Method of creating security associations in mobile IP networks
    1.
    发明授权
    Method of creating security associations in mobile IP networks 有权
    在移动IP网络中创建安全关联的方法

    公开(公告)号:US08189544B2

    公开(公告)日:2012-05-29

    申请号:US11474591

    申请日:2006-06-26

    IPC分类号: H04W4/00

    摘要: A key distribution scheme is provided, which is useful for establishing, distributing, and maintaining security associations in a Mobile IP network. An authentication server performs an initial validation of a new session and generates a root key which it delivers to the initial access gateway and to the home agent. The initial access gateway and the home agent each independently compute a derivative key available only to themselves. The initial access gateway, acting as proxy for the mobile station, uses the derivative key to sign the Mobile IP registration or binding update transactions, and sends the signed registration or binding update to the home agent for validation. Once the session is established between the mobile station and the home agent, the access gateways act as proxies on behalf of the mobile station to maintain the session mobility. In handoff, the new access gateway acquires the root key as part of the transferred session context. The new access gateway, acting as proxy for the mobile station, computes a new derivative key from the root key and uses it to sign a binding update.

    摘要翻译: 提供了一种密钥分配方案,对于在移动IP网络中建立,分发和维护安全关联是有用的。 认证服务器执行新会话的初始验证,并生成一个根密钥,该密钥将传递给初始接入网关和归属代理。 初始接入网关和归属代理各自独立地计算可用于其自身的导数密钥。 作为移动台的代理的初始接入网关使用派生密钥对移动IP注册或绑定更新事务进行签名,并将签名的注册或绑定更新发送到归属代理进行验证。 一旦在移动台和归属代理之间建立了会话,则接入网关代表移动台充当代理以维持会话移动性。 在切换中,新的接入网关获取根密钥作为传送的会话上下文的一部分。 新的接入网关作为移动台的代理,从根密钥计算新的派生密钥,并使用它来签署绑定更新。

    Method of creating security associations in mobile IP networks
    2.
    发明申请
    Method of creating security associations in mobile IP networks 有权
    在移动IP网络中创建安全关联的方法

    公开(公告)号:US20070297377A1

    公开(公告)日:2007-12-27

    申请号:US11474591

    申请日:2006-06-26

    IPC分类号: H04Q7/24

    摘要: A key distribution scheme is provided, which is useful for establishing, distributing, and maintaining security associations in a Mobile IP network. An authentication server performs an initial validation of a new session and generates a root key which it delivers to the initial access gateway and to the home agent. The initial access gateway and the home agent each independently compute a derivative key available only to themselves. The initial access gateway, acting as proxy for the mobile station, uses the derivative key to sign the Mobile IP registration or binding update transactions, and sends the signed registration or binding update to the home agent for validation. Once the session is established between the mobile station and the home agent, the access gateways act as proxies on behalf of the mobile station to maintain the session mobility. In handoff, the new access gateway acquires the root key as part of the transferred session context. The new access gateway, acting as proxy for the mobile station, computes a new derivative key from the root key and uses it to sign a binding update.

    摘要翻译: 提供了一种密钥分配方案,对于在移动IP网络中建立,分发和维护安全关联是有用的。 认证服务器执行新会话的初始验证,并生成一个根密钥,该密钥将传递给初始接入网关和归属代理。 初始接入网关和归属代理各自独立地计算可用于其自身的导数密钥。 作为移动台的代理的初始接入网关使用派生密钥对移动IP注册或绑定更新事务进行签名,并将签名的注册或绑定更新发送到归属代理进行验证。 一旦在移动台和归属代理之间建立了会话,则接入网关代表移动台充当代理以维持会话移动性。 在切换中,新的接入网关获取根密钥作为传送的会话上下文的一部分。 新的接入网关作为移动台的代理,从根密钥计算新的派生密钥,并使用它来签署绑定更新。

    Preparation for network interface recognition of network packet portion with declarative notation for field thereof and constraint therefor
    3.
    发明授权
    Preparation for network interface recognition of network packet portion with declarative notation for field thereof and constraint therefor 失效
    网络分组部分的网络接口识别准备用于其领域的声明符号和约束

    公开(公告)号:US06789127B1

    公开(公告)日:2004-09-07

    申请号:US09504627

    申请日:2000-02-15

    IPC分类号: G06F1516

    摘要: A system includes a compiler component that employs a declarative notation, for a description, that describes one or more fields of a network packet. The compiler component employs a declarative notation, for the description, that describes one or more constraints for at least one field of the one or more fields. The description is of a portion of the network packet. A representation based on the description is employable for recognition of the portion of the network packet at a network interface.

