Access authentication method applying to IBSS network
    1.
    发明授权
    Access authentication method applying to IBSS network 有权
    访问IBSS网络的认证方法

    公开(公告)号:US08312278B2

    公开(公告)日:2012-11-13

    申请号:US12740082

    申请日:2008-10-30

    IPC分类号: H04L9/32

    摘要: An access authentication method applying to IBSS network involves the following steps of: 1) performing authentication role configuration for network entities; 2) authenticating an authentication entity and a request entity that have been performed the authentication role configuration via an authentication protocol; and 3) after finishing the authentication, the authentication entity and the request entity perform the key negotiation, wherein, the message integrity check field and protocol synchronization lock-in field are added in a key negotiation message. The access authentication method applying to IBSS network provided by the invention has the advantages of the better safeness and the higher execution efficiency.

    摘要翻译: 适用于IBSS网络的接入认证方法包括以下步骤:1)对网络实体进行认证角色配置; 2)通过认证协议认证已经执行认证角色配置的认证实体和请求实体; 和3)认证完成后,认证实体和请求实体进行密钥协商,其中消息完整性检查字段和协议同步锁定字段被添加到密钥协商消息中。 适用于本发明提供的IBSS网络的接入认证方法具有安全性更高,执行效率更高的优点。

    METHOD OF ONE-WAY ACCESS AUTHENTICATION
    2.
    发明申请
    METHOD OF ONE-WAY ACCESS AUTHENTICATION 有权
    单向通信认证方法

    公开(公告)号:US20100268954A1

    公开(公告)日:2010-10-21

    申请号:US12741567

    申请日:2008-11-07

    IPC分类号: H04L9/32

    摘要: A method of one-way access authentication is disclosed. The method includes the following steps. According to system parameters set up by a third entity, a second entity sends an authentication request and key distribution grouping message to a first entity. The first entity verifies the validity of the message sent from the second entity, and if it is valid, the first entity generates authentication and key response grouping message and sends it to the second entity, which verifies the validity of the message sent from the first entity, and if it is valid, the second entity generates the authentication and key confirmation grouping message and sends the message to the first entity. The first entity verifies the validity of the authentication and key conformation grouping message, and if it is valid, the authentication succeeds and the key is regarded as the master key of agreement.

    摘要翻译: 公开了一种单向接入认证方法。 该方法包括以下步骤。 根据由第三实体建立的系统参数,第二实体向第一实体发送认证请求和密钥分发分组消息。 第一实体验证从第二实体发送的消息的有效性,并且如果其有效,则第一实体生成认证和密钥响应分组消息并将其发送到第二实体,其验证从第一实体发送的消息的有效性 实体,如果有效,则第二实体生成认证和密钥确认分组消息,并将消息发送到第一实体。 第一个实体验证认证和密钥组合分组消息的有效性,如果认证成功,则认证成功,密钥被视为协商的主密钥。

    Two-way access authentication method
    3.
    发明授权
    Two-way access authentication method 有权
    双向访问认证方式

    公开(公告)号:US08412943B2

    公开(公告)日:2013-04-02

    申请号:US12741982

    申请日:2008-11-07

    IPC分类号: H04L29/00

    摘要: A two-way access authentication method comprises: According to the system parameters pre-established by the third entity, the first entity sends the access authentication request packet to the second entity, then the second entity validates whether the signature of first entity is correct, and if yes, the share master key of second entity is calculated; the second entity generates the access authentication response packet and sends it to the first entity, then the first entity validates whether the signature of access authentication response packet and the message integrity check code are correct; if yes, the share master key of first entity is calculated; the first entity sends the access authentication acknowledge packet to the second entity, then the second entity validates the integrity of the access authentication acknowledge packet, if passing the validation, the share master key of first entity is consistent with that of the second entity, and the access authentication is achieved. For improving the security, after received the access authentication request packet sent by the first entity, the second entity may perform the identity validity validation and generates the access authentication response packet after passing the validation.

