WLAN session management techniques with secure rekeying and logoff
0 Assignments
0 Petitions
Accused Products
Abstract
The invention provides a method for improving the security of a mobile terminal in a WLAN environment by installing two shared secrets instead of one shared secret, the initial session key, on both the wireless user machine and the WLAN access point during the user authentication phase. One of the shared secrets is used as the initial session key and the other is used as a secure seed. Since the initial authentication is secure, these two keys are not known to a would be hacker. Although the initial session key may eventually be cracked by the would be hacker, the secure seed remains secure as it is not used in any insecure communication.
49 Citations
53 Claims
-
1-24. -24. (canceled)
-
25. A method for providing a secure communications session with a user terminal in a communications network, said method comprising:
-
receiving by said user terminal a secure key and a secure seed using a secure communications method, the secure key and the secure seed being suitable for storage in the user terminal for use during the secure communications session;
encrypting and transmitting data by the user terminal using a current session key, and decrypting data received by the user terminal using the current session key, the secure key initially being used as the current session key; and
periodically receiving, by said user terminal, a subsequent session key and using the subsequent session key as the current session key during subsequent communications. - View Dependent Claims (26, 27, 28, 29)
-
-
30. A method for providing a secure communications session with a mobile terminal in a communications network, said method comprising:
-
receiving a secure key by said mobile terminal using a secure communications method, the secure key being stored in the mobile terminal for use during the secure communications session;
encrypting and transmitting data by the mobile terminal using a current session key, and decrypting data received by said mobile terminal using the current session key; and
transmitting a logoff message by said mobile terminal to end the secure communications session, the logoff message being in encrypted form and including the secure key. - View Dependent Claims (31, 32, 33, 34)
-
-
35. A method for providing a secure communications session with a mobile terminal in a communications network, said method comprising:
-
receiving by said communications network a secure key using a secure communications method, the secure key being stored in the communications network for use during the secure communications session;
encrypting and transmitting data by said communications network using a current session key, and decrypting data received by said communications network using the current session key, the secure key initially being used as the current session key; and
periodically receiving a subsequent session key by the communications network and using the subsequent session key as the current session key during subsequent communications. - View Dependent Claims (36)
-
-
37. A method for providing a secure communications session with a mobile terminal in a communications network, said method comprising:
installing at least two shared secrets on the mobile terminal during a user authentication phase whereby a first secret is the initial session key and a second secret is utilized as secure seed to generate subsequent session keys. - View Dependent Claims (38, 39, 40, 41)
-
42. A method for providing a secure communications session with a mobile terminal in a communications network, said method comprising:
installing at least two shared secrets in an access point during a user authentication phase whereby a first secret is the initial session key and a second secret is utilized as secure seed to generate subsequent session keys. - View Dependent Claims (43, 44, 45, 46)
-
47. A method for providing a secure communications session between a mobile terminal and a communications network, said method comprising:
sending, by said mobile terminal, during session logoff an encrypted logoff request accompanied by a secure seed such that the secure seed appears in the logoff request.
-
48. An access point for providing a secure communications session between a mobile terminal and a communications network, comprising:
-
a means for transmitting a secure key and a secure seed using a secure communications method;
a means to encrypt data using the secure key; and
a means to periodically generate a subsequent session key using the secure seed. - View Dependent Claims (49, 50, 52)
-
-
51. A terminal device for providing a secure communications session with a communications network, comprising:
-
means to receive a secure key and a secure seed and a means to store the secure key and the secure seed for use during the secure communications session;
means to receive data and a means to decrypt the data using a current session key during the secure communications session, the secure key being used initially as the current session key;
means to encrypt and transmit data using said current session key; and
means to generate a subsequent session key using the current session key and the secure seed, the subsequent session key thereafter being used as the current session key for subsequent communications.
-
-
53. An access point for providing a secure communications session between a mobile terminal and a communications network, comprising:
-
a means to transmit a secure key and a secure seed and a means to store the secure key and the secure seed for use during the secure communications session;
a means to encrypt data and a means to transmit data to said mobile terminal and a means to receive data and a means to decrypt the data from the mobile terminal using a current session key during the secure communications session, the secure key being used initially as the current session key; and
a means to generate a subsequent session key using the current session key and the secure seed, the subsequent session key thereafter being used as the current session key for subsequent communications.
-
Specification