Invention Grant
- Patent Title: Strong anti-replay protection for IP traffic sent point to point or multi-cast to large groups
- Patent Title (中): 强大的反重放保护IP流量点播或多播到大群组
-
Application No.: US11249898Application Date: 2005-10-12
-
Publication No.: US07748034B2Publication Date: 2010-06-29
- Inventor: Scott Roy Fluhrer , Brian E. Weis
- Applicant: Scott Roy Fluhrer , Brian E. Weis
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Trellis IP Law Group, PC
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F12/16 ; G06F7/04 ; H04L9/32

Abstract:
A mechanism for providing strong anti-replay protection at a security gateway in a network for protection against an attacker duplicating encrypted packets. The mechanism assigns a unique sequence number to each encrypted packet and a time stamp. A receiving security gateway rejects packets that have a duplicative sequence number or that is too old to protect itself against replay attacks. Each security gateway checks off the sequence numbers as they are received knowing that the sending security gateway assigns sequence numbers in an increasing order. The receiving security gateway remembers the value of the highest sequence number that it has already seen as well as up to N additional sequence numbers. Any packet with a duplicative sequence number is discarded. In addition to the sequence number, each packet also has an associated time stamp that corresponds to an epoch during which it should be received. If the packet is received after the epoch has expired, the packet is rejected.
Public/Granted literature
- US20070083923A1 Strong anti-replay protection for IP traffic sent point to point or multi-cast to large groups Public/Granted day:2007-04-12
Information query