Secure prefix authorization with untrusted mapping services
Abstract
The first router (403a) associated with the first network node (410a) sends a first mapping lookup to the mapping service (405), the first mapping lookup including the specific device identification associated with the second network node (410b) The mapping service maintains multiple mappings that associate device identifiers with device locations. The first router (403a) receives a mapping response from the second router (402a) associated with the second network node (410b), the mapping response including a specific device location corresponding to the specific device identifier of the second network node (410b) . The first router (403a) establishes a secure session with the second router (402a), and based on the secure session, determines whether the second router is authorized to answer the specific device identifier associated with the second network node (410b).
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
16 claims: 1 independent, 15 dependent
- 11· 一种数据交换方法,包括: 在与第一网络节点相关联的第一路由器处: 将第一映射查找发送到映射服务,其中,所述第一映射查找包括与第二网络节点相关 联的特定设备标识符,所述映射服务维护将设备标识符与设备位置相关联的多个映射; 从与所述第二网络节点相关联的第二路由器接收映射响应,其中,所述映射响应包括 对应于所述第二网络节点的所述特定设备标识符的特定设备位置; 在所述第一路由器与所述第二路由器之间建立安全会话; 基于所述安全会话确定所述第二路由器是否被授权应答包括与所述第二网络节点相 关联的所述特定设备标识符的所述第一映射查找。
- 2如权利要求1所述的数据交换方法,其中,确定所述第二路由器是否被授权应答所述 特定设备标识符包括:通过所述安全会话接收证书链,并且验证所述链包括受信任的根证 书。
- 3如权利要求1所述的数据交换方法,其中,确定所述第二路由器是否被授权应答所述 特定设备标识符包括: 通过所述安全会话接收与所述设备标识符相关联的地址前缀、和所述第二路由器的信 任证书,并且指示来自证书授权的发布; 验证所述地址前缀被包括在所述信任证书中。
- 4如权利要求1所述的数据交换方法,进一步包括: 确定所述第二路由器未被授权应答所述特定设备标识符,并且响应于此使包括所述第 二路由器的先前存储的本地映射无效。
- 5如权利要求1所述的数据交换方法,进一步包括: 确定所述第二路由器被授权应答所述特定设备标识符,并且响应于此在所述第一路由 器处存储将所述特定设备标识符与所述特定设备位置相关联的本地映射。
- 6如权利要求5所述的数据交换方法,进一步包括: 基于存储在所述第一路由器处的所述本地映射,代表所述第一网络节点与所述第二路 由器通信。
- 7如权利要求1所述的数据交换方法,其中,所述方法是响应于从所述第一网络节点接 收一个或多个封包而被执行的,所述封包标识与所述第二网络节点相关联的设备标识符作 为目的地。
- 8如权利要求1所述的数据交换方法,进一步包括: 在所述第一映射查找中包括密钥,并且在与所述第二路由器建立所述安全会话之前, 验证所述映射响应包括所述密钥的预期版本。
- 9如权利要求1所述的数据交换方法,其中,确定所述第二路由器是否被授权应答与所 述第二网络节点相关联的所述特定设备标识符包括: 确定通过所述安全会话从所述第二路由器接收的公钥的有效性。 10 .一种数据交换设备,在与第一网络地址前缀相关联的第一路由器处,该设备包括: 用于将包括特定设备标识符的第一映射查找发送到第二路由器,并且响应于此从所述 第二路由器接收包括所述特定设备标识符的特定映射的第一映射响应的装置; 其中,所述第二路由器维护将设备标识符与设备位置相关联的多个映射; CN 103975552 Β 用于向所述第二路由器发送提供证书的请求,并且响应于此从所述第二路由器接收第 二映射响应的装置; 用于响应于确定所述第二映射响应包括所述证书,从所述第二映射响应提取所述证 书,并且使用所述证书来确定所述第二路由器是否是有权的,并且响应于确定所述第二路 由器是有权的而从所述第一映射响应提取所述特定映射并且将所述特定映射安装在所述 第一路由器处的装置。 11 ·如权利要求10所述的数据交换设备,进一步包括: 用于响应于确定所述第二映射响应不包括所述证书,丢弃在所述第一映射响应中提供 的所述特定映射的装置; 用于响应于确定所述第二映射响应包括所述证书,但是所述第二路由器不是有权的, 丢弃在所述第一映射响应中提供的所述特定映射的装置。
- 1012. 如权利要求10所述的数据交换设备,其中,所述特定映射被本地安装在所述第一路 由器的缓存中。
- 1113. 如权利要求10所述的数据交换设备,其中,所述第二映射响应进一步包括从认证机 构(CA)的根发源的完全信任链。
- 1214. 如权利要求10所述的数据交换设备,其中,所述特定映射包括所述第一路由器的端 口号,DTLS服务器被配置为通过所述端口号来通信。
- 1315. 如权利要求14所述的数据交换设备,其中,所述第二映射响应是来自分布式映射系 统的被转发的映射响应,并且用于所述发送中的网络地址前缀是在所述第一路由器处接收 到的网络地址前缀。
- 1416. 如权利要求15所述的数据交换设备,进一步包括: 用于从所述第二路由器接收基于所述端口号建立DTLS会话的请求,并且响应于此向所 述第二路由器发送至少一个信任证书的装置,其中所述至少一个信任证书包括由所述第一 路由器服务的所述网络地址前缀。
- 1517. 如权利要求16所述的数据交换设备,进一步包括: 用于从所述第二路由器接收一个或多个封包,并且将所述一个或多个封包转发到网络 节点的装置,所述封包标识所述第一网络地址前缀内的网络节点作为所述一个或多个封包 的目的地。
- 1618. 如权利要求17所述的数据交换设备,进一步包括: 用于向所述第二路由器指示在所述第一路由器处支持基于公钥的安全的装置。 CN 103975552 Β
Independent claims16
222 paragraphs, as filed
Technical field of data exchange via certified routers
[0001] The present disclosure relates to a network address mapping system, and more specifically to a security system using the network address mapping system.
Background technique
[0002] The methods described in this section are methods that can be performed, but do not have to be methods that have been conceived or implemented before. Therefore, unless otherwise indicated, any method described in this section should not be considered as prior art simply because it is included in this section.
[0003] Various protocols and standards have been proposed and developed to facilitate communication between users and devices over the Internet. Some methods use the IP address or MAC address of the device to indicate two things: the identity of the device and the location of the device.
[0004] However, in some cases, using IP or MAC addresses to indicate both the identity and location of the device may cause problems. For example, when a mobile device moves from one location to another, the MAC address of the mobile device remains the same while the device location changes. Therefore, using the device MAC address is not sufficient to determine the actual location of the device.
