EP2033404A1 - Verification et correction d'erreurs de donnees d'enregistrement dans un systeme de nommage - Google Patents
Verification et correction d'erreurs de donnees d'enregistrement dans un systeme de nommageInfo
- Publication number
- EP2033404A1 EP2033404A1 EP07788994A EP07788994A EP2033404A1 EP 2033404 A1 EP2033404 A1 EP 2033404A1 EP 07788994 A EP07788994 A EP 07788994A EP 07788994 A EP07788994 A EP 07788994A EP 2033404 A1 EP2033404 A1 EP 2033404A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- node
- correction code
- identifier
- registration data
- transmitted
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000012937 correction Methods 0.000 title claims abstract description 191
- 238000012795 verification Methods 0.000 title description 3
- 230000004044 response Effects 0.000 claims abstract description 37
- 238000000034 method Methods 0.000 claims description 43
- 230000005540 biological transmission Effects 0.000 claims description 15
- 230000008569 process Effects 0.000 claims description 13
- 238000004590 computer program Methods 0.000 claims description 12
- 230000006854 communication Effects 0.000 description 26
- 238000004891 communication Methods 0.000 description 26
- 239000003795 chemical substances by application Substances 0.000 description 21
- 230000006870 function Effects 0.000 description 12
- 238000010586 diagram Methods 0.000 description 5
- 238000012545 processing Methods 0.000 description 5
- 239000004248 saffron Substances 0.000 description 5
- 230000008901 benefit Effects 0.000 description 3
- 125000004122 cyclic group Chemical group 0.000 description 3
- 230000007175 bidirectional communication Effects 0.000 description 2
- 238000001514 detection method Methods 0.000 description 2
- 238000013507 mapping Methods 0.000 description 2
- 230000003287 optical effect Effects 0.000 description 2
- 241001591005 Siga Species 0.000 description 1
- 240000008042 Zea mays Species 0.000 description 1
- 235000005824 Zea mays ssp. parviglumis Nutrition 0.000 description 1
- 235000002017 Zea mays subsp mays Nutrition 0.000 description 1
- 230000008859 change Effects 0.000 description 1
- 235000005822 corn Nutrition 0.000 description 1
- 238000012217 deletion Methods 0.000 description 1
- 230000037430 deletion Effects 0.000 description 1
- 230000000977 initiatory effect Effects 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 238000004377 microelectronic Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L1/00—Arrangements for detecting or preventing errors in the information received
- H04L1/004—Arrangements for detecting or preventing errors in the information received by using forward error control
- H04L1/0041—Arrangements at the transmitter end
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/45—Network directories; Name-to-address mapping
- H04L61/4505—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
- H04L61/4511—Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0884—Network architectures or network communication protocols for network security for authentication of entities by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
- H04L63/123—Applying verification of the received information received data contents, e.g. message integrity
Definitions
- the present invention relates to the DNS protocol ("Domain Marne System" in English) and more particularly to the secure protocol DNSSEC
- a DNS naming system is specifically designed for a public communication network comprising an infrastructure such as the Internet or an intranet network connecting nodes such as terminals or servers.
- This naming system includes records that match for each of these nodes one or more understandable names, called domain names, for example "mydomain.com", to network information relating to the node, such as text fields, identifiers cryptographic, security parameters, a mail server, or more particularly IP type addresses ("Internet Protocol" in English).
- domain names for example "mydomain.com”
- IP type addresses Internet Protocol
- These correspondences are stored in naming files stored in one or more servers dedicated to the domain name service, called DNS servers. All of these servers are publicly accessible to any client node that requests access to a domain name, in order to find the correspondence between the domain name and the network node associated with said domain name.
- the DNS system uses Dynamic Host Configuration Protocol (DHCP) servers transmits information describing the telecommunications network, for example information about DNS proxy servers, SIP gateways ( "Session Initiation Protocol” as well as the assignment and referencing of an IP address.
- DHCP Dynamic Host Configuration Protocol
- SIP gateways "Session Initiation Protocol” as well as the assignment and referencing of an IP address.
- ENE TElephone NUmber Mapping" in English
- HIP Home Identity Protocol
- the DNS system initially designed for the internet connected network is also introduced in other connected networks such as the PSTN (Switched Telephone Network) network in application with the ENUM protocol in order to merge the data of these two different types of network. networks with different protocols.
- PSTN Switchched Telephone Network
- Ad-hoc networks without an infrastructure in which nodes communicate directly with each other without a central access point.
- the transmission of data within a network of poor transmission quality from a first node to a second node generates the reception and the processing of data which once considered erroneous by the second node are again transmitted by occupying another channel of the telecommunications network.
- the present invention overcomes the disadvantages mentioned above.
