Method and apparatus for initializing mobile wireless devices
Abstract
A method and system for enabling wireless devices distributed throughout an enterprise to be efficiently initialized for secure communications. The method and system utilize well known public key cryptography and machine unique identifiers to establish a secure channel and initialize the wireless devices.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
18 claims: 6 independent, 12 dependent
- 1一種用於使用伺服器初始化具有嵌入式無線電模組之第一裝置之方法,該伺服器具有嵌入式無線電模組,該方法包括下列步驟:由該伺服器使用該嵌入式無線電模組傳送詢問至該第一裝置;由該第一裝置回傳該第一裝置唯一裝置識別符至該伺服器;在該伺服器創建該第一裝置公用鍵、私用鍵對;在該伺服器創建該第一裝置之裝置認證,該裝置認證具有與該第一裝置相關之唯一硬體識別符以及與該第一裝置相關之公用鍵;傳輸該私用鍵、與該裝置認證以及簽名該裝置認證之認證權限之公用鍵至該第一裝置;以及在該第一裝置儲存該私用鍵至不可移除之保護儲存裝置中。 478269 六、申請專利範圍 1. 一種用於使用伺服器初始化具有嵌入式無線電模組之 第一裝置之方法,該伺服器具有嵌入式無線電模組,該方 . 法包括下列:由該伺服器使用該嵌入式無線電模組傳送詢問至該第 , 一裝置; . 由該第一裝置回傳該第一裝置唯一裝置識別符至該伺 ^ 服器; 在該伺服器創建該第一裝置公用鍵、私用鍵對; 在該伺服器創建該第一裝置之裝置認證,該裝置認證 具有與該第一裝置相關之唯一硬體識別符以及與該第一裝 置相關之公用鍵; 傳輸該私用鍵、與該裝置認證以及簽名該裝置認證之籲 認證權限之公用鍵至該第一裝置;以及 在該第一裝置儲存該私用鍵至不可移除之保護儲存裝 置中。 2. 如申請專利範圍第1項之t逢,其中該保護儲存裝置 為能夠執行牽涉到先前寫入資料計算之惟寫儲存裝置。 3 ·如申請專利範圍第1項之$法,其中該認證之拷貝為 儲存在企業資料庫中。 〜一 4 ·如申請專利範圍第1項之$法,其中該認證之拷貝為 儲存在LDAP目錄中。 5 · —種用於使用伺服器初始化具有嵌入式無線電模組之 _ 第一裝置之定身,該伺服器具有嵌入式無線電模組,該方 法包括下列步驟: CLAIMS 1. A method for initializing a first device having an embedded radio module using a server, the server having an embedded radio module, the method comprising the steps of: transmitting by the server using the embedded radio module Inquiring to the first device;returning, by the first device, the first device unique device identifier to the server;creating, by the server, the first device common key, a private key pair;creating the Device authentication of the first device, the device authenticating having a unique hardware identifier associated with the first device and a public key associated with the first device;transmitting the private key, authenticating with the device, and signing the device authentication And authenticating the public key to the first device;and storing the private key in the first device to the non-removable protected storage device. O:\61\61796.ptd 第27頁 478269 六、申請專利範圍 由該伺服器使用該嵌入式無線電模組傳送詢問至該第 一裝置; 在該第一裝置創建該第一裝置公用鍵、私用鍵對; 在該第一裝置儲存該私用鍵至不可移除之保護儲存裝 置中; 由該第一裝置回傳該第一裝置唯一裝置識別符以及該 公用鍵至該伺服器; 在該祠服器創建該第一裝置之裝置認證,該裝置認證 具有與該裝置識別符以及該公用鍵;以及 傳輸該裝置認證以及簽名該裝置認證之認證權限之公 用鍵至該第一裝置。 6 ·如申請專利範圍第5項之方g,其中該保護儲存裝置 為能夠執行牽涉到先前寫入資^料計算之惟寫儲存裝置。 7 · —種用於使用伺服器初始化具有嵌入式無線電模組之 第一裝置之,該伺服器具有嵌入式無線電模組,該系 統包括: 用於由該伺服器使用該嵌入式無線電模組傳送詢問至 該第一裝置、以及由該第一裝置回傳該第一裝置唯一裝置 識別符至該伺服器之通訊機制; 在該伺服器創建該第一裝置公用鍵、私用鍵對之處理 33: · , 在該伺服器創建之該第一裝置之裝置認證,該裝置認 證具有與該第一裝置相關之唯一硬體識別符以及與該第一 裝置相關之公用鍵; 第28頁 478269 六、申請專利範圍 名該ίί該通訊機制傳輸該私用#、與該裝置認證以及簽 該處1 f遇證之認證權限之公用鍵至該第-裝[·以及, \ ^器儲存該私用鍵至不可移除之保護儲存裝置t。· :2請專㈣圍第7項之mu保護館存裝置 : 行牽涉到先前寫入資料計算之惟寫儲存裝置。 2中請專利範圍第7項之I統,其中該㈣之拷貝為 储仔在企業資料庫中。 I 〇.如申請專利範圍第7項之系統,其中該認證之 儲存在LDAP目錄中。 〜一 ”、、 II · 一種初始化系統,該系統包括: 第一裝置,該^ 一裝置具有嵌入式無線電模組; 伺服器,該伺服器具有嵌入式無線電模組; 通訊機制,該通訊機制由該伺服器使用該嵌入式無線 電模組傳送詢問至該第一裝置; 其中該第一裝置創建該第一裝置公用鍵、私用鍵對; 铸存該私用鍵至不可移除之保護儲存裝置中;以及回傳該 第—裝置唯一裝置識別符以及該公用鍵至該伺服器; 該伺服器創建該第一裝置之裝置認證,該裝置認證具 有該裝置識別符以及該公用鍵;以及傳輸該裝置認證以及 簽名該裝置認證之認證權限之公用鍵至該第一裝置。 1 2·如申請專利範圍第11項之冬一生,其中該保護儲存裝 置為能夠執行牽涉到先前寫入資料計算之惟寫儲存裝置。 1 3 · —種用於使用伺服器初始化具有喪入式無線電模衾且 之苐一裝置之程式,該伺服益具有嵌入式無線電模組,該 IH1 第29頁 478269 六、申請專利範圍 程式包括: 由該伺服器使用該嵌入式無線電模組傳送詢問至該第 一裝置之電腦程式碼裝置; 由該第一裝置回傳該第一裝置唯一裝置識別符至該伺 , 服器之電腦程式碼裝置; _ 在該伺服器創建該第一裝置公用鍵、私用鍵對之電腦 - 程式碼裝置; 在該伺服器創建該第一裝置之裝置認證之電腦程式碼 裝置,該裝置認證具有與該第一裝置相關之唯一硬體識別 符以及與該第一裝置相關之公用鍵; 傳輸該私用鍵、與該裝置認證以及簽名該裝置認證之 認證權限之公用鍵至該第一裝置之電腦程式碼裝置;以及 春 在該第一裝置儲存該私用鍵至不可移除之保護儲存裝 置中之電腦程式碼裝置。 1 4.如申請專利範圍第1 3項之;J ,其中該保護儲存裝 置為能夠執行牽涉到先前寫入資~ 十算之惟寫儲存裝置。 1 5 ·如申請專利範圍第1 3項之竺式,其中該認證之拷貝 為儲存在企業資料庫中。 1 6.如申請專利範圍第1 3項之g式,其中該認證之拷貝 為儲存在企業資料庫中。 — 1 7. —種用於使用伺服器初始化具有嵌入式無線電模組 之第一裝置之程式,該伺服器具有嵌入式無線電模組,該 _ 程式包括: / 由該伺服器使用該嵌入式無線電模組傳送詢問至該第 O:\61\61796.ptd 第30頁 478269 六、申請專利範圍 一裝置之電腦程式碼裝置; 在該第一裝置創建該第一裝置公用鍵、私用鍵對之電 腦程式碼裝置; 在該第一裝置儲存該私用鍵至不可移除之保護儲存裝 置中之電腦程式碼裝置; 由該第一裝置回傳該第一裝置唯一裝置識別符以及該 公用鍵至該伺服器之電腦程式碼裝置; 在該伺服器創建該第一裝置之裝置認證之電腦程式碼 裝置,該裝置認證具有該裝置識別符以及該公用鍵;以及 傳輸該裝置認證以及簽名該裝置認證之認證權限之公 用鍵至該第一裝置之電腦程式碼裝置。 1 8 ·如申請專利範圍第1 7項之程式,其中該保護儲存裝 置為能夠執行牽涉到先前寫入資料計算之惟寫儲存裝置。 第31頁
- 5A method for initializing a first device having an embedded radio module using a server, the server having an embedded radio module, the method comprising the steps of:transmitting by the server using the embedded radio module Inquiring to the first device;creating, by the first device, the first device public key, a private key pair;storing, in the first device, the private key to the non-removable protection storage device;Transmitting, by the device, the first device unique device identifier and the common key to the server;creating, at the server, device authentication of the first device, the device authentication having the device identifier and the common key;and transmitting the The device authenticates and a common key that signs the authentication authority of the device authentication to the first device. 5.一種用於使用伺服器初始化具有嵌入式無線電模組之第一裝置之方法,該伺服器具有嵌入式無線電模組,該方法包括下列步驟:由該伺服器使用該嵌入式無線電模組傳送詢間至該第一裝置;在該第一裝置創建該第一裝置公用鍵、私用鍵對;在該第一裝置儲存該私用鍵至不可移除之保護儲存裝置中;由該第一裝置回傳該第一裝置唯一裝置識別符以及該公用鍵至該伺服器;在該伺服器創建該第一裝置之裝置認證,該裝置認證具有與該裝置識別符以及該公用鍵;以及傳輸該裝置認證以及簽名該裝置認證之認證權限之公用鍵至該第一裝置。
