Method for security information configuration wlan
Abstract
In a communication system including a device, an access point (AP) communicating with the device, and a mobile terminal communicating with the device and the AP, the device and the AP share a device key, which is a shared secret key to be used in wireless LAN communication suggest a way to To this end, the present invention enables one-way function operation by attaching a one-way function operation module to each device constituting a communication system. As described above, by performing a one-way function operation on data transmitted and received using the one-way function operation module, a third party can stably transmit and receive data through an attack.Device, mobile terminal, AP, authentication

Term
Term ended
Expired 25 April 2025, 1.4 years ago.
- Priority and filed
- Granted
- Expired
- Today
21 claims: 6 independent, 15 dependent
- 1디바이스와 상기 디바이스와 통신을 수행하는 엑세스 포인트(AP), 상기 디바이스와 AP와 통신을 수행하는 이동 단말을 포함하는 통신 시스템에서, 상기 이동 단말이 상기 AP와 비밀키를 공유하는 방법에 있어서, 상기 AP로 자신의 네트워크 정보가 포함된 비밀키 형성 요청 메시지를 전송하는 단계;상기 AP로부터 상기 AP의 네트워크 정보가 포함된 비밀키 형성 응답 메시지를 수신하는 단계;및 상기 AP의 네트워크 정보에 대응되는 비밀키를 생성하고, 생성된 상기 비밀키를 포함한 비밀키 형성 정보 메시지를 전송하는 단계;를 포함함을 특징으로 하는 상기 비밀키 공유 방법.
- 2제 1항에 있어서, 상기 이동 단말과 상기 AP는 근거리 통신 채널을 이용하여 상기 메시지들을 송수신함을 특징으로 하는 상기 비밀키 공유 방법.
- 3제 1항에 있어서, 상기 기 저장된 비밀키가 있는 경우, 상기 비밀키 형성 정보 메시지는 상기 기 저장된 비밀키를 포함함을 특징으로 하는 상기 비밀키 공유 방법.
- 4제 3항에 있어서, 상기 비밀키 형성 응답 메시지를 수신하면, 기 설정된 카운터를 증가시키고, 상기 비밀키 형성 정보 메시지는 상기 증가된 카운터를 포함함을 특징으로 하는 상기 비밀키 공유 방법.
- 5제 3항에 있어서, 상기 기 저장된 비밀키가 상기 AP에 저장되어 있으면, 상기 AP로부터 생성한 상기 비밀키의 공유를 지시하는 비밀키 형성 종료 메시지를 수신함을 특징으로 하는 상기 비밀키 공유 방법.
- 6디바이스와 상기 디바이스와 통신을 수행하는 엑세스 포인트(AP), 상기 디바이스와 AP와 통신을 수행하는 이동 단말을 포함하는 통신 시스템에서, 상기 이동 단말이 상기 디바이스와 디바이스키를 공유하는 방법에 있어서, 상기 디바이스로 디바이스키 형성 요청 메시지를 전송하는 단계;상기 디바이스로부터 상기 디바이스의 네트워크 정보가 포함된 디바이스키 형성 응답 메시지를 수신하는 단계;및 저장된 비밀키와 카운터, 전달받은 상기 디바이스의 네트워크 정보를 이용하여 디바이스키를 생성하고, 생성된 상기 디바이스키를 포함한 디바이스키 형성 정보 메시지를 전송하는 단계;를 포함함을 특징으로 하는 상기 디바이스키 공유 방법.
- 7제 6항에 있어서, 상기 디바이스의 네트워크 정보는 상기 디바이스의 맥(MAC) 어드레스임을 특징으로 하는 상기 디바이스키 공유 방법.
- 8제 6항에 있어서, 상기 디바이스키 형성 정보 메시지는 이동 단말이 저장하고 있는 카운터, 상기 AP의 네트워크 정보를 포함함을 특징으로 하는 상기 디바이스키 공유 방법.
- 9제 6항에 있어서, 상기 이동 단말과 상기 디바이스는 적외선 통신 채널을 이용하여 상기 메시지들을 송수신함을 특징으로 하는 상기 디바이스키 공유 방법.