- a first method according to the invention is intended to encode a registration data item relating to a first node and contained in a naming file included in a second node, in a telecommunications network.
- the first method is characterized in that it comprises the steps of: storing in the naming file an identifier of the first node in association with the registration data item, determining in a third node a correction code according to the data item recording transmitted with the identifier by the second node, and storing the correction code in the third node in association with the transmitted identifier.
- the first, second and third nodes are any nodes in the telecommunications network.
- the registration data server functions of the second node and the correction code determination functions of the third node can be performed by one and the same node of the network.
- an embodiment comprising the correction code node distinct from the server node has the advantage of securing the determination of the correction code relating to the recording data item.
- a second method according to the invention is intended to transmit registration data relating to a first node from a second node to a third node through a telecommunications network.
- the second method is characterized in that it comprises the steps of: transmitting a request including an identifier of the first node from the third node to the second node, transmitting the registration data associated with the identifier from the second node to the second node third node, and transmit an indication indicating a correction code determined according to the registration data and stored in a fourth node of the network, if the request includes a correction code request, from the fourth node to another node .
- the first node corresponds to any node present in the telecommunication network
- the second node corresponds to a server node
- the third node corresponds to a client node that requires registration data
- the fourth node corresponds to a correction code node. .
- Said other node may be the third node, the second node and the fourth node may be merged and said indication indicating a correction code may be the correction code itself.
- the indication is the correction code and is transmitted from the fourth node to the third node through the second node.
- the method then comprises a transmission of the request for a correction code extracted from the request transmitted by the third node, from the second node to the fourth node.
- the indication is the correction code.
- the method then comprises transmitting the correction code request extracted from the request transmitted by the third node, from the second node to the fourth node, and transmitting the correction code from the fourth node to the third node.
- the indication is an address of the fourth node.
- the method then includes transmitting the identifier of the first node from the third node to the fourth node in response to the address of the fourth node, and transmitting the correction code in association with the identifier from the fourth node to the fourth node. third node.
- a third method according to the invention is intended to verify a record data relating to a first node transmitted from a second node to a third node through a telecommunications network.
- the third method is characterized in that it comprises the steps of: transmitting a request including an identifier to the first node and a correction code request from the third node to the second node, transmitting the registration data associated with the first node; an identifier from the second node to the third node and a correction code determined according to the registration data and stored in a fourth node of the network, from the fourth node to the third node, and checking the accuracy of the registration data transmitted according to the correction code in the third node.
- the third method may further comprise a correction of the registration data verified according to the transmitted correction code if the registration data is deemed to be inaccurate.
- the transmission of a correction code associated with a required registration data and transmitted from the server node or a correction code node to the client node has the advantage that during a disturbed transmission of said registration data to detect errors in the registration data and correct it in the client node.
- This data correction avoids exchanging additional requests and responses between the two nodes to obtain correct registration data and to encumber the telecommunications network unnecessarily.
- the invention also relates to nodes, such as a node said server node participating in the determination of correction codes and / or carrying out functions of record data transmission server, a node called correction code node determining correction codes based on registration data and a node said client node checking registration data relating to other nodes, to implement the method achievements of the invention.
- Any node in the network can provide for other nodes of the network one or more of the preceding functions performed by a server node and / or a correction code node and / or a client node.
- a server node for encoding registration data relating to a first node in a telecommunications network, and containing a naming file is characterized in that it comprises: means for storing in the naming file an identifier of the first node node in association with the registration data, means for determining a correction code according to the registration data transmitted with the identifier by the second node, and means for storing the correction code in association with the transmitted identifier.
- a correction code node for encoding registration data relating to a first node in a telecommunications network, is characterized in that it comprises: means for determining a correction code as a function of the registration data transmitted with an identifier of the first node by a second node of the network, said identifier being associated with the registration data in a naming file contained in the second node, and means for storing the correction code in association with the transmitted identifier.
- a server node for transmitting registration data relating to a first node to a third node through a telecommunications network, is characterized in that it comprises: means for receiving a request including an identifier of the first node transmitted from the third node, and means for transmitting the registration data associated with the identifier to the third node, so that an indication indicating a correction code determined according to the registration data and stored in a fourth node of the network is transmitted from the fourth node to another node, if the request includes a correction code request.
- a client node for verifying a registration data relating to a first node transmitted from a second node through a telecommunications network, is characterized in that it comprises: a means for transmitting a request including a identifier of the first node and a correction code request to the second node, means for receiving the registration data associated with the identifier from the second node and a correction code determined according to the registration data and stored in a fourth network node, from the fourth node, and means for verifying the accuracy of the transmitted registration data according to the correction code.
