IP Library Patent Application 13979221
Patent Application
App. No. 13/979,221

METHODS AND APPARATUSES FOR DISTRIBUTING KEYS FOR PTP PROTOCOL

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/979,221
Abstract

The present invention provides a solution of automatically distributing PIP keys, and on that basis, provides a new encryption method. A domain control device is proposed to verify whether a network node is an eligible node in the domain; if the network node is an eligible node in the domain, then a key for the PTP protocol is sent to the network node. The methods and apparatuses according to the present invention enable access authentication of various forms of PTP network nodes, as well as the automatic configuration and dynamic sending of PTP keys, such that the security of the keys are significantly increased. Additionally, by means of SignCryption encryption algorithm, it is enabled that for each PTP message, not only message source authentication, message integrity authentication, message confidentiality, and replay protection can be provided, but also its sending network node can be tracked. Thus, the security is significantly increased.

Claims (39)

1 . A method for use in a domain control device of a communication network for distributing a key for the PTP protocol to a network node within a domain, comprising steps of:

verifying whether the network node is an eligible node in the domain; and

sending the key for the PTP protocol to the network node if the network node is an eligible node in the domain.

2 . The method according to claim 1 , wherein the step of verifying comprises steps of:

sending to the network node a request message for querying an identity;

receiving from the network node a response message for querying the identity, the response message comprising information of identity of the network node;

verifying whether the identity of the network node is eligible;

sending to the network node a request message for querying an authentication information;

receiving from the network node a response message for querying the authentication information;

verifying whether the authentication information is eligible; and

sending the key for the PTP protocol to the network node if the authentication information is eligible.

3 . The method according to claim 2 , wherein the identity of the network node and the authentication information are verified based on RADIUS authentication or DIAMETER authentication.

4 . The method according to claim 1 , wherein the step of verifying comprises a step of:

verifying whether the network node is an eligible node in the domain in an EAP authentication manner.

5 . The method according to claim 1 , wherein the step of sending the key for the PTP protocol to the network node comprises a step of:

implementing the sending of the key for the PTP protocol by extending a definition of “Type-Data” in a message that is defined in an EAP authentication.

6 . The method according to claim 1 , wherein the sending of the key for the PTP protocol is implemented by defining an “Expanded Type” in an EAP message to define a new EAP authentication manner.

7 . The method according to claim 1 , wherein the PTP protocol key is sent in a form of encrypted text.

8 . The method according to claim 1 , wherein the key for the PTP protocol comprises a shared symmetrical key defined in Annex K of the PTP protocol.

9 . The method according to claim 1 , wherein the key for the PTP protocol comprises a parameter and a private key defined in a SignCryption algorithm.

10 . A method for use in a network node of a communication network for encrypting a PTP protocol data packet, comprising steps of:

A. receiving a key for the PTP protocol from a domain control device in a domain to which the network node belongs; and

B. performing an encrypted communication following the PTP protocol with another network node in the domain with the key.

11 . The method according to claim 10 , wherein the key for the PTP protocol comprises a parameter and a first private key defined in a SignCryption algorithm, wherein the first private key is generated by the domain control device based on identity information of the network node, the step B comprising steps of:

when sending a unicast PTP data packet, generating a digital signature for the unicast PTP data packet based on the first private key and the identity information of a receiving node, and encrypting a text body of the unicast PTP data packet; and

performing decryption and digital signature verification for a received unicast PTP data packet based on the first private key and the identity information of a sending node.

12 . The method according to claim 11 , wherein the network node further sends and receives multicast or broadcast PTP data packets, and wherein the key for the PTP protocol further comprises identity information for a multicast group or broadcast group defined in the SignCryption algorithm and a second private key generated based on the identity information,

the step B further comprising steps of:

when sending a multicast or broadcast PTP data packet, generating a digital signature for the multicast or broadcast PTP data packet based on the first private key and the identity information of the multicast group or broadcast group, and encrypting a text body of the multicast or broadcast PTP data packet; and

performing decryption and digital signature verification for a received multicast or broadcast PTP data packet based on the second private key and the identity information of a sending node.

13 . The method according to claim 10 , wherein the key for the PTP protocol comprises a shared symmetrical key defined in Annex K of the PTP protocol, the step B comprising steps of:

performing a security protection for the PTP data packet with the encryption key according to Annex K of the PTP protocol; and

performing a security verification for the PTP data packet with the encryption key according to Annex K of the PTP protocol.

14 . An apparatus for use in a domain control device of a communication network for distributing a key for the PTP protocol to a network node within a domain, comprising:

first verifying means configured to verify whether the network node is an eligible node in the domain;

first sending means configured to send the key for the PTP protocol to the network node if the network node is an eligible node in the domain.

15 . An apparatus for encrypting the PTP protocol data packet in a network node of a communication network, comprising:

first receiving means configured to receive a key for the PTP protocol from a domain control device in a domain to which the network node belongs;

encrypted communication means configured to perform an encrypted communication following the PTP protocol with another network node in the domain with the key.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Aug 25, 2014
From: CREDIT SUISSE AG
To: ALCATEL LUCENT
Reel/Frame 033597/0001 →
SECURITY AGREEMENT Recorded Nov 8, 2013
From: ALCATEL LUCENT
To: CREDIT SUISSE AG
Reel/Frame 031599/0962 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2013
From: YAO, YIFENG
To: ALCATEL-LUCENT
Reel/Frame 030778/0708 →