IP Library Granted Patent US 7,917,939
Granted Patent B2
US 7,917,939 · App. 11/776,079 · Granted Mar 29, 2011

IPSec processing device, network system, and IPSec processing program

Assignee: Hitachi, Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,917,939
App. No.
11/776,079
Granted
Mar 29, 2011
Kind
B2
Abstract

Security policy databases capable of being fast retrieved while securing sequentiality. An IPSec processing device of the present invention performs communications by encrypting IP packets exchanged between a first IP network and a second IP network. The IPSec processing device includes a security policy database that stores security policies. The security policy database includes first, second, and third security policy databases. The first and third security policy databases include a linear list structure, and the second security policy database includes a hash list structure. The IPSec processing device, when performing at least one of transmission and reception of the IP packet, retrieves a security policy in the order of the first, second, and third security policy databases.

Claims (38)

1. An IPSec processing device that performs communications by encrypting IP packets exchanged between a first IP network and a second IP network,

wherein the IPSec processing device includes a security policy database that stores security policies,

wherein the security policy database includes a first security policy database, a second security policy database, and a third security policy database,

wherein the first security policy database and the third security policy database include a linear list structure,

wherein the second security policy database includes a hash list structure,

wherein the IPSec processing device, when performing at least one of transmission and reception of the IP packet, retrieves a security policy to be applied to the IP packet in the order of the first security policy database, the second security policy database, and the third security policy database; and

wherein the IPSec processing device stores security policies applied to system-based communications having higher priority than inter-user communications in the security policy databases as security policies for the system, and disposes the security policies for the system in positions preferentially retrieved.

2. The IPSec processing device according to claim 1 ,

wherein the security policies are sorted in the order in which they are checked in retrieval, and

wherein the IPSec processing device stores the sorted security policies in the first security policy database, the second security policy database, or the third security policy database.

3. The IPSec processing device according to claim 1 ,

wherein the security policies include priority with which they are checked in retrieval, and

wherein the IPSec processing device performs retrieval according to the priority.

4. The IPSec processing device according to claim 1 , wherein the second security policy database is split by the prefix length of an IP address included in the IP packet.

5. The IPSec processing device according to claim 1 ,

wherein the IPSec processing device stores the security policies in the security policy databases in association with information of users to whom the security policies are applied, and upon receiving specification of users to whom the security policies are applied, retrieves security policies associated with the specified users.

6. The IPSec processing device according to claim 5 , wherein the IPSec processing device retrieves the security policies at once for each of the specified users.

7. The IPSec processing device according to claim 5 ,

wherein the IPSec processing device exchanges an encryption key with an IPSec processing device of a communication destination, and creates the security policies, based on an IP address and user information included in a packet received when exchanging the encryption key.

8. A network system including an IPSec processing device that performs communications by encrypting IP packets exchanged between a first IP network and a second IP network,

wherein the IPSec processing device exchanges an encryption key with an IPSec processing device of a communication destination, creates the security policies, based on an IP address and user information included in a packet received when exchanging the encryption key, and includes a security policy database that stores the security policies,

wherein the security policy database includes a first security policy database, a second security policy database, and a third security policy database,

wherein the first security policy database and the third security policy database include a linear list structure,

wherein the second security policy database includes a hash list structure,

wherein the IPSec processing device, when performing at least one of transmission and reception of the IP packet, retrieves a security policy to be applied to the IP packet in the order of the first security policy database, the second security policy database, and the third security policy database, and

wherein the IPSec processing device stores security policies applied to system-based communications having higher priority than inter-user communications in the security policy databases as security policies for the system, and disposes the security policies for the system in positions preferentially retrieved.

9. The network system according to claim 8 ,

wherein the security policies are sorted in the order in which they are checked in retrieval, and

wherein the IPSec processing device stores the sorted security policies in the first security policy database, the second security policy database, or the third security policy database.

10. The network system according to claim 8 ,

wherein the security policies include priority with which they are checked in retrieval, and

wherein the IPSec processing device performs retrieval according to the priority.

11. The network system according to claim 8 ,

wherein the second security policy database is split by the prefix length of an IP address included in the IP packet.

12. The network system according to claim 8 ,

wherein the IPSec processing device stores the security policies in the security policy databases in association with information of users to whom the security policies are applied, and upon receiving specification of users to whom the security policies are applied, retrieves security policies associated with the specified users.

13. The network system according to claim 12 ,

wherein the IPSec processing device retrieves the security policies at once for each of the specified users.

Assignments (2)
MERGER Recorded Jan 19, 2010
From: HITACHI COMMUNICATION TECHNOLOGIES, LTD.
To: HITACHI, LTD.
Reel/Frame 023804/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2007
From: MORISHIGE, TAKEHIRO; MATSUKI, JOUSUKE; YANO, MASASHI
To: HITACHI COMMUNICATION TECHNOLOGIES, LTD.
Reel/Frame 019542/0976 →
Priority Claims (1)
JP 2006-225491 · Aug 22, 2006 · national
Continuity (1)
Related Publication 20080052756A1 · Feb 28, 2008