WO2010146242A1 - Metering unit for undeniable service management and a related method - Google Patents
Metering unit for undeniable service management and a related method Download PDFInfo
- Publication number
- WO2010146242A1 WO2010146242A1 PCT/FI2010/050517 FI2010050517W WO2010146242A1 WO 2010146242 A1 WO2010146242 A1 WO 2010146242A1 FI 2010050517 W FI2010050517 W FI 2010050517W WO 2010146242 A1 WO2010146242 A1 WO 2010146242A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- metering unit
- information
- data
- router
- network
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/10—Active monitoring, e.g. heartbeat, ping or trace-route
- H04L43/106—Active monitoring, e.g. heartbeat, ping or trace-route using time related information in packets, e.g. by adding timestamps
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/12—Discovery or management of network topologies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/50—Network service management, e.g. ensuring proper service fulfilment according to agreements
- H04L41/5003—Managing SLA; Interaction between SLA and QoS
- H04L41/5009—Determining service level performance parameters or violations of service level contracts, e.g. violations of agreed response time or mean time between failures [MTBF]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
Definitions
- This invention relates generally to communications networks. More particularly the present invention is directed to an undeniable service management platform for a packet switching network and a method for undeniably verifying outcomes of performed actions, actualizations of delivered services and/or presence of configurations.
- packet switching network such as the Internet
- the Internet which is an aggregate of multiple smaller networks, may have countless of users throughout the world.
- packets transferred on the Internet may include various other forms of data like video streaming data and bi-directional voice communications, for instance.
- US 2006150153 Al discloses a method for verifying digital objects by creating a unique digital fingerprint.
- the creation of the fingerprint is done inside a terminal device and stored along with the object.
- the verification method can be used to validate that the digital object has not been semantically altered, despite the restructuring or reformatting of the object.
- US 2005286535 Al discloses methods for verifying consumer equipment that is connected to a packet switched network. Information is hashed to generate a first hash value. Also the information in a memory of the consumer equipment is hashed in order to generate a second hash value. After that, the first hash value and the second hash value are compared to generate a verification indication for the consumer equipment. The Quality of Service for information packets that are communicated with the consumer equipment through the packet switched network is controlled based on the verification indication.
- the objective of the present invention is to at least alleviate one or more of the aforesaid defects related to the prior art solutions what comes to the authentication of service management.
- the objective is met by a metering unit, a system and a related method for monitoring and processing the data passed, or to be passed, through a router or through other data emitting and/or forwarding entity.
- the metering, or “monitoring”, unit according to an embodiment of the present invention, physically being either an internal or external to the router, is advantageously capable of undeniably verifying the outcomes of performed actions, actualizations of delivered services and/or configurations.
- the metering unit is preferably capable of monitoring and/or collecting the network topology information, such as the locations of its own and the elements near it in the network topology.
- TPM
- a method for generating undeniable information, to be performed by a metering unit comprises:
- information related to data passed through a router and to be verified such as a piece of the passed data or other information representing the passed data, and contextual information, such as data transfer direction information, metering unit configuration information, local time stamp information, and/or network topology information,
- a cryptographic digest such as a hash
- a non-repudiable data item such as a time stamp
- a system for generating undeniable information comprises a metering unit and at least one trusted third party for providing a non-repudiable data item. Additionally, the system may further comprise a network management system for controlling said metering unit.
- a method for verifying locations and configurations of a metering unit and one or more elements in the network, to be performed by the metering unit comprises:
- Distance and/or nearness may be determined embodiment-specifically.
- Distance/nearness may refer to physical distance/nearness and/or logical distance/nearness.
- distance/nearness may be determined utilizing at least one item selected from the group consisting of: element's network address or at least part thereof, transfer delay (one-way or roundtrip), geographical location (e.g. coordinates), and number of hops. Differences between the addresses or locations of two entities may be then used for determining the distance/nearness between them, for instance.
- the associated decision logic may apply fixed and/or dynamic threshold values. Accordingly, nearby elements relative to the metering unit may be determined.
- the metering unit may be configured to obtain ((through monitoring, for instance, the related parameter(s) such as the applied digest function) and verify its configuration(s) and location in the network topology. The verification may be performed by obtaining the non-repudiable data item from a trusted third party and/or by using the secured entity of the metering unit for signing the undeniable information consisting of configuration and location information and the non- repudiable data item.
- the metering unit may also be configured to obtain information related to the elements near it, according to predetermined criterion or criteria, in the network topology by using various one or more techniques.
- the metering unit may be configured to monitor and store the data (or at least part or indication thereof) passed through the router and the identifying information thereof.
- a cryptographic digest calculation may be performed for the data, or the hash or corresponding function's outcome for the data may be obtained by some other way.
- the non- repudiable data item may be obtained from the trusted third party.
- the undeniable information about the data passed through the router may be constructed by verifying with secured entity selected information as described herein in connection with various embodiments. The undeniable information may be then stored in the memory.
- one or more network elements are verified by using the trusted platform module (TPM) technique.
- TPM trusted platform module
- the cryptographic digest (function) calculation of data may be performed to adequate parts of the data (stream).
- the utility of the present invention arises from plurality of issues.
- the invention provides an effortless way for retain identifying information and undeniably verify the outcomes of performed actions, actualizations of delivered services and/or presence/nature of current configurations.
- Embodiments of the invention may also alleviate difficulties related to invoicing.
- Reliable verification of that the transmitted data has passed through the router may be made, according to the present invention, independent of operators or service providers.
- the metering units can be utilized by a network operator for invoicing services on Internet traffic terms without using a heavy connection set-up managed by the operator.
- the suggested procedure may further prevent the "man-in-the-middle" -type of misuse of the network resources and services.
- the reliability of the data traffic may be generally leveraged when it is possible to undeniably track the device and point of time where e.g. a transmission error has occurred.
- data passed through the router or “passed data” refers to any kind of data transferred via the router, such as data packets and data stream.
- the transferred data may be for example email data, image data, voice data, audio and/or video stream to name a few.
- identifying information refers to any kind of information included in the transferred data that can be utilized as such or together with other information to identify data traffic.
- trusted third party may refer to one or more entities, such as a timestamping authority and/or a certificate authority, which provide(s) required trusted information.
- non-repudiable data item may refer herein to a piece of data, such as a time stamp relative to the receiving time of a cryptographic digest (by e.g. a time-stamp service), preferably signed and/or otherwise verified such that the correctness and advantageously creation time of which cannot be disputed.
- the data item may include a time stamp with a signature covering e.g. the cryptographic digest, the associated time indication and optional further elements.
- cryptographic digest function refers to a selected function, such as a hash function, generated about the data passed through the router by using a selected, preferably complex-to-hack, algorithm.
- This preferably substantially one-way (irreversible) function is to generate what in this document is called a "cryptographic digest", that is, an unique identification of the source data, based on the essential property of the cryptographic digest function that guarantees (with a reasonable probability, taking into account the state-of-the-art) that no other piece of data will provide the same cryptographic digest when used as an input to the cryptographic digest function.
- a cryptographic digest that is, an unique identification of the source data, based on the essential property of the cryptographic digest function that guarantees (with a reasonable probability, taking into account the state-of-the-art) that no other piece of data will provide the same cryptographic digest when used as an input to the cryptographic digest function.
- the expression “undeniable information” refers herein at least to the data that the metering unit obtains and at least partially verifies by utilizing the secured entity.
- context information may refer herein to identifying information, data transfer direction information, metering unit configuration information, time (stamp) information and/or network topology information.
- network resource refers to whatever is obtained and/or controlled over the network.
- Fig. 1 illustrates an example of a network and the location of the metering unit in the network topology.
- Fig. 2 shows a block diagram of internals of the metering unit in accordance with an embodiment of the present invention.
- Fig. 3 illustrates a flow diagram of an embodiment of a method for generating undeniable information according to the present invention.
- Fig. 4a illustrates a rough flow diagram of the operation of the metering unit according to one embodiment thereof.
- Fig. 4b illustrates a flow diagram of an embodiment of a method for verifying configuration and the location of the metering unit.
