Traitement en cours

Veuillez attendre...

Paramétrages

Paramétrages

Aller à Demande

1. CN101621374 - Method, device and system for network authentication and server

Office
Chine
Numéro de la demande 200810068193.9
Date de la demande 30.06.2008
Numéro de publication 101621374
Date de publication 06.01.2010
Type de publication A
CIB
H04L 9/08
HÉLECTRICITÉ
04TECHNIQUE DE LA COMMUNICATION ÉLECTRIQUE
LTRANSMISSION D'INFORMATION NUMÉRIQUE, p.ex. COMMUNICATION TÉLÉGRAPHIQUE
9Dispositions pour les communications secrètes ou protégées
08Répartition de clés
H04L 9/32
HÉLECTRICITÉ
04TECHNIQUE DE LA COMMUNICATION ÉLECTRIQUE
LTRANSMISSION D'INFORMATION NUMÉRIQUE, p.ex. COMMUNICATION TÉLÉGRAPHIQUE
9Dispositions pour les communications secrètes ou protégées
32comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
CPC
H04L 63/06
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
63Network architectures or network communication protocols for network security
06for supporting key management in a packet data network
H04L 63/0823
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
63Network architectures or network communication protocols for network security
08for supporting authentication of entities communicating through a packet data network
0823using certificates
H04L 2463/061
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
2463Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
061applying further key derivation, e.g. deriving traffic keys from a pair-wise master key
H04W 36/0038
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
WWIRELESS COMMUNICATION NETWORKS
36Hand-off or reselection arrangements
0005Control or signalling for completing the hand-off
0011for data session or connection
0033with transfer of context information
0038of security context information
H04W 12/041
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
WWIRELESS COMMUNICATION NETWORKS
12Security arrangements; Authentication; Protecting privacy or anonymity
04Key management, e.g. using generic bootstrapping architecture [GBA]
041Key generation or derivation
H04W 12/0431
HELECTRICITY
04ELECTRIC COMMUNICATION TECHNIQUE
WWIRELESS COMMUNICATION NETWORKS
12Security arrangements; Authentication; Protecting privacy or anonymity
04Key management, e.g. using generic bootstrapping architecture [GBA]
043using a trusted network node as an anchor
0431Key distribution or pre-distribution; Key agreement
Déposants Huawei Technologies Co., Ltd.
华为技术有限公司
Inventeurs Gong Xiaoyu
宫小玉
Li Hongguang
李洪广
Mandataires
Titre
(EN) Method, device and system for network authentication and server
(ZH) 一种网络认证的方法、装置、系统及服务器
Abrégé
(EN) The invention provides a method, a device and a system for network authentication and a server. The method of the invention comprises the following steps: receiving a user authentication request forwarded by a first access management functional entity when the user attaches onto a second access management functional entity from the first access management functional entity; acquiring an authenticated key of a security domain of the second access management functional entity according to the user authentication request; and authenticating user according to the authenticated key. The method solves the problem of the prior art that the intra-domain and inter-domain switching of the user is time-consuming and insecure so as to cause user service packet loss or even temporary service interruption, realizes the secure authentication of the user during intra-domain or inter-domain movement and improves the security and reliability of the user authentication.
(ZH)

本发明提供了一种网络认证的方法、装置、系统及服务器。本发明所述方法包括:当用户从第一接入管理功能实体附着到第二接入管理功能实体时,接收来自所述第一接入管理功能实体转发的用户认证请求;根据所述用户认证请求,获得所述第二接入管理功能实体的安全域的认证密钥;根据所述认证密钥,对用户进行认证。解决了现有技术中用户在域内和域间切换时,耗时长,且安全性差,导致用户业务的丢包甚至暂时中断业务的问题,实现了用户在域内或者域间移动的安全的认证,提高了用户认证的安全性、可靠性。