CN1228174A - 计算机网络中传输安全的装置及方法 - Google Patents

计算机网络中传输安全的装置及方法 Download PDF

Info

Publication number
CN1228174A
CN1228174A CN97196344A CN97196344A CN1228174A CN 1228174 A CN1228174 A CN 1228174A CN 97196344 A CN97196344 A CN 97196344A CN 97196344 A CN97196344 A CN 97196344A CN 1228174 A CN1228174 A CN 1228174A
Authority
CN
China
Prior art keywords
bag
time
safe key
node
computer network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN97196344A
Other languages
English (en)
Inventor
安德雷·戈多罗加
格伦·S·福西特
约瑟夫·P·R·托塞
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Glenayre Electronics Inc
Original Assignee
Glenayre Electronics Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Glenayre Electronics Inc filed Critical Glenayre Electronics Inc
Publication of CN1228174A publication Critical patent/CN1228174A/zh
Pending legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/022One-way selective calling networks, e.g. wide area paging
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/606Protecting data by securing the transmission between two devices or processes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0803Configuration setting
    • H04L41/0813Configuration setting characterised by the conditions triggering a change of settings
    • H04L41/082Configuration setting characterised by the conditions triggering a change of settings the condition being updates or upgrades of network functionality
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/085Retrieval of network configuration; Tracking network configuration history
    • H04L41/0853Retrieval of network configuration; Tracking network configuration history by actively collecting configuration information or by backing up configuration information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/085Retrieval of network configuration; Tracking network configuration history
    • H04L41/0853Retrieval of network configuration; Tracking network configuration history by actively collecting configuration information or by backing up configuration information
    • H04L41/0856Retrieval of network configuration; Tracking network configuration history by actively collecting configuration information or by backing up configuration information by backing up or archiving configuration information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/08Configuration management of networks or network elements
    • H04L41/0896Bandwidth or capacity management, i.e. automatically increasing or decreasing capacities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/02Topology update or discovery
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/16Multipoint routing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/12Avoiding congestion; Recovering from congestion
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/26Flow control; Congestion control using explicit feedback to the source, e.g. choke packets
    • H04L47/263Rate modification at the source after receiving feedback
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/28Flow control; Congestion control in relation to timing considerations
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/37Slow start
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • H04L63/0442Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0807Network architectures or network communication protocols for network security for authentication of entities using tickets, e.g. Kerberos
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/123Applying verification of the received information received data contents, e.g. message integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/50Network services
    • H04L67/60Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources
    • H04L67/62Establishing a time schedule for servicing the requests
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/30Definitions, standards or architectural aspects of layered protocol stacks
    • H04L69/32Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
    • H04L69/322Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
    • H04L69/329Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the application layer [OSI layer 7]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W24/00Supervisory, monitoring or testing arrangements
    • H04W24/04Arrangements for maintaining operational condition
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/02Traffic management, e.g. flow control or congestion control
    • H04W28/10Flow control between communication endpoints
    • H04W28/12Flow control between communication endpoints using signalling between network elements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W60/00Affiliation to network, e.g. registration; Terminating affiliation with the network, e.g. de-registration
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/022One-way selective calling networks, e.g. wide area paging
    • H04W84/027One-way selective calling networks, e.g. wide area paging providing paging services
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/61Time-dependent
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/02Traffic management, e.g. flow control or congestion control
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/02Traffic management, e.g. flow control or congestion control
    • H04W28/10Flow control between communication endpoints
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W28/00Network traffic management; Network resource management
    • H04W28/02Traffic management, e.g. flow control or congestion control
    • H04W28/10Flow control between communication endpoints
    • H04W28/14Flow control between communication endpoints using intermediate storage
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W72/00Local resource management
    • H04W72/30Resource management for broadcast services
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/02Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
    • H04W8/04Registration at HLR or HSS [Home Subscriber Server]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W8/00Network data management
    • H04W8/02Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]; Transfer of mobility data, e.g. between HLR, VLR or external networks
    • H04W8/08Mobility data transfer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W80/00Wireless network protocols or protocol adaptations to wireless operation
    • H04W80/06Transport layer protocols, e.g. TCP [Transport Control Protocol] over wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W92/00Interfaces specially adapted for wireless communication networks
    • H04W92/16Interfaces between hierarchically similar devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W92/00Interfaces specially adapted for wireless communication networks
    • H04W92/16Interfaces between hierarchically similar devices
    • H04W92/24Interfaces between hierarchically similar devices between backbone network devices

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Hardware Redundancy (AREA)
  • Telephonic Communication Services (AREA)

Abstract

透露了一种用于在计算机网络中对从源节点向目的节点通信的具有首部和本体的报文进行证实的方法。源节点和目的节点能够访问与一个共同时间帧同步的时钟机制。该方法包括:使用从时钟机制获得的并且存储在首部的时间部分中的时间基准以及源节点和目的节点所知道的口令产生第一安全密钥,与报文包一起从源节点向目的节点通信第一安全密钥,并且当目的节点收到第一安全密钥和报文包时,使用口令和时间基准产生第二安全密钥并将第二安全密钥与第一安全密钥进行比较。如果第二安全密钥与第一安全密钥不一致,则丢弃该报文包。