- 7A system for initializing a first device having an embedded radio module using a server, the server having an embedded radio module, the system comprising:for transmitting by the server using the embedded radio module Querying to the first device, and back communication of the first device unique device identifier to the server by the first device;creating a processor for the first device common key and private key pair at the server a device authentication of the first device created by the server, the device authenticating having a unique hardware identifier associated with the first device and a public key associated with the first device;wherein the communication mechanism transmits the private a key, a common key with the device authentication and an authentication authority for signing the device authentication to the first device;and the processor stores the private key in the non-removable protected storage device. 7.一種用於使用伺服器初始化具有嵌入式無線電模組之第一裝置之系統,該伺服器具有嵌入式無線電模組,該系統包括:用於由該伺服器使用該嵌入式無線電模組傳送詢問至該第一裝置、以及由該第一裝置回傳該第一裝置唯一裝置識別符至該伺服器之通訊機制;在該伺服器創建該第一裝置公用鍵、私用鍵對之處理器;在該伺服器創建之該第一裝置之裝置認證,該裝置認證具有與該第一裝置相關之唯一硬體識別符以及與該第一裝置相關之公用鍵;其中該通訊機制傳輸該私用鍵、與該裝置認證以及簽名該裝置認證之認證權限之公用鍵至該第一裝置;以及,該處理器儲存該私用鍵至不可移除之保護儲存裝置中。
- 11An initialization system, the system comprising:a first device having an embedded radio module;a server having an embedded radio module;a communication mechanism, the communication mechanism being used by the server The embedded radio module transmits an inquiry to the first device;wherein the first device creates the first device common key, a private key pair;stores the private key into the non-removable protection storage device;and returns the a first device unique device identifier and the public key to the server;the server creates device authentication of the first device, the device authentication has the device identifier and the common key;and transmitting the device authentication and signing the device The public key of the authenticated authentication authority to the first device. 11.一種初始化系統,該系統包括:第一裝置,該第一裝置具有嵌入式無線電模組;伺服器,該伺服器具有嵌入式無線電模組;通訊機制,該通訊機制由該伺服器使用該嵌入式無線電模組傳送詢問至該第一裝置;其中該第一裝置創建該第一裝置公用鍵、私用鍵對;儲存該私用鍵至不可移除之保護儲存裝置中;以及回傳該第一裝置唯一裝置識別符以及該公用鍵至該伺服器;該伺服器創建該第一裝置之裝置認證,該裝置認證具有該裝置識別符以及該公用鍵;以及傳輸該裝置認證以及簽名該裝置認證之認證權限之公用鍵至該第一裝置。
- 13A program for initializing a first device having an embedded radio module using a server, the server having an embedded radio module, the program comprising:transmitting, by the server, the embedded radio module to the query a computer code device of the first device;the first device unique device identifier is returned by the first device to the computer code device of the server;the first device common key and the private key are created at the server a computer code device for creating a device authentication of the first device at the server, the device authenticating having a unique hardware identifier associated with the first device and a common associated with the first device a key;transmitting the private key, authenticating the device with the device and authenticating the authentication key of the device authentication to the computer program code device of the first device;and storing the private key to the non-removable device at the first device Protect the computer code device in the storage device. 13.一種用於使用伺服器初始化具有嵌入式無線電模組之第一裝置之程式,該伺服器具有嵌入式無線電模組,該程式包括:由該伺服器使用該嵌入式無線電模組傳送詢問至該第一裝置之電腦程式碼裝置;由該第一裝置回傳該第一裝置唯一裝置識別符至該伺服器之電腦程式碼裝置;在該伺服器創建該第一裝置公用鍵、私用鍵對之電腦程式碼裝置;在該伺服器創建該第一裝置之裝置認證之電腦程式碼裝置,該裝置認證具有與該第一裝置相關之唯一硬體識別符以及與該第一裝置相關之公用鍵;傳輸該私用鍵、與該裝置認證以及簽名該裝置認證之認證權限之公用鍵至該第一裝置之電腦程式碼裝置;以及在該第一裝置儲存該私用鍵至不可移除之保護儲存裝置中之電腦程式碼裝置。
- 17A program for initializing a first device having an embedded radio module using a server, the server having an embedded radio module, the program comprising:transmitting, by the server, the embedded radio module to the query a computer program code device of the first device;the computer device code device for creating the first device common key and the private key pair;the first device storing the private key to the non-removable protection storage a computer code device in the device;the first device unique device identifier and the public key to the server computer code device are returned by the first device;and the device is authenticated by the server a computer code device having the device identifier and the public key;and a computer program code device for transmitting the device authentication and a common key for signing the device authentication authentication authority to the first device. 17.一種用於使用伺服器初始化具有嵌入式無線電模組之第一裝置之程式,該伺服器具有嵌入式無線電模組,該程式包括:由該伺服器使用該嵌入式無線電模組傳送詢問至該第一裝置之電腦程式碼裝置;在該第一裝置創建該第一裝置公用鍵、私用鍵對之電腦程式碼裝置;在該第一裝置儲存該私用鍵至不可移除之保護儲存裝置中之電腦程式碼裝置;由該第一裝置回傳該第一裝置唯一裝置識別符以及該公用鍵至該伺服器之電腦程式碼裝置;在該伺服器創建該第一裝置之裝置認證之電腦程式碼裝置,該裝置認證具有該裝置識別符以及該公用鍵;以及傳輸該裝置認證以及簽名該裝置認證之認證權限之公用鍵至該第一裝置之電腦程式碼裝置。
