Nova Patents
EP1588535B1

Establishing communication tunnels

Abstract

A method for establishing a secure communications tunnel between a first node and a second node in a communication system includes a plurality of networks each having a respective tunnel control entity for controlling establishment of secure communications tunnels in the respective network. The first node operates in a first one of the networks and the second node operates in a second one of the networks. The method includes determining a route for the communications tunnel from the first network to the second network by way of one or more of the other networks. A request message digitally signed by the first node is formed and the identities of the tunnel control entity of the first network and the tunnel control entities of the other networks are included. The request message from the first node to the tunnel control entity of the second network is transmitted. In response to that message, the secure communication tunnel is established between the first node and the second node by way of the tunnel control entities identified in that message.

EP1588535B1, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 22 January 2024, 2.7 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

15 claims: 13 independent, 2 dependent

  1. 1
    A method for establishing a secure communications tunnel between a first node (MN) and a second node (CN) in a communication system including a plurality of networks (AS1-AS6) each having a respective tunnel control entity (SG1-SG5) for controlling establishment of secure communications tunnels in the respective network, the first node operating in a first one of the networks and the second node operating in a second one of the networks; the method characterised by :determining a route for the communications tunnel from the first network to the second network by way of one or more of the other networks;forming a request message digitally signed by the first node and including the identities of the tunnel control entity of the first network and the tunnel control entities of the said other networks;and transmitting the request message to the tunnel control entity of the second network;and in response to that message establishing the secure communication tunnel between the first node and the second node by way of the tunnel control entities identified in that message.
  2. 3
    A method as claimed in any preceding claim, wherein the communication system includes a key server that stores a secure communication key for each of the tunnel control entities, wherefrom the tunnel control entity of the second network may retrieve a secure communication key for any of the tunnel control entities identified in the message, and thereby establish a secure communication tunnel to that entity.
  3. 4
    A method as claimed in any preceding claim, wherein the step of determining a route comprises repeatedly:forming and digitally signing at the first node a request message requesting establishment of a secure communications tunnel from the first node to the second node and including the identity of each tunnel control entity that has transmitted its identity to the first node in a previous iteration of these steps;transmitting the request message from the first node to one of the tunnel control entities identified in the message;determining at the said one of the tunnel control entities another of the networks that is on a communication path from the network that has the said one of the tunnel control entities to the network in which the second node is operating;transmitting from the said one of the tunnel control entities to the tunnel control entity of the other of the networks a message indicating the request for establishment of a secure communications tunnel from the first node to the second node;and transmitting from the tunnel control entity of the other of the networks to the first node the identity of that tunnel control entity.
  4. 5
    A method as claimed in any of claims 1 to 3, wherein the method comprises:forming and digitally signing at the first node a request message requesting establishment of a secure communications tunnel from the first node to the second node and including the identity of a tunnel control entity;transmitting the request message from the first node to the tunnel control entity identified in the message;determining at the tunnel control entity that receives the request message another of the networks that is on a communication path from the network that has that tunnel control entity to the network in which the second node is operating;modifying the request message at the tunnel control entity by appending the identity of the tunnel control entity to the request message and digitally signing the request message;and forwarding the modified request message to the next hop towards the second node by transmitting the modified request message from the tunnel control entity to the tunnel control entity of the other of the networks.
  5. 6
    A method as claimed in any preceding claim, comprising:detecting that the first node has been or is to be handed over from the first network to a third one of the networks;informing the tunnel control entity of the third network of the communication tunnel from the first node to the second node;and determining a route for the communications tunnel from the third network to the second network by way of one or more of the other networks.
  6. 7
    A method as claimed in any preceding claim, wherein the first network is a local area network.
  7. 9
    A method as claimed in any preceding claim, wherein at least one of the networks on the route from the first network to the second network is a UMTS/3G network.
  8. 10
    A method as claimed in any preceding claim, wherein the or each request message is a message having router alert set.
  9. 11
    A method as claimed in any preceding claim, wherein the first node is a wireless communication terminal.
  10. 12
    A method as claimed in any preceding claim, wherein the tunnel is a virtual private network tunnel.
  11. 13
    A method as claimed in any preceding claim, wherein the tunnel is secured using the IPsec protocol.
  12. 14
    A communication system including a plurality of networks (AS1-AS6) each having a respective tunnel control entity (SG1-SG5) for controlling establishment of secure communications tunnels in the respective network, a first node (MN) operating in a first one of the networks (AS2) and a second node (CN) operating in a second one of the networks (AS6); the communication system being capable of supporting a secure communications tunnel between the first node and the second node, and characterised in comprising:means for determining a route for the communications tunnel from the first network to the second network by way of one or more of the other networks;means for forming a request message digitally signed by the first node and including the identities of the tunnel control entity of the first network and the tunnel control entities of the said other networks;and means for transmitting the request message to the tunnel control entity of the second network;and means for, in response to that message establishing the secure communication tunnel between the first node and the second node by way of the tunnel control entities identified in that message.
  13. 15
    A tunnel control entity (SG1-SG5) for controlling establishment of secure communications tunnels in a network comprised in a communication system including a plurality of networks, the tunnel control entity being arranged to:in response to receiving from another entity a request for establishment of a communication tunnel by way of the said network, transmit to the other entity the identity of the tunnel control entity;and in response to receiving a request for establishment of a communication tunnel from the said network to another network of the communication system, determine a route for the communications tunnel from the said network to the other network by way of one or more of the other networks included in the communication system (AS 1-AS6).