发明授权
US07032242B1 Method and system for distributed network address translation with network security features
有权
具有网络安全特性的分布式网络地址转换方法和系统
- 专利标题: Method and system for distributed network address translation with network security features
- 专利标题(中): 具有网络安全特性的分布式网络地址转换方法和系统
-
申请号: US09270967申请日: 1999-03-17
-
公开(公告)号: US07032242B1公开(公告)日: 2006-04-18
- 发明人: David Grabelsky , Michael S. Borella , Ikhlaq Sidhu , Danny M. Nessett
- 申请人: David Grabelsky , Michael S. Borella , Ikhlaq Sidhu , Danny M. Nessett
- 申请人地址: US MA Marlborough
- 专利权人: 3Com Corporation
- 当前专利权人: 3Com Corporation
- 当前专利权人地址: US MA Marlborough
- 代理机构: McDonnell Boehnen Hulbert & Berghoff LLP
- 主分类号: H04K1/00
- IPC分类号: H04K1/00 ; H04L9/00 ; G06F15/16
摘要:
A method and system for distributed network address translation with security features. The method and system allow Internet Protocol security protocol (“IPsec”) to be used with distributed network address translation. The distributed network address translation is accomplished with IPsec by mapping a local Internet Protocol (“IP”) address of a given local network device and a IPsec Security Parameter Index (“SPI”) associated with an inbound IPsec Security Association (“SA”) that terminates at the local network device. A router allocates locally unique security values that are used as the IPsec SPIs. A router used for distributed network address translation is used as a local certificate authority that may vouch for identities of local network devices, allowing local network devices to bind a public key to a security name space that combines a global IP address for the router with a set of locally unique port numbers used for distributed network address translation. The router issues security certificates and may itself be authenticated by a higher certificate authority. Using a security certificate, a local network device may initiate and be a termination point of an IPsec security association to virtually any other network device on an IP network like the Internet or an intranet. The method and system may also allow distributed network address translation with security features to be used with Mobile IP or other protocols in the Internet Protocol suite.
信息查询