Independent claims6
76 paragraphs, as filed
Method and apparatus for initializing a mobile wireless device
1A and 1B depict a typical setup flow between having an embedded radio module and a management server;
1C depicts an initialization process for a mobile device with sufficient computing power to generate a public/private key pair it possesses;
Figure 2 depicts a possible authentication process of a preferred embodiment of the present invention;
3 is a subset of sample networks in which the present invention can be fabricated;
Figure 4 shows the exemplary device authentication layout;
Figure 5A depicts a centralized access control flow;
Figure 5B depicts an access control flow using a cut-off mode;
Figure 6 depicts a consumer device pairing using device authentication.
The present invention relates generally to security management of wireless devices and more particularly to establishing secure, short-range networks for secure transmission of information between wireless devices.
Related patents
The application titled "Method and Apparatus for Initializing a Mobile Wireless Device" is related to the patent application of another country to which the application is made in parallel, and the application is specifically filed on May 21, 1999, and the serial number of the application is 08___,__ _ The name of the method and device for effectively initializing secure communication in a wireless device" and the application on May 21, 1999, the serial number of the application is 08___, ___ named "exclusively paired wireless The method and apparatus of the device are related to the application. All of these applications are assigned to the assignee of the present invention.
Background of the invention
The proliferation of wireless devices on computer networks has created significant problems in device synchronization and secure interconnection. Most wireless devices today are digital and use radio wave communication. Typical professionals using wireless devices today have a pager that receives digital messages, a digital cellular telephone, and a laptop with a wireless data modem to retrieve and transmit e-mail. To connect to the office or other network needs to be designed to connect to a wide area network or a local area network special hardware (such as a distribution card with a transmission mechanism), the hardware will then allow the connection cable professional staff to access the habits Resources for access.
Standards have been proposed for the consolidation of mobile communications with mobile computing. This standard is referred to herein as "Blue Bud", and it is proposed that a small, inexpensive radio be incorporated into each mobile device. Because this radio is designed to be standard, mobile devices and radio combinations can be optimized to reduce interference. This optimization is practicable because of the common wireless communication protocol made in a single radio band, rather than the many alternatives to the diverse techniques of the various radio bands available for today's wireless access. This small, low-power radio is intended to be distributed in modules or chips that can communicate with other "blueto" enabled products. The Bluetooth standard defines communication between two selection devices and/or a plurality of selection devices. Additional information about the Bluetooth Standard is available on its website at http:www.bluetooth.com.
The standard currently defines an unlicensed 2.4 GHz radio band that can support voice and data exchange. While many of the commonly agreed radio frequencies are operational, this particular portion of the radio spectrum display can be used for global low power unlicensed use. Using a 0-dBm transmitter, this low power will effectively establish a network of devices within a 10 meter radius, and a fast attenuation when the distance increases. With a 20-dBm transmitter, the effective radio range will be approximately 100 meters. Low-power radio modules are intended to be built on mobile computers, mobile phones, three-in-one phones, printers, fax machines, modems, network interfaces (such as LAN or WAN connections), digital cameras, broadcasters, headsets Headphones and more. Asymmetric asynchronous data transmission speeds up to 721KbS (thousands per second), or up to three isochronous 64Kbs voice channels, or a combination of voice and data channels totaling less than 1Mbs per microcell (millions per second) Bit) The symbol rate, currently supported by this specification, and expects that communication speed will increase if the technology advances. Bluetooth uses frequency hopping, so most uncoordinated minicells can co-exist in the proximity of each other.
