Wireless communication authentication
Summary by NHIP
Wireless Authentication System
The system authenticates mobile nodes by verifying codes derived from base station identifiers, router numbers, and secret keys. Successful authentication requires matching calculated codes and base station identification numbers within the authentication packet data.
Claim Score by NHIP
Abstract
A replay attack from an unauthorized user is easily avoided by wireless communication authentication. A mobile node acquires an inherent identification number owned by a base station connected to the mobile node, and sends authentication packet data including the identification number and information providing transfer route information for packet data sent to the mobile node through a wireless link. A router holds an inherent identification number owned by a base station connected to the router, and, if the identification number held by the router agrees with the identification number included in the authentication packet data sent from the mobile node, registers the transfer route information in a route table based on the authentication packet data.

Term
Projected expiry 14 October 2027.
- Priority
- Filed
- Granted
- Today
- Projected expiry
10 claims: 5 independent, 5 dependent
- 1A wireless communication authentication system comprising a mobile node connected to a base station through a wireless link and an authentication apparatus that authenticates authentication packet data sent from said mobile node, wherein said mobile node acquires an identification number of said base station through which said mobile node is connected to said authentication apparatus, calculates an authentication code using information including said identification number, a highest-level router number, and a mobile unit identifier and using a secret key that can be recognized by only said mobile node and said authentication apparatus, generates authentication packet data from said information and said authentication code, and sends said authentication packet data to said authentication apparatus through said base station;and wherein said authentication apparatus holds an identification number of a base station that is connected to and operates under said authentication apparatus, calculates the authentication code using said information in said authentication packet data and said secret key that said authentication apparatus recognizes, determines that authentication is successful when the calculated authentication code agrees with said authentication code included in said authentication packet data and when said identification number included in said authentication packet data agrees with said identification number that said authentication apparatus holds.
- 2A wireless communication authentication system comprising a mobile node connected to a base station through a wireless link and an authentication apparatus that authenticates authentication packet data sent from said mobile node, wherein said mobile node acquires an identification number of said base station through which said mobile node is connected to said authentication apparatus, calculates an authentication code using information including said identification number, a highest-level router number, and a mobile unit identifier and using a secret key that can be recognized by only said mobile node and said authentication apparatus, generates authentication packet data from said information and said authentication code, and sends said authentication packet data to said authentication apparatus through said base station;and wherein said authentication apparatus is connected to an authentication server, and said authentication server holds an identification number of a base station that is connected to and operates under said authentication apparatus, calculates the authentication code using said information in said authentication packet data and said secret that said authentication apparatus recognizes, determines that authentication is successful when the calculated authentication code agrees with said authentication code included in said authentication packet data and when said identification number included in said authentication packet data agrees with said identification number that said authentication server holds.
- 3Broadest claimClaim Score 47, average(NHIP)A wireless communication authentication system comprising a mobile node connected to a base station through a wireless link, and an authentication server connected to said base station and that authenticates authentication packet data sent from said mobile node;wherein said mobile node acquires an identification number of said base station through which said mobile node is connected to said authentication server, calculates an authentication code using information including said identification number, a highest-level router number, and a mobile unit identifier and using a secret key that can be recognized by only said mobile node and said authentication server, generates authentication packet data from said information and said authentication code, and sends said authentication packet data to said authentication server through said base station;and wherein said authentication server holds an identification number of a base station that is connected to and operates under said authentication server, calculates the authentication code using said information in said authentication packet data and said secret key that said authentication server recognizes, determines that authentication is successful when the calculated authentication code agrees with said authentication code included in said authentication packet data and when said identification number included in said authentication packet data agrees with said identification number that said authentication server holds.
- 4A method to be carried out by a wireless communication authentication system for authenticating, with authentication packet data, data for registering transfer route information for packet data to be sent to a mobile node connected to a base station through a wireless link, in a route table owned by an authentication apparatus that authenticates said packet data as authentication packet data, said method comprising the steps of:controlling said mobile node to acquire an identification number of said base station through which said mobile node is connected to said authentication apparatus, calculate an authentication code using information including said identification number, a highest-level router number, and a mobile unit identifier and using a secret key that can be recognized by only said mobile node and said authentication apparatus, generate authentication packet data from said information and said authentication code, and send said authentication packet data to said authentication apparatus through said base station;holding, by said authentication apparatus, an identification number of a base station that is connected to and operates under said authentication apparatus;calculating the authentication code using said information in said authentication packet data and said secret key that said authentication apparatus recognizes, and determining that authentication is successful when the calculated authentication code agrees with said authentication code included in said authentication packet data and when said identification number included in said authentication packet data agrees with said identification number of said base station that said authentication apparatus holds;and when the authentication is successful, registering said transfer route information in said route table based on said authentication packet data.
- 5A method to be carried out by an authentication server for authenticating the connection of a mobile node connected to a base station through a wireless link, to said base station, based on authentication packet data sent from said mobile node, comprising the steps of:controlling said mobile node to acquire an identification number of said base station through which said mobile node is connected to said authentication server, calculate an authentication code using information including said identification number, a highest-level router number, and a mobile unit identifier and using a secret key that can be recognized by only said mobile node and said authentication server, generate authentication packet data from said information and said authentication code, and send said authentication packet data to said authentication server through said base station;holding, by said authentication server, an identification number of a base station that is connected to and operates under said authentication server;controlling said authentication server to calculate the authentication code using said information in said authentication packet data and said secret key that said authentication server recognizes, and determine that authentication is successful when the calculated authentication code agrees with said authentication code included in said authentication packet data and when said identification number included in said authentication packet data agrees with said identification number of said base station that said authentication server holds;and when the authentication is successful, permitting said mobile node to connect to said base station.
Independent claims5
102 paragraphs in 4 sections, as filed
BACKGROUND OF THE INVENTION
1. Field of the Invention
The present invention relates to a wireless communication authentication system and a wireless communication authentication method for excluding an unauthorized user from a network that is connected to a wireless communication area.
2. Description of the Related Art
Generally, wireless communication systems need to authenticate legitimate users who are going to use the network in order to exclude an unauthorized user who would attempt to intercept data sent from a mobile node owned by a legitimate user to a wireless link and abuse the network based on the intercepted data.
