Methods, apparatuses, system, and related computer program products for handover security
    2.
    发明授权
    Methods, apparatuses, system, and related computer program products for handover security 有权
    方法,设备,系统和相关的计算机程序产品,用于切换安全

    公开(公告)号:US08331906B2

    公开(公告)日:2012-12-11

    申请号:US12809959

    申请日:2008-12-08

    IPC分类号: H04M1/66

    摘要: It is disclosed a method comprising receiving, prior to a handover operation, first key indication information, creating, prior to the handover operation, key information based on the received first key indication information, retaining the created key information, sending, after the handover operation, the received first key indication information associated with the key information created prior to the handover operation, and retrieving, after the handover operation, the retained key information based on the first key indication information; and a method comprising generating, prior to the handover operation, the first key indication information associated with key information intended to be created, sending, prior to the handover operation, the generated first key indication information, and receiving, after the handover operation, second key indication information corresponding to the generated first key indication information.

    摘要翻译: 公开了一种方法,包括在切换操作之前接收第一密钥指示信息,在切换操作之前,基于接收的第一密钥指示信息创建密钥信息,保留所创建的密钥信息,在切换操作之后发送 所接收的与切换操作之前创建的密钥信息相关联的第一密钥指示信息,以及在切换操作之后,基于第一密钥指示信息检索保留的密钥信息; 以及一种方法,包括在切换操作之前生成与要生成的密钥信息相关联的第一密钥指示信息,在切换操作之前发送生成的第一密钥指示信息,以及在切换操作之后接收第二密钥指示信息 与所生成的第一密钥指示信息对应的密钥指示信息。

    METHODS, APPARATUSES, SYSTEM, AND RELATED COMPUTER PROGRAM PRODUCTS FOR HANDOVER SECURITY
    3.
    发明申请
    METHODS, APPARATUSES, SYSTEM, AND RELATED COMPUTER PROGRAM PRODUCTS FOR HANDOVER SECURITY 有权
    方法,装置,系统和相关的计算机程序产品用于切换安全

    公开(公告)号:US20110201337A1

    公开(公告)日:2011-08-18

    申请号:US12809959

    申请日:2008-12-08

    IPC分类号: H04W36/00

    摘要: It is disclosed a method comprising receiving, prior to a handover operation, first key indication information, creating, prior to the handover operation, key information based on the received first key indication information, retaining the created key information, sending, after the handover operation, the received first key indication information associated with the key information created prior to the handover operation, and retrieving, after the handover operation, the retained key information based on the first key indication information; and a method comprising generating, prior to the handover operation, the first key indication information associated with key information intended to be created, sending, prior to the handover operation, the generated first key indication information, and receiving, after the handover operation, second key indication information corresponding to the generated first key indication information.

    摘要翻译: 公开了一种方法,包括在切换操作之前接收第一密钥指示信息,在切换操作之前,基于接收的第一密钥指示信息创建密钥信息,保留所创建的密钥信息,在切换操作之后发送 所接收的与切换操作之前创建的密钥信息相关联的第一密钥指示信息,以及在切换操作之后,基于第一密钥指示信息检索保留的密钥信息; 以及一种方法,包括在切换操作之前生成与要生成的密钥信息相关联的第一密钥指示信息,在切换操作之前发送生成的第一密钥指示信息,以及在切换操作之后接收第二密钥指示信息 与所生成的第一密钥指示信息对应的密钥指示信息。

    METHODS, APPARATUSES AND COMPUTER PROGRAM PRODUCTS FOR PROVIDING MULTI-HOP CRYPTOGRAPHIC SEPARATION FOR HANDOVERS
    4.
    发明申请
    METHODS, APPARATUSES AND COMPUTER PROGRAM PRODUCTS FOR PROVIDING MULTI-HOP CRYPTOGRAPHIC SEPARATION FOR HANDOVERS 审中-公开
    方法,设备和计算机程序产品,用于提供切换器的多层结构分离

