1460946094-3e9fba6a-7868-4f83-b2e8-39e659ad86c4

1. A method of managing access to a network, comprising the steps of:
providing a challenge-handshake protocol within an Extensible Authentication Protocol for authentication between a client and the network; and
deriving a network session key and a client session key, whereafter successful authentication of both the client to the network and the network to the client, the network session key is used to both create a packet signature and to encrypt a key value of a multicast key that is transmitted from the network to the client.
2. The method of claim 1, wherein the challenge-handshake protocol in the step of providing is a CHAP (Challenge-Handshake Authentication Protocol).
3. The method of claim 1, wherein authentication in the step of providing is performed mutually between the client and the network.
4. The method of claim 1, wherein the challenge-handshake protocol comprises the step of mutually authenticating a client and the network in response to a single sign-on by a user of the client.
5. The method of claim 1, wherein the challenge-handshake protocol in the step of providing facilitates authentication between the network and the client, which client is a wireless client.
6. The method of claim 1, wherein the challenge-handshake protocol in the step of providing facilitates authentication between the network and the client, which client is a wired client.
7. The method of claim 1, wherein the client session key is derived independently of the network session key, which both the network session key and the client session key are utilized for enabling secure communications between the client and the network.
8. The method of claim 7, wherein the network session key is derived from a username of a user input to the client and transmitted to the network.
9. The method of claim 1, wherein the challenge-handshake protocol in the step of providing is utilized between an authentication server disposed on the network and the client, the authentication server performing an authentication of the client, followed by the client performing an authentication of the network.
10. The method of claim 1, wherein the network includes an authentication server disposed thereon for providing authentication services and a network access server disposed thereon for providing communications between the client and the authentication server, whereafter successful mutual authentication between the authentication server and the client, the authentication server passes a session key to the network access server utilizing vendor-specific attribute data.
11. The method of claim 1, wherein the client is a wireless client including a network interface device, the network interface device adapted to host the challenge-handshake protocol utilized for authentication between the wireless client and the network.
12. A method of managing access to a network, comprising the steps of:
providing a challenge-handshake protocol within an Extensible Authentication Protocol for authentication between a client and the network;
wherein the network includes an authentication server disposed thereon for providing authentication services and a network access server disposed thereon for providing communications between the client and the authentication server, whereafter successful mutual authentication between the authentication server and the client, the authentication server passes a session key to the network access server utilizing vendor-specific attribute data.
13. The method of claim 12, wherein the challenge-handshake protocol in the step of providing is a CHAP (Challenge-Handshake Authentication Protocol).
14. The method of claim 12, wherein the challenge-handshake protocol comprises the step of mutually authenticating a client and the network in response to a single sign-on by a user of the client.
15. The method of claim 12, wherein the challenge-handshake protocol in the step of providing facilitates authentication between the network and the client, which client is a wireless client.
16. The method of claim 12, wherein the challenge-handshake protocol in the step of providing facilitates authentication between the network and the client, which client is a wired client.
17. The method of claim 12, wherein the challenge-handshake protocol in the step of providing is utilized between an authentication server disposed on the network and the client, the authentication server performing an authentication of the client, followed by the client performing an authentication of the network.
18. The method of claim 12, wherein the vendor-specific attribute data is indicative of an enctyption key value.
19. The method of claim 18, further comprising extracting the encryption key value by the network access server.
20. The method of claim 19, further comprising sending an encrypted message by the network access server to the client, the encrypted message indicating to the client a key length and key index of the session key.
21. The method of claim 20, further comprising, sending a second message by the network access server to the client, the second encrypted message comprising the key length, key index, and a value of a multicast key.
22. A system of managing access to a network, comprising:
an authentication server disposed on the network to provide an authentication service; and
a network access server disposed on the network in communication with a client seeking access to the network;
wherein the authentication server and the client are adapted to communicate utilizing a challenge-handshake protocol within an Extensible Authentication Protocol for authentication of the client and the authentication server; and
wherein a network session key and a client session key are derived, whereafter successful authentication of both the client to the network and the network to the client, the network session key is used to both create a packet signature and to encrypt a key value of a multicast key that is transmitted from the network access server to the client.
23. The system of claim 22, wherein the challenge-handshake protocol is a CHAP (Challenge-Handshake Authentication Protocol).
24. The system of claim 22, wherein the challenge-handshake protocol is utilized to mutual authenticate the client and the authentication server in response to a single sign-on by a user of the client.
25. The system of claim 22, wherein the challenge handshake protocol facilitates authentication between the network and the client, which is a wireless client.
26. The system of claim 22, wherein the challenge-handshake protocol facilitates authentication between the network and the client, which client is a wired client.
27. The system of claim 22, wherein the network session key is derived from a username of a user input to the client and transmitted to the authentication server.