- 10디바이스와 상기 디바이스와 통신을 수행하는 엑세스 포인트(AP), 상기 디바이스와 AP와 통신을 수행하는 이동 단말을 포함하는 통신 시스템에서, 상기 디바이스가 상기 AP와 디바이스키를 공유하는 방법에 있어서, 임의의 생성한 랜덤1과 디바이스키를 생성하기 위한 자신의 맥 어드레스와 카운터가 포함된 WPA 형성 요청 메시지를 전달하는 단계;전달한 상기 랜덤1을 일방향 함수 연산한 제1일방향 함수 연산값과 임의로 생성한 랜덤2가 포함된 인증 WPA 형성 요청 메시지를 수신하는 단계;및 상기 랜덤1을 일방향 함수 연산한 값이 상기 제1일방향 함수 연산값과 동일하면, 전달받은 상기 랜덤2를 일방향 함수 연산한 제2일방향 함수 연산값이 포함된 인증 WPA 형성 응답 메시지를 전달하는 단계;를 포함함을 특징으로 하는 상기 디바이스키 공유 방법.
- 11제 10항에 있어서, 상기 전달한 카운터와 맥 어드레스를 이용하여 디바이스키가 생성되고, 상기 생성된 디바이스키와 랜덤1을 이용하여 상기 제1일방향 함수 연산값을 산출함을 특징으로 하는 상기 디바이스키 공유 방법.
- 12제 10항에 있어서, 상기 전달받은 랜덤2와 기 저장된 디바이스키를 이용하여 상기 제2일방향 함수 연산값을 산출함을 특징으로 하는 상기 디바이스키 공유 방법.
- 13제 10항에 있어서, 기 저장된 상기 랜덤2를 일방향 함수 연산한 값이 상기 전달받은 제2일방향 함수 연산값과 동일하면, 상기 AP는 상기 디바이스키의 공유를 지시하는 WPA 형성 종료 메시지를 상기 디바이스로 전달함을 특징으로 하는 상기 디바이스키 공유 방법.
- 14디바이스와 상기 디바이스와 통신을 수행하는 엑세스 포인트(AP), 상기 디바이스와 AP와 통신을 수행하는 이동 단말을 포함하는 통신 시스템에서, 상기 이동 단말이 디바이스에 저장된 디바이스키의 폐기를 지시하는 방법에 있어서, 임의로 생성한 랜덤a와 상기 AP의 네트워크 정보가 포함된 디바이스키 폐기 요청 메시지를 전달하는 단계;상기 랜덤a와 기 저장된 디바이스키를 일방향 연산한 제a일방향 함수 연산값과 임의로 생성한 랜덤b, 상기 디바이스의 네트워크 정보가 포함된 인증 디바이스키 폐기 요청 메시지를 수신하는 단계;및 기 저장된 비밀키와 전달받은 상기 디바이스의 네트워크 정보를 이용하여 상기 디바이스키를 생성하고, 상기 생성한 디바이스키와 상기 랜덤a를 일방향 연산한 값이 상기 제a일방향 함수 연산값과 동일하면, 전달받은 랜덤b를 일방향 함수 연산한 제b일방향 함수 연산값이 포함된 인증 디바이스키 폐기 응답 메시지를 전달하는 단계;를 포함함을 특징으로 하는 상기 디바이스키 폐기 지시 방법.
- 15제 14항에 있어서, 상기 디바이스는 기 저장된 상기 디바이스키와 랜덤b를 일방향 연산한 값이 상기 제b일방향 함수 연산값과 동일하면, 상기 디바이스키를 폐기함을 특징으로 하는 상기 디바이스키 폐기 지시 방법.
- 16제 14항에 있어서, 상기 이동 단말과 상기 디바이스는 근거리 통신 채널을 이용하여 상기 메시지들을 송수신함을 특징으로 하는 상기 디바이스키 폐기 지시 방법.