[0005] Generally, software applications rely on the device address as a determinant of both device identity and location. For example, an application that facilitates data communication through a TCP session may rely on the IP address of the device to establish a TCP session. However, relying only on the device IP address prevents TCP-based applications from continuing to execute seamlessly.
[0006] In addition, if a network device starts to use another port to communicate with the Internet, even if the physical location of the device has not changed, the device will receive a new IP address, which will result in maintaining a continuous communication session about the device. problem. Therefore, the use of device addresses to indicate device identity and device location may be inaccurate.
[0007] In addition, even if accurate information about the location of the device is available, obtaining such information is usually vulnerable to security attacks.
Description of the drawings
[0008] The present invention is illustrated in the drawings by way of example rather than limitation, and the same reference numerals in the drawings refer to the same elements, in which:
[0009] FIG. 1 shows an example of a method of using a one-time key to protect a network address mapping system;
[0010] FIG. 2 shows an example of a method of using PKI keys to protect the network address mapping system;
[0011] FIG. 3 shows an example of a method of protecting a network address mapping system;
[0012] FIG. 4 shows an example of a network address mapping system;
[0013] FIG. 5 shows an example of a computer system on which an embodiment of the present invention may be implemented.
Detailed ways
[0014] In the following description, for illustrative purposes, many specific details are set forth to provide a comprehensive understanding of the present invention. However, it is obvious that the present invention can be implemented without these specific details. In other instances, well-known structures and devices are shown in block diagram form to avoid unnecessarily obscuring the present invention.
[0015] The embodiments are described here according to the following outline:
[0016] 1.0 Overview
CN 103975552 Β
[0017] 2.0 Overview of structure and function
[0018] 3.0 Example of a Secure Network Address Mapping System
[0019] 3.1 Using a one-time key to protect the network address mapping system
[0020] 3.2 Using PΚΙ keys to protect the network address mapping system
[0021] 4.0 Implementation Mechanism-Hardware Overview
[0022] 5.0 Extension and Replacement
[0023] 1.0 Overview
[0024] In one embodiment, the process is configured to utilize a certificate-based protocol to protect a distributed mapping system that is not fully trusted. In one embodiment, the identity of the device is separated from the location information of the device. Device identity (referred to as identity in one embodiment) and device location (referred to as location in one embodiment) are divided into two different namespaces, and different network addresses are used for identity and location.
[0025] The function of separating addresses for identity and location provides the following benefits: improved scalability of the routing system, larger location set, and improved multi-homing efficiency for input traffic engineering. The separation of identity and location allows to overcome some of the problems that many Internet applications are experiencing.
[0026] In one embodiment, a method for representing information about the identity and location of a captured device is proposed. In one implementation, the packet sent from the device includes the IP address information of the device and the location information of the device. The IP address information corresponds to the traditional device identification based on the device's IP address, and is directly known to the device. However, location information is determined by routers that are configured to determine the physical location of the device at a specific time, and use and maintain the mapping.
[0027] For example, a user located in a conference room in a specific building uses a mobile device to connect to the network. The router serving the device connection can determine the location of the mobile device at a given moment. When the user and the mobile device move to another conference room in the same building, the router can determine the new location of the mobile device, and can update the location information of the mobile device in a database maintained by the network.
[0028] The router serving the mobile device's access to the network can determine the current location of the mobile device at any specific time. Although the IP address and/or MAC address of the mobile device are unchanged, the change in the location of the mobile device can be tracked by routers in the network.
[0029] In one embodiment, the method is based on the continuity of the session (such as a TCP session) even if the mobile device has changed its location. Therefore, from the viewpoint of an application supporting a TCP session established for a mobile device, even if the mobile device changes location, a continuous TCP session can be maintained. Depending on the device IP address provided by the device and the device location identifier provided by the router, TCP support applications can be executed continuously.
[0030] In one embodiment, the identity of the device is separate from the location of the device. Although the identity can still be determined by the devices
The IP address represents, but the location of the device is determined by the router or server communicating with the device.
[0031] The processing of separating the device identity from the device location provided herein can prevent the failure of applications that rely on accurate information of the device location and will fail if only the IP address of the device is provided as the device identification information.
[0032] Separating the identity information of the device from the location information of the device allows applications that rely on the identity information of the device to continue to be bound to the identity information. Therefore, when the mobile device moves to another location, another router detects and updates the location information of the device, but the identity information of the device does not need to be updated. This improves session continuity regardless of the mobility of the device. The association between the device identity information and the device location information can be stored in a map maintained by the mapping system.
[0033] In one embodiment, a one-time key may be used to protect access to the distributed mapping system. The one-time key can be applied to a mapping system that is considered safe. One-time keys can be used to
CN 103975552 Β
The location information is protected before it is provided to the requester.
[0034] In one embodiment, a public key infrastructure (PKI)-based security process is used to protect the mapping system, thereby protecting the mapping system from security vulnerabilities attacks against entities existing in the mapping system.
[0035] PKI-based methods can be used to authenticate entities of the mapping system. For example, a PKI-based method may allow verification of whether the location information obtained for a specific identity is provided by an entity that is authorized to communicate with the mapping system and is authorized to provide location information to other entities.
[0036] 2.0 Structure and Function Overview
[0037] FIG. 4 shows an example of a network address mapping system 400. In one embodiment, the mapping system 400 includes a station 452 (site X), a mapping system 405, and a station 454 (site Y). In a practical embodiment, additional stations 452 and 454 and additional alternative topologies 405 may exist in the mapping system 400.
[0038] In one embodiment, the site 452 includes one or more node A 410a, one or more ingress tunnel routers 402a, and one or more egress tunnel routers 403a. The node A 410a may communicate with one or more domain name system (DNS) 412, and the node 410a may request and obtain one or more Internet Protocol (IP) addresses from the domain name system. In addition, the node 410a can communicate with any other node in the site 452 and any node in the site 454 through the connection 411.
[0039] One or more ingress tunnel routers 402a are responsible for interacting with the mapping system 405, and one or more egress tunnel routers 403a are responsible for receiving information from the mapping system 405.
[0040] In one embodiment, the site 454 includes one or more Node Bs 410b, one or more ingress tunnel routers 402b, and one or more egress tunnel routers 403b. Node B 410b can communicate with any other node in site 454 and any node in site 452 through connection 411.
[0041] One or more ingress tunnel routers 402b are responsible for interacting with the mapping system 405, and one or more egress tunnel routers 403b are responsible for receiving information from the mapping system 405.
[0042] If the node 410a requests to establish a communication connection 411 with the node 410b, the ingress tunnel router 402a establishes a communication connection 411 with the egress tunnel router 403b. However, in one embodiment, in order to obtain the current location information of the node 410b, before the connection 411 is established, the ingress tunnel router 402a establishes a tunnel through the mapping system 405. The tunnel is not known to the nodes 410a and 410b, but the tunnel allows ingress. The tunnel router 402a obtains the current location information of the node 410b.
