US2020128374A1PendingUtilityA1

System for authenticating and authorizing access to and accounting for wireless access vehicular environment consumption by client devices

Assignee: PAXGRID CDN INCPriority: Jul 1, 2016Filed: Sep 24, 2019Published: Apr 23, 2020
Est. expiryJul 1, 2036(~9.9 yrs left)· nominal 20-yr term from priority
H04L 63/0823H04W 84/005H04W 4/24H04W 4/44H04L 67/12G06F 21/45H04W 12/02H04L 43/0811H04L 2209/80H04L 63/08H04L 63/0892H04L 2209/84G06F 9/54H04W 12/08H04W 12/06H04W 12/04H04L 61/5092H04L 2101/659H04W 92/10H04W 92/045H04W 92/02H04W 88/14H04W 80/04H04W 88/08H04W 88/02H04W 12/069H04W 12/03H04W 12/084H04W 12/068H04W 12/086
59
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method are disclosed for authenticating and authorizing access to and accounting for consumption of bandwidth for IPv6 connectivity to the Internet over Wireless Access Vehicular Environment (WAVE) service channels by client devices using an Authentication, Authorization and Accounting (AAA) server. The AAA server authenticates and authorizes client devices to access WAVE service channels, and accounts for bandwidth consumption by the client devices using WAVE service channels to access the Internet. The AAA server enables an RSU infrastructure operator to quantify wireless bandwidth consumption by in-vehicle devices using the WAVE Service Channels, on a per-device basis.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An AAA server operated by, or on behalf of a Dedicated Short-Range Communications infrastructure authority, transmitting messages among and between On-board Units (OBU) and Roadside Units (RSU), said AAA server comprising at least one processor running at least one computer program adapted to communicate through the Internet with a plurality of user devices and/or an OBU operating a subnet for one or more user devices, with a plurality of RSUs, in order to carry out the functions of Authentication, Authorization and Accounting (AAA), enabling the authority to account for Wireless Access Vehicular Environment service channel bandwidth consumption by each of said user devices having been duly provisioned by said AAA server. 
     
     
         2 . An AAA server, as defined in  claim 1 , configured as a Certificate Management Entity and operable to issue Internet Subscription digital certificates for IPv6-addressable user devices and to transmit said certificates to said user devices over a secure communications channel, said certificates including the domain name of said AAA server. 
     
     
         3 . An AAA server, as defined in  claim 2 , linked to a PKI chain of trust between components of a Security Credentials and Management System (SCMS), operable to process requests from DSRC OBUs for said digital certificates, said requests encapsulating Personal Identifying Information (PII) for said OBUs and secured by the asymmetrical encryption algorithm specified in IEEE 1609.2, using an enrollment certificate issued to said OBUs by the SCMS and operable to establish said secure communications channel for sending said certificate to said OBU using the encryption key of said enrollment certificate. 
     
     
         4 . An AAA server, as defined in  claim 3 , operable to process requests from non-DSRC mobile devices for said digital certificates, said requests encapsulating PII for said mobile device, each mobile device initiating a handshaking protocol to establish a secure, symmetrically encrypted communications channel with said AAA server. 
     
     
         5 . An AAA server, as defined in  claim 3 , operable to receive combined authorization and authentication requests from OBUs, said requests incorporating credentials in the form of digital signatures generated using keys from said Internet Subscription certificates issued to said OBUs by said AAA server; operable to receive said combined authorization and authentication requests forwarded from one or more remote AAA servers on behalf of OBUs that have received said Internet Subscription certificates from said remote AAA servers; operable to process requests from both said OBUs and said remote AAA servers by cryptographic validation of the credentials presented correspondingly by said OBUs and said remote AAA servers, for each request querying a non-remote AAA database for a match with PII contained in the request, and returning a message to the requesting OBU or remote AAA, either granting or denying authorization with a code representing a reason for denial. 
     
     
         6 . An AAA server, as defined in  claim 3 , operable to receive authorization requests from said OBUs on behalf of non-DSRC mobile devices, to send UDP/IP authentication challenge messages directly or indirectly to IPv6 address of said non-DSRC mobile devices; to process responses to said authentication challenges which incorporate credentials in the form of digital signatures generated using keys from said Internet Subscription certificates issued to said non-DSRC mobile devices by said AAA server; and operable to receive said authorization requests forwarded from a remote AAA server on behalf of non-DSRC mobile devices that have received Internet Subscription credentials from said AAA server; operable to process said requests from both non-DSRC mobile devices and remote AAA servers by cryptographic validation of the credentials presented, querying the local AAA database for a match with PII contained in the request, and returning a message to the requester either granting or denying authorization with a code explaining the reason for denial. 
     
