IP Library › Granted Patent US 12,489,784
Granted Patent B2
US 12,489,784 · App. 17/256,386 · Granted Dec 2, 2025

Methods for verifying the validity of an IP resource, and associated access control server, validation server, client node, relay node and computer program

Inventors: Mohamed Boucadair (Chatillon, FR); Christian Jacquenet (Chatillon, FR)
Assignee: ORANGE
H04L63/1458H04L63/0236H04L63/0263H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,784
App. No.
17/256,386
Granted
Dec 2, 2025
Kind
B2
Abstract

A method for verifying validity of an IP resource associated with a client domain, implemented in an access control server. The method includes: receiving a list of at least one IP resource associated with the client domain, transmitted from a client node of the client domain to the access control server; selecting at least one IP resource to be validated from the list; and verifying the validity of the at least one selected IP resource.

Claims (50)

1 . A method for verifying validity of an IP resource associated with a client domain, implemented in a server, called an access control server, said method comprising:

receiving a list of at least one IP resource associated with said client domain, transmitted from a client node of said client domain to said access control server;

selecting at least one IP resource to be validated from said list, the at least one IP resource selected identifying at least another client node, which is different than the client node that transmitted the list; and

verifying that said at least one selected IP resource identifying at least another client node is actually associated with said client domain comprising the client node that transmitted the list, prior to initiating, by said access control server, any action related to said at least one selected IP resource, wherein the verifying comprises:

transmitting at least one request to the at least one selected IP resource, to be received or intercepted by at least one relay node of said client domain associated with said at least one selected IP resource, said request comprising a control message;

receiving a response to the request including an item of information characteristic of said control message, transmitted by said client node to said access control server, said relay node having previously relayed said request to said client node; and

validating said at least one IP resource selected by correlating said request and said response,

wherein said at least one IP resource selected belongs to a group consisting of an IP address, an IP prefix and a domain name.

2 . The method according to claim 1 , comprising selecting at least one further IP resource to be validated from said list, and wherein said verification further comprises:

obtaining an item of information representative of an identity of said client domain;

identifying at least one validation server associated with said at least one selected further IP resource; and

transmitting to said at least one validation server at least one request comprising said item of information representative of the identity of said client domain and said at least one selected further IP resource.

3 . The method according to claim 1 , wherein a validity period is associated with said list of at least one IP resource associated with the client domain.

4 . The method according to claim 1 , comprising initiating an action in response to a request for action on the at least another client node identified by said at least one selected IP resource.

5 . The method according to claim 4 , wherein said request for action comprises an information that said client domain is under attack and wherein said action is a mitigation action so that suspicious traffic is no longer routed to said client domain.

6 . The method according to claim 1 , comprising receiving a request from a client node of said client domain and to take at least one action to control access to said client domain in response to said request.

7 . The method according to claim 1 , wherein said client domain is a DOTS (DDoS (Distributed Denial of Service) Open Threat Signaling) domain, said access control server is a DOTS server, and said client node is a DOTS client, and wherein the method further comprises deleting, in a table of DOTS entries maintained by the access control server, the DOTS entries indicating IP resources that are not part of the list transmitted by said client node or rejecting DOTS requests indicating an IP resource that is not part of the list transmitted by said client node.

8 . The method according to claim 1 , wherein the list of at least one IP resource is a list of at least two IP resources.

9 . The method according to claim 8 , wherein the access control server does not belong to the client domain.

10 . A method for declaring an IP resource associated with a client domain, said method being implemented in a client node of said client domain and comprising:

obtaining by the client node a list of at least one IP resource associated with the client domain;

transmitting said list by the client node to an access control server configured to verify that said at least one IP resource is actually associated with said client domain;

receiving at least one request originating from said access control server, via at least one relay node of said client domain associated with at least one IP resource selected from said list by said access control server, said at least one IP resource selected belonging to a group consisting of an IP address, an IP prefix and a domain name, said at least one IP resource selected identifying at least another client node, which is different than the client node that transmitted the list, and said request comprising a control message; and

transmitting to said access control server a response to the request including an item of information characteristic of said control message.

