Methods for establishing a secure point-to-point call on a trunked network
    1.
    发明授权
    Methods for establishing a secure point-to-point call on a trunked network 有权
    在集群网络上建立安全点对点呼叫的方法

    公开(公告)号:US08724812B2

    公开(公告)日:2014-05-13

    申请号:US12983067

    申请日:2010-12-31

    IPC分类号: H04L9/08

    摘要: Methods for establishing secure point-to-point communications in a trunked radio system include receiving, at a trunking controller, a request from a source endpoint for a traffic channel for confidential communications between the source endpoint and a destination endpoint using a shared unique first symmetric key. The trunking controller provides keying material related to the symmetric key over the secured control channel to at least one of the source or destination endpoints and assigns a traffic channel. Moreover, in response to the request, the controller assigns a traffic channel. The keying material enables the unique first symmetric key to be securely established between the source and destination endpoints.

    摘要翻译: 用于在集群无线电系统中建立安全点对点通信的方法包括在中继控制器处,使用共享唯一的第一对称来在源端点和目的地端点之间接收来自源端点的业务信道的业务信道的请求 键。 中继控制器将与安全控制信道上的对称密钥相关的密钥材料提供给源端点或目的端点中的至少一个,并分配业务信道。 此外,响应于该请求,控制器分配业务信道。 密钥材料使得能够在源端点和目的端点之间安全地建立唯一的第一对称密钥。

    Method and apparatus for attaching a wireless device to a foreign 3GPP wireless domain using alternative authentication mechanisms
    2.
    发明授权
    Method and apparatus for attaching a wireless device to a foreign 3GPP wireless domain using alternative authentication mechanisms 有权
    使用替代认证机制将无线设备附接到外部3GPP无线域的方法和装置

    公开(公告)号:US08929862B2

    公开(公告)日:2015-01-06

    申请号:US13178612

    申请日:2011-07-08

    摘要: A method and apparatus for attaching a wireless device to a foreign wireless domain of a 3GPP communication system using an alternative authentication mechanism, wherein wireless device performs the method, which includes: sending a first attach request message to an infrastructure device in the foreign wireless domain; receiving an attach reject message from the infrastructure device upon an unsuccessful attempt to obtain authentication credentials for the wireless device from a home wireless domain of the wireless device using a standard 3GPP authentication mechanism; responsive to the attach reject message sending a second attach request message to the infrastructure device, wherein the second attach request message indicates an alternative authentication mechanism to the standard 3GPP authentication mechanism; and receiving an attach accept message from the infrastructure device when the wireless device is successfully authenticated using the alternative authentication mechanism.

    摘要翻译: 一种使用替代认证机制将无线设备附加到3GPP通信系统的外部无线域的方法和装置,其中无线设备执行该方法,其包括:向外部无线域中的基础设施设备发送第一附加请求消息 ; 在使用标准3GPP认证机制从无线设备的归属无线域获得无线设备的认证凭证的尝试不成功时,从基础设施设备接收附着拒绝消息; 响应于所述附着拒绝消息向所述基础设施设备发送第二附加请求消息,其中所述第二附着请求消息指示对所述标准3GPP认证机制的替代认证机制; 以及当使用替代认证机制成功认证无线设备时,从基础设施设备接收附加接受消息。

    MULTICAST DATA STREAM SELECTION IN A COMMUNICATION SYSTEM
    3.
    发明申请
    MULTICAST DATA STREAM SELECTION IN A COMMUNICATION SYSTEM 审中-公开
    通信系统中的多播数据流选择

    公开(公告)号:US20090161590A1

    公开(公告)日:2009-06-25

    申请号:US11959893

    申请日:2007-12-19

    IPC分类号: H04H20/71

    摘要: An apparatus and method for multicast data stream selection in a communication system includes a first step 300 of providing an intermediate server between a service entity and mobile clients. A next step 302 includes receiving a join request from a mobile client. A next step 304 includes deriving subgroups with each subgroup having at least one associated multicast data stream. A next step 310 includes deriving subgroup outer tunnels. A next step 316 includes encoding different data streams for the associated subgroups. A next step 320 includes mapping each data stream to the respective outer tunnels for each subgroup. A next step 322 includes sourcing the mapped streams to each subgroup. A next step 324 includes converting the mapped streams to a form that can be recognized by the mobile clients.