Description

计算机网络中传输安全的装置及方法
根据美国专利法第119(e)条,本申请要求享有1996年7月22日递交的临时申请第60/022,045号以及1996年7月12日递交的临时申请第60/021,617号的申请日。
本发明涉及计算机网络中的报文传输安全,更具体地涉及用于验证在计算机网络中通信的报文传输的装置及方法。
计算机网络是根据几种不同的模型配置的。在一种模型中,计算机网络具有多个通信互连的部件或节点,每个部件能够向另一个部件发送或者从其接收报文。这种报文包括信息请求和/或数据。每个部件相对于其他部件起到服务器和客户的作用。
各部件可以是完全互连的,从而每个部件具有与所有其他部件的通信连接。如此设计的计算机网络特别适合于使用多站播送传输协议。在多站播送传输协议中,源于一个节点的报文传输经过网络通信到所有其他节点。
在某些不理想情况下,计算机网络中的一个节点可能发生故障或者用无效的或非法的报文传输错误地填充计算机网络通信信道。在其他情况下,计算机网络的通信信道可能由来自计算机网络之外的敌意源的无效的或者不适当的报文传输发信所充斥。不论发生哪一种情况,计算机网络一般承认并且试图处理每个报文传输,好像消息传输是有效的。即使在计算机网络发现传输的错误性质之前,也浪费了大量的处理时间和资源。因此,无效报文传输不必要地加重了计算机网络处理资源的负担。当计算机网络使用多站播送传输协议时扩大了这一问题,因为这种计算机网络中的每个节点由于处理无效传输独自地加重了负担。
某些系统试图通过在每个报文传输中包含专用代码来解决这些问题。该代码被设计用来验证报文是由一个有效节点产生的。然而,分析了有效报文传输的敌意节点可能识别出报文的代码部分,并且将该代码简单地复制到无效报文中,从而使该报文看起来有效。这种无效报文继续对计算机网络的处理资源造成不必要的负担。
因此,本发明是一种计算机网络以及一种使网络部件能够有效地确定在网络上通信的传输的有效性的方法。
该计算机网络包括多个通信互连的部件。称为“节点”的抽象实体用于代表该网络中的部件。各部件通过它们各自的抽象节点相互识别和通信。
在本发明中,从一个节点向另一个节点传输的报文传输(或者包)包括一个首部和一个本体。包本体包括数据和/或信息请求。首部包括寻址信息、安全和时间代码以及与包传输相关的其他信息。该包首部的一部分保留用于存储指示发起该特定包的时间的时间基准。该包首部的另一部分保留用于存储由算法产生的唯一安全密钥,该算法将一已知的口令与所存储的时间基准组合起来。
当一个节点收到根据本发明编码的一个包时,该接收节点读取存储在该包首部中的时间基准,将其与现有时间基准进行比较。如果比较指示该包是“旧”的,即,存储于包首部中的发起时间位于可接受时间的预定窗口之外,则整个包被认定无效,并且立即被丢弃。该接收节点还由已知的口令和所存储的时间基准独立地产生一个安全密钥。将所产生的密钥与存储在包首部中的安全密钥进行比较。如果两个密钥不一致,则整个包被认定无效,并且立即被丢弃。因而,本发明为有效任务保持了节点处理能力。
较好的是,对丢弃的包进行记录,向网络操作员指示配置或者安全问题。
通过参照以下详细描述,并且结合附图,本发明的上述方面以及许多伴随的优点将变得清晰和更容易理解。
图1是示出适用于本发明的计算机网络的图;
图2示出具有一个首部和一个本体的报文包;以及
图3是示出已经与一个外部节点建立连接的计算机网络的图。
图1中示出一个适于采用本发明的计算机网络。在图1中,由节点A、B、C、D、E和F表示的网络部件都具有相互的通信链路。通信链路显示为每个节点伸向其他剩余节点的线。每个节点能够向和从任何其他节点发送和接收报文。
由节点A、B、C、D、E和F所表示的网络部件可以是单独的、独个的计算机,或者可以构成其他更大的计算机装置的部分。每个节点具有表示和向其他节点发送报文传输或包的计算能力。每个节点还具有从其他节点接收和处理包的计算能力。这样设计的计算机网络是众所周知的,并且易于由计算机网络领域内普通技术人员构造。
参照图2,从源节点向目的节点传输的报文包10具有一个首部12和一个本体14。本体14可以包括数据、信息请求或者它们的部分。首部12包括与报文包的传输和安全有关的信息。这个信息包括寻址信息(比如源和目的节点的标识)、可选安全域和由包通信的数据量的指示。首部12的一部分16保留用于存储指示发起该特定包的时间的时间基准。还保留一部分18用于存储一个安全密钥。如在下文所详述的,存储在包首部中的时间基准和安全密钥由接收包的节点用于确定包传输的有效性。
图1所示的每个节点可以访问一个保持时间基准的时钟机制(未示出)。时钟机制可以驻留在每个单独的网络部件中。可替换的是,各网络部件可以访问一个中央时钟机制。重要的是,在任何情况下,网络部件都共同地参照一个共同的时帧。
在每个单独的部件具有其自身驻留的时钟机制的情况下,每个时钟机制与一个共同的时帧同步。尽管对于本发明的目的该同步最好是精确的,但是一定量的时差是可以允许的。例如,所有节点在两分钟内与相同的时间基准同步(即正或负一秒)是足够的。
图1中所示的每个节点还可以使用一个或多个口令用于与其他节点进行通信。在本发明的一个实施方式中,属于一个载体或组织的网络内部的所有节点使用单一口令。在几个组织利用同一网络交换数据的情形下,为几个组织中的每一个设置不同的口令。以这种方式,每个节点将使用一个口令以便与其他共同拥有的节点进行通信,而且使用其他口令以便与属于访问该网络的其他组织的节点进行通信。
为了有助于建立包安全性,当产生一个报文包时,节点参考它的时钟机制,并且获得当前时间基准。这个时间基准记录在首部12的时间部分16中。尽管许多不同的时间格式适用于本发明,但是本发明优选实施方式使用了UNIX时间格式。一个32位的因特网时间格式也是适用的。
通过产生一个安全密钥并将其置入报文包首部12的密钥部分18中进步一建立了包安全性。根据本发明优选的实施方式,一个节点使用一个预定的密钥产生算法为每个包产生一个唯一的安全密钥。这个密钥产生算法将一个已知的口令与首部12的时间部分16中所记录的当前时间基准组合起来。在产生唯一安全密钥中也可以使用其他变量,包括源和目的节点标识符、包长度信息、序号和由包通信的实际数据。密钥产生算法可以使用常规的编码技术(例如进行加、减、乘、除、乘方、开方、逻辑比较等等),该技术使用口令、时间基准信息和其他变量(如果可用的话),与随机选择的数一起作为运算对象,以一种不易于反向的方式产生一个安全密钥。提供实现这种编码技术的计算机软件程序属于从事于计算机编程技术人员的普通技术。
在本发明的优选实施方式中,利用以下程序产生一个安全密钥。变量“in”是一个值的数组,其包括口令和记录于包首部的时间基准。变量“out”是与该包一起发送的安全密钥。
void security_key_hash(
unsigned long in [12],
unsigned long out [2])
{

      unsigned long ex [72];

      unsigned long r0, r1, r2, r3, r4, r5;

      unsigned int i;

      for (i=0;i<72;i++)

      ex[i]=0;

      for(i=0;i<72;i++)
      ex[i]=in[i];

      for(;i<72;i++)
				
				<dp n="d4"/>
ex[i]=ex[i-3]^ex[i-5]^ex[i-6]^ex[i-12];
r0=3822118087L;
r1=4206368529L;
r2=2636563960L;
r3=1419098426L;
r4=742554211L;
for(i=0;i<72;i++){
switch(i/18){

   case 0:

      r3)|(r2 &amp; r3))+

      (r4<<11)+(r4>>21)+2049053871L;

      break;

   case1:

      &amp; r3))+

      (r4<<11)+(r4>>21)+909867182L;

      break;

   case2:

      (~r1 &amp;~(r2 &amp; r3)))+

      (r4<<11)+(r4>>21)+2073245137L;

      break;

   case3:

      (~r1 &amp; ~r2))+

     (r4<<11)+(r4>>21)+4157358317L;

     break;
  }
r0=r1;
r1=r2;
				
