发明名称 CLOCK-BASED REPLAY PROTECTION
摘要 Nodes (102, 104) in a network include a pseudo-timestamp (206) in messages or packets, derived from local pseudo-time clocks (108) . When a packet is received, a first time is determined representing when the packet was sent and a second time is determined representing when the packet was received. If the difference between the second time and the first time is greater than a predetermined amount, the packet is considered to be stale and is rejected (410), thereby deterring replay. Because each node maintains its own clock and time, to keep the clocks relatively synchronized, if a time associated with a timestamp of a received packet is later than a certain amount with respect to the time at the receiver, the receiver's clock is set ahead (606) by an amount that expected to synchronize the receiver's and the sender's clocks. However, a receiver never sets its clock back, to deter attacks.
申请公布号 WO2006088695(A3) 申请公布日期 2006.10.05
申请号 WO2006US04262 申请日期 2006.02.06
申请人 CISCO TECHNOLOGY, INC.;WEIS, BRIAN E.;MCGREW, DAVID A. 发明人 WEIS, BRIAN E.;MCGREW, DAVID A.
分类号 H04H20/00;H04J3/06;H04L12/56 主分类号 H04H20/00
代理机构 代理人
主权项
地址