Forced encryption for wireless local area networks
Claim Score by NHIP
Abstract
A method of enforcing encryption on a public wireless local area network having at least one access point for the wireless connection of user terminals, an authentication, authorization and accounting system, and at least one access control point for controlling access to the network, for initiating an authentication, authorization and accounting procedure for an accessing terminal, and for providing an Internet access gateway functionality. The method includes authenticating a user terminal to the authentication, authorization and accounting system, requesting access to the Internet by the user terminal, and enforcing applications corresponding to the Internet access request of the user terminal to switch their traffic to an encrypting security service port.

Term
Term ended
Projected expiry passed 7 October 2023, 3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
12 claims: 3 independent, 9 dependent
- 1A method of enforcing encryption on a public wireless local area network, the public wireless local area network comprising:at least one access point for the wireless connection of corresponding user terminals;an authentication, authorization and accounting system;and at least one access control point for controlling access to the network, for initiating an authentication, authorization and accounting procedure for an accessing terminal, and for providing an Internet access gateway functionality;the method comprising: authenticating a user terminal to the authentication, authorization and accounting system upon arrival in a service area of the public wireless local area network;requesting access to the Internet by the user terminal;and enforcing applications corresponding to the Internet access request of the user terminal to switch their traffic to an encrypting security service port.
- 7A system for enforcing encryption on a public wireless local area network, comprising at least one user terminal, and a public wireless local area network, which comprises:at least one access point for the wireless connection of a user terminal;an authentication, authorization and accounting sub-system;and at least one access control point for controlling access to the network, for initiating an authentication, authorization and accounting procedure for a user terminal at the authentication, authorization and accounting sub-system upon its arrival in a service area of the public wireless local area network, for providing an Internet access gateway functionality, and for enforcing applications corresponding to an Internet access request of the user terminal to switch their traffic to an encrypting security service port.
- 10Broadest claimClaim Score 53, average(NHIP)An access control point network element for enforcing encryption on a public wireless local area network, comprising:means for controlling access to the network;means for initiating an authentication, authorization and accounting procedure for a user terminal at an authentication, authorization and accounting sub-system of the public wireless local area network upon arrival of the user terminal in a service area of the public wireless local area network;means for providing an Internet access gateway functionality;and means for enforcing applications corresponding to an Internet access request of the user terminal to switch their traffic to an encrypting security service port.
Independent claims3
20 paragraphs in 4 sections, as filed
[0001] The present application claims the benefit of priority of provisional application Serial No. 60/453,953, filed Mar. 13, 2003, the contents of which are incorporated herein by reference.
BACKGROUND OF THE INVENTION
[0002] The present invention relates to a method of enforcing encryption on a public wireless local area network as well as to a related system and network element.
Related Art
[0003] Currently, in practice all traffic in public access zones of wireless local area networks (WLAN) is not encrypted, with the exception of users of virtual private network (VPN) applications. However, in unlicensed public wireless local area networks (WLAN), special attention has to be paid to security issues such as to protect the end users privacy. So far, presently implemented wireless LAN installations comprise security features to offer an encryption for the open air interface. Though, these are not considered to be feasible for public installations due to a lack of being scaleable. Further, no feasible key distribution mechanisms for the encryption are known yet. Moreover, several vulnerabilities have been found so that ready-made tools may be found from the Internet to hack these systems.
[0004] Thus, standards are recently under development such as in “IEEE 802.11 task group i” which are about to develop solutions for these problems. Though, the implementation of these solutions will require new software and most likely also new hardware to be installed at the network, and, most importantly, new software and new hardware to be installed at the end users side.
SUMMARY OF THE INVENTION
[0005] Therefore, it is an object of the present invention to overcome the above shortcomings of the prior art. The present invention is a method of enforcing encryption on a public wireless local area network, the public wireless local area network comprising: at least one access point for the wireless connection of corresponding user terminals; an authentication, authorization and accounting system; and at least one access control point for controlling access to the network, for initiating an authentication, authorization and accounting procedure for an accessing terminal, and for providing an Internet access gateway functionality; the method comprising: authenticating a user terminal to the authentication, authorization and accounting system upon arrival in a service area of the public wireless local area network; requesting access to the Internet by the user terminal; and enforcing applications corresponding to the Internet access request of the user terminal to switch their traffic to an encrypting security service port.
[0006] In addition, the present invention is a system for enforcing encryption on a public wireless local area network, comprising at least one user terminal, and a public wireless local area network, which comprises: at least one access point for the wireless connection of a user terminal; an authentication, authorization and accounting sub-system; and at least one access control point for controlling access to the network, for initiating an authentication, authorization and accounting procedure for a user terminal at the authentication, authorization and accounting sub-system upon its arrival in a service area of the public wireless local area network, for providing an Internet access gateway functionality, and for enforcing applications corresponding to an Internet access request of the user terminal to switch their traffic to an encrypting security service port.