    公开(公告)号:US20110116629A1

    公开(公告)日:2011-05-19

    申请号:US12936332

    申请日:2009-03-30

    IPC分类号: H04L9/00

    摘要: A method, apparatus and computer program product are provided to provide cryptographical key separation for handovers. A method is provided which includes calculating a key based at least in part upon a previously stored first intermediary value. The method also includes calculating a second intermediary value based at least in part upon the calculated key. The method additionally includes sending a path switch acknowledgement including the second intermediary value to a target access point. The method may further include receiving a path switch message including an indication of a cell identification and calculating the encryption key based upon the indication of the cell identification. The method may further include storing the second intermediary value. The calculation of the key may further comprise calculating the key following a radio link handover. Corresponding apparatuses and computer program products are also provided.

    摘要翻译: 提供了一种方法,装置和计算机程序产品来提供用于切换的密码分离。 提供了一种方法,其包括至少部分地基于先前存储的第一中间值来计算密钥。 该方法还包括至少部分地基于所计算的密钥来计算第二中间值。 该方法另外包括将包括第二中间值的路径切换确认发送到目标接入点。 该方法还可以包括接收包括小区标识的指示的路径切换消息,并且基于小区标识的指示来计算加密密钥。 该方法还可以包括存储第二中间值。 密钥的计算还可以包括在无线电链路切换之后计算密钥。 还提供了相应的设备和计算机程序产品。

    METHODS AND APPARATUS FOR AUTHENTICATION
    5.
    发明申请
    METHODS AND APPARATUS FOR AUTHENTICATION 有权
    验证方法和设备

    公开(公告)号:US20140019763A1

    公开(公告)日:2014-01-16

    申请号:US13547512

    申请日:2012-07-12

    IPC分类号: H04L9/32

    摘要: Message authentication in an ad-hoc network. Upon creation of a message, a message authentication code is created using a key shared with members of a group comprising a subset of nodes of the ad-hoc network. The message authentication code may be created using a cryptographic process having the message and a message identifier as inputs. After or in parallel with broadcast of the message, a pointer to the message is broadcast. The message authentication code is publicly broadcast and those members of the group among which the key has been shared are able to authenticate the message as coming from a particular sender.

    摘要翻译: 在ad-hoc网络中的消息认证。 在创建消息时,使用与包括ad-hoc网络的节点的子集的组的成员共享的密钥来创建消息认证码。 可以使用具有消息的密码处理和消息标识符作为输入来创建消息认证码。 在消息的广播之后或与广播并行,广播指向消息的指针。 消息认证码被公开广播,并且其中已经共享密钥的组的成员能够将消息认证为来自特定发送者。

    Method and apparatus for providing efficient management of certificate revocation
    8.
    发明授权
    Method and apparatus for providing efficient management of certificate revocation 有权
    提供有效管理证书撤销的方法和装置

    公开(公告)号:US09083535B2

    公开(公告)日:2015-07-14

    申请号:US13882812

    申请日:2010-11-05

    IPC分类号: H04L9/32 H04L29/06

    摘要: A method for providing efficient management of certificate revocation may comprise storing a list of identifiers of digital certificates including a revocation list defining a list of revoked certificates in an accumulator, storing a witness value in association with at least some entries in the revocation list in which the witness value provides proof of the membership or non-membership of an identifier in the revocation list, enabling generation of a new accumulator and a new witness value responsive to each insertion or deletion of an entry in the revocation list, and enabling batch updates to the revocation list using a reduced bitlength value generated based on to a ratio of a value generated based on elements added to the revocation list to a value generated based on elements deleted from the revocation list. A corresponding apparatus is also provided. A method for certificate authorities (CA) that use Bloom filters for certificate revocation list (CRL) compression that enables the CA to hash only the entry that is to be un-revoked so that a good compression rate may be provided while avoiding computation of the entire CRL for each un-revocation.

