Claims
- 1. A method for providing security services for ad-hoc nodes, the method comprising the steps of:
transmitting a set of user identities from a first ad-hoc node to a network external to the first ad-hoc node, the set of user identities including user identities related to at least one ad-hoc node; generating a first set of authentication parameters in the external network, the first set of authentication parameters including an authentication vector for at least one user identity included in the set of user identities and at least one authentication vector including a second set of authentication parameters; transferring at least some of the authentication parameters of at least one second set of authentication parameters to the first ad-hoc node, whereby a third set of authentication parameters is received at the first ad-hoc node; and utilizing the third set of authentication parameters at the first ad-hoc node for providing a security service for at least one other ad-hoc node.
- 2. A method according to claim 1, further comprising the step of forming the set of user identities at the first ad-hoc node, the forming step being performed prior to the transmitting step.
- 3. A method according to claim 2, wherein the transferring step includes transferring a first user challenge in said at least one second set of authentication parameters, and wherein the utilizing step further comprises the steps of:
sending a second user challenge to ad-hoc nodes corresponding to the set of user identities; based on the second user challenge received, determining a user response in said ad-hoc nodes; returning the user responses to the first ad-hoc node; and authenticating at least one of said ad-hoc nodes based on the user response received from a corresponding ad-hoc node.
- 4. A method according to claim 2, further comprising including a plurality of user identities in the set of user identities.
- 5. A method according to claim 1, further comprising including one user identity in the set of user identities, wherein the first set of authentication parameters comprises one authentication vector.
- 6. A method according to claim 5, further comprising providing the one user identity comprising the identity of the first ad-hoc node.
- 7. A method according to claim 1, wherein
the transferring step further comprises transferring a set of security keys to the first ad-hoc node; and the utilizing step further comprises delivering at least some of the security keys to the at least one other ad-hoc node.
- 8. A method according to claim 1, further comprising performing the transmitting step periodically.
- 9. A method according to claim 3, further comprising forming an ad-hoc network.
- 10. A method according to claim 1, further comprising the step of changing an ad-hoc node that acts as the first ad-hoc node and said transmitting step, said generating step, said transferring step and said utilizing step are performed with respect to one first ad-hoc node at a time.
- 11. A system for providing security services for ad-hoc nodes, the system comprising:
first signaling means for transmitting a set of user identities from a first ad-hoc node to a network external to said first ad-hoc node, the set of user identities including user identities related to at least one ad-hoc node; in the external network, authentication means for generating a first set of authentication parameters, the first set of authentication parameters including an authentication vector for at least one user identity included in the set of user identities and at least one authentication vector including a second set of authentication parameters; second signaling means for transferring a third set of authentication parameters to the first ad-hoc node, the third set including at least some of the authentication parameters of at least one second set of authentication parameters, and; service provision means for utilizing the third set of authentication parameters for providing a security service for at least one ad-hoc node other than said first ad-hoc node.
- 12. A system according to claim 11, wherein several ad-hoc nodes form an ad-hoc network, and at least some of said several ad-hoc nodes being provided with the first signaling means and the service provision means.
- 13. A system according to claim 11, wherein the external network comprises a mobile communication network.
- 14. An ad-hoc node for providing security services in an ad-hoc network, the ad-hoc node comprising:
first signaling means for transmitting a set of user identities to a second network external to the ad-hoc network, the set of user identities including user identities related to at least one ad-hoc node; second signaling means for receiving a first set of authentication parameters from the second network, and service provision means for providing a security service in the ad-hoc network, the service provision means being configured to utilize the first set of authentication parameters received by the second signaling means.
- 15. A system for providing security services for ad-hoc nodes, the system comprising:
a first ad-hoc node configured to transmit a set of user identities to a network external to said first ad-hoc node, the set of user identities including user identities related to at least one ad-hoc node; and in the external network, an authentication unit configured to generate a first set of authentication parameters, the first set of authentication parameters including an authentication vector for at least one user identity included in the set of user identities and at least one authentication vector including a second set of authentication parameters; wherein the external network is configured to transmit a third set of authentication parameters to the first ad-hoc node, the third set including at least some of the authentication parameters of at least one second set of authentication parameters, and the first ad-hoc node is configured to utilize the third set of authentication parameters for providing a security service for at least one ad-hoc node other than said first ad-hoc node.
- 16. An ad-hoc node for providing security services in an ad-hoc network, the ad-hoc node comprising:
a first interface to an external network, the first interface being configured to transmit a set of user identities to the external network, the set of user identities including user identities related to at least one ad-hoc node, and to receive a first set of authentication parameters from the external network, and a second interface to an ad-hoc network, the second interface being operatively connected to the first interface for providing a security service based on the first set of authentication parameters in the ad-hoc network.
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority of U.S. Provisional Application Serial No. 60/454,306 entitled, “Provision of Security Services for an Ad-Hoc Network,” filed Mar. 14, 2003, the entire contents of which are incorporated herein by reference.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60454306 |
Mar 2003 |
US |