发明名称 ENFORCING THE PRINCIPLE OF LEAST PRIVILEGE FOR LARGE TUNNEL-LESS VPNs
摘要 Techniques for secure communication in a tunnel-less VPN are provided. A key server generates and provides, to each VPN gateway, different, yet mathematically-related keying material. A VPN gateway receives distinct keying material for each designated address block (e.g., subnet) behind the VPN gateway. In response to receiving a packet from one a source host whose address falls within one of the designated address blocks, the VPN gateway identifies the appropriate keying material. The VPN gateway determines an identifier for the address block that includes the destination address. The identifier and the identified keying material are used to generate a key. The VPN gateway encrypts the packet with the key and forwards the encrypted packet to the destination host.
申请公布号 US2010034207(A1) 申请公布日期 2010.02.11
申请号 US20080186044 申请日期 2008.08.05
申请人 MCGREW DAVID;WEIS BRIAN;WAINNER W SCOTT 发明人 MCGREW DAVID;WEIS BRIAN;WAINNER W. SCOTT
分类号 H04L12/56 主分类号 H04L12/56
代理机构 代理人
主权项
地址