Secure IP access protocol framework and supporting network architecture
Abstract
A protocol framework for a Secure IP Access (SIA) method, and supporting components deployed on IP hosts and IP networks. Using this method, an IP host can establish a secure data channel within an IP network over an insecure shared link while requesting IP address and networking configuration parameters from the IP network. A system administrator can implement strong access control against various attacks that an edge IP network may have to face, such as a denial-of-service attack that exhausts assignable IP addresses. This is a lightweight, scalable, and backward-compatible solution that can improve security performance for public and corporate LANs having open access such as wireless access points and Ethernet jacks.
Claims
exact text as granted — not AI-modified1 . A method for a first IP host to authenticate to a second IP host on the same link of an IP network, comprising the steps of:
(a) sending a DHCP_INFORM message including an option specifying the IP address of the second IP host; (b) receiving a DHCP_ACK message including an option containing a security token for establishing a secure data channel between the first and second IP hosts; (c) broadcasting an ARP request message including an option containing authentication credentials derived from the security token; and (d) receiving an ARP response message.
2 . The method recited in 1 , wherein the initiating IP host requests a security token from a secure IP access server on the IP network.
3 . The method recited in 2 , wherein the security token is a Kerboros ticket.Join the waitlist — get patent alerts
Track US2007101121A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.