- the invention relates to computer programs capable of being implemented respectively in the server node, the correction code node and the client node, said programs comprising code instructions which, when the programs are executed. in said nodes, perform the steps according to the method embodiments of the invention.
- FIG. 1 is a schematic block diagram of a first embodiment of a naming system including a client node and a server node according to the invention
- FIG. 2 is: a detailed block diagram of the naming system
- FIG. 3 is a representative diagram of a naming file included in a server node according to the invention.
- FIG. 4 is a representative diagram of fields composing a registration data error correction transmitted by the server node according to the invention
- FIG. 5 is an algorithm of a method for verifying and correcting registration data according to the first embodiment of the invention
- FIG. 6 is a schematic block diagram of a second embodiment of a naming system including a client node, a server node and a correction code node according to the invention
- FIGS. 7 and 8 are two algorithms of a method for checking and correcting recording data according to the second embodiment of the invention.
- a first embodiment of a DNS type naming system comprises at least one NCL client node. communicating via an RT telecommunications network with an NS server node.
- the client node can provide server node functions for nodes in the network.
- the serving node may provide client node functions for nodes in the network.
- the server node may be connected to or include a database containing at least one FN naming file.
- the naming file FN comprises records each associating an accessibility datum of a node of the network RT, called in the following of the given description of registration, to an identifier of this node.
- a record matches an understandable name assigned to the node with an internet address to access that node.
- ENUM specification (“Telephony N ⁇ mber Mapping") which is based on the DNS specification, a record matches a number in the usual telephone format of type E164 assigned to a node to a set of information of the node or its user such as another E164 type number, an IP address or an e-mail address.
- a naming file is described in more detail with reference to FIG.
- Nodes are entities such as a server, a mobile terminal, or a personal computer.
- the NCL client node is, for example, a terminal that, via the network RT, such as a conventional telecommunications network with an Internet-type infrastructure, requires registration data at a server node NS, for example a DNS server.
- the telecommunications network RT esc an ad-hoc network devoid of infrastructure where the nodes NS and NCL communicate. directly between them without going through a centralization point such as an access point.
- the server node NS is for example a user terminal which comprises an FN naming file containing the own registration data of the server node NS, or a copy of registration data relating to another node and obtained during an earlier request to a DNS server.
- the client node NCL wishes to obtain registration data relating to a node Na of the network and contained in the naming file FN of the server node NS.
- the client node NCL interrogates the server node NS by transmitting through the network RT a request RQ containing an identifier ID_Na of the node Na.
- the server node NS returns a response Rp containing a record data D_RRa associated with the identifier ID_JSIa in the file FN and an error correction data D_Ca in order to detect a possible transmission error of the data D_RRa and thus the correct.
- the client node NCL Upon receipt of the response RP, the client node NCL verifies the accuracy of the registration data D_RRa according to the error correction data D__Ca. If the data D_RRa is inaccurate, the NCL corrects it according to the error correction data D Ca and processes it.
- the client node NCL and the server node NS in FIG. 1 are more detailed in FIG. 2 in the form of functional blocks, most of which provide functions relating to the invention and can correspond to software and / or hardware modules.
- the NS server node and the NCL client node have modules that implement the method for checking and correcting registration data error of the invention described with reference to FIG.
- the server node NS comprises a network interface 1RS, a communication unit UCS, a file management unit UFS, a specific unit USS and a memory MS.
- the USS specific unit characterizes the node, for example the central processing unit of a personal computer PC, a server or a mobile terminal. All the modules of the server node are connected by a bidirectional communication bus BS.
- the server node NS communicates with the NCL client node via the network interface 1RS to receive requests from said client node and transmit responses to said requests.
- the 1RS interface of the NS server node can transmit requests to a DlSIS server and receive responses to the transmitted requests.
- the UCS communication unit of the server node interprets the received RQ requests and establishes RP responses to said requests.
- the received and interpreted requests are processed by the UFS naming file management unit which searches the FN file in the MS for the required registration data.
- the UFS unit also manages the updating of the file FN following the introduction, deletion or change of managed node profiles in the network RT or following the transmission of a new copy the FN file from, for example, a DNS server.
- the UFS unit also determines for each registration data of the naming file FN an error correction data by applying on the record data a predefined error correction algorithm. Each error correction data is saved in the FN file.
- the functionality of UCS, UFS and USS can be realized as software modules implemented in the NS server node and executed by a central processing unit of the NS node.
- the memory MS contains, among others, the naming file FN and an error correction establishment algorithm AG identified by an algorithm identifier 1 ⁇ G.
- the error correction setting algorithm corresponds to a cyclic redundancy check (CRC) algorithm in which the bit sequence of a record data is treated as a binary polynomial.