<figref idref="DRAWINGS">FIG. 1</figref> of the accompanying drawings shows a conventional host routing hierarchical network comprising external network <b>100</b>, a plurality of routers <b>101</b>, <b>102</b>-<b>1</b>, <b>102</b>-<b>2</b>, <b>103</b>-<b>1</b> through <b>103</b>-<b>4</b>, a plurality of base stations <b>104</b>-<b>1</b> through <b>104</b>-<b>8</b>, mobile node <b>105</b>, and authentication server <b>106</b>. Router <b>101</b> is connected to external network <b>100</b>. Routers <b>102</b>-<b>1</b>, <b>102</b>-<b>2</b> are connected to and operate under router <b>101</b>. Routers <b>103</b>-<b>1</b>, <b>103</b>-<b>2</b> are connected to and operate under router <b>102</b>-<b>1</b>. Routers <b>103</b>-<b>3</b>, <b>103</b>-<b>4</b> are connected to and operate under router <b>102</b>-<b>2</b>. Base stations <b>104</b>-<b>1</b>, <b>104</b>-<b>2</b> are connected to and operate under router <b>103</b>-<b>1</b>. Base stations <b>104</b>-<b>3</b>, <b>104</b>-<b>4</b> are connected to and operate under router <b>103</b>-<b>2</b>. Base stations <b>104</b>-<b>5</b>, <b>104</b>-<b>6</b> are connected to and operate under router <b>103</b>-<b>3</b>. Base stations <b>104</b>-<b>7</b>, <b>104</b>-<b>8</b> are connected to and operate under router <b>103</b>-<b>4</b>. Mobile node <b>105</b> is a node that is movable while being connected to the network. Authentication server <b>106</b> serves to authenticate data in routers <b>103</b>-<b>1</b> through <b>103</b>-<b>4</b>.
A wireless communication authentication process which is carried out in the conventional host routing hierarchical network shown in <figref idref="DRAWINGS">FIG. 1</figref> will be described below with reference to <figref idref="DRAWINGS">FIG. 2</figref> of the accompanying drawings.
It is assumed that mobile node <b>105</b> is currently present in an area covered by base station <b>104</b>-<b>2</b> and is connected to base station <b>104</b>-<b>2</b> through a wireless link. Therefore, data sent from mobile node <b>105</b> travels through a communication route extending from mobile node <b>105</b> through base station <b>104</b>-<b>2</b>, router <b>103</b>-<b>1</b>, router <b>102</b>-<b>1</b> to router <b>101</b>. The communication route is held in route tables that are owned respectively by routers <b>101</b>, <b>102</b>-<b>1</b>, <b>103</b>-<b>1</b>.
Thereafter, mobile node <b>105</b> moves from the area covered by base station <b>104</b>-<b>2</b> into an area covered by base station <b>104</b>-<b>3</b>.
When mobile node <b>105</b> moves, it sends route update data to base station <b>104</b>-<b>3</b> (step <b>301</b>). The route update data includes the identifier of a destination router, the identifier of mobile node <b>105</b>, a time stamp or a sequence number.
When the route update data sent from mobile node <b>105</b> is received by base station <b>104</b>-<b>3</b> (step <b>302</b>), the received route update data is sent from base station <b>104</b>-<b>3</b> to router <b>103</b>-<b>2</b> (step <b>303</b>).
When the route update data sent from base station <b>104</b>-<b>3</b> is received by router <b>103</b>-<b>2</b> (step <b>304</b>), the received route update data is sent from router <b>103</b>-<b>2</b> to authentication server <b>106</b> (step <b>305</b>).
When the route update data sent from router <b>103</b>-<b>2</b> is received by authentication server <b>106</b> (step <b>306</b>), the received route update data is authenticated by authentication server <b>106</b> (step <b>307</b>).
The route update data includes an authentication code in addition to the items described above. The authentication code is calculated by a hash function from a secret key and the above items, other than the authentication code, of the route update data. The secret key can be recognized by only authentication server <b>106</b> and mobile node <b>105</b>. In step <b>307</b>, the route update data is authenticated by recalculating the authentication code and determining whether the received authentication code is correct or not.
Even if the route update data is intercepted and used by an unauthorized user in the wireless zone between mobile node <b>105</b> and base stations <b>104</b>-<b>1</b> through <b>104</b>-<b>8</b>, the route update data thus intercepted and used is rejected as incorrect data. Specifically, since the route update data includes the time stamp or the sequence number, authentication server <b>106</b> detects a duplication of the time stamp or the sequence number and judges that the duplicated route update data is used by an unauthorized user.
When authentication server <b>106</b> authenticates the route update data, authentication server <b>106</b> sends an authentication result to router <b>103</b>-<b>2</b> (step <b>308</b>).
When the authentication result sent from authentication server <b>106</b> is received by router <b>103</b>-<b>2</b> (step <b>309</b>), if the authentication result is GOOD, then the route table in router <b>103</b>-<b>2</b> is updated based on the route update data which has been authenticated and information indicating that the base station to which the route update data has been sent is base station <b>104</b>-<b>3</b> (step <b>310</b>). At this time, the route table in router <b>103</b>-<b>2</b> is updated such that data to be sent to mobile node <b>105</b> will be routed through base station <b>104</b>-<b>3</b>. If the authentication result is NOT GOOD, then the route table is not updated, and the authentication process is put to an end.
After the route table in router <b>103</b>-<b>2</b> is updated, the route update data is sent from router <b>103</b>-<b>2</b> to router <b>102</b>-<b>1</b> (step <b>312</b>). Based on the received route update data and information indicating that the route update data is sent from router <b>103</b>-<b>2</b>, the route table in router <b>102</b>-<b>1</b> is updated (step <b>313</b>). At this time, the route table in router <b>102</b>-<b>1</b> is updated such that data to be sent to mobile node <b>105</b> will be routed through router <b>103</b>-<b>2</b>.
Router <b>101</b> which is higher in level than router <b>102</b>-<b>1</b> already has route information with respect to mobile node <b>105</b> and the route information does not need to be changed. Therefore, the route update data is not sent from router <b>102</b>-<b>1</b> to router <b>101</b>.
However, because one common authentication server is used to authenticate the route update data in routers <b>103</b>-<b>1</b> through <b>103</b>-<b>4</b>, problems arise as follows:
When a mobile node switches base stations which the mobile node connected to according to a technique known as handover for wireless communication systems, the authentication server authenticates the connected user for the base station which is newly connected to the mobile node. If the authentication server is widely spaced from the newly connected base station, then an authentication packet transmitted between the authentication server and the base station suffers a transmission delay, possibly resulting in a communication failure time upon handover.
It has been considered to reduce the transmission delay time by placing a plurality of authentication servers in respective positions close to the base stations or designing the base stations such that they also serve as authentication servers.
However, the above solutions make it possible for an unauthorized user to use the network based on a replay attack. The replay attack is one of hacking attempts to eavesdrop on the password or the encryption key of a user and use it to masquerade the user.
