IP Library Granted Patent US 8,438,629
Granted Patent B2
US 8,438,629 · App. 11/356,138 · Granted May 7, 2013

Packet security method and apparatus

Inventors: Yung-ji Lee (Suwon-si, KR); Kyung-hee Lee (Yongin-si, KR)
Assignee: Samsung Electronics Co., Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,438,629
App. No.
11/356,138
Granted
May 7, 2013
Kind
B2
Abstract

A packet security method and apparatus adjusts a security level of the packet according to a feature of the packet. The packet security method includes detecting a feature of a packet to be transmitted, determining a security level of the packet according to the detected feature, and generating a security packet according to the determined security level. The feature of the packet is at least one of a destination address of the packet, a transfer protocol of the packet, a packet size, an application for the packet, and a designated security level for the packet. According to the method, the security function is adoptively applied according to the feature of the packet being transmitted, and thus flexibility can be provided in the application of the security function to achieve an efficient use of resources.

Claims (39)

1. A packet security method of a packet security apparatus comprising:

detecting, by the packet security apparatus, a plurality of features of a packet to be transmitted;

determining, by the packet security apparatus, whether the detected plurality of features include a designated security level for the packet;

determining, by the packet security apparatus, a security level of the packet according to the designated security level if it is determined that the detected plurality of features include the designated security level;

determining, by the packet security apparatus, the security level of the packet according to the detected plurality of features if it is determined that the detected plurality of features do include the designated security level, wherein the security level of the packet is determined based on taking steps according to each of the plurality of features if it is determined that the detected plurality of features do not include the designated security level;

determining, by the packet security apparatus, whether a first algorithm corresponding to the determined security level of the packet exists in a security tool database; and

generating, by the packet security apparatus, a security packet according to the determined security level,

wherein the security packet is generated using a second algorithm corresponding to a security level nearest to the determined security level when the first algorithm corresponding to the determined security level does not exist in the security tool database,

wherein the plurality of features of the packet include at least one of a destination address of the packet, a transfer protocol of the packet, a packet size, and the designated security level for the packet.

2. The packet security method as claimed in claim 1 , further comprising determining the first or the second algorithm to encrypt the packet according to the determined security level.

3. The packet security method as claimed in claim 1 , further comprising determining the security level of the packet according to a predefined security policy if one or more predefined security policies exists.

4. The packet security method as claimed in claim 1 , wherein the security level is adjustable.

5. The packet security method as claimed in claim 2 , further comprising setting a new algorithm suitable for a destination device of the packet if the determined first or second algorithm is not suitable for the destination device of the packet.

6. A packet security apparatus comprising:

a packet feature detecting unit configured to detect a plurality of features of a packet to be transmitted;

a security level determining unit configured to determine whether the detected plurality of features include a designated security level for the packet, to determine a security level of the packet according to the designated security level if it is determined that the detected plurality of features include the designated security level, and to determine the security level of the packet according to the detected plurality of features if it is determined that the detected plurality of features do not include the designated security level, wherein the security level of the packet is determined based on taking steps according to each of the plurality of features if it is determined that the detected plurality of features do not include the designated security level; and

a security packet generating unit configured to determine whether a first algorithm corresponding to the determined security level exists in a security tool database, and to generate a security packet according to the determined security level,

wherein the security packet is generated using a second algorithm corresponding to a security level nearest to the determined security level when the first algorithm corresponding to the determined security level does not exist in the security tool database,

wherein the plurality of features of the packet include at least one of a destination address of the packet, a transfer protocol of the packet, a packet size, and the designated security level for the packet.

7. The packet security apparatus as claimed in claim 6 , wherein the security packet generating unit determines the first or the second algorithm used to encrypt the packet according to the determined security level.

8. The packet security apparatus as claimed in claim 6 , wherein if a predefined security policy exists for the packet security apparatus, the security level of the packet is determined according to the predefined security policy.

9. The packet security apparatus as claimed in claim 6 , wherein the security level is adjustable.

10. The packet security apparatus as claimed in claim 7 , wherein if the determined first or second algorithm is not suitable for a destination device of the packet, the security packet generating unit sets a new algorithm suitable for the destination device of the packet.

11. The packet security apparatus as claimed in claim 8 , further comprising a security policy table coupled to the security level determining unit, wherein the predefined security policy is contained within the security policy table.

12. A packet security method of a packet security apparatus comprising:

detecting, by the packet security apparatus, a plurality of features of a packet to be transmitted;

determining, by the packet security apparatus, whether the detected plurality of features include a designated security level for the packet;

determining, by the packet security apparatus, a security level of the packet according to the designated security level if it is determined that the detected plurality of features include the designated security level;

determining, by the packet security apparatus, the security level of the packet according to the detected plurality of features if it is determined that the detected plurality of features do not include the designated security level, wherein the security level of the packet is determined based on taking steps according to each of the plurality of features if it is determined that the detected plurality of features do not include the designated security level;

determining, by the packet security apparatus, whether a first algorithm corresponding to the determined security level of the packet exists in a security tool database; and

generating, by the packet security apparatus, a security packet according to the determined security level,

wherein the security packet is generated using a substitute algorithm corresponding to another security level higher or lower by one increment than the determined security level when the first algorithm corresponding to the determined security level does not exist in security tool database, and

wherein the plurality of features of the packet include at least one of a destination address of the packet, a transfer protocol of the packet, a packet size, and the designated security level for the packet.

13. A packet security apparatus comprising:

a packet feature detecting unit configured to detect a plurality of features of a packet to be transmitted;

a security level determining unit configured to determine whether the detected plurality of features include a designated security level for the packet, to determine a security level of the packet according to the designated security level if it is determined that the detected plurality of features include the designated security level, and to determine the security level of the packet according to the detected plurality of features if it is determined that the detected plurality of features do not include the designated security level, wherein the security level of the packet is determined based on taking steps according to each of the plurality of features if it is determined that the detected plurality of features do not include the designated security level; and

a security packet generating unit configured to determine whether a first algorithm corresponding to the determined security level exists in a security tool database, and to generate a security packet according to the determined security level,

wherein the security packet is generated using a substitute algorithm corresponding to another security level higher or lower by one increment than the determined security level when the first algorithm corresponding to the determined security level does not exist in the security tool database, and

wherein the plurality of features of the packet include at least one of a destination address of the packet, a transfer protocol of the packet, a packet size, and the designated security level for the packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2006
From: LEE, YUNG-JI; LEE, KYUNG-HEE
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 017598/0605 →
Priority Claims (2)
KR 10-2005-0014173 · Feb 21, 2005 · national
KR 10-2005-0108639 · Nov 14, 2005 · national
Continuity (1)
Related Publication 20060191002A1 · Aug 24, 2006