- CRC cyclic redundancy check
- the result obtained is an error correction code contained in the error correction data associated with said recording datum, and corresponds to the remainder of the polynomial division of said binary polynomial by a predefined programming polynomial PG.
- the generator polynomial PG is stored in the memory MS and is identified by an identifier I_PG.
- the NCL client node comprises an IRC network interface, a UCC communication unit, a USC specific unit and an MC memory.
- the USC specific unit characterizes the NCL node, for example the central processing unit of a personal computer PC, a server or a mobile terminal. All modules of the node are connected by a bidirectional communication bus BC.
- the NCL communicates with the NS server node via the IRC network interface to transmit RQ requests to the NS server node and receive RP responses to said requests.
- the UCC communication unit of the NCL node establishes the RQ requests and interprets the RP responses to said requests.
- the UCC communication unit verifies the accuracy of the received data record. If this is found to be wrong, the UCC corrects it.
- the functionality of the UCC and USC units can be realized as software modules implemented in the node and executed by a central processing unit of the node.
- the memory MC contains, inter alia, an error detection and correction algorithm AG which is the inverse algorithm of the error correction establishment algorithm AG stored in the memory MS of the server node NS.
- the algorithm AG x is stored and identified by an identifier I_AG identical to that of the algorithm AG, and the generator polynomial PG and the identifier I_PG are stored.
- the registration data of the nodes of the network RT are recorded in FN naming files arranged in tree structure according to their kinship domain.
- one domain contains all E164 type numbers beginning with "01”, another domain lists numbers beginning with "02" and so on, each of these domains having subdomains listing the numbers according to other characteristics.
- Each of these domains and / or subdomains is characterized by a naming file.
- the MS memory of the server node KS may contain one or more FN naming files.
- each FN naming file according to the invention is identified by a domain identifier I_D and comprises records, of which only two RRa and RRb are illustrated and respectively associate identifiers ID_Na and ID_Nb assigned to nodes.
- Na and Nb of the network RT to record data D_RRa and D ⁇ RRb of the nodes Na and Nb.
- the identifier IDJMa, IDJMb is for example a domain name according to the DNS specification, a type E164 standard telephone number according to the ENUM specification or a cryptographic identifier according to the HIT specification.
- the registration data D_RRa, D_RRb is the data required during a request from the client node NCL containing the identifier ID_Na, ID_Nb associated.
- the registration data is for example of the form "2001: 2: 56" for a record linked to an IP address (Internet Protocol "in English), of the form" servername_mail. corn "for a record linked to an e-mail server, or a text for a record related to the description of a profile.
- a record such as RRa is written in the form of a registration field including among others, the identifier ID_Na, a type TYa characterizing the record, and the record data D ⁇ RRa.
- the type TYa characterizes the recording by indicating for example that the registration data D RRa is relative to an IPv4 address "A", a name of "MX” e-mail server or "TXT” text.
- RRa record field In order to conform to the DNS / DNSSEC specification, other informative elements are inserted in the RRa record field, such as a class CLa of the record, for example the class "IN” relative to the internet, and TTLa ("Time To Live") life of the RRa record.
- a class CLa of the record for example the class "IN” relative to the internet
- TTLa Time To Live
- each recording field RRa, RRb is associated an error correction field comprising a type CRa, CRb characterizing the field, an error correction class CLca, CLcb, a lifetime of TTLca error correction, TTLcb, and error correction data D_Ca, D_Cb.
- the error correction field and more particularly the error correction data D__Ca transmitted at the same time as the recording data D__RRa serve to assist in the detection of error in the data transmitted and, if appropriate, to correct the erroneous data in order to obtain the required registration data.
- the error correction data D_Ca of the RRa record is shown in Figure 4 and includes subfields C1 to C9.
- the subfields C2, C8 and C9 are more particularly related to the invention.
- the subfield C2 comprises the identifier I_AG of the error correction establishment algorithm used to obtain an error correction code Ca included in the subfield C9.
- the subfield C8 includes the identifier I_PG of the generator polynomial, or the generator polynomial itself when the MC memory NCL client node does not entrust the polynomial.
- the error correction code Ca included in the subfield C9 is determined by applying the error correction establishment algorithm AG to the registration data D_RRa.
- the remainder of the polynomial division of the bit sequence composing the data D_RRa by the generator polynomial PG constitutes the error correction code Ca.
- the registration data item D RRa is concatenated with the data included in the subfields C1. to CB of the error correction data D_Ca, and thus concatenated in particular to the identifier of the error correction algorithm I_AG and the identifier I_PG of the generator polynomial PG.
- the result of the concatenation is applicable to the error correction establishment algorithm AG in order to determine the associated error correction code Ca transmitted with the registration data from the server node to the client node.
