US2014181967A1PendingUtilityA1

Providing-replay protection in systems using group security associations

Assignee: ROCKSTAR CONSORTIUM US LPPriority: Sep 12, 2003Filed: Mar 3, 2014Published: Jun 26, 2014
Est. expirySep 12, 2023(expired)· nominal 20-yr term from priority
H04L 63/104H04L 63/08H04L 63/1408H04L 63/0272H04L 63/166
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and apparatus is disclosed which enables detection of undesired packets received at a device in a network, where the device is a member of a group of devices in the network. A registration table stores transform identifiers for each member of a group and controls the forwarding of the transform identifiers to the members of the group as members are added and deleted. A transform identifier indicates a format or transformation of a packet transmitted by an associated member. The transform identifier can therefore be used at a receiving device to distinguish between transmissions by different members of the group, thereby enabling the receiving device to extract sequence information associated with the member from the packet. The sequence information can be compared against an expected sequence number for the member to determine whether the packet is an undesirable or rogue packet.

Claims

exact text as granted — not AI-modified
1 . A method of processing packets in an edge device of a network comprising a group of devices, the method comprising, at the edge device:
 associating a unique respective transform identifier with each other device of the group of devices, the group of devices using at least one group security association for communication between the devices in the group of devices, each unique transform identifier being determined by the at least one group security association;   associating a respective expected sequence number with each other device of the group of devices;   receiving a packet from a first device of the group of devices;   using the unique respective transform identifier associated with the first device to extract a sequence number from the packet received from the first device; and   comparing the extracted sequence number with the respective expected sequence number associated with the first device to determine validity of the packet received from the first device.   
     
     
         2 . The method of  claim 1 , wherein the at least one group security association comprises a group of security associations, each other device of the group of devices being associated with a unique respective group security association of the group of group security associations, and the unique respective transform identifier associated with each other device of the group of devices is associated with the respective group security association associated with that other device. 
     
     
         3 . The method of  claim 2 , wherein the unique respective transform identifier associated with each other device of the group of devices is the respective group security association associated with that other device. 
     
     
         4 . The method of  claim 1 , wherein the at least one group security association comprises a common group security association and the unique respective transfer identifier associated with each other device of the group of devices comprises a respective security protocol index associated with that other device. 
     
     
         5 . The method of  claim 4 , wherein the unique respective transform identifier is the respective security protocol index associated with that other device. 
     
     
         6 . The method of  claim 1 , comprising discarding the packet received from the first device if the packet received from the first device is determined to be invalid based on the comparing of the extracted sequence number with the respective expected sequence number. 
     
     
         7 . The method of  claim 1 , wherein associating a unique respective transform identifier with each other device of the group of devices comprises maintaining, at the edge device, a table of respective transform identifiers in association with identifiers of other devices of the group of devices. 
     
     
         8 . The method of  claim 1 , wherein associating a respective expected sequence number with each other device of the group of devices comprises maintaining, at the edge device, a table of respective expected sequence numbers in association with identifiers of the other devices of the group of devices. 
     
     
         9 . The method of  claim 1 , wherein comparing the extracted sequence number with the respective expected sequence number associated with the first device to determine validity of the packet received from the first device comprises determining that the packet received from the first device is invalid when the extracted sequence number is less than the respective sequence number associated with the first device. 
     
     
         10 . The method of  claim 1 , comprising updating the expected sequence number associated with the first device based on the extracted sequence number of the packet received from the first device. 
     
     
         11 . An edge device for a network comprising a group of devices, the edge device comprising:
 a storage medium configured to store:   data associating a unique respective transform identifier with each other device of the group of devices, the group of devices using at least one group security association for communication between the devices in the group of devices, each unique transform identifier being determined by the at least one group security association; and   data associating a respective expected sequence number with each other device of the group of devices; and   logic configured to:   receive a packet from a first device of the group of devices;   use the unique respective transform identifier associated with the first device to extract a sequence number from the packet received from the first device; and   compare the extracted sequence number with the respective expected sequence number associated with the first device to determine validity of the packet received from the first device.   
     
     
         12 . The edge device of  claim 11 , wherein the at least one group security association comprises a group of security associations, each other device of the group of devices being associated with a unique respective group security association of the group of group security associations, and the unique respective transform identifier associated with each other device of the group of devices is associated with the respective group security association associated with that other device. 
     
     
         13 . The edge device of  claim 12 , wherein the unique respective transform identifier associated with each other device of the group of devices is the respective group security association associated with that other device. 
     
     
         14 . The edge device of  claim 11 , wherein the at least one group security association comprises a common group security association and the unique respective transfer identifier associated with each other device of the group of devices comprises a respective security protocol index associated with that other device. 
     
     
         15 . The edge device of  claim 14 , wherein the unique respective transform identifier is the respective security protocol index associated with that other device. 
     
     
         16 . The edge device of  claim 11 , comprising logic configured to discard the packet received from the first device if the packet received from the first device is determined to be invalid based on the comparing of the extracted sequence number with the respective expected sequence number. 
     
     
         17 . The edge device of  claim 11 , wherein the data associating a unique respective transform identifier with each other device of the group of devices comprises a table of respective transform identifiers stored in association with identifiers of other devices of the group of devices. 
     
     
         18 . The edge device of  claim 11 , wherein the data associating a respective expected sequence number with each other device of the group of devices comprises a table of respective expected sequence numbers stored in association with identifiers of the other devices of the group of devices. 
     
     
         19 . The edge device of  claim 11 , wherein logic configured to compare the extracted sequence number with the respective expected sequence number associated with the first device to determine validity of the packet received from the first device comprises logic configured to determine that the packet received from the first device is invalid when the extracted sequence number is less than the respective sequence number associated with the first device. 
     
     
         20 . The edge device of  claim 11 , comprising logic configured to update the expected sequence number associated with the first device based on the extracted sequence number of the packet received from the first device.

Join the waitlist — get patent alerts

Track US2014181967A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.