EP1515491B1

Architecture for virtual private networks

Abstract

This record has no abstract on file.

EP1515491B1, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Expired 11 June 2018, 8.3 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

19 claims: 3 independent, 16 dependent

  1. 1
    A method for sending a data packet from a source (500, 600) in a local area network (LAN) (205) to a destination (570, 670) outside the LAN (205) comprising the steps of:receiving (310, 520) a data packet enroute from the source (500, 600) in the LAN (205) to the destination (570, 670);determining (320) if the source (500, 600) in the LAN (205) and the destination (570, 670) are members of a virtual private network, and if so: determining (340) an encryption algorithm for messages sent between members of the virtual private network by accessing a portion of a memory that maintains information identifying various encryption algorithms to be utilized for data packets sent between members of various virtual private networks;determining (340) a compression algorithm for messages sent between members of the virtual private network by accessing a portion of the memory that maintains information identifying various compression algorithms to be utilized for data packets sent between members of the various virtual private networks;executing (340, 530) the determined encryption algorithm on at least a payload portion of the data packet;executing (340, 530) the determined compression algorithm on at least the payload portion of the data packet;and forwarding (350, 530) the encrypted and compressed data packet to the destination (570, 670) outside the LAN (205).
  2. 8
    The method according to any of claims 1 to 7, further comprising:determining an authentication algorithm for messages sent between members of the virtual private network by accessing a portion of a memory that maintains information identifying various authentication algorithms to be utilized for data packets sent between members of various virtual private networks;and executing the determined authentication algorithm on the data packet, wherein the forwarded data packet is authenticated, encrypted, and compressed prior to being sent to the destination (570, 670) outside the LAN (205).
  3. 11
    A virtual private network unit (252, 254) for sending a data packet from a source (211-213, 221-223) in a local area network (LAN) (205) to a destination (201-203) outside the LAN (205) comprising:an input (252, 254) for receiving a data packet enroute from the source (211-213, 221-223) in the LAN (205) to the destination (201-203);circuitry and software for determining if the source (211-213, 221-223) in the LAN (205) and the destination (201-203) are members of a virtual private network, and if so for: determining an encryption algorithm for messages sent between members of the virtual private network by accessing a portion of a memory that maintains information identifying various encryption algorithms to be utilized for data packets sent between members of various virtual private networks;determining a compression algorithm for messages sent between members of the virtual private network by accessing a portion of the memory that maintains information identifying various compression algorithms to be utilized for data packets sent between members of the various virtual private networks;executing the determined encryption algorithm on at least a payload portion of the data packet;executing the determined compression algorithm on at least the payload portion of the data packet;and an output for forwarding the encrypted and compressed data packet to the destination (201-203) outside the LAN (205).