WO2004084458A2

Wlan session management techniques with secure rekeying and logoff

Abstract

The invention provides a method for improving the security of a mobile terminal in a WLAN environment by installing two shared secrets instead of one shared secret, the initial session key, on both the wireless user machine and the WLAN access point during the user authentication phase. One of the shared secrets is used as the initial session key and the other is used as a secure seed. Since the initial authentication is secure, these two keys are not known to a would be hacker. Although the initial session key may eventually be cracked by the would be hacker, the secure seed remains secure as it is not used in any insecure communication.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

23 claims: 11 independent, 12 dependent

  1. 1
    We Claim:1. A method for providing a secure communications session with a user terminal in a communications network, the method comprising the steps of: transmitting first and second secure keys to the user terminal using a secure communications method, the first and second secure keys being suitable for storage in the user terminal for use during the secure communications session;encrypting and transmitting data to the user terminal using a current session key, and receiving and decrypting data received from the user terminal using the current session key, the first secure key initially being used as the current session key;and periodically generating a subsequent session key using the second secure key and using the subsequent session key as the current session key during subsequent communications between the communications network and the user terminal.
  2. 4
    A method for providing a secure communications session with a mobile terminal in a wireless local access network (WLAN), the method comprising the steps of:transmitting first and second secure keys to the mobile terminal using a secure communications method, the first and second secure keys being suitable for storage in the mobile terminal for use during the secure communications session;encrypting and transmitting data to the mobile terminal using a current session key, and receiving and decrypting data received from the mobile terminal using the current session key, the first secure key initially being used as the current session key;and periodically generating a subsequent session key using the second secure key and using the subsequent session key as the current session key during subsequent communications with the mobile terminal.
  3. 7
    A method for providing a secure communications session with a mobile terminal in a wireless local access network (WLAN), the method comprising the steps of:generating a secure key;transmitting the secure key to the mobile terminal using a secure communications method, the secure key being stored in the mobile terminal for use during the secure communications session;encrypting and transmitting data to the mobile terminal using a current session key, and receiving and decrypting data received from the mobile terminal using the current session key;and ending the secure communications session in response to receiving a logoff message from the mobile terminal, the logoff message being in encrypted form and including the secure key.
  4. 8
    A method for providing a secure communications session with a mobile terminal in a wireless local access network (WLAN), the method comprising the steps of:generating first and second secure keys;transmitting the first and second secure keys to the WLAN using a secure communications method, the first and second secure keys being stored in the WLAN for use during the secure communications session;encrypting and transmitting data to the WLAN using a current session key, and receiving and decrypting data received from the WLAN using the current session key, the first secure key initially being used as the current session key;and periodically generating a subsequent session key using the second secure key and using the subsequent session key as the current session key during subsequent communications with the mobile terminal.
  5. 11
    A method for providing a secure communications session with a mobile terminal in a wireless local access network (WLAN), the method comprising the steps of:generating a secure key;transmitting the secure key to the WLAN using a secure communications method, the secure key being stored in the WLAN for use during the secure communications session;encrypting and transmitting data to the WLAN using a current session key, and receiving and decrypting data received from the WLAN using the current session key;and ending the secure communications session in response to receiving a logoff message from the WLAN, the logoff message being in encrypted form and including the secure key.
  6. 12
    A method for providing a secure communications session with a mobile terminal in a wireless local access network (WLAN), the method comprising the steps of:installing at least two shared secrets on both the mobile terminal and the WLAN access point during the user authentication phase whereby a first secret is the initial session key and a second secret is utilized as secure seed to generate subsequent session keys.
  7. 18
    A method for providing a secure communications session between a mobile terminal and a wireless local access network (WLAN), the method comprising the steps of:a mobile terminal sending during session logoff an encrypted logoff request accompanied by the secure seed such that the secure seed appears in the logoff request.
  8. 19
    An access point for providing a secure communications session between a mobile terminal and a wireless local access network (WLAN), comprising:a means for transmitting first and second secure keys to the mobile terminal using a secure communications method and a means to encrypt data using the first secure key and a means to periodically generate a subsequent session key using the second secure key.
  9. 20
    A terminal device for providing a secure communications session with a communications network, comprising:a means to receive a first secure key and a second secure key and a means to store the first secure key and the second secure key for use during the secure communications session;a means to receive data and a means to decrypt the data using a current session key during the secure communications session, the first secure being using initially as the current session key;and a means to generate a subsequent session key using the current session key and the second secure key, the subsequent session key thereafter being used as the current session key for subsequent communications.
  10. 22
    The access point for providing a secure communications session between a mobile terminal and a wireless local access network (WLAN) in claim 20, wherein the means to periodically generate a subsequent session key comprises a means to generate a subsequent session key using a combination of a new key and the second secure key, the new key being generated by means using the first secure key.
  11. 23
    The access point for providing a secure communications session between a mobile terminal and a wireless local access network (WLAN) in claim 20, wherein the means to periodically generate a subsequent session key comprises a means to generate a subsequent session key by concatenating the new key and the second secure key and a means for running a hash algorithm to generate the subsequent session key.