JP6687636B2 - サービス−ユーザプレーン手法のためのネットワークトークンを使用した効率的なポリシー施行 - Google Patents

サービス−ユーザプレーン手法のためのネットワークトークンを使用した効率的なポリシー施行 Download PDF

Info

Publication number
JP6687636B2
JP6687636B2 JP2017544289A JP2017544289A JP6687636B2 JP 6687636 B2 JP6687636 B2 JP 6687636B2 JP 2017544289 A JP2017544289 A JP 2017544289A JP 2017544289 A JP2017544289 A JP 2017544289A JP 6687636 B2 JP6687636 B2 JP 6687636B2
Authority
JP
Japan
Prior art keywords
network token
network
token
application server
packet
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
JP2017544289A
Other languages
English (en)
Japanese (ja)
Other versions
JP2018508146A5 (enExample
JP2018508146A (ja
Inventor
ス・ボム・イ
ギャヴィン・バーナード・ホーン
ジョン・ナシールスキー
ステファノ・ファッチン
Original Assignee
クアルコム,インコーポレイテッド
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by クアルコム,インコーポレイテッド filed Critical クアルコム,インコーポレイテッド
Publication of JP2018508146A publication Critical patent/JP2018508146A/ja
Publication of JP2018508146A5 publication Critical patent/JP2018508146A5/ja
Application granted granted Critical
Publication of JP6687636B2 publication Critical patent/JP6687636B2/ja
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • H04W12/084Access security using delegated authorisation, e.g. open authorisation [OAuth] protocol
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/20Traffic policing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/10Flow control; Congestion control
    • H04L47/22Traffic shaping
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/14Session management
    • H04L67/146Markers for unambiguous identification of a particular session, e.g. session cookie or URL-encoding
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/2866Architectures; Arrangements
    • H04L67/30Profiles
    • H04L67/303Terminal profiles
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • H04W12/088Access security using filters or firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
JP2017544289A 2015-02-24 2016-01-14 サービス−ユーザプレーン手法のためのネットワークトークンを使用した効率的なポリシー施行 Active JP6687636B2 (ja)

Applications Claiming Priority (7)

Application Number Priority Date Filing Date Title
US201562120159P 2015-02-24 2015-02-24
US62/120,159 2015-02-24
US201562161768P 2015-05-14 2015-05-14
US62/161,768 2015-05-14
US14/866,425 US10505850B2 (en) 2015-02-24 2015-09-25 Efficient policy enforcement using network tokens for services—user-plane approach
US14/866,425 2015-09-25
PCT/US2016/013463 WO2016137598A2 (en) 2015-02-24 2016-01-14 Efficient policy enforcement using network tokens for services - user-plane approach

Publications (3)

Publication Number Publication Date
JP2018508146A JP2018508146A (ja) 2018-03-22
JP2018508146A5 JP2018508146A5 (enExample) 2019-02-07
JP6687636B2 true JP6687636B2 (ja) 2020-04-22

Family

ID=56690617

Family Applications (1)

Application Number Title Priority Date Filing Date
JP2017544289A Active JP6687636B2 (ja) 2015-02-24 2016-01-14 サービス−ユーザプレーン手法のためのネットワークトークンを使用した効率的なポリシー施行

Country Status (8)

Country Link
US (4) US10505850B2 (enExample)
EP (1) EP3262821B1 (enExample)
JP (1) JP6687636B2 (enExample)
KR (1) KR102487923B1 (enExample)
CN (1) CN107409125B (enExample)
BR (1) BR112017018021A2 (enExample)
TW (1) TWI668976B (enExample)
WO (1) WO2016137598A2 (enExample)