				<dp n="d5"/>
r2=(r3<<27)+(r3>>5);
r3=r4;
r4=r5;
out[0]=r0+(r2*2628165923L)+(r4*545239213L);
out[1]=r1+(r3*68740181L);
}
带有完整的首部和本体的明确表示的包经过计算机网络传送到目的节点。在处理收到的一个报文包之前,目的节点验证该包的有效性。根据本发明,包有效性是通过检查存储在包首部中的时间基准和安全密钥进行确定的。于是,一方面,目的节点参照时钟机制以获得当前时间基准。目的节点将当前时间基准与记录在包首部中的时间基准进行比较。以这种方式,将存储在包首部中的时间用于确定该包的“年龄”。
较好的是,节点通过从当前时间基准中减去首部中的时间基准来完成比较步骤。得到一个时间差值,它反映了在该包的源点发起报文与在该包的目的地收到报文之间的时间差。
根据本发明的优选实施方式,为正常的包传输延迟分配一个预定时间量。如果比较步骤得到的时间差值大于为正常的包传输所分配的时间,则假定该包无效并且立即排除于进一步的考虑。目的节点丢弃、忽略、擦除或者否定对该包的进一步考虑。
在另一实施方式中,目的节点可以通过首先获得当前时间基准并然后从该时间基准中减去预定的时间量来完成比较步骤。如果记录于报文包中的时间基准早于减法步骤得到的时间基准,则假定该包为“旧”,因而无效。因为“旧”报文包不受进一步考虑,所以保留了计算机网络的处理资源。
在本发明另一方面中,包有效性是通过检查存储于包首部中的安全密钥来建立的。目的节点,按照密钥产生算法,使用与包传输相关的口令、代表何时发起该包的时间基准以及其他变量(如果可用),产生一个安全密钥,该安全密钥应该与包首部中存储的密钥一致。如果所产生的安全密钥与包首部中所记录的安全密钥不一致,则假定源节点不知道该口令,不知道该时间,或者没有一个适当的密钥产生程序。假定包为无效,并且立即排除进一步的考虑。如上所述,目的节点丢弃、忽略、擦除或者否定对该包的进一步考虑。
本发明为这些情况提供了一种解决方案,这些情况是有效的网络节点发生故障或者变成威胁到网络的运行并且重复的过时的报文充斥网络通信信道。与需要网络部件处理这种无效报文不同的是,根据本发明构造的计算机网络使用基于时间的机制确定报文的年龄。当一个节点发生故障并且利用相同报文的多个拷贝充斥计算机网络时,在预定时间量之后,记录于报文首部的时间信息将指示该报文为“旧”并被假定无效。该无效的报文被忽略,从而保留了网络部件用于其他有效任务的宝贵的处理时间。在使用多站播送通信的计算机网络中,比如使用多站播送传输协议的网络中,增加了时间节省。本发明因而降低了计算机网络的总体处理负担。
这本发明还为这种情况提供了一种解决方案,这种情况是位于计算机网络之外的一个节点获得对网络的通信访问。例如在图3中,节点X已经获得经过节点A、B和C对网络的通信访问。节点X可能威胁到该网络的正常运行并且利用无效的报文充斥网络的通信信道。由敌意节点X发起的报文在报文首部中有可能缺乏适当的时间基准,或者缺乏与网络的时钟机制同步的时间基准。对于使用本发明的计算机网络,该报文的无效性将被很快地确定,这是因为报文中的时间信息将不位于网络所建立的可接受时间窗口内。
如先前所述,根据本发明构造的计算机网络也使用基于密钥机制以确定报文传输的有效性。包括有消息传输的安全密钥由口令、时间基准及其他可用变量唯一组合产生。在如上所述的敌意节点X具有对网络通信访问的情况下,敌意节点X所发起的报文在报文首部中将可能缺少适当的安全密钥。如所述,适当安全密钥需要知道口令、时间基准和其他可用变量。在敌意节点X成功于包括了适当时间基准的情况下,敌意节点X将不可能包括适当安全密钥,除非敌意节点X还可使用适当口令、其他变量和适当安全密钥产生算法。以这种方式,本发明将一个口令与一个时间基准链接起来以提供一个安全密钥,用于建立和确定经过计算机网络通信的报文传输的有效性。
在采用用于通信控制的用户数据图协议(User Datagram Protocol-UDP)的计算机网络中本发明特别有用。UDP是一个“无连接”传输协议,并因此,节点不需建立与其他节点的特定连接以发送报文。无连接环境对上述外部敌意节点X获得对网络的访问的情况特别敏感。一旦节点X获得对网络的访问,节点X能够向计算机网络内的任一个或者所有节点传送无效包。本发明为计算机网络内的节点提供一种手段以确定报文传输的有效性并且排除那些不符合适当标准的传输。如果接收节点发现任何包中的时间基准或者安全密钥无效,各节点能够假定发送节点不知道口令或者适当的时间基准,并且丢弃包。于是降低了敌意节点能够利用无效数据充斥计算机网络的机会,而这种机会在使用多站播送协议或者UDP时增大了它的可能性。
尽管已示出和描述了本发明的优选实施方式,但是应认识到,可以做出各种改变而不背离本发明的实质和范围。例如,尽管图1示出全网状的面向连接的网络,但是应认识到,本发明既可用于点对点传输也可用于多站播送类型传输的其他拓扑和结构的计算机网络。环形、星形或者线形网络结构是众所周知的,并且适用于实现本发明。

Claims (14)

1.在计算机网络中用于证实从源节点到目的节点通信的报文包的方法,源节点和目的节点能够访问一个与共同时间帧同步的时钟机制,该方法包括:
(a)使用从所述时钟机制获得的时间基准以及由所述源节点和所述目的节点所知道的口令产生第一安全密钥;
(b)与报文包一起从所述源节点向所述目的节点通信所述第一安全密钥;
(c)当所述目的节点收到所述第一安全密钥和所述报文包时,使用所述口令和所述时间基准产生第二安全密钥并且将所述第二安全密钥与所述第一安全密钥进行比较;以及
(d)如果所述第二安全密钥与所述第一安全密钥不一致,丢弃所述报文包。
2.根据权利要求1的证实报文包的方法,其中产生所述第一安全密钥和所述第二安全密钥还使用从节点标识符、包长度信息、序号、实际包数据和随机选择的数所组成的组中所选择的信息。
3.根据权利要求1的证实报文包的方法,其中所述报文包是由一个首部和一个本体组成的,并且其中所述第一安全密钥存储在所述报文包首部中。
4.根据权利要求1的证实报文包的方法,还包括:如果所述报文包被丢弃则记录与所述报文包有关的信息。
5.根据权利要求1的证实报文包的方法,还包括:
(a)与所述报文包一起通信从所述时钟机制获得的第一时间基准;
(b)当所述目的节点收到所述第一时间基准和所述报文包时,将所述第一时间基准和从所述时钟机制获得的第二时间基准进行比较;以及
(c)如果所述第一时间基准与所述第二时间基准之间的时间差大于预定时间量,则丢弃所述报文包。
6.根据权利要求5的证实报文包的方法,其中所述报文包具有一个首部和一个本体,并且其中所述第一时间基准存储在所述报文包首部中。
7.根据权利要求5的证实报文包的方法,其中所述预定时间量基于计算出的正常包传输延迟。
8.根据权利要求5的证实报文包的方法,其中所述第一时间基准和所述第二时间基准使用UNIX时间格式。
9.一种计算机网络,包括由节点表示的多个通信互连部件,其中从源节点向目的节点通信的报文包括一个使用口令和时间基准产生的第一安全密钥,并且其中所述目的节点利用所述口令和所述时间基准产生第二安全密钥并且将所述第二安全密钥与所述第一安全密钥进行比较,如果所述第二安全密钥与所述第一安全密钥不一致,则所述目的节点丢弃该报文包。
10.根据权利要求9的计算机网络,其中产生所述第一安全密钥和所述第二安全密钥时还使用从节点标识符、包长度信息、序号、实际包数据和随机选择的数所组成的组中所选择的信息。
11.根据权利要求9的计算机网络,还包括一个用于在所述报文包被丢弃时对与所述报文包有关的信息进行记录的日志。
12.根据权利要求9的计算机网络,其中所述报文包包括第一时间基准,其中所述目的节点将所述第一时间基准与第二时间基准进行比较,并且其中如果第一时间基准与第二时间基准之间的时间差大于预定时间量,则丢弃所述报文包。
13.根据权利要求12的计算机网络,其中所述预定时间量基于计算出的正常包传输延迟。
14.根据权利要求12的计算机网络,其中所述第一时间基准和所述第二时间基准使用UNIX时间格式。
CN97196344A 1996-07-12 1997-07-11 计算机网络中传输安全的装置及方法 Pending CN1228174A (zh)

