ATE311060T1 - Verfahren und system zur netzwerkadressübersetzung mit sicherheitseigenschaften - Google Patents

Verfahren und system zur netzwerkadressübersetzung mit sicherheitseigenschaften

Info

Publication number
ATE311060T1
ATE311060T1 AT00914989T AT00914989T ATE311060T1 AT E311060 T1 ATE311060 T1 AT E311060T1 AT 00914989 T AT00914989 T AT 00914989T AT 00914989 T AT00914989 T AT 00914989T AT E311060 T1 ATE311060 T1 AT E311060T1
Authority
AT
Austria
Prior art keywords
security
address translation
ipsec
network address
local
Prior art date
Application number
AT00914989T
Other languages
English (en)
Inventor
David A Grabelsky
Michael S Borella
Ikhlaq S Sidhu
Danny M Nessett
Original Assignee
3Com Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from US09/270,967 external-priority patent/US7032242B1/en
Application filed by 3Com Corp filed Critical 3Com Corp
Application granted granted Critical
Publication of ATE311060T1 publication Critical patent/ATE311060T1/de

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/09Mapping addresses
    • H04L61/25Mapping addresses of the same type
    • H04L61/2503Translation of Internet protocol [IP] addresses
    • H04L61/2514Translation of Internet protocol [IP] addresses between local and global IP addresses
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/09Mapping addresses
    • H04L61/25Mapping addresses of the same type
    • H04L61/2503Translation of Internet protocol [IP] addresses
    • H04L61/256NAT traversal
    • H04L61/2564NAT traversal for a higher-layer protocol, e.g. for session initiation protocol [SIP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/062Network architectures or network communication protocols for network security for supporting key management in a packet data network for key distribution, e.g. centrally by trusted party
    • H04L63/064Hierarchical key distribution, e.g. by multi-tier trusted parties
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/164Implementing security features at a particular protocol layer at the network layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2101/00Indexing scheme associated with group H04L61/00
    • H04L2101/60Types of network addresses
    • H04L2101/618Details of network addresses
    • H04L2101/663Transport layer addresses, e.g. aspects of transmission control protocol [TCP] or user datagram protocol [UDP] ports

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Small-Scale Networks (AREA)
AT00914989T 1999-03-17 2000-03-15 Verfahren und system zur netzwerkadressübersetzung mit sicherheitseigenschaften ATE311060T1 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US09/270,967 US7032242B1 (en) 1998-03-05 1999-03-17 Method and system for distributed network address translation with network security features
PCT/US2000/007057 WO2000056034A1 (en) 1999-03-17 2000-03-15 Method and system for distributed network address translation with network security features

Publications (1)

Publication Number Publication Date
ATE311060T1 true ATE311060T1 (de) 2005-12-15

Family

ID=23033611

Family Applications (1)

Application Number Title Priority Date Filing Date
AT00914989T ATE311060T1 (de) 1999-03-17 2000-03-15 Verfahren und system zur netzwerkadressübersetzung mit sicherheitseigenschaften

Country Status (4)

Country Link
EP (1) EP1159815B1 (de)
AT (1) ATE311060T1 (de)
DE (1) DE60024237T2 (de)
WO (1) WO2000056034A1 (de)