- 17디바이스와 상기 디바이스와 통신을 수행하는 엑세스 포인트(AP), 상기 디바이스와 AP와 통신을 수행하는 이동 단말을 포함하는 통신 시스템에서, 상기 이동 단말이 AP에 저장된 디바이스키의 폐기를 지시하는 방법에 있어서, 임의로 생성한 랜덤c와 상기 디바이스의 네트워크 정보가 포함된 WPA 폐기 요청 메시지를 전달하는 단계;상기 랜덤c와 기 저장된 디바이스키를 일방향 연산한 제c일방향 함수 연산값과 임의로 생성한 랜덤d가 포함된 인증 WPA 폐기 요청 메시지를 수신하는 단계;및 기 저장된 상기 디바이스키와 전달받은 상기 랜덤c를 일방향 연산한 값이 전달받은 상기 제c일방향 함수 연산값과 동일하면, 전달받은 상기 랜덤d를 일방향 함수 연산한 제d일방향 함수 연산값이 포함된 인증 WPA 폐기 응답 메시지를 전달하는 단계;를 포함함을 특징으로 하는 상기 디바이스키 폐기 지시 방법.
- 18제 17항에 있어서, 상기 AP는 기 저장된 상기 디바이스키와 랜덤d를 일방향 연산한 값이 전달받은 상기 제d일방향 함수 연산값과 동일하면, 상기 디바이스키를 폐기함을 특징으로 하는 상기 디바이스키 폐기 지시 방법.
- 19디바이스와 상기 디바이스와 통신을 수행하는 엑세스 포인트(AP), 상기 디바이스와 AP와 통신을 수행하는 이동 단말을 포함하는 통신 시스템에서, 상기 이동 단말이 상기 AP와 비밀키를 공유하는 방법에 있어서, 상기 AP로 자신의 네트워크 정보가 포함된 비밀키 형성 요청 메시지를 전송하는 단계;및 상기 AP로부터 AP의 네트워크 정보에 대응되는 비밀키가 포함된 비밀키 형성 정보 메시지를 전송하는 단계;를 포함함을 특징으로 하는 상기 비밀키 공유 방법.
- 20제 19항에 있어서, 상기 이동 단말과 상기 AP는 근거리 통신 채널을 이용하여 상기 메시지들을 송수신함을 특징으로 하는 상기 비밀키 공유 방법.
- 21제 19항에 있어서, 상기 기 저장된 비밀키가 있는 경우, 상기 비밀키 형성 정보 메시지는 상기 기 저장된 비밀키를 포함함을 특징으로 하는 상기 비밀키 공유 방법.
Independent claims21
8 paragraphs, as filed
Method for security information configuration in WLAN
1 is a diagram illustrating a wireless LAN including a mobile terminal, a device, and an AP according to an embodiment of the present invention;
2 is a diagram illustrating a process of sharing a secret key between a mobile terminal and an AP according to an embodiment of the present invention;
3 is a diagram illustrating a process of sharing a device key between a device and an AP according to an embodiment of the present invention, and
4 is a diagram illustrating a process of discarding stored information by a device and an AP according to an embodiment of the present invention.
<backgroundart><p>The present invention relates to a method of forming security information in a wireless LAN, and more particularly, to a method of forming security information between a device constituting a wireless LAN and an AP.</p><p> Currently, the Internet connection using a wired LAN used in each office or school is rapidly changing to a wireless communication using an 802.11 wireless LAN or Bluetooth or infrared communication. Wireless LAN is also called Wi-Fi because it makes the wireless network more convenient to use like hi-fi audio. A wireless LAN can use high-speed Internet through a PDA or a laptop computer within a certain distance from where an access point (AP) is installed. Because wireless LAN uses wireless resources, there is no need for a telephone line or a dedicated line, but a wireless LAN card must be installed in a PDA or notebook computer. Also, in the early days of wireless LAN, the reach of radio waves was only 10m, but in the 2000s, it increased to about 50~200m. In addition, it is possible to send and receive large-capacity multimedia information using a wireless LAN with a transmission speed of 4 to 11 Mbps.</p><p>Moreover, as the demand for high-speed wireless Internet is rapidly growing, the existing wireless LAN is becoming an alternative as the infrastructure of the high-speed wireless public network. The reason why wireless LAN is highlighted is because it is expected that it can overcome the low transmission speed of mobile communication systems and that secure communication of wireless LAN users can be ensured as security technology is actively developed. In particular, the wireless LAN security technology is a task that must be solved along with the improvement of the transmission speed in the wireless section.</p><p>As described above, the device constituting the wireless LAN performs communication with an external network or other device using radio resources. In general, wireless resources are more easily exposed to third-party attacks than wired resources. Therefore, there is a need for a method for safely performing communication between a device and an AP from a third party's attack.</p></backgroundart><abstractproblem><p>An object of the present invention to solve the above problem is to propose a method of sharing a device key to securely perform communication between a device and an AP from a third party attack.</p><p>Another object of the present invention is to propose a method of securely discarding a device key shared between a device constituting a wireless LAN and an AP.</p></abstractproblem>
<p>In order to achieve the above objects, the present invention provides a communication system including a device, an access point (AP) communicating with the device, and a mobile terminal communicating with the device and the AP, wherein the mobile terminal is secretly communicated with the AP. A method of sharing a key, comprising: transmitting a secret key formation request message including its own network information to the AP; receiving a secret key formation response message including network information of the AP from the AP; and generating a secret key corresponding to the network information of the AP, and transmitting a secret key formation information message including the generated secret key.