EP1563642B1

Location privacy through ip address space scrambling

Abstract

This record has no abstract on file.

EP1563642B1, drawing sheet 1
Sheet 1 of 14

Term

Term ended

Expired 29 October 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

24 claims: 13 independent, 11 dependent

  1. 1
    A computer-implemented pseudo-prefix-computation method comprising computing a pseudo prefix for use in forming a network address (400) of a host (114) located in a privacy domain (122), the pseudo prefix enabling the network address to provide location privacy to the host, wherein the network address enables one or more first routers (102, 104, 106) route packets to the host based on routing information (206, 208) obtained from the host's address (400), and wherein the network address comprises a privacy-domain portion (206) and at least a first portion associated with the host's address, the privacy domain portion enabling one or more second routers (108, 110, 112) outside the privacy domain to deliver such packets to the privacy domain, but the network address does not disclose to the one or more second routers at least the first portion (208), the first portion comprising at least a part of a routing prefix of one of the one or more first routers; wherein computing the pseudo prefix comprises:obtaining a value comprising the first portion (208) of the routing information;obtaining an encryption key corresponding to a secret decryption key available to each first router but not to the one or more second routers;encrypting the value comprising the first portion under the encryption key to generate the pseudo prefix, wherein the first portion is decryptable by means of the secret decryption key.
  2. 3
    A pseudo-prefix-computation method as recited in any preceding claim, wherein the pseudo-prefix-computation method is performed in the privacy domain.
  3. 4
    A pseudo-prefix-computation method as recited in any preceding claim, wherein the host is one of a plurality of hosts located in the privacy domain.
  4. 5
    A pseudo-prefix-computation method as recited in any preceding claim, wherein the pseudo prefix is specific to the host.
  5. 7
    A pseudo-prefix-computation method as recited in any preceding claim, wherein computing the pseudo prefix comprises logically combining a suffix to be used in the host's address with a shared secret key.
  6. 9
    A pseudo-prefix-computation method as recited in any preceding claim, wherein computing the pseudo prefix comprises logically combining (i) the first portion and (ii) a message authentication code computed over nonce data and over a suffix of the host's address to produce a result.
  7. 11
    A pseudo-prefix-computation method as recited in any preceding claim, wherein the encryption key is obtained as a hash of a suffix to be used in the host's address and of secret information related to the secret decryption key and shared by a plurality of routers of the privacy domain.
  8. 12
    A pseudo-prefix-computation method as recited in any preceding claim, wherein:the pseudo prefix is one of a set of pseudo prefixes each of which is computed using encryption of a value comprising the first portion of the routing information, the first portion being decryptable by each first router from any one of the pseudo prefixes;and the pseudo-prefix-computation method comprises: establishing the set of the pseudo prefixes;selecting a subset of the set of the pseudo prefixes;wherein the host address is formed using a pseudo prefix from the subset.
  9. 16
    A pseudo-prefix-computation method as recited in any one of claims 13 to 15 wherein the host receives both the subset of pseudo prefixes and information about the lifetime of each pseudo prefix.
  10. 17
    A pseudo-prefix-computation method as recited in any one of claims 12 to 16 wherein each pseudo prefix is computed by a process comprising encrypting the first portion and a pseudo prefix index number.
  11. 20
    A routing method for routing a data packet comprising a destination address, the destination address comprising a privacy-domain portion (206) and allowing a pseudo prefix to be obtained from the destination address, the routing method comprising:applying a decryption process with a secret decryption key to a pseudo prefix obtained from the destination address to obtain at least a first portion (208) of routing information;and transmitting the packet based on the first portion, to deliver the packet to a host (114) whose network address is the destination address, wherein the privacy-domain portion (206) enables one or more routers (108, 110, 112) which do not have the secret decryption key to route the packet to a router having the secret decryption key.
  12. 21
    A first computer system having a processor operable to perform a pseudo-prefix-computation method according to any one of claims I to 19.
  13. 23
    A computer program product comprising program code for performing a pseudo-prefix-computation method according to any of claims 1 to 19.
Independent claims13