Abstract:
La descripción se refiere a técnicas y tecnologías para establecer un enlace seguro entre un autenticador de mafia y un distribuidor de clave de malla para transportar mensajes de asociación de seguridad; el enlace seguro puede permitir que el distribuidor de clave de malla comunique resultados de un proceso de autenticación al autenticador de malla.
Abstract:
Un método para comunicación entre un nodo de transmisor y un nodo de receptor en una red de comunicación de salto múltiple (100), que comprende: formatear información en una estructura de datos para generar un cuadro de acción de malla (400), en donde el cuadro de acción de malla (400) comprende un encabezado (420) que comprende una dirección fuente (SA) que identifica dicho nodo, una dirección destino (DA) que identifica un nodo de destinatario, una dirección de transmisor (TA) que identifica un nodo de remitente, y una dirección de receptor (RA) que identifica un nodo de receptor; y un campo de cuerpo (430) que comprende una unidad de datos de acción de malla (434); y enviar el cuadro de acción de malla desde el nodo de transmisor.
Abstract:
A method and apparatus for establishing security associations between nod es of an ad hoc wireless network includes two authentication steps: an initi al first contact step (authentication, authorization, and accounting (AAA)-b ased authentication), and a "light-weight" step that reuses key material gen erated during first contact. A mesh authenticator within the network provide s two roles. The first role is to implement an 802.1X port access entity (PA E), derive transient keys used for encryption with a supplicant mesh point v ia a four-way handshake and take care of back end communications with a key distributor. The second role is as a key distributor that implements a AAA-c lient and derives keys used to authenticate a mesh point during first contac t or fast security association. The key distributor and the on-line authenti cation server can communicate to one another without these messages being tr ansported over mesh links.
Abstract:
The disclosure relates to techniques and technologies for establishing a secure link between a mesh authenticator and a mesh key distributor for transporting security association messages. The secure link can allow the mesh key distributor to communicate results of an authentication process to the mesh authenticator.
Abstract:
A mesh station applying for access to a network includes a list of peer stations in messages of an authenticated key establishment protocol. A mesh key distributor derives a key delivery key and generates a top level key, and then delivers the top level key to the mesh station. Following the key establishment protocol, the mesh key distributor also creates pairwise keys for use between the mesh station and the peer stations listed in its peer list. The list of peers permits the identifier for the peer to be bound into the derived key, which helps ensure that the key used between each pair of peers is unique. Once the mesh key distributor finishes creating a key for one of the stations on the peer list, the mesh key distributor sends a message to the peer to initiate a key push.
Abstract:
A method and apparatus for providing a key for secure communications is provided herein. During operation a node wishing to join a network, will authenticate with an authentication server and then derive a pairwise key (e.g., a Pair-wise Transient Key (PTK)) used for encryption of unicast traffic. The node will also create its own group transient key (GTK) for use in encrypting multicast or broadcast traffic. Once the GTK is generated, it will be provided to an authenticator as part of an association request message.
Abstract:
The disclosure relates to techniques and technologies for establishing a secure link between a mesh authenticator and a mesh key distributor for transporting security association messages. The secure link can allow the mesh key distributor to communicate results of an authentication process to the mesh authenticator.
Abstract:
A method of communication between a transmitter node and a receiver node in a multi-hop communication network (100), comprising: formatting information into a data structure to generate a mesh action frame (400), wherein the mesh action frame (400) comprises a header (420) comprising a source address (SA) that identifies such a node, a destination address (DA) that identifies a recipient node, a transmitter address (TA) that identifies a sender node, and a receiver address (RA) that identifies a receiver node; and a body field (430) comprising a mesh action data unit (434); and sending the mesh action action frame from the transmitter node.
Abstract:
A method and apparatus for providing a key for secure communications is provided herein. During operation a node wishing to join a network, will authenticate with an authentication server and then derive a pairwise key (e.g., a Pair-wise Transient Key (PTK)) used for encryption of unicast traffic. The node will also create its own group transient key (GTK) for use in encrypting multicast or broadcast traffic. Once the GTK is generated, it will be provided to an authenticator as part of an association request message.
Abstract:
A method for security authentication within a wireless network is disclosed. A method within an adhoc mesh network for two devices to quickly determine roles (i.e. which is the authenticator and which is the supplicant) while establishing a security association is provided for. The invention further provides for the inclusion of cached key information in the role negotiation process and the application of role negotiation to a shortened three-way handshake.