[0043] In one embodiment, the ingress tunnel router 402a is configured to establish a tunnel between the site 452 and the site 454, where the tunnel includes the mapping system 405.
[0044] In one embodiment, the tunnel between the site 452 and the site 454 through the mapping system 405 is a virtual tunnel, and the existence of the tunnel is not communicated to the devices in the site 452 and the devices in the site 454. Therefore, if, for example, the node 410a communicates with the node 410b, the ingress tunnel router 402a and the egress tunnel router 403b can establish a tunnel through the mapping system 405.
[0045] In one embodiment, the mapping system 405 includes one or more mapping resolvers 404 and one or more mapping servers 406. In some implementations, the mapping system 405 may be a distributed system including various servers communicatively coupled with each other, the servers including one or more mapping resolvers 404, one or more mapping servers 406, and other servers.
[0046] The mapping resolver 404 and the mapping server 406 are responsible for creating and maintaining the mapping between the identity information and location information of the devices existing in the sites 452 and 454.
CN 103975552 Β
[0047] In one embodiment, the mapping resolver 404 receives a request for analyzing the location of the device, processes the request to obtain the requested location information, and returns the location information of the device to the requester.
[0048] The mapping resolver 404 resolves the problem of the location information of the device whose device ID is known. For example, after providing the IP address of a specific device, the mapping server 404 of the mapping system 405 can determine the current location information of the specific device.
In one embodiment, the mapping server 406 maintains a mapping between the identification information and location information of the devices in the network, and is configured to provide this information when the location information of the devices is requested.
[0050] In one embodiment, the mapping resolver 404 and the mapping server 406 cooperate with each other to provide a response to a request for location information of a network device. The processing of receiving requests, processing requests, and obtaining responses to requests can be analogous to processing performed by devices such as Domain Name System (DNS), except that DNS processes requests for IP addresses while mapping resolver 404 and mapping server 406 process location information Request.
[0051] In one embodiment, the network address mapping system 400 includes multiple tunnel routers (such as two or more ingress tunnel routers 402a, 402b and two or more egress tunnel routers 403a, 403b) or Multiple tunnel routers cooperate. The tunnel router is responsible for establishing a tunnel between routers and encapsulating location information requests and responses.
[0052] In one embodiment, a virtual tunnel is established by the mapping system 405 in the following manner, in which end nodes such as nodes 410a and 410b are not aware of the existence of the tunnel. For example, for the node 410b and the node 410a, the egress tunnel router 403b can establish a tunnel with the ingress tunnel router 402a in the following manner, in which the nodes 410a and 410b are not aware of the existence of the tunnel.
[0053] The implementation of the proposed method can be based on any one of a number of data communication protocols including TCP/IP, where the device can be packaged (as in IP) or segmented (as over TCP) in the data communication protocol Exchange data in the form of. Therefore, in the following description, a reference to a data packet can also be understood as a reference to a data segment containing the packet.
[0054] In one embodiment, end nodes such as node A 410a and node B 410b do not know the difference between the identities and IP addresses that can be assigned to each corresponding node. For example, when generating a data packet or data segment destined for node A 410a, node B 410b can send node B 410b without knowing whether the included IP address is indeed the IP address assigned to node 410a or just the identity assigned to node 410a. The IP address of 410a is included in the packet/fragment header.
[0055] The distinction between identity and IP address is not directly used by nodes; however, tunnel routers such as egress tunnel router 403a/b and ingress tunnel router 402a/b use different values.
[0056] In one embodiment, the tunnel router is responsible for determining whether the received data packet includes the identity information of the endpoint node or the IP address of the endpoint node. For example, when receiving a data packet from the endpoint 410b and destined for the endpoint node 410a, the egress tunnel router 403b determines whether the data packet includes the identity of the node 410a or the IP address of the node 410a.
[0057] If the received packet includes the endpoint identifier of the destination node, the tunnel router transmits the endpoint identifier of the destination node to the mapping resolver 404 to determine the location of the destination node. Once the mapping resolver 404 (in cooperation with the mapping server 406) determines the location of the destination node, the location information of the destination node is transmitted to the tunnel router. The tunnel router encapsulates the received packet to include the location information of the destination node, and forwards the encapsulated packet to the destination.
[0058] However, if the received packet includes the IP address of the destination node, the tunnel router transmits the received packet to the destination according to the IP address that has been included in the received packet.
[0059] Separating identity from location enables endpoint mobility. For example, the mobile node 410b may be statically provided with identities for all of its connections. The packet with the header from the identity namespace can be encapsulated in the outer header from the location space by the mobile node 410b, thereby establishing a tunnel to the destination site. Packet is based on the outer layer
CN 103975552 Β
The header is routed to the destination site. Once the packet reaches the destination site, the outer header of the packet is removed and the packet is delivered to the end host or application.
[0060] In one embodiment, the mapping system stores the association between identity and location. In one embodiment, the map is designed to withstand the manipulation of the map performed by the opponent. The mapping is protected from situations where an adversary can redirect traffic and disrupt the reliability and security of the network.
[0061] In one embodiment, the identity-location mapping is protected, especially if the mapping is dynamically updated (this is the case for mobile devices). For example, the location associated with the identity of the mobile node changes when the mobile node moves from one location to another, and therefore the mapping between the identity and the location is frequently updated to reflect the current location of the mobile device. It may be difficult to distinguish the legal update of the location information performed by the mapping system from the illegal update of the location information performed by the opponent.
[0062] Security measures for the mapping system can be provided in a variety of ways. In one embodiment, map registration and protection map-response messages are used to implement security measures.
[0063] In one embodiment, in order to support the use of node identifiers by the tunnel router, nodes in the network need to register with the mapping system. Initially, a process similar to assigning an IP address to a device can be used to assign an identity to a node or device. For example, dynamic host configuration protocol (DHCP) can be used to assign identities. DHCP allows network devices to automatically obtain valid IP addresses from the server. DHCP can also allow nodes or devices to automatically obtain valid identities from the server. In fact, DHCP can be configured in a way that does not distinguish between IP address and identity.
[0064] In order to register, the node provides node identity information and node location information to the mapping system. For example, the mobile device 410b may register its own identity and location to the associated mapping server 406 through a mapping registration message. The mapping server 406 may be an authoritative entity for identity, and may be configured to be able to verify the authorization, authenticity, and integrity of the registration.
[0065] For example, the exit node 403b may initiate the registration process with the mapping system by sending a mapping registration message 409 to the mapping server 406, and may provide its identity and location information in the message, and may request the mapping server 406 to register the identity and location information. In the example depicted in FIG. 4, the mapping registration message 409 includes identity information 1.1.0.0/16 and location information as a prefix.
