Proxy certificate management for nfv environment (pcs)
US-2024275775-A1 · Aug 15, 2024 · US
US9819688B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9819688-B2 |
| Application number | US-201414543381-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 17, 2014 |
| Priority date | Apr 14, 2009 |
| Publication date | Nov 14, 2017 |
| Grant date | Nov 14, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A peer enrollment method, a route updating method, a communication system, and relevant devices to improve security of a peer-to-peer (P2P) network. The peer enrollment method includes: receiving an enrollment request from a peer, where the enrollment request carries identity information of the peer; verifying the identity information of the peer, and if the verification succeeds, obtaining peer location information of the peer and generating a peer credential according to the peer location information; and sending the peer credential carrying the peer location information to the peer so that the peer joins the P2P network according to the peer credential. Embodiments of the present application further provide a route updating method, a communication system, and relevant devices. Embodiments of the present application may improve security of the P2P network effectively.
Opening claim text (preview).
What is claimed is: 1. A peer enrollment method comprising: receiving, by an enrollment server in a peer-to-peer network, an enrollment request of a peer device, wherein the enrollment request comprises identity information of the peer device; verifying, by the enrollment server, the identity information of the peer device, and when the verification succeeds, obtaining peer location information of the peer device, and generating a peer credential of the peer device according to the peer location information, wherein the peer credential includes anti-counterfeiting information which verifies the peer credential, wherein the anti-counterfeiting information comprises a character string for generating check information by applying an algorithm and the peer credential is verified by comparing the generated check information and preset check information; and sending, by the enrollment server, the peer credential comprising the peer location information to the peer device, wherein the peer credential is used by the peer device to join the peer-to-peer network, the peer-to-peer network configured to prevent malicious peers without peer credentials from joining, and wherein upon successfully joining the peer-to-peer network, a second peer device in the peer-to-peer network updates a routing table of the second peer device according to the peer credential of the peer device. 2. The method of claim 1 , wherein the obtaining the peer location information of the peer device comprises: sending a request for obtaining the peer location information to a topology information server, wherein the request carries the identity information of the peer device; and receiving the peer location information of the peer device returned by the topology information server, wherein the peer location information is one of the following: an autonomous system identification (ID) allocated by the topology information server for the peer device according to the identity information, an area ID allocated by the topology information server for the peer device according to the identity information, and peer coordinates allocated by the topology information server for the peer device according to the identity information. 3. The method of claim 1 , wherein the obtaining the peer location information of the peer device comprises: sending a request for obtaining the peer location information to a content delivery network (CDN) redirection server, wherein the request comprises the identity information of the peer device; receiving an address of an edge server which is closest to the peer device in a physical distance, returned by the CDN redirection server, wherein the address of the edge server is determined by the CDN redirection server for the peer device according to the identity information; and using the address of the edge server as the peer location information of the peer device. 4. The method of claim 1 , wherein the obtaining the peer location information of the peer device comprises: sending a request for obtaining the peer location information to a content delivery network (CDN) redirection server, wherein the request comprises the identity information of the peer device; receiving an address of an edge server which is the closest to the peer device in a physical distance, returned by the CDN redirection server, wherein the address of the edge server is determined by the CDN redirection server for the peer device according to the identity information; converting the address of the edge server into a corresponding location identification (ID) according to a preset algorithm; and using the corresponding location ID as the peer location information of the peer device. 5. The method of claim 1 , wherein the peer credential is a preset template structure. 6. A communication system comprising: an enrollment server in a peer-to-peer network, configured to receive an enrollment request of a peer device, wherein the enrollment request comprises identity information of the peer device; verify the identity information of the peer device; when the verification succeeds, obtain peer location information of the peer device, and send a peer credential comprising the peer location information to the peer device, wherein the peer credential carries anti-counterfeiting information which verifies the peer credential, wherein the anti-counterfeiting information comprises a character string for generating check information by applying an algorithm and the peer credential is verified by comparing the generated check information and preset check information; and the peer device, configured to send the enrollment request to the enrollment server, wherein the enrollment request comprises the identity information of the peer device; receive the peer credential that is sent by the enrollment server and comprises the peer location information; and join the peer-to-peer network according to the peer credential, wherein the peer-to-peer network is configured to prevent malicious peers without peer credentials from joining, and wherein upon successfully joining the peer-to-peer network, a second peer device in the peer-to-peer network updates a routing table of the second peer device according to the peer credential of the peer device. 7. The communication system of claim 6 , further comprising: an information providing server, configured to provide the peer location information of the peer device to the enrollment server. 8. The communication system of claim 7 , wherein: the information providing server is a topology information server; the enrollment server is further configured to send the identity information of the peer device to the topology information server, and receive the peer location information returned by the topology information server; and the topology information server is configured to allocate the peer location information for the peer device according to the identity information sent by the enrollment server, and return the peer location information to the enrollment server, wherein the peer location information is one of an autonomous system identification (ID), an area ID, and peer coordinates. 9. The communication system of claim 7 , wherein: the information providing server is a content delivery network (CDN) redirection server; the enrollment server is further configured to send the identity information of the peer device to the CDN redirection server, and receive the peer location information returned by the CDN redirection server; and the CDN redirection server is configured to determine an address of an edge server closest to the peer device in a physical distance, according to the identity information sent by the enrollment server, use the address of the edge server as the peer location information of the peer device, and send the peer location information to the enrollment server. 10. The communication system of claim 9 , wherein the enrollment server is further configured to convert the address of the edge server into a corresponding location identification (ID) according to a preset algorithm and use the location ID as the peer location information of the peer device. 11. The communication system of claim 6 , wherein the peer credential is a preset template structure. 12. A server in a peer-to-peer network, the server comprising: a hardware processor; and a non-transitory processor readable medium having processor-executed instructions stored thereon, the processor-executed instructions including a plurality of units, the units including: a receiving unit, configured to receive an enrollment request of a peer device, wherein the enrollment request carries identity information
Program or device authentication · CPC title
Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title
Peer-to-peer [P2P] networks · CPC title
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.