[0007] Furthermore, the present invention is also an access control point network element for enforcing encryption on a public wireless local area network, comprising: means for controlling access to the network; means for initiating an authentication, authorization and accounting procedure for a user terminal at an authentication, authorization and accounting sub-system of the public wireless local area network upon arrival of the user terminal in a service area of the public wireless local area network; means for providing an Internet access gateway functionality; and means for enforcing applications corresponding to an Internet access request of the user terminal to switch their traffic to an encrypting security service port.
[0008] In a preferred embodiment of the present invention, the access control point retrieves information from RADIUS messages which user terminals do not use a 802.11i encryption, and directs the traffic encryption enforcement only to the such identified user terminals.
[0009] Preferably, the encrypting security service is the secure sockets layer (SSL) or the transport layer security (TLS).
[0010] Accordingly, it is an advantage of the present invention that it is suitable for virtually all wireless local area network terminals without requiring any software installations at the terminal side. In addition, no changes on a used operating system or a browser type are necessary. Further, the present invention is transparent for most of the network elements thus requiring only minor changes in the network.
[0011] Hence, a major security enhancement for public wireless local area network access zones is provided by the present invention. That is, contrary to the prior art, the present invention also allows end users without a virtual private network to use most of their applications securely. On the other hand, the present invention is transparent for users of a virtual private network. In general, the present invention is easy to implement and to deploy, and it does not require any changes at the terminals of any end user, since there already exists a wide support for the secure sockets layer and for the transport layer security, while most of the used applications such as browsing and email are addressed by the present invention.
BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Further details, features and advantages of the present invention will become more readily apparent from the following detailed description of the preferred embodiments which is to be taken in conjunction with the appended drawing, in which:
[0013]FIG. 1 shows a wireless local area network architecture underlying the present invention.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0014] As shown in FIG. 1, a public wireless local area network underlying the present invention comprises the following physical and logical elements: wireless local area network (WLAN) terminals UT used by end users and access points AP, access control points ACP and authentication, authorization and accounting (AAA) systems AAA operated by a network operator. The terminals UT are used to access the wireless local area network via a radio interface. The counterpart in the network regarding this interface is the access point AP. An access control point ACP controls the access to the network and initiates the authentication, authorization and accounting (AAA) for the terminal UT in question. The authentication, authorization and accounting system AAA is a back end system for providing corresponding functions. All or some of the above network elements may reside in a same physical network element.
[0015] According to the preferred embodiment of the present invention, if an end user arrives to a public wireless local area network service area (a public access zone PAZ), she/he authenticates herself/himself towards the authentication, authorization and accounting system AAA. After the authentication, the end user has access to the Internet IP, but her/his traffic over the air-interface is not necessarily encrypted.
[0016] Here, when the end user tries to access the Internet IP, the access control point ACP forces applications X to switch the traffic to an encrypted port such as according to the secure sockets layer SSL (as developed by Netscape) or according to the transport layer security TLS (see RFC2246 of the Internet Engineering Task Force), before it allows any traffic to go through. This is possible even if the initial request for the application in question is sent un-encrypted. Examples of applications that can be forced to use the secure sockets layer SSL or the transport layer security TLS encryption include application layer protocols running on top of the TCP/IP (transport control protocol, Internet protocol) and UDP/IP (user datagram protocol), respectively, such as the hypertext transfer protocol HTTP for browsing the Internet, the Internet message access protocol 4 IMAP4 as well as the post office protocol 3 POP3 for incoming mail, and the simple mail transfer protocol SMTP for outgoing mail.
[0017] The above described enforcement to switch the traffic to an encrypted port can also be configured to only take place for users without an 802.11i encryption in the WLAN interface. In this case, the access control point ACP retrieves this knowledge from RADIUS (Remote Authentication Dial-In User Service) messages.
[0018] Thus, what is described above is a method as well as related system and network element of enforcing encryption on a public wireless local area network, the public wireless local area network comprising: at least one access point for the wireless connection of corresponding user terminals; an authentication, authorization and accounting system; and at least one access control point for controlling access to the network, for initiating an authentication, authorization and accounting procedure for an accessing terminal, and for providing an Internet access gateway functionality; the method comprising: authenticating a user terminal to the authentication, authorization and accounting system upon arrival in a service area of the public wireless local area network; requesting access to the Internet by the user terminal; and enforcing applications corresponding to the Internet access request of the user terminal to switch their traffic to an encrypting security service port.
[0019] While it is described above what is presently considered to be the preferred embodiments of the present invention, it is apparent to those who are skilled in the art that various changes and modifications may be made without departing from the spirit and scope of the present invention as defined in the appended claims.
