Method and apparatus for providing an adaptable security level in an electronic communication
First Claim
Patent Images
1. A method performed by a communication device, the method comprising:
- said communication device receiving a plurality of frames, wherein each individual frame having a header and associated data, the header of each individual frame including security control bits that indicate for that individual frame whether encryption has been provided for the individual frame and whether integrity has been provided for the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, wherein the one or more security mode bits are used to indicate whether encryption is on or off, and wherein the integrity level bits indicate which of at least four integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength;
on a frame-by-frame basis, for each individual frame, said communication device;
identifying a security level for the individual frame based on the security control bits in the header of the frame;
checking said security level against predetermined minimum security requirements for said communication device; and
rejecting the individual frame in response to said security level not meeting said predetermined minimum security requirements.
2 Assignments
0 Petitions
Accused Products
Abstract
A method of communicating in a secure communication system, comprises the steps of assembling a message at a sender, then determining a security level, and including an indication of the security level in a header of the message. The message is then sent to a recipient.
-
Citations
21 Claims
-
1. A method performed by a communication device, the method comprising:
-
said communication device receiving a plurality of frames, wherein each individual frame having a header and associated data, the header of each individual frame including security control bits that indicate for that individual frame whether encryption has been provided for the individual frame and whether integrity has been provided for the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, wherein the one or more security mode bits are used to indicate whether encryption is on or off, and wherein the integrity level bits indicate which of at least four integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; on a frame-by-frame basis, for each individual frame, said communication device; identifying a security level for the individual frame based on the security control bits in the header of the frame; checking said security level against predetermined minimum security requirements for said communication device; and rejecting the individual frame in response to said security level not meeting said predetermined minimum security requirements. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A non-transitory computer-readable storage medium comprising computer-executable instructions that are configured when executed, by data processing apparatus of a communication device, to perform operations comprising:
-
receiving a plurality of frames, wherein each individual frame having a header and associated data, the header of each individual frame including security control bits that indicate for that individual frame whether encryption has been provided for the individual frame and whether integrity has been provided for the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, wherein the one or more security mode bits are used to indicate whether encryption is on or off, and wherein the integrity level bits indicate which of at least four integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; on a frame-by-frame basis, for each individual frame; identifying a security level for the individual frame based on the security control bits in the header of the frame; checking said security level against predetermined minimum security requirements for said communication device; and rejecting the individual frame in response to said security level not meeting said predetermined minimum security requirements. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
-
21. A device, comprising:
-
a memory; and one or more processors communicatively coupled with the memory and configured to; receive a plurality of frames, wherein each individual frame having a header and associated data, the header of each individual frame including security control bits that indicate for that individual frame whether encryption has been provided for the individual frame and whether integrity has been provided for the individual frame, wherein the security control bits include one or more security mode bits and integrity level bits, wherein the one or more security mode bits are used to indicate whether encryption is on or off, and wherein the integrity level bits indicate which of at least four integrity levels is utilized, the integrity levels corresponding to signing operations of a sender of increasing strength; and on a frame-by-frame basis, for each individual frame; identify a security level for the individual frame based on the security control bits in the header of the frame; check said security level against predetermined minimum security requirements for said communication device; and reject the individual frame in response to said security level not meeting said predetermined minimum security requirements.
-
Specification