US2015271140A1PendingUtilityA1

Tunnelling of Information

Assignee: TECTIA OYJPriority: Jun 15, 1999Filed: May 21, 2015Published: Sep 24, 2015
Est. expiryJun 15, 2019(expired)· nominal 20-yr term from priority
H04L 63/0272H04L 63/029H04L 61/256H04L 61/6063H04L 12/4633H04L 2101/663H04L 61/2564H04L 67/568H04L 61/00H04L 61/2575H04L 61/2553H04L 61/5007H04L 61/2514H04L 61/2578H04L 69/161H04L 69/16H04L 69/165H04L 45/026H04L 63/0428H04L 63/164H04L 63/04H04L 61/25
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

This invention provides a method for providing network security services, such as those provided by the IPSEC protocol, through network address translation (NAT). The method is based on determining the transformations that occur on a packet and compensating for the transformations. Because only TCP and UDP protocols work through NATs, the IPSEC AH/ESP packets are encapsulated into UDP packets for transport. Special operations are performed to allow reliable communications in such environments.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A device comprising at least one processor, and at least one memory including computer program code, the at least one memory and the computer program code being configured to, with the at least one processor, cause the device to
 communicate information in packets conforming a first protocol, and   tunnel information to be communicated to another device to a second protocol in response to determining possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device.   
     
     
         2 . The device according to  claim 1 , configured to tunnel the information in response to determination of at least one network address translation and/or a protocol conversion between the device and the other device. 
     
     
         3 . The device according to  claim 1 , configured to determine the possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device based on the other device not responding to a packet send earlier thereto. 
     
     
         4 . The device according to  claim 1 , configured to determine the possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device based on configuration of the device. 
     
     
         5 . The device according to  claim 1 , configured to determine the possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device based on stored information. 
     
     
         6 . The device according to  claim 1 , configured to encapsulate the packets to be communicated to the other device into User Datagram Protocol (UDP) packets and/or Transport Control Protocol (TCP) packets. 
     
     
         7 . The device according to  claim 1 , comprising an end node or a virtual private network (VPN) device. 
     
     
         8 . A method for communication of packets from a device configured for communication of packets according to a first protocol, the method comprising tunneling information to be communicated from the device to another device to a second protocol in response to determining possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device. 
     
     
         9 . The method according to  claim 8 , comprising performing the tunneling in response to determining at least one network address translation and/or a protocol conversion between the device and the other device. 
     
     
         10 . The method according to  claim 8 , comprising sending a packet to the other device in accordance with the first protocol and determining the possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device based on the other device not responding to the packet. 
     
     
         11 . The method according to  claim 8 , comprising determining the possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device based on configuration of the device. 
     
     
         12 . The method according to  claim 8 , comprising storing information about communication of packet to the other device and determining the possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device based on the stored information. 
     
     
         13 . The method according to  claim 8 , comprising selectively encapsulating the packets to be communicated to the other device into User Datagram Protocol (UDP) packets and/or Transport Control Protocol (TCP) packets. 
     
     
         14 . A non-transitory computer readable media, comprising program code for causing a processor to perform instructions for
 communicating, by a device, information in packets conforming a first protocol, and   tunneling information to be communicated from the device to another device to a second protocol in response to determining possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device.   
     
     
         15 . The non-transitory computer readable media of  claim 14 , further comprising program code for causing the processor to perform instructions for
 determining at least one network address translation and/or protocol conversion between the device and the other device, and   tunneling the information in response thereto.   
     
     
         16 . The non-transitory computer readable media of  claim 14 , further comprising program code for causing the processor to perform instructions for determining the possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device based on the other device not responding a packet send to the other device in accordance with the first protocol. 
     
     
         17 . The non-transitory computer readable media of  claim 14 , further comprising program code for causing the processor to perform instructions for determining the possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device based on configuration of the device. 
     
     
         18 . The non-transitory computer readable media of  claim 14 , further comprising program code for causing the processor to perform instructions for storing information about communication of packet to the other device and determining the possibility of packets conforming the first protocol being incapable of traversing at least one node between the device and the other device based on the stored information. 
     
     
         19 . The non-transitory computer readable media of  claim 14 , wherein the program code is configured for causing the processor to perform instructions for encapsulating the packets to be communicated to the other device into User Datagram Protocol (UDP) packets and/or Transport Control Protocol (TCP) packets. 
     
     
         20 . The non-transitory computer readable media of  claim 14  configured for an end node or a virtual private network (VPN) device.

Join the waitlist — get patent alerts

Track US2015271140A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.