IP Library Patent Application 14258444
Patent Application
App. No. 14/258,444

EFFICIENT INTERNET PROTOCOL SECURITY AND NETWORK ADDRESS TRANSLATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/258,444
Abstract

Various exemplary embodiments relate to a method performed by a network processing device for creating a NAT session with a tunnel between two nodes, the method comprising: receiving a packet; determining the packet does not have a Security Association; establishing a Security Association associated with a tunnel; generating a tunnel identifier for the tunnel; creating a NAT session information; and storing the NAT session information and the tunnel identifier.

Claims (63)

1 . A method performed by a network processing device for creating a NAT session with a tunnel between two nodes, the method comprising:

receiving a packet;

determining the packet does not have a Security Association;

establishing a Security Association associated with a tunnel;

generating a tunnel identifier for the tunnel, wherein the tunnel identifier is to be used in a NAT session request;

creating a NAT session information; and

storing the NAT session information and the tunnel identifier.

2 . The method of claim 1 , where the step of creating a NAT session information further comprises:

performing a hash on a destination address, a source address, a protocol, and a port information stored in header fields of the packet.

3 . The method of claim 1 , wherein the step of establishing a Security Association further comprises:

sending a request to a remote node, wherein the request comprises a cryptographic key, information identifying a first network endpoint and a first port and a second network endpoint and a second port, and a tunnel type.

4 . The method of claim 3 , wherein the second network endpoint is determined by information stored in header fields of the packet.

5 . The method of claim 1 , further comprising:

generating a NAT session request comprising the tunnel identifier.

6 . A method performed by a network processing device for processing a packet, the method comprising:

receiving an encrypted packet comprising an encrypted first set of headers and an unencrypted second set of headers;

determining a NAT session information from the unencrypted first set of headers;

determining the NAT session information is associated with a tunnel;

decrypting the packet; and

sending the packet towards a destination address stored in the first set of headers.

7 . The method of claim 6 , wherein the step of determining the NAT session information further comprises:

performing a hash on a destination address, a source address, a protocol, and a port information stored in the second set of headers; and

locating the NAT session information that matches the hash, where the NAT session information is stored in a table and comprises the hash.

8 . The method of claim 6 , wherein the step of determining the NAT session information is associated with a tunnel further comprises:

determining the NAT session information comprises a tunnel identifier.

9 . The method of claim 6 , wherein the step of sending the packet towards a destination address stored in the first set of headers further comprises:

performing a route lookup on the header information in the decrypted packet.

10 . The method of claim 6 further comprising:

determining the NAT session information is associated with an expired NAT session;

creating a new NAT session information; and

storing the new NAT session information and a tunnel identifier associated with the tunnel.

11 . A non-transitory machine-readable storage medium encoded with instructions for execution by a network processing device for creating a NAT session with a tunnel between two nodes, the non-transitory machine-readable storage medium comprising:

instructions for receiving, at the network processing device, a packet;

instructions for determining the packet does not have a Security Association;

instructions for establishing a Security Association associated with a tunnel;

instructions for generating a tunnel identifier for the tunnel, wherein the tunnel identifier is to be used in a NAT session request;

instructions for creating a NAT session information; and

instructions for storing the NAT session information and the tunnel identifier in a data store.

12 . The non-transitory machine-readable storage medium of claim 11 , wherein the instructions for creating a NAT session information further comprises:

instructions for performing a hash on a destination address, a source address, a protocol, and a port information stored in header fields of the packet.

13 . The non-transitory machine-readable storage medium of claim 11 , wherein the instructions for establishing a Security Association further comprises:

instructions for sending a request to a remote node, wherein the request comprises a cryptographic key, information identifying a first network endpoint and a first port and a second network endpoint and a second port, and a tunnel type.

14 . The non-transitory machine-readable storage medium of claim 13 , further comprising:

instructions for determining the second network endpoint based upon information stored in header fields of the packet.

15 . The non-transitory machine-readable storage medium of claim 11 , further comprising:

instructions for generating a NAT session request comprising the tunnel identifier.

16 . A non-transitory machine-readable storage medium encoded with instructions for execution by a network processing device for processing a packet, the non-transitory machine-readable storage medium comprising:

instructions for receiving, at the network processing device, an encrypted packet comprising an encrypted first set of headers and an unencrypted second set of headers;

instructions for determining a NAT session information from the unencrypted first set of headers;

instructions for determining the NAT session information is associated with a tunnel;

instructions for decrypting the packet; and

instructions for sending the packet towards a destination address stored in the first set of headers.

17 . The non-transitory machine-readable storage medium of claim 16 , wherein the instructions for determining the NAT session information further comprises:

instructions for performing a hash on a destination address, a source address, a protocol, and a port information stored in the second set of headers; and

instructions for locating the NAT session information that matches the hash, wherein the NAT session information is stored in a table and comprises the hash.

18 . The non-transitory machine-readable storage medium of claim 16 , wherein the instructions for determining the NAT session information is associated with a tunnel further comprises:

instructions for determining the NAT session information comprises a tunnel identifier.

19 . The non-transitory machine-readable storage medium of claim 16 , wherein the instructions for sending the packet towards a destination address stored in the first set of headers further comprises:

instructions for performing a route lookup on the header information in the decrypted packet.

20 . The non-transitory machine-readable storage medium of claim 16 , further comprising:

instructions for determining the NAT session information is associated with an expired NAT session;

instructions for creating a new NAT session information; and

instructions for storing the new NAT session information and a tunnel identifier associated with the tunnel.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Aug 28, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT CANADA INC.
Reel/Frame 033655/0425 →
SECURITY INTEREST Recorded Aug 7, 2014
From: ALCATEL-LUCENT CANADA INC.
To: CREDIT SUISSE AG
Reel/Frame 033500/0326 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2014
From: ORTACDAG, EREL; PATEL, NIRMESH
To: ALCATEL-LUCENT CANADA, INC.
Reel/Frame 032728/0116 →