28. The system of claim 22, wherein the authentication server performs an authentication of the client, followed by the client performing an authentication of the authentication server.
29. The system of claim 22, wherein after successful mutual authentication between the authentication server and the client, the authentication server passes a session key to the network access server utilizing vendor-specific attribute data.
30. The system of claim 22, wherein the client is a wireless client including a network interface device, the network interface device adapted to host the challenge-handshake protocol utilized for authentication between the wireless client and the network.
31. The system of claim 22, wherein the network access server is a network switch adapted to facilitate communication between the authentication server and the client, which client is a wired client.
32. A system of managing access to a network, comprising:
an authentication server disposed on the network to provide an authentication service; and
a network access server disposed on the network in communication with a client seeking access to the network;
wherein the authentication server and the client are adapted to communicate utilizing a challenge-handshake protocol within an Extensible Authentication Protocol for authentication of the client and the authentication server; and
wherein after successful mutual authentication between the authentication server and the client, the authentication server passes a session key to the network access server utilizing vendor-specific attribute data.
33. The system of claim 32, wherein the challenge-handshake protocol is a CHAP (Challenge-Handshake Authentication Protocol).
34. The system of claim 32, wherein the challenge-handshake protocol is utilized to mutual authenticate the client and the authentication server in response to a single sign-on by a user of the client.
35. The system of claim 32, wherein the challenge-handshake protocol facilitates authentication between the network and the client, which is a wireless client.
36. The system of claim 32, wherein the challenge-handshake protocol facilitates authentication between the network and the client, which client is a wired client.
37. The system of claim 32, wherein a session key is derived for enabling secure communications between the client and the network access server.
38. The system of claim 32, wherein a network session key and a client session key are derived, which client session key is derived independently of the network session key, which both the network session key and the client session key are utilized for enabling secure communications between the client and the network access server.
39. The system of claim 38, wherein the network session key is derived from a username of a user input to the client and transmitted to the authentication server.
40. The system of claim 32, wherein the authentication server performs an authentication of the client, followed by the client performing an authentication of the authentication server.
41. The system of claim 32, wherein a network session key and a client session key are derived, whereafter successful authentication of both the client to the network and the network to the client the network session key is used to both create a packet signature and to encrypt a key value of a multicast key that is transmitted from the network access server to the client.
42. A system according to claim 32, wherein the vendor-specific attribute data is indicative of an encryption key value.
43. A system according to claim 42, wherein the network access server extracts the encryption key value by the network access server.
44. A system according to claim 43, wherein the network access server responsive to extracting the encryption key value sends an encrypted message to the client, the encrypted message indicating to the client a key length and key index of the session key.
45. A system according to claim 44, wherein the network access server is responsive to extracting the encryption key value to send a second message to the client, the second encrypted message comprising the key length, key index, and a value of a multicast key.
46. The system of claim 32, wherein the client is a wireless client including a network interface device, the network interface device adapted to host the challenge-handshake protocol utilized for authentication between the wireless client and the network.
47. The system of claim 32, wherein the network access server is a network switch adapted to facilitate communication between the authentication server and the client, which client is a wired client.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. An apparatus for obtaining a biopsy sample, comprising:
a first cannula having a lumen surrounded by a lumen wall, said first cannula having a distal end with a sharp edge, said first cannula further having a slit beginning at a point proximal of said distal end and extending proximally, said wall between said distal end and said slit being smooth;
a second cannula within said lumen of said first cannula, said second cannula having a lumen and a closed distal end tapering to a point, said second cannula having an outer diameter such that said second cannula has a close and rotatable fit with said wall of said first cannula, said second cannula further having a slit beginning at a point proximal of said tapering distal end surface and not in the tapering surface and bounded by at least one sharpened edge,
wherein said cannulas have a first open relative position, in which said slits define an open passage from the exterior of said first cannula to the lumen of said second cannula, and a second closed position, in which said slits are rotationally offset from each other, and wherein change between said first position and said second position is accomplished by rotation of at least one of said cannulas, and wherein said slits are helical and extend about 360 degrees around said respective first and second cannulas.
2. The apparatus of claim 1, wherein said slits are substantially congruent to each other, so that when said cannulas are in said first open relative position, said slits are substantially exactly aligned along their entireties.
3. The apparatus of claim 2, wherein said first cannula has a central longitudinal axis, and said second cannula is rotatable around said central longitudinal axis.
4. The apparatus of claim 3, wherein said slits are non-parallel to said central longitudinal axis.
5. The apparatus of claim 4, wherein said slits are diagonal or helical with respect to said central longitudinal axis.
6. The apparatus of claim 3, wherein said slits are parallel to said central longitudinal axis.
7. The apparatus of claim 1, wherein said distal end of said first cannula is closed, said cannulas being configured so that said tapering distal end of said second cannula can engage said closed distal end of said first cannula, and so that when said tapering distal end engages said closed distal end of said first cannula, said slits are relatively positioned in one of: said first open relative position, said second closed relative position, and a position between said first and second relative positions.
