IP Library Granted Patent US 7,979,901
Granted Patent B2
US 7,979,901 · App. 11/320,567 · Granted Jul 12, 2011

Controlling the number of internet protocol security (IPsec) security associations

Assignee: Nokia Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,979,901
App. No.
11/320,567
Granted
Jul 12, 2011
Kind
B2
Abstract

The invention provides a system and method for controlling the number of Internet Protocol Security (IPsec) security associations per Internet Key Exchange (IKE) security association for a single user. The limit on the number of security association (SA) tunnels per key management protocol SA may be stored in a server. A user equipment sends a request, to the server, to set up a new SA. The server, upon receiving the request, checks whether the limit on the number of SA tunnels per key management protocol has been reached. The request is accepted when the limit has not yet been reached.

Claims (34)

1. A method comprising:

storing, at a server, a limit on a number of security association tunnels per key management protocol security association;

receiving a request, at the server, from a user equipment to set up a new security association;

checking whether the limit on the number of security association tunnels per key management protocol has been reached; and

accepting the request when the limit on the number of security association tunnels has not been reached.

2. The method of claim 1 , further comprising:

wherein the server is implemented by at least one processor.

3. The method of claim 1 , further comprising:

denying the request when the limit on the number of security association tunnels has been reached.

4. The method of claim 1 ,

wherein the server comprises an authentication, authorization, and accounting server, and wherein the authentication, authorization, and accounting server authenticates a subscriber based on authentication information retrieved from at least one of a home subscriber server and a home location register.

5. The method of claim 1 , wherein the receiving further comprises receiving the request from the user equipment to set up the new security association under an existing key management protocol security association.

6. The method of claim 1 , wherein the storing further comprises storing the limit on the number of security association tunnels in a home subscriber server.

7. The method of claim 1 , further comprising:

deleting a prior security association for a network, when a quantity of security associations is reached.

8. An apparatus comprising:

a memory configured to store a limit on a number of security association tunnels per key management protocol security association; and

a processor configured to

receive a request from a user equipment to set up a new security association;

check whether the limit on the number of security association tunnels per key management protocol has been reached; and

accept the request when the limit on the number of security association tunnels has not been reached.

9. The apparatus of claim 8 , wherein the request is denied when the limit has been reached.

10. The apparatus of claim 8 , wherein the request is sent by a user equipment.

11. The apparatus of claim 8 , wherein the new security association is set up under an existing key management protocol security association.

12. The apparatus of claim 8 , wherein the key management protocol comprises an internet key exchange protocol.

13. The apparatus of claim 8 , wherein the memory is included in a home subscriber server.

14. A system comprising:

storing means, at a server, for storing a limit on a number of security association tunnels per key management protocol security association;

receiving means for receiving a request, at the server, from a user equipment to set up a new security association;

checking means for checking whether the limit on the number of security association tunnels per key management protocol has been reached; and

accepting means for accepting the request when the limit on the number of security association tunnels has not been reached.

15. The system of claim 14 , wherein the receiving means comprises means for receiving the request from the user equipment to set up the new security association under an existing key management protocol security association.

16. The system of claim 14 , wherein the storing means comprises means for storing, at the server, the limit on the number of security association tunnels per internet key exchange security association.

17. The system of claim 14 , wherein the storing means comprises means for storing the limit on the number of security association tunnels in a home subscriber server.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2015
From: NOKIA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 035442/0976 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2005
From: DAJIANG, ZHANG
To: NOKIA CORPORATION
Reel/Frame 017434/0885 →
Continuity (1)
Related Publication 20070157305A1 · Jul 5, 2007