US20080098228A1

Method and apparatus for authentication of session packets for resource and admission control functions (RACF)

Claim Score by NHIP

Read claim 15, the broadest

Abstract

The invention that addresses the problem of authentication of the transport packet stream (which constitutes a flow within a session), which has been admitted into a managed packet network. Authentication and the subsequent policing of the flows supporting an identified client's authorized service prevent a large class of denial of service attacks described below. Specifically, the invention addresses two different matters: 1) key distribution and management 2) various forms of using a shared key for the authentication of transport packets on the user-to-network-interface (UNI).

US20080098228A1, drawing sheet 1
Sheet 1 of 3

Term

Projected expiry 14 September 2030.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

17 claims: 3 independent, 14 dependent

  1. 1
    A method of authenticating a transport packet stream in a managed packet network comprising the steps of:receiving at a RACF (Resource and Admission Control Function) a request for service from a client application transmitted through a service control function;authenticating said transport packet stream, using a session key, based on session flow parameters associated with said transport packet stream without regard to identity of a client.
  2. 13
    A method of authenticating a transport packet stream in a managed packet network comprising the steps of:receiving at a RACF a request for service from a client application transmitted through a service control function;authorizing the request from the service control function;creating a key, K F , for a session flow to be established, K F being shared between said client application and a gateway;passing a quantity (X or Y, from which X can be determined) to the service control function, wherein X is included in a token to be passed to a client application, wherein a client can determine a session flow key K F .
  3. 15
    Broadest claimClaim Score 81, broad(NHIP)A resource and control function apparatus comprising:a processor operable to receive a request for service from a client application transmitted through a service control function;and authenticating said transport packet stream, using a session key, based on session flow parameters associated with said transport packet stream without regard to identity of a client.