11 . The method according to claim 10 , comprising:

receiving an item of information representative of an identity of said client domain, generated by a validation server associated with at least one IP resource selected from said list by said access control server; and

transmitting to said access control server said item of information representative of the identity of said client domain.

12 . The method according to claim 10 , wherein a validity period is associated with said list of at least one IP resource associated with the client domain.

13 . A method for processing at least one IP resource validation request associated with a client domain,

said method comprising:

receiving or intercepting by a relay node of the client domain at least one request to at least one selected IP resource associated with the client domain, said at least one request originating from an access control server and comprising a control message, the at least one IP resource having been selected by the access control server from a list of at least one IP resource actually associated with the client domain and belonging to a group consisting of an IP address, an IP prefix and a domain name, the list being previously transmitted from a client node of said client domain to said access control server, and the at least one IP resource selected identifying at least another client node, which is different than the client node that transmitted the list; and

transmitting by the relay node said at least one request to said client node.

14 . The method according to claim 13 , wherein a validity period is associated with said list of at least one IP resource associated with the client domain.

15 . A method for verifying validity of an IP resource associated with a client domain,

said method comprising:

receiving by a validation server at least one request comprising an item of information representative of an identity of a client domain and of said at least one selected IP resource, the validation server being associated with the at least one selected IP resource, which was selected by an access control server from a list of at least one IP resource associated with the client domain, the list having been previously transmitted from a client node of said client domain to said access control server, the at least one selected IP resource identifying at least another client node which is different than the client node that transmitted the list;

identifying by the validation server said client domain based on said item of information representative of the identity of the client domain; and

verifying by the validation server that the at least one selected IP resource is actually associated with the client domain, taking into account the identity of the client domain, wherein the at least one selected IP resource belongs to a group consisting of an IP address, an IP prefix and a domain name.

16 . The method according to claim 15 , wherein the method comprises, the following acts implemented by the validation server prior to verifying validity of said at least one selected IP resource:

determining said item of information representative of the identity of said client domain; and

transmitting, to said client node, said item of information representative of the identity of the client domain.

17 . The method according to claim 15 , wherein a validity period is associated with said list of at least one IP resource associated with the client domain.

18 . An access control server comprising:

at least one programmable computing machine or one dedicated computing machine configured to verify validity of an IP resource associated with a client domain, implementing:

receiving a list of at least one IP resource associated with said client domain, transmitted from a client node of said client domain to said access control server;

selecting at least one IP resource to be validated from said list, wherein the at least one IP resource selected belongs to a group consisting of an IP address, an IP prefix and a domain name, and the at least one IP resource selected identifies at least another client node, which is different than the client node that transmitted the list; and

verifying that said at least one selected IP resource identifying at least another client node is associated with said client domain comprising the client node that transmitted the list, prior to initiating, by said access control server, any action related to said at least one selected IP resource, wherein the verifying comprises:

transmitting at least one request to the at least one selected IP resource, to be received or intercepted by at least one relay node of said client domain associated with said at least one selected IP resource, said request comprising a control message;

receiving a response to the request including an item of information characteristic of said control message, transmitted by said client node to said access control server, said relay node having previously relayed said request to said client node; and