[0066] After receiving the mapping registration message 409, the mapping server 406 registers the received identity and location information in a database or any other data storage structure on the server.
[0067] In one embodiment, a corresponding node (correspondent node, CN) performs a DNS lookup to find out the identity of the node, and uses the identity to start sending packets to the node.
[0068] If the router 402a does not have a mapping entry for the identity in its cache, the router 402a can perform a lookup in the mapping system. The router 402a can complete the search by sending the mapping lookup message 401 to the mapping resolver 404. In the example depicted in FIG. 4, the mapping lookup message 401 includes the identity prefix "1.1.0.10" and "n" corresponding to a random number, which will be described below.
[0069] The mapping lookup message 401 including the identity prefix and the random number is delivered to the mapping server 406 through the mapping system 405.
[0070] In one embodiment, the mapping server 406 receives the mapping lookup message 407 including the identity, and parses the location information of the identity.
[0071] In one embodiment, in order to resolve the location information of the provided identity, the mapping server 406 obtains the location information associated with the provided identity, includes the location information in the mapping lookup 408, and adds the mapping lookup message
CN 103975552 Β
408 is sent to the egress tunnel router 403b.
[0072] After identifying the location information associated with the identity, the mapping server 406 transmits the mapping lookup 408 to the egress tunnel router 403b. As described below, the mapping lookup message 408 may include a hash of a random number (represented as n=h(n)). In addition, the mapping lookup message 408 may include encrypted information (denoted as HMAC-1). The following describes the process of generating HMAC-1.
[0073] In one embodiment, after receiving the mapping lookup message 408, the egress tunnel router 403b sends the mapping lookup message 408 as a mapping response message 411a to the ingress tunnel router 402a to provide location information corresponding to a specific identity.
[0074] Alternatively, after receiving the mapping search message 408, the egress tunnel router 403b encrypts the content of the message before sending the message as a mapping response to the ingress tunnel router 402a. For example, using a random number hash n'= h(n), the egress tunnel router can encrypt the location information included in the message, generate HMAC-2 (described below), and send a random number including the hash (n' = h (N)) HMAC-1 generated by the mapping server 406, and HMAC-2 mapping response message 411co generated by the egress tunnel router 403b
[0075] In an embodiment, the mapping response message 411c further includes PKI-ID and port identifier<sub>O</sub>The PKI-ID is a public key infrastructure (PKI) identifier indicating the PKI used to authenticate the egress tunnel router 403b. For example, PΚΙ-ID may indicate the certification authority (CA) that issued the key.
[0076] The port identifier is an identifier of a port on which the egress tunnel router 403b can receive a query about the certificate provided to the egress tunnel router. For example, if after receiving the mapping response message 411c, the ingress tunnel router 402a wants to verify whether the egress tunnel router 403b is authorized to communicate with the mapping system, then the ingress tunnel router 402a can send a message to the port identified by the mapping response message 41lc. The router port of the exit tunnel indicated by the symbol sends the corresponding query. Refer to Figure 2 to provide details on verifying the authorization of the egress tunnel router.
[0077] In one embodiment, once the ingress tunnel router 402a determines that the content of the received message is compromised and the message is received from an authorized entity, the ingress tunnel router 402a starts to encapsulate the data packet in the data plane And transmit the data packet to the intended destination.
[0078] In one embodiment, the mapping response 411 (a, b, or c) includes routing location information, and optionally includes weights and priorities associated with a particular mapping.
[0079] If the mobile device (eg, node 410b) changes its location, the mobile device can generate another mapping registration message 409 in which the mobile device can provide its identity and updated location information. The mapping registration message 409 is received by the mapping server 406. The mapping server 406 updates the mapping information of the identity and updates the location information associated with the identity.
[0080] Once the location information associated with the specific identity is registered or updated in the mapping system, the location information is used in the encapsulation of the data packet to the site that includes the node identified by the specific identity.
[0081] In one embodiment, the forwarding of data packets is performed in the data plane of the router, and the encapsulation of data packets is performed in the control plane of the router. In one embodiment, processing in the control plane needs to be protected.
[0082] 3.0 Example of a Secure Network Address Mapping System
[0083] In one embodiment, the security processing for the mapping system has the effect of providing authentication of the members involved (such as the mapping resolver 404, the mapping server 406, the routers 402a/b and 403a/b), and Ensure that the members involved are authorized to provide mapping information and services. For example, it may be desirable to protect the mapping system from counterfeiters who want to intercept information about the mapping system and interfere with the functions of the mapping system. It may also be desirable to prevent unauthorized entities from manipulating the mapping
CN 103975552 Β
Radio system, information stored by the mapping server, and updated information provided to the mapping server.
[0084] In some cases, it can be assumed that the mapping system is safe and functional, and therefore the mapping lookup message is delivered to its intended destination. Alternatively, it can be assumed that the packet is transmitted to a location other than the intended destination.
[0085] In addition, the security method herein may assume that man-in-the-middle attacks cannot be performed on the mapping system through the GRE tunnel, and the information (including random numbers) included in the mapping lookup message cannot be read by a third-party entity. When the tunnel is secure or if GRE and IPSec are used to deploy the tunnel, this assumption is reasonable and therefore provides enhanced confidentiality to the mapping system.
[0086] In one embodiment, additional security mechanisms are used to prevent attacks on the mapping system from entities located outside the mapping system and from man-in-the-middle entities that may be located within the mapping system.
[0087] In one embodiment, the mapping system is implemented for IP prefixes and not necessarily only for individual IP addresses. Implementing a mapping system to handle IP prefixes can make the mapping system robust and efficient. For example, if the identity is expressed as the prefix 1.1.0.0/32, the general server will send the largest IP prefix corresponding to 1.1.0.0/32. Therefore, if the next request is for the identity prefix designated as 1.1.0.0/32, the tunnel router can rely on the information that has been received for the prefix 1.1.0.0/32.
[0088] In one embodiment, the mapping system utilizes additional parameters associated with IP addresses and IP prefixes. For example, the mapping system can utilize specific values of survival time parameters, freshness indicators, and other parameters. For example, for a mobile device, the value of the time-to-live parameter may be relatively small because the mobile device is expected to change its location frequently.
[0089] In one embodiment, the security mechanism is designed to prevent attacks where the tunnel router requests an identity that it does not possess by providing the location of the identity in the mapping response message.
[0090] For example, if an intruder (attacker) intercepts the mapping registration message, changes the information included in the mapping registration message, and sends the changed information to the mapping system, the mapping system can receive two instructions indicating a specific device. Two or more mapping registration messages in two or more different locations. The information stored in the database of the mapping system will be established by incoherent information.