- the other subfields are present so that the invention conforms to the DNS / DNSSEC specification.
- the subfield Cl includes the type TYa of the RRa record covered by the error correction field.
- the subfield C3 corresponds to the hierarchical location of the domain or sub-domain relating to the RRa record in the tree of the DNS type.
- Subfield C4 includes the TTLa lifetime of the RRa record.
- Subfields C5 and C6 are respectively the end and start dates of the registration data D__RRa.
- the current date when checking the accuracy of the D_RRa data by The NCL node is between the start and end dates.
- the scus-field C7 contains the domain identifier IJD identifying the file FN.
- each recording field RRa, RRb is associated a signature field comprising a type SIGa, SIGb characterizing the field, a signature class CLsa, CLsb, a signature lifetime TTLsa , TTLsb, and a signature data D_Sa, D Sb including a signature of the recording data D_RRa, DJlRb.
- the signature field and more particularly the signature data D_Sa, D_Sb transmitted at the same time as the associated recording data D_RRa, DJRRb serve to authenticate the origin and to guarantee the integrity of the registration data D_RRa. , D_RRb.
- To this signature data can be associated an error correction field as described above, the error correction data of said field being determined according to the signature data.
- the method of checking and correcting registration data error of the DNS naming system includes steps
- step E1 the name file management unit UH 1 S in the server node KS updates the naming file FN. For example, a new node
- the UFS stores the RRa record in the FK file as shown in Figure 3.
- the UFS also determines the error correction data. D_Ca according to the recording data D___RRa associated with the recording RRa, as described with reference to FIG. 4, and storing the data D__Ca of the error correction field in the file FN.
- a signature data D_Sa of the registration data RRa is determined and stored in the file FN. This update is performed at any time on demand by an operator of the network RT, or periodically.
- the client node NCL wishes to initiate a communication with a node Na of the network RT by knowing only the identifier ID_Na of the node Na.
- step E2 the UCC communication unit of the NCL node establishes a request RQ containing at least the identifier ID_Na, which is transmitted by the IRC network interface of the NCL node to the server node NS through the network RT .
- the request RQ may also contain a request for a DCC error correction code, in order to detect a possible transmission error of the data D_RRa and thus correct it.
- step E3 the 1RS network interface of the server node NS receives the request RQ which is processed by the communication unit UCS of the server node NS. According to the identifier IDJNa extracted from the request RQ, the file management unit naming
- step E4 the UFS verifies whether a DCC error correction code request is included in the RQ request. If no request
- the communication unit UCS establishes a response RP transmitted by the network interface 1RS from the server node NS to the client node NCL through the network RT and containing the requested data D_RRa associated with the identifier ID__Na.
- the UCC communication unit of the NCL client node processes the data D_RRa in step E7.
- the UCS communication unit establishes a response RP which is transmitted by the NSRS network interface of the server node NS to the NCL client node through the RT network.
- the response RP comprises the identifier ID__Na, the recording data DJRRa and the error correction data D_Ca which notably contains the identifier I__AG of the error correction algorithm AG, the identifier I_PG of the generator polynomial PG and the error correction code Ca.
- the requests and responses exchanged between the NS server node and the NCL client node are in accordance with the DNS requests and responses.
- step E5 the IRC network interface of the NCL client node receives the response RP.
- the client node's UCC communication unit finds the error correction algorithm AG and the generator polynomial PG in the memory MC.
- the communication unit UCC verifies the accuracy of the recording data transmitted D__RRa.
- the record data transmitted D_RRa is concatenated with the error correction code transmitted Ca into a concatenation data which is divided by the generator polynomial PG. If the division result is zero, then the registration data has been successfully transmitted and is processed in step E7 by the USC specific unit of the NCL client node.
- step E5 the registration data is incorrect.
- the communication unit UCC corrects the data by application of the error correction algorithm AG with the error correction code Ca to the transmitted registration data D_RRa.
- the error correction algorithm is implemented to determine a most probable registration data based on the error correction code Ca.
- the new determined registration data is again tested in step E5 by concatenating the error correction code Ca and the registration data determined into a concatenation data, and dividing the concatenation data by the concatenation data. PG generator polynomial. If the result is zero, then the determined registration data is correct and is processed in step E7 by the USC specific unit of the client node NCL. In the opposite case, a new registration data is determined in step E6. The loop of steps E5 and E ⁇ is repeated a predetermined number, for example between 2 and 5, to converge to a substantially zero recurring division result and therefore to a relatively correct determined registration data.
- step E4 the server node NS transmits in the response RP, together with the identifier ID_Na of the node Na and the registration data D__RRa, a first error correction data D_Ca associated with the data item. recording, the signature data D Sa also associated with the registration data and a second error correction data comprising an error correction code determined according to the signature data and associated therewith.