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
US2161796P 1996-07-12 1996-07-12
US60/021,617 1996-07-12
US2204596P 1996-07-22 1996-07-22
US60/022,045 1996-07-22

Publications (1)

Publication Number Publication Date
CN1228174A true CN1228174A (zh) 1999-09-08

Family

ID=26694902

Family Applications (2)

Application Number Title Priority Date Filing Date
CN97197582A Pending CN1228909A (zh) 1996-07-12 1997-07-11 用于无线消息传送系统的堵塞控制方法
CN97196344A Pending CN1228174A (zh) 1996-07-12 1997-07-11 计算机网络中传输安全的装置及方法

Family Applications Before (1)

Application Number Title Priority Date Filing Date
CN97197582A Pending CN1228909A (zh) 1996-07-12 1997-07-11 用于无线消息传送系统的堵塞控制方法

Country Status (8)

Country Link
US (5) US5913921A (zh)
EP (1) EP0976284A4 (zh)
KR (1) KR20000023741A (zh)
CN (2) CN1228909A (zh)
AU (5) AU3658497A (zh)
GB (1) GB2330284B (zh)
SE (1) SE9900033L (zh)
WO (4) WO1998002994A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1324485C (zh) * 2003-07-23 2007-07-04 永丰纸业股份有限公司 可携式安全信息存取系统及方法
CN100357901C (zh) * 2005-12-21 2007-12-26 华为技术有限公司 一种主设备和备份设备之间数据核查的方法
CN1864390B (zh) * 2003-10-29 2010-10-27 思科技术公司 用于利用安全性标记提供网络安全性的方法和装置
CN103748987B (zh) * 2009-07-14 2011-01-12 北京理工大学 一种基于模糊神经网络的攻击知识的自动更新方法