[0091] According to another example, if an intruder intercepts the mapping response message, changes the information included in the mapping response message, and sends the changed message to the mapping system, the intruder may be able to redirect the data traffic to his Equipment, which adversely affects the security of data communication.
[0092] According to other examples, messages sent from various sources (including intruders) to the mapping system can place high demands on bandwidth in the network. Sending high-volume messages may delay communication within the network, thereby adversely affecting the efficiency of the mapping system.
[0093] In one embodiment, a one-time key method and a PKI key method can be used to combat various attacks on the mapping system. Each method is described separately below.
[0094] 3.1 Using a one-time key to protect the network address mapping system
[0095] In one embodiment, it is assumed that the mapping system itself is trusted, but the nodes, devices, and other entities communicating with the mapping system are not trusted.
[0096] One aspect of the security architecture is to provide a reasonable level of security without adding too much complexity to the mapping system.
[0097] In one embodiment, the protection of the network address mapping system is based on a one-time key method that implements random numbers. The random number is a random number generated by a node or tunnel router that initiates communication with the mapping system after receiving one or more packets destined for a specific destination node.
CN 103975552 Β
[0098] In one embodiment, it is assumed that the connection between the ingress tunnel router and the mapping server is trustworthy and secure, and therefore the random number can be safely transmitted in the message sent from the ingress tunnel router to the mapping server. Alternatively, if the connection between the ingress tunnel router and the mapping server is not trustworthy, a shared key known only by the ingress tunnel router and the mapping server can be used to encrypt the random number.
[009] However, once the mapping server receives a message with a random number, the mapping server must protect the message before transmitting the message to the egress tunnel router. Because the connection between the mapping server and the egress tunnel router is assumed to be untrustworthy, the mapping server uses random numbers to encrypt the content in the message and sends the message with the encrypted payload to the egress tunnel router. As the encryption key, the mapping server can use, for example, a hash of a random number, as will be described below. Therefore, the random number is called a one-time key.
[0100] The random number itself (or the hash of the random number) can be used to encrypt the content of the message received at the mapping server before it is sent from the mapping server to the egress tunnel router. Since the exit node does not know the one-time key (random number), the exit node cannot decrypt the content encrypted with the random number. Therefore, if the egress tunnel router is indeed untrustworthy, the egress node cannot understand the content of the intercepted message.
[0101] FIG. 1 shows an example of a method of protecting the network address mapping system 100 using a one-time key. In block 101, the first router in the first prefix receives one or more packets destined for node B. The term "first router" is used to indicate any one of the tunnel router or the end node. For example, the first router may be an ingress tunnel router 402a/b as depicted in FIG. 4, or an endpoint node 410a/b (such as a mobile device) as depicted in FIG. 4 as well.
[0102] After receiving one or more packets destined for Node B, the first router generates a random number. In one embodiment, the random number is a one-time key used to protect messages sent to and received from the mapping system.
[0103] The random number may be a randomly generated number. The random number can be regenerated every time the tunnel router receives a packet destined for a new destination. Alternatively, the random number can be generated once in each communication session, rejection period, or for each specific network device. Other methods for timing random number generation can also be implemented.
[0104] In one embodiment, the random number is associated with the identity and stored locally, where the identity mapping lookup is generated. The random number can be stored in a storage device associated with the tunnel router that generated the mapping lookup message or in any storage device with which the tunnel router can communicate.
[0105] In block 102, the first router sends the first mapping lookup message to the distributed mapping service. The first mapping lookup includes the device identifier (such as identity) and random number as described above. In one embodiment, the randomly generated random number (n) included in the message is transmitted in a clear (unencrypted) form.
[0106] Alternatively, the random number may be encrypted. The use of encrypted random numbers protects the exchange of messages from attacks described as man-in-the-middle attacks. If the mapping server and the ingress tunnel router belong to the same domain, a shared key can be used to encrypt the random number. If the mapping server and the ingress tunnel router do not belong to the same domain (for example, when the ingress tunnel router is an access device from an external network and dynamically gains access to the mapping resolver), other methods of protecting the path can be implemented.
[0107] In one embodiment, the key used to encrypt the random number is shared between the first router such as the ingress tunnel router and the mapping server. The key can be used to protect the integrity of the messages exchanged between the first router and the mapping server.
[0108] In one embodiment, the ingress tunnel router does not use a random number as an encryption key. The random number is transported to the mapping server in the message, as the information used by the mapping server as a one-time key, to encrypt the content of the message before it is transmitted to the egress tunnel router. The mapping server uses a random number as an encryption key to protect the mapping
CN 103975552 Β
The content of the message sent by the possibly insecure connection between the server and the egress tunnel router.
[0109] In one embodiment, after receiving the mapping lookup message with the encrypted random number, the mapping parser decrypts the random number and forwards the mapping lookup message to the mapping system as a decrypted message. Specifically, the mapping lookup message is sent to the mapping server.
[0110] In one embodiment, a random number (n) can be used as a key to encrypt the identity prefix and generate HMAC. Therefore, the random number (η) represents the one-time key shared between the ingress tunnel router and the mapping system including both the mapping resolver and the mapping server.
[0111] The random number is called a one-time key because it is used only once, and it is only used to obtain the location information of a specific identity. Whenever a new mapping lookup message is generated, a new random number can be generated and shared by the ingress tunnel router and the mapping system.
[0112] However, the random number (shared secret) is unknown to the egress tunnel router and is not disclosed to it, because it is assumed that the egress tunnel router is an untrusted entity. For example, if an attacker gains access to the egress tunnel router, sharing the key with the egress tunnel router may result in damage to the security in the mapping system. In addition, if the attacker intercepts the message and determines that there is a hash value in the message, sharing the key with the egress tunnel router may help the attacker reverse the hashing process and determine the original value of the random number (n). Therefore, the design does not share the key with the egress tunnel to protect the message from tampering by possible attackers who gain access to the egress tunnel router.
[0113] In one embodiment, the message sent to the egress tunnel router includes a hash of the random number. Use random numbers to encrypt the identity prefix and generate HMAC. Neither the hash of the random number nor the HMAC can be understood by the egress tunnel router.
[0114] In one embodiment, before the egress tunnel router sends the message to the ingress tunnel router, the egress tunnel router uses the hash of the random number as a key to further encrypt part of the message. The random number hash included in the message received by the egress tunnel router from the mapping server can be used as an additional key. Figure 3 depicts an example where the egress tunnel router uses the hashed random number as an additional key.
[0115] FIG. 3 shows an example of a method 300 for protecting a network address mapping system.
[0116] In block 301, the egress tunnel router uses the hashed random number to encrypt the mapping to find the content of the message. In one embodiment, the egress tunnel router uses the hashed random number to protect the content of the message before the message is transmitted from the egress tunnel router to the ingress tunnel router. The hashed random number is used as a key to protect the connection between the egress tunnel router and the ingress tunnel router.
