Nova Patents
EP1284076A2

Ipsec processing

Abstract

A network device for implementing IPSec and comprising at least one IP forwarder (IPFW) arranged to receive IP packets each of which is associated with a Security Association (SA). The IP forwarder(s) determines the destinations of the packets, and forwards the packets to their destinations. A plurality of security procedure modules (SecProcs) are coupled to the IP forwarder(s) and are arranged to implement security procedures for received IP packets in parallel. A security controller (SC) is arranged to allocate negotiated SAs amongst the security procedure modules and to notify the security procedure modules and the IP forwarder(s) of the allocation, whereby the IP forwarder(s) can send IP packets to the security procedure module implementing the associated SA.

Term

Term ended

Projected expiry passed 3 May 2021, 5.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

7 claims: 4 independent, 3 dependent

  1. 1
    Claims of equivalent WO 0191413 A2 Claims 1. A network device for implementing IPSec and comprising:at least one IP forwarder arranged to receive IP packets each of which is associated with a Security Association (SA), to determine the destinations of the packets, and to forward the packets to their destinations;a plurality of security procedure modules coupled to the IP forwarder(s) and arranged to implement security procedures for received LP packets in parallel;and a security controller arranged to allocate negotiated SAs amongst the security procedure modules and to notify the security procedure modules and the IP forwarder(s) of the allocation, whereby the IP forwarder(s) can send IP packets to the security procedure module implementing the associated SA.
  2. 5
    A device according to any one of the preceding claims, wherein the security controller is coupled to an Internet Key Exchange (IKE) module which is responsible for negotiating SAs with peer IKE modules, and the security controller is arranged to receive from the IKE module details of negotiated SAs.
  3. 6
    A device according to any one of the preceding claims, wherein the IP forwarder(s), security procedure modules, and/or security controller are implemented in software or in hardware, or in a combination of hardware and software.
  4. 7
    A method of processing IP packets at a network networking device, the method comprising:allocating negotiated SAs amongst a plurality of security procedure modules arranged to implement security procedures for received IP packets;notifying the security procedure modules and at least one IP forwarder of said allocation;and receiving IP packets at the IP forwarder(s), identifying the SAs associated with the packets, and forwarding the packets to the security procedure modules implementing the associated SAs.