摘要:
A method and a system for distributing key of media stream are provided. The method comprises: determining, by a security management server, whether a domain to which the calling terminal belongs and a domain to which a called terminal belongs subscribe a key distribution protocol; generating a key based on encryption capability information obtained in a calling process, and distributing the generated key to the calling terminal and the called terminal, if the protocol has been subscribed; generating a key based on encryption capability information obtained in a calling process, and distributing the generated key to the terminal at the same side as the security management server, if the protocol has not been subscribed. By applying the disclosure, the key is generated by the security management server, so that complexity may be reduced for media stream key negotiation to facilitate promotion of media stream encryption service.
摘要:
A method and a system for distributing key of media stream are provided. The method comprises: determining, by a security management server, whether a domain to which the calling terminal belongs and a domain to which a called terminal belongs subscribe a key distribution protocol; generating a key based on encryption capability information obtained in a calling process, and distributing the generated key to the calling terminal and the called terminal, if the protocol has been subscribed; generating a key based on encryption capability information obtained in a calling process, and distributing the generated key to the terminal at the same side as the security management server, if the protocol has not been subscribed. By applying the disclosure, the key is generated by the security management server, so that complexity may be reduced for media stream key negotiation to facilitate promotion of media stream encryption service.
摘要:
A prepaid accounting system for a wireless local area network (WLAN) and a method thereof are provided. The system includes: an authentication control point, an authentication server, and a service control point. The authentication control point is used to control access of a subscriber to WLAN; the authentication server is used to perform authentication, authorization and accounting for the subscriber; and the service control point is used to store and update subscriber information. The method includes the steps of: upon the start of accounting, an authentication server requesting a service control point to check account balance of a subscriber; during the accounting, the authentication server periodically requesting the service control point to check the account balance of the subscriber; and upon the termination of accounting, the authentication server notifying the service control point of the termination of accounting and the service control point updating the balance.
摘要:
Disclosed is a method for implementing authentication of high rate packet data (HRPD) services, applicable to multi-mode networks including IS95/CDMA2000 1x and CDMA2000 HRPD networks. The method includes an Access Terminal (AT) using the user information in the User Identity Module (UIM) as the user identifier and starting an authentication in accordance with the Extended Authentication Protocol (EAP). A Mobile Switching Center (MSC)/Visiting Location Register (VLR) obtains a random number and a first authentication number based on the user identifier, and the AT calculates a second authentication number based on said random number. The MSC/VLR compares the first authentication number with the second authentication number to determine whether they are consistent. If consistent, the authentication is successful. Otherwise, the authentication is aborted. With the disclosed method, authentication can be made by using the original MSC and HLR/AC in the CDMA IS95 or CDMA2000 1x network. The method allows low cost and easy operation for the user as well as convenient maintenance for the operator.
摘要:
Disclosed is a method for implementing authentication of high rate packet data (HRPD) services, applicable to multi-mode networks including IS95/CDMA2000 1x and CDMA2000 HRPD networks. The method includes an Access Terminal (AT) using the user information in the User Identity Module (UIM) as the user identifier and starting an authentication in accordance with the Extended Authentication Protocol (EAP). A Mobile Switching Center (MSC)/Visiting Location Register (VLR) obtains a random number and a first authentication number based on the user identifier, and the AT calculates a second authentication number based on said random number. The MSC/VLR compares the first authentication number with the second authentication number to determine whether they are consistent. If consistent, the authentication is successful. Otherwise, the authentication is aborted. With the disclosed method, authentication can be made by using the original MSC and HLR/AC in the CDMA IS95 or CDMA2000 1x network. The method allows low cost and easy operation for the user as well as convenient maintenance for the operator.