</p><p>In order to achieve the above objects, the present invention provides a communication system including a device, an access point (AP) communicating with the device, and a mobile terminal communicating with the device and the AP, wherein the mobile terminal is the device and the device A method for sharing a key, the method comprising: transmitting a device key formation request message to the device; Receiving a device key formation response message including network information of the device from the device; and generating a device using the stored secret key and counter, and the received network information of the device, and transmitting a device key formation information message including the generated device key. suggest a way</p><p>In order to achieve the above objects, the present invention provides a device and an access point (AP) for communicating with the device, and in a communication system including a mobile terminal for communicating with the device and the AP, the device is the AP and the device key In the method of sharing, transmitting a WPA formation request message including a randomly generated random 1, own MAC address for generating a device key, and a counter; receiving an authentication WPA formation request message including a first one-way function calculation value obtained by performing a one-way function operation on the delivered random 1 and randomly generated random 2; and when the value obtained by performing a one-way function operation on the random 1 is the same as the first one-way function operation value, transmitting an authentication WPA formation response message including a second one-way function operation value obtained by performing a one-way function operation on the random 2 ; proposes the device key sharing method comprising a.</p><p>In order to achieve the above object of the present invention, in a communication system comprising a device and an access point (AP) communicating with the device, and a mobile terminal communicating with the device and the AP, the mobile terminal is a device stored in the device A method for instructing revocation of a key, the method comprising: transmitting a device key revocation request message including randomly generated random a and network information of the AP; receiving an authentication device key revocation request message including a first one-way function operation value obtained by one-way operation of the random a and a pre-stored device key, randomly generated random b, and network information of the device; and generating the device key using the previously stored secret key and the received network information of the device, and if the value obtained by one-way operation of the generated device key and the random a is the same as the one-way function operation value a, transfer Transmitting the authentication device key revocation response message including the b th one-way function operation value obtained by one-way function operation of the received random b; proposes the device key revocation instruction method comprising:</p><p>In order to achieve the above object of the present invention, in a communication system comprising a device and an access point (AP) communicating with the device, and a mobile terminal communicating with the device and the AP, the mobile terminal is a device stored in the AP A method for instructing revocation of a key, the method comprising: transmitting a WPA revocation request message including randomly generated random c and network information of the device; receiving an authentication WPA revocation request message including a c-th one-way function calculated by one-way operation of the random c and a pre-stored device key and a randomly generated random d; and if the value obtained by one-way operation of the previously stored device key and the received random c is the same as the received c-th one-way function operation value, a d-th one-way function operation value obtained by performing a one-way function operation on the received random d is included. It proposes a method for instructing revocation of the device key comprising; transmitting an authentication WPA revocation response message.</p><p>Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings.</p><p>1 illustrates devices constituting a wireless LAN according to an embodiment of the present invention. That is, the wireless LAN includes the device 102 , the AP 104 , and the mobile terminal (relay terminal) 100 . In general, a wireless LAN includes at least one device and at least one AP 104 , but FIG. 1 shows only one device 102 and one AP 104 for convenience of description. Hereinafter, the characteristics of each device constituting the wireless LAN will be described.</p><p>The mobile terminal 100 guarantees mobility, like a mobile phone or a PAD phone, and provides a user interface (UI). In addition, the mobile terminal 100 is capable of infrared communication by including an infrared communication module, and includes a one-way function algorithm module for key generation.</p><p>The device 102 performs wireless communication with the AP 104 using a wireless channel, and performs infrared communication with the mobile terminal 100 using an infrared channel. Of course, the infrared channel is also an example of a wireless channel, but hereinafter, the infrared channel and the wireless channel will be used separately. The device 102 includes an infrared communication module to perform infrared communication, and a one-way function algorithm module for key generation.</p><p>The AP 104 also includes an infrared communication module for performing infrared communication with the mobile terminal 100 . Hereinafter, a process of sharing a secret key between the AP 104 and the device 102 will be described with reference to FIGS. 2 to 3 .