validating said at least one IP resource selected by correlating said request and said response.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2021
From: BOUCADAIR, MOHAMED; JACQUENET, CHRISTIAN
To: ORANGE
Reel/Frame 054985/0912 →
Priority Claims (1)
FR 1856015 · Jun 29, 2018 · national
Continuity (1)
Related Publication 20210273974A1 · Sep 2, 2021
References Cited (35)
US 8392421B1 · Nucci · 2013 [cited by examiner]
US 8769622B2 · Chang et al. · 2014 [cited by applicant]
US 9288214B2 · Chang et al. · 2016 [cited by applicant]
US 10542001B1 · Leung · 2020 [cited by examiner]
US 20130007845A1 · Chang et al. · 2013 [cited by applicant]
US 20140373138A1 · Park · 2014 [cited by examiner]
US 20150007274A1 · Chang et al. · 2015 [cited by applicant]
US 20160028554A1 · Lea · 2016 [cited by examiner]
US 20160173526A1 · Kasman · 2016 [cited by examiner]
US 20170149833A1 · Ngo · 2017 [cited by examiner]
US 20180041468A1 · Miller · 2018 [cited by examiner]
US 20180054438A1 · Li · 2018 [cited by examiner]
US 20180109554A1 · Reddy et al. · 2018 [cited by applicant]
US 20180159894A1 · Reddy · 2018 [cited by examiner]
US 20190327222A1 · Hsu · 2019 [cited by examiner]
CN 1937499A · 2007 [cited by applicant]
CN 100539501C · 2009 [cited by examiner]
CN 103563294A · 2014 [cited by applicant]
English translation of the Written Opinion of the International Searching Authority dated Sep. 16, 2019 for corresponding International Application No. PCT/FR2019/051609 filed Jun. 28, 2019. [cited by applicant]
“Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile”, D. Cooper et al., RFC 5280, May 2008. [cited by applicant]
“Distributed Denial-of-Service Open Threat Signaling (DOTS) Signal 25 Channel Specification”, draft-ietf-dots-signal-channel, Reddy, T. et al., Jan. 2018. [cited by applicant]
First Chinese Office Action dated Sep. 20, 2022, for corresponding Chinese Application No. 201980051584.6. [cited by applicant]
International Search Report and Written Opinion dated Sep. 6, 2019 for corresponding International Application No. PCT/FR2019/051609, filed Jun. 28, 2019. [cited by applicant]
Mortensen et al., “Distributed Denial of Service (DDoC) Open Threat Signaling Requirements; draft0ietf-dots-requirements-14.txt”, Distributed Denial of Service (DDOS) Open Threat Signaling Requriements; Draft-IETF-DOTS-… [cited by applicant]
Mortenson et al., “Distributed Denial of Service Open Threat Signaling (DOTS) Architecture; draft-ietf-dots-architecture=05.txt”, Distributed Denial of Service Open Threat Signaling (DOTS) Architecture; Draft-IETF-DOTS-… [cited by applicant]
D. Eastlake et al., “Randomness Requirements for Security”, RFC 4086, Jan. 2005. [cited by applicant]
T. Reddy et al., “Distributed Denial-of-Service Open Threat Signaling (DOTS) Data Channel-11”, draft-ietfdots-data-channel, Dec. 18, 2017. [cited by applicant]
P. Ferguson et al., “Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing”, RFC2827, May 2000. [cited by applicant]
E. Guttman et al., “Users' Security Handbook” RFC2504, Feb. 1999. [cited by applicant]
E. Rescorla et al., “Datagram Transport Layer Security Version 1.2”, RFC 6347, DOI 10.17487/RFC6347, Jan. 2012. [cited by applicant]
E. Rescorla et al., “The Datagram Transport Layer Security (DTLS) Protocol Version 1.3”, draft-ietf-tls-dtls13-22, Nov. 29, 2017. [cited by applicant]
T. Dierks et al., “The Transport Layer Security (TLS) Protocol Version 1.2”, RFC 5246, DOI 10.17487/RFC5246, Aug. 2008. [cited by applicant]
E. Rescorla, “The Transport Layer Security (TLS) Protocol Version 1.3”, draft-ietf-tlstls13-23, Jan. 5, 2018. [cited by applicant]
D. McGrew, “An Interface and Algorithms for Authenticated Encryption”, RFC5116, Jan. 2008. [cited by applicant]
P. Leach et al., “A Universally Unique IDentifier (UUID) URN Namespace”, RFC4122, Jul. 2005. [cited by applicant]