Families Citing this family (39)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10505850B2 (en) 2015-02-24 2019-12-10 Qualcomm Incorporated Efficient policy enforcement using network tokens for services—user-plane approach
WO2016209131A1 (en) * 2015-06-25 2016-12-29 Telefonaktiebolaget Lm Ericsson (Publ) Setting up a dedicated bearer in a radio communication network
US11290425B2 (en) * 2016-02-01 2022-03-29 Airwatch Llc Configuring network security based on device management characteristics
US20190028928A1 (en) * 2016-03-07 2019-01-24 Telefonaktiebolaget Lm Ericsson (Publ) Method for Traffic Steering, Network Device and Terminal Device
EP3440869B1 (en) * 2016-04-08 2022-12-14 Nokia Technologies Oy Method and apparatus for u-plane sub-service flow mapping
CN108076459B (zh) * 2016-11-08 2021-02-12 北京华为数字技术有限公司 网络接入控制方法、相关设备及系统
US10356830B2 (en) * 2017-01-17 2019-07-16 Cisco Technology, Inc. System and method to facilitate stateless serving gateway operations in a network environment
US10784986B2 (en) 2017-02-28 2020-09-22 Intel Corporation Forward error correction mechanism for peripheral component interconnect-express (PCI-e)
US10250436B2 (en) 2017-03-01 2019-04-02 Intel Corporation Applying framing rules for a high speed data link
WO2018205148A1 (zh) * 2017-05-09 2018-11-15 华为技术有限公司 一种数据包校验方法及设备
US11102194B2 (en) * 2017-06-27 2021-08-24 Applied Invention, Llc Secure communication network
US11856027B2 (en) 2017-06-27 2023-12-26 Applied Invention, Llc Secure communication system
US12238104B2 (en) 2017-06-27 2025-02-25 Applied Invention, Llc Secure communication system
US10419446B2 (en) 2017-07-10 2019-09-17 Cisco Technology, Inc. End-to-end policy management for a chain of administrative domains
US10666624B2 (en) * 2017-08-23 2020-05-26 Qualcomm Incorporated Systems and methods for optimized network layer message processing
CN110167067B (zh) * 2018-02-13 2021-10-22 展讯通信(上海)有限公司 数据传输方法及装置、存储介质、终端、基站
US11108812B1 (en) * 2018-04-16 2021-08-31 Barefoot Networks, Inc. Data plane with connection validation circuits
CN112567777B (zh) * 2018-08-13 2024-03-08 苹果公司 用于受限本地运营商服务接入的演进分组核心中的技术
CN109614147B (zh) * 2018-12-03 2022-02-22 郑州云海信息技术有限公司 一种phy寄存器读写方法和装置
US10771189B2 (en) 2018-12-18 2020-09-08 Intel Corporation Forward error correction mechanism for data transmission across multi-lane links
US11637657B2 (en) 2019-02-15 2023-04-25 Intel Corporation Low-latency forward error correction for high-speed serial links
US11249837B2 (en) 2019-03-01 2022-02-15 Intel Corporation Flit-based parallel-forward error correction and parity
US11503471B2 (en) * 2019-03-25 2022-11-15 Fortinet, Inc. Mitigation of DDoS attacks on mobile networks using DDoS detection engine deployed in relation to an evolve node B
US11296994B2 (en) 2019-05-13 2022-04-05 Intel Corporation Ordered sets for high-speed interconnects
CN110392061A (zh) * 2019-08-06 2019-10-29 郑州信大捷安信息技术股份有限公司 一种网络接入控制系统及方法
CN113950802B (zh) * 2019-08-22 2023-09-01 华为云计算技术有限公司 用于执行站点到站点通信的网关设备和方法
KR102739176B1 (ko) * 2019-10-16 2024-12-06 현대자동차주식회사 차량 통신 연결 장치 및 그 방법
US11740958B2 (en) 2019-11-27 2023-08-29 Intel Corporation Multi-protocol support on common physical layer
US11469890B2 (en) * 2020-02-06 2022-10-11 Google Llc Derived keys for connectionless network protocols
CN111356157B (zh) * 2020-03-15 2024-10-25 腾讯科技(深圳)有限公司 实现网络能力开放的方法及相关设备
GB2598084A (en) * 2020-07-16 2022-02-23 The Sec Dep For Foreign Commonwealth And Development Affairs Acting Through The Government Communica Payload assurance at a network boundary
US12189470B2 (en) 2020-09-18 2025-01-07 Intel Corporation Forward error correction and cyclic redundancy check mechanisms for latency-critical coherency and memory interconnects
US11818097B2 (en) * 2021-04-25 2023-11-14 A10 Networks, Inc. Packet watermark with static salt and token validation
US11546358B1 (en) * 2021-10-01 2023-01-03 Netskope, Inc. Authorization token confidence system
WO2023224424A1 (en) * 2022-05-20 2023-11-23 Samsung Electronics Co., Ltd. Application server assisted content management in cellular network
US11895213B2 (en) 2022-05-20 2024-02-06 Samsung Electronics Co., Ltd. Application server assisted content management in cellular network
CN115396186B (zh) * 2022-08-24 2025-01-17 江铃汽车股份有限公司 一种基于车载网关的车内通信防火墙系统的运行方法
US20240414210A1 (en) * 2023-06-09 2024-12-12 Fortinet, Inc. Systems and methods for edge processing using selectively suspended network security
US20250247702A1 (en) * 2024-01-25 2025-07-31 Qualcomm Incorporated Downlink message protection for ambient wireless devices

