Method and apparatus for distribution of global encryption key in a wireless transport network
Abstract
A method of providing encryption service in a wireless transport network comprises the step of designating a first wireless device as a global encryption key server to create and maintain the global encryption key for a wireless transport network encryption. Nest step is to distribute the global encryption key from the first wireless device to a second wireless device in the wireless transport network. The existing global encryption key in the second wireless device is replaced by the global encryption key. Further step is to transit an expiring global encryption key to a new global encryption key in the wireless transport network without traffic loss and security.
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
13 claims: 7 independent, 6 dependent
- 1一種在無線傳輸網路中提供加密服務之方法,係包括:指定一第一無線裝置當作全域密鑰之伺服器,以產生、維護供無線傳輸網路加密用之全域密鑰;在無線傳輸網路中,從該第一無線裝置散佈該全域密鑰至在該無線傳輸網路內之第二無線裝置;以及取代位於該第二無線裝置內之現存全域密鑰成為該全域密鑰。
- 2如申請專利範圍第1項所述之方法,更包含在該無線傳輸網路中將一到期的全域密鑰轉換為一新的全域密鑰。
- 3如申請專利範圍第1項所述之方法,更包含若無線傳輸網路中已指定的全域密鑰伺服器發生故障,則選擇一新的且已指定的全域密鑰伺服器。
- 4如申請專利範圍第3項所述之方法,更包含當該故障的全域密鑰伺服器恢復時,重新選擇一個全域密鑰伺服器。
- 5如申請專利範圍第2項所述之方法,更包含若無線傳輸網路中已指定的全域密錀伺服器發生故障,則選擇一新的且已指定的全域密鑰伺服器。
- 6如申請專利範圍第5項所述之方法,更包含當故障的全域密鑰伺服器恢復時,重新選擇一個全域密鑰伺服器。
- 7如申請專利範圍第1項所述之方法,其中該第一無線裝置包括一無線傳輸裝置,其具有在無線傳輸網路中中繼傳遞廣播訊框的能力。
- 8如申請專利範圍第1項所述之方法,其中該第二無線裝置包括一無線傳輸裝置,其具有在無線傳輸網路中中繼傳遞廣播訊框的能力。
- 9如申請專利範圍第1項所述之方法,其中該第一無線裝置與第二無線裝置建構出無線傳輸網路之其中一個區塊。
- 10.一種在無線傳輸網路中可散佈全域密鑰的無線裝置,其包括:一處理單元與記憶體;一認證裝置,係耦接該處理單元,以對無線傳輸網路中分隔網路區塊的其他無線裝置進行認證;一選擇裝置,係耦接該處理單元,用來在選擇一全域密鑰,以利於全域密鑰散佈;一散佈裝置,係耦接該處理單元,以利於散佈該全域密鑰;以及一解密/再加密裝置,係耦接該處理單元,用來在無線傳輸網路中執行解密/再加密之功能。
- 11如申請專利範圍第10項所述之無線裝置,其中該無線裝置包括一無線傳輸裝置,其具有在無線傳輸網路中中繼傳遞廣播訊框的能力。
- 12如申請專利範圍第10項所述之無線裝置,其中該其他無線裝置包括一無線傳輸裝置,其具有在無線傳輸網路中中繼傳遞廣播訊框的能力。
- 13如申請專利範圍第10項所述之無線裝置,其中該第一無線裝置與該其他無線裝置建構出無線傳輸網路之其中一個區塊。
Independent claims13
24 paragraphs, as filed
Method and device for distributing global key in wireless transmission network
The present invention relates to a wireless communication system, in particular to a wireless transmission network system, which can distribute global keys in a wireless network.
A typical wireless network system includes one or more access devices for communication. The user can communicate with the access device through a personal computer and a notebook computer through a wireless device. The wireless local area network (WLANS) initially allowed wireless transmission to a wired local area network (LAN), such as a place where a wired system does not exist or an area where the traditional wired local area network is insufficient. WLANS is often used to serve mobile devices, such as laptop (or notebook) computers and personal digital assistants (PDAS). Generally speaking, the access point is used in the service area of the wireless local area network to ensure that there is sufficient data processing capability in the coverage area to reduce the setup cost of each access point. However, the access point must also be installable to reduce the gap in the coverage area and provide sufficient coverage.
