IP Library Granted Patent US 8,250,357
Granted Patent B2
US 8,250,357 · App. 09/952,520 · Granted Aug 21, 2012

Tunnel interface for securing traffic over a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,250,357
App. No.
09/952,520
Granted
Aug 21, 2012
Kind
B2
Abstract

A flexible, scalable hardware and software platform that allows a service provider to easily provide internet services, virtual private network services, firewall services, etc., to a plurality of customers. One aspect provides a method and system for delivering security services. This includes connecting a plurality of processors in a ring configuration within a first processing system, establishing a secure connection between the processors in the ring configuration across an internet protocol (IP) connection to a second processing system to form a tunnel, and providing both router services and host services for a customer using the plurality of processors in the ring configuration and using the second processing system. A secure communications tunnel is formed by routing all packets for the tunnel through an encrypting router at the sending end to obtain encrypted packets, and routing the encrypted packets through a decrypting router at the receiving end of an IP connection.

Claims (19)

1. A method of delivering security services through a service provider network, the method comprising:

establishing a first routing node within a first processing system;

establishing a second routing node within a second processing system;

establishing an internet protocol (IP) connection communications path between the first processing system and the second processing system that includes the first routing node and the second routing node, wherein establishing includes:

connecting the first routing node to a set of one or more service provider routers of a plurality of service provider routers within the service provider network; and

configuring one or more of the plurality of service provider routers to implement a virtual private network between the set of one or more service provider routers and the second routing node;

receiving a plurality of data packets into the first routing node;

forwarding the received plurality of data packets to a selected service provider router of the set of one or more service provider routers;

encrypting the received plurality of data packets to form encrypted packets within the selected service provider router, without regard to any indication regarding encryption in the received plurality of data packets;

sending the encrypted packets from the selected service provider router to the second routing node;

receiving the encrypted packets into the second routing node;

decrypting the received encrypted packets, without regard to any indication regarding decryption in the received encrypted packets, to form decrypted packets; and

sending the decrypted packets to a destination in the second processing system.

2. The method of claim 1 , wherein, to support a communications network, the first processing system includes one or more control processors, one or more access processors, and one or more processing processors.

3. The method of claim 1 , wherein for a first customer of the service provider, a first virtual router within the service provider network forms the first routing node in the first processing system and is operationally connected to a second virtual router within the service provider network, and the second virtual router forms the second routing node in the second processing system.

4. The method of claim 1 , wherein for each of a plurality of customers of the service provider network, the virtual private network is formed using a virtual encrypting router formed in the service provider network and operationally connected to a virtual decrypting router formed in the second processing system.

5. The method of claim 1 , wherein said connecting the first routing node to a set of one or more service provider routers within the service provider network includes connecting a plurality of processors in a ring configuration within the service provider network.

6. The method of claim 5 , wherein said connecting the plurality of processors in the ring configuration includes forming a dual rotating ring architecture.

7. The method of claim 5 , wherein said connecting the plurality of processors in the ring configuration includes forming a dual counter-rotating ring midplane.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2025
From: PALISADE TECHNOLOGIES, LLP
To: ATHENA SECURITY, LLP
Reel/Frame 073476/0208 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2025
From: FORTINET, INC.
To: PALISADE TECHNOLOGIES, LLP
Reel/Frame 073476/0494 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2006
From: COSINE COMMUNICATIONS, INC.
To: FORTINET, INC
Reel/Frame 017962/0682 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2002
From: SUN, CHIH-TANG; YUM, KIHO; MATTHEWS, ABRAHAM R.
To: COSINE COMMUNICATIONS, INC.
Reel/Frame 012834/0386 →