Families Citing this family (155)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6560461B1 (en) * 1997-08-04 2003-05-06 Mundi Fomukong Authorized location reporting paging system
JP3286584B2 (ja) * 1997-11-20 2002-05-27 株式会社日立製作所 多重化ルータ装置
US7162510B2 (en) * 1998-03-16 2007-01-09 Schneider Automation Inc. Communication system for a control system over Ethernet and IP networks
US6631136B1 (en) * 1998-08-26 2003-10-07 Hypercom Corporation Methods and apparatus for data communication using a hybrid transport switching protocol
US6212559B1 (en) * 1998-10-28 2001-04-03 Trw Inc. Automated configuration of internet-like computer networks
US6240511B1 (en) * 1998-12-14 2001-05-29 Emc Corporation Method and apparatus for detecting system configuration changes
US6665304B2 (en) * 1998-12-31 2003-12-16 Hewlett-Packard Development Company, L.P. Method and apparatus for providing an integrated cluster alias address
US6768737B1 (en) * 1999-06-08 2004-07-27 International Business Machines Corporation Control and maintenance of multicast distribution employing embedded displays
US6909900B1 (en) * 1999-07-01 2005-06-21 Gte Wireless Service Corporation Wireless mobile call location and delivery for non-geographic numbers using a wireline SSP+SCP/wireless HLR interface
US7260716B1 (en) * 1999-09-29 2007-08-21 Cisco Technology, Inc. Method for overcoming the single point of failure of the central group controller in a binary tree group key exchange approach
US6684331B1 (en) 1999-12-22 2004-01-27 Cisco Technology, Inc. Method and apparatus for distributing and updating group controllers over a wide area network using a tree structure
US7181014B1 (en) 1999-09-10 2007-02-20 Cisco Technology, Inc. Processing method for key exchange among broadcast or multicast groups that provides a more efficient substitute for Diffie-Hellman key exchange
US7434046B1 (en) 1999-09-10 2008-10-07 Cisco Technology, Inc. Method and apparatus providing secure multicast group communication
US7013389B1 (en) 1999-09-29 2006-03-14 Cisco Technology, Inc. Method and apparatus for creating a secure communication channel among multiple event service nodes
US7103185B1 (en) 1999-12-22 2006-09-05 Cisco Technology, Inc. Method and apparatus for distributing and updating private keys of multicast group managers using directory replication
US6987855B1 (en) 1999-09-10 2006-01-17 Cisco Technology, Inc. Operational optimization of a shared secret Diffie-Hellman key exchange among broadcast or multicast groups
US7702732B1 (en) 1999-09-29 2010-04-20 Nortel Networks Limited Methods for auto-configuring a router on an IP subnet
US6684241B1 (en) * 1999-09-29 2004-01-27 Nortel Networks Limited Apparatus and method of configuring a network device
US6778531B1 (en) * 1999-11-04 2004-08-17 Lucent Technologies Inc. Multicast routing with service-level guarantees between ingress egress-points in a packet network
US6697856B1 (en) 1999-11-19 2004-02-24 Cisco Technology, Inc. Healing of incomplete circuits in networks
US6711409B1 (en) 1999-12-15 2004-03-23 Bbnt Solutions Llc Node belonging to multiple clusters in an ad hoc wireless network
DE10000302B4 (de) * 2000-01-05 2011-08-11 Robert Bosch GmbH, 70469 Verfahren und Vorrichtung zum Austausch von Daten zwischen wenigstens zwei mit einem Bussystem verbundenen Teilnehmern
US7089211B1 (en) * 2000-01-12 2006-08-08 Cisco Technology, Inc. Directory enabled secure multicast group communications
US6456599B1 (en) 2000-02-07 2002-09-24 Verizon Corporate Services Group Inc. Distribution of potential neighbor information through an ad hoc network
US6775709B1 (en) 2000-02-15 2004-08-10 Brig Barnum Elliott Message routing coordination in communications systems
US7054636B1 (en) * 2000-03-01 2006-05-30 Gte Wireless Services Corporation Method and system for communicating data from wireline terminals to mobile terminals
US20040168174A1 (en) * 2000-03-08 2004-08-26 Baker Tyler Foley System for object cloing and state synchronization across a network node tree
US6757294B1 (en) 2000-03-13 2004-06-29 International Business Machines Corporation System and method for amicable small group multicast in a packet-switched network
US6785275B1 (en) * 2000-03-13 2004-08-31 International Business Machines Corporation Method and system for creating small group multicast over an existing unicast packet network
US7035223B1 (en) 2000-03-23 2006-04-25 Burchfiel Jerry D Method and apparatus for detecting unreliable or compromised router/switches in link state routing
US6977937B1 (en) 2000-04-10 2005-12-20 Bbnt Solutions Llc Radio network routing apparatus
US6987726B1 (en) 2000-05-22 2006-01-17 Bbnt Solutions Llc Management of duplicated node identifiers in communication networks
AU2001263498A1 (en) 2000-06-01 2001-12-11 Bbnt Solutions Llc Method and apparatus for varying the rate at which broadcast beacons are transmitted
US7302704B1 (en) 2000-06-16 2007-11-27 Bbn Technologies Corp Excising compromised routers from an ad-hoc network
US6941457B1 (en) * 2000-06-30 2005-09-06 Cisco Technology, Inc. Establishing a new shared secret key over a broadcast channel for a multicast group based on an old shared secret key
US6493759B1 (en) 2000-07-24 2002-12-10 Bbnt Solutions Llc Cluster head resignation to improve routing in mobile communication systems
US7023818B1 (en) 2000-07-27 2006-04-04 Bbnt Solutions Llc Sending messages to radio-silent nodes in ad-hoc wireless networks
US6973053B1 (en) 2000-09-12 2005-12-06 Bbnt Solutions Llc Using direct cluster member to cluster member links to improve performance in mobile communication systems
US6771651B1 (en) * 2000-09-29 2004-08-03 Nortel Networks Limited Providing access to a high-capacity packet network
US6973039B2 (en) * 2000-12-08 2005-12-06 Bbnt Solutions Llc Mechanism for performing energy-based routing in wireless networks
US7116640B2 (en) * 2000-12-22 2006-10-03 Mitchell Paul Tasman Architecture and mechanism for forwarding layer interfacing for networks
NO20006683D0 (no) * 2000-12-28 2000-12-28 Abb Research Ltd Fremgangsmåte for tidssynkronisering
AU2002306436A1 (en) * 2001-02-12 2002-10-15 Asm America, Inc. Improved process for deposition of semiconductor films
JP3930258B2 (ja) * 2001-02-27 2007-06-13 株式会社日立製作所 インターネットローミング方法
US6853617B2 (en) * 2001-05-09 2005-02-08 Chiaro Networks, Ltd. System and method for TCP connection protection switching
US7120456B1 (en) 2001-11-07 2006-10-10 Bbn Technologies Corp. Wireless terminals with multiple transceivers
US7389536B2 (en) * 2001-11-14 2008-06-17 Lenovo Singapore Pte Ltd. System and apparatus for limiting access to secure data through a portable computer to a time set with the portable computer connected to a base computer
US7334125B1 (en) 2001-11-27 2008-02-19 Cisco Technology, Inc. Facilitating secure communications among multicast nodes in a telecommunications network
US20030154254A1 (en) * 2002-02-14 2003-08-14 Nikhil Awasthi Assisted messaging for corporate email systems
US6934876B1 (en) * 2002-06-14 2005-08-23 James L. Holeman, Sr. Registration system and method in a communication network
US7164919B2 (en) 2002-07-01 2007-01-16 Qualcomm Incorporated Scheduling of data transmission for terminals with variable scheduling delays
US8320241B2 (en) * 2002-07-30 2012-11-27 Brocade Communications System, Inc. Fibre channel network employing registered state change notifications with enhanced payload
US7251690B2 (en) * 2002-08-07 2007-07-31 Sun Microsystems, Inc. Method and system for reporting status over a communications link
US7822688B2 (en) * 2002-08-08 2010-10-26 Fujitsu Limited Wireless wallet
US20040107170A1 (en) * 2002-08-08 2004-06-03 Fujitsu Limited Apparatuses for purchasing of goods and services
US7784684B2 (en) * 2002-08-08 2010-08-31 Fujitsu Limited Wireless computer wallet for physical point of sale (POS) transactions
US7801826B2 (en) * 2002-08-08 2010-09-21 Fujitsu Limited Framework and system for purchasing of goods and services
KR100493234B1 (ko) * 2002-11-25 2005-06-02 한국전자통신연구원 노드 시스템, 이를 이용한 이중링 통신 시스템 및 그 통신방법
US7406535B2 (en) * 2002-12-20 2008-07-29 Symantec Operating Corporation Role-based message addressing for a computer network
US7467194B1 (en) 2002-12-20 2008-12-16 Symantec Operating Corporation Re-mapping a location-independent address in a computer network
US7653059B1 (en) 2002-12-20 2010-01-26 Symantec Operating Corporation Communication sessions for a computer network
US8370523B1 (en) 2002-12-20 2013-02-05 Symantec Operating Corporation Managing routing information for a computer network
US8275864B1 (en) 2002-12-20 2012-09-25 Symantec Operating Corporation Peer-to-peer network with recovery capability
US7404006B1 (en) 2002-12-20 2008-07-22 Symantec Operating Corporation Publishing a network address in a computer network
US7327741B1 (en) 2002-12-20 2008-02-05 Symantec Operating Corporation Detecting and breaking cycles in a computer network
US7292585B1 (en) 2002-12-20 2007-11-06 Symantec Operating Corporation System and method for storing and utilizing routing information in a computer network
US7983239B1 (en) 2003-01-07 2011-07-19 Raytheon Bbn Technologies Corp. Systems and methods for constructing a virtual model of a multi-hop, multi-access network
US6934298B2 (en) * 2003-01-09 2005-08-23 Modular Mining Systems, Inc. Hot standby access point
US20040236800A1 (en) * 2003-05-21 2004-11-25 Alcatel Network management controlled network backup server
US20040246902A1 (en) * 2003-06-02 2004-12-09 Weinstein Joseph J. Systems and methods for synchronizing multple copies of a database using datablase digest
US8886705B1 (en) 2003-06-30 2014-11-11 Symantec Operating Corporation Goal-oriented storage management for a distributed data storage network
US7590693B1 (en) 2003-07-17 2009-09-15 Avaya Inc. Method and apparatus for restriction of message distribution for security
US7881229B2 (en) * 2003-08-08 2011-02-01 Raytheon Bbn Technologies Corp. Systems and methods for forming an adjacency graph for exchanging network routing data
US7606927B2 (en) * 2003-08-27 2009-10-20 Bbn Technologies Corp Systems and methods for forwarding data units in a communications network
US7668083B1 (en) 2003-10-28 2010-02-23 Bbn Technologies Corp. Systems and methods for forwarding data in a communications network
US7555527B1 (en) 2003-11-07 2009-06-30 Symantec Operating Corporation Efficiently linking storage object replicas in a computer network