While this specification describes an important leap forward in device interaction capabilities, it still has problems with the secure communication setup of the device. This specification allows handheld or wireless devices to be connected to what we call "micro-networks" or "micro-cells." The minicell is only an actual (or small) network. This micro-network replaces the cables used to connect the actual approximation devices (within the above radio range). With a Bluetooth radio, an access point, (or a wireless device) can attach a minicell to a corporate LAN or WAN. Deploying these new devices in the enterprise exposes most unique security and management issues.
Prior art in this field, such as the above specifications, defines the method of authentication and encryption of the baseband (entity) layer of the device, but these methods have hitherto no cognitive limitations, which will be analyzed below. All prior art methods that will be described have means for securely providing a secret cryptographic key to subsequent authentication and encryption using a suitable cryptographic device. These methods vary depending on how the keys are obtained. They also differ depending on the key reuse policy or their leading personal identification number (PIN) code.
The first typical method allowed by the prior art is that for two devices, when received via some unregulated external device, the secret keys are only known to them. This method may be suitable for manufacturing two devices that are always paired with each other. They can be stored in conjunction with the partner device identifier and used again each time they wish to communicate. In the event that no method is provided to change the key, the two devices are paired forever and cannot be paired with a device that receives a different permanent key at the time of manufacture. The disadvantage of this key reuse strategy is that the secure combination between the two devices is permanent. Another disadvantage is that if a third party is able to learn the key in some way, it will then be able to emulate another device or arbitrarily eavesdrop on the two devices. In all of these scenarios, a third party can even imitate or unnotically eavesdrop because the radio frequency communication with the intended radio frequency (RF) spectrum can penetrate through perspective barriers such as buildings and walls.
The second method, often described, is slightly safer than the first method and may be suitable for two devices that are exclusively paired on a long-term basis, such as a personal computer and a wireless mouse, or a cell phone and its wireless telephone headset. This method requires two devices to provide the same string called PIN. The PIN can be provided by the manufacturer or entered by the user on each device. The prior art defines how PINs are combined with specific known, fixed material, and specific transient data to generate subsequent secret keys for authentication and encryption. The precise details of how this happens can be important here. The second device wishes to create a long-term pairing relationship and store the keys associated with the pairing device. The PIN used to generate the key is no longer needed and can be retained or discarded. Then use this save button if you want the device to be paired at any time. If the device changes the owner's identity, it is possible to delete the previous key, enter a PIN for the new pairing relationship, and create and store a new key. One disadvantage of this method is that if the third party learns the key in some way, such as by speaking through a spoken word or keyboard input eavesdropping, the key can be learned by eavesdropping according to the pairing process. Once the key is known, it can mimic another device or eavesdrop on encrypted communication.
The third variation provided by the prior art may be suitable for two devices that trust each other only during a single transaction or data exchange. In this method, the user enters the PIN on the second device only before the transaction. The PIN is used as above to generate a key. This key is used for authentication and encryption of the transaction, but the PIN and the key are deleted after processing. In the event that the second device wishes to perform another transaction in the future, the second device must be constructed again with a PIN, which is cumbersome for the user.
In the less secure variation of this third method, the device stores the PIN in combination with the partner device identifier, but deletes the button after use. Therefore, whenever the same PIN is used, the same PIN is used, but a new key is generated before each communication session. The third method improves the security of the second method by frequently changing the key, and if the PIN is successfully learned and eavesdropped during the process, thus limiting the duration that the third party may violate the security.
A fourth method known in the prior art is to request baseband authentication and encryption, but to generate a key for each new communication session using a zero length PIN. This method may be chosen by the manufacturer who wants his product to be removed from the shipping box without any construction by the user to work immediately, and who wants to provide the lowest level of safety. The disadvantage of this approach is that it is similar to those of the third method, in which a third party knowing that the zero length PIN is used can eavesdrop on the pairing process and learn the secret key, enabling it to emulate another device and/or eavesdrop on encrypted communication. .
Obviously, the method of exchanging the key via insecure exchange has the possibility of imitation and eavesdropping. The current technical suggestion to the other person to tell the other person the key or the PIN number, either on a piece of paper or via email, so the secret can be entered by the device user on each device. If this spoken language, paper, or email is observed by a third party, the secret may be revealed. A small amount of improvement is to define the key or the PIN is known to a single person who enters the key or PIN on the second device. This method removes the situation of eavesdropping or peek at the key or PIN, but the keyboard input itself may be observed by a third party, such as by using a hidden camera. It is slightly safer to use a portion of the data exchanged in a non-secure manner to generate a secret key for each communication session or process, but if the malicious third party eavesdrops on key generation and exchange processing, it is still subject to imitation and eavesdropping. If a third party acquires the secret in some way, it is clear that the strategy of reusing the secret is more likely to be exposed than if the secret was never used again.
The prior art methods described above are inadequate, cumbersome, and mobile computers that are not usable in a corporate environment. An example of such a solution proposed by the present invention is shown in FIG.
In FIG. 3, the presence server 301 is connected to a typical enterprise LAN 303. The second server 311 is connected to the first server 301 on the wAN and is also conventionally connected to the LAN 321. A wireless device, such as wireless notebook 315, can be coupled to a wireless access point on server 311. The wireless device can also transmit information directly to the printer 313 on the atmospheric waves (rather than transmitting information to the server 311 and causing the server to use conventional wireless connections to transmit information to the printer 313).
Another aspect depicted in FIG. 3 includes a wireless notebook 309, a telephone 307, and a pager 305. In this scenario, all of these 3 devices can communicate, such that the phone 307 or the pager 305 can transmit a message to the notebook 319 to log in to the notebook 309 at the table. A practical example of this scenario in the career world may be that someone is in a meeting and is waiting for the arrival of an urgent email. The system can be configured to send new emails to the notebook 309 (on a cellular modem or via a micro-network attached to the laptop's LAN), email subject or sender can be on the piconet The way is transmitted by the notebook 309 to the pager 305, and the pager will vibrate and display the message. In addition, the computer can dial a wireless phone and use the text-to-word function to read aloud by emergency email. Another useful solution may be that the fax machine 317 has a wireless connection to the notebook 319, so the notebook computer user can use the basic telephone network attached to the fax machine to transmit information to other people without having to connect to the mobile computer or by The mobile computer unplugs or accesses a server that has a connection to the printer. This connection will be formed directly between the notebook 319 and the fax machine 317 as wireless. Another advantageous solution is to provide a wireless transceiver for a home cable modem or an ADSL adapter, such that all types of devices in the home - such as computers, telephone handsets, television receivers, video recorders, audio speakers, and recorders - can be used Wireless connection access cable network. This solution provides great convenience for the user, wherein the device can be easily added or moved without inconvenience and wasting cables or winding in the house. It is also worth looking forward to from the point of view of the manufacturer or service provider, as it allows a single entity to access the unified enhancement of multiple services within the device.