    摘要翻译: 用于提供证书吊销的有效管理的方法可以包括存储数字证书的标识符列表,包括定义撤消证书的列表的撤销列表在累加器中,存储与撤销列表中的至少一些条目相关联的证人值, 证人值提供了撤销列表中的标识符的成员身份证明或非成员身份证明,能够响应于撤销列表中的条目的每次插入或删除而生成新的累加器和新的证人值,并且允许批量更新 所述撤销列表使用基于基于添加到撤销列表的元素生成的值与基于从撤销列表中删除的元素生成的值而生成的缩减比特长度值。 还提供了相应的装置。 一种使用布隆过滤器进行证书吊销列表(CRL)压缩的证书颁发机构(CA)的方法,该方法使CA只能对未撤销的条目进行散列,以便可以提供良好的压缩率,同时避免计算 每个撤销的整个CRL。

    Methods and apparatus for authentication
    9.
    发明授权
    Methods and apparatus for authentication 有权
    认证方法和设备

    公开(公告)号:US09210578B2

    公开(公告)日:2015-12-08

    申请号:US13547512

    申请日:2012-07-12

    IPC分类号: H04L29/06 H04W12/10 H04W84/18

    摘要: Message authentication in an ad-hoc network. Upon creation of a message, a message authentication code is created using a key shared with members of a group comprising a subset of nodes of the ad-hoc network. The message authentication code may be created using a cryptographic process having the message and a message identifier as inputs. After or in parallel with broadcast of the message, a pointer to the message is broadcast. The message authentication code is publicly broadcast and those members of the group among which the key has been shared are able to authenticate the message as coming from a particular sender.

    摘要翻译: 在ad-hoc网络中的消息认证。 在创建消息时,使用与包括ad-hoc网络的节点的子集的组的成员共享的密钥来创建消息认证码。 可以使用具有消息的密码处理和消息标识符作为输入来创建消息认证码。 在消息的广播之后或与广播并行,广播指向消息的指针。 消息认证码被公开广播,并且其中已经共享密钥的组的成员能够将消息认证为来自特定发送者。

    METHOD AND APPARATUS FOR PROVIDING EFFICIENT MANAGEMENT OF CERTIFICATE REVOCATION
    10.
    发明申请
    METHOD AND APPARATUS FOR PROVIDING EFFICIENT MANAGEMENT OF CERTIFICATE REVOCATION 有权
    提供有效管理认证证书的方法和设备

    公开(公告)号:US20130238897A1

    公开(公告)日:2013-09-12

    申请号:US13882812

    申请日:2010-11-05

    IPC分类号: H04L9/32

    摘要: A method for providing efficient management of certificate revocation may comprise storing a list of identifiers of digital certificates including a revocation list defining a list of revoked certificates in an accumulator, storing a witness value in association with at least some entries in the revocation list in which the witness value provides proof of the membership or non-membership of an identifier in the revocation list, enabling generation of a new accumulator and a new witness value responsive to each insertion or deletion of an entry in the revocation list, and enabling batch updates to the revocation list using a reduced bitlength value generated based on to a ratio of a value generated based on elements added to the revocation list to a value generated based on elements deleted from the revocation list. A corresponding apparatus is also provided. A method for certificate authorities (CA) that use Bloom filters for certificate revocation list (CRL) compression that enables the CA to hash only the entry that is to be un-revoked so that a good compression rate may be provided while avoiding computation of the entire CRL for each un-revocation.

    摘要翻译: 用于提供证书吊销的有效管理的方法可以包括存储数字证书的标识符列表,包括定义撤消证书的列表的撤销列表在累加器中,存储与撤销列表中的至少一些条目相关联的证人值, 证人值提供了撤销列表中的标识符的成员身份证明或非成员身份证明,能够响应于撤销列表中的条目的每次插入或删除而生成新的累加器和新的证人值,并且允许批量更新 所述撤销列表使用基于基于添加到撤销列表的元素生成的值与基于从撤销列表中删除的元素生成的值而生成的缩减比特长度值。 还提供了相应的装置。 一种使用布隆过滤器进行证书吊销列表(CRL)压缩的证书颁发机构(CA)的方法,该方法使CA只能对未撤销的条目进行散列,以便可以提供良好的压缩率,同时避免计算 每个撤销的整个CRL。