Family Cites Families (43)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH07307752A (ja) * 1994-05-10 1995-11-21 Toshiba Corp 計算機の通信方式
US7370004B1 (en) 1999-11-15 2008-05-06 The Chase Manhattan Bank Personalized interactive network architecture
US6621793B2 (en) * 2000-05-22 2003-09-16 Telefonaktiebolaget Lm Ericsson (Publ) Application influenced policy
US6941326B2 (en) * 2001-01-24 2005-09-06 Microsoft Corporation Accounting for update notifications in synchronizing data that may be represented by different data structures
FI115687B (fi) * 2002-04-09 2005-06-15 Nokia Corp Pakettidatan siirtäminen langattomaan päätelaitteeseen
WO2006045402A1 (en) 2004-10-26 2006-05-04 Telecom Italia S.P.A. Method and system for transparently authenticating a mobile user to access web services
CN101120573A (zh) * 2004-12-22 2008-02-06 高通股份有限公司 使用灵活协议配置的连接建立
US7990998B2 (en) 2004-12-22 2011-08-02 Qualcomm Incorporated Connection setup using flexible protocol configuration
WO2006114628A2 (en) 2005-04-26 2006-11-02 Vodafone Group Plc Sae/lte telecommunications networks
US8261078B2 (en) * 2006-06-09 2012-09-04 Telefonaktiebolaget Lm Ericsson (Publ) Access to services in a telecommunications network
US20080076425A1 (en) * 2006-09-22 2008-03-27 Amit Khetawat Method and apparatus for resource management
US7957306B2 (en) 2006-09-08 2011-06-07 Cisco Technology, Inc. Providing reachability information in a routing domain of an external destination address in a data communications network
CN101064695A (zh) * 2007-05-16 2007-10-31 杭州看吧科技有限公司 一种P2P(Peer to Peer)安全连接的方法
US8955088B2 (en) 2007-11-07 2015-02-10 Futurewei Technologies, Inc. Firewall control for public access networks
EP2241081B1 (en) 2008-01-26 2018-05-02 Citrix Systems, Inc. Systems and methods for fine grain policy driven cookie proxying
US8452011B2 (en) * 2008-10-24 2013-05-28 Qualcomm Incorporated Method and apparatus for billing and security architecture for venue-cast services
US9106541B2 (en) * 2008-12-10 2015-08-11 Telefonaktiebolaget L M Ericsson (Publ) Token-based correlation of control sessions for policy and charging control of a data session through a NAT
US8527774B2 (en) 2009-05-28 2013-09-03 Kaazing Corporation System and methods for providing stateless security management for web applications using non-HTTP communications protocols
US8750370B2 (en) * 2009-09-04 2014-06-10 Brocade Communications Systems, Inc. Congestion-adaptive compression
US8301895B2 (en) 2009-12-02 2012-10-30 Microsoft Corporation Identity based network policy enablement
US8949978B1 (en) * 2010-01-06 2015-02-03 Trend Micro Inc. Efficient web threat protection
US9398517B2 (en) * 2010-01-11 2016-07-19 Blackberry Limited System and method for enabling discovery of local service availability in local cellular coverage
JP5440210B2 (ja) 2010-01-28 2014-03-12 富士通株式会社 アクセス制御プログラム、アクセス制御方法およびアクセス制御装置
US8565091B2 (en) 2010-10-28 2013-10-22 Telefonaktiebolaget L M Ericsson (Publ) Dynamic control of air interface throughput
CN102469020B (zh) * 2010-11-19 2017-10-17 华为技术有限公司 一种业务控制方法及系统、演进基站、分组数据网网关
CN102625271B (zh) * 2011-01-26 2016-09-07 中兴通讯股份有限公司 一种共设mtc设备的信令优化方法和系统
US8978100B2 (en) * 2011-03-14 2015-03-10 Verizon Patent And Licensing Inc. Policy-based authentication
US9173099B2 (en) 2011-03-30 2015-10-27 Htc Corporation Method of subscription control in a mobile communication system
CN103460786B (zh) * 2011-04-01 2016-11-09 交互数字专利控股公司 用于共享公共pdp上下文的系统和方法
US20120323990A1 (en) * 2011-06-15 2012-12-20 Microsoft Corporation Efficient state reconciliation
US8976813B2 (en) 2011-09-08 2015-03-10 Motorola Solutions, Inc. Secure quality of service
US8667579B2 (en) 2011-11-29 2014-03-04 Genband Us Llc Methods, systems, and computer readable media for bridging user authentication, authorization, and access between web-based and telecom domains
WO2013128470A1 (en) 2012-02-27 2013-09-06 Deshpande Nachiket Girish Authentication and secured information exchange system, and method therefor
US8621590B2 (en) 2012-03-19 2013-12-31 Cable Television Laboratories, Inc. Multiple access point zero sign-on
US9818161B2 (en) * 2012-06-05 2017-11-14 Apple Inc. Creating a social network message from an interface of a mobile device operating system
US9693366B2 (en) 2012-09-27 2017-06-27 Interdigital Patent Holdings, Inc. End-to-end architecture, API framework, discovery, and access in a virtualized network
US20150264739A1 (en) * 2012-10-08 2015-09-17 Nokia Solutions And Networks Oy Methods, devices, and computer program products for keeping devices attached without a default bearer
DE102013102487A1 (de) 2013-03-12 2014-09-18 Deutsche Telekom Ag Verfahren und Vorrichtung zur Steuerung des Zugriffs auf digitale Inhalte
US9098687B2 (en) 2013-05-03 2015-08-04 Citrix Systems, Inc. User and device authentication in enterprise systems
WO2015023537A2 (en) * 2013-08-16 2015-02-19 Interdigital Patent Holdings, Inc. Methods and apparatus for hash routing in software defined networking
US10505850B2 (en) 2015-02-24 2019-12-10 Qualcomm Incorporated Efficient policy enforcement using network tokens for services—user-plane approach
US9648141B2 (en) * 2015-03-31 2017-05-09 Cisco Technology, Inc. Token delegation for third-party authorization in computer networking
US10362011B2 (en) 2015-07-12 2019-07-23 Qualcomm Incorporated Network security architecture

