×

System and method to support networking functions for mobile hosts that access multiple networks

  • US 7,929,528 B2
  • Filed: 09/30/2008
  • Issued: 04/19/2011
  • Est. Priority Date: 12/31/2002
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method of routing packets between a first network access device and a second network access device, the method being performed at a secure mobility gateway having an internet interface and an intranet interface, comprising:

  • receiving an encapsulated internet protocol-in-user datagram protocol packet having an internet protocol packet sent from the first network access device to the second network access device through the internet interface, the internet protocol packet being encrypted;

    locating a mobile status record for the first network access device;

    verifying the encapsulated internet protocol-in-user datagram protocol packet based on a parameter contained in the internet protocol-in-user datagram protocol packet and, if the parameter is valid, thenupdating the mobile status record by replacing a current care-of internet protocol address in the mobile status record with an outer source internet protocol address of the encapsulated internet protocol-in-user datagram protocol packet, replacing a current interface in the mobile status record with the internet interface if the current interface is the intranet interface for the first network access device, and replacing a packet sequence number for the first network access device in the mobile status record with the packet sequence number of the encapsulated internet protocol-in-user datagram protocol packet for the first network access device, if the packet sequence number of the encapsulated internet protocol-in-user datagram protocol packet is greater than a current packet sequence number stored in the mobile status record;

    decapsulating the encapsulated internet protocol-in-user datagram protocol packet;

    decrypting the internet protocol packet and;

    sending the internet protocol packet that is unencrypted to the second network access device through the intranet interface, as if the first network access device is deployed on a subnet of an intranet that is represented by the intranet interface, wherein the mobile status record is located using a security association index number in the encapsulated internet protocol-in-user datagram protocol packet.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×