    摘要翻译: 双向接入认证方法包括:根据第三实体预先建立的系统参数,第一实体向第二实体发送接入认证请求报文,第二实体验证第一实体的签名是否正确, 如果是,则计算第二实体的共享主密钥; 第二实体生成接入认证响应报文并将其发送给第一实体,则第一实体验证接入认证响应报文的签名和消息完整性检查码是否正确; 如果是,则计算第一实体的共享主密钥; 第一实体向第二实体发送接入认证确认分组,则第二实体验证接入认证确认分组的完整性,如果通过验证,则第一实体的共享主密钥与第二实体的共享主密钥一致, 实现了访问认证。 为了提高安全性,在接收到由第一实体发送的接入认证请求分组之后,第二实体可以在通过验证之后执行身份有效性验证并生成接入认证响应分组。

    ACCESS AUTHENTICATION METHOD APPLYING TO IBSS NETWORK
    4.
    发明申请
    ACCESS AUTHENTICATION METHOD APPLYING TO IBSS NETWORK 有权
    应用于IBSS网络的访问认证方法

    公开(公告)号:US20110314286A1

    公开(公告)日:2011-12-22

    申请号:US12740082

    申请日:2008-10-30

    IPC分类号: H04L9/08 G06F15/16

    摘要: An access authentication method applying to IBSS network involves the following steps of: 1) performing authentication role configuration for network entities; 2) authenticating an authentication entity and a request entity that have been performed the authentication role configuration via an authentication protocol; and 3) after finishing the authentication, the authentication entity and the request entity perform the key negotiation, wherein, the message integrity check field and protocol synchronization lock-in field are added in a key negotiation message. The access authentication method applying to IBSS network provided by the invention has the advantages of the better safeness and the higher execution efficiency.

    摘要翻译: 适用于IBSS网络的接入认证方法包括以下步骤:1)对网络实体进行认证角色配置; 2)通过认证协议认证已经执行认证角色配置的认证实体和请求实体; 和3)认证完成后,认证实体和请求实体进行密钥协商,其中消息完整性检查字段和协议同步锁定字段被添加到密钥协商消息中。 适用于本发明提供的IBSS网络的接入认证方法具有安全性更高,执行效率更高的优点。

    TWO-WAY ACCESS AUTHENTICATION METHOD
    5.
    发明申请
    TWO-WAY ACCESS AUTHENTICATION METHOD 有权
    两路访问认证方法

    公开(公告)号:US20100250952A1

    公开(公告)日:2010-09-30

    申请号:US12741982

    申请日:2008-11-07

    IPC分类号: H04L9/32 G06F21/00

    摘要: A two-way access authentication method comprises: According to the system parameters pre-established by the third entity, the first entity sends the access authentication request packet to the second entity, then the second entity validates whether the signature of first entity is correct, and if yes, the share master key of second entity is calculated; the second entity generates the access authentication response packet and sends it to the first entity, then the first entity validates whether the signature of access authentication response packet and the message integrity check code are correct; if yes, the share master key of first entity is calculated; the first entity sends the access authentication acknowledge packet to the second entity, then the second entity validates the integrity of the access authentication acknowledge packet, if passing the validation, the share master key of first entity is consistent with that of the second entity, and the access authentication is achieved. For improving the security, after received the access authentication request packet sent by the first entity, the second entity may perform the identity validity validation and generates the access authentication response packet after passing the validation.

    摘要翻译: 双向接入认证方法包括:根据第三实体预先建立的系统参数,第一实体向第二实体发送接入认证请求报文,第二实体验证第一实体的签名是否正确, 如果是,则计算第二实体的共享主密钥; 第二实体生成接入认证响应报文并将其发送给第一实体,则第一实体验证接入认证响应报文的签名和消息完整性检查码是否正确; 如果是,则计算第一实体的共享主密钥; 第一实体向第二实体发送接入认证确认分组,则第二实体验证接入认证确认分组的完整性,如果通过验证,则第一实体的共享主密钥与第二实体的共享主密钥一致, 实现了访问认证。 为了提高安全性,在接收到由第一实体发送的接入认证请求分组之后,第二实体可以在通过验证之后执行身份有效性验证并生成接入认证响应分组。

    Entity bi-directional identificator method and system based on trustable third party
    6.
    发明授权
    Entity bi-directional identificator method and system based on trustable third party 有权
    基于可信第三方的实体双向识别方法和系统

    公开(公告)号:US08356179B2

    公开(公告)日:2013-01-15

    申请号:US12739678

    申请日:2008-10-23

    摘要: An entity bi-directional identification method and system based on a trustable third party thereof are provided. The system comprises a first entity, which is for sending a first message to a second entity, sending a third message to a third entity after receiving a second message sent by the second entity, verifying the fourth message after receiving a fourth message sent by the third entity, sending a fifth message to the second entity after the verification is finished; the second entity, which is for receiving the first message sent by the first entity, sending the second message to the first entity, verifying the fifth message after receiving the fifth message sent by the first entity; the third entity, which is for receiving the third message sent by the first entity, checking if the first entity and the second entity are legal, implementing the pretreatment according to the checking result, sending the first entity the fourth message after the treatment is finished.

