Claims
- 1. A method of preventing spoofing in a telecommunications system which comprises a terminal capable of transmitting data packets and at least one node for receiving and forwarding data packets in a first subsystem, the method comprising:
activating in the first subsystem a packet data address for the terminal for transmitting data packets between the terminal and a second subsystem; storing the packet data address in at least one node of the first subsystem via which the data packets of the packet data address are routed; receiving in said node the packet sent from the terminal, the packet comprising a destination address and a source address; checking in said node whether the source address of the packet is the same as the packet data address; and transmitting the packet from the node towards the destination address only if the addresses are identical.
- 2. The method of claim 1, further comprising:
maintaining information on first packet data address types in said node, the information including at least one packet data address type on which said check is performed; and performing said check only if the packet data address is of the first packet data address type.
- 3. The method of claim 2, wherein the first packet data address type includes at least an IP address according to the Internet protocol.
- 4. The method of claim 1 wherein said node is the gateway support node of the first subsystem which routes the data packet from the terminal to the second subsystem.
- 5. The method of claim 1 wherein said node is a support node which serves the mobile station and routes the packet received from the terminal forward in the first subsystem.
- 6. The method of claim 1 wherein the first subsystem is a packet radio network which uses a GTP protocol and in which the packet data address is activated by activating the corresponding PDP context.
- 7. A method of preventing spoofing in a telecommunications system which comprises a terminal capable of transmitting data packets and at least one node for receiving and forwarding data packets in a first subsystem, the method comprising:
activating in the first subsystem a packet data address for the terminal for transmitting data packets between the terminal and a second subsystem; storing the packet data address in at least one node of the first subsystem via which the data packets of the packet data address are routed; receiving in said node the packet sent from the terminal, the packet comprising a destination address and a source address; defining the packet data address as a set of allowed packet data addresses; checking in said node whether the source address of the packet belongs to the set of allowed packet data addresses; and transmitting the packet from the node towards the destination address only if the source address of the packet belongs to the set of allowed packet data addresses.
- 8. The method of claim 1, further comprising:
maintaining information on first packet data address types in said node, the information including at least one packet data address type on which said check is performed; and performing said check only if the packet data address is of the first packet data address type.
- 9. The method of claim 8, wherein the first packet data address type includes at least an IP address according to the Internet protocol.
- 10. The method of claim 2, wherein said node is the gateway support node of the first subsystem which routes the data packet from the terminal to the second subsystem.
- 11. The method of claim 2, wherein said node is a support node which serves the mobile station and routes the packet received from the terminal forward in the first subsystem.
- 12. The method of claim 2, wherein the first subsystem is a packet radio network which uses a GTP protocol and in which the packet data address is activated by activating the corresponding PDP context.
- 13. A network node of a packet network for transmitting data packets from a terminal of the packet network to a receiver, the network node being arranged to activate at least one packet data address for the terminal which the terminal can use when transmitting data packets, to attach a packet received from the terminal to the packet data address used by the terminal, and, in response to receiving a packet, to compare the source address of the packet with the packet data address used by the terminal and to send the packet from the network node towards the destination address of the packet only if the addresses are identical.
- 14. The network node of claim 13, the network node being further arranged to maintain information on first packet data address types on which said comparison is performed and to perform the comparison only if the packet data address used by the terminal is of the first packet data address type.
- 15. The network node of claim 13, wherein the network node is a gateway support node of a packet radio network using a GTP protocol.
- 16. The network node of claim 13, wherein the network node is a support node serving the terminal in a packet radio network using a GTP protocol.
- 17. A network node of a packet network for transmitting data packets from a terminal of the packet network to a receiver, the network node being arranged to activate at least one packet data address for the terminal which the terminal can use when transmitting data packets, the packet data address being defined as a set of allowed packet data addresses, to attach a packet received from the terminal to the packet data address used by the terminal; and
in response to receiving a packet, to check whether the source address of the packet belongs to the set of allowed packet data addresses of the packet data address used by the terminal and to send the packet from the network node towards the destination address of the packet only if the source address belongs to the set of allowed packet data addresses.
- 18. The network node of claim 17, the network nodebeing further arranged to maintain information on first packet data address types on which said comparison is performed and to perform the comparison only if the packet data address used by the terminal is of the first packet data address type.
- 19. The network node of claim 17, wherein the network node is a gateway support node of a packet radio network using a GTP protocol.
- 20. The network node of claim 17, wherein the network node is a support node serving the terminal in a packet radio network using a GTP protocol.
Priority Claims (1)
Number |
Date |
Country |
Kind |
19992767 |
Dec 1999 |
FI |
|
Parent Case Info
[0001] This application is a Continuation of International Application PCT/FI00/1114 filed Dec. 19, 2000 which designated the U.S. and was published under PCT Article 21(2) in English.
Continuations (1)
|
Number |
Date |
Country |
Parent |
PCT/FI00/01114 |
Dec 2000 |
US |
Child |
10175517 |
Jun 2002 |
US |