- Fig. 4c illustrates a flow diagram of an embodiment of a method for collecting information about the network topology.
- Figure 1 illustrates an example of a network and the location of the metering unit in the network topology.
- Figure 1 is no way meant to be precise representation of the network architecture, but only to serve as a rough example of possible elements in the network and their mutual functional connections.
- User (terminal) and network devices 102 are connected in the networks via different access points such as base stations, WLAN access points, and/or routers 104 (several of such functionalities may also be integrated with a single physical apparatus), and the routers 104 are typically connected with several other routers of a number of networks.
- a metering unit 106 is functionally connectable to one router 104, i.e.
- the metering unit 106 can either be integrated in a router 104 or it can be an external device or, in some cases, the metering unit 106 can even be physically distributed.
- the router is an element that forwards data between the sender and recipient thereof.
- the router may be located in a network, or a border of two or more (sub-)networks, and connect the multiple networks together, for example.
- the metering unit 106 may monitor one or more routers 104.
- the trusted third party 110 is a network device, e.g. a server, to which the metering unit 106 connects via the network, whereas the control means 108 may be directly connected to the metering unit 106.
- the (remote) control means 108 is connected to the metering unit 106 via the network.
- the network wherein the metering unit operates, may be a private or a public packet switching network or a part of a larger network or other type of a communications network having at least one router in it.
- the connections to the network and/or within the network may be implemented in a wired, such as fiber optics or cable, and/or wireless manner, such as radio waves, micro waves and infrared waves, for example.
- the user (terminal) and network devices 102 being at least functionally connected to a router 104 may include any type of devices typically used in the network, such as PC's, laptops, mobile devices, servers, hosts, etc., to name a few.
- the data transferred in the network may be located in packets or it may be multimedia data transferred as a stream of packets.
- the control and/or the configuration of the metering unit, as well as reading and/or transfer of the stored data from the storage means of the metering unit, can be provided with one or more remote control means 108, such as a network management system dedicated or an integrated part of a larger whole.
- the remote control means 208 can be any type of separate device capable for connecting to the metering unit 106 and it may contain a user interface for controlling the metering unit 106.
- the metering unit 106 may also comprise a user interface providing possibility to directly control and/or configure the metering unit.
- the user interface may comprise a display or a connector to an external display, and keyboard/keypad or other applicable control input means (e.g. touch screen or voice control input, or separate keys/buttons/knobs) configured so as to provide the user of the metering unit 106 with practicable data visualization and metering unit control means.
- keyboard/keypad or other applicable control input means e.g. touch screen or voice control input, or separate keys/buttons/knobs
- the metering unit obtains the non-repudiable data item from a trusted third party 110, which can be one or more entities, such as timestamping authority or certificate authority.
- the trusted third party is a service external of the metering unit, more generally, the trusted third party is accessible via the network as the other user and network devices.
- the trusted third party is normally an authority or an instance approved by an authority, e.g. a reliable timestamp can be obtained from French postal service.
- the used trusted third parties are such that the acquiring of the non-repudiable data item is performed fast enough, e.g. within a few seconds.
- the metering unit could itself comprise an entity for providing non-repudiable data items.
- the non-repudiable data item includes accurate time reference data, for example a timestamp, which is utilized to unquestionably define a certain point of time.
- an embodiment of the metering unit in accordance with the present invention comprises a processing means 202, a storage means 204, one or more transceivers 206, a control means 208, one or more secured entities 210 and, optionally, one or more additional logic blocks 212.
- control means 208 is a local internal counterpart to the external control means 108 in Fig. 1.
- the control means 208 may contain, for example, local execution logic of the remote control means for implementing the instructions by the remote control means.
- the processing means 202 comprises at least one processor, such as one or more microprocessors, micro-controllers, DSP's (digital signal processor), programmable logic chips, etc., or any desired combination thereof.
- the processor may comprise a plurality of cooperating processors or sub-processors.
- the processing means 202 is configured to execute the code stored in a storage means 204, which may imply processing instructions and data relative to the metering unit functionalities of the present invention and optionally other functionalities, such as OS related functionalities, I/O-related functionalities, and other applications.
- the processing means 202 controls the secured entity 210, as well as the additional logic blocks 212.
- the storage means 204 may be divided between one or more physical memory chips or other memory elements, and it may comprise code, e.g. in a form of a computer program/application for the metering unit, and other data. Moreover, the storage means 204 may further include other storage media, such as a preferably detachable memory card, a floppy disc, a CD-ROM, fixed storage medium such as hard drive.
- the storage means 204 may be non-volatile, e.g. ROM, PROM, EEPROM or flash memory, and/or volatile, e.g. RAM, by nature.
- the transceiver 206 complying with predetermined wired or wireless technology, for communication primarily with the router the metering unit is connected to and, in addition to that, with other devices such as network devices and separate devices, for example the control means of the metering unit.
- the transceiver can be a device that has both transmitting and receiving capabilities or the transceiver may consist of a separate transmitter and receiver. While having more than one transceiver in the metering unit, some of transceivers can be implemented for wired network, for example converting electrical pulses to light and vice versa, and the other can be implemented for wireless network technology, such as GSM, UMTS, WLAN, Bluetooth, Wimax, etc.
- the secured entity 210 included in the metering unit is for verifying and signing the information obtained by the metering unit.
- the secured entity 210 may be implemented by using the trusted platform module (TPM) technique or some other technique, in which the secured entity 210 is a physical device having a unique identifier and in which the functionalities of the entity are physically secured.
- TPM trusted platform module
- the secured entity has a public/private key pair, which the private key is generated within the secured entity and never exposed outside it.
- the metering unit may also comprise additional logic blocks 212, such as a math block, for processing data packets.
- the logic blocks 212 are typically stored in the storage means 204 of the metering unit and they can be executed by the processor 202.
- the logic blocks can be used for the cryptographic digest function, i.e. the hash function, calculation.
- the hash function calculation e.g. RIPEMD- 128, RIPEMD- 160 and/or SHA-2 family. Therefore, a table or other entity may be maintained for the hash function so as to confirm, with which method the cryptographic digest function has been calculated.
- the cryptographic digest function calculation method is advantageously changeable and the other advantageous requirements for the method are that the calculation procedure is fast enough and the approximated crack time of the hash function should be at least as long as the required retaining time of the identifying information, e.g. about two years.
- the metering unit may, in practice, comprise numerous further functional and/or structural elements for providing various beneficial communication, processing, or other features, whereupon this disclosure is not to be constructed as limiting the presence of potential additional elements in any manner.
- Figure 3 illustrates a flow diagram of the method for constructing undeniable information according to the present invention.
- the method for verifying and signing information with the secured entity is similar regardless of the content of the information.
- the verification method for every verification step in the metering unit is described herein in conjunction with Figure 3.
- the data that is desired to be verified is obtained.
- the data can be any information obtained by the metering unit: data passed through the router, information related to the network topology and/or to configuration (e.g. predetermined configuration parameters such as the used digest function, transfer speed, QoS (quality of Service settings), etc.) of the metering unit, for example.
- the transferred data packets or data stream may be e.g. email, image, voice, audio and/or video stream. When it comes to data stream, it is divided into appropriate packets, e.g. duration of about 1-2 second, depending on the buffer length of the router. Mark bits may are added to the packets so that synchronization of the cryptographic digest functions can be performed afterwards.
- the data can be obtained several ways.
- contextual information such as identifying information of the data passed through the router
- the identifying information typically comprises data traffic and location information, such as data transfer direction information, as well as information required for identifying the subscriber or the user of a network resource, e.g. the connection source, the destination information of the packet, starting time of the transfer, the ending time of the certain network resource, etc.
- the other contextual information may comprise information related to the network topology and/or to configurations of the metering unit, for example, or some other related information, e.g. timestamp of the metering unit.
- the metering unit obtains the cryptographic digest for the data desired to be verified.
- the cryptographic digest is calculated in the metering unit by using an additional math block or by the secured entity.
