×

Packet filter policy verification system

  • US 7,039,053 B1
  • Filed: 02/28/2001
  • Issued: 05/02/2006
  • Est. Priority Date: 02/28/2001
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method for validating an n-dimensional policy table in a router, the router having at least two interfaces, the policy table having at least two policy rules, and each policy rule in the policy table having at least one dimension, the method comprising:

  • making a first determination whether every dimension of any first policy rule intersects any subsequent policy rule in every dimension of the subsequent policy rule; and

    if the first determination is that none of the policy rules intersect each other in every dimension, then producing an output signal indicating that the policy table is valid andif the first determination is that any first policy rule of the policy table intersects any subsequent policy rule in every dimension, thereby defining a first and a second intersecting policy rule, making a second determination whether one of said first and second intersecting policy rules is a subset of the other of the said first and second intersecting policy rules.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×