US7680950B1 (en) 2003-11-07 2010-03-16 Symantec Operating Corporation Efficient search for storage objects in a network
US8060619B1 (en) 2003-11-07 2011-11-15 Symantec Operating Corporation Direct connections to a plurality of storage object replicas in a computer network
US7570600B1 (en) 2003-12-17 2009-08-04 Symantec Operating Corporation Overlay network with efficient routing and recovery
US7650509B1 (en) 2004-01-28 2010-01-19 Gordon & Howard Associates, Inc. Encoding data in a password
US7877605B2 (en) * 2004-02-06 2011-01-25 Fujitsu Limited Opinion registering application for a universal pervasive transaction framework
US8413155B2 (en) 2004-03-13 2013-04-02 Adaptive Computing Enterprises, Inc. System and method for a self-optimizing reservation in time of compute resources
KR100533686B1 (ko) * 2004-05-21 2005-12-05 삼성전자주식회사 모바일 애드 혹 네트워크에서의 데이터 전송 방법 및 이를이용한 네트워크 장치
US7698552B2 (en) * 2004-06-03 2010-04-13 Intel Corporation Launching a secure kernel in a multiprocessor system
US20070266388A1 (en) 2004-06-18 2007-11-15 Cluster Resources, Inc. System and method for providing advanced reservations in a compute environment
US8176490B1 (en) 2004-08-20 2012-05-08 Adaptive Computing Enterprises, Inc. System and method of interfacing a workload manager and scheduler with an identity manager
US7190633B2 (en) 2004-08-24 2007-03-13 Bbn Technologies Corp. Self-calibrating shooter estimation
US7126877B2 (en) * 2004-08-24 2006-10-24 Bbn Technologies Corp. System and method for disambiguating shooter locations
WO2006053093A2 (en) 2004-11-08 2006-05-18 Cluster Resources, Inc. System and method of providing system jobs within a compute environment
US8863143B2 (en) * 2006-03-16 2014-10-14 Adaptive Computing Enterprises, Inc. System and method for managing a hybrid compute environment
WO2006107531A2 (en) 2005-03-16 2006-10-12 Cluster Resources, Inc. Simple integration of an on-demand compute environment
US9231886B2 (en) 2005-03-16 2016-01-05 Adaptive Computing Enterprises, Inc. Simple integration of an on-demand compute environment
CA2603577A1 (en) 2005-04-07 2006-10-12 Cluster Resources, Inc. On-demand access to compute resources
US9137256B2 (en) * 2005-05-10 2015-09-15 Tara Chand Singhal Method and apparatus for packet source validation architechure system for enhanced internet security
JP4665617B2 (ja) * 2005-06-10 2011-04-06 沖電気工業株式会社 メッセージ認証システム,メッセージ送信装置,メッセージ受信装置,メッセージ送信方法,メッセージ受信方法およびプログラム
US7688739B2 (en) * 2005-08-02 2010-03-30 Trilliant Networks, Inc. Method and apparatus for maximizing data transmission capacity of a mesh network
WO2007035655A2 (en) 2005-09-16 2007-03-29 The Trustees Of Columbia University In The City Of New York Using overlay networks to counter denial-of-service attacks
JP4667194B2 (ja) * 2005-10-07 2011-04-06 株式会社エヌ・ティ・ティ・ドコモ 規制制御システム、無線通信端末装置、規制制御方法、無線通信端末制御方法
KR100757872B1 (ko) * 2006-02-06 2007-09-11 삼성전자주식회사 네트워크에서의 혼잡 발생 예고 시스템 및 방법
US20070194881A1 (en) 2006-02-07 2007-08-23 Schwarz Stanley G Enforcing payment schedules
EP2080124A4 (en) * 2006-07-09 2013-10-16 Microsoft Amalgamated Company Iii SYSTEMS AND METHODS FOR MANAGING NETWORKS
US9026267B2 (en) 2007-03-09 2015-05-05 Gordon*Howard Associates, Inc. Methods and systems of selectively enabling a vehicle by way of a portable wireless device
US20080304437A1 (en) * 2007-06-08 2008-12-11 Inmarsat Global Ltd. TCP Start Protocol For High-Latency Networks
JP4944716B2 (ja) * 2007-09-10 2012-06-06 サンデン株式会社 無線通信モデム
US7773519B2 (en) * 2008-01-10 2010-08-10 Nuova Systems, Inc. Method and system to manage network traffic congestion
US20090238070A1 (en) * 2008-03-20 2009-09-24 Nuova Systems, Inc. Method and system to adjust cn control loop parameters at a congestion point
US8174359B1 (en) 2008-04-30 2012-05-08 Hme Wireless, Inc. Systems and methods for automatically programming pagers
WO2010003113A1 (en) * 2008-07-03 2010-01-07 The Trustees Of Columbia University In The City Of New York Methods and systems for controlling traffic on a communication network
US8437223B2 (en) * 2008-07-28 2013-05-07 Raytheon Bbn Technologies Corp. System and methods for detecting shooter locations from an aircraft
US8686841B2 (en) 2008-12-12 2014-04-01 Gordon*Howard Associates, Inc. Methods and systems related to activating geo-fence boundaries and collecting location data
US8581712B2 (en) 2008-12-12 2013-11-12 Gordon * Howard Associates, Inc . Methods and systems related to establishing geo-fence boundaries
US8659404B2 (en) 2008-12-12 2014-02-25 Gordon Howard Associates, Inc. Methods and systems related to establishing geo-fence boundaries and collecting data
US8018329B2 (en) 2008-12-12 2011-09-13 Gordon * Howard Associates, Inc. Automated geo-fence boundary configuration and activation
US8798045B1 (en) 2008-12-29 2014-08-05 Juniper Networks, Inc. Control plane architecture for switch fabrics
US8918631B1 (en) 2009-03-31 2014-12-23 Juniper Networks, Inc. Methods and apparatus for dynamic automated configuration within a control plane of a switch fabric
US8139504B2 (en) * 2009-04-07 2012-03-20 Raytheon Bbn Technologies Corp. System, device, and method for unifying differently-routed networks using virtual topology representations
US8311085B2 (en) 2009-04-14 2012-11-13 Clear-Com Llc Digital intercom network over DC-powered microphone cable
US9049617B2 (en) 2009-09-23 2015-06-02 At&T Intellectual Property I, L.P. Signaling-less dynamic call setup and teardown by utilizing observed session state information
US8320217B1 (en) 2009-10-01 2012-11-27 Raytheon Bbn Technologies Corp. Systems and methods for disambiguating shooter locations with shockwave-only location
US11720290B2 (en) 2009-10-30 2023-08-08 Iii Holdings 2, Llc Memcached server functionality in a cluster of data processing nodes
US10877695B2 (en) 2009-10-30 2020-12-29 Iii Holdings 2, Llc Memcached server functionality in a cluster of data processing nodes
US8845836B2 (en) * 2009-12-23 2014-09-30 The Goodyear Tire & Rubber Company Geodesic tire and method of manufacture
US8855102B2 (en) * 2010-01-29 2014-10-07 Elster Solutions, Llc Wireless communications providing interoperability between devices capable of communicating at different data rates
AU2011210743A1 (en) * 2010-01-29 2012-07-26 Elster Solutions, Llc Clearing redundant data in wireless mesh network
US8694654B1 (en) 2010-03-23 2014-04-08 Juniper Networks, Inc. Host side protocols for use with distributed control plane of a switch
US8718063B2 (en) * 2010-07-26 2014-05-06 Juniper Networks, Inc. Methods and apparatus related to route selection within a network
US9282060B2 (en) 2010-12-15 2016-03-08 Juniper Networks, Inc. Methods and apparatus for dynamic resource management within a distributed control plane of a switch
US8560660B2 (en) 2010-12-15 2013-10-15 Juniper Networks, Inc. Methods and apparatus for managing next hop identifiers in a distributed switch fabric system
US9391796B1 (en) 2010-12-22 2016-07-12 Juniper Networks, Inc. Methods and apparatus for using border gateway protocol (BGP) for converged fibre channel (FC) control plane
US9106527B1 (en) 2010-12-22 2015-08-11 Juniper Networks, Inc. Hierarchical resource groups for providing segregated management access to a distributed switch
US8581711B2 (en) 2011-03-22 2013-11-12 Gordon*Howard Associates, Inc. Methods and systems of rule-based intoxicating substance testing associated with vehicles
ES2408131B1 (es) * 2011-05-12 2014-06-05 Telefónica, S.A. Sistema y método para interconexión de redes de distribución de contenido
US8781900B2 (en) 2011-09-09 2014-07-15 Gordon*Howard Associates, Inc. Method and system of providing information to an occupant of a vehicle
GB2495489A (en) * 2011-10-10 2013-04-17 Anthony Ward Method and system for encryption/decryption of data comprising the generation of a codebook
CN103139843B (zh) * 2011-11-30 2018-07-31 中兴通讯股份有限公司 一种优先级扩展队列实现方法及系统
US9565159B2 (en) 2011-12-21 2017-02-07 Juniper Networks, Inc. Methods and apparatus for a distributed fibre channel control plane
US9665997B2 (en) 2013-01-08 2017-05-30 Gordon*Howard Associates, Inc. Method and system for providing feedback based on driving behavior
US9639906B2 (en) 2013-03-12 2017-05-02 Hm Electronics, Inc. System and method for wideband audio communication with a quick service restaurant drive-through intercom
US9840229B2 (en) 2013-03-14 2017-12-12 Gordon*Howard Associates, Inc. Methods and systems related to a remote tamper detection
US10536565B2 (en) * 2013-03-14 2020-01-14 International Business Machines Corporation Efficient centralized stream initiation and retry control
US9378480B2 (en) 2013-03-14 2016-06-28 Gordon*Howard Associates, Inc. Methods and systems related to asset identification triggered geofencing
US8928471B2 (en) 2013-03-14 2015-01-06 Gordon*Howard Associates, Inc. Methods and systems related to remote tamper detection
US9035756B2 (en) 2013-03-14 2015-05-19 Gordon*Howard Associates, Inc. Methods and systems related to remote tamper detection
US9013333B2 (en) 2013-06-24 2015-04-21 Gordon*Howard Associates, Inc. Methods and systems related to time triggered geofencing
US20150145875A1 (en) * 2013-11-27 2015-05-28 Aashish Pangam Command scheduler for a display device
RU2713851C1 (ru) * 2015-08-05 2020-02-07 АйПиКОМ ГМБХ УНД КО. КГ Способ передачи сообщений между узлами одночастотной сети связи
US9843550B2 (en) * 2015-11-29 2017-12-12 International Business Machines Corporation Processing messages in a data messaging system using constructed resource models
US9701279B1 (en) 2016-01-12 2017-07-11 Gordon*Howard Associates, Inc. On board monitoring device
CN106878957B (zh) 2017-03-10 2019-05-14 Oppo广东移动通信有限公司 广播队列生成方法、装置和终端设备
WO2019004901A1 (en) * 2017-06-26 2019-01-03 Telefonaktiebolaget Lm Ericsson (Publ) CONTROL SIGNALING IN A WIRELESS COMMUNICATION SYSTEM TO PREVENT ATTACKS DEPENDING INTEGRITY AND TIMER PROTECTION RULES
CN115714742A (zh) * 2018-05-11 2023-02-24 华为技术有限公司 一种报文发送的方法、网络节点和系统
US20230412534A1 (en) * 2019-04-30 2023-12-21 William Michael Pearce Method of Detecting Incomplete Instant Messaging Record Sets using Sequential Numbering
US20230262040A1 (en) * 2019-04-30 2023-08-17 William Michael Pearce Method of Detecting Incomplete Electronic Record Sets using Sequential Numbering
US11044198B1 (en) * 2020-08-05 2021-06-22 Coupang Corp. Systems and methods for pooling multiple user requests to mitigate network congestion
CN113301605B (zh) * 2021-05-18 2023-03-24 成都欧珀通信科技有限公司 消息传输方法、系统及相关装置

