Data communication network
8 claims: 3 independent, 5 dependent
- 1CONCLUSIES 1. Datacommunicatienetwerk geschikt voor informatieuitwisseling tussen computers, welk netwerk ten minste een althans draadloos LAN (local area network) omvat en in een bedieningsgebied verspreid opgestelde toegangsorganen (access points) voor koppeling van de in het ten minste ene LAN opgenomen computers aan het netwerk, met het kenmerk, dat het ten minste ene draadloze LAN virtueel is uitgevoerd en dat het berichtenverkeer met de tot dat LAN behorende computers geïndividualiseerd is door versleuteling van de tussen de computers en de toegangsorganen uitgewisselde informatie onder toepassing van een voor ieder LAN unieke sleutel.
- 2Datacommunicatienetwerk volgens conclusie 1, met het kenmerk, dat voorzien is in een voor iedere computer unieke sleutel.
- 3Datacommunicatienetwerk volgens conclusie 1 of 2, met het kenmerk, dat deze is ingericht voor het genereren van de unieke sleutel op het moment dat berichtenverkeer tussen één of meer computers uit een LAN en het netwerk tot stand komt.
- 4Datacommunicatienetwerk volgens conclusie 3, met het kenmerk, dat de generatie van de unieke sleutel geschiedt met een op zichzelf bekend public-key algoritme.
- 5Datacommunicatienetwerk volgens een der conclusies 1-4, met het kenmerk, dat de toegangsorganen onderling gekoppeld zijn met op zichzelf bekende bedrade netwerkverbindingen .
- 6Datacommunicatienetwerk volgens een der conclusies 1-5, met het kenmerk, dat ieder toegangsorgaan een filterorgaan heeft voor het verwijderen van informatie die gericht is tot een computer van een ander LAN dan in het bedieningsgebied van dat toegangsorgaan aanwezig is, of afkomstig is van een computer van een eerste LAN en gericht tot een computer van een tweede LAN.
- 7Datacommunicatienetwerk volgens conclusie 6, met het kenmerk, dat het filterorgaan is ingericht voor de verwijdering uit het berichtenverkeer van voorafbepaalde typen informatie .
- 8Datacommunicatienetwerk volgens een der conclusies 1-7, met het kenmerk, dat iedere in een draadloos LAN ι opgenomen computer voorzien is van een orgaan voor weigering ί 5 van door andere computers verzonden berichten. I 9. Datacommunicatienetwerk volgens een der voorgaande conclusies, met het kenmerk, dat iedere computer voorzien - is van een of meer verdere sleutels voor codering en decodering van het berichtenverkeer dat bestemd is voor een groep 10 computers of voor alle computers die in hetzelfde virtuele LAN zijn opgenomen. F’T'S (ÏW r Cell Β 1/1 wired backbone OCTROOIRAAD RAPPORT BETREFFENDE HET ONDERZOEK NAAR DE STAND VAN DE TECHNIEK Octrooiaanvrage Nr.:NO 134152 NL 1008351 VAN BELANG ZIJNDE LITERATUUR EOB FORM 02.83 (P0414) AANHANGSEL BEHORENDE BIJ HET RAPPORT BETREFFENDE HET ONDERZOEK NAAR DE STAND VAN DE TECHNIEK, UITGEVOERD IN DE OCTROOIAANVRAGE NR. NO 134152 NL 1008351 Het aanhangsel bevat een opgave van elders gepubliceerde octrooiaanvragen of octrooien (zogenaamde leden van dezelfde octrooifamilie), die overeenkomen met octrooischriften genoemd in het rapport. De opgave is samengesteld aan de hand van gegevens uit het computerbestand van het Europees Octrooibureau per De juistheid en volledigheid van deze opgave wordt noch door het Europees Octrooibureau, noch door de Octrooiraad gegarandeerd ;de gegevens worden verstrekt voor informatiedoeleinden. or . i 1QQQ EPO FOAM P0466 Algemene informatie over dit aanhangsel is gepubliceerd in de 'Official Journal' van het Europees Octrooibureau nr 12/82 blz 448 ev
Independent claims8
44 paragraphs in 2 sections, as filed
Office for the
Industrial Property
The Netherlands
<img file="NL1008351C2_D0001.tif" />
© 1008351 © C PATENT<sup>20</sup> © Patent application: 1008351 © Filed: 19.02.98 © Int.Ci.®
H04L12 / 28, H04L12 / 22
<td>© Registered:</td><td>(© Patent holder (s):</td>
<td> 20.08.99</td><td>No Wires Needed BV in Bilthoven.</td>
<td>©) Date:</td><td>© Inventor (s):</td>
<td> 20.08.99</td><td>Ronald Alexander Brockmann in Utrecht</td>
<td></td><td>Arnoud Roderick Swimmer in Utrecht</td>
<td>© Published:</td><td>Maarten Hoeben in Zeist</td>
<td>01.10.99 IE 99/10</td><td></td>
<td></td><td>© Authorized representative:</td>
<td></td><td>Drs. A. Kupecz et al. At 1000 HB Amsterdam.</td>
54) Data communication network.