When considering an enterprise solution, the problem of prior art failure to access becomes quite obvious. The companies used here refer to very large-scale computer installations or networks, such as those typically developed by large companies or organizations with thousands to tens of thousands of employees. Because of their size or because they work in most terrain locations, companies often have smaller locations and/or parks that house thousands of employees. This location and campus are often interconnected by network facilities so that employees can access the applications, resources, databases, and other computer facilities needed to perform their work at any corporate location when moving from one location to another. In the user's corporate solution, thousands to tens of thousands of users will roam wireless devices to thousands of locations, and employees want to wirelessly connect to most devices throughout the day in an unplanned way. . The "roaming" reference used herein actually moves the user itself or its mobile device containing the radio module from one location to another.
Because of the versatility of personal computers (that is, PCs often perform many different programs that exchange data with many different applications and devices representing many different users), the security of PC users needs to be performed from complete distrust to full trust. Scope, and make things more complicated. The latest technology described previously provides most of the methods to create a security policy, but no one is satisfied with its corporate context. Let us examine if any of the techniques previously described can be used by network administrators to restrict access to the network.
1. The device can be permanently paired with another device by the manufacturer, but this is not flexible and prevents the device from having multiple communication partners.
2. The device can have a long-term pairing relationship with other specific devices, for example by entering a common PIN at the device, whereby a button can be created for storage and reuse, or a new button can be generated for each communication session. In addition to the disadvantages listed previously, this strategy does not meet the PC needs to have different communication partners with different security levels and is actually used for different processing from the same partner.
3. The administrator can construct all network access points with the same PIN and then provide a PIN to all possible mobile computer users who are allowed to access. This approach minimizes administrator construction efforts because only a PIN is set (although at most access points) and a properly constructed PC is allowed to roam anywhere in the enterprise and gain access via any access point, but if the secret PIN is compromised At the time, a malicious third party can gain access to all access points. If an authorized employee leaves the company, there is no easy way to revoke access. This design is unacceptable because it is so unsafe.
4. The administrator can construct each network access point or group of access points with different PINs, and then provide a PIN for a specific access point to a specific group of authorized users. If an unauthorized user learns the PIN, it gains access to a set of access points. Managing PIN lists on many mobile computers becomes difficult. It is difficult to revoke user access rights if the user holds the access device. The administrator can change the access point PIN to block unauthorized users, but this method forces all authorized users to update their construction at the same time. If the administrator wants to add a new network access point with a new PIN, all authorized users must be notified and must update their PCS. It is difficult to give the user access to access points of different groups, for example during an action. Obviously this design is not working.
5. The administrator can assign a unique PIN to each mobile PC and construct a list of authorized PINs at a particular access point. Management is more difficult. If the list contains all users, they become unmanageable for a long time and also increase the cost of the access point device because additional memory must be provided to store many PINs. If this list contains a subset of users, the ability of the user to roam is limited. If the user adds or removes, the manager must update the information of all relevant storage points. This method is quite secure except that if a person gains knowledge of an access list at any access point, it can obtain access to the access point by mimicking another device or another user PIN that is not suitable.
It is clear from the foregoing that short-range wireless mobility presents a security challenge for enterprise network managers. This situation is dealt with by the present invention.
Summary of invention
The present invention allows a digitally authenticated connection to be used in a secure manner using a wireless device that includes a radio module. The invention does not require manual login of the user identification, password or encryption key. The present invention also allows efficient management of security devices within an enterprise without the additional administrative cost of creating an initialization device. The present invention describes a method, apparatus, and program product for authenticating, securely generating, and exchanging encrypted short password keys, and means for executing and managing discrete access control in an enterprise, while deleting the inelasticity of pre-constructed secrets and reducing and manual login, Store and/or secretly re-use the relevant security exposure.
Purpose of the invention
It is an object of the present invention to provide a method for active initialization of an active device with an embedded radio module.
Another object of the present invention is to accomplish the initialization of a wireless device in a new and unique manner using known public key techniques.
Another object of the present invention is to use secure storage in a distributed enterprise appliance to provide a secure method of wireless authentication and communication.
These and other objects of the present invention will be described in further detail with reference to the accompanying drawings and the preferred embodiments.
Simple illustration
1A and 1B depict a typical setup flow between having an embedded radio module and a management server;
1C depicts an initialization process for a mobile device with sufficient computing power to generate a public/private key pair it possesses;
Figure 2 depicts a possible authentication process of a preferred embodiment of the present invention;
3 is a subset of sample networks in which the present invention can be fabricated;
Figure 4 shows the exemplary device authentication layout;
Figure 5A depicts a centralized access control flow;
Figure 5B depicts an access control flow using a cut-off mode;
Figure 6 depicts a consumer device pairing using device authentication.
Detailed description of preferred embodiments
The preferred embodiments of the present invention are presented to provide sufficient enabling information for the author so that the reader can make the present invention. It is not intended to limit or limit the invention in any way.
The Bluetooth specification designer has not yet demonstrated authentication and encryption at the baseband (or physical) layer, but the current methods for initializing this authentication and encryption have unacceptable characteristics of mobile computers in the corporate context. So far, there has been significant confusion about how to effectively create security (ie, the same authentication, encryption, access control, and management) in the enterprise. Defining who can interact with whom and "shared secrets" (such as PIN numbers, secret keys) will be used to ensure that the inventive method of connection between particular devices, users, applications, and groups does not yet exist.
In the corporate situation, security issues have become enormous, and most of the norms have targeted this issue. Applications and devices may require different levels of security and the ability to allow different levels of security access. There is no one to carefully consider the answers such as entering a PIN before each process and never storing a PIN or password key, or using the same recorded PIN or repeating the end of all processed password keys is acceptable. It is also unacceptable to generate a short-lived new password key on the stored PIN action fly because any person who knows the PIN may potentially be aware of the new link key by eavesdropping the pairing process.
The present invention addresses this and other problems in wireless environments and other possible environmentally secure communications. The present invention is by no means limited to the present production. The same applies to any mobile environment where the device is a method of frequently accessing other devices and a secure form that requires identification and authentication, a method of securely generating and exchanging cryptographic keys available for encryption and other purposes, and discrete (ie, per device) , per-user, per-application, or per-process access control methods, including adding, revoking, or changing access rights.