Also Published As

Publication number Publication date
US11910191B2 (en) 2024-02-20
TWI668976B (zh) 2019-08-11
CN107409125A (zh) 2017-11-28
EP3262821B1 (en) 2024-08-14
KR102487923B1 (ko) 2023-01-11
US20230091356A1 (en) 2023-03-23
CN107409125B (zh) 2021-02-19
KR20170118732A (ko) 2017-10-25
EP3262821A2 (en) 2018-01-03
US11570622B2 (en) 2023-01-31
US20190349306A1 (en) 2019-11-14
WO2016137598A3 (en) 2016-11-03
WO2016137598A2 (en) 2016-09-01
US20220150699A1 (en) 2022-05-12
JP2018508146A (ja) 2018-03-22
US20160248682A1 (en) 2016-08-25
TW201644238A (zh) 2016-12-16
BR112017018021A2 (pt) 2018-04-10
US10505850B2 (en) 2019-12-10
US11265712B2 (en) 2022-03-01

Similar Documents

Publication Publication Date Title
US11910191B2 (en) Efficient policy enforcement using network tokens for services—user-plane approach
US11290382B2 (en) Efficient policy enforcement for downlink traffic using network access tokens—control-plane approach
JP6438593B2 (ja) サービスcプレーン手法のためにネットワークトークンを使用する効率的なポリシー実施
CN107409133B (zh) 一种具有完全前向保密的认证与密钥协商的方法以及设备
JP5922785B2 (ja) データセキュリティチャネル処理方法およびデバイス
WO2020034864A1 (zh) 一种用户面安全策略实现方法、装置及系统
WO2012167500A1 (zh) 一种隧道数据安全通道的建立方法
WO2019071472A1 (zh) 一种业务策略创建方法及装置
WO2022174729A1 (zh) 保护身份标识隐私的方法与通信装置
JP2016136776A (ja) データセキュリティチャネル処理方法およびデバイス

Legal Events

Date Code Title Description
A521 Request for written amendment filed

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20170825

A521 Request for written amendment filed

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20181221

A621 Written request for application examination

Free format text: JAPANESE INTERMEDIATE CODE: A621

Effective date: 20181221

A131 Notification of reasons for refusal

Free format text: JAPANESE INTERMEDIATE CODE: A131

Effective date: 20190917

A977 Report on retrieval

Free format text: JAPANESE INTERMEDIATE CODE: A971007

Effective date: 20190911

A521 Request for written amendment filed

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20191216

TRDD Decision of grant or rejection written
A01 Written decision to grant a patent or to grant a registration (utility model)

Free format text: JAPANESE INTERMEDIATE CODE: A01

Effective date: 20200309

A61 First payment of annual fees (during grant procedure)

Free format text: JAPANESE INTERMEDIATE CODE: A61

Effective date: 20200402

R150 Certificate of patent or registration of utility model

Ref document number: 6687636

Country of ref document: JP

Free format text: JAPANESE INTERMEDIATE CODE: R150

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250