<figref idref="DRAWINGS">FIG. 3</figref> of the accompanying drawings shows a wireless communication authentication system employing routers which also serve as authentication servers. The wireless communication authentication system shown in <figref idref="DRAWINGS">FIG. 3</figref> comprises external network <b>200</b>, a plurality of authentication-capable routers <b>201</b>, <b>202</b>-<b>1</b>, <b>202</b>-<b>2</b>, a plurality of base stations <b>204</b>-<b>1</b> through <b>204</b>-<b>8</b>, and mobile nodes <b>205</b>, <b>207</b>. Router <b>201</b> is connected to external network <b>200</b>. Routers <b>202</b>-<b>1</b>, <b>202</b>-<b>2</b> are connected to and operate under router <b>201</b>. Authentication-capable routers <b>203</b>-<b>1</b>, <b>203</b>-<b>2</b> are edge routers with an authenticating function which are connected to and operate under router <b>202</b>-<b>1</b>. Authentication-capable routers <b>203</b>-<b>3</b>, <b>203</b>-<b>4</b> are edge routers with an authenticating function which are connected to and operate under router <b>202</b>-<b>2</b>. Base stations <b>204</b>-<b>1</b>, <b>204</b>-<b>2</b> are connected to and operate under authentication-capable router <b>203</b>-<b>1</b>. Base stations <b>204</b>-<b>3</b>, <b>204</b>-<b>4</b> are connected to and operate under authentication-capable router <b>203</b>-<b>2</b>. Base stations <b>204</b>-<b>5</b>, <b>204</b>-<b>6</b> are connected to and operate under authentication-capable router <b>203</b>-<b>3</b>. Base stations <b>204</b>-<b>7</b>, <b>204</b>-<b>8</b> are connected to and operate under router <b>203</b>-<b>4</b>. Mobile nodes <b>205</b>, <b>207</b> are nodes that are movable while being connected to the network. Mobile node <b>207</b> is the mobile node of an unauthorized user who intercepts route update data in a wireless zone between mobile node <b>205</b> and base station <b>204</b>-<b>2</b> and attempts to masquerade mobile node <b>205</b> to use the network.
A wireless communication authentication process which is carried out in the wireless communication authentication system shown in <figref idref="DRAWINGS">FIG. 3</figref> will be described below with reference to <figref idref="DRAWINGS">FIG. 4</figref> of the accompanying drawings.
It is assumed that mobile node <b>205</b> is currently present in an area covered by base station <b>204</b>-<b>2</b> and is going to be connected to base station <b>204</b>-<b>2</b> through a wireless link. Mobile node <b>205</b> sends route update data to base station <b>204</b>-<b>2</b> (step <b>401</b>). The route update data includes the identifier of a destination router, the identifier of mobile node <b>205</b>, a time stamp or a sequence number.
When the route update data sent from mobile node <b>205</b> is received by base station <b>204</b>-<b>2</b> (step <b>402</b>), the received route update data is sent from base station <b>204</b>-<b>2</b> to authentication-capable router <b>203</b>-<b>1</b> (step <b>403</b>).
When the route update data sent from base station <b>204</b>-<b>2</b> is received by authentication-capable router <b>203</b>-<b>1</b> (step <b>404</b>), the received route update data is authenticated by authentication-capable router <b>203</b>-<b>1</b> (step <b>405</b>).
The route update data includes an authentication code in addition to the items described above. The authentication code is calculated by a hash function from a secret key and the above items, other than the authentication code, of the route update data. The secret key is recognized by only authentication-capable routers <b>203</b>-<b>1</b> through <b>203</b>-<b>4</b> and mobile node <b>205</b>. In step <b>405</b>, the route update data is authenticated by recalculating the authentication code and determining whether the received authentication code is correct or not.
If the authentication result produced by authentication-capable router <b>203</b>-<b>1</b> is GOOD, then the route table in authentication-capable router <b>203</b>-<b>1</b> is updated based on the route update data which has been authenticated and information indicating that the base station to which the route update data has been sent is base station <b>204</b>-<b>2</b> (step <b>406</b>). At this time, the route table in authentication-capable router <b>203</b>-<b>1</b> is updated such that data to be sent to mobile node <b>205</b> will be routed through base station <b>204</b>-<b>2</b>. If the authentication result is NOT GOOD, then the route table is not updated, and the authentication process is put to an end.
After the route table in authentication-capable router <b>203</b>-<b>1</b> is updated, the route update data is sent from authentication-capable router <b>203</b>-<b>1</b> to router <b>202</b>-<b>1</b> (step <b>407</b>).
When the route update data sent from authentication-capable router <b>203</b>-<b>1</b> is received by router <b>202</b>-<b>1</b> (step <b>408</b>), the route table in router <b>202</b>-<b>1</b> is updated based on the received route update data and information indicating that authentication-capable router from which the route update data has been sent is authentication-capable router <b>203</b>-<b>1</b> (step <b>409</b>). At this time, the route table in router <b>202</b>-<b>1</b> is updated such that data to be sent to mobile node <b>205</b> will be routed through authentication-capable router <b>203</b>-<b>1</b>. Thereafter, the route update data is sent from router <b>202</b>-<b>1</b> to router <b>201</b> (step <b>410</b>).
The route update data sent from mobile node <b>205</b> to base station <b>204</b>-<b>2</b> in step <b>401</b> is intercepted by mobile node <b>207</b> owned by an unauthorized user who is present in the area covered by base station <b>204</b>-<b>3</b> (step <b>411</b>). Mobile node <b>207</b> masquerades mobile node <b>205</b> and sends the intercepted route update data to base station <b>204</b>-<b>3</b> (step <b>412</b>). The route update data sent from mobile node <b>207</b> is received by base station <b>204</b>-<b>3</b> (step <b>413</b>). The received route update data is sent from base station <b>204</b>-<b>3</b> to authentication-capable router <b>203</b>-<b>2</b> (step <b>414</b>).
When the route update data sent from base station <b>204</b>-<b>3</b> is received by authentication-capable router <b>203</b>-<b>2</b> (step <b>415</b>), the received route update data is authenticated by authentication-capable router <b>203</b>-<b>2</b> (step <b>416</b>).
Unlike authentication server <b>106</b> shown in <figref idref="DRAWINGS">FIG. 1</figref> which is common to all the routers, the individual routers shown in <figref idref="DRAWINGS">FIG. 3</figref> have respective authenticating functions. Therefore, even though the route update data includes a sequence number or a time stamp, the route update data that includes the same sequence number or the same time stamp is received by the different authentication-capable routers. Each of the authentication-capable routers is thus unable to determine whether the route update data is incorrect or not from its authentication records, but recognizes all successfully authenticated route update data as legitimate route update data. Accordingly, the data used by the unauthorized user is not excluded, but is normally processed.
If the authentication result produced by authentication-capable router <b>203</b>-<b>2</b> is GOOD, then the route table in authentication-capable router <b>203</b>-<b>2</b> is updated based on the route update data which has been authenticated and information indicating that the base station to which the route update data has been sent is base station <b>204</b>-<b>3</b> (step <b>417</b>). At this time, the route table in authentication-capable router <b>203</b>-<b>2</b> is updated such that data to be sent to mobile node <b>205</b> will be routed through base station <b>204</b>-<b>3</b>. If the authentication result is NOT GOOD, then the route table is not updated, and the authentication process is put to an end.
After the route table in authentication-capable router <b>203</b>-<b>2</b> is updated, the route update data is sent from authentication-capable router <b>203</b>-<b>2</b> to router <b>202</b>-<b>1</b> (step <b>418</b>).