    摘要翻译: 提供了一种基于可信任第三方的实体双向识别方法和系统。 该系统包括用于向第二实体发送第一消息的第一实体,在接收到由第二实体发送的第二消息之后向第三实体发送第三消息,在接收到由第二实体发送的第四消息之后验证第四消息 第三实体,在验证完成之后向第二实体发送第五消息; 所述第二实体用于接收由所述第一实体发送的所述第一消息,向所述第一实体发送所述第二消息,在接收到由所述第一实体发送的所述第五消息之后验证所述第五消息; 用于接收第一实体发送的第三消息的第三实体,检查第一实体和第二实体是否合法,根据检查结果实现预处理,在处理完成之后发送第一实体第四消息 。

    Systems, methods and computer-accessible media for acquiring and authenticating public key certificate status
    7.
    发明授权
    Systems, methods and computer-accessible media for acquiring and authenticating public key certificate status 有权
    用于获取和验证公钥证书状态的系统,方法和计算机可访问媒体

    公开(公告)号:US08195935B2

    公开(公告)日:2012-06-05

    申请号:US12442462

    申请日:2007-07-16

    IPC分类号: H04L29/06

    摘要: Exemplary embodiments of systems, methods and computer-accessible medium can be provided for obtaining and verifying a public key certificate status. In particular, it is possible to construct and send a certificate query request, construct and send a combined certificate query request, construct and send a combined certificate status response, deliver a certificate status response, perform a verification by the general access point, and/or perform a verification by the user equipment. The exemplary embodiments address some of the deficiencies of conventional methods which have a complicated implementation as well as likely inability of such conventional methods to be applied to the network architecture of user equipment, a general access point and a server. The exemplary embodiments of the systems, methods and computer-accessible medium can obtain a user certificate status to provide certificate statuses of the user or the user equipment and the general access point when the user equipment accesses the network via the general access point. Message exchanges can be reduced, bandwidth and calculation resources can be saved, and higher efficiency can be achieved. According to another exemplary embodiment, by way of adding random numbers into the certificate query request and the combined certificate query request, as well as the message m, freshness of the certificate status response can be facilitated and even ensured, and security protection can be enhanced.

    摘要翻译: 可以提供系统,方法和计算机可访问介质的示例性实施例,以获得和验证公钥证书状态。 特别地,可以构建和发送证书查询请求,构造和发送组合的证书查询请求,构造并发送组合证书状态响应,递送证书状态响应,由一般接入点执行验证和/ 或执行用户设备的验证。 示例性实施例解决了具有复杂实现的常规方法的一些缺陷以及这种常规方法可能不适用于用户设备,通用接入点和服务器的网络架构的一些缺陷。 当用户设备经由通用接入点访问网络时,系统,方法和计算机可访问介质的示例性实施例可以获得用户证书状态以提供用户或用户设备以及通用接入点的证书状态。 可以减少消息交换,节省带宽和计算资源,实现更高的效率。 根据另一示例性实施例,通过在证书查询请求和组合证书查询请求中添加随机数以及消息m,可以促进并甚至确保证书状态响应的新鲜度,并且可以增强安全性保护 。

    ENTITY BI-DIRECTIONAL IDENTIFICATOR METHOD AND SYSTEM BASED ON TRUSTABLE THIRD PARTY
    8.
    发明申请
    ENTITY BI-DIRECTIONAL IDENTIFICATOR METHOD AND SYSTEM BASED ON TRUSTABLE THIRD PARTY 有权
    基于可信赖第三方的实体双向识别方法和系统

