Protected mutual authentication over an unsecured wireless communication channel
    1.
    发明授权
    Protected mutual authentication over an unsecured wireless communication channel 有权
    通过不安全的无线通信信道进行受保护的相互认证

    公开(公告)号:US07024690B1

    公开(公告)日:2006-04-04

    申请号:US09561088

    申请日:2000-04-28

    IPC分类号: H04L9/00 H04K1/00

    摘要: A process for mutual authentication of users and networks over an unsecured wireless communication channel. In one embodiment, sensitive information (e.g., passwords) is not communicated over the unsecured channel. Rather, hashed representations of user identifiers, passwords, etc., and randomly generated numbers are communicated between the client and the network during the log-in process. The representations may be encrypted with a one-way hash function such that it is not computationally feasible for an eavesdropper to decrypt. In one embodiment, the representation may be generated based on the user identifier, password and/or MAC address of a wireless LAN card.

    摘要翻译: 用于通过不安全的无线通信信道进行用户和网络的相互认证的过程。 在一个实施例中,敏感信息(例如,密码)不通过不安全的信道传送。 相反,在登录过程中,在客户端和网络之间传递用户标识符,密码等的随机生成的数字和随机生成的数字。 这些表示可以用单向散列函数加密,使得窃听者解密不是计算上可行的。 在一个实施例中,可以基于无线LAN卡的用户标识符,密码和/或MAC地址来生成表示。

    Using a key lease in a secondary authentication protocol after a primary authentication protocol has been performed
    2.
    发明授权
    Using a key lease in a secondary authentication protocol after a primary authentication protocol has been performed 有权
    在执行了一次认证协议之后,在辅助认证协议中使用密钥租约

    公开(公告)号:US06920559B1

    公开(公告)日:2005-07-19

    申请号:US09561416

    申请日:2000-04-28

    摘要: The present invention provides a method and system for using a key lease in a secondary authentication protocol after a primary authentication protocol has been performed. In one embodiment, the primary authentication protocol comprises a strong, secure, computationally complex authentication protocol. Moreover, the secondary authentication protocol comprises a less complex (compared to the primary authentication protocol) and less secure (compared to the primary authentication protocol) authentication protocol which can be performed in a length of time that is shorter than a length of time required to perform the primary authentication protocol. In one embodiment, a wireless client electronic system (WC) completes the primary authentication protocol with a wireless network access point electronic system of a wireless network (AP). When the WC is required to authenticate with another AP, the WC authenticates itself with another AP by using the secondary authentication protocol. However, the WC is required to periodically complete the primary authentication protocol, guarding against the possibility that the secondary authentication protocol may be exploited by an unauthorized intruder to attack the wireless network. In one embodiment, a third party technique is implemented to store a key necessary to perform the secondary authentication protocol.

    摘要翻译: 本发明提供了在执行主认证协议之后在辅认证协议中使用密钥租赁的方法和系统。 在一个实施例中,主认证协议包括强的,安全的,计算上复杂的认证协议。 此外,辅助认证协议包括较不复杂(与主认证协议相比)和较不安全的(与主认证协议相比)认证协议,其可以在比时间长度短的时间长度执行 执行主认证协议。 在一个实施例中,无线客户端电子系统(WC)用无线网络(AP)的无线网络接入点电子系统完成主认证协议。 当需要WC与另一个AP进行认证时,WC通过使用辅助认证协议对另一个AP进行身份验证。 然而,WC需要定期完成主认证协议,防止未经授权的入侵者利用辅助认证协议攻击无线网络的可能性。 在一个实施例中,实现第三方技术以存储执行辅助认证协议所必需的密钥。

    Method and system for improving throughput over wireless local area networks with a dynamic contention window
    3.
    发明授权
    Method and system for improving throughput over wireless local area networks with a dynamic contention window 有权
    用动态争用窗口提高无线局域网吞吐量的方法和系统

    公开(公告)号:US06965942B1

    公开(公告)日:2005-11-15

    申请号:US09759389

    申请日:2001-01-12

    IPC分类号: G06F15/16 H04L12/43

    CPC分类号: H04W74/085 H04W84/12

    摘要: A method and system for increasing the overall network throughput over a wireless local area network (WLAN). Specifically, in one embodiment of the present invention, the dynamic selection of an initial value for a contention window in the Distributed Coordinated Function (DCF) mode is determined according to the load conditions over the WLAN in a method and system. Stations and access points within a WLAN monitor conditions within the network to establish an initial value for the contention window, also called a minimum contention window value, which is lower than that set by the IEEE 802.11 communication standard. Some factors to consider in determining the load conditions include but are not limited to the following: number of transmissions; number of receptions; and number of collisions.