[0117] The random number itself is used as a key to protect the location information transmitted by the mapping server to the egress tunnel router, and the hashed random number is used as another key to protect the communication between the egress tunnel router and the ingress tunnel router. connection.
[0118] In one embodiment, a part of the message encrypted by the egress tunnel router using the hashed random number includes the identity information and/or location information obtained by the mapping server from the mapping for the specific identity. The location information may have been encrypted by the mapping server using random numbers. The egress tunnel router may use the hashed random number to encrypt the encrypted router location information included in the message received from the mapping server.
[0119] Since the egress tunnel router does not know the value of the original random number, the egress tunnel router cannot decrypt the information encrypted by the mapping system. However, the egress tunnel router can use the hashed random number to encrypt the location information that has been encrypted once. The double-encrypted information generated by the egress tunnel router by encrypting the information that has been encrypted once is called HMAC-2 in this article<sub>O</sub>
[0120] In block 302, the egress tunnel router generates a hash of the hashed random number. The exit tunnel generates a hash of the hashed random number, thereby generating a hash of the hashed random number. As mentioned above, the first hash of the random number can be
Radio server generation. After receiving the mapping lookup message from the mapping server, the egress tunnel router can hash the hashed random number again. The hash of the hashed random number is referred to herein as n" = h (h (n)) ο
[0121] In block 303, the egress tunnel router generates a mapping response message. The mapping response can include the identity information (described above), the hash of the hashed random number (n"=h(h(n))), the location information (HMAC-1) encrypted by the mapping server using the random number encryption once. ), and the double-encrypted location information (HMAC-2) generated by the egress tunnel router by encrypting the encrypted location information once. The message can be formatted as the mapping response message 411c depicted in FIG. 4<sub>o </sub>[0122] In block 304, the egress tunnel router sends a mapping response message to the ingress tunnel router. In one embodiment, the egress tunnel router sends a hash (n" = h (h (n))) that includes identity information, a random number of the hash, and the location information (HMAC) encrypted by the mapping server using a random number. -1), and the double-encrypted location information (HMAC-2) message generated by the egress tunnel router by encrypting the encrypted location information once. The mapping response message 411c is depicted in FIG. 4<sub>o</sub>
[0123] Referring again to FIG. 1, in block 103, the first router (ingress tunnel router) receives a mapping response message from the second router (egress tunnel router).
[0124] In one embodiment, the mapping response includes the above-described double-hash random number (n"=h(h(n))), the location information (HMAC-1) that is encrypted once, and the location of the double-encryption Information (HMAC-2), depicted in Figure 4 as the mapping response 411co
[0125] In block 104, the first router determines whether the random number is valid.
[0126] In response to sending a mapping lookup message with an identity and a random number, the tunnel router receives a mapping response message. Based on the content of the mapping response message, the tunnel router determines whether the mapping response message is legal. For example, after receiving a mapping response message in response to sending a mapping lookup message with a specific identity and a specific random number, the tunnel router generates a hash of the random number stored at the entrance tunnel router, and compares the random number of the generated hash Whether the number matches the random number of the hash included in the mapping response message. If the random numbers match, the tunnel router determines that the mapping lookup message and the mapping response message are not intercepted by the enemy, and the communication is secure.
[0127] Since the random number is shared between the ingress tunnel router and the mapping system, the ingress tunnel router can retrieve its own copy of the random number, generate a hash of the random number, and compare the hash of the random number with the received one. The mapping response is compared with the random number of the extracted hash.
[0128] In one embodiment, the method of using random numbers embedded in the mapping lookup and mapping response allows determining whether the received mapping response message is an unsolicited mapping response message. If the random number embedded in the mapping response message does not match the random number used in the mapping lookup for the same identity, it is most likely that the mapping response message is unsolicited and may have been generated by an intruder.
[0129] In addition, using random numbers, the ingress tunnel router can decrypt the encrypted location information (HMAC-1), and using the hashed random number, the ingress tunnel router can perform double encryption on the location information (HMAC-2). Decrypted.
[0130] If the random number is valid, the process proceeds to step 106; otherwise, the process proceeds to step 105, where the first router destroys the mapping (if this is necessary).
[0131] In block 106, the first router establishes a datagram transport layer security (DTLS) session with the second router, and sends the second mapping lookup directly to the second router. The DTLS protocol provides communication privacy for datagram protocols such as UDP. DTLS allows datagram-based applications to communicate in a way that is designed to prevent eavesdropping, tampering, or message forgery. The establishment of a DTLS session is described in Figure 2.
[0132] GRE and IPsec can also be used to protect the communication of data packets from nodes and tunnel routers.
CN 103975552 Β
[0133] In block 107, the first router determines whether the second router is authorized to communicate with the mapping system. The first router may be an ingress tunnel router, and the second router may be an egress tunnel router. One of the methods for determining whether the second router is authorized to communicate with the mapping system is described in FIG. 2 below.
[0134] Referring again to FIG. 1, if the second router is authorized to communicate with the mapping system, the process proceeds to step 109; otherwise, the process proceeds to step 108, in which the first router terminates the previously established secure session and Destroy any mapping associated with the second router.
[0135] In block 109, the first router locally installs the mapping and sends one or more data packets to node B. The mapping may include a mapping between an identity and a location, thereby indicating a device identifier associated with the location of the device.
[0136] Using a random number allows to confirm whether the received mapping response message matches the previously sent mapping lookup message. Most likely, the intruder (attacker) does not know the random number in the message and does not recognize that the random number in the message is needed. Therefore, even if he generates an illegal mapping response message, the message will not include a valid random number. A message without a valid random number can be easily identified as illegal by the mapping system.
[0137] For example, an intruder (attacker) intercepts a mapping lookup message with a specific identity, and extracts the identity from the intercepted mapping lookup message; however, he does not recognize the random number in the message. The intruder generates a mapping response message, associates location information that is different from the actual location information of the device identified by a specific identity, and propagates the generated mapping response message with incorrect device location information. Once such a mapping response message is received by the tunnel router, the tunnel router analyzes the content of the message, determines that a valid random number is missing in the message, and ignores the message. Therefore, the use of random numbers provides a security mechanism for exchanging information using mapping lookup and mapping response messages. However, in some applications, stronger security mechanisms may be required.
[0138] In one embodiment, security measures based on random numbers are strengthened by allowing additional mechanisms that assume that the mapping system cannot be trusted.
[0139] 3.2 Using PΚΙ Key to Protect Network Address Mapping System
[0140] In this section, it is assumed that the mapping system is an untrusted system. For example, when the mapping system is outsourced, maintained by different organizations, or maintained in different countries, the integrity of the system cannot be trusted. Maintaining the integrity of the mapping system may require the implementation of specific security mechanisms.