- the cryptographic digest is obtained by some other way. For instance, the calculation may be performed by some other element in the network, e.g. the metering unit in the service producer's side on the network, and the cryptographic digest is passed together with the data. This is a lighter way to produce the cryptographic digest, but, however, potentially more unreliable.
- the hash function can be obtained instead of the cryptographic digest calculation. In some cases the hash function of the data can be obtained from somewhere else, but the cryptographic digest may be calculated nevertheless.
- the cryptographic digest function consists of the number of the data packets.
- the cryptographic digest calculation cannot be performed this way.
- the cryptographic digest is obtained for the contextual information or suitable parts thereof, too. This is convenient in case the contextual information is also desired to be verified by the trusted third party/parties, for instance.
- the cryptographic digest function/functions is/are sent to a trusted third party/parties and the signed cryptographic digest function/functions is/are returned with the non-repudiable data item/items.
- the non-repudiable data item is typically a timestamp indicating the exact point of time. For increasing the reliability the timestamp can be obtained from various trusted third parties.
- the undeniable information is constructed at step 308 by attaching the cryptographic digest function and/or hash function and the non-repudiable data item as well as the contextual information to the data that is desired to be verified.
- the data to be verified may comprise at least the suitable parts of the transferred data. If the data has well known hash function, the hash function with the identifying information might be sufficient instead of the data. In some cases, a part of the data with the identifying information may be enough, for example, in the case of streaming data, and otherwise, the data comprises identifying information and the entire transferred data.
- the undeniable information is verified in the secured entity at step 310.
- the desired data is verified by sending the cryptographic digest function of the data to the secured entity.
- the secured entity verifies the data by signing the cryptographic digest and/or optional further data using the private key of the secured entity and returns the signed cryptographic digest and/or optional further data back to the metering unit.
- the undeniable information is stored in the memory, step 312.
- the memory may be the storage means of the metering unit or it may be some other external storage. In case of external storage, several metering units may employ the same storage.
- information related to the data transferred via the router includes the transferred data itself (e.g. consumed content such as an audiovisual representation, e.g.
- the metering unit may supervise, through background execution of a related monitoring task, for example, that multiple copies of the transferred (payload) data or part of it are not stored, for instance, if a copy is already stored in the local or remote storage to which the metering unit has access. In that case, the metering unit may have gained a link to the stored data from the sending device and the metering unit may then optionally forward the link, e.g. within the contextual information, in conjunction with the transferred data to the next device, for example. Alternatively, the metering unit may itself generate a link to the already-stored copy of the transferred data after detecting the existence thereof.
- the metering unit may, for example, compare existing digests of older data transmissions to the just determined digest of the current transmission and when a match is found, generate the link instead of storing the same transferred data once more.
- the metering unit may include a qualifier, e.g. a link, in the transferred data to indicate to the other devices that the data has already been stored.
- the undeniable information may be transmitted for permanent storing to a network management and/or some other management or other entity associated with one or more metering units. The undeniable information may be sent e.g. as appropriate-sized blocks or immediately after generating it.
- access codes for example, bank access codes and alike, are not stored or they are stored in encrypted form. While storing encrypted information, it is possible to store also the encryption keys so that the encrypted information is decodable afterwards. Otherwise, the undeniable data that relates to the configuration of the metering units and the network topology is normally stored as such.
- the construction and the verification of the undeniable information are performed in a different order as can be seen in Figure 3 presented with broken arrows.
- the data and/or the cryptographic digest thereof and/or the related contextual information and/or the cryptographic digest thereof are verified by using the secured entity of the metering unit, at step 310.
- the cryptographic digest of the data and/or the contextual information or the cryptographic digest thereof is sent to the trusted third party/parties, at step 306.
- the trusted third party/parties will return the sent data with (preferably signed) time stamp as a non-repudiable data item. Then, the undeniable information is constructed and stored, at steps 308 and 312, as described above. In one, either alternative or supplementary, embodiment the data and the contextual information thereof can still be verified in the secured entity 310 after sending the aforesaid data and contextual information to the trusted third party at 306.
- Figure 4a illustrates a rough flow diagram of possible procedures of the metering unit in connection with an embodiment of the present invention.
- the metering unit may verify the components in it 402, i.e. the secured entity, as well as the associated configurations and/or preferably information related to its location.
- the metering unit preferably obtains information about the network topology 404, i.e. the locations of elements nearby it in the network, and after that, the metering unit initiates the obtaining and the verification of the data passed through the router 406.
- the verification of one or more components in the metering unit 402 may be performed right after the metering unit is assembled to its location and optionally every time the configuration(s) of the metering unit are changed.
- the metering unit may be configured to perform the verification occasionally or periodically, e.g. once in a week.
- Acquisition and verification of the information related to the network topology 404 may be performed more often than the verification of the metering unit (identity and/or e.g. configuration) itself. Since the elements in the network may change frequently, although the locations of routers may be more stabile, the information concerning the network topology may expire fast. The appropriate time period for confirming the network topology may be once in a minute or on daily/weekly basis, for instance. In one embodiment the metering unit monitors the elements nearby it continually by a background run.
- the obtaining and verification of the data passed through the router 406 may be performed substantially continuously. At least functional connectability between the metering unit and the router enables the metering unit to at least monitor the transferred data. In some embodiments the transferred data may also physically pass through the metering unit.
- the secured entity provides a certification that the particular secured entity is genuine 410. It may confirm that the used public/private key pair of the secured entity for signing is protected, too.
- the certificates may be verified and signed by trusted third party, typically a certificate authority.
- the metering unit may obtain information related to its own location in the network topology 412.
- the location information can be obtained by several ways.
- the metering unit may utilize a link state protocol, for instance, requesting the MAC-address of the router, to which the metering unit is connected, by using a proper protocol, e.g. ARP -protocol (Address Resolution Protocol).
- ARP -protocol Address Resolution Protocol
- the metering unit can also determine whether it is within a wider area, such as an intranet.
- the metering unit may obtain information related to its location in the network topology by detecting the network or sub-network wherein it is located.
- It may acquire location information by monitoring network address information of one or more other network elements, e.g. neighbouring elements, and/or of the metering unit and/or the router itself, for example.
- the identifying information of the router that the metering unit is connected to, or of other element(s) may be entered manually to the metering unit by using the control means of the metering unit, for example.
- the metering unit verifies the information related to its configuration(s) and location in the network.
- the obtained and verified information related to the location and configuration(s) of the metering unit is stored in the storage means of the metering unit.
- the information, such as location and/or configuration information, related to the elements nearby the metering unit in the network is obtained 420, for example, by inquiring/requesting the MAC-address of the elements.
- the metering unit may also require the obtained information to be verified by the secured entity of the elements.
- the metering unit may collect information about the network topology by monitoring the IP-signaling of the elements and collecting the required information from it.
- the metering unit may as well control the authenticity of the obtained information by observing the response time of the elements. For example, the response time should be short if the element is claimed to be nearby the metering unit.
- the used memory may be the storage means of the metering unit or the metering unit may collect the network topology information to some external storage, which might be shared between several metering units and/or other devices.
- the stored information about the network topology can be united afterwards with the information of the other metering units and/or the network topology information collected by some other components to create a wider view of the elements in the network and a route of some particular data packet. This information is useful when tracking afterwards a precise error point of a transferred data packet.
- the method for verifying the data passed through the router is utilized while monitoring and verifying the network traffic in the aspect of SLA (Service Level Agreement).
- At least one metering unit according to an embodiment of the present invention is preferably utilized to monitor input and/or output traffic of the network so as to produce undeniable information including accurate timestamp for the purposes of the SLA system.
- the metering unit is configured to monitor the acknowledgement traffic of the router, where at least one party in the transmission path is the router and the other(s) may be, for example, the entity that has sent the transferred data and/or the end user, who receives the transferred data.
- the verification procedure may be accomplished after the acknowledgement information is sent and/or received by the router.
- the procedure of monitoring the acknowledgement traffic preferably allows the metering unit to verify faultless packets only; whereas the corrupted packets may be omitted by the metering unit or possibly some other classification procedure may be performed to them.