- the OCC unit of the NCL node checks the accuracy of the transmitted signature data according to the second transmitted error correction data, similarly to the verification of the accuracy of the registration data D_RRa according to the first error correction data transmitted D__Ca, described in step E4.
- the UCC unit does not correct said signature data and decides not to execute the steps E5 to E7, or possibly to execute them.
- step E7 when the registration data D_RRa is deemed to be correct, the UCC unit verifies the authentication and the integrity of the transmitted registration data as a function of the signature data D Sa. If the registration data D_RRa is not authenticated, the UCC unit decides not to process the registration data D_RRa. In the opposite case, the unit UCC processes the data D_RRa.
- a second embodiment of a DNS type naming system comprises an NCL client node, a server node NS and an NCO correction code node communicating with each other via a telecommunications network RT.
- the NCL client node and the NS server node are substantially analogous to the NCL and NS nodes of Figures 1 and 2 except that the NS node no longer includes error correction data stored in the FN naming file.
- the client node and the server node can further provide correction code node functions for nodes of the network.
- the NCO correction code node may provide server node and / or client node functions for nodes in the network.
- the NCO correction code node comprises a UGO error correction code management unit and an MCO error correction code memory.
- the unit UGO determines the error correction codes Ca, Cb according to the recording data RRa, RRb of the nodes Na, Nb of the network RT stored in the naming file FN of the server node NS and in a similar way to the determination of the error correction codes in the first realization.
- the codes Ca, Cb are determined by applying an error correction setting algorithm AG, such as a cyclic redundancy check algorithm, to the recording data RRa, RRb.
- the correction data D_Ca and D__Cb each including in particular an error correction code Ca, Cb, the identifier I_AG of the error correction algorithm AG and the identifier I_PG of the generator polynomial PG, are then stored in the MCO memory in association with the identifiers ID_Na, ID_Nb of the nodes of the network RT.
- the algorithm AG and the generator polynomial PG are also stored in the memory MCO.
- the client node NCL wishing to obtain a registration data item relating to a node Na of the network interrogates the server node NS by transmitting, through the network RT, a first request RQ1 containing an identifier ID_Na of the node Na and a DCC correction code request.
- the server node NS transmits the registration data D RRa associated with the identifier ID Na to the node NCL client.
- the error correction data D Ca associated with the ID_Na identifier is transmitted from the KCQ node to the client node either directly or via the NS server node after receiving a request RQ2 transmitted from the server node and including the identifier ID Na and the DCC correction code request.
- the client node NCL On receipt of the response RP1 and / or the response RP2, the client node NCL checks the accuracy of the registration data D_RRa as a function of the error correction data D_Ca. If the data D_RRa is incorrect, the NCL corrects it according to the error correction data D_Ca and processes it.
- the method for checking and correcting registration data error of the DNS protocol naming system comprises steps Sl to SlO shown in FIG. 7 and described with reference to FIG. embodiment of Figure 6.
- step S1 when updating the naming file FN by the UFS naming file management unit in the server node NS, the introduction of a new node N0 in the network RT, l UFS unit stores in the FN file the RRa record relating to the node Na.
- the UCS communication unit of the node NS establishes a message M containing the record data D_RRa of the record RRa and the associated identifier ID_Na in order to transmit the message M via the interface 1RS to the code node NCO correction.
- step S2 the UGO unit of the NCO node determines the error correction code Ca by applying the correction establishment algorithm AG to the transmitted data D RRa, and stores the code data. DjCa including the determined code Ca in the memory MCO in association with the transmitted identifier ID_Na. If the MCL client node knowing only the identifier IDJIa of the node Na wishes to initiate a communication with the node Na of the network RT, the following steps S3 to SlO are executed.
- step S3 the UCC communication unit of the NCL node establishes a first request RQ1 which contains at least the identifier ID Na and which is transmitted by the IRC network interface of the NCL node to the server node NS through the RT network.
- the request RQ1 may also include a DCC correction code request in order to detect a possible transmission error of the data D_RRa and thus correct it.
- step S4 the network interface 1RS of the server node NS receives the request RQ1 which is processed by the communication unit UCS of the server node NS.
- the UFS naming file management unit of the server node searches the file FN for the registration data D__RRa.
- step S5 the UFS verifies whether a DCC correction code request is included in the RQ1 request. If no DCC request is included in the request RQ1, the communication unit UCS establishes a response RP1 transmitted by the network interface 1RS from the server node NS to the client node NCL through the network RT and containing the requested data. D_RRa associated with the identifier IDJNIa.
- the UCC communication unit of the client node NCL processes the data D_RRa in step S ⁇ .