Family Cites Families (52)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US4023163A (en) * 1975-09-19 1977-05-10 Johnson Controls, Inc. High security alarm transmission system
US4885778A (en) * 1984-11-30 1989-12-05 Weiss Kenneth P Method and apparatus for synchronizing generation of separate, free running, time dependent equipment
US4901277A (en) * 1985-09-17 1990-02-13 Codex Corporation Network data flow control technique
US5416827A (en) 1985-11-27 1995-05-16 Seiko Communications Holding Nv Paging system with registration mode which interrupts the pager's standard operating protocol and is energized with a higher duty cycle
US5079767A (en) * 1988-09-27 1992-01-07 Digital Equipment Corporation Method of multicast message distribution
US5113499A (en) * 1989-04-28 1992-05-12 Sprint International Communications Corp. Telecommunication access management system for a packet switching network
US5455865A (en) * 1989-05-09 1995-10-03 Digital Equipment Corporation Robust packet routing over a distributed network containing malicious failures
US5175765A (en) * 1989-05-09 1992-12-29 Digital Equipment Corporation Robust data broadcast over a distributed network with malicious failures
US5138615A (en) * 1989-06-22 1992-08-11 Digital Equipment Corporation Reconfiguration system and method for high-speed mesh connected local area network
US5081678A (en) * 1989-06-28 1992-01-14 Digital Equipment Corporation Method for utilizing an encrypted key as a key identifier in a data packet in a computer network
FI894371A (fi) * 1989-09-15 1991-03-16 Nokia Mobile Phones Ltd Telefonsystem.
CA2075048C (en) * 1990-01-30 1999-08-17 Gregory A. Pascucci Networked facilities management system
US5153902A (en) * 1990-04-27 1992-10-06 Telefonaktiebolaget L M Ericsson Multi-exchange paging system for locating a mobile telephone in a wide area telephone network
CA2040234C (en) * 1991-04-11 2000-01-04 Steven Messenger Wireless coupling of devices to wired network
US5319638A (en) * 1991-09-12 1994-06-07 Bell Communications Research, Inc. Link-by-link congestion control for packet transmission systems
EP0537903A2 (en) * 1991-10-02 1993-04-21 International Business Machines Corporation Distributed control system
EP0546572B1 (en) * 1991-12-12 1999-04-07 Nec Corporation Mobile communications system having central radio station for paging mobile users via base stations
US5353331A (en) 1992-03-05 1994-10-04 Bell Atlantic Network Services, Inc. Personal communications service using wireline/wireless integration
US5579379A (en) 1992-03-05 1996-11-26 Bell Atlantic Network Services, Inc. Personal communications service having a calling party pays capability
FI95758C (fi) * 1992-05-25 1996-03-11 Nokia Telecommunications Oy Sijainninpäivitys solukkoradioverkossa
US5357561A (en) * 1992-07-10 1994-10-18 Motorola, Inc. Communication unit control for wide area communication systems
US5432841A (en) * 1992-07-10 1995-07-11 Rimer; Neil A. System for locating and communicating with mobile vehicles
US5428645A (en) * 1992-11-03 1995-06-27 International Business Machines Corporation Anonymous time synchronization method
GB2272310A (en) * 1992-11-07 1994-05-11 Ibm Method of operating a computer in a network.
EP0598969B1 (en) * 1992-11-27 1999-02-10 International Business Machines Corporation Inter-domain multicast routing
US5440613A (en) 1992-12-30 1995-08-08 At&T Corp. Architecture for a cellular wireless telecommunication system
US5331634A (en) * 1993-01-29 1994-07-19 Digital Ocean, Inc. Technique for bridging local area networks having non-unique node addresses
US5574860A (en) * 1993-03-11 1996-11-12 Digital Equipment Corporation Method of neighbor discovery over a multiaccess nonbroadcast medium
CA2124974C (en) * 1993-06-28 1998-08-25 Kajamalai Gopalaswamy Ramakrishnan Method and apparatus for link metric assignment in shortest path networks
US5475735A (en) 1993-12-02 1995-12-12 Motorola, Inc. Method of providing wireless local loop operation with local mobility for a subscribed unit
CA2176032A1 (en) * 1994-01-13 1995-07-20 Bankers Trust Company Cryptographic system and method with key escrow feature
US5815577A (en) * 1994-03-18 1998-09-29 Innovonics, Inc. Methods and apparatus for securely encrypting data in conjunction with a personal computer
US5459725A (en) * 1994-03-22 1995-10-17 International Business Machines Corporation Reliable multicasting over spanning trees in packet communications networks
US5485163A (en) * 1994-03-30 1996-01-16 Motorola, Inc. Personal locator system
DE69429983T2 (de) * 1994-05-25 2002-10-17 International Business Machines Corp., Armonk Datenübertragungsnetz und Verfahren zum Betreiben des Netzes
US5475682A (en) * 1994-06-10 1995-12-12 At&T Corp. Method of regulating backpressure traffic in a packet switched network
US5751967A (en) * 1994-07-25 1998-05-12 Bay Networks Group, Inc. Method and apparatus for automatically configuring a network device to support a virtual network
ES2164084T3 (es) * 1994-09-13 2002-02-16 Cit Alcatel Metodo para modificar un arbol multidestino en una red de conmutacion.
US5633859A (en) * 1994-09-16 1997-05-27 The Ohio State University Method and apparatus for congestion management in computer networks using explicit rate indication
US5548533A (en) * 1994-10-07 1996-08-20 Northern Telecom Limited Overload control for a central processor in the switching network of a mobile communications system
US5613012A (en) * 1994-11-28 1997-03-18 Smarttouch, Llc. Tokenless identification system for authorization of electronic transactions and electronic transmissions
US5579372A (en) * 1994-12-12 1996-11-26 Telefonaktiebolaget Lm Ericsson Flow control method for short message service - busy subscriber
US5506838A (en) * 1994-12-29 1996-04-09 Emc Corporation Packet propagation and dynamic route discovery apparatus and techniques
US5577122A (en) * 1994-12-29 1996-11-19 Trimble Navigation Limited Secure communication of information
US5778068A (en) * 1995-02-13 1998-07-07 Eta Technologies Corporation Personal access management system
US5594945A (en) * 1995-02-14 1997-01-14 Bellsouth Corporation Method of providing registration reminder message to a roaming pager upon entry into a new service area
US5537395A (en) * 1995-04-13 1996-07-16 Northern Telecom Limited Method and apparatus for setting a channel congestion message in a wireless multiple access packet data system
US5649289A (en) * 1995-07-10 1997-07-15 Motorola, Inc. Flexible mobility management in a two-way messaging system and method therefor
US5805578A (en) * 1995-10-27 1998-09-08 International Business Machines Corporation Automatic reconfiguration of multipoint communication channels
US5684800A (en) * 1995-11-15 1997-11-04 Cabletron Systems, Inc. Method for establishing restricted broadcast groups in a switched network
US5724509A (en) * 1996-04-22 1998-03-03 Motorola, Inc. Method and apparatus for synchronizing implementation of configuration information in a communication system
US5872773A (en) * 1996-05-17 1999-02-16 Lucent Technologies Inc. Virtual trees routing protocol for an ATM-based mobile network