- the metering unit may be configured to delete the corrupted packets completely, which induces a missing packets situation noticed in a receiving entity, for example in a host device of the end user, and which will further initiate the packets retransmission.
- the sent and/or received acknowledgement information may be included in the contextual information of the data passed through the router.
- the reliability of the undeniable information of performed actions and/or actualizations of delivered services is increased and afterwards it is easier to undeniably verify the functionality of the router.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Health & Medical Sciences (AREA)
- Cardiology (AREA)
- General Health & Medical Sciences (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
A metering unit, functionally connectable to a router, and related method for monitoring and processing the data passed through a router, wherein the metering unit, internal or external device of the router, is capable of undeniably verifying outcomes of performed actions, actualizations of delivered services and/or current configurations. In addition, the metering unit is advantageously capable of monitoring and collecting the information of the network topology, such as the locations of its own and the elements nearby it in the network topology.
Description
METERING UNIT FOR UNDENIABLE SERVICE MANAGEMENT AND A RELATED METHOD
FIELD OF THE INVENTION This invention relates generally to communications networks. More particularly the present invention is directed to an undeniable service management platform for a packet switching network and a method for undeniably verifying outcomes of performed actions, actualizations of delivered services and/or presence of configurations.
BACKGROUND OF THE INVENTION
Today a packet switching network, such as the Internet, which is an aggregate of multiple smaller networks, may have countless of users throughout the world. In addition to email, packets transferred on the Internet may include various other forms of data like video streaming data and bi-directional voice communications, for instance.
The importance and the usage of the Internet are rapidly changing as enhanced techniques including different broadband methods offer more possibilities to exploit more advanced applications. Accordingly, e-commerce is growing fast; it has been estimated that product sales in online shops totaled $146.4 billion in the United States in 2006, for example, whereupon the importance of the e-commerce is increasing year by year. Another example is provided by the e-services that the governments of several countries and enterprises offer to citizens and customers, respectively, for doing business in the Internet. For example, electronic voting is already possible e.g. in Estonia and will also be introduced in many other countries in the near future.
However, the increased possibilities to do business in Internet have also brought on new security concerns. For example, frauds, identity thefts and phishing are some examples of today's threats in the Internet. Protecting confidential information is a customary business requirement, and in many cases also an ethical and/or legal requirement. Demands for the successful fulfillment of the legal requirements will
be on the increase when the Internet solutions replace critical solutions, such as the above-mentioned voting. For instance, European Union has given a directive on the retention of identifying information that shall be saved for even two years. The responsibility to retain the identifying information may be left to the providers of publicly available electronic communications services or of public communications networks.
The verification of the level of service management, the accuracy of configurations or the actualization of services or management actions is not always simple to accomplish. Because of outsourcing and third parties service management of the Internet has spread causing difficulties in verifying the above-mentioned security issues. Nevertheless, preserving the trust of the subscribers or other users and the various governments in the disjointed and controlled environment requires clear and undeniable verifiability of deviations, i.e. who did what and when.
US 2006150153 Al discloses a method for verifying digital objects by creating a unique digital fingerprint. The creation of the fingerprint is done inside a terminal device and stored along with the object. The verification method can be used to validate that the digital object has not been semantically altered, despite the restructuring or reformatting of the object.
US 2005286535 Al discloses methods for verifying consumer equipment that is connected to a packet switched network. Information is hashed to generate a first hash value. Also the information in a memory of the consumer equipment is hashed in order to generate a second hash value. After that, the first hash value and the second hash value are compared to generate a verification indication for the consumer equipment. The Quality of Service for information packets that are communicated with the consumer equipment through the packet switched network is controlled based on the verification indication.
SUMMARY OF THE INVENTION
The objective of the present invention is to at least alleviate one or more of the aforesaid defects related to the prior art solutions what comes to the authentication of service management.
The objective is met by a metering unit, a system and a related method for monitoring and processing the data passed, or to be passed, through a router or through other data emitting and/or forwarding entity. The metering, or "monitoring", unit according to an embodiment of the present invention, physically being either an internal or external to the router, is advantageously capable of undeniably verifying the outcomes of performed actions, actualizations of delivered services and/or configurations. In addition, the metering unit is preferably capable of monitoring and/or collecting the network topology information, such as the locations of its own and the elements near it in the network topology. Accordingly, in one aspect a metering unit functionally connectable to a router comprises a processing means for executing instructions and processing data, a storage means for storing data, and a transceiver for receiving and transmitting data, said metering unit further comprising one or more secured entities, such as trusted platform modules (TPM), for verifying, such as signing, data in the metering unit, the metering unit being configured to obtain information related to the data passed through the router, such as a piece of the passed data or other information representing the passed data, and contextual information, such as identifying information, data transfer direction information, metering unit configuration information, local time stamp information, and/or network topology information, obtain a cryptographic digest, such as a hash, for the information related to the data passed through the router and optionally to at least part of the contextual information, obtain a non-repudiable data item, such as a time stamp, from a trusted third party, such as a trusted time stamp server, relative to cryptographic digest and optionally to at least part of the contextual information, and to construct undeniable information and store it in the storage means, said undeniable information comprising the cryptographic digest, the contextual information, the non-repudiable data item, and verification information, such as a signature, based on verifying at least one of said digest, contextual information, and non-repudiable data item by the secured entity.
In one embodiment, all three elements, i.e. digest, contextual information and the non-repudiable data item, are verified. In another embodiment, only selected one or two of these elements are verified. Instead of all contextual information, only part of it may be verified. According to another aspect of the present invention, a method for generating undeniable information, to be performed by a metering unit, comprises:
- obtaining information related to data passed through a router and to be verified, such as a piece of the passed data or other information representing the passed data, and contextual information, such as data transfer direction information, metering unit configuration information, local time stamp information, and/or network topology information,
- obtaining a cryptographic digest, such as a hash, for the information related to the data passed through the router and optionally to at least part of the contextual information, - obtaining a non-repudiable data item, such as a time stamp, from a trusted third party, such as a trusted time stamp server, relative to cryptographic digest and optionally to at least part of the contextual information,
- verifying, such as signing, at least one of said digest, contextual information, and non-repudiable data item by the secured entity, - constructing undeniable information, said undeniable information comprising cryptographic digest, the contextual information, the non-repudiable data item, and verification information, such as a signature, and
- storing said undeniable information.
In a further aspect, a system for generating undeniable information comprises a metering unit and at least one trusted third party for providing a non-repudiable data item. Additionally, the system may further comprise a network management system for controlling said metering unit.
In one embodiment, which may be executed as a stand-alone or supplementary solution, a method for verifying locations and configurations of a metering unit and
one or more elements in the network, to be performed by the metering unit, comprises:
- obtaining information related to the configuration and location of the metering unit in the network topology, - verifying information related to the configuration and location of the metering unit in the network topology,
- storing the obtained and verified information related to the configuration and location of the metering unit,
- obtaining information related to one or more elements nearby the metering unit in the network topology,
- verifying the obtained information related to the one or more elements nearby the metering unit in the network topology, and
- storing the obtained and verified information related to the one or more elements nearby the metering unit in the network topology. Distance and/or nearness may be determined embodiment-specifically. Distance/nearness may refer to physical distance/nearness and/or logical distance/nearness. For example, distance/nearness may be determined utilizing at least one item selected from the group consisting of: element's network address or at least part thereof, transfer delay (one-way or roundtrip), geographical location (e.g. coordinates), and number of hops. Differences between the addresses or locations of two entities may be then used for determining the distance/nearness between them, for instance. The associated decision logic may apply fixed and/or dynamic threshold values. Accordingly, nearby elements relative to the metering unit may be determined. In one embodiment the metering unit may be configured to obtain ((through monitoring, for instance, the related parameter(s) such as the applied digest function) and verify its configuration(s) and location in the network topology. The verification may be performed by obtaining the non-repudiable data item from a trusted third party and/or by using the secured entity of the metering unit for signing the undeniable information consisting of configuration and location information and the non- repudiable data item.
In another embodiment the metering unit may also be configured to obtain information related to the elements near it, according to predetermined criterion or criteria, in the network topology by using various one or more techniques.