When the route update data sent from authentication-capable router <b>203</b>-<b>2</b> is received by router <b>202</b>-<b>1</b> (step <b>419</b>), the route table in router <b>202</b>-<b>1</b> is updated based on the received route update data and information indicating that authentication-capable router from which the route update data has been sent is authentication-capable router <b>203</b>-<b>2</b> (step <b>420</b>). At this time, the route table in router <b>202</b>-<b>1</b> is updated such that data to be sent to mobile node <b>205</b> will be routed through authentication-capable router <b>203</b>-<b>2</b>.
As described above, the communication route to legitimate mobile node <b>205</b>, which has been updated in step <b>409</b>, is changed by mobile node <b>207</b> that has impersonated mobile node <b>205</b>. Consequently, legitimate mobile node <b>205</b> is no longer able to use the wireless communication authentication system.
In view of the above problems, a process of excluding an unauthorized user is disclosed in JP-1995-203540A. According to the disclosed process, the base stations of a wireless communication network have respective authenticating functions. When a mobile node sends a connection request to a base station, the base station sends an inherent identification number of its own to the mobile node. The mobile node generates an authentication code as well as other route information based on the identification number, adds the authentication code to route update data, and sends the route update data to the base station. The base station determines, based on its authenticating function, whether the identification number included in the received route update data is the same as the identification number of the base station or not. An unauthorized user who has sent route update data including a different identification number is thus excluded.
The process disclosed in the above patent document is problematic in that many base stations installed in a wireless communication area need to have respective authenticating functions, and an edge router has to recognize whether all base stations connected to and operable under the edge router have respective authenticating functions or not. In addition, if there is a base station having no authenticating function, then the edge router is required to perform some authenticating process on its own.
SUMMARY OF THE INVENTION
It is an object of the present invention to provide a wireless communication authentication system and a wireless communication authentication method which are capable of performing a quick authentication process for avoiding a replay attack carried out by an unauthorized user, without the need for the addition of authenticating functions to respective base stations.
According to the present invention, a mobile node acquires an inherent identification number owned by a base station connected to the mobile node. The mobile node sends authentication packet data including the acquired identification number and information providing transfer route information through the base station to a router. If the identification number of the base station which is included in the authentication packet data sent from the mobile node and received by the router and an inherent identification number held by the router and owned by a base station connected to the router agree with each other, then the transfer route information is registered in a route table in the router based on the authentication packet data.
As described above, only if the identification number of the base station which is included in the authentication packet data sent from the mobile node agrees with the identification number of the base station which is held by the router, the transfer route information is registered in the route table in the router based on the authentication packet data. Even if an unauthorized user intercepts authentication packet data on a wireless link and sends the intercepted authentication packet data to a different router, the identification number of the base station which is included in the authentication packet data and the identification number of the base station which is held by the router do not agree with each other, and no transfer route information is registered in the route table. Consequently, a transfer route based on the data sent from the unauthorized user is not established, and the unauthorized user is excluded from the network. If the function according to the present invention is provided in the router, then the function does not need to be provided in each of a number of base stations installed in a wireless area. Furthermore, each of routers used independently operates to perform the above sequence, a high-speed authentication process can be carried out.
The above and other objects, features, and advantages of the present invention will become apparent from the following description with reference to the accompanying drawings which illustrate examples of the present invention.
BRIEF DESCRIPTION OF THE DRAWINGS
<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram of a conventional host routing hierarchical network to which a mobile node is connected;
<figref idref="DRAWINGS">FIG. 2</figref> is a sequence diagram illustrative of a wireless communication authentication process which is carried out in the conventional host routing hierarchical network shown in <figref idref="DRAWINGS">FIG. 1</figref>;
<figref idref="DRAWINGS">FIG. 3</figref> is a block diagram of a wireless communication authentication system employing routers which also serve as authentication servers;
<figref idref="DRAWINGS">FIG. 4</figref> is a sequence diagram illustrative of a wireless communication authentication process which is carried out in the wireless communication authentication system shown in <figref idref="DRAWINGS">FIG. 3</figref>;
<figref idref="DRAWINGS">FIG. 5</figref> is a block diagram of a wireless communication authentication system according to a first embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 6</figref> is a block diagram of an authentication-capable router in the wireless communication authentication system shown in <figref idref="DRAWINGS">FIG. 5</figref>;
<figref idref="DRAWINGS">FIG. 7</figref> is a block diagram of a mobile node in the wireless communication authentication system shown in <figref idref="DRAWINGS">FIG. 5</figref>;
<figref idref="DRAWINGS">FIG. 8</figref> is a sequence diagram illustrative of a wireless communication authentication process which is carried out in the wireless communication authentication system shown in <figref idref="DRAWINGS">FIGS. 5 through 7</figref>;
<figref idref="DRAWINGS">FIG. 9</figref> is a block diagram of a wireless communication authentication system according to a second embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 10</figref> is a block diagram of a RADIUS server in the wireless communication authentication system shown in <figref idref="DRAWINGS">FIG. 9</figref>;
<figref idref="DRAWINGS">FIG. 11</figref> is a block diagram of a mobile node in the wireless communication authentication system shown in <figref idref="DRAWINGS">FIG. 9</figref>; and
<figref idref="DRAWINGS">FIG. 12</figref> is a sequence diagram illustrative of a wireless communication authentication process which is carried out in the wireless communication authentication system shown in <figref idref="DRAWINGS">FIGS. 9 through 11</figref>.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
1st Embodiment:
<figref idref="DRAWINGS">FIG. 5</figref> shows in block form a wireless communication authentication system according to a first embodiment of the present invention. As shown in <figref idref="DRAWINGS">FIG. 5</figref>, the wireless communication authentication system according to the first embodiment comprises external network <b>10</b>, a plurality of routers <b>1</b>, <b>2</b>-<b>1</b>, <b>2</b>-<b>2</b>, a plurality of authentication-capable routers <b>3</b>-<b>1</b> through <b>3</b>-<b>4</b>, a plurality of base stations <b>4</b>-<b>1</b> through <b>4</b>-<b>8</b>, and mobile node <b>5</b>. Router <b>1</b> is connected to external network <b>10</b>. Routers <b>2</b>-<b>1</b>, <b>2</b>-<b>2</b> are connected to and operate under router <b>1</b>. Authentication-capable routers <b>3</b>-<b>1</b>, <b>3</b>-<b>2</b> are edge routers with an authenticating function which are connected to and operate under router <b>2</b>-<b>1</b>. Authentication-capable routers <b>3</b>-<b>3</b>, <b>3</b>-<b>4</b> are edge routers with an authenticating function which are connected to and operate under router <b>2</b>-<b>2</b>. Base stations <b>4</b>-<b>1</b>, <b>4</b>-<b>2</b> are connected to and operate under authentication-capable router <b>3</b>-<b>1</b>. Base stations <b>4</b>-<b>3</b>, <b>4</b>-<b>4</b> are connected to and operate under authentication-capable router <b>3</b>-<b>2</b>. Base stations <b>4</b>-<b>5</b>, <b>4</b>-<b>6</b> are connected to and operate under authentication-capable router <b>3</b>-<b>3</b>. Base stations <b>4</b>-<b>7</b>, <b>4</b>-<b>8</b> are connected to and operate under router <b>3</b>-<b>4</b>. Mobile node <b>5</b> sends packet data to and receives packet data from external network <b>10</b> through the wireless communication authentication system.
