The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 26, 2014

Filed:

Jan. 10, 2008
Applicant:

Yoshihiro Oba, Englewood Cliffs, NJ (US);

Inventor:

Yoshihiro Oba, Englewood Cliffs, NJ (US);

Assignees:

Toshiba America Research, Inc., Washington, DC (US);

Telecordia Technologies, Inc., Piscataway, NJ (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 9/08 (2006.01); H04L 29/06 (2006.01); H04L 9/32 (2006.01); G06F 7/04 (2006.01); G06F 15/16 (2006.01); G06F 17/30 (2006.01); G06F 21/33 (2013.01);
U.S. Cl.
CPC ...
H04L 63/0807 (2013.01); H04L 9/321 (2013.01); H04L 9/3213 (2013.01); G06F 21/335 (2013.01);
Abstract

A media-independent handover key management architecture is disclosed that uses Kerberos for secure key distribution among a server, an authenticator, and a mobile node. In the preferred embodiments, signaling for key distribution is based on re-keying and is decoupled from re-authentication that requires EAP (Extensible Authentication Protocol) and AAA (Authentication, Authorization and Accounting) signaling similar to initial network access authentication. In this framework, the mobile node is able to obtain master session keys required for dynamically establishing the security associations with a set of authenticators without communicating with them before handover. By separating re-key operation from re-authentication, the proposed architecture is more optimized for a proactive mode of operation. It can also be optimized for reactive mode of operation by reversing the key distribution roles between the mobile node and the target access node.


Find Patent Forward Citations

Loading…