Claims
- 1. A system for authentication and authorization, comprising:
(a) an authorizer configured to determine if a requestor is authorized to access a resource associated with a request; (b) a client that is an Internet Protocol version 6 (IPv6) host, wherein the client is configured to make the request; and (c) a local attendant that is accessible to the authorizer and the client and that provides a conduit through which messages between the client and the authorizer pass, wherein the authorizer, the client, and a peer on which the resource may be accessed are each in separate domains, wherein each domain is defined as a set of one or more entities such that if the set includes more than one entity, a connection between any two of the entities in the set can be secured by static credentials that are known by each of the two entities.
- 2. The system of claim 1, wherein the static credentials include a key.
- 3. The system of claim 1, wherein the static credentials include a mutually known algorithm.
- 4. The system of claim 1, wherein the static credentials include a key and a mutually known algorithm.
- 5. The system of claim 1, wherein the client employs a subscriber identity module (SIM) that includes credentials for use in authenticating the client to another device.
- 6. The system of claim 5, wherein if the requestor is authorized to access the resource associated with the request, the authorizer is further configured to provide to the peer a session key for accessing the resource, wherein the session key indicates that the requestor is authorized to access the resource.
- 7. The system of claim 6, wherein the SIM generates a copy of the session key for use by the client.
- 8. The system of claim 6, wherein the peer provides access to a network.
- 9. The system of claim 6, wherein the peer provides a service to the client.
- 10. The system of claim 6, wherein the peer is a home agent of the client.
- 11. The system of claim 1, wherein the client is a mobile node.
- 12. The method of claim 1, wherein the request and a reply are sent using an authentication, authorization, and accounting (AAA) version 6 or higher protocol.
- 13. The system of claim 1, wherein the local attendant is an access router.
- 14. The system of claim 1, wherein the local attendant is an Internet Protocol version 6 (IPv6) router.
- 15. The system of claim 1, wherein the local attendant communicates with at least one local AAA server.
- 16. A method for authentication and authorization, comprising:
(a) sending an identity associated with a client to an authorizer, wherein the identity is sent using Internet Protocol version 6 (IPv6); (b) generating, by the authorizer, a challenge that is calculated using the client identity; (c) sending the challenge to the client; (d) generating, by the client, a response employing the client identity and the challenge; (e) sending the response to the authorizer; (f) comparing, by the authorizer, the challenge to the client response; (g) transferring, by the authorizer, a key to a device providing a service to the client; and (h) automatically generating a copy of the key for use by the client by employing a subscriber identity module (SIM) associated with the client.
- 17. The method of claim 16, wherein each message between the authorizer and the client passes through a local attendant.
- 18. The method of claim 17, wherein the authorizer, the client, and a peer providing access to a resource requested by the client are each in separate domains, wherein each domain is defined as a set of one or more entities such that if the set includes more than one entity, a connection between any two of the entities in the set can be secured by static credentials that are known by each of the two entities.
- 19. The method of claim 16, wherein the client is a mobile node.
- 20. The method of claim 16, wherein the challenge and the response are sent using an authentication, authorization, and accounting (AAA) version 6 or higher protocol.
- 21. The method of claim 16, further comprising the step of acknowledging, by the authorizer, that the transfer step is complete.
- 22. A system for authenticating and authorization, comprising:
(a) means for determining if a requestor is authorized to access a resource associated with a request; (b) means for requesting access to the resource; (c) means for passing messages between the requestor and the determining means, wherein the determining means, the requesting means, and the message passing means are each in a separate domain, wherein each domain is defined as a set of one or more entities such that if the set includes more than one entity, a connection between any two of the entities in the set can be secured by static credentials that are known by each of the two entities.
RELATED APPLICATION
[0001] This application is a Utility Patent application based on a previously filed U.S. Provisional Patent application, U.S. Serial No. 60/305,123 filed on Jul. 12, 2001, the benefit of the filing date of which is hereby claimed under 35 U.S.C. §119(e).
Provisional Applications (1)
|
Number |
Date |
Country |
|
60305123 |
Jul 2001 |
US |