发明名称 System and method for dynamic macro placement of IP connection filters
摘要 Virtual Private Networking (VPN) is an emerging technology area enabling e-business on the Internet. A key underlying VPN technology is IP Security (IPsec), a means of providing private (encrypted and authenticated) secure data transmission over public (Internet) networks. The definition of what data to protect ultimately results in IP filter rules, loaded to the operating system kernel. These are used to select the correct IP datagrams and cause each to be processed by the correct IPsec Security Associations. Along with other attributes, a VPN connection can be started, stopped, and monitored. Connection filters which are used to implement VPN connections are dynamic, and must be inserted and deleted within the currently installed set of IP filters (non-VPN related). Since IP filter order is crucial to proper functioning, the basic problem is, where to place these dynamic filters. This filter placement problem has a macro and a micro part. The macro filter placement problem is solved, and a customer policy to protect data is enforced, even if no VPN connection is active.
申请公布号 US6643776(B1) 申请公布日期 2003.11.04
申请号 US19990240718 申请日期 1999.01.29
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BODEN EDWARD B.;MELVILLE MARK J.
分类号 G09C1/00;H04L12/56;H04L29/06;(IPC1-7):G06F11/30;G06F15/173;G06F15/16;G06F17/30 主分类号 G09C1/00
代理机构 代理人
主权项
地址