首页> 外国专利> A ZERO-CONFIGURATION SECURE MOBILITY NETWORKING TECHNIQUE WITH WEB-BASE AUTHENTICATION METHOD FOR LARGE WLAN NETWORKS

A ZERO-CONFIGURATION SECURE MOBILITY NETWORKING TECHNIQUE WITH WEB-BASE AUTHENTICATION METHOD FOR LARGE WLAN NETWORKS

机译:大型WLAN网络的基于Web认证的零配置安全移动网络技术。

摘要

A zero-configuration secure mobility networking technique for WLANs is provided, utilizing split link-layer and a Web-based authentication. The link- layer authentication process facilitates network-to-user authentication and generation of session-specific encryption keys for air traffic using digital certificates to prevent man-in- the-middle attacks without requiring users to have pre-configured accounts. Although any WLAN host can pass the link-layer authentication and obtain link connectivity, the WLAN only allows the host to obtain IP networking configuration parameters and to communicate with a Web-based authentication server prior to initiating the Web- based authentication process that is responsible for user-to-network authentication. The Web- based authentication server employs a Web page for initial authentication and a Java applet for consequent authentications. In-the Web page, registered users can manually, or configure their Web browsers to automatically, submit their authentication credentials; new users can open accounts, make one-time payments, or refer the Web-based authentication server to other authentication servers where hey have accounts. Once a user is authenticated to the WLAN, the user's mobile host obtains full IP connectivity and receives secure mobility support from the WLAN. The mobile host always owns a fixed IP address as it moves from one access point to another in the WLAN. All wireless traffic between the mobile host and the WLAN is encrypted. Whenever the mobile host moves to a new access point, a Java applet (or an equivalent client-side program delivered over Web) enables automatic authentication of the mobile host to the WLAN. In addition, the ZCMN method supports dynamic load balancing between home agents. Thus, a mobile host can change home agents during active sessions.
机译:利用分离的链路层和基于Web的身份验证,提供了一种用于WLAN的零配置安全移动网络技术。链路层身份验证过程使用数字证书来促进网络到用户的身份验证以及针对空中流量的会话专用加密密钥的生成,从而防止中间人攻击,而无需用户具有预先配置的帐户。尽管任何WLAN主机都可以通过链路层身份验证并获得链路连接,但是WLAN仅允许主机获取IP网络配置参数并在启动负责的基于Web的身份验证过程之前与基于Web的身份验证服务器进行通信。用于用户到网络的身份验证。基于Web的身份验证服务器使用网页进行初始身份验证,并使用Java小程序进行后续身份验证。在Web页面中,注册用户可以手动或将其Web浏览器配置为自动提交其身份验证凭据。新用户可以开设帐户,一次性付款或将基于Web的身份验证服务器引用到其他拥有帐户的身份验证服务器。用户通过WLAN身份验证后,用户的移动主机将获得完整的IP连接,并从WLAN接收安全的移动性支持。当移动主机从WLAN中的一个接入点移动到另一个接入点时,它始终拥有固定的IP地址。移动主机和WLAN之间的所有无线流量均已加密。每当移动主机移动到新的访问点时,Java小程序(或通过Web交付的等效客户端程序)都可以自动向WLAN认证移动主机。另外,ZCMN方法支持本地代理之间的动态负载平衡。因此,移动主机可以在活动会话期间更改家乡代理。

著录项

  • 公开/公告号CA2413944C

    专利类型

  • 公开/公告日2007-07-24

    原文格式PDF

  • 申请/专利权人 AT&T CORP.;

    申请/专利号CA20022413944

  • 发明设计人 LUO HUI;

    申请日2002-12-11

  • 分类号H04L9/32;H04L12/12;H04L12/24;H04L12/28;

  • 国家 CA

  • 入库时间 2022-08-21 20:54:06

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号