×

Method and apparatus for dynamically securing voice and other delay-sensitive network traffic

  • US 7,366,894 B1
  • Filed: 11/27/2002
  • Issued: 04/29/2008
  • Est. Priority Date: 06/25/2002
  • Status: Active Grant
First Claim
Patent Images

1. An apparatus for dynamically securing delay-sensitive network traffic, comprising:

  • means for receiving, at one or more of a hub router and a spoke router of a packet switched network, a request from a source device for secure network traffic between the source device having a private network address at a source node and a destination device having a private network address at a destination node;

    means for obtaining from a route server the private network address of the destination device at the destination node, based on signaling information associated with the request;

    means for obtaining, from at least one of a next hop server, a cache at the source node, a call setup signal and a nonstandard data field associated with a call setup confirm signal, a public network address of the destination node associated with the private network address;

    means for creating, in response to the request, a virtual circuit between the source node and the destination node based on the public network address of the destination node associated with the private network address;

    means for encrypting network traffic for transporting at least from the source node to the destination node over the virtual circuit;

    wherein the obtaining means, creating means and encrypting means are in one or more of the routers of the packet switched network;

    wherein the virtual circuit comprises a component of a full mesh virtual private network (VPN), wherein the encrypting means conform to the Internet Protocol Security (IPsec) protocol and wherein the delay-sensitive network traffic comprises Voice over Internet Protocol (VoIP), other voice, facsimile, multimedia, teleconferencing or videoconferencing related traffic;

    wherein;

    the packet switched network comprises at least one hub router and a plurality of spoke routers that are each communicatively coupled with the at least one hub router with a tunnel configured with the VPN there between;

    the tunnel between the at least one hub router and each of the spoke routers is in a continuously up condition; and

    a source spoke router is configured to dynamically determine, using a next hop routing protocol (NHRP), a destination address for the target spoke router, in response to a request from one of the spoke routers, which functions as the source spoke router, to transmit a packet to a subnet behind another of the spoke routers, which functions as a target spoke router, the at least one hub router functions as an NHRP server and handles the request for the source spoke router; and

    the source spoke router and the target spoke router are configured to;

    dynamically configure a VPN tunnel between each other, which complies with the IPsec protocol, via a multi-point Generic Routing Encapsulation (mGRE) interface; and

    transfer data directly between each other.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×