Contents4
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2006209766A1 | Cited by | United States of America | Pre-grant |
| US8051147B2 | Cited by | United States of America | Search report |
| US2009222535A1 | Cited by | United States of America | Pre-grant |
| US2018007719A1 | Cited by | United States of America | Search report |
| US10110322B2 | Cited by | United States of America | Applicant |
| US7848517B2 | Cited by | United States of America | Applicant |
| US8077682B2 | Cited by | United States of America | Search report |
| US9787411B2 | Cited by | United States of America | Applicant |
| US2007080784A1 | Cited by | United States of America | Pre-grant |
| US2006193297A1 | Cited by | United States of America | Pre-grant |
| US7609162B2 | Cited by | United States of America | Applicant |
| CN105472328A | Cited by | China | Search report |
| US2011033044A1 | Cited by | United States of America | Pre-grant |
| CN102594835A | Cited by | China | Search report |
| WO2006111951A2 | Cited by | World Intellectual Property Organization (WIPO) | Applicant |
| US8914869B2 | Cited by | United States of America | Applicant |
| US8259933B2 | Cited by | United States of America | Applicant |
| US9596049B2 | Cited by | United States of America | Applicant |
| US8767958B2 | Cited by | United States of America | Applicant |
| US10470054B2 | Cited by | United States of America | Search report |
| US2002009199A1 | Cites | United States of America | Pre-grant |
| US2002174335A1 | Cites | United States of America | Pre-grant |
| US2003009691A1 | Cites | United States of America | Pre-grant |
| US2003046587A1 | Cites | United States of America | Pre-grant |
| US2003095663A1 | Cites | United States of America | Pre-grant |
| US2003119481A1 | Cites | United States of America | Pre-grant |
| US2003131228A1 | Cites | United States of America | Pre-grant |
| US2004203783A1 | Cites | United States of America | Pre-grant |
| US6081900A | Cites | United States of America | Pre-grant |
| US6178244B1 | Cites | United States of America | Pre-grant |
7 members in 5 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 45395303 | United States of America | P | |
| 45395303 | United States of America | P | |
| 67948603 | United States of America | A | |
| 60453953 | – | – | – |
| US20030453953P | – | – | – |
| US20030679486 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| US2004181663A1 | United States of America | A1 | |
| WO2004082237A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1602216A1 | European Patent Office (EPO) | A1 | |
| EP1602216B1 | European Patent Office (EPO) | B1 | |
| AT381192T | Austria | T | |
| DE602004010625D1 | Germany | D1 | |
| DE602004010625T2 | Germany | T2 |
91 transactions on the USPTO file
Abandoned after 6 non-final rejections, 4 final rejections, 2 RCEs and 2 appeals.
- Non-final rejections
- 6
- Final rejections
- 4
- RCEs
- 2
- Appeals
- 2
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Mail Abandonment for Failure to Respond to Office ActionAbandonedMABN2 | MABN2 | |
| Aband. for Failure to Respond to O. A.AbandonedABN2 | ABN2 | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Correspondence Address ChangeC.ADB | C.ADB | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Miscellaneous Incoming LetterLET. | LET. | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Mail Examiner Interview Summary (PTOL - 413)MEXIN | MEXIN | |
| Examiner Interview Summary Record (PTOL - 413)EXIN | EXIN | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Mail Appeals conf. Reopen Prosec.MAPCR | MAPCR | |
| Pre-Appeals Conference Decision - Reopen ProsecutionAPCR | APCR | |
| Request for Pre-Appeal Conference FiledAP.C | AP.C | |
| Notice of Appeal FiledN/AP | N/AP | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Miscellaneous Incoming LetterLET. | LET. | |
| Miscellaneous Incoming LetterLET. | LET. | |
| Mail Examiner Interview Summary (PTOL - 413)MEXIN | MEXIN | |
| Examiner Interview Summary Record (PTOL - 413)EXIN | EXIN | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Mail Appeals conf. Reopen Prosec.MAPCR | MAPCR | |
| Pre-Appeals Conference Decision - Reopen ProsecutionAPCR | APCR | |
| Request for Pre-Appeal Conference FiledAP.C | AP.C | |
| Notice of Appeal FiledN/AP | N/AP | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Correspondence Address ChangeC.AD | C.AD | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Correspondence Address ChangeC.AD | C.AD | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Return from OIPEWROIPE | WROIPE | |
| Application Return TO OIPEROIPE | ROIPE | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Cleared by L&R (LARS)L128 | L128 | |
| Referred to Level 2 (LARS) by OIPE CSRL198 | L198 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: application discontinuationABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTIONSTCB | STCB | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 2004181663
- Publication, EPODOC
- US2004181663
- Application
- 10679486
- Application, DOCDB
- 67948603
- Application, EPODOC
- US20030679486
Titles
- English
- Forced encryption for wireless local area networks
Classification
- CPC, 8
- H04W12/06
- H04L12/2856
- H04L63/0428
- H04L63/0807
- H04W12/001
- H04W12/02
- H04W84/12
- H04W12/03
- IPC, 2
- H04L12 28
- H04L29 06
- USPC, 2
- 713155000
- 726015000