Methods and Devices Having a Key Distributor Function for Improving the Speed and Quality of a Handover
Abstract
Embodiments relate to a key distributer node (AS) for a network, which comprises: a) a memory device ( 1 ) with at least one first key, b) at least one data communication device ( 2 ) that can exchange data with first and second access nodes (MAP 1 , MAP 2 ) for a terminal (STA) integrated wirelessly into the network, c) at least one processor ( 3 ) connected to the memory device ( 1 ) and the data communication device ( 2 ), wherein functions are provided for the processor(s) that allow authentication of the terminal (STA) at the second access node (MAP 2 ) in response to a key request received by the second access node (MAP 2 ), d) a derivation of a second key from the first key, and e) triggered transmission of the second key through the data communication device to the second access node (MAP 2 ). Connections to the network's first and second access nodes (MAP 1 , MAP 2 ) with security relationships are provided for the key distributor node (AS) when using the first key.
Claims
exact text as granted — not AI-modified1 . A key distributor node for a mesh network, comprising:
a) a memory device with at least one first key, said first key derived from a master key for a plurality of terminals incorporated into a mesh network, b) at least one data communication device exchanging data with first and second access nodes for a terminal integrated wirelessly into the network, c) at least one processor connected to the memory device and the data communication device,
wherein functions are provided for at least one processor that authenticates of the terminal at the second access node in response to a received key request from the second access node;
d) a second key, to be derived from the first key stored in the memory device, and
e) triggered transmission of the second key through the data communication device to the second access node,
wherein the key distributor node has connections to the mesh network's first and second access nodes with security relationships that are established when the key request is received by the second access node, when using the first key.
2 . The key distributor node of claim 1 , wherein the key distributor node is an authentication server.
3 . The key distributor node of claim 1 , the key distributor node is a node on a mesh network.
4 . The key distributor node of claim 1 , wherein the second key encodes proprietary features of the terminal.
5 . The key distributor node of claim 1 , wherein the first and second keys are symmetric key pairs.
6 . A combination key distributor node comprising the key distributor node of claim 1 , the first access node and the second access node.
7 . The combination key distributor node of claim 6 , wherein the first and second access nodes are nodes on a mesh network.
8 . A network comprising the key distributor node of claim 1 , the first access node, the second access node, and a terminal.
9 . A method for authenticating a terminal during a handover procedure in a network comprising the key distributor node of claim 1 , the first access node, the second access node and a network terminal, comprising in sequence:
receiving, by the network terminal, an authentication query through the second access node, requesting the second key at the key distributor node through the second access node, deriving the second key from the first key, triggering transmission of the second key through the data communication device to the second access node, sending the second key through the data communication device to the second access node, transmitting an authentication response through the second access node to the terminal, and associating the terminal with the second access node.
10 . The method of claim 9 , comprising performing the steps of receiving, requesting, deriving, triggering, sending, transmitting, and associating if the terminal is located in a wireless cell overlap area of the first and second access nodes.
11 . The method of claim 9 , further comprising configuring the key distributor node, nodes (AS), wherein an initial authentication of the first and second access node, is performed before the receiving step at the key distributor node by storing the first key in the storage device.
12 . Computer-readable storage media comprising instructions that, when implemented, carry out the method of claim 9 .
13 . (canceled)
14 . (canceled)
15 . The key distributor node of claim 1 , wherein the network facilitates at least one member of the group consisting of a voice-over-IP application and a video-on-demand application.
16 . The network of claim 8 , wherein said network is a mesh network.
17 . The network of claim 16 , wherein the mesh network is a local network.Join the waitlist — get patent alerts
Track US2012239933A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.