EP1580958B1

Internet protocol tunnelling using templates

Abstract

A method and apparatus for processing IP packets is disclosed. The method comprises defining sets of packet fields referred to as templates (in method steps 1101-1102), storing the templates in a memory, determining (in a step 1104) if a current IP packet is intended to be processed, identifying (in the step 1104) the process to be applied to the current IP packet, selecting, depending on an attribute of the identified process, at least one of the stored templates, and operating (in a step 1107) upon the current IP packet, using the templates, to form a processed IP packet.

EP1580958B1, drawing sheet 1
Sheet 1 of 19

Term

Term ended

Expired 24 March 2025, 1.5 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

12 claims: 4 independent, 8 dependent

  1. 1
    A method of processing IP packets, the method comprising the steps of:creating a security association for the IP packets based upon a security policy;defining (1101, 1113) a plurality of sets of packet fields linked to the security association;storing (1102) the sets of defined packet fields in a memory;determining (1104) if a current one of the IP packets is intended to be processed;identifying (1104) the process to be applied to the current IP packet;selecting, depending on an attribute of the identified process, at least one of the stored sets of defined packet fields;and operating (1107) upon the current IP packet, using the at least one set of selected packet fields, to form a processed IP packet, characterized in that each said set of defined packet fields comprises an extension header and a predicted extension header, that is created when the security association is created, said predicted extension header being associated with the extension header, said predicted extension header being an IPv6 "Type 0" routing extension header as predicted to be seen at a destination for said packet, and said predicted extension header being invariant for the lifetime of the security association;and the method further comprises repeating said operating step (1107) using said extension header and said associated predicted extension header for a subsequent IP packet on which said security association is invoked.
  2. 6
    An apparatus for processing IP packets, the apparatus comprising:means for creating a security association for the IP packets based upon a security policy;means for defining a plurality of sets of packet fields linked to the security association;means for storing the sets of defined packet fields in a memory;means for determining if a current one of the IP packets is intended to be processed;means for identifying the process to be applied to the current IP packet;means for selecting, depending on an attribute of the identified process, at least one of the stored sets of defined packet fields;and means for operating upon the current IP packet, using the at least one set of selected packet fields, to form a processed IP packet, characterized in that each said set of defined packet fields comprises an extension header and a predicted extension header, that is created when the security association is created, said predicted extension header being associated with the extension header, said predicted extension header being an IPv6 "Type 0" routing extension header as predicted to be seen at a destination for said packet, and said predicted extension header being invariant for the lifetime of the security association;and the apparatus further comprises means for repeating said operating step (1107) using said extension header and said associated predicted extension header for a subsequent IP packet on which said security association is invoked.
  3. 9
    A computer program product having a computer readable medium having a computer program recorded therein for directing a processor to process IP packets, said computer program comprising:code for creating a security association for the IP packets based upon a security policy;code for defining a plurality of sets of packet fields linked to the security association;code for storing the sets of defined packet fields in a memory;code for determining if a current one of the IP packets is intended to be processed;code for identifying the process to be applied to the current IP packet;code for selecting, depending on an attribute of the identified process, at least one of the stored sets of defined packet fields;and code for operating upon the current IP packet, using the at least one set of selected packet fields, to form a processed IP packet, characterized in that each said set of defined packet fields comprises an extension header and a predicted extension header, that is created when the security association is created, said predicted extension header being associated with the extension header, said predicted extension header being an IPv6 "Type 0" routing extension header as predicted to be seen at a destination for said packet, and said predicted extension header being invariant for the lifetime of the security association;and the computer program further comprises code for repeating said operating step (1107) using said extension header and said ne associated predicted extension header for a subsequent IP packet on which said security association is invoked.
  4. 12
    A computer program for directing a processor to process IP packets, said computer program comprising:code for creating a security association for the IP packets based upon a security policy;code for defining a plurality of sets of packet fields linked to the security association;code for storing the sets of defined packet fields in a memory;code for determining if a current one of the IP packets is intended to be processed;code for identifying the process to be applied to the current IP packet;code for selecting, depending on an attribute of the identified process, at least one of the stored sets of defined packet fields;and code for operating upon the current IP packet , using the at least one set of selected packet fields, to form a processed IP packet, characterized in that each said set of defined packet fields comprises an extension header and a predicted extension header, that is created when the security association is created, said predicted extension header being associated with the extension header said predicted extension header being an IPv6 "Type 0" routing extension header as predicted to be seen at a destination for said packet, and said predicted extension header being invariant for the lifetime of the security association;and the computer program further comprises code for repeating said operating step (1107) using said extension header and said associated predicted extension header for a subsequent IP packet on which said security association is invoked.