</p><p>2 is a process for sharing a secret key between the AP 104 and the mobile terminal 100 according to an embodiment of the present invention.</p><p>The mobile terminal 100 has an AP mode for communicating with the AP 104 and a device mode for communicating with the device 102 . The mobile terminal 100 converts the mode to the AP mode in order to share the secret key with the AP 104 . Also, the mobile terminal 100 initializes the stored parameter values before performing communication with the AP 104 . In connection with the present invention, the AP 104 initializes a counter, a service set identifier (SSID). The SSID is a unique identifier composed of 32 bytes constituting each header of packets transmitted through a wireless LAN. That is, when a plurality of APs constitute a wireless LAN, each AP has a unique SSID, and the device 102 performs wireless communication with a specific AP 104 using the SSID.</p><p>In step S200 , the mobile terminal 100 transmits a secret key formation request message (MKconfig_request message) and its own information to the AP 104 using an infrared channel. The secret key formation request message is a message requesting to start the secret key formation mode for secret key formation. Of course, the mobile terminal 100 and the AP 104 transmit and receive messages and necessary information using an infrared channel. Self information included in the secret key formation request message includes network information of the mobile terminal 100 .</p><p>Upon receiving the secret key formation request message, the AP 104 searches whether a secret key for the mobile terminal 100 is stored. In addition, the AP 104 searches for its own network information, the SSID.</p><p>In step S202, the AP 104 transmits a secret key formation response message including the SSID (MKconfig_response message) to the mobile terminal 100 using an infrared channel. The secret key formation response message is a message indicating that the AP 104 can receive a new secret key. Upon receiving the secret key formation response message, the mobile terminal 100 determines whether the same SSID as the received SSID is stored. If the same SSID as the received SSID is stored, a new secret key is generated and the generated secret key is stored. Of course, if the same SSID as the received SSID is stored, the mobile terminal 100 stores a secret key related to the stored SSID.</p><p>If the same SSID as the received SSID is not stored, a memory for the SSID is allocated, the received SSID is stored, a random secret key is generated, and the generated secret key is stored. Upon receiving the secret key formation response message, the mobile terminal 100 increments the counter by one. Of course, if the same SSID as the received SSID is not stored, the mobile terminal 100 does not store the SSID-related secret key.</p><p> In step S204 , the mobile terminal 100 transmits a secret key formation information message (MKconfig_info message) to the AP 104 using an infrared channel. The secret key formation information message includes an existing secret key and a newly generated (or randomly generated) secret key counter. Of course, when there is no existing secret key, that is, when the same SSID as the SSID received in step S202 is not stored, the mobile terminal 100 expresses information about the existing secret key as null.</p><p> Upon receiving the secret key formation information message, the AP 104 determines whether the transmitted existing secret key and the stored secret key are the same. If the received secret key and the stored secret key are the same, the AP 104 transmits the secret key formation end message (MKconfig_complete message) to the mobile terminal 100 by using an infrared channel in step S206 . Of course, the AP 104 updates the table using the information stored in the secret key formation message. The mobile terminal 100 having performed the above-described process notifies the user that the sharing of the secret key has ended. That is, by using the display unit, voice unit, vibrating unit, etc. of the mobile terminal 100, the user is notified that the sharing of the secret key has ended.</p><p>If the received secret key and the stored secret key are not the same, the AP 104 transmits a secret key formation failure message (MKconfig_failure message) to the mobile terminal 100 in step S206 .</p><p> Of course, the AP 104 recognizes that a third party is involved in sharing the secret key between the mobile terminal 100 and the AP 104 if the received counter is smaller than or equal to the stored counter. Accordingly, the AP 104 transmits the secret key formation end message only when the received counter is greater than the stored counter.</p><p> Although FIG. 2 shows that the mobile terminal generates the secret key, the AP may generate the secret key according to the user's setting. That is, upon receiving the secret key formation request message, the AP may generate a secret key using its own network information.</p><p>By performing the above-described process, the mobile terminal 100 and the AP 104 share a new secret key, and the mobile terminal 100 is switched to the device mode by the user. Also, the mobile terminal 100 and the AP 104 perform communication using an infrared channel, but the present invention is not limited thereto. That is, it is obvious that the mobile terminal 100 and the AP 104 can communicate using different short-range communication channels.