- step S5 a request for a DCC correction code is included in the request RQ1
- the communication unit UCS establishes a second request RQ2 including the ID_Na identifier and the DCC request to be transmitted to the NCO correction code node.
- the NCO node UCO error correction code management unit finds in the memory MCO the error correction data D_Ca associated with the identifier ID__Na. and include it in a response RP2 with the identifier ID_Na.
- the response RP2 is transmitted to the server node NS.
- step S8 the UCS communication unit of the server node NS processes the response RP2 and establishes a response RP1 relating to the request RQ1.
- the response RP1 comprises the identifier ID_Na, the registration data D_RRa, and the error correction data D__Ca.
- step S9 the IRC network interface of the NCL client node receives the response RP1.
- steps S9, SlO and S ⁇ are similar to steps E5 to E7 of the first embodiment described with reference to FIG.
- the response RP2 in the step S7 is directly transmitted from the NCO correction code node to the NCL client node, the NCL node address being included in the RQ2 request transmitted by the NS server node.
- the node NS simultaneously transmits to the request RQ2 a response RP1 to the node NCL including only the registration data D__RRa and the identifier ID Na, and optional notification that the error correction data associated with the data D_RRa is transmitted by another node.
- the client node NCL On receipt of the two responses RP1 and R2, the client node NCL performs steps S9, Sl0 and S6.
- FIG. 8 A second variant of the recording data error checking and correction method relating to the second embodiment of the invention is illustrated in FIG. 8. This second variant comprises steps P1 to P10.
- Steps P1 to P4 are similar to steps S1 to S4 described with reference to FIG.
- step P5 the unit UFS checks whether a DCC correction code request is included in the request RQ1. If no DCC request is included in the request RQ1, the communication unit UCS establishes a response RP1 transmitted by the network interface 1RS from the server node NS to the client node NCL through the network RT and containing the requested data. D__RRa associated with the identifier ID__Na. The UCC communication unit of the client node NCL processes the data item D__RRa in step P6.
- step P5 a DCC correction code request is included in the request RQ1, the communication unit UCS establishes; a response RP1 including the identifier IDJNIa, the registration data D_RRa and an address ADJNICO of the NCO correction code node, and transmits it to the client node NCL.
- step P7 on receipt of the response RP1, the UCC unit of the client node NCL establishes a second request RQ2 including the identifier ID_Na, the request for correction code DCC and the address of the node MCL, the request RQ2 being transmitted to the NCO correction code node having AD NCO address.
- the error correction code management unit UCO finds in the memory MCO the error correction data D__Ca associated with the identifier ID__Na and the includes in a response RP2 with the identifier IDJ) Ja, the identifier I_AG of the error correction algorithm ⁇ G ⁇ and the identifier I_PG of the generator polynomial PG.
- the response RP2 is transmitted to the NCL node.
- the IRC network interface of the NCL client node receives the response RP2.
- the following steps P9, PlO and P ⁇ are similar to steps E5 to E7 of the first embodiment described with reference to FIG.
- the record data D_RRa and the error correction data D__Ca are respectively transmitted from the server node NS and the NCO correction code node to a node other than the NCL node and having required the data D_RRa and D Ca.
- the node Nb of the network RT does not include a device for requesting DNS type registration data of the node Na with which it wants to communicate. The node Nb thus uses the services of the client node NCL to acquire the data D RRa and DJZa.
- the steps of the method of the invention are determined by the instructions of a computer program incorporated partly in a server node and partly in a client node, or partly in a server node, in a node client and partly in a correction code node, the nodes communicating through a telecommunications network.
- the program includes program instructions which, when said program is executed in processors of the server node and the client node, or the server node, the client node, and the correction code node, whose operation is then controlled by the client. execution of the program, perform the steps of the method according to the invention.
- the invention also applies to a computer program, including a computer program on or in an information carrier, adapted to implement the invention.
- This program can use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code such as in a partially compiled form, or in any other form desirable to implement the method according to the invention.
- the information carrier may be any entity or device capable of storing the program.
- the medium may comprise storage means or recording medium on which is recorded the computer program according to the invention, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a USB key, or a magnetic recording means, for example a floppy disk or a hard disk.
- the information medium may be a transmissible medium such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means.
- the program according to the invention can in particular be downloaded to an Internet type network.
