×

Security protocol

  • US 20010023482A1
  • Filed: 12/07/2000
  • Published: 09/20/2001
  • Est. Priority Date: 12/08/1999
  • Status: Active Grant
First Claim
Patent Images

1. A system with a local application entity and communications means by which the local application entity can exchange application messages with peer remote application entities on other systems, the communication means including a transport entity for providing transport services, and a security entity logically positioned above the transport entity and operative to set up secure communication sessions with peer security entities in other systems for the passing of application messages in protocol data units (PDUs) exchanged between the security entities, the security entity including a tunnelling mechanism for establishing a tunnel through an access-controlling intermediate system whereby to enable the local application entity to exchange application messages securely with a remote application entity on another system reachable via said intermediate system, the tunnelling mechanism establishing this tunnel by first setting up a first security session with said intermediate system and then a nested, second, security session with said another system with PDUs associated with the second session being encapsulated within PDUs associated with the first session and being extracted by the intermediate system for sending to said another system;

  • and each PDU having a message-type field by which the security entity in the intermediate system can determine whether a PDU it receives encapsulates a PDU to be extracted and sent on.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×