     
         7 . An AAA server, as defined in  claim 3 , operable, in the case where the domain name of the Certificate Management Entity having issued credentials used by a user device to request authentication and authorization, identifies a remote AAA server, to forward said request to said remote AAA server, using credentials obtained from said SCMS chain of trust to secure communications with said remote server. 
     
     
         8 . An AAA server, as defined in  claim 3 , operable, in the case where the domain name of the Certificate Management Entity having issued the credentials used by a user device to respond to an authentication challenge from said AAA server, identifies a remote AAA server, to forward said request to said remote AAA server, using credentials obtained from said SCMS chain of trust to secure communications with said remote AAA server. 
     
     
         9 . An AAA server, as defined in  claim 1 , operable to use Remotely Triggered Black Hole (RTBH) filtering with internal Border Gateway Protocol to send UPDATE messages to RSUs within a same Autonomous System, said UPDATE messages being triggered by, and encapsulating the results of an authentication and authorization request for Internet Subscription services received from a user device, said results being either the failure to authenticate said mobile device, or the granting or denial of authorization to said user device. 
     
     
         10 . A Roadside Unit (RSU) configured with an extended IPv6 Management Information Base (MIB) operable to determine packet and byte count statistics for Wireless Access Vehicular Vehicle (WAVE) service channel usage per client device, said client device being either an On-board Unit (OBU), a non-DSRC mobile device that is IPv6-reachable through an OBU, or a DSRC-enabled user device; said IPv6 MIB being also operable to retrieve, for each datagram received from an IPv6 node operating in a route optimization mode of Mobile IPv6, a fixed “home address” of the mobile node carried in the Mobile IPv6 routing header of said datagram; said RSU being operable to accumulate, in Non-volatile Random Access Memory (NOVRAM), said packet and byte count statistics for WAVE service channel usage per client device and periodically to send said statistics to a AAA server, encapsulated in a UDP/IP message, only refreshing said NOVRAM table when the AAA server has acknowledged reception of said UDP/IP message. 
     
     
         11 . An RSU as defined in  claim 10 , compliant with the USDOT specifications found in http://docplayer.net/11087167-Dsrc-roadside-unit-rsu-specifications-document.html or a functional equivalent thereof. 
     
     
         12 . An RSU, as defined in  claim 11 , operable to process RTBH filtering instructions from a AAA server within a same Autonomous System. 
     
     
         13 . An OBU, compliant with WAVE and IEEE 802.11p and configurable with dual-radio capability, running at least one application level computer program adapted to request authentication and authorization from a AAA server, for IPv6 connectivity to the Internet, either on behalf of a neighboring non-DSRC mobile device or for itself, and configured with an extended IPv6 MIB operable to retrieve the addresses of neighboring devices when a new entry is inserted in a routing table, using either a synchronous method based on SNMP GET to retrieve the routing table periodically, or an asynchronous method based on SNMP TRAP to report “real-time” changes in the routing table. 
     
     
         14 . An OBU, as defined claim in  14 , operable to request “Internet Subscription” credentials from a AAA server, using its SCMS enrollment certificate from encryption of the request to, and decryption of the response from, said AAA server, and operable to use said credentials when requesting authentication and authorization from said AAA server for said IPv6 connectivity to the Internet. 
     
     
         15 . A system facilitating communication between and among On-board Units (OBU) and Roadside Units (RSU) utilizing Dedicated Short-Range Communications (DSRC) to communicate through the Internet with a plurality of user devices and/or an OBU operating a subnet for one or more user devices, said system comprising:
 a server transmitting messages among and between the OBU and the RSU, said server comprising at least one processor running at least one computer program adapted to authenticate the user device, authorize the user device to have access to Wireless Access Vehicular Environment (WAVE) service channels, and account for bandwidth consumption by each of said user devices having been duly authenticated and authorized by said AAA server.   
     
     
         16 . A system as defined in  claim 15 , comprising a plurality of servers operated by, or on behalf of a Dedicated Short-Range Communications (DSRC) infrastructure authority.

Join the waitlist — get patent alerts

Track US2020128374A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.