</p><p>3 is a diagram illustrating a process of sharing a secret key between the device 102 and the AP 104 according to an embodiment of the present invention. Hereinafter, a process of sharing a secret key between the device 102 and the AP 104 according to an embodiment of the present invention will be described in detail with reference to FIG. 3 .</p><p>The mobile terminal 100 transmits a device key formation request message (DK (Device Key) config_request message) to the device 102 using an infrared channel in step S300 . For convenience of explanation, the secret key shared between the device and the AP is referred to as a device key. The device key formation request message is a message requesting transmission of configuration information. The mobile terminal 100 that has transmitted the device key formation request message increments the counter value by 1.</p><p>The device 102 transmits a device key formation response message (DKconfig_response message) to the mobile terminal 100 by using an infrared channel in step S302 . The device formation response message includes the MAC address of the device. Upon receiving the device formation response message, the mobile terminal 100 forms a device key using the stored secret key, the received MAC address, and the counter. The mobile terminal 100 notifies the user that an error has occurred if the device formation response message is not received within the set time.</p><p>The mobile terminal 100 transmits the device configuration information message (DKconfig_info message) to the device 102 using an infrared channel in step S304 . The device formation information message includes the device key generated in step S302, the SSID stored in the mobile terminal 100, and a counter. Upon receiving the device configuration information message, the mobile terminal 100 determines whether the same SSID as the received SSID is stored in the memory. If the same SSID as the received SSID is stored in the memory, the device 102 updates the memory using the received information. If the received SSID is not stored, the device 102 allocates a memory to store the received information, and stores the received information in the allocated memory.</p><p>The device 102 performing the above-described process transmits the device key formation complete message (DKconfig_complete message) to the mobile terminal 100 by using an infrared channel in step S306 . Of course, if an error occurs while performing the above-described process, the device 102 transmits a device key formation failure message (DKconfig_failure message) to the mobile terminal 100 using an infrared channel in step S306 . The device key formation failure message includes information on the cause of the error.</p><p>The device 102 having transmitted the device key formation completion message establishes a wireless channel for wireless communication with the AP 104 in step S308.</p><p>In step S310 , the device 102 transmits a WPA configuration request message (WPAconfig_request message) to the AP 104 . The WPA formation request message includes random 1 obtained from the device key corresponding to the same SSID as the SSID of the current channel, MAC address, and counter. Random 1 is a random value randomly generated by the device 102 .</p><p>Upon receiving the WPA formation request message, the AP 104 proceeds with the subsequent process only when the received counter is greater than the stored counter. That is, when the received counter is not greater than the stored counter, the AP 104 recognizes that it is a retransmission message. The AP 104 generates a device key using the received MAC address and counter. In addition, the AP 104 calculates a first one-way function calculation value, which is a value obtained by calculating the generated device key and the received random 1 as a one-way function. Also, the AP 104 generates random 2. Random 2 is a random value randomly generated by the AP 104 .</p><p>In step S312 , the AP 104 transmits an authentication WPA configuration request message (AuthWPAconfig_request message) to the device 102 . The authentication WPA formation request message includes a first one-way function operation value and a random 2. As described above, when the stored counter is equal to or greater than the received counter, the AP 104 transmits a WPA configuration_failure message to the device 102 in step S312 .</p><p>Upon receiving the authentication WPA formation request message, the device 102 determines whether a value obtained by calculating the stored device key and random 1 as a one-way function is the same as the first one-way function operation value. If they are not identical, the device 102 transmits an authentication WPA formation failure message (AuthWPAconfig_failure message) to the AP 104 in step S312 . In the same case, the device 102 calculates a second one-way function calculation value, which is a value obtained by calculating the device key and random 2 as a one-way function.</p><p>In the same case, in step S312 , the device 102 transmits an authentication WPA configuration response message (AuthWPAconfig_response message) to the AP 104 . The authentication WPA formation response message includes a second one-way function operation value.