会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • Method, system, and device for negotiating SA on IPv6 network
    • 用于在IPv6网络上协商SA的方法,系统和设备
    • US08418242B2
    • 2013-04-09
    • US12987502
    • 2011-01-10
    • Dong ZhangLifeng Liu
    • Dong ZhangLifeng Liu
    • H04L12/22H04L12/24
    • H04L67/141H04L63/061H04L63/164H04L67/14H04L69/24
    • A method, system, and device for negotiating a security association (SA) on an Internet Protocol version 6 (IPv6) network are disclosed. In this method, the initiator and the responder generate an SA through the interaction of two messages. Compared with the conventional procedure for setting up an SA based on the Internet Key Exchange Protocol (IKE), the interaction procedure in the present invention is simplified significantly. Therefore, the negotiation is faster and more convenient. In addition, with the present invention, cryptographically generated address parameters (CGA Params) are carried in the message and the CGA may be verified so that the invader cannot spoof the address.
    • 公开了一种在因特网协议版本6(IPv6)网络上协商安全关联(SA)的方法,系统和设备。 在这种方法中,发起者和应答者通过两个消息的交互生成SA。 与基于互联网密钥交换协议(IKE)建立SA的常规过程相比,本发明的交互过程被大大简化。 因此,谈判更快更方便。 另外,利用本发明,在消息中携带密码产生的地址参数(CGA Params),并且可以验证CGA,使得入侵者不能欺骗地址。
    • 2. 发明申请
    • METHOD, SYSTEM, AND DEVICE FOR NEGOTIATING SA ON IPv6 NETWORK
    • 在IPv6网络上讨论SA的方法,系统和设备
    • US20110107104A1
    • 2011-05-05
    • US12987502
    • 2011-01-10
    • Dong ZhangLifeng Liu
    • Dong ZhangLifeng Liu
    • H04L9/00
    • H04L67/141H04L63/061H04L63/164H04L67/14H04L69/24
    • A method, system, and device for negotiating a security association (SA) on an Internet Protocol version 6 (IPv6) network are disclosed. In this method, the initiator and the responder generate an SA through the interaction of two messages. Compared with the conventional procedure for setting up an SA based on the Internet Key Exchange Protocol (IKE), the interaction procedure in the present invention is simplified significantly. Therefore, the negotiation is faster and more convenient. In addition, with the present invention, cryptographically generated address parameters (CGA Params) are carried in the message and the CGA may be verified so that the invader cannot spoof the address.
    • 公开了一种在因特网协议版本6(IPv6)网络上协商安全关联(SA)的方法,系统和设备。 在这种方法中,发起者和应答者通过两个消息的交互生成SA。 与基于互联网密钥交换协议(IKE)建立SA的常规过程相比,本发明的交互过程被大大简化。 因此,谈判更快更方便。 另外,利用本发明,在消息中携带密码产生的地址参数(CGA Params),并且可以验证CGA,使得入侵者不能欺骗地址。
    • 3. 发明授权
    • Method, system and apparatus for establishing communication
    • 用于建立通信的方法,系统和装置
    • US08880891B2
    • 2014-11-04
    • US12976701
    • 2010-12-22
    • Lifeng LiuDong Zhang
    • Lifeng LiuDong Zhang
    • H04L9/32H04L29/06
    • H04L63/126H04L9/3247H04L63/0869H04L63/1458H04L2209/20
    • A method, a system, and an apparatus for establishing communication are disclosed. The method is invented to establish communication between at least two communication parties including a first communication party and a second communication party. The method includes: sending a Cryptographically Generated Address (CGA) request to the first communication party; receiving CGA parameters and a CGA signature returned by the first communication party; and authenticating the CGA parameters and the CGA signature, and establishing communication with the first communication party if the authentication succeeds. By using the method disclosed herein, in the process of establishing communication, the communication party authenticates the CGA parameters and CGA signature carried in the CGA extension header to determine authenticity of the CGA, thus preventing the IP address spoofing and preventing or mitigating the network security problems caused by the IP address spoofing.
