Encryption key delivery method in wireless network, master unit and slave unit
Classification
- IPC, 1
- H04L9 08