CA2349520A1

An agile network protocol for secure communications with assured system availability

Abstract

A plurality of computer nodes communicates using seemingly random IP source and destination addresses and (optionally) a seemingly random discriminator field. Data packets matching criteria defined by a moving window of valid addresses are accepted for further processing, while those that do not meet the criteria are rejected. In addition to "hopping" of IP addresses and discriminator fields, hardware addresses such as Media Access Control addresses can be hopped. The hopped addresses are generated by random number generators having non-repeating sequence lengths that are easily determined a- priori, which can quickly jump ahead in sequence by an arbitrary number of random steps and which have the property that future random numbers are difficult to guess without knowing the random number generator's parameters. Synchronisation techniques can be used to re-establish synchronization betwe en sending and receiving nodes. These techniques include a self-synchronization technique in which a sync field is transmitted as part of each packet, and a "checkpoint" scheme by which transmitting and receiving nodes can advance to a known point in their hopping schemes. A fast-packet reject technique based o n the use of presence vectors is also described.

CA2349520A1, drawing sheet 1
Sheet 1 of 19

Term

Term ended

Projected expiry passed 29 October 2019, 6.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

7 claims: 4 independent, 3 dependent

  1. 1
    CA 02349520 2001-04-27 22-11-2000 US 009925323 CLAIMS [Claims 1-49 are cancelled.] AMENDED SHEET »·ΙΧ. L~1 ν%-*1 IlCu \ CA*02349520* 2001-04-27 CCI IT ECM· 22-11-2000 +49 69 239944rtfi:*n US 009925323 50. A method of transmitting data from a first computer to a second computer, the data comprising a plurality of data bytes arranged in a particular order, the method comprising the steps of;25 (1) establishing in the first computer and second computer a common algorithm that determines how data will be randomly distributed across a plurality of data packets;
  2. 2
    (2) in the first computer, randomly distributing the plurality of data bytes across the plurality of data packets according to the common algorithm;AMENDED SHEET CA 02349520 2001-04-27 WO 00/27090 PCT/US99/25323 -
  3. 4
    (4) adding a cleartext packet header to route the packet encrypted in step (3); and CA 02349520 2001-04-27 WO 00/27090 PCT/US99/25323 (5) transmitting the packet created in step (4). 55. The method of claim 54, further comprising the steps of:
  4. 5
    (5) at each intermediate computer, decrypting the packet received from a previous computer and decrypting it using the link key;5
  5. 6
    (6) re-encrypting the packet using a different link key known to a next intermediate computer in the network;
  6. 7
    (7) adding a cleartext packet header to route the packet re-encrypted in step (6); and (8) transmitting the packet created in step (7) to the next intermediate computer. 56. The method of claim 55, further comprising the step of, at the receiving computer, 10 decrypting the packet using the session key. 57. A method of transmitting data over a computer network, comprising the steps of:at an originating terminal connected to the computer network, receiving a stream of data and forming first level data packet payloads therefrom;identifying a network destination address for the stream of data and adding first level 15 headers containing data representing the network destination address to each of the data packets to form a first level packet;encrypting each of the first level packets to form second level packet payloads;attaching to the second level packet, payloads headers containing as destination addresses, addresses of at least one intermediate router connecting the originating terminal to the destination 20 to form second level packets;sending the second level packets to the at least one intermediate router;at the at least one intermediate router, decrypting at least one of the second level payloads and determining from the first level headers the destination address, forming new packets containing at least the first level packet payloads, and attaching headers thereto containing the 25 destination address, whereby a true destination of the data stream is concealed behind a layer of encryption for at least a portion of its travel over the network. 58. The method of claim 57, wherein the step of attaching includes determining the at least one intermediate router by randomly selecting from a group of intermediate routers. CA 02349520 2001-04-27 WO 00/27090 PCT/US99/25323 59. The method of claim 57, wherein the step of determining from the first level headers the destination address includes converting the data representing the network destination address with the network destination address by means of correlation data stored on the intermediate router. 5 60. The method of claim 57, further comprising the step of including in one of the First and second layer headers, an indicator of a number of hops to be made by the first level packet before arriving at the network destination, the at least one intermediate router decrementing the indicator of a number of hops and sending the first level packet to another intermediate router responsively to a value of the indicator of a number of hops. 10 61. A method of routing packets on a packet network, comprising the steps of: block-encrypting, with a session key, message data to form payloads;dividing an encrypted block resulting from the block-encrypting into at least two data payloads such that interleaving portions of data resulting from the block-encrypting step are among the at least two data payloads;15 encrypting, with a link key, each of the at least two data payloads, together with destination data identifying a final destination for the packets;combining, with a first payload resulting from the last step of encrypting, a first hop address indicating a first intermediate destination address and transmitting a first packet resulting thereby to the first intermediate destination address;20 combining, with a second payload resulting from the last step of encrypting, a second hop address indicating a second intermediate destination address and transmitting a second packet resulting thereby to the second intermediate destination address. 62. The method of claim 61, further comprising the steps of: combining, in the first packet, a first hop counter;25 at a terminal coinciding with the first intermediate destination address, determining, responsively to the first hop counter, to send the first packet to the final destination address;and at the terminal coinciding with the first intermediate destination address, decrypting with the link key the first payload to expose the final destination address and sending the first packet CA 02349520 2001-04-27 WO 00/27090 PCT/ÜS99/25323 to the final destination address, responsively to the step of determining. 63. The method of claim 61, further comprising the steps of: combining, in the second packet, a second hop counter;at a terminal coinciding with the second intermediate destination address, determining, 5 responsively to the second hop counter, to send the first packet to the final destination address;at the terminal coinciding with the second intermediate destination address, decrypting with the link key the second payload to expose the final destination address and sending the second packet to the final destination address, responsively to the last step of determining.