</p><p>Upon receiving the authentication WPA formation response message, the AP 104 determines whether the value obtained by calculating the stored device key and random 2 as a one-way function is the same as the value of the second one-way function operation received. If they are not the same, the AP 104 transmits a WPA configuration failure message (WPAconfig_failure message) to the device 102 in step S316. In the same case, the AP 104 records the device information in the registered device table. That is, the AP 104 stores the MAC address and device key of the device 102 in the registered device table. Then, the AP 104 updates and stores the counter.</p><p>In step S316 , the AP 104 transmits a WPA configuration end message (WPAconfig_complete message) to the device 102 . By performing the above-described processes, the device 102 and the AP 104 perform a mutual authentication process. In step S318 , the device 102 performs a re-association process for session termination or session extension.</p><p>4 illustrates a process of revoking the device key authenticated between the device 102 and the AP 104 according to an embodiment of the present invention.</p><p>The device 102 stores a device key, and the mobile terminal 100 stores a secret key. In addition, the AP 104 stores a device key and a secret key. In this case, the secret key is shared with the mobile terminal 100 and is not a value that is divided by device. That is, step S200 is performed only once for one mobile terminal and one AP.</p><p>In step S400 , the mobile terminal 100 transmits a device key revocation request message (DKrev_request message) to the device 102 . The device key revocation request message includes SSID and random a. Random a is a random value randomly generated by the mobile terminal 100 .</p><p>Upon receiving the device key revocation request message, the device 102 searches for a device key corresponding to the SSID. The device 102 calculates a one-way function calculation value obtained by calculating the retrieved device key and the received random a as a one-way function.</p><p>In step S402 , the device 102 transmits an authentication device key revocation request message (AuthDKrev_request message) to the mobile terminal 100 . The authentication device key revocation request message includes a MAC address of the device 102, a random b, a counter, and an a-th one-way function operation value. Of course, if there is no same SSID, the device 102 transmits a device key failure message (DK_failure message) to the mobile terminal 100 in step S402.</p><p>Upon receiving the authentication device key revocation request message, the mobile terminal 100 generates a device key using the secret key, MAC address, and counter. The mobile terminal 100 determines whether or not the value obtained by calculating the generated device key and the stored random a as a one-way function is the same as the value of the received one-way function operation. If not identical, the mobile terminal 100 transmits an authentication device key revocation failure message (AuthDKrev_failure message) to the device 102 in step S404. In the same case, the mobile terminal 100 generates a b-th one-way function calculation value, which is a value obtained by calculating the device key and random b as a one-way function.</p><p>In step S404 , the mobile terminal 100 transmits an authentication device key revocation response message (AuthDKrev_response message) to the device 102 . The authentication device key revocation response message includes a b-th one-way function operation value. Upon receiving the authentication device key revocation response message, the device 102 determines whether the value obtained by calculating the stored device key and the random b as a one-way function is the same as the received value of the b-th one-way function operation.</p><p>If they are not identical, the device 102 transmits a device key revocation failure message (DKrev_failure message) to the mobile terminal 100 in step S406. In the same case, the device 102 transmits a device key revocation end message (DKrev_complete message) to the mobile terminal 100 in step S406, and discards the stored information. By receiving the device key revocation end message, the mobile terminal 100 recognizes that the information stored by the device 102 has been discarded. Of course, the mobile terminal 100 may record that the information stored by the device 102 is discarded in the stored revocation table.</p><p>Hereinafter, a process of discarding information stored in the AP 104 will be described.</p><p>In step S408 , the mobile terminal 100 transmits a WPA revocation request message (WPArev_request message) to the AP 104 . The WPA revocation request message is a message requesting to discard information about the device 102 stored in the AP 104 . The WPA revocation request message includes random c, the MAC address of the device 102 . Random c is a random value randomly generated by the mobile terminal 100 .