发明名称 Method and system for authenticating peer devices using EAP
摘要 A system and method for authenticating a peer device onto a network using Extensible Authentication Protocol (EAP). The key lifetime associated with the keying material generated in the peer device and the authentication server is communicated from the authenticator to the peer device within the EAP Success message. The peer device, having been provided with the key lifetime, can anticipate the termination of its authenticated session and initiate re-authentication prior to expiry of the key lifetime.
申请公布号 US9391776(B2) 申请公布日期 2016.07.12
申请号 US201414460978 申请日期 2014.08.15
申请人 BlackBerry Limited 发明人 Salomone Leonardo Jose Silva
分类号 H04L9/32;H04L29/06 主分类号 H04L9/32
代理机构 Ridout & Maybee LLP 代理人 Ridout & Maybee LLP
主权项 1. A method for authenticating a peer device onto a network having an authenticator and an authentication server, the authentication server supporting modifications to Extensible Authentication Protocol (EAP), the network being accessible through an access point associated with the authenticator, the method including steps of: exchanging EAP-specific authentication messages between the peer device and the authentication server via the authenticator; generating keying material in the peer device, wherein the authentication server generates said keying material and an associated key lifetime in the authentication server, and communicates said keying material and said associated key lifetime from the authentication server to the authenticator; receiving an EAP Success packet from the authenticator to the peer device following the exchange of EAP-specific authentication messages, wherein the EAP Success packet comprises a code field set to Success, and wherein the EAP Success packet exclusively contains said associated key lifetime, to complete authentication to grant the peer device unblocked access to the network; conducting a 4-way handshake, without receiving the associated key lifetime during the 4-way handshake, to complete said authentication and grant the peer device unblocked access to the network after communication of the EAP Success packet to the peer device; and establishing re-authentication with the authentication server via the authenticator, at a time which is a fixed time interval prior to session timeout of the associated key lifetime as selected by a user of the peer device, including generating second keying material; and responsive to determining no active media sessions are disrupted as a result of the re-authentication, completing the re-authentication with the second keying material.
地址 Waterloo CA