The invention relates to a data communication network suitable for the exchange of information between computers, which network comprises at least one at least a wireless local area network (LAN) and access points (access points) arranged in a control area for linking the terminals. at least one LAN included computers on the network. The at least one wireless LAN is virtualized and the message traffic with the computers belonging to that LAN is individualized by encrypting the information exchanged between the computers and the access members using a key unique to each LAN.
NL C 1008351
The contents of this patent correspond to the original filed description with claim (s) and any drawings.
NL 43.468-VB / yt
Data communication network
The invention relates to a data communication network suitable for information exchange between computers, which network comprises at least one at least a wireless LAN (local area network) and which has access points (access points) arranged in an operating area for coupling the at least one access points. LAN included computers to the network.
Such a data communication network has been known from practice for years. The wireless local area network (LAN) included in such a data communications10 network has been developed to provide greater flexibility, mobility and reduce otherwise necessary infrastructure and management costs. In such a wireless LAN a laptop computer can be included, which is arranged for wireless communication. In order to provide the communication function, the network is equipped with so-called access points, which are located in the geographical area served by the wireless LAN. Typically, an access member serves a small area called Cell, and has a radius between 10 and 100 meters.
The use of several access organs is therefore necessary to serve a somewhat extensive catchment area. These access organs are mutually connected by means of known per se network techniques which may or may not be wired. An example of this is the Ethernet infrastructure.
The data communication network which is the object of the present invention comprises at least one wireless local area network, and can be further wired for linking to further virtual local area networks, whether or not further, for example according to the IEEE 802.IQ standard for virtual LANs. When such a data communication network provides for the possibility of using multiple wireless local area networks, a problem arises that lies in the nature of the wireless communication. After all, such wireless communication is over the air, so that when computers from different local area networks are located in the same geographical area, the integrity of the message traffic in the relevant local area networks is maintained, according to the state of the technique is very difficult.
Various solutions are conceivable for this problem. On the one hand, the number of access organs can be duplicated in accordance with the number of local area networks present in a particular operating area, however this is very expensive and inefficient in using the available transmission frequencies. Another solution is not to increase the number of access bodies, but to limit the mobility of the computers belonging to local area networks. However, this is not a problem solution15, but a problem avoidance. It is also possible to opt out of smaller local area networks and to set up the system as an integrated network. In that case, the identified problem does not arise, but problems arise with regard to the security of the message traffic, and the management problems of the system increase exponentially. Accordingly, the performance of the system deteriorates because information intended for a limited number of computers is then sent to everyone.
The object of the invention is to provide a system in which the data communication network can be used when several wireless LANs must be able to form part thereof, without this placing undue burdens on the control problems of the message traffic in the system or on concessions to the mobility of the various computer users who are in a wireless LAN are included.
According to the invention, the data communication network is set up for this purpose in such a way that the at least one wireless LAN is virtually implemented and that the message traffic with the computers belonging to that LAN is individualized by encrypting the information exchanged between the computers and the access organs using an information each LAN unique key.
In a preferred embodiment, a key is unique for each computer. In this way, point-to-point data connections are possible between the various wireless networked computers and the access members. To this end, data encryption techniques that are generally known from the literature can be applied. The only requirement that is made here is that the keys that are used are suitable for distinguishing the individual data connections between the respective computers and the access members. With the provision of these keys, the respective access members can be arranged to recognize which virtual LAN or virtual LANs they belong to, as well as to which LAN the computers that send and / or receive messages to and from those access members belong. The various keys can be predefined for each LAN.
In a particular embodiment, however, it is advantageous that the data communication network is arranged to generate the unique key when message traffic between one or more computers from a LAN and the network is established. This has advantages from a manageability point of view.
A suitable form of implementation surrounded by the necessary guarantees as regards authentication of the message traffic is characterized in that the generation of the unique key takes place with a public key algorithm known per se; see W. Diffie and ME Heilman, New Directions in Cryptography, IEEE Transactions on Information Theory, v. IT-22, n. 6, Nov 1976, pp. 644-654.
It is advantageous that the access members are mutually coupled with wired network connections known per se. However, this is not a requirement; the network connections between the various access bodies may also be wireless.
In order to limit the load that the message traffic constitutes in the data communication network according to the invention, it is desirable that each access device has a filter device for removing information directed to a computer from a different LAN than is present in the operating area of that access device , or from a computer on a first LAN and addressed to
T UiH a computer from a second LAN. This also guarantees the virtual star structure of the network.
From the viewpoint of message traffic security, it is desirable that the filtering device be adapted to remove from the message traffic predetermined types of information, for example information that may be classified as infringing the security or integrity of a network or part thereof. This may be particularly important in the case of information exchange in one
- 10 WINDOWS-NT environment.
