EP1574009A1

Systems and apparatuses using identification data in network communication

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 17 November 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

82 claims: 7 independent, 75 dependent

  1. 1
    Claims of equivalent WO 2004047407 A1 CLAIMS 1. A system characterized by:a first node (10, 12, 14, 15, 18) generating a packet including data based on a user identifier and source identifier;a second node (70) receiving the packet and determining whether the packet is to be released to its destination based on an authorization policy defined for the user identifier and source identifier of the packet;and a third node (90, 92, 94) receiving and processing the packet if the second node releases the packet to the third node.
  2. 13
    An apparatus characterized by:a node (10, 12, 14, 16, 18) for including data based on at least one of a user identifier and a source identifier in a header of a packet.
  3. 33
    An apparatus characterized by:a node (10, 12, 14, 16, 18) for transforming a user identifier, appending a first key index to the user identifier, and including the transformed user identifier and appended first key index in a first field of a header of a packet.
  4. 53
    An apparatus characterized by:a node (10, 12, 14, 16, 18) for generating a packet with a header having a transformed user identifier, a first key index, a transformed session identifier, and a second key index;creating a session identifier based on the transformed user identifier, the first key index, the transformed session identifier, and the second key index;encrypting the session identifier using the first key identified by the first key index;generating a hash based on the session identifier;and storing at least part of the hash.
  5. 58
    An apparatus characterized by:a node (70) for extracting data based on at least one of a user identifier and a source identifier from a header of a packet.
  6. 68
    An apparatus characterized by:a node (70) for receiving a packet having a transformed user identifier, first key index, fransformed source identifier, and second key index;extracting a transformed user identifier, first key index, transformed source identifier, and second key index from a packet;creating a session identifier based on the transformed user identifier, the first key index, the transformed session identifier, and the second key index;encrypting the session identifier using the first key identified by the first key index;and generating a hash based on the session identifier.
  7. 74
    An apparatus characterized by:a node (70) for receiving a packet;extracting a user identifier and source identifier from the packet;checking authorization policy based on the user identifier and source identifier to determine whether the user and source are authorized to pass to a destination indicated by the packet;releasing the packet if the checking indicates that the packet is permitted by the policy to pass to its destination;and dropping the packet if the authorization policy indicates that the packet is not permitted to pass to its destination.