As shown in <figref idref="DRAWINGS">FIG. 6</figref>, authentication-capable router <b>3</b>-<b>2</b> shown in <figref idref="DRAWINGS">FIG. 5</figref> comprises base station communication unit <b>11</b>, packet transfer unit <b>12</b>, higher-level router communication unit <b>13</b>, route update data processor <b>14</b>, user authenticator <b>15</b>, base station manager <b>16</b>, route table storage unit <b>17</b>, user information storage unit <b>18</b>, and base station information storage unit <b>19</b>. Base station communication unit <b>11</b> communicates with base stations <b>4</b>-<b>3</b>, <b>4</b>-<b>4</b> shown in <figref idref="DRAWINGS">FIG. 5</figref>. Route table storage unit <b>17</b> registers and stores transfer route information of packet data. Packet transfer unit <b>12</b> transfers packet data to base stations <b>4</b>-<b>3</b>, <b>4</b>-<b>4</b> or router <b>2</b>-<b>1</b> based on the transfer route information stored in route table storage unit <b>17</b>. Higher-level router communication unit <b>13</b> communicates with router <b>2</b>-<b>1</b> as a higher-level router shown in <figref idref="DRAWINGS">FIG. 5</figref>. Route update data processor <b>14</b> processes route update data sent from base stations <b>4</b>-<b>3</b>, <b>4</b>-<b>4</b>. Base station information storage unit <b>19</b> stores in advance information of the base stations that are connected to and operate under authentication-capable router <b>3</b>-<b>2</b>. Base station manager <b>16</b> manages the information of the base stations which is stored in base station information storage unit <b>19</b>. User information storage unit <b>18</b> stores in advance user information (mobile unit identifiers, secret keys, etc.) of users who are allowed to use the wireless communication authentication system. User authenticator <b>15</b> manages the user information stored in user information storage unit <b>18</b> and authenticates users based on the user information. Each of other authentication-capable routers <b>3</b>-<b>1</b>, <b>3</b>-<b>3</b>, <b>3</b>-<b>4</b> has structural and processing details identical to those of authentication-capable router <b>3</b>-<b>2</b> though different routers and base stations are connected to authentication-capable routers <b>3</b>-<b>1</b>, <b>3</b>-<b>3</b>, <b>3</b>-<b>4</b>.
As shown in <figref idref="DRAWINGS">FIG. 7</figref>, mobile node <b>5</b> shown in <figref idref="DRAWINGS">FIG. 5</figref> comprises route update data generator <b>21</b>, wireless communication unit <b>22</b>, wireless controller <b>23</b>, user information storage unit <b>24</b>, and base station connection information storage unit <b>25</b>. Wireless communication unit <b>22</b> communicates with base stations <b>4</b>-<b>1</b> through <b>4</b>-<b>8</b> shown in <figref idref="DRAWINGS">FIG. 5</figref> through a wireless link. Base station connection information storage unit <b>25</b> stores connection information required for mobile node <b>5</b> to connect to base stations <b>4</b>-<b>1</b> through <b>4</b>-<b>8</b>. Wireless controller <b>23</b> manages the connection information stored in base station connection information storage unit <b>25</b>, and controls wireless communication unit <b>22</b>. User information storage unit <b>24</b> stores in advance user information including mobile unit identifiers, secret keys, etc. Route update data generator <b>21</b> manages the user information stored in user information storage unit <b>24</b>, and generates route change data for registering or changing communication routes of packet data.
A wireless communication authentication process which is carried out in the wireless communication authentication system shown in <figref idref="DRAWINGS">FIGS. 5 through 7</figref> will be described below with reference to <figref idref="DRAWINGS">FIG. 8</figref>.
It is assumed that mobile node <b>5</b> has been connected to base station <b>4</b>-<b>2</b> and moves such that the base station to which mobile node <b>5</b> is connected changes from base station <b>4</b>-<b>2</b> to base station <b>4</b>-<b>3</b>.
When mobile node <b>5</b> moves from an area covered by base station <b>4</b>-<b>2</b> to an area covered by base station <b>4</b>-<b>3</b>, mobile node <b>5</b> establishes its connection to base station <b>4</b>-<b>3</b>. Mobile node <b>5</b> sends a signal for requesting a base station ID representing an inherent identification number owned by base station <b>4</b>-<b>3</b> (step <b>801</b>).
When the signal for requesting a base station ID is sent from mobile node <b>5</b>, the signal is received by base station <b>4</b>-<b>3</b> (step <b>802</b>).
When the signal for requesting a base station ID is received by base station <b>4</b>-<b>3</b>, base station <b>4</b>-<b>3</b> sends the base station ID representing its own inherent identification number to mobile node <b>5</b> (step <b>803</b>). The base station ID sent from base station <b>4</b>-<b>3</b> is received by mobile node <b>5</b> (step <b>804</b>). The base station ID may be any inherent number for identifying a base station. For example, the base station ID may be an IP address or the latitude and longitude of a location where base station <b>4</b>-<b>3</b> is installed.
When the base station ID of base station <b>4</b>-<b>3</b> is received by wireless communication unit <b>22</b> of mobile node <b>5</b>, the received base station ID is stored in base station connection information storage unit <b>25</b> by wireless controller <b>23</b>. Route update data generator <b>21</b> generates route update data as authentication packet data from the stored base station ID, a highest-level router number as a destination of packet data representing transfer route information, a mobile unit identifier stored in user information storage unit <b>24</b>, and a first authentication code that is generated from the above items of information and the secret key (step <b>805</b>). The highest-level router number as a destination is an inherent identification number held by router <b>1</b>, and may be an IP address or the like of router <b>1</b>.
When the route update data is generated, the generated route update data is sent from wireless communication unit <b>22</b> to base station <b>4</b>-<b>3</b> (step <b>806</b>). When the sent route update data is received by base station <b>4</b>-<b>3</b> (step <b>807</b>), the received route update data is sent from base station <b>403</b> to authentication-capable router <b>3</b>-<b>2</b> (step <b>808</b>).
When the route update date sent from base station <b>4</b>-<b>3</b> is received by base station communication unit <b>11</b> of authentication-capable router <b>3</b>-<b>2</b> (step <b>809</b>), the received route update data is output from base station communication unit <b>11</b> to packet transfer unit <b>12</b>. The route update data that is supplied to packet transfer unit <b>12</b> is transferred therefrom to route update data processor <b>14</b>.