The manageability of the system is further served by the fact that each computer included in a wireless LAN is provided with a means for rejecting messages sent by other computers. In this way, a star structure is effectively provided between the various access members and the computers communicating with these access members.
It is further desirable that each computer be provided with one or more further keys for encrypting and decrypting the message traffic destined for a group of 20 computers or for all computers included in the same virtual LAN. In addition to the point-to-point data message communication in the virtual LAN, individual communication
I basis, also provide for the possibility of multipoint message communication and broadcast message communication.
; Z The application of the invention is possible using the standard IEEE 802.11 technology for wireless local area networks. By applying the invention, the respective virtual wireless local area networks are distinguished and separated from each other, without there being a risk that message traffic will end up elsewhere than at the destination. With the invention it is possible for the computer users within the various local area networks to move freely within the distribution area served by the various access organs.
The invention will now be explained in more detail with reference to a single drawing, which schematically shows the data communication network according to the invention.
The data communication network shown is suitable for the exchange of information between computers, each of which is indicated by the station name for%. The data communication network shown comprises, at least in the part shown, two virtual local area networks, designated VLAN 1 and VLAN 2. The virtual local area networks VLAN 1 and VLAN 2 are linked to the network via terrestrial messaging, which takes place using a access element in the figure indicated by access point. According to the invention, the message traffic between such an access point and the computer station is encrypted with a key code which is unique per computer in the case shown, and thus an individualized connection is provided between each computer station and the relevant access point access point.
It is also possible to apply such a unique key code only per LAN, so that all computers of that LAN can then participate in the message traffic. The determination of the key unique for each LAN or computer is made, for example, in advance. It is also possible to suspend the determination of those unique keys until the moment that traffic between one or more computers from a LAN and the network starts to be established. The generation can then take place by means of a public-key algorithm in itself. Such public-key algorithms are known to the person skilled in the art and need not be further explained here.
The figure further shows that the respective access point access points are mutually coupled with wired network connections known per se, referred to as wired backbone. For the effective use of the data communication network without excessive load through excessive messaging, each access point ac30 cess point is provided with a filtering means for removing information addressed to a computer from a different LAN VLAN 1 or VLAN 2 than in the respective operating area (Cell A or Cell B) of that access device is present. The filtering means is also arranged to remove information from a first LAN and addressed to a computer from a second LAN. A logical separation of the VLANs is the result. This filter member can also provide for the removal of specific types of messages. Incidentally, each computer station is arranged to have a means for refusing messages sent by other computer stations. In this way, a star structure is given to the information network.
Due to the virtual and wireless nature of the local area networks used in the network according to the invention, without the loss of the integrity of a local area network, a computer station that is part of local area network VLAN 2 can be part of one operating area Cell A be moved to an operating area Cell B provided by another access point access point. The invention thus achieves the advantage that, despite the use of a wireless computer station in conjunction with virtual local area networks, the advantages associated with the latter technique, namely an improved controllability of the message traffic in the data communication network, and without concessions to the mobility of the computers used in the network is realized. The speed of the message traffic in this network, and the logical separation of the LANs is thereby ensured by the filtering elements included in the various access elements that are part of the network.
<sup>r</sup>T. .nut Η ·
Contents2
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US5199072A | Cites | United States of America | XY | Search report | 1,5,8,9 |
| US5309516A | Cites | United States of America | YA | Search report | 2,3 |
| WO9512942A1 | Cites | World Intellectual Property Organization (WIPO) | A | Search report | 1 |
| WO9604734A1 | Cites | World Intellectual Property Organization (WIPO) | YA | Search report | 6 |
7 members in 5 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 1008351 | Netherlands (Kingdom of the) | A | |
| NL19981008351 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| NL1008351C2This record | Netherlands (Kingdom of the) | C2 | |
| EP0939519A1 | European Patent Office (EPO) | A1 | |
| US6487657B1 | United States of America | B1 | |
| EP0939519B1 | European Patent Office (EPO) | B1 | |
| AT450100T | Austria | T | |
| ATE450100T1 | Austria | T1 | |
| DE69941644D1 | Germany | D1 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Lapsed due to non-payment of the annual feeLapsedVD1 | VD1 |
Numbers
- Publication, DOCDB
- 1008351
- Publication, EPODOC
- NL1008351C
- Application
- 1008351
- Application, DOCDB
- 1008351
- Application, EPODOC
- NL19981008351
Titles2
- Dutch
- Datacommunicatienetwerk.
- English
- Data communication network.
Classification
- CPC, 7
- H04L63/065
- H04L12/22
- H04L12/46
- H04L63/0227
- H04W84/12
- H04L49/354
- H04W12/041
- IPC, 4
- H04L12 22
- H04L12 28
- H04L12 46
- H04L29 06
