The present invention relates to wireless communications systems, more particular, to a wireless transport network system that is capable of distribution of global encryption key in a wireless network.
Typical wireless network systems comprise one or more access devices for communication purposes. The users may be communicated with the access device with personal computers or notebook computers via wireless means. Wireless local area networks (WLANs) were originally intended to allow wireless connections to a wired local area network (LAN), such as where premises wiring systems were nonexistent or inadequate to support conventional wired LANS. WLANs are often used to service mobile computing devices, such as laptop computers and personal digital assistants (PDAs). Typically, Access Points (APs) are set to ensure adequate radio coverage throughout the service area of the WLAN, while minimizing the costs associated with the installation of each AP. The APs must be configured to eliminate coverage gaps and to provide adequate coverage.
A wireless transport network is a network comprises a plurality of wirelessly connected devices that are responsible for relaying traffic for associated mobile clients. An example of a wireless transport network is a plurality of IEEE 802.11 capable devices that provide transport service for IEEE 802.11 or Bluetooth capable clients such as laptop computers, PDA (personal digital assistant), and the like. The network can further comprise one or more connections to a wired network through one or multiple edge devices. The edge devices are equipped and capable of both wireless and wired communication.
In a wireless transport network, confidentiality and authenticity of data traffic is most important. The transmission domain (the air) by nature is not secured and therefore encryption is essential in any wireless transport networks. Pair-wise encryption/decryption between every neighboring wireless network device of a wireless transport network is inefficient and time-consuming if hardware-assist encryption and decryption is not available. A data frame that leaves from one wireless device from one end of a wireless transport network to the other end of the same network might need several encryptions and decryptions before it reaches its final destination. Furthermore, a group key for a broadcast or a multicast data frame is still needed in addition to pair-wise encryption keys. A more efficient and easy-to-manage encryption/decryption scheme in a wireless transport network is to use a global encryption key for wireless transport network encryption service. Once a data frame from client mobile station enters a wireless transport network, it is encrypted only once until it reaches the exit wireless device, where it would be decrypted once.
Furthermore, in a wireless transport network, wireless devices might be temporary out of service, resulting in separated network segments. Each of the network segments might have a different global encryption key, which is used in the confine of the segment. When network segments are joined by a new wireless device, a new global encryption key is needed. The invention is particularly concerned with deploying a unique global encryption key for wireless devices that form a wireless transport network and with several wireless transport network segments that are joined by a new wireless device.
The purpose for the present invention is to provide an encryption key distribution method in a wireless transport network. A plurality of wireless transport devices and at least one edge device are needed in the network.
The method of providing encryption service in a wireless transport network comprises the step of designating a first wireless device as a global encryption key server to create and maintain the global encryption key for a wireless transport network encryption. Next step is to distribute the global encryption key from the first wireless device to a second wireless device in the wireless transport network. The existing global encryption key in the second wireless device is replaced by the global encryption key. Further step is to transit an expiring global encryption key to a new global encryption key in the wireless transport network without traffic loss and security.
The method further includes a step of selecting a new designated global encryption key server in the case of failure of the designated global encryption key server in the wireless transport network. A step of selecting a new designated global encryption key server is performed in the case of failure of the designated global encryption key server in the wireless transport network. Re-selecting a designated global encryption key server is employed when the failed designated global encryption key server recovers.
The present invention discloses a wireless device capable of distributing a global encryption key in a wireless transport network. The device includes a processing unit and memory. The wireless device includes a wireless transport device. The device also includes means for authenticating coupled to the processing unit to authenticate another wireless device (such as another wireless transport device) in separated network segments of the wireless transport network, and means for selecting is coupled to the processing unit for selecting a global encryption key among the separate network segments for global encryption key distribution. Means for distributing is coupled to the processing unit to distribute the global encryption key. Means for decrypting/re-encrypting is also coupled to the processing unit for performing decrypting/re-encrypting in the wireless transport network until all the separate network segments use the global encryption key.
The present invention provides a method and a means for providing secured communication in a wireless transport network. The invention provides a method to create, maintain, and distribute global encryption key to all wireless devices in a wireless transport network. The invention provides a means for a wireless device to join segments of a wireless transport network with different global encryption keys to a seamlessly integrated wireless transport network with a single global encryption key.
Wireless Transport Network
As illustrated in
Method of Providing Encryption Service
The novel aspect according to the present invention is a method of providing encryption service in a wireless transport network. Please refer to
The further step in accordance with the above method includes the step (240) of selecting a new designated global encryption key server by the user, controller or network service provider in the case of temporary failure of the designated global encryption key server in a wireless transport network, please refer to
Please refer to
Therefore, the present invention provides the unique global encryption key for wireless devices that form a wireless transport network and with several wireless transport network segments that are joined by a new wireless device.
It will be appreciated that the preferred embodiments described above are cited by way of example, and that the present invention is not limited to what has been particularly shown and described hereinabove. Rather, the scope of the present invention includes both combinations and sub-combinations of the various features described hereinabove, as well as variations and modifications thereof which would occur to persons skilled in the art upon reading the foregoing description and which are not disclosed in the prior art.
This application claims the benefit of U.S. provisional application serial No. 60/495185, filed on Aug. 15, 2003, which provisional application is hereby incorporated by reference. The present invention is also related to co-pending application serial number ______, filed on Aug. 10, 2004, under Express Mail Label No. EV547998129US and entitled “Methods and Apparatus for Broadcast Traffic Reduction on a Wireless Transport Network”. The co-pending application is incorporated herein for reference.
Number | Date | Country | |
---|---|---|---|
60495185 | Aug 2003 | US |