    摘要翻译: 用于通信系统中的组播数据流选择的装置和方法包括在服务实体和移动客户端之间提供中间服务器的第一步骤300。 下一步骤302包括从移动客户端接收加入请求。 下一步骤304包括导出子组,其中每个子组具有至少一个关联的多播数据流。 下一步骤310包括导出子组外部隧道。 下一步骤316包括对相关联的子组编码不同的数据流。 下一步骤320包括将每个数据流映射到每个子组的相应外部隧道。 下一步骤322包括将映射的流源发送到每个子组。 下一步骤324包括将映射的流转换成可由移动客户端识别的形式。

    Combining mobile VPN and internet protocol
    4.
    发明授权
    Combining mobile VPN and internet protocol 有权
    结合移动VPN和互联网协议

    公开(公告)号:US08379623B2

    公开(公告)日:2013-02-19

    申请号:US11775307

    申请日:2007-07-10

    IPC分类号: H04J3/24 H04L12/56 H04L12/28

    摘要: A method (200, 300, 400) of communicating an IPv6 packet (120) over an IPv4 based network (102). The method can include receiving the IPv6 packet to be communicated to a remote unit (104), encapsulating the IPv6 packet in an IPv4 transition packet (122), and communicating the IPv4 transition packet to an IPv4 MVPN (114) server configured to communicate the packet to the remote unit via infrastructure of an IPv4 radio access network. Another aspect of the present invention relates to a method of processing an IPv6 packet received over an IPv4 based network. The method can include receiving from an MVPN server an IPv4 formatted packet that is being communicated to a remote unit, and removing from the packet at least one IPv4 header to result in the packet being formatted in accordance with IPv6.

    摘要翻译: 一种在基于IPv4的网络(102)上传送IPv6分组(120)的方法(200,300,400)。 该方法可以包括接收要传送到远程单元(104)的IPv6分组,将IPv6分组封装在IPv4转换分组(122)中,以及将IPv4转换分组传送到被配置为传送该IPv4转发分组的IPv4 MVPN(114)服务器 通过IPv4无线电接入网络的基础设施将数据包分组到远程单元。 本发明的另一方面涉及一种处理通过基于IPv4的网络接收的IPv6分组的方法。 该方法可以包括从MVPN服务器接收正在传送到远程单元的IPv4格式的分组,以及从分组移除至少一个IPv4报头以导致根据IPv6格式化分组。

    METHOD FOR ENABLING MULTICAST TRAFFIC FLOWS OVER HYBRID MULTICAST CAPABLE AND NON-MULTICAST CAPABLE RADIO ACCESS NETWORKS (RANS)
    5.
    发明申请
    METHOD FOR ENABLING MULTICAST TRAFFIC FLOWS OVER HYBRID MULTICAST CAPABLE AND NON-MULTICAST CAPABLE RADIO ACCESS NETWORKS (RANS) 审中-公开
    用于实现混合多播通道和非多播能力无线接入网络(RANS)的多播业务流量的方法

    公开(公告)号:US20090036152A1

    公开(公告)日:2009-02-05

    申请号:US11831485

    申请日:2007-07-31

    IPC分类号: H04B7/26

    CPC分类号: H04L12/189 H04L12/1836

    摘要: A method for multicast packet communication by mobile entities (113) using one or more radio access networks (RANs) (107, 109, 111) that include receiving a multicast message at a router (105) and then determining multicast capabilities of a mobile entity (ME) (113). An optimal multicast delivery mode is selected for delivering a multicast message to the ME (113) at the radio access network (107, 109, 111). The multicast message is then delivered to the ME (113) at the radio access network (107, 109, 111) according to the selected delivery mode.

