IP Library Granted Patent US 7,505,473
Granted Patent B2
US 7,505,473 · App. 10/611,358 · Granted Mar 17, 2009

Transmission of broadcast packets in secure communication connections between computers

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,505,473
App. No.
10/611,358
Granted
Mar 17, 2009
Kind
B2
Abstract

A method and devices are provided for handling a broadcast packet in a computer ( 131, 132, 612, 622, 632, 711, 721, 731, 741, 1111, 1112, 1301 ) that has an IPsec-protected connection to a part ( 121, 122, 141, 732, 733, 742, 743, 1113, 1114 ) of a logical network segment ( 101, 601, 701, 1101 ) within which the broadcast packet should be distributed. The IPsec protection specifies, what kinds of packets are acceptable for transmission over the IPsec-protected connection. The broadcast packet is encapsulated ( 204, 311, 508, 835, 838, 840, 842, 849, 852, 909 ) into a form that is acceptable for transmission over the IPsec-protected connection. It is then transmitted ( 205, 206, 312, 509, 836, 839, 841, 843, 850, 853, 910 ) to the part of the logical network segment through the IPsec-protected connection.

Claims (25)

1. A gateway computer ( 131 , 132 , 612 , 622 , 632 , 711 , 721 , 731 , 741 , 1111 , 1112 , 1301 ) for offering another computer device an IPsec-protected connection to and from a logical network segment ( 101 , 601 , 701 , 1101 ) within which the distribution of broadcast packets is allowable, wherein the IPsec protection is arranged to specify, what kinds of packets are acceptable for transmission over an IPsec-protected connection, characterized in that the gateway computer comprises:

means ( 1311 , 1321 ) for encapsulating a broadcast packet into a form that is acceptable for transmission over an IPsec-protected connection,

means ( 1312 , 1322 ) for unicast transmitting the encapsulated broadcast packet to the other computer device through an IPsec-protected connection,

a first network interface ( 1322 ) for connecting the gateway computer to a logical network segment comprising several computer devices,

a second network interface ( 1312 ) for connecting the gateway computer to individual hosts for the purpose of making such individual hosts appear as parts of the logical network segment,

an IPsec component ( 1311 ) coupled to the second network interface ( 1312 ) for implementing IPsec protection within connections through said second network interface,

a broadcast packet handler component ( 1350 ), wherein the broadcast packet handler component is arranged to:

receive ( 1355 ) broadcast packets from either of the first ( 1322 ) and second ( 1312 ) network interfaces,

forward ( 1353 ) received broadcast packets to application layer entities ( 1302 ) in the gateway computer,

forward ( 1353 ) broadcast packets received from the first network interface ( 1322 ) towards the second network interface ( 1312 ),

forward ( 1353 ) broadcast packets received from the second network interface ( 1312 ) towards the first network interface ( 1322 ),

forward ( 1353 ) broadcast packets from application layer entities ( 1302 ) in the gateway computer towards the first and second network interfaces, and

instruct the IPsec component ( 1311 ) regarding protected transmission of broadcast packets through the second network interface,

characterized in that the broadcast packet handler component ( 1350 ) is additionally arranged to receive information ( 1355 ) from the IPsec component ( 1311 ) regarding the number and endpoints of currently existing IPsec-protected connections through the second network interface.

2. A host computer ( 121 , 122 , 141 , 732 , 733 , 742 , 743 , 1113 , 1114 , 1301 ), comprising means ( 1311 , 1312 ) for establishing an IPsec-protected connection to and from a gateway computer of a logical network segment within which the distribution of broadcast packets is allowable, wherein the IPsec protection is arranged to specify, what kinds of packets are acceptable for transmission over the IPsec-protected connection, characterized in that the host computer comprises:

means ( 1311 ) for encapsulating a broadcast packet into a form that is acceptable for transmission over the IPsec-protected connection,

means ( 1312 ) for unicast transmitting the encapsulated broadcast packet to the gateway computer through the IPsec-protected connection,

a network interface ( 1312 ) for connecting the host computer to a gateway computer,

an IPsec component ( 1311 ) coupled to the network interface ( 1312 ) for implementing IPsec protection within connections through said network interface, and

a broadcast packet handler component ( 1350 ), wherein the broadcast packer handler component is arranged to:

receive ( 1355 ) broadcast packets from the network interface,

forward ( 1353 ) received broadcast packets to application layer entities ( 1302 ) in the host computer,

forward ( 1353 ) broadcast packets from application layer entities ( 1302 ) in the host computer towards the network interface ( 1312 ), and

instruct the IPsec component ( 1311 ) regarding protected transmission of broadcast packets through the network interface,

characterized in that the broadcast packet handler component ( 1350 ) is additionally arranged to receive ( 1355 ) information from the IPsec component ( 1311 ) regarding the number and endpoints of currently existing IPsec-protected connections through the network interface.

Assignments (13)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2019
From: VERIMATRIX
To: RAMBUS INC.
Reel/Frame 051262/0413 →
PARTIAL RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 21, 2019
From: GLAS SAS, AS AGENT
To: INSIDE SECURE
Reel/Frame 051076/0306 →
CHANGE OF ADDRESS Recorded Oct 16, 2019
From: VERIMATRIX
To: VERIMATRIX
Reel/Frame 050733/0003 →
CHANGE OF NAME Recorded Oct 7, 2019
From: INSIDE SECURE
To: VERIMATRIX
Reel/Frame 050647/0428 →
SECURITY INTEREST Recorded Feb 27, 2019
From: INSIDE SECURE
To: GLAS SAS, AS SECURITY AGENT
Reel/Frame 048449/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2013
From: AUTHENTEC, INC.
To: INSIDE SECURE
Reel/Frame 029748/0128 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2010
From: SAFENET, INC.
To: AUTHENTEC, INC.
Reel/Frame 024823/0745 →
PARTIAL RELEASE OF COLLATERAL Recorded Mar 19, 2010
From: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS FIRST AND SECOND LIEN COLLATERAL AGENT
To: SAFENET, INC.
Reel/Frame 024103/0730 →
CHANGE OF NAME Recorded Mar 5, 2008
From: SFNT FINLAND OY
To: SAFENET, INC.
Reel/Frame 020609/0987 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Apr 19, 2007
From: SAFENET, INC.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL AGENT
Reel/Frame 019181/0012 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 16, 2007
From: SAFENET, INC.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS, AS COLLATERAL AGENT
Reel/Frame 019161/0506 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2004
From: SSH COMMUNICATIONS SECURITY CORP.
To: SFNT FINLAND OY
Reel/Frame 015215/0805 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2003
From: PAAVOLAINEN, SANTERI
To: SSH COMMUNICATIONS SECURITY CORP.
Reel/Frame 014101/0555 →