Enhanced security for direct link communications
    3.
    发明授权
    Enhanced security for direct link communications 有权
    增强直接链接通信的安全性

    公开(公告)号:US08892874B2

    公开(公告)日:2014-11-18

    申请号:US12639293

    申请日:2009-12-16

    摘要: A method for secure direct link communications between multiple wireless transmit/receive units (WTRUs). The WTRUs exchange nonces that are used for generating a common nonce. A group identification information element (GIIE) is generated from at least the common nonce and is forwarded to an authentication server. The authentication server generates a group direct link master key (GDLMK) from the GIIE to match WTRUs as part of a key agreement group. Group key encryption key (GKEK) and a group key confirmation key (GKCK) are also generated based on the common nonce and are used to encrypt and sign the GDLMK so that base stations do not have access to the GDLMK. Also disclosed is a method for selecting a key management suite (KMS) to generate temporal keys. A KMS index (KMSI) may be set according to a selected KMS, transmitted to another WTRU and used to establish a direct link.

    摘要翻译: 一种用于多个无线发射/接收单元(WTRU)之间的安全直接链路通信的方法。 WTRU交换用于生成公共随机数的随机数。 从至少公共随机数生成组标识信息元素(GIIE),并将其转发给认证服务器。 认证服务器从GIIE生成组直接链路主密钥(GDLMK),作为密钥协商组的一部分匹配WTRU。 组密钥加密密钥(GKEK)和组密钥确认密钥(GKCK)也是基于通用随机数生成的,用于对GDLMK进行加密和签名,以使基站无法访问GDLMK。 还公开了一种用于选择密钥管理套件(KMS)以生成时间密钥的方法。 可以根据所选择的KMS设置KMS索引(KMSI),发送到另一个WTRU并用于建立直接链路。

    AUTHENTICATION FOR SECURE WIRELESS COMMUNICATION
    4.
    发明申请
    AUTHENTICATION FOR SECURE WIRELESS COMMUNICATION 有权
    安全无线通信认证

    公开(公告)号:US20140173682A1

    公开(公告)日:2014-06-19

    申请号:US13121190

    申请日:2009-09-18

    IPC分类号: H04W12/06

    摘要: A method and apparatus for use in authentication for secure wireless communication is provided. A received signal is physically authenticated and higher layer processed. Physical authentication includes performing hypothesis testing using a channel impulse response (CIR) measurement of the received signal and predetermined referenced data. Higher layer processing includes validating the signal using a one-way hash chain value in the signal. Once a signal is authenticated, secure wireless communication is performed.

    摘要翻译: 提供了一种用于安全无线通信认证的方法和装置。 接收到的信号经过身份验证并进行了较高层处理。 物理认证包括使用接收信号的信道脉冲响应(CIR)测量和预定的参考数据进行假设检验。 较高层处理包括使用信号中的单向哈希链值验证信号。 一旦信号被认证,就执行安全的无线通信。

    VALIDATION AND/OR AUTHENTICATION OF A DEVICE FOR COMMUNICATION WITH NETWORK
    5.
    发明申请
    VALIDATION AND/OR AUTHENTICATION OF A DEVICE FOR COMMUNICATION WITH NETWORK 有权
    用于与网络通信的设备的验证和/或认证

    公开(公告)号:US20140129815A9

    公开(公告)日:2014-05-08

    申请号:US12760690

    申请日:2010-04-15

    IPC分类号: G06F21/02 G06F9/445

    CPC分类号: H04W12/10 H04L63/123

    摘要: A device may include a trusted component. The trusted component may be verified by a trusted third party and may have a certificate of verification stored therein based on the verification by the trusted third party. The trusted component may include a root of trust that may provide secure code and data storage and secure application execution. The root of trust may also be configured to verify an integrity of the trusted component via a secure boot and to prevent access to the certain information in the device if the integrity of the trusted component may not be verified.

    摘要翻译: 设备可以包括可信组件。 受信任的组件可以由受信任的第三方验证,并且可以基于可信赖的第三方的验证来存储其中的验证证书。 受信任的组件可以包括可以提供安全代码和数据存储以及安全应用执行的信任根。 还可以配置信任根以通过安全引导来验证可信组件的完整性,并且如果可信组件的完整性可能未被验证,则阻止访问设备中的某些信息。

    Secure session key generation
    6.
    发明授权
    Secure session key generation 有权
    安全会话密钥生成

    公开(公告)号:US08510559B2

    公开(公告)日:2013-08-13

    申请号:US12419798

    申请日:2009-04-07

    IPC分类号: H04L9/00

    摘要: A method and apparatus for securing the interface between a Universal Integrated Circuit Card (UICC) and a Terminal in wireless communications is disclosed. The security of Authentication and Key Agreement (AKA) and application level generic bootstrapping architecture (GBA) with UICC-based enhancements (GBA_U) procedures is improved. A secure shared session key is used to encrypt communications between the UICC and the Terminal. The secure shared session key generated using authenticating or non-authenticating procedures.