    公开(公告)号:US20100306839A1

    公开(公告)日:2010-12-02

    申请号:US12739678

    申请日:2008-10-23

    IPC分类号: H04L9/32 G06F21/00

    摘要: An entity bi-directional identification method and system based on a trustable third party thereof are provided. The system comprises a first entity, which is for sending a first message to a second entity, sending a third message to a third entity after receiving a second message sent by the second entity, verifying the fourth message after receiving a fourth message sent by the third entity, sending a fifth message to the second entity after the verification is finished; the second entity, which is for receiving the first message sent by the first entity, sending the second message to the first entity, verifying the fifth message after receiving the fifth message sent by the first entity; the third entity, which is for receiving the third message sent by the first entity, checking if the first entity and the second entity are legal, implementing the pretreatment according to the checking result, sending the first entity the fourth message after the treatment is finished.

    摘要翻译: 提供了一种基于可信任第三方的实体双向识别方法和系统。 该系统包括用于向第二实体发送第一消息的第一实体,在接收到由第二实体发送的第二消息之后向第三实体发送第三消息,在接收到由第二实体发送的第四消息之后验证第四消息 第三实体,在验证完成之后向第二实体发送第五消息; 所述第二实体用于接收由所述第一实体发送的所述第一消息,向所述第一实体发送所述第二消息,在接收到由所述第一实体发送的所述第五消息之后验证所述第五消息; 用于接收第一实体发送的第三消息的第三实体,检查第一实体和第二实体是否合法,根据检查结果实现预处理,在处理完成之后发送第一实体第四消息 。

    Light access authentication method and system
    9.
    发明授权
    Light access authentication method and system 有权
    光接入认证方法和系统

    公开(公告)号:US08560847B2

    公开(公告)日:2013-10-15

    申请号:US12745288

    申请日:2008-12-02

    IPC分类号: H04L9/28 H04K1/00

    CPC分类号: H04L9/321 H04L2209/805

    摘要: A light access authentication method and system, the method includes: the trustful third party writes the MSG cipher text formed by enciphering MSG into the first entity; the second entity attains the MSG cipher text from the first entity, and attains the key from the trustful third party after attaining the MSG cipher text; the MSG cipher text is deciphered according to the key, and the MSG plaintext is attained. The embodiment of the present invention can be widely applied at a condition limited by the equipment and environment, and the access authentication is simplified and lightened.

    摘要翻译: 一种光接入认证方法和系统,所述方法包括:信任第三方将通过加密MSG形成的MSG密文写入第一实体; 第二实体从第一实体获得MSG密文,并在获得MSG密文后获得信任第三方的密钥; 根据密钥解密MSG密文,并获得MSG明文。 本发明的实施例可以在受设备和环境限制的条件下被广泛应用,并且访问认证被简化和减轻。

    SECURE TRANSMISSION METHOD FOR BROADBAND WIRELESS MULTIMEDIA NETWORK BROADCASTING COMMUNICATION
    10.
    发明申请
    SECURE TRANSMISSION METHOD FOR BROADBAND WIRELESS MULTIMEDIA NETWORK BROADCASTING COMMUNICATION 审中-公开
    宽带无线多媒体网络广播通信的安全传输方法

    公开(公告)号:US20100316221A1

    公开(公告)日:2010-12-16

    申请号:US12863304

    申请日:2009-01-14

    IPC分类号: H04L9/08 H04L9/00

    摘要: A secure transmission method for broadband wireless multimedia network broadcasting communication includes the following steps: a secure channel between big base station and small base station is established by utilizing security protocols; the big base station distributes a Broadcast Traffic Encryption Key to each small base station through the secure channel; the small base station transmits the Broadcast Traffic Encryption Key to the user passing the authentication and authorization. The above solution solves the problem of broadcast secure communication of the big base station working in the mixed covering mode of large and small cells, realizes the identification of not only the user but also the base station, and ensures that only the authorized user can receive broadcast service.

    摘要翻译: 一种用于宽带无线多媒体网络广播通信的安全传输方法包括以下步骤:利用安全协议建立大基站与小型基站之间的安全通道; 大基站通过安全通道向每个小型基站分配广播业务加密密钥; 小基站向通过认证授权的用户发送广播业务加密密钥。 以上解决方案解决了以大小小区混合覆盖模式工作的大型基站的广播安全通信问题,不仅可以对用户进行识别,而且可以实现基站识别,确保只有授权用户可以接收 广播服务。