When the route update data is supplied to route update data processor <b>14</b>, the route update data is authenticated by user authenticator <b>15</b>.
Specifically, user authenticator <b>15</b> retrieves user information stored in user information storage unit <b>18</b>, using as a retrieval key the mobile unit identifier included in the route update data. User authenticator <b>15</b> calculates a second authentication code using the secret key that is included in the user information that has been retrieved. User authenticator <b>15</b> compares the calculated second authentication code with the first authentication code included in the route update data (step <b>810</b>).
If the retrieval of user information fails or the calculated second authentication code does not agree with the first authentication code included in the route update data, then the route update data is recognized as incorrect data, and the wireless communication authentication process is terminated.
If the calculated second authentication code agrees with the first authentication code included in the route update data, then base station manager <b>16</b> determines whether the base station ID included in the route update data is the base station ID of a base station that is connected to and operates under its own router, i.e., authentication-capable router <b>3</b>-<b>2</b> (step <b>811</b>).
If base station manager <b>16</b> judges that the base station ID included in the route update data agrees with the base station ID, which is stored in base station information storage unit <b>19</b>, of a base station that is connected to and operates under its own router, then base station manager <b>16</b> sends an agreement signal to route update data processor <b>14</b>. Route update data processor <b>14</b> instructs packet transfer unit <b>12</b> to generate a route based on the route update data.
Packet transfer unit <b>12</b> now generates or updates a route for packet data sent from router <b>2</b>-<b>1</b> as a higher-level router for mobile node <b>5</b> (step <b>812</b>). At this time, the route update data of mobile node <b>5</b> has been received through base station <b>4</b>-<b>3</b> by authentication-capable router <b>3</b>-<b>2</b>. Therefore, the route to base station <b>4</b>-<b>3</b> is stored in route table storage unit <b>17</b> as a route for packet data sent from router <b>2</b>-<b>1</b> for mobile node <b>5</b>.
If base station manager <b>16</b> judges that the base station ID included in the route update data does not agree with the base station ID, which is stored in base station information storage unit <b>19</b>, of a base station that is connected to and operates under its own router, then the route update data is recognized as incorrect data, and the wireless communication authentication process is terminated.
Thereafter, higher-level router communication unit <b>13</b> sends the route update data to router <b>2</b>-<b>1</b> as a higher-level router (step <b>813</b>).
When the route update data is received by router <b>2</b>-<b>1</b> (step <b>814</b>), the route table in router <b>2</b>-<b>1</b> is updated based on the route update data (step <b>815</b>).
2nd Embodiment:
A wireless communication authentication system according to a second embodiment of the present invention will be described below particularly with respect to a process of authenticating a connection to a wireless LAN base station according to the protocol of IEEE802.1x, for example.
As shown in <figref idref="DRAWINGS">FIG. 9</figref>, the wireless communication authentication system according to the second embodiment comprises external network <b>40</b>, a pair of routers <b>31</b>-<b>1</b>, <b>31</b>-<b>2</b>, a plurality of base stations <b>32</b>-<b>1</b> through <b>32</b>-<b>8</b>, mobile node <b>33</b>, and a pair of RADIUS servers <b>34</b>-<b>1</b>, <b>34</b>-<b>2</b>. Routers <b>31</b>-<b>1</b>, <b>31</b>-<b>2</b> are connected to external network <b>40</b>. Base stations <b>32</b>-<b>1</b> through <b>32</b>-<b>4</b> are connected to and operate under router <b>31</b>-<b>1</b>. Base stations <b>32</b>-<b>5</b> through <b>32</b>-<b>8</b> are connected to and operate under router <b>31</b>-<b>2</b>. Mobile node <b>33</b> sends packet data to and receives packet data from external network <b>40</b> through the wireless communication authentication system. RADIUS (Remote Authentication Dial-In User Service) servers <b>34</b>-<b>1</b>, <b>34</b>-<b>2</b> are connected respectively to routers <b>31</b>-<b>1</b>, <b>31</b>-<b>2</b>. RADIUS servers <b>34</b>-<b>1</b>, <b>34</b>-<b>2</b> are servers having a protocol for determining (authenticating) whether a network resource can be utilized or not and for recording (accounting) the fact that a network resource is utilized. RADIUS servers <b>34</b>-<b>1</b>, <b>34</b>-<b>2</b> may be connected directly to base stations <b>32</b>-<b>1</b> through <b>32</b>-<b>8</b>, not through routers <b>31</b>-<b>1</b>, <b>31</b>-<b>2</b>.
As shown in <figref idref="DRAWINGS">FIG. 10</figref>, RADIUS server <b>34</b>-<b>1</b> shown in <figref idref="DRAWINGS">FIG. 9</figref> comprises communication controller <b>41</b>, RADIUS processor <b>42</b>, EAP processor <b>43</b>, user authenticator <b>44</b>, base station manager <b>45</b>, user information storage unit <b>46</b>, and base station information storage unit <b>47</b>. Communication controller <b>41</b> communicates with router <b>31</b>-<b>1</b> shown in <figref idref="DRAWINGS">FIG. 9</figref>. RADIUS processor <b>42</b> performs an authentication process with respect to base stations <b>32</b>-<b>1</b> through <b>32</b>-<b>4</b> according to the RADIUS protocol. EAP processor <b>43</b> analyzes EAP (PPP Extensible Authentication Protocol) data that has been encapsulated according to the RADIUS protocol. Base station information storage unit <b>47</b> stores in advance information of the base stations connected to and operable under router <b>31</b>-<b>1</b> that is connected to RADIUS server <b>34</b>-<b>1</b>. Base station manager <b>45</b> manages the information of the base stations which is stored in base station information storage unit <b>47</b>. User information storage unit <b>46</b> stores in advance user information (user names, secret keys, etc.) of users who are allowed to use the wireless communication authentication system. User authenticator <b>44</b> manages the user information stored in user information storage unit <b>46</b> and authenticates users based on the user information. RADIUS server <b>34</b>-<b>2</b> has structural and processing details that are identical to those of RADIUS server <b>34</b>-<b>1</b> though a different router is connected to RADIUS server <b>34</b>-<b>2</b>.
As shown in <figref idref="DRAWINGS">FIG. 11</figref>, mobile node <b>33</b> shown in <figref idref="DRAWINGS">FIG. 9</figref> comprises wireless communication unit <b>51</b>, EAP processor <b>52</b>, wireless controller <b>53</b>, user information storage unit <b>54</b>, and base station connection information storage unit <b>55</b>. Wireless communication unit <b>51</b> communicates with base stations <b>32</b>-<b>1</b> through <b>32</b>-<b>8</b> shown in <figref idref="DRAWINGS">FIG. 9</figref> through a wireless link. Base station connection information storage unit <b>55</b> stores connection information required for mobile node <b>33</b> to connect to base stations <b>32</b>-<b>1</b> through <b>32</b>-<b>8</b>. Wireless controller <b>53</b> manages the connection information stored in base station connection information storage unit <b>55</b>, and controls wireless communication unit <b>51</b>. User information storage unit <b>54</b> stores in advance user information including user names, secret keys, etc. EAP processor <b>52</b> manages the user information stored in user information storage unit <b>54</b>, and generates an EAP authentication packet.
