发明名称 METHODS AND DEVICES FOR ENFORCING NETWORK ACCESS CONTROL UTILIZING SECURE PACKET TAGGING
摘要 Disclosed are methods, devices, and media for enforcing network access control, the method including the steps of: extracting a packet signature from a packet (or packet fragment) received from a network; storing the packet signature and the packet in a buffer; computing a buffer signature using a per-endpoint secret key; determining whether the packet signature and the buffer signature are identical; and upon determining the packet signature and the buffer signature are identical, transmitting the packet to a protocol stack. Preferably, the step of extracting includes extracting the packet signature from a field (e.g. identification field) of a header of the packet. Preferably, the method further includes the step of: upon determining the packet signature and the buffer signature are not identical, discarding the packet. Methods for receiving a packet from a protocol stack, and transmitting the packet to a network are disclosed as well.
申请公布号 US2009249466(A1) 申请公布日期 2009.10.01
申请号 US20080056462 申请日期 2008.03.27
申请人 CHECK POINT SOFTWARE TECHNOLOGIES LTD. 发明人 MOTIL KIRILL;COHEN ALMOG;SHEFFER YARON
分类号 G06F17/00;G06F15/16;H04L9/32 主分类号 G06F17/00
代理机构 代理人
主权项
地址