EP1515491A2

Architecture for virtual private networks

Abstract

Protocols and architecture for secure virtual private networks. Intraenterprise data communications are supported in a secure manner over the Internet or other public network space with the implementation of secure virtual private networks. Members of a virtual private network group exchange data that may be compressed, encrypted and authenticated, if the exchange is between members of the group.

EP1515491A2, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Projected expiry passed 11 June 2018, 8.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

11 claims: 3 independent, 8 dependent

  1. 1
    A method for sending a data packet from a first member of a virtual private network to a second member of said virtual private network comprising the steps of:receiving said data packet enroute to said second member;determining that said data packet is being sent between members of said virtual private network;determining the packet manipulation rules for packets sent between members of said virtual private network;forming a secure data packet by executing said packet manipulation rules on said data packet;and forwarding said secure data packet to said second member of said virtual private network,    wherein said data packet contains information of a source address and a destination address of said data packet,
  2. 6
    A method for recovering an original data packet from a secure data packet sent between members of a virtual private network comprising the steps of:receiving said secure data packet;determining the packet manipulation rules for packets sent between members of said virtual private network;recovering the original data packet by manipulating the secure data packet by reversing the identified packet manipulation rules;and forwarding the recovered data packet to its destination,    wherein said source data packet contains information of a source address and a destination address of said secure data packet.
  3. 9
    A system for securely exchanging data packets between members of a virtual private network group comprising;a first computer at a first site, said first computer having a first network address;a first router associated with said first site for routing data packets originating from said first computer over a public network;a first virtual private network unit disposed between said first router and said public network, said first virtual public network unit for identifying virtual private network group data traffic and for securing said data traffic by manipulating said data traffic according to packet manipulation rules maintained by said first virtual private network unit;a second router associated with a second site for coupling said second site to the public network;a second virtual private network unit disposed between said second router and the public network for intercepting network traffic destined for said second site, said second virtual public network unit for detecting virtual private network group traffic and for recovering original packet data;and a second computer at said second site, said second computer having a second network address for receiving said packet data,    wherein said data packet contains information of a source address and a destination address of said data packet.