    • 公开了一种用于建立通信的方法,系统和装置。 该方法被发明以在包括第一通信方和第二通信方的至少两个通信方之间建立通信。 该方法包括:向第一通信方发送加密生成地址(CGA)请求; 接收第一通信方返回的CGA参数和CGA签名; 并认证CGA参数和CGA签名,并且如果认证成功,则建立与第一通信方的通信。 通过使用本文公开的方法,在建立通信的过程中,通信方认证CGA扩展报头中携带的CGA参数和CGA签名以确定CGA的真实性,从而防止IP地址欺骗并防止或减轻网络安全 IP地址欺骗引起的问题。
    • 4. 发明申请
    • METHOD AND APPARATUS FOR PROCESSING PACKETS
    • 处理包装的方法和装置
    • US20110119534A1
    • 2011-05-19
    • US13012223
    • 2011-01-24
    • Lifeng LIUDong Zhang
    • Lifeng LIUDong Zhang
    • H04L9/00G06F11/07
    • H04L63/126H04L29/12915H04L61/6059H04L63/164
    • A method and apparatus for processing packets are provided to extend the usage of a Cryptographically Generated Addresses (CGA) protocol. The method includes: receiving an Internet Protocol version 6 (IPv6) packet carrying CGA related information from a sender; obtaining the CGA related information from the IPv6 packet at the network layer, where the CGA related information includes the CGA parameters (CGA Params) and CGA signature (CGA Sig) of the sender; verifying the source address of the IPv6 packet according to the CGA Params and CGA Sig; transmitting the payload of the IPv6 packet after the verification succeeds. In the present invention, the packet is not limited to the IPv6 packet; the IP packet of a version later than IPv6 or the IP packet compatible with IPv6 may also be used.
    • 提供了一种用于处理数据包的方法和装置,以扩展密码生成地址(CGA)协议的使用。 该方法包括:从发送方接收携带CGA相关信息的因特网协议版本6(IPv6)分组; 从网络层的IPv6数据包获取CGA相关信息,其中CGA相关信息包括发送方的CGA参数(CGA参数)和CGA标志(CGA Sig); 根据CGA Params和CGA Sig验证IPv6数据包的源地址; 验证成功后,发送IPv6报文的有效载荷。 在本发明中,分组不限于IPv6分组; 也可以使用比IPv6更短的IP分组或与IPv6兼容的IP分组。
    • 5. 发明申请
    • METHOD, SYSTEM AND APPARATUS FOR ESTABLISHING COMMUNICATION
    • 用于建立通信的方法,系统和设备
    • US20110093716A1
    • 2011-04-21
    • US12976701
    • 2010-12-22
    • Lifeng LiuDong Zhang
    • Lifeng LiuDong Zhang
    • H04L9/32H04L29/06
    • H04L63/126H04L9/3247H04L63/0869H04L63/1458H04L2209/20
    • A method, a system, and an apparatus for establishing communication are disclosed. The method is invented to establish communication between at least two communication parties including a first communication party and a second communication party. The method includes: sending a Cryptographically Generated Address (CGA) request to the first communication party; receiving CGA parameters and a CGA signature returned by the first communication party; and authenticating the CGA parameters and the CGA signature, and establishing communication with the first communication party if the authentication succeeds. By using the method disclosed herein, in the process of establishing communication, the communication party authenticates the CGA parameters and CGA signature carried in the CGA extension header to determine authenticity of the CGA, thus preventing the IP address spoofing and preventing or mitigating the network security problems caused by the IP address spoofing.
    • 公开了一种用于建立通信的方法,系统和装置。 该方法被发明以在包括第一通信方和第二通信方的至少两个通信方之间建立通信。 该方法包括:向第一通信方发送加密生成地址(CGA)请求; 接收第一通信方返回的CGA参数和CGA签名; 并认证CGA参数和CGA签名,并且如果认证成功,则建立与第一通信方的通信。 通过使用本文公开的方法,在建立通信的过程中,通信方认证CGA扩展报头中携带的CGA参数和CGA签名以确定CGA的真实性,从而防止IP地址欺骗并防止或减轻网络安全 IP地址欺骗引起的问题。