Patent · US Expired

Method and apparatus for reducing the number of tunnels used to implement a security policy on a network

US7107613B1 · kind B1 · utility

95Cited by
2References
34Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMar 27, 2002
Grant dateSep 12, 2006
Priority date
Expiry dateOct 8, 2024

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/164
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

According to one embodiment, the number of tunnels on a network may be reduced. A set of tunnels are selected which exchange data packets between a first security device and a second security device. Each tunnel in the set of tunnels specify a dimensional range for data packets that are subject to that tunnel. A super tunnel is determined to replace the set of tunnels, so that a dimensional range of the data packets that are made subject to the super tunnel encompass a dimensional range of the data packets that were made subject to the set of tunnels. A determination is made as to whether the super tunnel excludes data packets that are permitted by the first security device and the second security device, but not subject to any one of the tunnels other than tunnels in the set of tunnels. In response to determining that the tunnel excludes data packets that are permitted by the first security device and the second security device, but not subject to any one of the tunnels in the set of tunnels, the super tunnel is implemented between the first security device and the second security device.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.