PL2294850T3

Method of securing exchanges between an applicant node and a destination node

Abstract

The invention relates to a method for securing exchanges between an applicant node (N4) and a destination node (Nl), said nodes belonging to a communication network (2). The method comprises the following steps implemented by a security server (Serv): - a step of reception of a request sent by the applicant node with a view to access to the destination node; - a step of dispatching a response to the request, said response comprising a proof of authentication intended for the destination node and a session key, intended to be used for the exchanges between the applicant node and destination node, characterized in that, at least one secret, to be shared with at least one applicant node, distinct from the session key, being associated with the destination node, the response furthermore comprises said secret. The secret is then used by the applicant node to authenticate intermediate nodes (N3) enabling it to reach the destination node.

Term

2.7 yearsto projected expiry

Projected expiry 5 June 2029, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

12 claims: 5 independent, 7 dependent

  1. 1
    Patent claims Zastrzeżenia patentowe 1. A method of securing the exchange between the reporting node (N4) and the destination node (N1), said nodes being part of the communication network (2), said method comprising the following steps implemented by the security server (Serv):1. Sposób zabezpieczania wymiany pomiędzy węzłem zgłaszającym (N4) i węzłem docelowym (N1), przy czym wymienione węzły należą do sieci komunikacyjnej (2), wymieniony sposób obejmuje następujące etapy realizowane przez serwer zabezpieczający (Serv): - etap odbioru (F1) żądania (M1, M3) wysył anego przez wę zeł zgł aszają cy dla dostę pu do węzła docelowego;- stage of receiving (F1) the request (M1, M3) sent by the reporting node for access to the destination node;- etap wysyłania (F7) odpowiedzi (M4) na żądanie, a wymieniona odpowiedź zawiera dowód uwierzytelniający, przeznaczony dla węzła docelowego i klucz sesyjny, przeznaczony do użycia dla wymian pomiędzy węzłem zgłaszającym i docelowym, znamienny tym, że co najmniej jeden sekret, do dzielenia z co najmniej jednym innym węzłem zgłaszającym, odrębny od klucza sesyjnego, jest skojarzony z węzłem docelowym, a odpowiedź wysł ana do węzła zgłaszającego zawiera również wymieniony sekret. - the step of sending (F7) the response (M4) on request, and said response includes an authentication proof, intended for the destination node and a session key, intended for use for exchanges between the reporting and destination node, characterized in that at least one secret to be shared with at least one other reporting node, separate from the session key, is associated with the destination node, and the reply sent to the reporting node also includes said secret.
  2. 3
    The method of communication between the reporting node (N4) and the destination node (N1), said nodes belonging to one communication network (2), said method comprising the following steps implemented by the reporting node:3. Sposób komunikacji pomiędzy węzłem zgłaszającym (N4) i węzłem docelowym (N1), przy czym wymienione węzły należą do jednej sieci komunikacyjnej (2), wymieniony sposób obejmuje następujące etapy realizowane przez węzeł zgłaszający: - etap wysył ania (E1) żądania (M1) do serwera zabezpieczają cego dla dostę pu do węzła docelowego;- stage of sending (E1) request (M1) to the security server for access to the destination node;- etap otrzymywania (E4) odpowiedzi (M4) na żądanie zawierają ce dowód uwierzytelniający, przeznaczony dla węzła docelowego i klucz sesyjny, przeznaczony do użycia dla wymian pomiędzy węzłem zgłaszającym i docelowym, znamienny tym, że odpowiedź zawiera również co najmniej jeden sekret i wymieniony sposób obejmuje poza tym etap uwierzytelniania co najmniej jednego innego węzła za pomocą wymienionego co najmniej jednego sekretu, a wymieniony inny węzeł jest zdolny do połączenia się z węzłem docelowym. - the step of receiving (E4) the response (M4) on request containing the authentication proof, intended for the destination node and the session key, intended for use for exchanges between the reporting and destination node, characterized in that the response also contains at least one secret and said method furthermore includes the step of authenticating at least one other node using said at least one secret, and said other node is able to connect to the destination node.