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1324485C (zh) * 2003-07-23 2007-07-04 永丰纸业股份有限公司 可携式安全信息存取系统及方法
CN1864390B (zh) * 2003-10-29 2010-10-27 思科技术公司 用于利用安全性标记提供网络安全性的方法和装置
CN100357901C (zh) * 2005-12-21 2007-12-26 华为技术有限公司 一种主设备和备份设备之间数据核查的方法
CN103748987B (zh) * 2009-07-14 2011-01-12 北京理工大学 一种基于模糊神经网络的攻击知识的自动更新方法

Also Published As

Publication number Publication date
US6173157B1 (en) 2001-01-09
AU3724297A (en) 1998-02-09
WO1998003033A1 (en) 1998-01-22
US6032258A (en) 2000-02-29
AU3724897A (en) 1998-02-09
KR20000023741A (ko) 2000-04-25
WO1998002819A1 (en) 1998-01-22
WO1998002994A1 (en) 1998-01-22
SE9900033D0 (sv) 1999-01-08
US20010012270A1 (en) 2001-08-09
AU3599997A (en) 1998-02-09
EP0976284A1 (en) 2000-02-02
GB2330284A (en) 1999-04-14
SE9900033L (sv) 1999-03-03
AU3658497A (en) 1998-02-09
CN1228909A (zh) 1999-09-15
EP0976284A4 (en) 2001-08-16
US5913921A (en) 1999-06-22
GB2330284B (en) 2000-12-20
AU3658997A (en) 1998-02-09
US6088336A (en) 2000-07-11
WO1998003024A1 (en) 1998-01-22

Similar Documents

Publication Publication Date Title
CN1228174A (zh) 计算机网络中传输安全的装置及方法
Mitchell et al. Automated analysis of cryptographic protocols using mur/spl phi
CN105577691B (zh) 一种安全访问方法和服务器
US5600722A (en) System and scheme of cipher communication
US5928363A (en) Method and means for preventing unauthorized resumption of suspended authenticated internet sessions using locking and trapping measures
US6363479B1 (en) System and method for signing markup language data
CN1323538C (zh) 一种动态身份认证方法和系统
EP1278112A1 (en) A process for providing access of a client to a content provider server under control of a resource locator server
CN101378315B (zh) 认证报文的方法、系统、设备和服务器
GB2318486A (en) Data communications using public key cryptography
CN108259437A (zh) 一种http访问方法、http服务器和系统
Gürgens et al. Security analysis of (un-) fair non-repudiation protocols
CN109300211A (zh) 一种门禁控制方法、装置及系统
CN108512849A (zh) 一种访问服务器的握手方法及系统
MX2007011639A (es) Metodo para poner en practica un mecanismo de rastreo de estado en una sesion de comunicacion entre un servidor y un sistema de cliente.
EP1398903B1 (en) Digital signature validation and generation
Gollmann et al. Authentication services in distributed systems
EP1293857A1 (en) Server access control
KR100908378B1 (ko) 에이전트를 이용한 타임스탬프 서비스 방법
CN115357915A (zh) 基于深度学习和信息隐藏的区块链方法和医康养交易系统
Toussaint A new method for analyzing the security of cryptographic protocols
Kudo Electronic submission protocol based on temporal accountability
JP2000276444A (ja) 通信装置、通信システム及びコンピュータ読み取り可能な記憶媒体
CN111193787B (zh) 同步方法及装置
JPH10322325A (ja) 暗号認証方式

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C02 Deemed withdrawal of patent application after publication (patent law 2001)
WD01 Invention patent application deemed withdrawn after publication