发明申请
US20090249466A1 METHODS AND DEVICES FOR ENFORCING NETWORK ACCESS CONTROL UTILIZING SECURE PACKET TAGGING
有权
使用安全分组标签执行网络访问控制的方法和设备
- 专利标题: METHODS AND DEVICES FOR ENFORCING NETWORK ACCESS CONTROL UTILIZING SECURE PACKET TAGGING
- 专利标题(中): 使用安全分组标签执行网络访问控制的方法和设备
-
申请号: US12056462申请日: 2008-03-27
-
公开(公告)号: US20090249466A1公开(公告)日: 2009-10-01
- 发明人: Kirill MOTIL , Almog Cohen , Yaron Sheffer
- 申请人: Kirill MOTIL , Almog Cohen , Yaron Sheffer
- 申请人地址: IL Tel Aviv
- 专利权人: Check Point Software Technologies Ltd.
- 当前专利权人: Check Point Software Technologies Ltd.
- 当前专利权人地址: IL Tel Aviv
- 主分类号: G06F17/00
- IPC分类号: G06F17/00 ; G06F15/16 ; H04L9/32
摘要:
Disclosed are methods, devices, and media for enforcing network access control, the method including the steps of: extracting a packet signature from a packet (or packet fragment) received from a network; storing the packet signature and the packet in a buffer; computing a buffer signature using a per-endpoint secret key; determining whether the packet signature and the buffer signature are identical; and upon determining the packet signature and the buffer signature are identical, transmitting the packet to a protocol stack. Preferably, the step of extracting includes extracting the packet signature from a field (e.g. identification field) of a header of the packet. Preferably, the method further includes the step of: upon determining the packet signature and the buffer signature are not identical, discarding the packet. Methods for receiving a packet from a protocol stack, and transmitting the packet to a network are disclosed as well.
公开/授权文献
信息查询