Arrangement in an IP node for preserving security-based sequences by ordering IP packets according to quality of service requirements prior to encryption
    1.
    发明申请
    Arrangement in an IP node for preserving security-based sequences by ordering IP packets according to quality of service requirements prior to encryption 有权
    IP节点中的布置,用于通过在加密之前根据服务质量要求对IP包进行排序来保护基于安全性的序列

    公开(公告)号:US20050182833A1

    公开(公告)日:2005-08-18

    申请号:US10759182

    申请日:2004-01-20

    IPC分类号: G06F15/16 G06F15/173 H04L9/00

    摘要: A router has at least one outbound interface configured for establishing multiple IP-based secure connections (i.e., tunnels) with respective destinations based on transmission of encrypted data packets via the IP-based secure connections. The encrypted data packets are generated by a cryptographic module, where each encrypted packet successively output from the cryptographic module includes a corresponding successively-unique sequence number. The supply of data packets to the cryptographic module is controlled by a queue controller: the queue controller assigns, for each secure connection, a corresponding queuing module configured for outputting a group of data packets associated with the corresponding secure connection according to a corresponding assigned maximum output bandwidth. Each queuing module also is configured for reordering the corresponding group of data packets according to a determined quality of service policy and the corresponding assigned maximum output bandwidth.

    摘要翻译: 路由器具有至少一个出站接口,被配置为基于经由基于IP的安全连接的加密数据分组的传输来建立与相应目的地的多个基于IP的安全连接(即,隧道)。 加密数据分组由加密模块生成,其中从加密模块连续输出的每个加密分组包括对应的连续唯一的序列号。 向密码模块提供数据分组由队列控制器控制:队列控制器为每个安全连接分配相应的排队模块,该队列模块被配置为根据对应的分配的最大值输出与相应的安全连接相关联的一组数据分组 输出带宽。 每个排队模块还被配置为根据确定的服务质量策略和相应的分配的最大输出带宽来重新排序相应的数据分组组。