In a further, possibly supplementary, embodiment the metering unit may be configured to monitor and store the data (or at least part or indication thereof) passed through the router and the identifying information thereof. A cryptographic digest calculation may be performed for the data, or the hash or corresponding function's outcome for the data may be obtained by some other way. The non- repudiable data item may be obtained from the trusted third party. The undeniable information about the data passed through the router may be constructed by verifying with secured entity selected information as described herein in connection with various embodiments. The undeniable information may be then stored in the memory.
In a further embodiment one or more network elements, including the metering unit itself, are verified by using the trusted platform module (TPM) technique.
In one embodiment the cryptographic digest (function) calculation of data (e.g. bit stream) may be performed to adequate parts of the data (stream).
The utility of the present invention arises from plurality of issues. The invention provides an effortless way for retain identifying information and undeniably verify the outcomes of performed actions, actualizations of delivered services and/or presence/nature of current configurations. Embodiments of the invention may also alleviate difficulties related to invoicing. Reliable verification of that the transmitted data has passed through the router may be made, according to the present invention, independent of operators or service providers. While retaining the identifying information required by e.g. the authorities, the metering units can be utilized by a network operator for invoicing services on Internet traffic terms without using a heavy connection set-up managed by the operator. The suggested procedure may further prevent the "man-in-the-middle" -type of misuse of the network resources and services. Moreover, the reliability of the data traffic may be generally leveraged when it is possible to undeniably track the device and point of time where e.g. a transmission error has occurred.
In this text "data passed through the router" or "passed data" refers to any kind of data transferred via the router, such as data packets and data stream. The transferred
data may be for example email data, image data, voice data, audio and/or video stream to name a few.
The expression "identifying information" refers to any kind of information included in the transferred data that can be utilized as such or together with other information to identify data traffic.
The expression "trusted third party" may refer to one or more entities, such as a timestamping authority and/or a certificate authority, which provide(s) required trusted information.
Furthermore, the expression "non-repudiable data item" may refer herein to a piece of data, such as a time stamp relative to the receiving time of a cryptographic digest (by e.g. a time-stamp service), preferably signed and/or otherwise verified such that the correctness and advantageously creation time of which cannot be disputed. For example, the data item may include a time stamp with a signature covering e.g. the cryptographic digest, the associated time indication and optional further elements. In this text "cryptographic digest function" refers to a selected function, such as a hash function, generated about the data passed through the router by using a selected, preferably complex-to-hack, algorithm. The intent of this preferably substantially one-way (irreversible) function is to generate what in this document is called a "cryptographic digest", that is, an unique identification of the source data, based on the essential property of the cryptographic digest function that guarantees (with a reasonable probability, taking into account the state-of-the-art) that no other piece of data will provide the same cryptographic digest when used as an input to the cryptographic digest function.
Still, the expression "undeniable information" refers herein at least to the data that the metering unit obtains and at least partially verifies by utilizing the secured entity.
Further, the expression "contextual information" may refer herein to identifying information, data transfer direction information, metering unit configuration information, time (stamp) information and/or network topology information. In this text the expression "network resource" refers to whatever is obtained and/or controlled over the network.
Various embodiments of the present invention are disclosed in the dependent claims.
BRIEF DESCRIPTION OF THE DRAWINGS
Next the invention will be described in more detail with reference to the following drawings:
Fig. 1 illustrates an example of a network and the location of the metering unit in the network topology.
Fig. 2 shows a block diagram of internals of the metering unit in accordance with an embodiment of the present invention. Fig. 3 illustrates a flow diagram of an embodiment of a method for generating undeniable information according to the present invention.
Fig. 4a illustrates a rough flow diagram of the operation of the metering unit according to one embodiment thereof.
Fig. 4b illustrates a flow diagram of an embodiment of a method for verifying configuration and the location of the metering unit.
Fig. 4c illustrates a flow diagram of an embodiment of a method for collecting information about the network topology.
DETAILED DESCRIPTION OF THE EMBODIMENTS Figure 1 illustrates an example of a network and the location of the metering unit in the network topology. Figure 1 is no way meant to be precise representation of the network architecture, but only to serve as a rough example of possible elements in the network and their mutual functional connections. User (terminal) and network devices 102 are connected in the networks via different access points such as base stations, WLAN access points, and/or routers 104 (several of such functionalities may also be integrated with a single physical apparatus), and the routers 104 are typically connected with several other routers of a number of networks. A metering unit 106, according to an embodiment of the present invention, is functionally connectable to one router 104, i.e. the metering unit 106 can either be integrated in a
router 104 or it can be an external device or, in some cases, the metering unit 106 can even be physically distributed. The router is an element that forwards data between the sender and recipient thereof. The router may be located in a network, or a border of two or more (sub-)networks, and connect the multiple networks together, for example. The metering unit 106 may monitor one or more routers 104. Generally, the trusted third party 110 is a network device, e.g. a server, to which the metering unit 106 connects via the network, whereas the control means 108 may be directly connected to the metering unit 106. Alternatively, the (remote) control means 108 is connected to the metering unit 106 via the network. The network, wherein the metering unit operates, may be a private or a public packet switching network or a part of a larger network or other type of a communications network having at least one router in it. The connections to the network and/or within the network may be implemented in a wired, such as fiber optics or cable, and/or wireless manner, such as radio waves, micro waves and infrared waves, for example. The user (terminal) and network devices 102 being at least functionally connected to a router 104 may include any type of devices typically used in the network, such as PC's, laptops, mobile devices, servers, hosts, etc., to name a few. Furthermore, the data transferred in the network may be located in packets or it may be multimedia data transferred as a stream of packets. The control and/or the configuration of the metering unit, as well as reading and/or transfer of the stored data from the storage means of the metering unit, can be provided with one or more remote control means 108, such as a network management system dedicated or an integrated part of a larger whole. The remote control means 208 can be any type of separate device capable for connecting to the metering unit 106 and it may contain a user interface for controlling the metering unit 106. Instead or in addition to the separate device, the metering unit 106 may also comprise a user interface providing possibility to directly control and/or configure the metering unit. In this case, the user interface may comprise a display or a connector to an external display, and keyboard/keypad or other applicable control input means (e.g. touch screen or voice control input, or separate keys/buttons/knobs) configured so as to provide the user of the metering unit 106 with practicable data visualization and metering unit control means.
Moreover, the metering unit obtains the non-repudiable data item from a trusted third party 110, which can be one or more entities, such as timestamping authority
or certificate authority. Generally, the trusted third party is a service external of the metering unit, more generally, the trusted third party is accessible via the network as the other user and network devices. The trusted third party is normally an authority or an instance approved by an authority, e.g. a reliable timestamp can be obtained from French postal service. Usually, the used trusted third parties are such that the acquiring of the non-repudiable data item is performed fast enough, e.g. within a few seconds. Distributed or multiple trusted third parties as well as several trusted third party servers/services can also be used to eliminate (as far as possible) the need to trust any single trusted third party stakeholder/system. That will further increase the reliability and reduce the vulnerability of timestamps. Alternatively, the metering unit could itself comprise an entity for providing non-repudiable data items. Typically, the non-repudiable data item includes accurate time reference data, for example a timestamp, which is utilized to unquestionably define a certain point of time. With the reference to Figure 2, an embodiment of the metering unit in accordance with the present invention comprises a processing means 202, a storage means 204, one or more transceivers 206, a control means 208, one or more secured entities 210 and, optionally, one or more additional logic blocks 212.
At first, the control means 208 is a local internal counterpart to the external control means 108 in Fig. 1. The control means 208 may contain, for example, local execution logic of the remote control means for implementing the instructions by the remote control means.
Still, the processing means 202 comprises at least one processor, such as one or more microprocessors, micro-controllers, DSP's (digital signal processor), programmable logic chips, etc., or any desired combination thereof. In addition, the processor may comprise a plurality of cooperating processors or sub-processors. The processing means 202 is configured to execute the code stored in a storage means 204, which may imply processing instructions and data relative to the metering unit functionalities of the present invention and optionally other functionalities, such as OS related functionalities, I/O-related functionalities, and other applications. In addition, the processing means 202 controls the secured entity 210, as well as the additional logic blocks 212.