    摘要翻译: 一种用于使用一个或多个无线电接入网络(RAN)(107,109,111)的移动实体(113)进行组播分组通信的方法,包括在路由器(105)处接收多播消息,然后确定移动实体的多播能力 (ME)(113)。 在无线接入网络(107,109,111)选择最佳组播递送模式以将多播消息传送到ME(113)。 然后根据所选择的传递模式,将多播消息传送到无线电接入网络(107,109,111)处的ME(113)。

    Application steering and application blocking over a secure tunnel
    6.
    发明授权
    Application steering and application blocking over a secure tunnel 有权
    通过安全隧道进行应用程序转向和应用程序阻止

    公开(公告)号:US08677114B2

    公开(公告)日:2014-03-18

    申请号:US11619878

    申请日:2007-01-04

    IPC分类号: H04L9/00 H04L29/06

    摘要: Techniques are provided for enabling application steering/blocking in a secure network which includes a network entity, and a first tunnel endpoint coupled to the network entity over an encrypted tunnel. The first tunnel endpoint associates at least a first Security Parameter Index (SPI) to a first application identifier to generate first mapping information (MI), communicates the first MI to the network entity, and transmits an encrypted message to the network entity over the encrypted tunnel. The encrypted message includes an encrypted packet and an unencrypted header including the first SPI. The network entity determines the first SPI from the unencrypted header, determines the first application identifier based on the first SPI and the first MI, and identifies a first application associated with the first application identifier. The network entity can still perform application steering/blocking even though traffic passing through the tunnel is encrypted.

    摘要翻译: 提供技术用于在包括网络实体的安全网络中实现应用导向/阻塞,以及通过加密隧道耦合到网络实体的第一隧道端点。 所述第一隧道端点将至少第一安全参数索引(SPI)与第一应用标识符相关联以生成第一映射信息(MI),将所述第一MI传送到所述网络实体,并且通过所述加密的消息向所述网络实体发送加密消息 隧道。 加密消息包括加密分组和包括第一SPI的未加密报头。 网络实体从未加密报头确定第一SPI,基于第一SPI和第一MI确定第一应用标识符,并识别与第一应用标识符相关联的第一应用。 即使通过隧道的流量被加密,网络实体仍然可以执行应用程序转向/阻塞。

    Method and system for mutual authentication of nodes in a wireless communication network
    7.
    发明授权
    Method and system for mutual authentication of nodes in a wireless communication network 有权
    无线通信网络节点相互认证方法及系统

    公开(公告)号:US08001381B2

    公开(公告)日:2011-08-16

    申请号:US12037516

    申请日:2008-02-26

    IPC分类号: H04L9/28 H04K1/00

    摘要: A method as provided enables mutual authentication of nodes in a wireless communication network. The method includes processing at a first node a beacon message received from a second node, wherein the beacon message comprises a first nonce value (step 405). An association request message comprising a certificate of the first node, a first signed block of authentication data, and a second nonce value is then transmitted from the first node to the second node (step 410). The second node can then verify a signature of the certificate of the first node and verify a signature of the first signed block of authentication data. An association reply message received from the second node is then processed at the first node (step 415), whereby the first node verifies a signature of a certificate of the second node and verifies a signature of a second signed block of authentication data.

    摘要翻译: 所提供的方法能够实现无线通信网络中的节点的相互认证。 该方法包括在第一节点处处理从第二节点接收的信标消息,其中信标消息包括第一随机值(步骤405)。 然后从第一节点向第二节点发送包括第一节点的证书,第一有符号的认证数据块和第二随机数值的关联请求消息(步骤410)。 然后,第二节点可以验证第一节点的证书的签名并验证第一签名的认证数据块的签名。 然后在第一节点处处理从第二节点接收到的关联应答消息(步骤415),由此第一节点验证第二节点的证书的签名并验证第二签名的认证数据块的签名。

    METHOD AND SYSTEM FOR MUTUAL AUTHENTICATION OF NODES IN A WIRELESS COMMUNICATION NETWORK
    8.
    发明申请
    METHOD AND SYSTEM FOR MUTUAL AUTHENTICATION OF NODES IN A WIRELESS COMMUNICATION NETWORK 有权
    无线通信网络中的节点认证方法与系统

    公开(公告)号:US20090217043A1

    公开(公告)日:2009-08-27

    申请号:US12037516

    申请日:2008-02-26

    IPC分类号: H04L9/14

    摘要: A method as provided enables mutual authentication of nodes in a wireless communication network. The method includes processing at a first node a beacon message received from a second node, wherein the beacon message comprises a first nonce value (step 405). An association request message comprising a certificate of the first node, a first signed block of authentication data, and a second nonce value is then transmitted from the first node to the second node (step 410). The second node can then verify a signature of the certificate of the first node and verify a signature of the first signed block of authentication data. An association reply message received from the second node is then processed at the first node (step 415), whereby the first node verifies a signature of a certificate of the second node and verifies a signature of a second signed block of authentication data.