- the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in carrying out the method according to the invention.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0652118A FR2902260A1 (fr) | 2006-06-13 | 2006-06-13 | Verification et correction d'erreurs de donnees d'enregistrement dans un systeme de nommage |
| PCT/FR2007/051428 WO2007144538A1 (fr) | 2006-06-13 | 2007-06-12 | Verification et correction d'erreurs de donnees d'enregistrement dans un systeme de nommage |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2033404A1 true EP2033404A1 (fr) | 2009-03-11 |
Family
ID=37616001
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP07788994A Withdrawn EP2033404A1 (fr) | 2006-06-13 | 2007-06-12 | Verification et correction d'erreurs de donnees d'enregistrement dans un systeme de nommage |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP2033404A1 (fr) |
| FR (1) | FR2902260A1 (fr) |
| WO (1) | WO2007144538A1 (fr) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2658217A1 (fr) * | 2012-04-24 | 2013-10-30 | DomiNIC GmbH | Procédé et dispositif de stockage, de gestion et d'utilisation de droits pour l'utilisation d'une ressource |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| GB2346303A (en) * | 1999-01-30 | 2000-08-02 | Motorola Ltd | Error protection in a communications system |
| FR2853186B1 (fr) * | 2003-03-24 | 2005-07-22 | Sagem | Systeme et procede de transmission de donnees autorisant un adressage dynamique au moyen d'identifiants statiques |
-
2006
- 2006-06-13 FR FR0652118A patent/FR2902260A1/fr active Pending
-
2007
- 2007-06-12 WO PCT/FR2007/051428 patent/WO2007144538A1/fr not_active Ceased
- 2007-06-12 EP EP07788994A patent/EP2033404A1/fr not_active Withdrawn
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2007144538A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| FR2902260A1 (fr) | 2007-12-14 |
| WO2007144538A1 (fr) | 2007-12-21 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US7415536B2 (en) | Address query response method, program, and apparatus, and address notification method, program, and apparatus | |
| EP2807789B1 (fr) | Gestion de certificats ssl implicite sans indication de nom de serveur (sni) | |
| EP2933986B1 (fr) | Procédé assisté par ordinateur et produit programme d'ordinateur pour le traitement de requêtes d'entité nommées à l'aide d'une fonctionnalité en mémoire cache dans un système de nom de domaine | |
| US7039656B1 (en) | Method and apparatus for synchronizing data records between a remote device and a data server over a data-packet-network | |
| US7617322B2 (en) | Secure peer-to-peer cache sharing | |
| US7502923B2 (en) | Systems and methods for secured domain name system use based on pre-existing trust | |
| EP3651408B1 (fr) | Procédé d'identification anonyme d'un module de sécurité | |
| US20100082777A1 (en) | Method, system, and apparatus for creating network accounts and configuring devices for use therewith | |
| EP1974522B1 (fr) | Serveur, client et procédé pour gérer des requetes DNSSEC | |
| EP2424189A2 (fr) | Procédés et systèmes d'encouragement de communications sécurisées | |
| US20090240758A1 (en) | Intelligent establishment of peer-to-peer communication | |
| EP2476058A1 (fr) | Procédé et système de récupération d'un registre défectueux | |
| US12568062B2 (en) | Experience differentiation | |
| US11258770B2 (en) | Methods and devices for delegation of distribution of encrypted content | |
| WO2007144538A1 (fr) | Verification et correction d'erreurs de donnees d'enregistrement dans un systeme de nommage | |
| EP2014057A2 (fr) | Identification de noeuds dans un reseau | |
| EP4222632B1 (fr) | Procédé de synchronisation d'une pluralité de serveurs de communications, dispositifs et programmes d'ordinateurs correspondants | |
| EP3900306A1 (fr) | Procédé de détermination d'une chaîne de délégation associée à une résolution d'un nom de domaine dans un réseau de communication | |
| FR3091097A1 (fr) | Procédé d’acquisition d’une chaîne de délégation relative à la résolution d’un identifiant de nom de domaine dans un réseau de communication | |
| EP4128717A1 (fr) | Délégation d'une fonction de résolution d'identifiants de nommage | |
| WO2012001273A1 (fr) | PROCEDE D'ALLOCATION SECURISEE D'UNE ADRESSE IPv6 A UN NŒUD D'UN RESEAU PRIVE | |
| GB2401292A (en) | Secure network communication | |
| FR2961984A1 (fr) | Synchronisation de liste des utilisateurs dans un reseau p2p |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20090109 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC MT NL PL PT RO SE SI SK TR |
|
| AX | Request for extension of the european patent |
Extension state: AL BA HR MK RS |
|
| DAX | Request for extension of the european patent (deleted) | ||
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ORANGE |
|
| 17Q | First examination report despatched |
Effective date: 20160405 |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: H04L 29/12 20060101ALI20160830BHEP Ipc: H04L 29/06 20060101AFI20160830BHEP Ipc: H04L 1/00 20060101ALI20160830BHEP |
|
| INTG | Intention to grant announced |
Effective date: 20160915 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20170126 |