Preferred embodiments of the present invention involve authentication combinations associated with users and devices. Authentication, as shown in FIG. 4, typically includes at least a device identifier 4010, a device common key 4015, and an area in which 4020 data can be selected. In addition to the preferred implementation, the present invention involves centralized management of the access control database.
In the prior art, authentication has been combined with a user or a high-level application rather than with a device. Therefore, the user can obtain authentication by the workstation to the workstation based on the authentication of the user such as the smart card and the identification of the user with the corresponding private key (the private key is the user agent controlling its use). The verification and confirmation of the certification is done via the TCPIP process between the communication devices. The present invention closely couples the authentication with the device or, more specifically, with a radio module included in the device, the device unique identifier being used as the unique identifier for authentication.
A preferred embodiment of the present invention specifies an authentication to each of the devices including the proposed radio module. The exemplary authentication described includes the unique 48-bit IEEE (MAC) address of the device (although any unique identifiers, etc. are used equally well), device common keys, correctness periods, and authentication authority signatures. In a preferred embodiment of the invention, the device identifier is stored in the authentication "subject" field. Each device has integrated it into a pair (common key, private key) that is the same as the public key stored in the authentication described above. The device also obtains the authentication authority public key or the authentication authority common key of the authentication authorization chain (hereinafter referred to as the CA common key), so that the authentication authentication received by other devices can be verified. If the authentication authority is known and trusted, the signature of the authentication authority indicates that the combination between the device identifier and the public key of the device authentication can be trusted. The public key of the authentication authority is the signature used to verify the authentication of other devices.
As is well known in the art of public key cryptography, a public key can decrypt data encrypted by a corresponding private key. In addition, the private key can decrypt the data encrypted by the corresponding public key. It is also well known that a data block can be signed by computing a hash on the data block and then encrypting the hash with the signer's private key. The signature can be tested by decrypting the signature with the signer's public key and comparing the result to the hash of the data block just calculated. If these values match, the display signer has a private key corresponding to the public key and the data block is not changed.
In a preferred embodiment of the invention, the device private key is stored in the device in a manner that actually protects the private key value but allows the device resident software to require the hardware to perform a digital signature operation using the private key value. One way to accomplish this is to use a write-only storage device so that the software of the resident device cannot read the key, but the device can perform operations relative to the information. An example of the operation based on the protection value is a digital signature operation using a private key value. While this embodiment is preferred, any other device that protects the information is equally applicable. For example, another location of the actual secure storage device is a smart card or a smart card chip. If the correct PIN or password is entered, the storage device of the current smart card device allows the data to be read. This situation is still superior to the prior art, because the prior art requires inputting a password or a PIN for each device accessed, however, the smart card creation of the present invention requires only a single password or PIN input once during initialization, and the authentication is used for another A secure transaction.
First, a method is provided for initializing a device that is decentralized by an embedded radio module that is delivered to a central point, such as a business, prior to distribution to an end user. Traditionally, when placing new computing or communication devices to enterprise services, personnel perform management procedures that build the device to allow access to specific enterprise resources such as networks, databases, servers, and the like. This is a string of numbers by entering some secret information such as a PIN or a password. This is quite error prone and tedious, time consuming work. With the present invention, an administrator of an enterprise device (including a radio module) utilizes a server having a radio capable of communicating with a radio on an enterprise device. When the server is within an acceptable proximity, an inquiry is sent to the enterprise device. The enterprise device returns its unique device identifier, preferably a 48-bit IEEE (MAC) address. In a secure situation, the server then creates a public/private key pair and enterprise device related authentication and securely transmits these data items to the device that created the data item. The enterprise device stores the authentication (to any type of storage device) and its private key (to the previously described protected storage device). The certified copy is placed in the corporate database. Figure 1 depicts the information flow in more detail.
For the extra security of the high-function device, the above process is modified, so the device generates a common key/private key pair and only transmits the common key to the management server. For greater security, special memory (protective storage) on the device can be added to perform this key pair generation, so that the private key will not be available even for software on the device.
In FIG. 1A, first the management server or initialization device 1001 transmits a query 1010 to the new mobile device 1003 requesting the unique identifier of the mobile device 1003. The mobile device 1003 transmits 1020 its unique identifier 1015 to the management server 1001. The administrator of the management server 1001 then verifies that the unique identifier transmitted by the mobile device is the same as the unique identifier received by the other method for the device (e.g., printed on the device, device-related file transfer, etc.). The connection is established between devices 1001 and 1003. The administrator enters a PIN or encryption key 1025 on one or both of the management server 1001 and the mobile device 1003 such that the transient security link can be established for device initialization using prior art flow 1030. As a result, a secure connection between 1003 and 1001 is established on 1030. The management server 1001 then acquires or generates a common key/private key pair 1035 of the mobile device 1003. At 1045, the management server 1001 places the created public key 1040 with the device 1003 unique identifier 1015 acquired during the previous process in the authentication request message buffer 1050. At 1055, the management server 1001 establishes a secure connection to the authentication authority 1005 and, when authenticating the rights signature 1065, transmits 1060 the authentication request 1050 prepared for the mobile device 1003 to the authentication authority and the backhaul 1070 to authenticate the authorization private key signature. When the management server 1001 receives the signed authentication 1050', the authentication 1050' is stored in step 1075 and the signed authentication 1050' and the corresponding private key are transmitted on the secure connection 1080 (provided the management server generates a public key/private key) The authentication to the mobile device 1003 and the transmission of the authentication authority (including the public key of the authentication authority to the mobile device 1003, and ending the dialogue. The authentication of the signature and its associated private key is stored in the mobile device 1003 for future use. The device private key is a common key with authentication authority (the signature used to verify other device authentication is in the protected storage device 1090 and the device is authenticated to be stored in any suitable location. In a preferred embodiment, the device authentication The copy is also stored in a seven-page access control database for future use. The PIN is deleted 1095 to obtain a shared secret between the management server 1001 and the mobile device 1003.
