US2006070122A1PendingUtilityA1
Method and apparatus for a distributed firewall
Individually held — no corporate assignee on recordPriority: Jun 30, 1999Filed: Sep 28, 2005Published: Mar 30, 2006
Est. expiryJun 30, 2019(expired)· nominal 20-yr term from priority
Inventors:Steven Michael Bellovin
H04L 63/0236H04L 63/08H04L 63/0218
43
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method and apparatus for implementing a distributed firewall is described. A packet filter processor receives a packet sent from a first device to a second device. The packet filter processor authenticates an identifier for the packet. For example, authentication could be performed using a cryptographically-verifiable identifier. The packet filter processor determines whether to send the packet to the second device, based on the authentication and a set of policy rules. The packet filter processor sends the packet to the second device in accordance with the determination
Claims
exact text as granted — not AI-modified1 - 2 . (canceled)
3 . A method for filtering packets, comprising:
receiving a packet sent from a first device to a second device; authenticating an identifier for said packet; determining whether to send said packet to said second device; and sending said packet to said second device in accordance with said determination wherein said identifier is a common host identifier.
4 - 22 . (canceled)
23 . A method for filtering packets, comprising:
receiving a packet sent from a first device to a second device; authenticating an identifier for said packet; determining whether to send said packet to said second device; and sending said packet to said second device in accordance with said determination further comprising a second buffer for storing said compared data packet prior to forwarding said compared data packet to the second device wherein said random access memory comprises dynamic random access memory.
24 . The apparatus of claim 23 , further comprising a non-volatile random access memory for storing parameters used by said operating system program
25 . The apparatus of claim 24 , further comprising means for receiving an updated list of origination addresses.
26 . The apparatus of claim 25 , wherein said means for receiving comprises an asynchronous terminal device and a serial port coupled to said dynamic random access memory.
27 . The apparatus of claim 25 , wherein said means for receiving comprises a network interface card coupled to said dynamic random access memory
28 . The apparatus of claim 21 , wherein said first network is a wireless network, and said input means comprises means for receiving said data packets from said wireless network.
29 . A distributed firewall system, comprising:
a first network device; a second network device in communication with said first network device; a packet filter processor for each network device; an encryption means coupled to said packet filter processor, said encryption means for decrypting and authenticating a packet sent between said first network device and said second network device; and a system management module to manage said packet filter processors.
30 . The system of claim 29 wherein said authenticating comprises:
retrieving a pointer to a security association from an authentication header from said packet; retrieving a key associated with said security association; and determining whether said packet is authentic using said key.
31 . (Previously added): The system of claim 30 wherein said authentication header is an IPSEC authentication header.Join the waitlist — get patent alerts
Track US2006070122A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.