WO9967930A2

Method and arrangement for implementing ipsec policy management using filter code

Abstract

A data processing system implements a security protocol based on processing data in packets. The data processing system comprises packet processing means (301) for storing filter code (304) and processing data packets according to stored filter code, and policy managing means (305) for generating filter code and communicating generated filter code to the packet processing means (301). The packet processing means (301) is arranged to examine, whether the stored filter code is applicable for processing a certain packet. If the stored filter code is not applicable for the processing of a packet, the packet is communicated to the policy managing means (305), which generates filter code applicable for the processing of the packet and communicates the generated filter code to the packet processing means (301).

WO9967930A2, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

20 claims: 2 independent, 18 dependent

  1. 1
    CLAIMS 1. A data processing system for implementing a security protocol based on processing data in packets, characterized in that said data processing system comprises:- packet processing means (308) for storing filter code (304) and processing data packets (301) according to stored filter code, and - policy managing means (305) for generating filter code and communicating generated filter code to said packet processing means, wherein said packet processing means is arranged to examine (503, 504, 505), whether the stored filter code is applicable for processing a certain packet, and to communicate (507) such packets for the processing of which the stored filter code is not applicable to said policy managing means, and said policy managing means is arranged to, as a response to receiving a packet from said packet processing means, either (508, 509) - generate filter code applicable for the processing of the packet and communicate the generated filter code to said packet processing means, or - process the packet by said policy managing means, or - process the packet by said policy managing means and generate filter code applicable for the processing of the packet and communicate the generated filter code to said packet processing means.
  2. 20
    A method for implementing a security protocol based on processing data in packets, characterized in that it comprises the steps of:a) examining (502, 504, 505), whether a piece of stored filter code is applicable for processing a certain packet in a packet processing means, whereby a positive result means that a a piece of stored filter code is applicable for processing a certain packet and a negative result means that a piece of stored filter code is not applicable for processing a certain packet, b) following a positive result in step a), processing (503, 506) the packet in said packet processing means according to the stored filter code, c) following a negative result in step a), communicating (507) the packet into a policy managing means and examining (508), whether filter code should be generated and communicated to said packet processing means for the processing of the packet in said packet processing means, whereby a positive result means that filter code should be generated and communicated to said packet processing means and a negative result means that filter code should not be generated and communicated to said packet processing means, d) following a positive result in step c), generating (509) filter code applicable for the processing of the packet and communicating the generated filter code to said packet processing means, e) following a negative result in step c), examining, whether filter code should be generated and communicated to said packet processing means for the processing of further similar packets in said packet processing means, whereby a positive result means that filter code should be generated and communicated to said packet processing means and a negative result means that filter code should not be generated and commumcated to said packet processing means, f) following a positive result in step e), processing the packet in the policy managing means and generating filter code applicable for the processing of further similar packet and communicating the generated filter code to said packet processing means, and g) following a negative result in step e), processing the packet in the policy managing means.