发明授权
- 专利标题: Cryptographic peer discovery, authentication, and authorization for on-path signaling
- 专利标题(中): 路由信令的密码对等体发现,认证和授权
-
申请号: US11115542申请日: 2005-04-26
-
公开(公告)号: US07350227B2公开(公告)日: 2008-03-25
- 发明人: David A. McGrew , Melinda L. Shore
- 申请人: David A. McGrew , Melinda L. Shore
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Hickman Palermo Truong & Becker LLP
- 主分类号: H04L9/00
- IPC分类号: H04L9/00 ; G06F17/00 ; G06F15/16 ; H04K1/00 ; G06F9/00
摘要:
A method is disclosed for cryptographic peer discovery, authentication, and authorization. According to one embodiment, a data packet, which is addressed to a destination device other than an intermediary network device, is intercepted at the intermediary network device. The data packet contains a request and a group identifier. A shared secret cryptographic key, which is mapped to the group identifier, is selected. A challenge is sent toward an upstream device from whence the data packet came. A response is received. A verification value is generated based on the cryptographic key and the challenge. It is determined whether the response matches the verification value. If the response matches the verification value, then it is determined whether the request is allowed by an authorization set that is mapped to the group identifier. If the request is allowed, then a policy of the intermediary network device is configured based on the request.
公开/授权文献
信息查询