[0141] FIG. 2 shows an example of a method for protecting the network address mapping system 200 using a PKI key.
[0142] In one embodiment, using the PKI key to protect the mapping system 200 includes associating the certificate with the egress tunnel router.
[0143] In some cases, the router may not trust the mapping system, the destination mapping server, or the egress tunnel router (which may be part of the mapping system). For these situations, the router can try to verify the certificate of the mapping system device to determine whether the device is authorized to cooperate with the mapping system.
[0144] In one embodiment, the one-time key security infrastructure is modified and extended to incorporate a PKI that provides strong authentication of the identity prefix owned by the router.
[0145] In one embodiment, the ingress tunnel router may request the egress tunnel router to prove that the egress tunnel router is indeed authorized to communicate messages to and from the mapping system. For example, the ingress tunnel router can request the egress tunnel router to provide its certificate to prove the authorization of the egress tunnel router.
[0146] In one embodiment, when a router requests location information of a specific identity, the router transmits a mapping lookup message to the mapping system, and receives a mapping response message in response.
[0147] In block 201, a server such as an ingress tunnel router receives from an egress tunnel router including a specific identity
CN 103975552 Β
The mapping response message of the location information.
[0148] In one embodiment, the mapping response message contains a field that indicates to the router whether to support PKI-based security.
[0149] If the router supports PK1-based security, the router can directly transmit another mapping lookup message to the recently learned router location through a datagram transport layer security (DTLS) session to request a certificate from the router. The mapping lookup message 411b depicted in FIG. 4 includes the identity and an indication that the server requests a certificate from the router.
[0150] In response to receiving the mapping lookup message, the router may include the certificate into the DTLS protocol datagram along with the full trust chain issued from the root of the certification authority (CA), and respond with a mapping response message.
[0151] In block 202, in response to sending another mapping lookup message to the egress tunnel router, the ingress tunnel router receives a message with a certificate.
[0152] In block 202, the ingress tunnel router extracts the certificate from the message and determines whether the egress tunnel router is authorized. For example, the router can verify the certificate list and the identity prefix chain included in the certificate. In addition, the router can verify whether the identity prefix included in the message is a valid router certificate.
[0153] In block 204, if it is determined that the egress tunnel router is authorized to communicate with the mapping system, the process proceeds to step 205, where in step 205 the router may install the mapping included in the previously received mapping response message locally. In the cache. However, if it is determined that the egress tunnel router is not authorized, the process proceeds to step 206, where the ingress tunnel router does not install the mapping, and optionally destroys the mapping.
[0154] In one embodiment, the PKI-based security method allows verification of the authenticity of the components of the mapping system. For example, if the egress tunnel router and the ingress tunnel router are located in different countries and the ingress tunnel router cannot be sure whether the egress tunnel router is trustworthy, the presented PKI-based method allows verifying whether the egress tunnel router is indeed trustworthy. Only if the egress tunnel router can present a valid certificate (and a full trust chain issued from the root of the certification authority (CA)), can the egress tunnel router be considered a trusted entity.
[0155] In one embodiment, the certificate is distributed to each router in advance and the trust chain is established when the certificate is distributed. For example, certificates can be distributed using DTLS, and can involve the exchange of several messages between entities in order to provide the entities with corresponding certificates.
[0156] In one embodiment, the mapping server is used as an egress tunnel router. The mapping server and the egress tunnel router can be the same device. Therefore, the certificate can also be provided to the mapping server in advance.
[0157] 4.0 Implementation Mechanism-Hardware Overview
[0158] According to one embodiment, the techniques described herein are implemented by one or more dedicated computing devices. Dedicated computing devices may be hardwired to perform these technologies, or may include digital electronic devices such as one or more application specific integrated circuits (ASIC) or field programmable gate arrays (FPGA) that are permanently programmed to perform these technologies, or may It includes one or more general-purpose hardware processors that are programmed to execute these techniques according to program instructions in firmware, memory, other storage devices, or a combination. These dedicated computing devices can also combine custom hard-wired logic, ASIC or FPGA with custom programming to implement these technologies. The dedicated computing device may be a desktop computer system, a portable computer system, a handheld device, a networked device, or any other device that incorporates hard-wired and/or program logic to implement these technologies.
[0159] For example, FIG. 5 is a block diagram showing a computer system 500 on which an embodiment of the present invention may be implemented. The computer system 500 includes a bus 502 or other communication mechanisms for transmitting information, and a hardware processor 504 coupled with the bus 502 for processing information. The hardware processor 504 may be, for example, a general-purpose microprocessor.
[0160] The computer system 500 also includes a bus 502 coupled to store information and instructions to be executed by the processor 504
CN 103975552 Β
The main memory 506, such as random access memory (RAM) or other dynamic storage devices. The main memory 506 may also be used to store temporary variables or other intermediate information during the execution of instructions executed by the processor 504. These instructions, when stored in a non-transitory storage medium accessible to the processor 504, make the computer system 500 a dedicated machine customized to perform the operations specified in the instructions.
[0161] The computer system 500 further includes a read-only memory (ROM) 508 or other static storage device coupled to the bus 502 for storing static information and instructions for the processor 504. A storage device 510 such as a magnetic disk or an optical disk is provided and coupled to the bus 502 for storing information and instructions.
[0162] The computer system 500 may be coupled to a display 512 (such as a cathode ray tube (CRT)) through the bus 502 for displaying information to a computer user. An input device 514 including alphanumeric and other keys is coupled to the bus 502 for transmitting information and command selections to the processor 504. Another type of user input device is a cursor controller 516, such as a mouse, trackball, or cursor direction keys, for transmitting direction information and command selection to the processor 504 and for controlling cursor movement on the display 512. This input device usually has two degrees of freedom along two axes (a first axis (eg x) and a second axis (eg y)), which allows the device to specify a position in a plane.
[0163] The computer system 500 may use customized hard-wired logic, one or more ASICs or FPGAs, firmware, and/or program logic combined with a computer system to make or program the computer system 500 into a dedicated machine to implement the techniques described herein. According to one embodiment, the techniques herein are executed by the computer system 500 in response to the processor 504 executing one or more sequences of one or more instructions contained in the main memory 506. These instructions can be read into the main memory 506 from another storage medium such as the storage device 510. The execution of the sequence of instructions contained in the main memory 506 causes the processor 504 to perform the processing steps described herein. In alternative embodiments, hard-wired circuits can be used in place of or in combination with software instructions.