Furthermore, the storage means 204 may be divided between one or more physical memory chips or other memory elements, and it may comprise code, e.g. in a form of a computer program/application for the metering unit, and other data. Moreover, the storage means 204 may further include other storage media, such as a preferably detachable memory card, a floppy disc, a CD-ROM, fixed storage medium such as hard drive. The storage means 204 may be non-volatile, e.g. ROM, PROM, EEPROM or flash memory, and/or volatile, e.g. RAM, by nature.
Moreover, the transceiver 206, complying with predetermined wired or wireless technology, for communication primarily with the router the metering unit is connected to and, in addition to that, with other devices such as network devices and separate devices, for example the control means of the metering unit. The transceiver can be a device that has both transmitting and receiving capabilities or the transceiver may consist of a separate transmitter and receiver. While having more than one transceiver in the metering unit, some of transceivers can be implemented for wired network, for example converting electrical pulses to light and vice versa, and the other can be implemented for wireless network technology, such as GSM, UMTS, WLAN, Bluetooth, Wimax, etc.
Furthermore, the secured entity 210 included in the metering unit is for verifying and signing the information obtained by the metering unit. The secured entity 210 may be implemented by using the trusted platform module (TPM) technique or some other technique, in which the secured entity 210 is a physical device having a unique identifier and in which the functionalities of the entity are physically secured. Usually, the secured entity has a public/private key pair, which the private key is generated within the secured entity and never exposed outside it. The metering unit may also comprise additional logic blocks 212, such as a math block, for processing data packets. The logic blocks 212 are typically stored in the storage means 204 of the metering unit and they can be executed by the processor 202. The logic blocks, especially math blocks, can be used for the cryptographic digest function, i.e. the hash function, calculation. Several methods can be used for the hash function calculation, e.g. RIPEMD- 128, RIPEMD- 160 and/or SHA-2 family. Therefore, a table or other entity may be maintained for the hash function so as to confirm, with which method the cryptographic digest function has been calculated. The cryptographic digest function calculation method is advantageously changeable and the other advantageous requirements for the method are that the
calculation procedure is fast enough and the approximated crack time of the hash function should be at least as long as the required retaining time of the identifying information, e.g. about two years.
It is clear to a skilled person that the metering unit may, in practice, comprise numerous further functional and/or structural elements for providing various beneficial communication, processing, or other features, whereupon this disclosure is not to be constructed as limiting the presence of potential additional elements in any manner.
Turning to Figure 3, Figure 3 illustrates a flow diagram of the method for constructing undeniable information according to the present invention. The method for verifying and signing information with the secured entity is similar regardless of the content of the information. Thus, the verification method for every verification step in the metering unit is described herein in conjunction with Figure 3.
At step 302, the data that is desired to be verified is obtained. The data can be any information obtained by the metering unit: data passed through the router, information related to the network topology and/or to configuration (e.g. predetermined configuration parameters such as the used digest function, transfer speed, QoS (quality of Service settings), etc.) of the metering unit, for example. The transferred data packets or data stream may be e.g. email, image, voice, audio and/or video stream. When it comes to data stream, it is divided into appropriate packets, e.g. duration of about 1-2 second, depending on the buffer length of the router. Mark bits may are added to the packets so that synchronization of the cryptographic digest functions can be performed afterwards. Moreover, the data can be obtained several ways. While data is transferred via the router, it will also preferably pass through the metering unit, but in the case of the network topology and related data, for example, the metering unit may request the desired data, or the metering unit may monitor the data traffic and obtain the desired information from there.
Further, contextual information, such as identifying information of the data passed through the router, is obtained at the step 302. The identifying information typically comprises data traffic and location information, such as data transfer direction information, as well as information required for identifying the subscriber or the user of a network resource, e.g. the connection source, the destination information
of the packet, starting time of the transfer, the ending time of the certain network resource, etc. The other contextual information may comprise information related to the network topology and/or to configurations of the metering unit, for example, or some other related information, e.g. timestamp of the metering unit. At step 304, the metering unit obtains the cryptographic digest for the data desired to be verified. In some embodiment the cryptographic digest is calculated in the metering unit by using an additional math block or by the secured entity. In some other embodiment the cryptographic digest is obtained by some other way. For instance, the calculation may be performed by some other element in the network, e.g. the metering unit in the service producer's side on the network, and the cryptographic digest is passed together with the data. This is a lighter way to produce the cryptographic digest, but, however, potentially more unreliable. In addition, if a data passed through the router has a well known hash function, the hash function can be obtained instead of the cryptographic digest calculation. In some cases the hash function of the data can be obtained from somewhere else, but the cryptographic digest may be calculated nevertheless. Yet, in an additional or alternative embodiment, the cryptographic digest function consists of the number of the data packets. On the other hand, in case the metering unit obtains information about the network topology, the cryptographic digest calculation cannot be performed this way. In one more, either alternative or supplementary, embodiment the cryptographic digest is obtained for the contextual information or suitable parts thereof, too. This is convenient in case the contextual information is also desired to be verified by the trusted third party/parties, for instance.
At step 306, the cryptographic digest function/functions is/are sent to a trusted third party/parties and the signed cryptographic digest function/functions is/are returned with the non-repudiable data item/items. The non-repudiable data item is typically a timestamp indicating the exact point of time. For increasing the reliability the timestamp can be obtained from various trusted third parties.
The undeniable information is constructed at step 308 by attaching the cryptographic digest function and/or hash function and the non-repudiable data item as well as the contextual information to the data that is desired to be verified. In case of the data passed through the router, the data to be verified may comprise at least the suitable parts of the transferred data. If the data has well known hash function, the hash function with the identifying information might be sufficient
instead of the data. In some cases, a part of the data with the identifying information may be enough, for example, in the case of streaming data, and otherwise, the data comprises identifying information and the entire transferred data.
Next, the undeniable information is verified in the secured entity at step 310. Typically, the desired data is verified by sending the cryptographic digest function of the data to the secured entity. Then the secured entity verifies the data by signing the cryptographic digest and/or optional further data using the private key of the secured entity and returns the signed cryptographic digest and/or optional further data back to the metering unit. Finally, the undeniable information is stored in the memory, step 312. The memory may be the storage means of the metering unit or it may be some other external storage. In case of external storage, several metering units may employ the same storage. In one embodiment, information related to the data transferred via the router includes the transferred data itself (e.g. consumed content such as an audiovisual representation, e.g. a movie) or at least part thereof, and is stored as such. In some embodiments, the metering unit may supervise, through background execution of a related monitoring task, for example, that multiple copies of the transferred (payload) data or part of it are not stored, for instance, if a copy is already stored in the local or remote storage to which the metering unit has access. In that case, the metering unit may have gained a link to the stored data from the sending device and the metering unit may then optionally forward the link, e.g. within the contextual information, in conjunction with the transferred data to the next device, for example. Alternatively, the metering unit may itself generate a link to the already-stored copy of the transferred data after detecting the existence thereof. The metering unit may, for example, compare existing digests of older data transmissions to the just determined digest of the current transmission and when a match is found, generate the link instead of storing the same transferred data once more. In case the metering unit stores the data in some external storage and/or the storage means of the metering unit, the metering unit may include a qualifier, e.g. a link, in the transferred data to indicate to the other devices that the data has already been stored. Alternatively or additionally, the undeniable information may be transmitted for permanent storing to a network management and/or some other management or other entity associated with one or more metering units. The undeniable information may be sent e.g. as appropriate-sized blocks or immediately after generating it.
Generally, access codes, for example, bank access codes and alike, are not stored or they are stored in encrypted form. While storing encrypted information, it is possible to store also the encryption keys so that the encrypted information is decodable afterwards. Otherwise, the undeniable data that relates to the configuration of the metering units and the network topology is normally stored as such.