A wireless communication authentication process which is carried out in the wireless communication authentication system shown in <figref idref="DRAWINGS">FIGS. 9 through 11</figref> will be described below with reference to <figref idref="DRAWINGS">FIG. 12</figref>. Router <b>31</b>-<b>1</b> is not shown in <figref idref="DRAWINGS">FIG. 12</figref> because no processing is performed in router <b>31</b>-<b>1</b> though packet data to be described below is routed through router <b>31</b>-<b>1</b>.
It is assumed that mobile node <b>33</b> is currently present in an area covered by base station <b>32</b>-<b>2</b>. Mobile node <b>33</b> establishes its connection to base station <b>32</b>-<b>2</b>, and sends a signal for requesting a base station ID representing an inherent identification number owned by base station <b>32</b>-<b>2</b> (step <b>1201</b>).
When the signal for requesting a base station ID is sent from mobile node <b>33</b>, the signal is received by base station <b>32</b>-<b>2</b> (step <b>1202</b>).
When the signal for requesting a base station ID is received by base station <b>32</b>-<b>2</b>, base station <b>32</b>-<b>2</b> sends the base station ID representing its own inherent identification number to mobile node <b>33</b> (step <b>1203</b>). The base station ID sent from base station <b>32</b>-<b>2</b> is received by mobile node <b>33</b> (step <b>1204</b>). The base station ID may be any inherent number for identifying a base station. For example, the base station ID may be an IP address or the like.
When the base station ID of base station <b>32</b>-<b>2</b> is received by wireless communication unit <b>51</b> of mobile node <b>33</b>, the received base station ID is stored in base station connection information storage unit <b>55</b> by wireless controller <b>53</b>. The stored base station ID is indicated to EAP processor <b>52</b>.
Thereafter, EAP processor <b>52</b> generates an EAPOL (EAP over LAN) start packet for starting an authentication process according to the protocol of IEEE802.1x (step <b>1205</b>). The generated EAPOL start packet is sent from wireless communication unit <b>51</b> to base station <b>32</b>-<b>2</b> (step <b>1206</b>). When the sent EAPOL start packet is received by base station <b>32</b>-<b>2</b> (step <b>1207</b>), an EAP request packet of an authentication request type depending on the received EAPOL start packet is sent from base station <b>32</b>-<b>2</b> to mobile node <b>33</b> (step <b>1208</b>). The sent EAP request packet is received by mobile node <b>33</b> (step <b>1209</b>). The EAPOL start packet and the EAP request packet will not be described in detail below as existing packets are used as the EAPOL start packet and the EAP request packet.
When the EAP request packet is received by wireless communication unit <b>51</b> of mobile node <b>33</b>, EAP processor <b>52</b> generates an EAP response packet representing authentication packet data serving as route update data, from the base station ID stored in base station connection information storage unit <b>55</b>, information as to a destination of packet data representing transfer route information registered in router <b>31</b>-<b>1</b>, a user name and a sequence number stored in user information storage unit <b>54</b>, and a first authentication code that is generated from the above items of information and the secret key (step <b>1210</b>). The information as to a destination of packet data is an inherent identification number owned by a destination of packet data sent from mobile node <b>33</b>, may be an IP address or the like of the destination.
When the EAP response packet is generated, the generated EAP response packet is sent from wireless communication unit <b>51</b> to base station <b>32</b>-<b>2</b> (step <b>1211</b>). When the EAP response packet sent from wireless communication unit <b>51</b> is received by base station <b>32</b>-<b>2</b> (step <b>1212</b>), the received EAP response packet is encapsulated into a RADIUS access request packet (step <b>1213</b>), which is sent from base station <b>32</b>-<b>2</b> to RADIUS server <b>34</b>-<b>1</b> (step <b>1214</b>).
When the RADIUS access request packet is received by communication controller <b>41</b> of RADIUS server <b>34</b>-<b>1</b> (step <b>1215</b>), the received RADIUS access request packet is transferred to RADIUS processor <b>42</b>. RADIUS processor <b>42</b> extracts the EAP response packet from the RADIUS access request packet (step <b>1216</b>).
The extracted EAP response packet is output from RADIUS processor <b>42</b> to EAP processor <b>43</b>, which determines whether the EAP response packet supplied to EAP processor <b>43</b> has been sent from a legitimate user or not.
Specifically, user authenticator <b>44</b> retrieves user information stored in user information storage unit <b>46</b>, using as a retrieval key the user name included in the EAP response packet. User authenticator <b>44</b> calculates a second authentication code using the secret key that is included in the user information that has been retrieved. User authenticator <b>44</b> compares the calculated second authentication code with the first authentication code included in the EAP response packet (step <b>1217</b>).
If the retrieval of user information fails or the calculated second authentication code does not agree with the first authentication code included in the EAP response packet, then the EAP response packet is recognized as incorrect data, and the wireless communication authentication process is terminated.
If the calculated second authentication code agrees with the first authentication code included in the EAP response packet, then base station manager <b>45</b> determines whether the base station ID included in EAP response packet is the base station ID of a base station that is connected to and operates under its own router, i.e., router <b>31</b>-<b>1</b> (step <b>1218</b>).
Base station manager <b>45</b> determines whether the base station ID included in the EAP response packet agrees with the base station ID, which is stored in base station information storage unit <b>47</b>, of a base station connected to and operable under router <b>31</b>-<b>1</b> that is connected to RADIUS server <b>34</b>-<b>1</b> or not. If the base station IDs agree with each other, then base station manager <b>45</b> sends an agreement signal to EAP processor <b>43</b>. Then, EAP processor <b>43</b> indicates an authentication success to RADIUS processor <b>42</b>, which sends a RADIUS access permission packet through communication controller <b>41</b> to base station <b>32</b>-<b>2</b> (step <b>1219</b>). At this time, router <b>31</b>-<b>1</b> on the route for the RADIUS access permission packet going from RADIUS server <b>34</b>-<b>1</b> to base station <b>32</b>-<b>2</b> recognizes that the connection of mobile node <b>33</b> to the wireless communication authentication system is permitted. The route table is updated for transferring packet data sent from external network <b>40</b> for mobile node <b>33</b> to base station <b>32</b>-<b>2</b>.
When the RADIUS access permission packet is received by base station <b>32</b>-<b>2</b> (step <b>1220</b>), base station <b>32</b>-<b>2</b> sends an EAP authentication success packet to mobile node <b>33</b> (step <b>1221</b>). The EAP authentication success packet sent from base station <b>32</b>-<b>2</b> is received by mobile node <b>33</b> (step <b>1222</b>), starting packet communications between mobile node <b>33</b> and external network <b>40</b>.