  3. 7
    A server (300) to secure exchanges between the reporting node and the destination node in a communication network, comprising:7. Serwer (300) dla zabezpieczenia wymian pomiędzy węzłem zgłaszającym i węzłem docelowym w sieci komunikacyjnej, zawierający: - receiving means (302) of the request sent by the reporting node to access the destination node;- środki odbioru (302) żądania wysył anego przez węzeł zgłaszający dla dostępu do węzła docelowego;- 15 - środki wysyłania (304) odpowiedzi na żądanie, a wymieniona odpowiedź zawiera dowód uwierzytelniający, przeznaczony dla węzła docelowego i klucz sesyjny, przeznaczony do użycia dla wymian pomiędzy węzłem zgłaszającym i docelowym, zmienny tym, że środki wysyłania są poza tym tak przystosowane do zawierania w odpowiedzi sekretu, a wymieniony sekret, do dzielenia z co najmniej jednym innym węzłem zgłaszającym, odrębny od klucza sesyjnego, jest skojarzony z węzłem docelowym. - the means of sending (304) the response to the request, and said response includes an authentication ID, intended for the destination node and a session key, intended to be used for exchanges between the reporting and destination node, variable in that the sending means are also so adapted to containing a secret in response, and said secret, to be shared with at least one other reporting node, separate from the session key, is associated with the destination node.
  4. 8
    Node (400) of the communication network, comprising:8. Węzeł (400) sieci komunikacyjnej, zawierający: - means of sending (402) requests to the server for access to the target node;- ś rodki wysył ania (402) żądania do serwera dla dostę pu do w ę z ł a docelowego;- means of receiving (404) the response to the request, and the response includes an authentication proof intended for the destination node and a session key, intended for use for exchanges between the node and the destination node, variable in that the means of reception are further adapted to receive a response containing at least one secret and said node further comprise authentication means (406) of at least one other node by means of said at least one secret, and said other node is able to connect to the destination node. - ś rodki odbioru (404) odpowiedzi na żądanie, a odpowiedź zawiera dowód uwierzytelniający, przeznaczony dla węzła docelowego i klucz sesyjny, przeznaczony do użycia dla wymian pomiędzy węzłem i węzłem docelowym, zmienny tym, że środki odbioru są poza tym przystosowane do odbioru odpowiedzi zawierającej co najmniej jeden sekret i wymieniony węzeł zawiera poza tym środki uwierzytelniania (406) co najmniej jednego innego węzła za pomocą wymienionego co najmniej jednego sekretu, a wymieniony inny węzeł jest zdolny do połączenia się z węzłem docelowym.
  5. 12
    The signal carrying the response to the request for access to the destination node, sent by the reporting node, and the said response is sent by the server to the reporting node and contains the authentication proof intended for the destination node and the session key intended for use for exchanges between the nodes to the notifier and target person, characterized in that said answer also contains at least one secret mentioned, and said secret, for sharing with at least one other reporting node, separate from the session key, is associated with the destination node. 12. Sygnał przenoszący odpowiedź na zgłoszenie dla dostępu do węzła docelowego, wysłaną przez węzeł zgłaszający, a wymieniona odpowiedź jest wysyłana przez serwer do węzła zgłaszającego i zawiera dowód uwierzytelniający, przeznaczony dla węzła docelowego i klucz sesyjny, przeznaczony do uż ycia dla wymian pomię dzy wę z ł em zgł aszają cym i docelowym, znamienny tym, że wymieniona odpowiedź zawiera poza tym co najmniej jeden wymieniony sekret, a wymieniony sekret, do dzielenia z co najmniej jednym innym węzłem zgłaszającym, odrębny od klucza sesyjnego, jest skojarzony z węzłem docelowym. Prepared and verified Sporządziła i zweryfikowała Grażyna Palka Patent Attorney Grażyna Palka Rzecznik patentowy