Alternatively, in other embodiment the construction and the verification of the undeniable information are performed in a different order as can be seen in Figure 3 presented with broken arrows. After obtaining the data and related contextual information, at step 302, and obtaining the cryptographic digest function for the data and possibly for the contextual information or suitable part(s) thereof, at step 304, the data and/or the cryptographic digest thereof and/or the related contextual information and/or the cryptographic digest thereof are verified by using the secured entity of the metering unit, at step 310. Next, the cryptographic digest of the data and/or the contextual information or the cryptographic digest thereof is sent to the trusted third party/parties, at step 306. The trusted third party/parties will return the sent data with (preferably signed) time stamp as a non-repudiable data item. Then, the undeniable information is constructed and stored, at steps 308 and 312, as described above. In one, either alternative or supplementary, embodiment the data and the contextual information thereof can still be verified in the secured entity 310 after sending the aforesaid data and contextual information to the trusted third party at 306.
Turning to Figure 4a, Figure 4a illustrates a rough flow diagram of possible procedures of the metering unit in connection with an embodiment of the present invention. At first, the metering unit may verify the components in it 402, i.e. the secured entity, as well as the associated configurations and/or preferably information related to its location. Next, the metering unit preferably obtains information about the network topology 404, i.e. the locations of elements nearby it in the network, and after that, the metering unit initiates the obtaining and the verification of the data passed through the router 406.
Generally, the verification of one or more components in the metering unit 402 may be performed right after the metering unit is assembled to its location and optionally every time the configuration(s) of the metering unit are changed. In addition, the
metering unit may be configured to perform the verification occasionally or periodically, e.g. once in a week.
Acquisition and verification of the information related to the network topology 404 may be performed more often than the verification of the metering unit (identity and/or e.g. configuration) itself. Since the elements in the network may change frequently, although the locations of routers may be more stabile, the information concerning the network topology may expire fast. The appropriate time period for confirming the network topology may be once in a minute or on daily/weekly basis, for instance. In one embodiment the metering unit monitors the elements nearby it continually by a background run.
Respectively, the obtaining and verification of the data passed through the router 406 may be performed substantially continuously. At least functional connectability between the metering unit and the router enables the metering unit to at least monitor the transferred data. In some embodiments the transferred data may also physically pass through the metering unit.
The steps concerning the verification of the components in the metering unit is illustrated in Figure 4b. At first, the secured entity provides a certification that the particular secured entity is genuine 410. It may confirm that the used public/private key pair of the secured entity for signing is protected, too. The certificates may be verified and signed by trusted third party, typically a certificate authority.
After certification of the secured entity 410, the configuration(s) and the location information of the metering unit can be verified as described herein, for instance. In the beginning, the metering unit may obtain information related to its own location in the network topology 412. The location information can be obtained by several ways. The metering unit may utilize a link state protocol, for instance, requesting the MAC-address of the router, to which the metering unit is connected, by using a proper protocol, e.g. ARP -protocol (Address Resolution Protocol). The metering unit can also determine whether it is within a wider area, such as an intranet. The metering unit may obtain information related to its location in the network topology by detecting the network or sub-network wherein it is located. It may acquire location information by monitoring network address information of one or more other network elements, e.g. neighbouring elements, and/or of the metering unit and/or the router itself, for example. On the other hand, the identifying information
of the router that the metering unit is connected to, or of other element(s), may be entered manually to the metering unit by using the control means of the metering unit, for example.
At step 414, the metering unit verifies the information related to its configuration(s) and location in the network. At step 416, the obtained and verified information related to the location and configuration(s) of the metering unit is stored in the storage means of the metering unit.
Respectively, in Figure 4c, the information, such as location and/or configuration information, related to the elements nearby the metering unit in the network is obtained 420, for example, by inquiring/requesting the MAC-address of the elements. In some embodiment the metering unit may also require the obtained information to be verified by the secured entity of the elements. In one other, either supplementary or alternative, embodiment, the metering unit may collect information about the network topology by monitoring the IP-signaling of the elements and collecting the required information from it. Further, in some advanced embodiments, the metering unit may as well control the authenticity of the obtained information by observing the response time of the elements. For example, the response time should be short if the element is claimed to be nearby the metering unit. Next, the obtained information about the network topology is then verified by the secured entity 422. Finally, the obtained and verified information related to the network topology is stored in the memory 424. The used memory may be the storage means of the metering unit or the metering unit may collect the network topology information to some external storage, which might be shared between several metering units and/or other devices. The stored information about the network topology can be united afterwards with the information of the other metering units and/or the network topology information collected by some other components to create a wider view of the elements in the network and a route of some particular data packet. This information is useful when tracking afterwards a precise error point of a transferred data packet.
In a preferred embodiment the method for verifying the data passed through the router is utilized while monitoring and verifying the network traffic in the aspect of SLA (Service Level Agreement). At least one metering unit according to an
embodiment of the present invention is preferably utilized to monitor input and/or output traffic of the network so as to produce undeniable information including accurate timestamp for the purposes of the SLA system.
In one, either supplementary or alternative, embodiment the metering unit is configured to monitor the acknowledgement traffic of the router, where at least one party in the transmission path is the router and the other(s) may be, for example, the entity that has sent the transferred data and/or the end user, who receives the transferred data. In this embodiment, the verification procedure may be accomplished after the acknowledgement information is sent and/or received by the router.
The procedure of monitoring the acknowledgement traffic preferably allows the metering unit to verify faultless packets only; whereas the corrupted packets may be omitted by the metering unit or possibly some other classification procedure may be performed to them. The metering unit may be configured to delete the corrupted packets completely, which induces a missing packets situation noticed in a receiving entity, for example in a host device of the end user, and which will further initiate the packets retransmission.
Furthermore, the sent and/or received acknowledgement information may be included in the contextual information of the data passed through the router. Thus, the reliability of the undeniable information of performed actions and/or actualizations of delivered services is increased and afterwards it is easier to undeniably verify the functionality of the router.
The scope of the patent will be defined by the appended claims. Skilled persons will appreciate the fact that various changes and modifications may be made to the explicitly disclosed embodiments and features thereof without diverging from the scope as set forth in the claims.
Claims
1. A metering unit (106) functionally connectable to a router comprising a processing means (202) for executing instructions and processing data, a storage means (204) for storing data, and a transceiver (206) for receiving and transmitting data, said metering unit further comprising one or more secured entities (210), such as trusted platform modules (TMP), for verifying, such as signing, data in the metering unit, the metering unit being configured to obtain information related to the data passed through the router, such as a piece of the passed data or other information representing the passed data, and contextual information, such as identifying information, data transfer direction information, metering unit configuration information, local time stamp information, and/or network topology information, obtain a cryptographic digest, such as a hash, for the information related to the data passed through the router and optionally to at least part of the contextual information, obtain a non-repudiable data item, such as a time stamp, from a trusted third party, such as a trusted time stamp server, relative to cryptographic digest and optionally to at least part of the contextual information, and to construct undeniable information and store it in the storage means, said undeniable information comprising the cryptographic digest, the contextual information, the non-repudiable data item, and verification information, such as a signature, based on verifying at least one of said digest, contextual information, and non-repudiable data item by the secured entity.
2. A metering unit of any preceding claim, further comprising a control means (208) for controlling and/or configuring said metering unit and/or providing said undeniable information from said metering unit.
3. A metering unit of any preceding claim, wherein said metering unit is external of said router.
4. A metering unit of claim 1-2, wherein said metering unit is integrated into said router.
5. A metering unit of claim 1-2, wherein said metering unit is physically distributed among a plurality of network devices.
6. A metering unit of any preceding claim, wherein said metering unit comprises one or more logic blocks (212) for processing said collected data.
7. A metering unit of claim 6, wherein one or more of said logic blocks are configured to perform calculation of the cryptographic digest using a cryptographic digest function.
8. A metering unit of any preceding claim, wherein said cryptographic digest function for the data is executed in a device of a service provider and included in the data passed through the router.
9. A metering unit of any preceding claim, wherein said non-repudiable data item comprises a time stamp obtained from said trusted third party.
10. A metering unit of any preceding claim, wherein said information related to the data passed through the router comprises the identification information.