As noted above, the flow is slightly modified to be preferred if the enterprise device has sufficient computing power to create its own common key/private key pair as shown in Figure 1C. Instead of the management server generating a public/private key pair, the device 1003 generates a common key/private key pair itself 1110 and immediately stores its private key into the protected storage 1115. In this case, the 1003 private key is never transmitted to anyone. The device 1003 establishes a secure or non-secure connection 1120 with the management server and transmits only 1125 its public key to the management server 1001. The management server 1001 still performs the same steps of placing the common key and the device identifier into the authentication request, and securely transmitting the data to the authentication authority (CA1005, so the authentication authority can use the private key to generate the digital signature authentication 1050, and the transmission signature The authentication is returned to the management server 1001, and the signed authentication is transmitted to the device 1003 on a secure or non-secure connection for use in a storage device having any suitable memory location, as illustrated in Figures 1A and 1B. In this form, the device 1003 must also acquire the authentication authority public key 1130 and store it in the manner previously described.
Once public keys, private keys, and authentication have been created, administrators can use standard decentralized technologies, such as those that are applicable to IBM's on-demand servers, to combine special users or groups of users, with access control groups. The user of the group or the device group and the device features of the login device.
Another variation of the above specific embodiment is the inclusion of additional material in the extended field within the signature authentication. This additional field may include, for example, user group relevance, access control groups, etc., which may then be used to isolate the pairing to allow for autonomous access policy decisions.
During operation, when the wireless connection using the present invention is first established between one of the devices that have provided device authentication, the authentication and encryption are initially turned off. The device establishes a "pairing" relationship with another device using a communication protocol similar to controlling the record, which is securely circulated, connected, and included in the SSL TLS to achieve a symmetric key agreement. While SSL TLS provides many options that can result in a key protocol, any of these options are suitable for use by the present invention, and a preferred embodiment is the Diffie-Hellman key protocol. The SSL TLS Control Record Protocol allows the devices to exchange authentications with each other, resulting in mutual authentication without having to enter or store a PIN or password key on each device and no longer need to use a password key or PIN. The dialog key is generated by performing the SHA-1 function according to the SSL key material obtained by the SSL TLS control record communication protocol, and then takes the n-byte sub-set required as needed, and then transmitted to the local encryption by each device of the pairing device. a component (such as the baseband firmware of the preferred embodiment) for use as a link key during a conversation with the partner, a key agreement with the partner device has been reached or during a key agreement <sub>,</sub> Less; or cycle time is suitable for applications, users, devices, and business needs. The encryption is initiated using the partner that generated the key. If the key agreement expires and the conversation is still in progress, the pairing device can use the same SSL TLS control record communication protocol to securely use the previous session key encryption to establish another key agreement, resulting in the new dialog key being passed again to its individual cryptographic component. As explained previously. While SSL TLS is chosen for preferred embodiments because it is considered fairly thorough testing and security, any method that uses authentication exchanges and private keys to generate a conversation can be used. Another suitable prior art method is illustrated by the IP Security Protocol (IPSec) Working Group of the IETF (Request for Annotated Computer and Communication Technology File) of the RFC Series. Refer to the "IP Security Document Guidelines" for background information.
2 depicts an example flow for establishing secure communication between a plurality of devices, each device using the present invention to assemble a wireless transceiver. In the preferred embodiment, the process of FIG. 2 sometimes occurs after each device has provided its own device authentication, its own private key, and the authentication authority familiar with the common key, as previously explained with reference to FIG. However, the invention does not exclude the provision of data items in some other way. When the first device, such as notebook computer 2003, requires communication with the second device 2001, the first device 2003 transmits a connection request 2005 to the second device 2001. The non-secure connection 2010 is established between the first and second devices. In addition, 2010 can use a default PIN, such as a zero-length PIN for authentication and/or encryption. When the control flow of the SSL TLS protocol is performed in our preferred embodiment, the following functions are performed; if another process replaces this control flow, the same functionality must be provided. Negotiation occurs 2020 if there is any agreement based on the need for authentication type, encryption, cryptographic algorithm details, and compression details. For this use, it is considered to be bidirectional (the first speaker and the second speaker will know each other), the request for encryption and the algorithm is used by the baseband hardware/firmware or other cryptographic components presented by the pairing device, and ultimately Compression is specific to NULL. When the authentication is performed, the special memory (protected storage device) is required to be signed with the local device private key (protection value) to provide the device identity to the second device, and the special memory is required to verify the authentication authority signature. The second device authentication is confirmed, so the public key included in the authentication is trusted to verify the second device signature. If the partner identification fails at any point, the conversation is terminated. To request the result of the encryption, the dialog key agrees on the security mode 2030 and at this point the SSL/TLS protocol or equivalent agreement is used to initialize the protocol key 2035 for the baseband transport (or other suitable local encryption). The component) terminates to enable the cryptographic operation to act 2040 afterwards.
The result of the identification process described above results in the exchange and verification of the two device certifications. This means that the optional extension fields for these certifications are applicable to policy decisions. For example, the second device 2001 can query the local or enterprise access control data by using the required device identifier or the selectable (related independent or group name) authentication field according to the content of the authentication of the first device 2003. The library determines which resources/functions can be used by the encrypted connection in 2003. All of these operations are done securely directly through negotiation between devices, and do not require the input and storage of secrets associated with each potential communication partner, such as user identifiers and passwords, PINs based on some users or administrators. It is an encryption key, which is different from the initialization procedure of FIG. 1 or an equivalent program. As previously described, the common keys for providing device authentication, private keys, and authentication authority for each device are provided.
In a preferred embodiment, the device is logged into an access control database of the server, the authentication providing access control methods to services and resources, and selecting priorities that must be applicable to the device, such as formatting A particular type of data stream can be accessed or accessed. In case the mobile device using the authentication method described in the present invention is missing from the designated user, the device authentication can be revoked (just now the credit card issuer cancels the stolen credit card). Authentication revocation in a central location, such as a directory or database, is only effective if the authentication protocol of other devices needs to interact with the directory or database. In the non-connected mode, where authentication does not require access to the directory or database, the most efficient method of access revocation and rejection is to expire the device authentication and the device requires the user to periodically change device authentication. The validation cycle field is provided for certification for this purpose, as previously mentioned. Figure 5 depicts this field in more detail.
FIG. 5A shows centralized access control in which mobile device 1003 requests access to first resource 5001. The mobile device 1003 and the first source 5001 perform mutual authentication and negotiation encryption 5010. The mobile device 1003 then requests access to at least one resource 5020. The first resource 5001 transmits the authentication request 5030 of the mobile device 1003 to the central directory or the repository 1005. Access is permitted or denied based on information in the Central Library or Directory 5050.
