IP Library Patent Application 11523760
Patent Application
App. No. 11/523,760

Re-encrypting policy enforcement point

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/523,760
Filed
Sep 19, 2006
Art Unit
2436
USPC
713/153
Abstract

Providing end-to-end security poses many challenges to security solutions. In Internet Security (IPsec), securing data locally and remotely, as well as reducing the number of security associations and polices needed to secure that data are such challenges. The provided method and apparatus answer theses challenges by i) decrypting an encrypted packet according to a first policy, ii) establishing a local secure connection to an end node on a local network according to a second security policy in an event a source and a destination of the packet belong to a same security group, and the destination of the packet is on the local network, and iii) establishing a remote secure connection to a remote network according to a third security policy in an event the source and the destination of the packet belong to a same security group, and the destination of the packet is the remote network.

Claims (31)

1 . A network security method for providing local network security and remote network security comprising:

decrypting an encrypted packet according to a first security policy to yield a decrypted packet;

establishing a local secure connection to an end node on a local network according to a second security policy in an event a source of the decrypted packet and a destination of the decrypted packet belong to a same security group, and the destination of the decrypted packet is on the local network; and

establishing a remote secure connection to a remote network according to a third security policy in an event the source of the decrypted packet and the destination of the decrypted packet belong to a same security group, and the destination of the decrypted packet is the remote network.

2 . The method of claim I wherein the establishing the local secure connection to the end node includes encrypting the decrypted packet with a set of local security parameters.

3 . The method of claim 1 wherein the establishing the remote secure connection to the remote network includes encrypting the decrypted packet with a set of remote security parameters.

4 . The method of claim 1 further comprising dropping the decrypted packet in an event the source of the decrypted packet and the destination of the decrypted packet belong to different security groups, and a network only allows encrypted packets.

5 . The method of claim 1 further comprising:

passing the decrypted packet unencrypted to the end-node on the local network in an event the source of the decrypted packet and the destination of the decrypted packet belong to different security groups, and the local network allows unencrypted packets; and

passing the decrypted packet unencrypted to the remote network in an event the source of the decrypted packet and the destination of the decrypted packet belong to different security groups, and the remote network allows unencrypted packets.

6 . The method of claim 1 further comprising negotiating security policies.

7 . The method of claim 6 wherein the negotiating includes exchanging security policies using Internet Key Exchange (IKE).

8 . The method of claim 1 further comprising distributing security policies.

9 . The method of claim 8 wherein the distributing includes configuring security policies using a policy and key distribution system.

10 . The method of claim 1 further comprising assigning the decrypted packet to a security group.

11 . The method of claim 10 wherein the assigning includes tagging the decrypted packet with a Virtual Local Area Network (VLAN) tag.

12 . A network security apparatus for securing a local network and a remote network comprising:

a de-encryptor which decrypts an encrypted packet to yield a decrypted packet;

a local securer communicatively coupled to the de-encryptor which establishes a secure connection to an end node on a local network according to a first security policy in an event a source of the decrypted packet and a destination of the decrypted packet belong to a same security group, and the destination of the decrypted packet is on the local network; and

a remote securer communicatively coupled to the de-encryptor which establishes a secure connection to a remote network according to a second security policy in an event the source of the decrypted packet and the destination of the decrypted packet belong to a same security group, and the destination of the decrypted packet is the remote network.

13 . The apparatus of claim 12 wherein the local securer is a local policy enforcement point.

14 . The apparatus of claim 13 wherein the local policy enforcement point encrypts the decrypted packet with a set of local security parameters.

15 . The apparatus of claim 12 wherein the second securing unit is a remote policy enforcement point.

16 . The apparatus of claim 15 wherein the remote policy enforcement point encrypts the decrypted packet with a set of remote security parameters.

17 . The apparatus of claim 12 further comprising a router which drops the decrypted packet in an event the source of the decrypted packet and the destination of the decrypted packet belong to different security groups, and a network only allows encrypted packets.

18 . The apparatus of claim 12 further comprising a router which i) passes the decrypted packet unencrypted to the end-node on the local network in an event the source of the decrypted packet, and the destination of the decrypted packet belong to different security groups and the local network allows unencrypted packets, and ii) passes the decrypted packet unencrypted to the remote network in an event the source of the decrypted packet and the destination of the decrypted packet belong to different security groups, and the remote network allows unencrypted packets.

19 . The apparatus of claim 12 further comprising a security policy loader which negotiates security policies in an event Internet Key Exchange (IKE) is used, and distributes security policies in an event a policy and key distribution system is used.

20 . A computer program product comprising a computer usable medium having a computer usable program code for providing local network security and remote network security, the computer program product including;

computer useable program code for decrypting an encrypted packet according to a first security policy to yield a decrypted packet;

computer useable program code for establishing a local secure connection to an end node on a local network according to a second security policy in an event a source of the decrypted packet and a destination of the decrypted packet belong to a same security group, and the destination of the decrypted packet is on the local network; and

computer useable program code for establishing a remote secure connection to a remote network according to a third security policy in an event the source of the decrypted packet and the destination of the decrypted packet belong to a same security group, and the destination of the decrypted packet is the remote network.

Assignments (12)
CHANGE OF NAME Recorded Apr 15, 2011
From: CIPHEROPTICS, INC.
To: CERTES NETWORKS, INC.
Reel/Frame 026134/0111 →
RELEASE OF SECURITY INTEREST Recorded Feb 9, 2011
From: ADAMS CAPITAL MANAGEMENT III, L.P.
To: CIPHEROPTICS INC.
Reel/Frame 025774/0398 →
RELEASE OF SECURITY INTEREST Recorded Feb 9, 2011
From: ADAMS CAPITAL MANAGEMENT III, L.P.
To: CIPHEROPTICS INC.
Reel/Frame 025775/0040 →
RELEASE OF SECURITY INTEREST Recorded Jan 12, 2011
From: VENTURE LENDING & LEASING IV, INC.
To: CIPHEROPTICS, INC.
Reel/Frame 025625/0961 →
SECURITY AGREEMENT Recorded Sep 29, 2010
From: CIPHEROPTICS INC.
To: ADAMS CAPITAL MANAGEMENT III, L.P.
Reel/Frame 025051/0762 →
RELEASE OF SECURITY INTEREST Recorded May 13, 2010
From: ADAMS CAPITAL MANAGEMENT III, LP
To: CIPHEROPTICS, INC.
Reel/Frame 024379/0889 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2010
From: ADAMS CAPITAL MANAGEMENT III, L.P.
To: CIPHEROPTICS INC.
Reel/Frame 023890/0220 →
SECURITY AGREEMENT Recorded Dec 29, 2009
From: CIPHEROPTICS INC.
To: ADAMS CAPITAL MANAGEMENT III, L.P.
Reel/Frame 023713/0623 →
SECURITY AGREEMENT Recorded Apr 7, 2009
From: CIPHEROPTICS INC.
To: RENEWABLE ENERGY FINANCING, LLC
Reel/Frame 022516/0338 →
SECURITY AGREEMENT Recorded Apr 24, 2007
From: CIPHEROPTICS, INC.
To: ADAMS CAPITAL MANAGEMENT III, L.P.
Reel/Frame 019198/0810 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2007
From: MCALISTER, DONALD
To: CIPHEROPTICS, INC.
Reel/Frame 019118/0509 →
SECURITY AGREEMENT Recorded Dec 21, 2006
From: CIPHEROPTICS INC.
To: VENTURE LENDING & LEASING IV, INC.
Reel/Frame 018728/0421 →