The wireless transmission network includes most wireless connection devices, which are responsible for relaying the traffic flow of related mobile clients. For example, a wireless transmission network has many IEEE 802.11 devices that can provide IEEE 802.11 or Bluetooth services, such as laptop computers, personal digital assistants, or similar devices. The wireless transmission network further includes one or more connections, which are connected to the wired network through one or more boundary devices. Configured edge devices (edge devices) and have wireless communication and wired communication capabilities.
In wireless transmission networks, the confidentiality and reliability of data traffic are very important. The transmission field (during broadcasting) is inherently insecure, so encryption becomes necessary in wireless transmission networks. If hardware encryption and decryption are not possible, pairing encryption and decryption between each adjacent wireless network device of the wireless transmission network is not only inefficient and time-consuming. After the data frame is transmitted from a wireless device, it is transmitted from one end of the wireless transmission network to the other end of the network. Before reaching the final destination, it must undergo multiple encryption and decryption processes. Therefore, in addition to the pairing key, it is still necessary to provide a group key for broadcasting or multi-casting data frames. In wireless transmission networks, a more efficient and easy-to-manage encryption/decryption architecture uses a global encryption key to provide encryption services for wireless transmission networks. When a data frame enters the wireless transmission network from the mobile client, it needs to be encrypted each time until it reaches the wireless device, and it will be decrypted accordingly each time.
In addition, in a wireless transmission network, wireless devices may temporarily stop service, causing the network to be divided into several segments. Each network block may have a different global key, which is used exclusively in that network block. When a new wireless device is added to the network block, a new global key is also generated. The present invention particularly relates to a single global key used for a wireless device to form a wireless transmission network, and a plurality of wireless transmission network blocks newly added to a wireless device.
The object of the present invention is to provide a key distribution method for wireless transmission network. In a wireless transmission network, multiple wireless transmission devices and at least one boundary device are required.
The present invention discloses a method for providing encryption services in a wireless transmission network. The method includes: designating a first wireless device as a server of the global key to generate and maintain the global key for encryption of the wireless transmission network . In the next step, in the wireless transmission network, the global key is distributed from the first wireless device to the second wireless device in the wireless transmission network. Then replace the existing global key in the second wireless device with the global key. The next step is to convert an expired global key into a new global key in the wireless transmission network without losing network traffic and security.
The method further includes a step of selecting a new and designated global key server if the designated global key server in the wireless transmission network fails. When the failed global key server recovers, select a new global key server.
The invention discloses a wireless device capable of distributing a global key in a wireless transmission network. The device includes a processing unit and a memory. The wireless device also includes a wireless transmission device. The wireless device additionally includes an authentication device, which is coupled to the processing unit to authenticate other wireless devices (for example, another wireless transmission device) that separates network blocks in the wireless transmission network; a selection device is coupled The processing unit is connected to select a global key to facilitate the distribution of the global key; a dissemination device is coupled to the processing unit to distribute the global key; and a decryption/re-encryption device is coupled The processing unit is connected to perform the decryption/re-encryption function in the wireless transmission network until all the separated network blocks use the global key.
The invention provides a method and a device for providing safe communication in a wireless transmission network. The present invention provides a method that can generate, maintain and distribute a global key to all wireless devices in a wireless transmission network. The present invention provides a device, which is used in a wireless device, and can add wireless transmission network blocks with different global keys to a seamlessly and integrated wireless transmission network with a single global key.
Wireless transmission network
FIG. 1 shows a wireless transmission network 100 which includes at least one edge device 102. The wired network 104 can be added to the border device 102, bridges and access points (Access Points) or base stations (Base Stations) (not shown in the figure). The present invention further includes a plurality of wireless transmission devices 106, which are coupled to a border device 102 by wireless connection. The wireless transmission devices 106 have the ability to relay broadcast frames in a wireless network. The configured boundary device 102 has wireless communication and wired communication capabilities. Each boundary device 102 can communicate with the wireless transmission device 106, and the wireless transmission device 106 communicates with other nearby devices, such as one or more mobile clients 108 or other nearby wireless transmission devices 106. Please refer to FIG. 1, the wireless transmission network 100 includes a plurality of IEEE 802.11 capable devices to provide IEEE 802.11 or Bluetooth capable client transmission services. The client is, for example, a laptop (or notebook) computer, Personal digital assistants or other similar devices. The wireless transmission network 100 further includes one or more connections, which are connected to the wired network 104 through one or more boundary devices 102.
