发明名称 Technique for processing data packets in a communication network
摘要 A technique for processing secure data packets that are directly and not directly addressed to a policy enforcement point (PEP). The present invention incorporates a dual internal path for the fast path processing of secure data packets at a PEP. A first path is used to process secure data packets addressed to the PEP. A second path is used to process secure data packets not addressed to the PEP. On the first path, secure data packets addressed to the PEP are transferred to the PEP for immediate processing. On the second path, a series of checks are performed to maximize the speed of processing the secure data packets. In addition, policies associated with the secure data packets are retrieved and destination address/mask combinations are used along with destination addresses in the secure data packets to determine if the packets are to be further processed or dropped.
申请公布号 US2007214502(A1) 申请公布日期 2007.09.13
申请号 US20070699765 申请日期 2007.01.30
申请人 MCALISTER DONALD K 发明人 MCALISTER DONALD K.
分类号 G06F15/16 主分类号 G06F15/16
代理机构 代理人
主权项
地址