EP1574009B1

Systems and apparatuses using identification data in network communication

Abstract

This record has no abstract on file.

EP1574009B1, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Expired 17 November 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

26 claims: 3 independent, 23 dependent

  1. 1
    A system for preventing intrusions in a communications network, the system comprising:a source node (10, 12, 14, 16, 18) for generating a transport control protocol/Internet protocol TCP/IP packet including a header with data embedded within the header that includes a user identifier and a source identifier which are in transformed form and which are associated with a user and source device of the source node;a gatekeeper node (70) for receiving the TCP/IP packet, for recovering the user identifier and the source identifier from the packet header by extraction of the user identifier and the source identifier from the packet header, reformation of the user identifier and reformation of the source identifier, and for determining whether the TCP/IP packet is to be released;and a destination node (90, 92, 94) for receiving and processing the TCP/IP packet if the gatekeeper node releases the packet to the destination node, wherein the gatekeeper node (70) determines whether the TCP/IP packet is to be released based on an authorisation policy associated with the user and source device identified by the user identifier and source identifier recovered from the packet header, characterised in that the TCP/IP packet is a synchronisation SYN packet having a sequence number field and an acknowledge field and the user identifier and source identifier are held in the sequence number field and the acknowledge field respectively.
  2. 12
    An apparatus for preventing intrusions in a communications network, the apparatus comprising a source node (10, 12, 14, 16, 18) for intercepting a transport control protocol/Internet protocol TCP/IP packet, transforming a user identifier and a source identifier associated with a user and a source device of the source node (10, 12, 14, 16, 18), and inserting into a header of the TCP/IP packet the transformed user identifier and the transformed source identifier, characterised in that the TCP/IP packet comprises a synchronisation SYN packet having a sequence number field and an acknowledge field and the user identifier and source identifier are held in the sequence number field and the acknowledge field respectively.
  3. 22
    An apparatus for preventing intrusions in a communications network, the apparatus comprising a gatekeeper node (70) for receiving a transport control protocol/Internet protocol TCP/IP packet including a header with data embedded within the header that includes a user identifier and a source identifier which are in transformed form and which are associated with a user and source device, extracting the user identifier and source identifier from the packet header, reforming the user identifier, reforming the source identifier, and determining whether the TCP/IP packet is to be released, characterised in that the TCP/IP packet is a synchronisation SYN packet having a sequence number field and an acknowledge field and the user identifier and the source identifier are held in the sequence number field and the acknowledge field respectively.