发明名称 Method and system for distributed network address translation with network security features
摘要 A method and system for distributed network address translation with security features. The method and system allow Internet Protocol security protocol ("IPsec") to be used with distributed network address translation. The distributed network address translation is accomplished with IPsec by mapping a local Internet Protocol ("IP") address of a given local network device and a IPsec Security Parameter Index ("SPI") associated with an inbound IPsec Security Association ("SA") that terminates at the local network device. A router allocates locally unique security values that are used as the IPsec SPIs. A router used for distributed network address translation is used as a local certificate authority that may vouch for identities of local network devices, allowing local network devices to bind a public key to a security name space that combines a global IP address for the router with a set of locally unique port numbers used for distributed network address translation. The router issues security certificates and may itself be authenticated by a higher certificate authority. Using a security certificate, a local network device may initiate and be a termination point of an IPsec security association to virtually any other network device on an IP network like the Internet or an intranet. The method and system may also allow distributed network address translation with security features to be used with Mobile IP or other protocols in the Internet Protocol suite.
申请公布号 US7032242(B1) 申请公布日期 2006.04.18
申请号 US19990270967 申请日期 1999.03.17
申请人 3COM CORPORATION 发明人 GRABELSKY DAVID;BORELLA MICHAEL S.;SIDHU IKHLAQ;NESSETT DANNY M.
分类号 H04K1/00;G06F15/16;H04L9/00 主分类号 H04K1/00
代理机构 代理人
主权项
地址