Families Citing this family (22)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7107614B1 (en) 1999-01-29 2006-09-12 International Business Machines Corporation System and method for network address translation integration with IP security
US6636596B1 (en) 1999-09-24 2003-10-21 Worldcom, Inc. Method of and system for providing intelligent network control services in IP telephony
US7388953B2 (en) * 1999-09-24 2008-06-17 Verizon Business Global Llc Method and system for providing intelligent network control services in IP telephony
JP3636095B2 (ja) * 2000-05-23 2005-04-06 インターナショナル・ビジネス・マシーンズ・コーポレーション Vpn接続のセキュリティ
US20020188871A1 (en) * 2001-06-12 2002-12-12 Corrent Corporation System and method for managing security packet processing
FI116027B (fi) * 2001-09-28 2005-08-31 Netseal Mobility Technologies Menetelmä ja järjestelmä viestien turvallisen lähettämisen varmistamiseksi
GB2381423B (en) * 2001-10-26 2004-09-15 Ericsson Telefon Ab L M Addressing mechanisms in mobile IP
FI116017B (fi) * 2002-01-22 2005-08-31 Netseal Mobility Technologies Menetelmä viestien lähettämiseksi turvallisten mobiiliviestintäyhteyksien läpi
US7558873B1 (en) 2002-05-08 2009-07-07 Nvidia Corporation Method for compressed large send
US7191331B2 (en) 2002-06-13 2007-03-13 Nvidia Corporation Detection of support for security protocol and address translation integration
US7120930B2 (en) 2002-06-13 2006-10-10 Nvidia Corporation Method and apparatus for control of security protocol negotiation
AU2003240506A1 (en) * 2002-06-13 2003-12-31 Nvidia Corporation Method and apparatus for enhanced security for communication over a network
GB2418821B (en) * 2002-06-13 2006-08-09 Nvidia Corp Method and apparatus for enhanced security for communication over a network
US7143137B2 (en) * 2002-06-13 2006-11-28 Nvidia Corporation Method and apparatus for security protocol and address translation integration
US7143188B2 (en) 2002-06-13 2006-11-28 Nvidia Corporation Method and apparatus for network address translation integration with internet protocol security
US7437548B1 (en) 2002-07-11 2008-10-14 Nvidia Corporation Network level protocol negotiation and operation
US7620070B1 (en) 2003-06-24 2009-11-17 Nvidia Corporation Packet processing with re-insertion into network interface circuitry
JP2005236728A (ja) * 2004-02-20 2005-09-02 Matsushita Electric Ind Co Ltd サーバ装置、要求発行機器、要求受諾機器、通信システム及び通信方法
US8117340B2 (en) * 2005-04-25 2012-02-14 Microsoft Corporation Trans-network roaming and resolution with web services for devices
US7765591B2 (en) 2005-05-05 2010-07-27 Cisco Technology, Inc. Method and system for prioritizing security operations in a communication network
DE102014207800B4 (de) 2014-04-25 2023-06-01 Bayerische Motoren Werke Aktiengesellschaft Verfahren und Vorrichtung zum Reduzieren einer Netzwerklast bei Multicast- und Broadcast-Kommunikation
US9413659B2 (en) 2014-06-11 2016-08-09 Cisco Technology, Inc. Distributed network address and port translation for migrating flows between service chains in a network environment

Also Published As

Publication number Publication date
EP1159815B1 (de) 2005-11-23
WO2000056034A1 (en) 2000-09-21
DE60024237D1 (de) 2005-12-29
DE60024237T2 (de) 2006-06-29
EP1159815A1 (de) 2001-12-05

Similar Documents

Publication Publication Date Title
ATE311060T1 (de) Verfahren und system zur netzwerkadressübersetzung mit sicherheitseigenschaften
DE602004012870D1 (de) Verfahren und system zur benutzerauthentifizierung in einer benutzer-anbieterumgebung
DE602004010519T2 (de) Fernzugriffs-vpn-aushandlungsverfahren und aushandlungseinrichtung
WO2004017552A3 (en) Establishing authenticated network connections
FI20001837A7 (fi) Autentikointi
CA2241052A1 (en) Application level security system and method
WO2004023263A3 (en) System for allowing network traffic through firewalls
US20060271707A1 (en) Domain name system resolution
EP1494429A3 (de) Verfahren zur Durchführung sicherer Betriebskommunikation
US20030055990A1 (en) Single-modem multi-user virtual private network
ATE513403T1 (de) System und verfahren zur provisionierung und authentifizierung über ein netzwerk
US20030041136A1 (en) Automated configuration of a virtual private network
ATE536020T1 (de) Vpn-zertifizierung dritter
WO2003073216A3 (en) Secure traversal of network components
ATE352163T1 (de) Verfahren und vorrichtung zur bereitstellung eines sicheren vpn-zugriffs mittels veränderter zertifikat-zeichenketten
CZ138799A3 (cs) Vnější přístup k prostředkům počítače firewallem
ATE307449T1 (de) Verfahren zur paketauthentifizierung in gegenwart von netzwerkadressübersetzungen und protokollumwandlungen
GB0108267D0 (en) Facilitating legal intercveption of IP connections
WO2004079497A3 (en) Using tcp to authenticate ip source addresses
NO20080870L (no) Autentisering og autorisering av en ekstern klient
EP1162807A3 (de) Vefahren und System zur gesicherte legale Raüme in einem Infrastruktur mit öffentlichem Schlüssel
EP0807911A3 (de) Kunden/Server-Protokoll zum Überprüfen der Echtheit
WO2001047232A3 (en) Secure enrollment of a device with a clearinghouse server for internet telephony system
DE60043053D1 (de) Selbstgenerierung von zertifikaten unter verwendung eines sicheren mikroprozessors in einer vorrichtung zur digitalen datenübertragung
WO2001031843A3 (en) Systems and methods for providing dynamic network authorization, authentication and accounting

Legal Events

Date Code Title Description
RER Ceased as to paragraph 5 lit. 3 law introducing patent treaties