As shown in FIG. 1, all wireless transmission devices 106 can transmit broadcast frames to other mobile clients 108 or wireless transmission devices 106 via a wireless network. The present invention is not directly related to the control transmission path, but is related to the encryption and/or decryption service of the wireless network. The wireless transmission device 106 includes an information table that includes neighboring devices, and the broadcast frame transmitted from the specific wireless transmission device 106 can be received by the neighboring devices. The wireless transmission network 100 includes at least one border device 102, which is coupled between the wired local area network and the wireless local area network. At least one wireless transmission device 106 is connected to the border device 102 and at least one mobile client 108 via a wireless network. The wireless transmission device 106 can construct one of the blocks of the wireless transmission network.
Methods of providing encryption services
The invention relates to a method for providing encryption services in a wireless transmission network. Please refer to FIG. 2, the method of the present invention includes an initial step 200, which designates a wireless device as the server of the global key to generate and maintain the global key for wireless transmission network encryption. The wireless device can be any mobile wireless device, wireless transmission device or border device. The above-mentioned device constructs one of the blocks of the wireless transmission network. Then enter step 210, the global key is issued from the server of the global key (the designated wireless device) to all wireless devices in the same wireless transmission network. When the wireless device receives the global encryption key, the wireless device will perform the subsequent procedures to replace an existing global encryption key with a new one (step 220), in other words, the current received global encryption key (Current Received Global Encryption Key). ). In step 230, the wireless device converts an expired global key into a new global key within the same wireless transmission network without losing network traffic and security.
In the next step 240, if the designated global key server in the wireless transmission network has a temporary failure, the user, control unit or network service provider will select a new and designated global key server . In step 250, when the failed global key server recovers, the system service provider re-selects a global key server.
Please refer to FIG. 3, in order to achieve the above functions, the wireless device needs to be implanted with a mechanism or device for adding the global keys of multiple separate network blocks to the wireless transmission network. The mechanism or device includes a processing unit 300 and a memory 310. The authentication device 320 is coupled to the processing unit 300 to authenticate other wireless devices that separate network blocks in the wireless transmission network. The selection device 330 is coupled to the processing unit 300 and is used to select a new global key among the separated network blocks. For dissemination of the new global key, the network block has substantially less additional burden (overhead). The distributing device 340 is connected to the processing unit 300 for distributing the new global key to the required separated network block. The decryption/re-encryption device 350 is coupled to the processing unit 300 and is used to perform decryption/re-encryption operations between separate network blocks in the wireless transmission network until all block networks use the new global key .
In summary, the present invention provides a single global key used for a wireless device to form a wireless transmission network, and a plurality of wireless transmission network blocks newly added to a wireless device.
The above description is for illustrative purposes only, and is not intended to limit the present invention. Any equivalent modifications or alterations that do not depart from the spirit and scope of the present invention should be included in the scope of the appended patent application.
<p>100. . . Wireless transmission network</p><p>102. . . Boundary device</p><p>104. . . Wired network</p><p>106. . . Wireless transmission device</p><p>108. . . Mobile client</p><p>200~250. . . Step description</p><p>300. . . Processing unit</p><p>310. . . Memory</p><p>320. . . Authentication device</p><p>330. . . Select device</p><p>340. . . Spreading device</p><p>350. . . Decryption/re-encryption device</p>
Figure 1 shows a block diagram of the wireless transmission network of the present invention.
Figure 2 shows the flow chart of the present invention.
Figure 3 shows a block diagram according to the present invention.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN103973462A | Cited by | China | Search report |
7 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 10918005 | United States of America | – | |
| 91800504 | United States of America | A |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| US2005036623A1 | United States of America | A1 | |
| US2005050004A1 | United States of America | A1 | |
| TW200607296A | Taiwan Province of China | A | |
| TW200611532A | Taiwan Province of China | A | |
| TWI292997BThis record | Taiwan Province of China | B | |
| US2009060200A1 | United States of America | A1 | |
| TWI322608B | Taiwan Province of China | B |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- I292997
- Application
- 94117462
Titles4
- Chinese
- 在無線傳輸網路中散佈全域密鑰的方法與裝置
- English
- METHOD AND APPARATUS FOR DISTRIBUTION OF GLOBAL ENCRYPTION KEY IN A WIRELESS TRANSPORT NETWORK
- Unlabeled
- 在無線傳輸網路中散佈全域密鑰的方法與裝置
- Unlabeled
- Method and device for distributing global key in wireless transmission network
Classification
- IPC, 1
- H04L9 12