EP2850776B1

Tls abbreviated session identifier protocol

Abstract

This record has no abstract on file.

EP2850776B1, drawing sheet 1
Sheet 1 of 6

Term

6.6 yearsleft in the term

Expires 9 May 2033.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

13 claims: 8 independent, 5 dependent

  1. 1
    A method of authentication between a client (310) and a server (311), the method comprising:a) negotiating a secure network connection between the client and the server using Transport Layer Security, TLS, protocol;characterized in that the method further comprises: b) providing a unique abbreviated session identifier, ASI (302a), by the server along with a TLS protocol session identifier;c) associating the unique ASI with the TLS protocol session identifier;and d) transmitting the unique ASI along with the TLS protocol session identifier to the client;wherein subsequent data packets transferred between the client and the server include (401) the unique ASI, and wherein the unique ASI received in one of the data packets is used for re-establishing (405) the secure network connection following disconnection.
  2. 3
    The method of any one of claims 1 to 2, wherein the data packets are encapsulated with a TLS ASI header (500, 600) indicative of the unique ASI.
  3. 5
    The method of any one of claims 1 to 4, wherein a pre-existing field of each of the subsequent data packets is used to accommodate the unique ASI.
  4. 7
    The method of any one or claims 1 to 6, wherein the unique ASI is a random arbitrarily chosen or generated value, a port number, or an Internet Protocol (IP) address.
  5. 9
    A system (300) for authenticating connection between a client and a server, the system comprising:a) a client (310) configured to send data or receive data or both;b) a server (311) configured to send data or receive data or both;c) the system configured to negotiate a secure network connection between the client and the server using Transport Layer Security, TLS, protocol;characterized in that : d) the server is configured to provide a unique abbreviated session identifier, ASI (302a), along with a TLS protocol session identifier;e) the server is configured to associate the unique ASI with the TLS protocol session identifier;and f) the server is configured to transmit the unique ASI with the TLS protocol session identifier;and wherein at least some subsequent data packets transferred between the client and the server include (401) the unique ASI, and wherein the unique ASI received in one of the data packets is used for re-establishing (405) the secure network connection following disconnection.
  6. 11
    The system of any one of claims 9 to 10, wherein the data packets are encapsulated with a TLS ASI header (500, 600) indicative of the unique ASI.
  7. 12
    The system of any one of claims 9 to 11, wherein a pre-existing field of each of the subsequent data packets is used to accommodate the unique ASI and optionally wherein the subsequent data packets comprise client-originating data packets, and wherein the pre-existing field of the client-originating data packets comprises a destination IP address field, a destination port number field, or both, the server further configured to:adjust operation to use a destination IP address indicated in the destination IP address field and a destination port number indicated in the destination port number field for communication with the client, in accordance with an established TCP/IP protocol.
  8. 13
    A computer program product comprising a computer readable memory storing computer executable instructions thereon that when executed by a computer perform the following steps of authentication between a client (310) and a server (311):a) negotiating a secure network connection between the client and the server using Transport Layer Security, TLS, protocol;characterized in that the steps include: b) providing a unique abbreviated session identifier, ASI (302a), by the server along with a TLS protocol session identifier;c) associating the unique ASI with the TLS protocol session identifier;d) transmitting the unique ASI along with the TLS protocol session identifier to the client;and wherein at least some subsequent data packets transferred between the client and the server include (401) the unique ASI, and wherein the unique ASI received in one of the data packets is used for re-establishing (405) the secure network connection following disconnection.