发明名称 System and method for internet protocol security processing
摘要 A decentralized method for IPSec processing in virtual environments includes assigning a unique identifier to each of a set of compute nodes. Each compute node can emulate one or more virtual machines that generate IP packets for forwarding over a network (e.g., the Internet). An IP packet, received from a trusted source at a compute node, is encrypted and a trailer is appended to the encrypted packet. The trailer includes the unique identifier of the compute node. The encrypted packet with appended trailer is forwarded to a secure gateway that can perform an anti-replay check using stored parameters corresponding to the unique identifier in the trailer. In inbound processing, the unique identifier is inserted into a trailer appended to an encrypted packet by the security gateway and a VPN server directs the incoming encrypted packet to the appropriate compute node for forwarding to the virtual machine.
申请公布号 US9473466(B2) 申请公布日期 2016.10.18
申请号 US201414511188 申请日期 2014.10.10
申请人 FREESCALE SEMICONDUCTOR, INC. 发明人 Vemulapalli Jyothi;Addepalli Srinivasa Rao
分类号 H04L29/06;H04L29/12 主分类号 H04L29/06
代理机构 代理人 Bergere Charles E.
主权项 1. A method of processing IP packets, the method comprising: assigning a unique identifier to a first network device; and at the first network device: receiving an IP packet;encrypting the IP packet;appending a first trailer to the encrypted IP packet, wherein the first trailer includes the unique identifier; andforwarding the encrypted IP packet with the first trailer to a remote network device; at the remote network device: receiving a second IP packet from an untrusted source;identifying a destination address included in the second IP packet;encrypting the second IP packet;appending a second trailer to the encrypted second IP packet, wherein the second trailer includes the unique identifier of the first network device that emulates a virtual machine having the identified destination address; andforwarding the encrypted second IP packet with the second trailer to a second network device; and at the second network device: receiving the encrypted second IP packet with the second trailer from the remote network device; andforwarding the encrypted second IP packet to the first network device that emulates the virtual machine having the identified destination address.
地址 Austin TX US