Therefore, even though no authenticating function is present in routers <b>31</b>-<b>1</b>, <b>31</b>-<b>2</b>, a high-speed authentication process can be performed by authentication servers provided respectively near routers <b>31</b>-<b>1</b>, <b>31</b>-<b>2</b>.
When the authentication process is performed, RADIUS servers <b>34</b>-<b>1</b>, <b>34</b>-<b>2</b> may send encryption keys to base stations <b>32</b>-<b>1</b> through <b>32</b>-<b>8</b> and mobile node <b>33</b>.
RADIUS servers <b>34</b>-<b>1</b>, <b>34</b>-<b>2</b> shown in <figref idref="DRAWINGS">FIG. 9</figref> may be replaced with servers employing another authentication protocol.
The numbers of routers <b>1</b>, <b>2</b>-<b>1</b>, <b>2</b>-<b>2</b>, <b>31</b>-<b>1</b>, <b>31</b>-<b>2</b>, authentication-cable routers <b>3</b>-<b>1</b> through <b>3</b>-<b>4</b>, RADIUS servers <b>34</b>-<b>1</b>, <b>34</b>-<b>2</b>, and base stations <b>4</b>-<b>1</b> through <b>4</b>-<b>8</b>, <b>32</b>-<b>1</b> through <b>32</b>-<b>8</b>, and the number of hierarchical levels thereof are not limited to the illustrated numbers.
While preferred embodiments of the present invention have been described using specific terms, such description is for illustrative purposes only, and it is to be understood that changes and variations may be made without departing from the spirit or scope of the following claims.
Contents4
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both waysCites: the store holds 40 of 41
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2000341749A | Cites | Japan | Applicant |
| JP2001266277A | Cites | Japan | Applicant |
| US2002018569A1 | Cites | United States of America | Search report |
| JP2002281010A | Cites | Japan | Applicant |
| JP2002300152A | Cites | Japan | Applicant |
| US2003169713A1 | Cites | United States of America | Applicant |
| US2004088544A1 | Cites | United States of America | Search report |
| US2004240411A1 | Cites | United States of America | Applicant |
| JP2004274602A | Cites | Japan | Applicant |
| US2005014515A1 | Cites | United States of America | Search report |
| US2005191992A1 | Cites | United States of America | Applicant |
| US2005249225A1 | Cites | United States of America | Search report |
| US2006004643A1 | Cites | United States of America | Search report |
| US2006034238A1 | Cites | United States of America | Applicant |
| US2006101273A1 | Cites | United States of America | Search report |
| US6304968B1 | Cites | United States of America | Search report |
| US6668166B1 | Cites | United States of America | Search report |
| US6891819B1 | Cites | United States of America | Applicant |
| US6973068B2 | Cites | United States of America | Applicant |
| US7095857B2 | Cites | United States of America | Applicant |
| US7177848B2 | Cites | United States of America | Search report |
| JPH07203540A | Cites | Japan | Applicant |
| JPH11161618A | Cites | Japan | Applicant |
| US20020018569A1 | Cites | United States of America | Search report |
| US20030169713A1 | Cites | United States of America | Applicant |
| US20040088544A1 | Cites | United States of America | Search report |
| US20040240411A1 | Cites | United States of America | Applicant |
| US20050014515A1 | Cites | United States of America | Search report |
| US20050191992A1 | Cites | United States of America | Applicant |
| US20050249225A1 | Cites | United States of America | Search report |
| US20060004643A1 | Cites | United States of America | Search report |
| US20060034238A1 | Cites | United States of America | Applicant |
| US20060101273A1 | Cites | United States of America | Search report |
| JP7203540 | Cites | Japan | Applicant |
| JP11161618 | Cites | Japan | Applicant |
| JP2000341749A | Cites | Japan | Applicant |
| JP2001266277A | Cites | Japan | Applicant |
| JP2002281010A | Cites | Japan | Applicant |
| JP2002300152A | Cites | Japan | Applicant |
| JP2004274602A | Cites | Japan | Applicant |
| E. Farag et al., "Structure and Network Control of a Hierarchical Mobile Network Architecture," Computers and Communications, Conference Proceedings of the 1995 IEEE Fourteenth Annual International Phoenix Conference, pp. 671-677. | Non-patent | – | Applicant |
| E. Farag et al., “Structure and Network Control of a Hierarchical Mobile Network Architecture,” Computers and Communications, Conference Proceedings of the 1995 IEEE Fourteenth Annual International Phoenix Conference, pp. 671-677. | Non-patent | – | Applicant |
5 members in 3 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 2005182029 | Japan | – | |
| 2005182029 | Japan | A | |
| 2005182029 | Japan | A | |
| 2005182029 | – | – | – |
| JP20050182029 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| EP1737183A1 | European Patent Office (EPO) | A1 | |
| US2006291659A1 | United States of America | A1 | |
| JP2007006003A | Japan | A | |
| JP4375287B2 | Japan | B2 | |
| US9270652B2This record | United States of America | B2 |
104 transactions on the USPTO file
Allowed after 5 non-final rejections, 4 final rejections, 3 RCEs and 1 appeal.
- Non-final rejections
- 5
- Final rejections
- 4
- RCEs
- 3
- Appeals
- 1
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Interview Summary - Examiner Initiated - TelephonicEXET | EXET | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Interview Summary - Applicant Initiated - TelephonicMEXAT | MEXAT | |
| Interview Summary- Applicant InitiatedEXIA | EXIA | |
| Interview Summary - Applicant Initiated - TelephonicEXAT | EXAT | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Mail Appeals conf. Reopen Prosec.MAPCR | MAPCR | |
| Pre-Appeals Conference Decision - Reopen ProsecutionAPCR | APCR | |
| Request for Pre-Appeal Conference FiledAP.C | AP.C | |
| Notice of Appeal FiledN/AP | N/AP | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Examiner Interview Summary (PTOL - 413)MEXIN | MEXIN | |
| Examiner Interview Summary Record (PTOL - 413)EXIN | EXIN | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| New or Additional Drawing FiledC614 | C614 | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Application Is Now CompleteCOMP | COMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Maintenance fee paymentMAFP | MAFP | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication
- 09270652
- Publication, DOCDB
- 9270652
- Publication, EPODOC
- US9270652
- Application
- 11454886
- Application, DOCDB
- 45488606
- Application, EPODOC
- US20060454886
Titles
- English
- Wireless communication authentication
Patent term adjustment
- A delay
- +875 daysthe office missed an examination deadline
- B delay
- +533 dayspendency past three years
- Overlap
- −108 daysdelays counted once
- Applicant delay
- −818 days
- Net adjustment
- 482 days
Classification
- CPC, 3
- H04L63/08
- H04W12/0602
- H04W12/06
- IPC, 10
- G09C1 00
- H04M1 66
- H04L9 32
- H04L12 701
- H04L12 753
- H04L29 06
- H04M1 68
- H04M3 16
- H04W12 00
- H04W12 06
- USPC, 1
- 001001000