    摘要翻译: 一种用于通过无线局域网(WLAN)增加总体网络吞吐量的方法和系统。 具体地说,在本发明的一个实施例中,根据在方法和系统中的WLAN上的负载条件来确定分布式协调功能(DCF)模式中的竞争窗口的初始值的动态选择。 WLAN监视器内的站点和接入点在网络内条件下建立竞争窗口的初始值,也称为最小竞争窗口值,该值低于IEEE 802.11通信标准设置的最小竞争窗口值。 在确定负载条件时要考虑的一些因素包括但不限于以下:变速箱数量; 接待人数; 和碰撞次数。

    Method and system for improving throughput over wireless local area networks with mode switching
    4.
    发明授权
    Method and system for improving throughput over wireless local area networks with mode switching 有权
    用于通过模式切换提高无线局域网的吞吐量的方法和系统

    公开(公告)号:US06990116B1

    公开(公告)日:2006-01-24

    申请号:US09759770

    申请日:2001-01-12

    IPC分类号: H04L12/413

    摘要: A method and system for increasing the overall network throughput over a wireless local area network (WLAN). Specifically, in one embodiment of the present invention, the dynamic switching between the Distributed Coordination Function (DCF) and Point Coordination Function IEEE 802.11 access modes is determined according to the load conditions over the WLAN in a method and system. Stations and access points within a WLAN monitor conditions within the network to determine which access mechanism is most optimum for the current load conditions. Some factors to consider in determining the load conditions include but are not limited to the number of transmissions, number of receptions, and number of collisions.

    摘要翻译: 一种用于通过无线局域网(WLAN)增加总体网络吞吐量的方法和系统。 具体地说,在本发明的一个实施例中,分布式协调功能(DCF)和点协调功能IEEE 802.11接入模式之间的动态切换是根据WLAN中的方法和系统中的负载条件确定的。 WLAN监视器内的站点和接入点在网络内进行条件,以确定哪种访问机制对于当前的负载条件是最佳的。 在确定负载条件时要考虑的一些因素包括但不限于传输次数,接收次数和冲突次数。

    Method and system for providing network connectivity and mobility while roaming
    5.
    发明授权
    Method and system for providing network connectivity and mobility while roaming 有权
    漫游时提供网络连接和移动性的方法和系统

    公开(公告)号:US07002932B1

    公开(公告)日:2006-02-21

    申请号:US09759848

    申请日:2001-01-12

    IPC分类号: H04H1/00

    摘要: A method and system for providing network connectivity and mobility for a roaming client. Specifically, in one embodiment of the present invention, an access point (AP) is enabled with a smart agent and associated protocol. The smart agent is capable of monitoring the AP link status to the backbone network and where applicable the capability to capture the TCP/IP information. Further, the smart agent located at the AP has the capability of sending the AP connection and network status information to a client when that client associates with the AP, or when the AP's network status or configuration changes. The effect of the invention is to provide a radically simple user experience in networking connectivity and mobility in both wired and wireless network infrastructures.

    摘要翻译: 一种用于为漫游客户端提供网络连接和移动性的方法和系统。 具体地,在本发明的一个实施例中,接入点(AP)能够使用智能代理和相关协议。 智能代理能够监控到骨干网的AP链路状态,并在适用的情况下监视捕获TCP / IP信息的能力。 此外,位于AP的智能代理具有当客户端与AP相关联时或当AP的网络状态或配置发生变化时向客户端发送AP连接和网络状态信息的能力。 本发明的效果是提供有线和无线网络基础设施中的网络连接性和移动性的极简单的用户体验。