    摘要翻译: 公开了一种在无线通信中用于固定通用集成电路卡(UICC)和终端之间的接口的方法和装置。 基于UICC的增强(GBA_U)程序的身份验证和密钥协商(AKA)和应用级通用引导体系结构(GBA)的安全性得到了改进。 安全的共享会话密钥用于加密UICC和终端之间的通信。 使用验证或非验证过程产生的安全共享会话密钥。

    Support of physical layer security in wireless local area networks
    7.
    发明授权
    Support of physical layer security in wireless local area networks 有权
    支持无线局域网中的物理层安全

    公开(公告)号:US08433894B2

    公开(公告)日:2013-04-30

    申请号:US12499530

    申请日:2009-07-08

    IPC分类号: H04L29/06

    摘要: A method and an apparatus for performing physical layer security operation are disclosed. A physical layer performs measurements continuously, and reports the measurements to a medium access control (MAC) layer. The MAC layer processes the measurements, and sends a security alert to a security manager upon detection of an abnormal condition based on the measurements. The security manager implements a counter-measure upon receipt of the security alert. The measurements include channel impulse response (CIR), physical medium power measurement, automatic gain control (AGC) value and status, automatic frequency control (AFC) gain and status, analog-to-digital converter (ADC) gain, Doppler spread estimate, and/or short preamble matched filter output. The security manager may switch a channel, switch a channel hopping policy, change a back-off protocol, or change a beamforming vector upon reception of the security alert.

    摘要翻译: 公开了一种用于执行物理层安全操作的方法和装置。 物理层连续执行测量,并将测量结果报告给介质访问控制(MAC)层。 MAC层处理测量,并且在基于测量检测到异常状况时向安全管理器发送安全警报。 安全管理员在收到安全警报后实施对抗措施。 测量包括信道脉冲响应(CIR),物理介质功率测量,自动增益控制(AGC)值和状态,自动频率控制(AFC)增益和状态,模数转换器(ADC)增益,多普勒扩展估计, 和/或短前同步码匹配滤波器输出。 在接收到安全警报时,安全管理器可以切换信道,切换信道跳频策略,改变退避协议或改变波束成形向量。

    IDENTITY MANAGEMENT ON A WIRELESS DEVICE
    8.
    发明申请
    IDENTITY MANAGEMENT ON A WIRELESS DEVICE 有权
    无线设备的身份管理

    公开(公告)号:US20120254959A1

    公开(公告)日:2012-10-04

    申请号:US13237344

    申请日:2011-09-20

    IPC分类号: H04W12/04

    摘要: A wireless device may perform a local authentication to reduce the traffic on a network. The local authentication may be performed using a local web server and/or a local OpenID provider (OP) associated with the wireless device. The local web server and/or local OP may be implemented on a security module, such as a smartcard or a trusted execution environment for example. The local OP and/or local web server may be used to implement a provisioning phase to derive a session key, associated with a service provider, from an authentication between the wireless device and the network. The session key may be reusable for subsequent local authentications to locally authenticate a user of the wireless device to the service provider.

    摘要翻译: 无线设备可以执行本地认证以减少网络上的流量。 可以使用与无线设备相关联的本地Web服务器和/或本地OpenID提供商(OP)来执行本地认证。 本地Web服务器和/或本地OP可以在例如智能卡或可信执行环境的安全模块上实现。 可以使用本地OP和/或本地Web服务器实现供应阶段,以从无线设备和网络之间的认证导出与服务提供商相关联的会话密钥。 会话密钥可以可重用于随后的本地认证,以向服务提供商本地认证无线设备的用户。

    METHOD AND APPARATUS FOR SECURE TRUSTED TIME TECHNIQUES
    9.
    发明申请
    METHOD AND APPARATUS FOR SECURE TRUSTED TIME TECHNIQUES 有权
    用于安全实时技术的方法和装置

    公开(公告)号:US20100011214A1

    公开(公告)日:2010-01-14

    申请号:US12389088

    申请日:2009-02-19

    IPC分类号: H04L9/00

    摘要: A method and apparatus to establish a trustworthy local time based on trusted computing methods are described. The concepts are scaling because they may be graded by the frequency and accuracy with which a reliable external time source is available for correction and/or reset, and how trustworthy this external source is in a commercial scenario. The techniques also take into account that the number of different paths and number of hops between the device and the trusted external time source may vary. A local clock related value which is protected by a TPM securely bound to an external clock. A system of Accuracy Statements (AS) is added to introduce time references to the audit data provided by other maybe cheaper sources than the time source providing the initial time.

    摘要翻译: 描述了基于可信计算方法建立可靠的本地时间的方法和装置。 概念是缩放,因为它们可以通过可靠的外部时间源可用于校正和/或重置的频率和准确度进行分级,并且在商业场景中该外部源是如何可信赖的。 这些技术还考虑到设备与受信任的外部时间源之间的不同路径和跳数的数量可能会有所不同。 由TPM保护的本地时钟相关值安全地绑定到外部时钟。 添加准确性声明(AS)的系统来引入时间参考,以提供其他可能比提供初始时间的时间源更便宜的源提供的审计数据。

    SECURE SESSION KEY GENERATION
    10.
    发明申请
    SECURE SESSION KEY GENERATION 有权
    安全会话密钥生成

    公开(公告)号:US20090313472A1

    公开(公告)日:2009-12-17

    申请号:US12419798

    申请日:2009-04-07

    IPC分类号: H04L9/00 H04L29/06

    摘要: A method and apparatus for securing the interface between a Universal Integrated Circuit Card (UICC) and a Terminal in wireless communications is disclosed. The security of Authentication and Key Agreement (AKA) and application level generic bootstrapping architecture (GBA) with UICC-based enhancements (GBA_U) procedures is improved. A secure shared session key is used to encrypt communications between the UICC and the Terminal. The secure shared session key generated using authenticating or non-authenticating procedures.

    摘要翻译: 公开了一种在无线通信中用于固定通用集成电路卡(UICC)和终端之间的接口的方法和装置。 基于UICC的增强(GBA_U)程序的身份验证和密钥协商(AKA)和应用级通用引导体系结构(GBA)的安全性得到了改进。 安全的共享会话密钥用于加密UICC和终端之间的通信。 使用验证或非验证过程产生的安全共享会话密钥。