Node device and communication control method for improving security of packet communications
Abstract
At a node device, after an exchange procedure for exchanging a security association information is carried out, the security association information is stored in a memory unit while a management information including the destination address, the identification information, and an information regarding a valid period of the security association information is stored in a non-volatile medium, such that it is possible to recover the normal state quickly without damaging the safety, when a temporary operation trouble occurs at one node under an environment in which a plurality of nodes are carrying out communications safely by using a prescribed security protocol.
Claims
exact text as granted — not AI-modified1 . A node device, comprising:
an exchange procedure processing unit configured to carry out an exchange procedure for exchanging a security association information including a destination address of a packet communication, an identification information of the destination address that is unique to the destination address, and a parameter information regarding a cryptographic processing to be used in the packet communication, with a node that becomes a correspondent of the packet communication according to a prescribed security protocol, prior to the packet communication; a memory unit configured to store the security association information exchanged by the exchange procedure; a management unit configured to store and manage a management information including the destination address, the identification information, and an information regarding a valid period of the security association information and not including a secret key, for each security association information stored in the memory unit, in a non-volatile medium; and a packet processing unit configured to transmit a notification message containing the destination address and the identification information to the node that becomes the correspondent, when the security association information specified by the destination address that indicates the node device itself and the identification information that are contained in a header of a received packet destined to the node device according the prescribed security protocol does not exist as a valid security association information and the management information corresponding to that security association information exists as a valid management information in the non-volatile medium, in order to notify this fact to the node that becomes the correspondent.
2 . The node device of claim 1 , wherein the exchange procedure processing unit exchanges the security association information with the node that becomes the correspondent as a destination, with the node that becomes the correspondent prior to transmitting the notification message, and
the packet processing unit produces a packet according to the prescribed security protocol that contains the notification message according to the parameter information regarding the cryptographic processing that is contained in the security association information exchanged by the exchange procedure, and transmits the packet to the node that becomes the correspondent.
3 . The node device of claim 2 , wherein the packet processing unit verifies an authenticity of the notification message, and if the authenticity of the notification message is verified, deletes the security association information specified by the destination address and the identification information contained in the notification message from the memory unit, upon receiving the notification message.
4 . The node device of claim 2 , wherein the exchange procedure processing unit also carries out another exchange procedure for the security association information to be used in a packet transfer direction along which the notification message is to be transmitted and the security association information to be used in a direction opposite to the packet transfer direction, and
the packet processing unit uses each security association information exchanged by the another exchange procedure for packet transfers to be carried out subsequent to a processing of the notification message.
5 . The node device of claim 1 , wherein the packet processing unit processes the received packet according to the parameter information regarding the cryptographic processing contained in the security association information when the security association information specified by the destination address indicating the node device and the identification information that are contained in the header of the received packet destined to the node device according to the prescribed security protocol exists as a valid security association information.
6 . The node device of claim 1 , wherein the packet processing unit discards the received packet when the security association information specified by the destination address indicating the node device and the identification information that are contained in the header of the received packet destined to the node device according to the prescribed security protocol does not exist as a valid security association information.
7 . The node device of claim 1 , wherein the memory unit is formed by an internal memory device which becomes a state of not storing data that were stored before a fault occurs at the node device, after the node device is recovered from the fault and re-activated.
8 . The node device of claim 1 , wherein the packet processing unit produces and transmits a packet according to the prescribed security protocol according to the parameter information regarding the cryptographic processing that is contained in the security association information when the security association information to be used exists as a valid security association information in the memory unit, and
produces and transmits a packet according to the prescribed security protocol according to the parameter information regarding the cryptographic processing that is contained in the security association information after the exchange procedure by the exchange procedure processing unit is carried out when the security association information to be used does not exist as a valid security association information in the memory unit, at a time of transmitting the packet according to the prescribed security protocol.
9 . The node device of claim 1 , wherein the management unit stores and manages the information regarding the valid period of the security association information which indicates a lifetime.
10 . The node device of claim 1 , wherein the exchange procedure processing unit uses the prescribed security protocol which is an IPsec (Internet Protocol Security) protocol.