[0164] The term "storage medium" as used herein refers to any non-transitory medium that stores data and/or instructions that cause a machine to operate in a specific manner. Such storage media may include non-volatile media and/or volatile media. Non-volatile media includes, for example, optical or magnetic disks, such as storage device 510. Volatile media includes dynamic memory, such as main memory 506. Common forms of storage media include, for example, floppy disks, floppy disks, hard disks, solid-state drives, magnetic tapes, or any other magnetic data storage media> CD-ROM, any other optical data storage media, any physical media with hole patterns, RAM, PROM, and EPROM, FLASH-EPROM, NVRAM, any other memory chip or floppy cassette.
[0165] The storage medium is different from the transmission medium, but can be used in combination with it. Transmission media participates in transferring information between storage media. For example, the transmission medium includes coaxial cables, copper wires, or optical fibers, including wires containing bus 502. Transmission media can also take the form of acoustic or light waves, such as those generated during radio waves or infrared data communications.
[0166] Various forms of media may be involved in carrying one or more sequences of one or more instructions to the processor 504 for execution. For example, the instructions may initially be carried on a magnetic disk or solid-state drive of a remote computer. The remote computer can load instructions into its dynamic memory and use a modem to send the instructions over the telephone line. A modem local to the computer system 500 can receive the data on the telephone line and use an infrared transmitter to convert the data into an infrared signal. The infrared detector can receive the data carried in the infrared signal and an appropriate circuit can place the data on the bus 502. The bus 502 carries data to the main memory 506, from which the processor 504 retrieves and executes instructions. The instructions received by the main memory 506 may optionally be stored on the storage device 510 before or after being executed by the processor 504.
[0167] The computer system 500 also includes a communication interface 518 coupled to the bus 502. The communication interface 518 provides two-way data communication coupled to the network link 520 (the network link 520 is connected to the local network 522). For example, the communication interface 518 may be
CN 103975552 Β
Integrated Services Digital Network (ISDN) card, cable modem, satellite modem, or modem that provides a data communication connection to the corresponding type of telephone line. As another example, communication interface 518 may be a local area network (LAN) card that provides a data communication connection to a compatible LAN. A wireless link can also be implemented. In any of these implementations, the communication interface 518 sends and receives electrical, electromagnetic, or optical signals that carry digital data streams representing various types of information.
[0168] The network link 520 generally provides data communication to other data services through one or more networks. For example, the network link 520 may provide a connection through a local network 522 to a host computer 524 or to a data device operated by an Internet service provider (ISP) 526. ISP 526 in turn provides data communication through a global packet data communication network (now commonly referred to as the "Internet") 528. Both the local network 522 and the Internet 528 use electrical, electromagnetic or optical signals that carry digital data streams. Signals through the network link 520 and through the communication interface 518 carrying digital signals to and from the computer system 500 and signals through various networks are exemplary forms of transmission media.
[0169] The computer system 500 may send messages and receive data (including program codes) through the network, the network link 520, and the communication interface 518. In the Internet example, the server 530 may transmit the requested code for the application program through the Internet 528, the ISP 526, the local network 522, and the communication interface 518.
[0170] The received code may be executed by the processor 504 when it is received and/or stored in the storage device 510, or stored in other non-volatile memory for later execution.
[0171] In the above, the embodiments of the present invention have been described with reference to several specific details that may vary according to the implementation. Therefore, the drawings and drawings are considered to be illustrative rather than restrictive. The only and exclusive indicator of the scope of the invention and what the applicant intends to be the scope of the invention is the literal and equivalent scope of the set of claims generated by this application, in the specific form in which these claims generate including any subsequent corrections .
[0172] 5.0 Extensions and Replacements
[0173] In the above, the embodiments of the present invention have been described with reference to several specific details that may vary according to the implementation. Therefore, the drawings and drawings are considered to be illustrative rather than restrictive.
[0174] Examples include:
[0175] 1. A method executed by the mapping server, the method comprising:
[0176] At the mapping server that maintains multiple mappings associating network device identifiers with network device locations:
[0177] Receive a mapping lookup that includes the first version of the specific network device identifier and key;
[0178] Generate the second version of the key;
[0179] multiple address prefixes are generated, and the router associated with the specific network device identifier has the right to the address prefix;
[0180] sending the second version of the key and the plurality of address prefixes to the router.
[0181] 2. The method of claim 1, wherein generating the plurality of address prefixes comprises applying a hash function to the plurality of network address prefixes, wherein the hash function uses a key as a hash Keywords.
[0182] 3. The method of claim 1, wherein the mapping lookup is issued by the first router when trying to send one or more packets to a network node associated with the specific device identifier.
[0183] 4. The method of claim 2, wherein the network node is associated with a specific address prefix of the plurality of address prefixes served by the router.
[0184] 5. The method of claim 4, further comprising: establishing with the router before the sending
DTLS session, and based on the DTLS session, send the second version of the key and the plurality of
CN 103975552 Β
Address prefix.
[0185] 6. The method of claim 1, further comprising: verifying that the specific device identifier corresponds to a specific device location or address prefix based on the multiple mappings.
[0186] 7. The method of claim 1, further comprising: receiving the mapping lookup from a mapping resolver configured to forward mapping requests from multiple other address prefixes.
[0187] 8. A method executed by a mapping parser, the method comprising:
[0188] receiving a mapping lookup including a specific device identifier and key associated with the second network node from the first router associated with the first network node;
[0189] Forward the mapping lookup to a mapping server that maintains multiple mappings that associate device identifiers with device locations.
[0190] 9. The method of claim 8, further comprising: establishing a secure connection with the first router before receiving the mapping request.
[0191] 10. The method of claim 9, wherein the secure connection is a DTLS connection.
[0192] 11. The method of claim 9, further comprising: determining that the mapping lookup is invalid and sending a negative mapping response to the first router.
[0193] 12. The method of claim 9, wherein the first router and the second router are in different address prefixes.
CN 103975552 Β
9 priority claims, no other members on record
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 13311976 | United States of America | – | |
| 201113311976 | United States of America | A | |
| 201113311976 | United States of America | A | |
| 2012068025 | United States of America | W | |
| 2012068025 | United States of America | W | |
| 13311976 | – | – | – |
| PCTUS2012068025 | – | – | – |
| US201113311976 | – | – | – |
| WO2012US68025 | – | – | – |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Termination of patent right due to non-payment of annual feeCF01 | CF01 | |
| Patent grantGrantedGR01 | GR01 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 103975552
- Publication, DOCDB
- 103975552
- Publication, EPODOC
- CN103975552B
- Application
- 800597083
- Application, DOCDB
- 201280059708
- Application, EPODOC
- CN201280059708
Titles2
- Chinese
- 经由经认证的路由器的数据交换
- English
- Data exchange via certified router
Classification
- CPC, 6
- H04L61/103
- H04L63/0428
- H04W40/20
- H04L63/0823
- H04L61/4588
- H04L61/5084
- IPC, 3
- H04L9 00
- G06F15 16
- H04L9 32