IL140263A

Method and arrangement for implementing ipsec policy management using filter code

Abstract

A data processing system implements a security protocol based on processing data in packets. The data processing system comprises processing packets for storing filter code and processing data packets according to stored filter code, and a policy managing function for generating filter code and communicating generated filter code for packet processing. The packet processing function is arranged to examine, whether the stored filter code is applicable for processing a certain packet. If the stored filter code is not applicable for the processing of a packet, the packet is communicated to the policy managing function, which generates filter code applicable for the processing of the packet and communicates the generated filter code for packet processing.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 2 independent, 18 dependent

  1. 1
    WO 99/67930 PCT/FI99/00536 13 CLAIMS 1. A data processing system for implementing a security protocol based on processing data in packets, characterized in that said data processing system comprises:- packet processing means (308) for storing filter code (304) and processing data packets (301) according to stored filter code, and - policy managing means (305) for generating filter code and communicating generated filter code to said packet processing means, wherein said packet processing means is arranged to examine (503, 504, 505), whether the stored filter code is applicable for processing a certain packet, and to communicate (507) such packets for the processing of which the stored filter code is not applicable to said policy managing means, and said policy managing means is arranged to, as a response to receiving a packet from said packet processing means, either (508, 509) - generate filter code applicable for the processing of the packet and communicate the generated filter code to said packet processing means, or - process the packet by said policy managing means, or - process the packet by said policy managing means and generate filter code applicable for the processing of the packet and communicate the generated filter code to said packet processing means.
  2. 20
    A method for implementing a security protocol based on processing data in packets, characterized in that it comprises the steps of:a) examining (502, 504, 505), whether a piece of stored filter code is applicable for processing a certain packet in a packet processing means, whereby a positive result means that a a piece of stored filter code is applicable for processing a certain packet and a negative result means that a piece of stored filter code is not applicable for processing a certain packet, b) following a positive result in step a), processing (503, 506) the packet in said packet processing means according to the stored filter code, WO 99/67930 PCT/FI99/00536 16 c) following a negative result in step a), communicating (507) the packet into a policy managing means and examining (508), whether filter code should be generated and communicated to said packet processing means for the processing of the packet in said packet processing means, whereby a positive result means that 5 filter code should be generated and communicated to said packet processing means and a negative result means that filter code should not be generated and communicated to said packet processing means, d) following a positive result in step c), generating (509) filter code applicable for the processing of the packet and communicating the generated filter code to said 10 packet processing means, e) following a negative result in step c), examining, whether filter code should be generated and communicated to said packet processing means for the processing of further similar packets in said packet processing means, whereby a positive result means that filter code should be generated and communicated to said packet 15 processing means and a negative result means that filter code should not be generated and communicated to said packet processing means, f) following a positive result in step e), processing the packet in the policy managing means and generating filter code applicable for the processing of further similar packet and communicating the generated filter code to said packet processing 20 means, and g) following a negative result in step e), processing the packet in the policy managing means. For the Applicant©