</p><p>Upon receiving the WPA revocation request message, the AP 104 searches for a MAC address corresponding to the SSID. If the corresponding MAC address is not found, the AP 104 transmits a WPA revocation failure (WPArev_failure message) in step S410 . When the corresponding MAC address is found, the AP 104 acquires a device key corresponding to the MAC address. In addition, the AP 104 calculates a c-th one-way function calculation value obtained by calculating the stored device key and the received random c as a one-way function. Also, the AP 104 generates a random d.</p><p>In step S410 , the AP 104 transmits an authentication WPA revocation request message (AuthWPArev_request message) to the mobile terminal 100 . The authentication WPA revocation request message includes random d and c-th one-way function operation values.</p><p>Upon receiving the authentication WPA revocation request message, the mobile terminal 100 determines whether the value obtained by calculating the stored device key and random c as a one-way function is the same as the value of the c-th one-way function operation received. If not identical, the mobile terminal 100 transmits an authentication WPA revocation failure message (AuthWPArev_failure message) to the AP 104 in step S412 . In the same case, the mobile terminal 100 generates a d-th one-way function calculation value, which is a value obtained by calculating the device key and random d as a one-way function.</p><p>In step S412 , the mobile terminal 100 transmits an authentication WPA revocation response message (AuthWPArev_response message) to the AP 104 . The authentication WPA revocation response message includes the d-th one-way function operation value. Upon receiving the authentication WPA revocation response message, the AP 104 determines whether a value obtained by calculating the stored device key and random d as a one-way function is the same as the received d-th one-way function operation value.</p><p>If they are not identical, the AP 104 transmits a WPA revocation failure message (WPArev_failure message) to the mobile terminal 100 in step S414 . In the same case, the AP 104 transmits a WPA revocation end message (WPArev_complete message) to the mobile terminal 100 in step S414, and discards the stored device related information. That is, the MAC address and device key of the device stored in the registered device table are discarded. By receiving the WPA revocation end message, the mobile terminal 100 recognizes that the information stored by the AP 104 has been discarded.</p>
<p>As described above, the present invention proposes a method of sharing authentication information between a device and an AP using a mobile terminal, thereby safely transmitting and receiving data from a third party attack. That is, by sharing the secret key and the device key using the one-way function generation module included in the mobile terminal and the AP, data can be safely transmitted and received from a third party attack.</p><p> In the foregoing, the present invention has been shown and described with respect to preferred embodiments for illustrating the principles of the present invention, but the present invention is not limited to the construction and operation as shown and described as such. Rather, it will be apparent to those skilled in the art that many changes and modifications may be made to the present invention without departing from the spirit and scope of the appended claims. Accordingly, it is intended that all such suitable alterations and modifications and equivalents be considered to fall within the scope of the present invention.</p>
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| KR101328779B1 | Cited by | Republic of Korea | Examiner |
| WO2013012244A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| KR101289810B1 | Cited by | Republic of Korea | Search report |
| WO2013012244A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8528051B2 | Cited by | United States of America | Applicant |
| WO0122685A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| KR20040088137A | Cites | Republic of Korea | Search report |
| JP2004056762A | Cites | Japan | Search report |
| KR20050048936A | Cites | Republic of Korea | Search report |
| KR20050082889A | Cites | Republic of Korea | Search report |
| KR1020040088137A | Cites | Republic of Korea | – |
| KR1020050048936A | Cites | Republic of Korea | – |
| KR1020050082889A | Cites | Republic of Korea | – |
2 members in 2 offices
Members2
| Document | Office | Kind | |
|---|---|---|---|
| KR100628566B1This record | Republic of Korea | B1 | |
| US2006242412A1 | United States of America | A1 |
10 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-5-5-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-5-5-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Changes to party contact information recordedST27 STATUS EVENT CODE: A-5-5-R10-R18-OTH-X000 (AS PROVIDED BY THE NATIONAL OFFICE)R18 | R18 | |
| Lapse due to unpaid annual feeLapsedLAPS | LAPS | |
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Written decision to grantGRNT | GRNT | |
| Decision to grant or registration of patent rightE701 | E701 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 10-0628566
- Application
- 100034007
Titles2
- Korean
- 무선랜에서 보안 정보 형성 방법
- English
- How to form security information in wireless LAN
Classification
- CPC, 13
- H04L9/0844
- H04L9/30
- H04L63/061
- H04L63/08
- H04L63/10
- H04W12/06
- H04W12/08
- H04L2209/80
- H04L63/0492
- H04W12/50
- H04L9/32
- H04L9/08
- H04L12/28
- IPC, 4
- H04L9 30
- H04L9 08
- H04L12 28
- H04L9 32