    摘要翻译: 系统包括对描述网络分组的一个或多个字段的描述采用声明符号的编译器组件。 编译器组件采用声明符号,描述描述一个或多个字段的至少一个字段的一个或多个约束。 该描述是网络分组的一部分。 基于描述的表示可用于在网络接口处识别网络分组的部分。

    Method for reducing service interruptions during a hand off in a wireless system
    4.
    发明授权
    Method for reducing service interruptions during a hand off in a wireless system 有权
    在无线系统中减少切换中的服务中断的方法

    公开(公告)号:US07551604B2

    公开(公告)日:2009-06-23

    申请号:US10824762

    申请日:2004-04-14

    IPC分类号: H04L12/66

    CPC分类号: H04W36/02

    摘要: A method is provided for controlling communications to and from an access terminal during a hand off period. A smart packet filter is used to identify a packet flow, apply a first treatment to a packet flow based on its destination, and transmit the first treated packet flow along a first route to the access terminal. During a hand off, the packet stream is duplicated, a second treatment is applied to the packet flow and the second treated duplicate packet flow is transmitted to the access terminal via a second route.

    摘要翻译: 提供一种用于在切换期间控制与来自接入终端的通信的方法。 使用智能分组过滤器来识别分组流,基于其目的地对分组流应用第一处理,并且将第一处理的分组流沿着第一路由发送到接入终端。 在切换期间,分组流被复制,第二处理被应用于分组流,并且第二处理的重复分组流经由第二路由被发送到接入终端。

    Streamlined service subscription in distributed architectures
    5.
    发明授权
    Streamlined service subscription in distributed architectures 有权
    分布式架构中简化的服务订阅

    公开(公告)号:US07376840B2

    公开(公告)日:2008-05-20

    申请号:US10260843

    申请日:2002-09-30

    IPC分类号: H04K1/00

    CPC分类号: H04L63/0823 H04L63/123

    摘要: Cryptography is used to generate a token that both authorizes request processing and establishes constraints on that authorization. A mobile communications device user or client subscribes to an information service of a content provider. A description of the subscribed service is generated. The client applies a digital signature to the description and optionally encrypts the signed description. A token is generated based on the signed description. The content provider presents the token to the request processing entity of a mobile service provider in order to establish trust between the content provider and the request processing entity. The request processing entity decrypts the token and verifies the signature of the client. The request of the content provider is validated through a comparison of the request with the constraints indicated in the decrypted token. Valid requests are processed. For example, a request for location information about the client is fulfilled in order for the content provider to push a local weather report to the mobile device of the client.

    摘要翻译: 密码学用于生成一个令牌,它既授权请求处理,也为该授权建立约束。 移动通信设备用户或客户端订阅内容提供商的信息服务。 生成订阅服务的描述。 客户端将数字签名应用于描述,并可选地加密签名描述。 基于签名描述生成令牌。 内容提供商将令牌呈现给移动服务提供商的请求处理实体,以建立内容提供商与请求处理实体之间的信任。 请求处理实体解密令牌并验证客户端的签名。 通过将请求与解密的令牌中指示的约束进行比较来验证内容提供商的请求。 有效请求被处理。 例如,满足关于客户端的位置信息的请求,以便内容提供商将本地天气报告推送到客户端的移动设备。

    Method for providing multiple points of connectivity to subscribers of wireless communication networks
    8.
    发明授权
    Method for providing multiple points of connectivity to subscribers of wireless communication networks 有权
    为无线通信网络的用户提供多个连接点的方法

    公开(公告)号:US06950657B1

    公开(公告)日:2005-09-27

    申请号:US09609907

    申请日:2000-07-03

    CPC分类号: H04W92/22

    摘要: A method for allowing a mobile of a wireless communication simultaneous access to multiple data networks coupled to the wireless communication network. A network interface is created between network controlling elements, such as Base Station Controllers, of the wireless communication network. The network interface allows various communication channels established by the mobile to be routed to network controlling elements that are coupled to the various data networks. Information from various established communication channels are routed between various network controlling elements. Thus, a mobile is able to communicate simultaneously with different data networks. The network interface also allows handoffs to be executed with virtually no interruptions and no loss of information being exchanged between the mobile and system equipment involved in the handoff.

    摘要翻译: 一种用于允许无线通信的移动台同时访问耦合到无线通信网络的多个数据网络的方法。 在无线通信网络的网络控制元件(例如基站控制器)之间创建网络接口。 网络接口允许由移动台建立的各种通信信道被路由到耦合到各种数据网络的网络控制元件。 来自各种已建立的通信信道的信息在各种网络控制元件之间路由。 因此,移动台能够与不同的数据网络同时进行通信。 网络接口还允许在几乎没有中断的情况下执行切换,并且在切换中涉及的移动和系统设备之间没有信息交换丢失。