8. The apparatus of claim 1, further comprising a handle having an inner portion and an outer portion, said outer portion fixed to said first cannula and said inner portion fixed to said second cannula, wherein rotation of at least one of said handle portions with respect to the other shifts said cannulas toward one of said relative positions.
9. The apparatus of claim 8, wherein said inner handle portion is rotatable with respect to said outer handle portion, and wherein said inner handle portion is spring-biased, said bias tending to hold said cannulas in said second relative position.
10. The apparatus of claim 9, further comprising a triggering mechanism adapted to hold said inner handle portion in a cocked position against said bias, wherein said cocked position corresponds to said cannulas being in said first open relative position, and wherein release of said triggering mechanism allows said bias to rotate said second cannula within said first cannula.
11. The apparatus of claim 1, wherein at least one of said distal end of said first cannula and said distal end of said second cannula includes a marker that is at least one of radiopaque and echogenic.
12. An apparatus for obtaining a biopsy sample, comprising:
a first tubular member having a distal end and a slit a distance proximally away from said distal end;
a second tubular member rotatably positioned within said first tubular member and having a slit with at least one sharpened lateral edge; and
a handle having a first portion attached to said first tubular member and a second portion attached to said second tubular member, said handle including a spring-bias and a triggering mechanism,
wherein said apparatus has a first uncocked configuration in which said slits do not overlap, and a second cocked configuration in which said second tubular member and second handle portion are rotated from said first configuration against the bias so that said slits overlap and said triggering mechanism maintains said second configuration, and wherein activation of said triggering mechanism when said apparatus is in said second configuration results in said bias rotating said second tubular member within said first tubular member to said first configuration, and wherein said slits are helical and extend about 360 degrees around said respective first and second tubular members.
13. The apparatus of claim 12, wherein at least one of said slits is diagonal or helical.
14. The apparatus of claim 12, wherein in said second configuration the entirety of said slit of said second tubular member overlaps said slit of said first tubular member.
15. The apparatus of claim 12, wherein said second tubular member is adapted to be entirely withdrawn longitudinally from within said first tubular member to retrieve a sample within said second tubular member.
16. The apparatus of claim 12, wherein each of said slits has a length measured along a longitudinal axis of their respective tubular members and a width measured perpendicular to the longitudinal axis of their respective tubular members, and wherein said widths are substantially constant and subtend an arc of more than 90 degrees but less than 180 degrees of their respective tubular members.
17. The apparatus of claim 12, wherein said slit of said first tubular member has at least one lateral edge that is sharpened, and said sharpened lateral edge of said slit of said first tubular member faces said sharpened lateral edge of said slit of said second tubular member when said apparatus is in said second cocked configuration.
18. An apparatus for obtaining a biopsy sample, comprising:
a first cannula having a central lumen surrounded by a lumen wall, said first cannula having a distal end with a sharp edge, said first cannula further having a diagonal or helical slit beginning at a point proximal of said distal end and extending proximally, said wall between said distal end and said slit being smooth;
a second cannula having a lumen and a closed distal end tapering to a point, said second cannula being positioned within said lumen of said first cannula so that said tapering distal end of said second cannula is within or extending from said distal end of said first cannula, said second cannula having an outer diameter such that said second cannula has a close and rotatable fit with said wall of said first cannula, said second cannula further having a diagonal or helical slit beginning at a point proximal of said tapering distal end and bounded by at least one sharpened edge,
wherein said cannulas have a first open relative position, in which said slit of said first cannula lies over the entirety of said slit of said second cannula and said slits define an open passage from the exterior of said first cannula to the lumen of said second cannula, and a second closed position, in which said slits are rotationally offset from each other and no part of said slots face each other, and wherein change between said first position and said second position is accomplished by rotation of said second cannula with respect to said first cannula; and
a handle having a first portion fixed to said first cannula and a second portion fixed to said second cannula, said second portion rotatable with respect to said first portion to rotate said second cannula with respect to said first cannula, said handle including a spring biasing said second handle portion so that said cannulas are in said second closed relative position and a triggering mechanism adapted to hold one or both of said handle portions against the bias of the spring so that said cannulas are in said first open relative position.
19. The apparatus of claim 18, wherein said distal end of said first cannula is closed, and said tip of said second cannula abuts said distal end of said first cannula.
20. The apparatus of claim 18, wherein said distal end of said first cannula is open, and said tip of said second cannula faces outward from said distal end of said first cannula and forms with said distal end of said first cannula a leading insertion end of said apparatus.
21. The apparatus of claim 18, wherein at least one of said distal end of said first cannula and said tip of said second cannula includes a marker that is at least one of radiopaque and echogenic.