Figure 5B shows a disconnected mode access control in which two devices 1003 and 5001 mutually authenticate and negotiate encryption 5010. The mobile device 1003 requests access to the resource 5020, but in the non-connected scenario, the receiving resource 5001 views the option material of the decrypted authentication 5100. When viewing the data, the first resource 5001 determines whether access is permitted based on the authentication field and the locally stored information 5110. The certification field can contain information such as the expiration date of the certification. Access request information as previously permitted or denied 5150 <sub>,</sub> However, based on this locally obtained information.
Using the present invention, the first resource is authenticated if the following three statements are true: (1) its authentication chain can be returned by checking the individually included signature back to the authentication authority signer that found the trust (as defined by the authentication authority stored in Figure 1B) It can be confirmed by the point indicated by the key, (2) can display the possession of the private key associated with the public key included in the authentication, and (3) the device identifier stored in the authentication matches the device real device identifier, by Other methods such as vision or determination by standard communication procedures. In a preferred embodiment, the first device proves to have a matching private key by means of SSL TLS or an equivalent protocol to control the challenge signature in the recording process. The impostor may steal the first device authentication and eavesdropping from the unprotected storage device to learn the first device MAC (machine) address. The impostor may then attempt to emulate the first device by spoofing the unique identifier (MAC address) and replaying its authentication, but the impostor has no way to obtain the private key of the first device of the protected storage device. It is not possible to sign the inquiry.
Other examples that may be useful in the present invention include the creation of long-term secure pairing relationships between devices without the use of PIN or encryption keys, such as bonding devices such as headsets and mobile phones, as shown in FIG. This example can be done as follows. The user has two devices (6001 and 6003) and he or she wishes to establish a secure relationship between the two devices. Each device is provided with the device authentication previously described, including its device identifier or serial number, and can also be seen externally or via other external devices. Instead of the device authentication, matching private keys, and authentication rights, the public keys are generated by the administrator, and these data items can be pre-installed by the manufacturer 6010. The device is then shipped by the manufacturer in an uninitialized (unpaired) state, i.e., without defining a link key, PIN, or pairing relationship. When the device is unpaired, the user presses a button 6020 that performs a special function to bring the two unpaired devices into the vicinity of the radio. The device is caused to transmit its authentication 6030 to other devices as explained with reference to FIG. 2. At least one of the two devices needs to have a display device that can display the pairing device 6040 identifier 6040 (without excluding hearing or other output devices). The device with the display verifies the other authentication by checking the authentication chain authentication using the authentication authority public key. If the authenticated device identifier matches the device identifier written outside the device or known by the external device, it is the recognized identifier 6050. The user then presses button 6060 (does not exclude other devices that make the decision) and the device accepts the pairing relationship and the device identifier (or optionally the link button) is transmitted to the permanent or long-term storage device (flash random access) Take memory or a similar storage device that represents a local access control database. If the authentication does not match the device identifier, the user rejects the pairing and the operation terminates 6070. The two devices are now paired and can be safely re-authenticated at any time in the future (using authentication or optionally sharing keys for the link key) and establishing encrypted communications. This situation allows the manufacturer to uniquely pair the devices without having to synchronize device manufacturing throughout the process. If the owner of the paired device chooses the transfer device ownership to any of the persons, the owner can delete the pairing relationship and the future owner can establish a new pairing relationship by performing the same steps as previously explained.
The device authentication based initialization method is particularly suitable for consumer devices having long term exclusive pairings such as wireless telephone reception and telephone base stations, personal computers and wireless audio headsets, personal computers, and wireless mice.
45 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45
36 members in 18 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 09316804 | United States of America | – | |
| 31680499 | United States of America | A | |
| 19990316804 | – | – | – |
| US19990316804 | – | – | – |
Members36
| Document | Office | Kind | |
|---|---|---|---|
| CA2371329A1 | Canada | A1 | |
| WO0072506A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU5084500A | Australia | A | |
| KR20010114272A | Republic of Korea | A | |
| EP1179244A1 | European Patent Office (EPO) | A1 | |
| TW478269BThis record | Taiwan Province of China | B | |
| TW480864B | Taiwan Province of China | B | |
| CZ20014168A3 | Czechia | A3 | |
| CN1351789A | China | A | |
| IL146384A0 | Israel | A0 | |
| IL146384D0 | Israel | D0 | |
| TW498669B | Taiwan Province of China | B | |
| HU0201561A2 | Hungary | A2 | |
| HUP0201561A2 | Hungary | A2 | |
| JP2003500923A | Japan | A | |
| HU0201561A3 | Hungary | A3 | |
| HUP0201561A3 | Hungary | A3 | |
| KR100415022B1 | Republic of Korea | B1 | |
| PL354839A1 | Poland | A1 | |
| US6772331B1 | United States of America | B1 | |
| MXPA01011969A | Mexico | A | |
| HU223924B1 | Hungary | B1 | |
| US6886095B1 | United States of America | B1 | |
| CA2371329C | Canada | C | |
| US6980660B1 | United States of America | B1 | |
| SG118221A1 | Singapore | A1 | |
| EP1179244B1 | European Patent Office (EPO) | B1 | |
| AT332599T | Austria | T | |
| ATE332599T1 | Austria | T1 | |
| JP2006203936A | Japan | A | |
| DE60029217D1 | Germany | D1 | |
| IL146384A | Israel | A | |
| ES2263474T3 | Spain | T3 | |
| CN1293720C | China | C | |
| DE60029217T2 | Germany | T2 | |
| JP2010158030A | Japan | A |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A | |
| Issue of patent certificate for granted invention patentGrantedGD4A | GD4A |
Numbers
- Publication
- 478269
- Publication, DOCDB
- 478269
- Publication, EPODOC
- TW478269B
- Application
- 89109589
- Application, DOCDB
- 89109589
- Application, EPODOC
- TW200089109589
Titles3
- Chinese
- ???????????????
- English
- METHOD AND APPARATUS FOR INITIALIZING MOBILEWIRELESS DEVICES )
- English
- Method and apparatus for initializing mobile wireless devices
Classification
- CPC, 3
- H04L63/0823
- H04W12/06
- H04W12/0609
- IPC, 5
- H04L9 00
- H04L9 32
- H04L12 28
- H04L12 56
- H04L29 06