    摘要翻译: 所提供的方法能够实现无线通信网络中的节点的相互认证。 该方法包括在第一节点处处理从第二节点接收的信标消息,其中信标消息包括第一随机值(步骤405)。 然后从第一节点向第二节点发送包括第一节点的证书,第一有符号的认证数据块和第二随机数值的关联请求消息(步骤410)。 然后,第二节点可以验证第一节点的证书的签名并验证第一签名的认证数据块的签名。 然后在第一节点处处理从第二节点接收到的关联应答消息(步骤415),由此第一节点验证第二节点的证书的签名并验证第二签名的认证数据块的签名。

    Method and Apparatus for Dynamic Adaptation of Network Transport
    9.
    发明申请
    Method and Apparatus for Dynamic Adaptation of Network Transport 审中-公开
    网络传输动态适应的方法与装置

    公开(公告)号:US20090059788A1

    公开(公告)日:2009-03-05

    申请号:US11846756

    申请日:2007-08-29

    IPC分类号: H04L12/26 H04L12/56

    摘要: An intermediate device of a network includes network and transport layers, a dispatcher, a splitter and a connections database. The splitter intercepts a message packet in the network layer and modifies the network routing header and transport header of the message packet to form a modified message packet. The dispatcher receives modified message packets from the transport layer, recovers information from the message packets, passes the modified message packets back to the transport layer and adapts the transport layer to adapt communication dependent upon the information recovered from the message packets. The connections database stores the original source address, the original destination address, the original source port identifier and the original destination port identifier of an incoming message packet. A message packet is modified, with reference to the connections database, so that message packets from the first and second nodes are routed through the dispatcher.

    摘要翻译: 网络的中间设备包括网络和传输层,调度器,分离器和连接数据库。 分离器拦截网络层中的消息包,并修改消息包的网络路由头和传输头,以形成修改的消息包。 调度员从传输层接收修改的消息包,从消息包中恢复信息,将修改的消息包传递回传输层,并根据从消息包中恢复的信息调整传输层以适应通信。 连接数据库存储输入消息包的原始源地址,原始目的地址,原始源端口标识符和原始目的地端口标识符。 参考连接数据库修改消息包,以便来自第一和第二个节点的消息包通过调度器进行路由。

    COMBINING MOBILE VPN AND INTERNET PROTOCOL
    10.
    发明申请
    COMBINING MOBILE VPN AND INTERNET PROTOCOL 有权
    组合移动VPN和互联网协议

    公开(公告)号:US20090016253A1

    公开(公告)日:2009-01-15

    申请号:US11775307

    申请日:2007-07-10

    IPC分类号: H04Q7/26 H04H1/00

    摘要: A method (200, 300, 400) of communicating an IPv6 packet (120) over an IPv4 based network (102). The method can include receiving the IPv6 packet to be communicated to a remote unit (104), encapsulating the IPv6 packet in an IPv4 transition packet (122), and communicating the IPv4 transition packet to an IPv4 MVPN (114) server configured to communicate the packet to the remote unit via infrastructure of an IPv4 radio access network. Another aspect of the present invention relates to a method of processing an IPv6 packet received over an IPv4 based network. The method can include receiving from an MVPN server an IPv4 formatted packet that is being communicated to a remote unit, and removing from the packet at least one IPv4 header to result in the packet being formatted in accordance with IPv6.

    摘要翻译: 一种在基于IPv4的网络(102)上传送IPv6分组(120)的方法(200,300,400)。 该方法可以包括接收要传送到远程单元(104)的IPv6分组,将IPv6分组封装在IPv4转换分组(122)中,以及将IPv4转换分组传送到被配置为传送该IPv4转发分组的IPv4 MVPN(114)服务器 通过IPv4无线电接入网络的基础设施将数据包分组到远程单元。 本发明的另一方面涉及一种处理通过基于IPv4的网络接收的IPv6分组的方法。 该方法可以包括从MVPN服务器接收正在传送到远程单元的IPv4格式的分组,以及从分组移除至少一个IPv4报头以导致根据IPv6格式化分组。