11 . The node device of claim 1 , wherein the exchange procedure processing unit carries out the exchange procedure which is a procedure according to an IKE (Internet Key Exchange).
12 . A communication control method for a node device for carrying out a packet communication with another node device, comprising:
carrying out an exchange procedure for exchanging a security association information including a destination address of the packet communication, an identification information of the destination address that is unique to the destination address, and a parameter information regarding a cryptographic processing to be used in the packet communication, with the another node device that becomes a correspondent of the packet communication according to a prescribed security protocol, prior to the packet communication; storing the security association information exchanged by the exchange procedure in an internal memory device, and storing a management information including the destination address, the identification information, and an information regarding a valid period of the security association information and not including a secret key, for each security association information stored in the internal memory device, in a non-volatile medium; receiving a packet destined to the node device according to the prescribed security protocol from the another node device; and transmitting a notification message containing the destination address and the identification information to the another node device, when the security association information specified by the destination address that indicates the node device itself and the identification information that are contained in a header of a received packet does not exist as a valid security association information and the management information corresponding to that security association information exists as a valid management information in the non-volatile medium, in order to notify this fact to the another node device.
13 . The communication control method of claim 12 , further comprising:
exchanging the security association information with the another node device as a destination, with the another node device prior to transmitting the notification message, and producing a packet according to the prescribed security protocol that contains the notification message according to the parameter information regarding the cryptographic processing that is contained in the security association information exchanged by the exchanging step, and transmitting the packet to the another node device.
14 . A communication control method for a first node device and a second node device that carry out a packet communication, comprising:
carrying out an exchange procedure for exchanging a security association information including a destination address of the packet communication, an identification information of the destination address that is unique to the destination address, and a parameter information regarding a cryptographic processing to be used in the packet communication, between the first node device and the second node device according to a prescribed security protocol, prior to the packet communication; storing the security association information exchanged by the exchange procedure in an internal memory device of each one of the first node device and the second node device, and storing a management information including the destination address, the identification information, and an information regarding a valid period of the security association information and not including a secret key, for each security association information stored in the internal memory device, in a non-volatile medium at least at the second node device; producing a packet according to the prescribed security protocol according to the parameter information regarding the cryptographic processing contained in the security association information at the first node device, and transmitting the packet to the second node device; receiving the packet transmitted to the second node device according to the prescribed security protocol from the first node device at the second node device; carrying out another exchange procedure for exchanging the security association information including the destination address of the packet communication according to a notification message, the identification information of the destination address that is unique to the destination address, and the parameter information regarding the cryptographic processing to be used in the packet communication, prior to transmitting the notification message containing the destination address and the identification information to the first node device; producing another packet according to the prescribed security protocol that contains the notification message according to the parameter information regarding the cryptographic processing contained in the security association information at the second node device, and transmitting the another packet to the first node device; receiving the another packet according to the prescribed security protocol that contains the notification message from the second node device at the first node device; and verifying an authenticity of the notification message, and if the authenticity of the notification message is verified, deleting the security association information specified by the destination address and the identification information contained in the notification message, at the first node device.
15 . A computer readable medium storing computer program instructions, which when executed by a computer, cause the computer to function as a node device by performing steps comprising:
exchanging a security association information including a destination address of a packet communication, an identification information of the destination address that is unique to the destination address, and a parameter information regarding a cryptographic processing to be used in the packet communication, with a node that becomes a correspondent of the packet communication according to a prescribed security protocol, prior to the packet communication; storing the security association information exchanged by the exchange procedure; storing and managing management information including the destination address, the identification information, and an information regarding a valid period of the security association information and not including a secret key, for each security association information stored in the preceding storing step, in a non-volatile medium; and transmitting notification message containing the destination address and the identification information to the node that becomes the correspondent, when the security association information specified by the destination address that indicates the node device itself and the identification information that are contained in a header of a received packet destined to the node device according to the prescribed security protocol does not exist as a valid security association information and the management information corresponding to that security association information exists as a valid management information in the non-volatile medium, in order to notify this fact to the node that becomes the correspondent.Join the waitlist — get patent alerts
Track US2008126796A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.