11. A metering unit of claim 10, wherein said information related to the data passed through the router further comprises the data passed through the router.
12. A metering unit of claim 10, wherein said information related to the data passed through the router further comprises a part of the data passed through the router.
13. A metering unit of claims of any preceding claim, wherein a qualifier is included in contextual information to notify other elements in the network about the storage of the data.
14. A metering unit of any preceding claim, wherein said metering unit is configured to obtain and verify the information related to its own configurations and location in the network topology and generating the undeniable information of said obtained information.
15. A metering unit of any preceding claim, wherein said metering unit is configured to obtain and verify the information related to the locations of the elements nearby said metering unit in the network topology and generating the undeniable information of said obtained information.
16. A metering unit of any preceding claim, wherein said network elements, including the metering unit, are verified by using said secured entity/entities.
17. A metering unit of any preceding claim, wherein the metering unit is configured to monitor the acknowledgement traffic of the router.
18. A metering unit of claim 17, wherein the metering unit is configured to verify only the data in relation to which the acknowledgement information is sent and/or received by the router.
19. A metering unit of claim 17 or 18, wherein acknowledgement information is included in the contextual information of the transferred data.
20. A system for generating undeniable information comprising a metering unit (106) of any of preceding claim and at least one trusted third party (110) for providing a non-repudiable data item.
21. A system of claim 20 further comprising a network management system for controlling said metering unit.
22. A method for generating undeniable information (406), to be performed by a metering unit, comprising:
-obtaining information related to data passed through a router and to be verified, such as a piece of the passed data or other information representing the passed data, and contextual information, such as data transfer direction information, metering unit configuration information, local time stamp information, and/or network topology information (302),
-obtaining a cryptographic digest, such as a hash, for the information related to the data passed through the router and optionally to at least part of the contextual information (304), -obtaining a non-repudiable data item, such as a time stamp, from a trusted third party, such as a trusted time stamp server, relative to cryptographic digest and optionally to at least part of the contextual information (306),
-verifying, such as signing, at least one of said digest, contextual information, and non-repudiable data item by the secured entity (310),
-constructing undeniable information, said undeniable information comprising cryptographic digest , the contextual information, the non-repudiable data item, and verification information, such as a signature, (308), and
-storing said undeniable information (312).
23. A method of claim 22, further comprising, in order to verify location and configuration of a metering unit and information related to one or more elements in the network (402, 404):
-obtaining information related to the configuration and location of the metering unit in the network topology (410, 412), -verifying information related to the configuration and location of the metering unit in the network topology (414),
-storing the obtained and verified information related to the configuration and location of the metering unit (416),
-obtaining information related to one or more elements nearby the metering unit in the network topology (420),
-verifying the obtained information related to the one or more elements nearby the metering unit in the network topology (422), and
-storing the obtained and verified information related to the one or more elements nearby the metering unit in the network topology (424).
24. A method of claim 23, wherein said metering unit obtains information related to the network topology by utilizing a link state protocol.
25. A method of any of claims 23-24, wherein said metering unit obtains the information related to the elements nearby said metering unit in the network by monitoring the IP signaling of said elements.
26. A method of any of claims 23-25, wherein said metering unit requests the verification for the information related to the elements nearby said metering unit in the network to be performed by the secured entity of said elements.
27. A method of any of claims 23-26, wherein said metering unit detects at least part of the information related to the elements in the network by monitoring the response time of the elements.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FI20095685 | 2009-06-17 | ||
| FI20095685A FI20095685A0 (en) | 2009-06-17 | 2009-06-17 | Computing hardware for reliable service management and related method |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2010146242A1 true WO2010146242A1 (en) | 2010-12-23 |
Family
ID=40825388
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/FI2010/050517 Ceased WO2010146242A1 (en) | 2009-06-17 | 2010-06-17 | Metering unit for undeniable service management and a related method |
Country Status (2)
| Country | Link |
|---|---|
| FI (1) | FI20095685A0 (en) |
| WO (1) | WO2010146242A1 (en) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1228451B1 (en) * | 1999-11-05 | 2003-12-10 | Sign On I Stockholm Aktiebolag | Automatic form accessing and submission system and method |
| US20070022296A1 (en) * | 2005-07-25 | 2007-01-25 | Gordon Caverly | Electronic data registry and certification system and method |
| US20090044010A1 (en) * | 2007-08-08 | 2009-02-12 | Sun Microsystems, Inc. | System and Methiod for Storing Data Using a Virtual Worm File System |
| CN101447999A (en) * | 2008-10-31 | 2009-06-03 | 神州数码金程(北京)科技有限公司 | Security exchange system and realization method thereof |
-
2009
- 2009-06-17 FI FI20095685A patent/FI20095685A0/en not_active Application Discontinuation
-
2010
- 2010-06-17 WO PCT/FI2010/050517 patent/WO2010146242A1/en not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1228451B1 (en) * | 1999-11-05 | 2003-12-10 | Sign On I Stockholm Aktiebolag | Automatic form accessing and submission system and method |
| US20070022296A1 (en) * | 2005-07-25 | 2007-01-25 | Gordon Caverly | Electronic data registry and certification system and method |
| US20090044010A1 (en) * | 2007-08-08 | 2009-02-12 | Sun Microsystems, Inc. | System and Methiod for Storing Data Using a Virtual Worm File System |
| CN101447999A (en) * | 2008-10-31 | 2009-06-03 | 神州数码金程(北京)科技有限公司 | Security exchange system and realization method thereof |
Non-Patent Citations (1)
| Title |
|---|
| SUNG-WOO T. ET AL: "Modeling and Design of Notarial system supporting Secure Transactions in Electronic Commerce based on the Internet", INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING [ONLINE], January 1998 (1998-01-01), Retrieved from the Internet <URL:http://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=648389&userType=&tag=1> * |
Also Published As
| Publication number | Publication date |
|---|---|
| FI20095685A0 (en) | 2009-06-17 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3948614B1 (en) | System and method of providing policy selection in a network | |
| US8166122B2 (en) | Method and apparatus for generating a figure of merit for use in transmission of messages in a multi-level secure environment | |
| KR102660475B1 (en) | Platform and method for certifying an electronic contract for electronic identification and trust services (eidas) | |
| US8274401B2 (en) | Secure data transfer in a communication system including portable meters | |
| Wang et al. | A large-scale and longitudinal measurement study of {DKIM} deployment | |
| US20050138365A1 (en) | Mobile device and method for providing certificate based cryptography | |
| US8694789B2 (en) | System and method for generating a non-repudiatable record of a data stream | |
| JP2005517348A (en) | A secure electronic messaging system that requires a key search to derive a decryption key | |
| GB2392590A (en) | Establishing a chain of secure communication links for delegation | |
| CA2457478A1 (en) | System and method for warranting electronic mail using a hybrid public key encryption scheme | |
| US9647876B2 (en) | Linked identifiers for multiple domains | |
| US20210184852A1 (en) | System and method for securely transmitting non-pki encrypted messages | |
| US9742722B2 (en) | Method, a system and a computer program product for certifying that a destination email server has received an email message sent from a sender to at least one destination address | |
| CN101667999B (en) | Method and system for transmitting peer-to-peer broadcast stream, data signature device and client | |
| US20170244567A1 (en) | Technique for handling data in a data network | |
| Hale et al. | On end-to-end encryption | |
| KR102462411B1 (en) | Platform and method for authenticating electronic announcements for electronic identification and authentication services (EDS) | |
| JP2009100345A (en) | E-mail relay apparatus | |
| WO2005096543A1 (en) | Method of providing key containers | |
| JP2007053569A (en) | Electronic mail security device and system therefor | |
| JP6548904B2 (en) | Method of generating certified electronic contract by telecommunications company customer | |
| JP2003087232A (en) | Duplicate terminal discovery method | |
| US7949878B2 (en) | Telecommunication-assisted time stamp | |
| WO2010146242A1 (en) | Metering unit for undeniable service management and a related method | |
| JP4543570B2 (en) | Verification system |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 10789069 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 10789069 Country of ref document: EP Kind code of ref document: A1 |