Patents Assigned to SSH Communications Security Ltd.
  • Publication number: 20100138560
    Abstract: This invention provides a method for providing network security services, such as those provided by the IPSEC protocol, through network address translation (NAT). The method is based on determining the transformations that occur on a packet and compensating for the transformations. Because only TCP and UDP protocols work through NATs, the IPSEC AH/ESP packets are encapsulated into UDP packets for transport. Special operations are performed to allow reliable communications in such environments.
    Type: Application
    Filed: January 8, 2010
    Publication date: June 3, 2010
    Applicant: SSH COMMUNICATIONS SECURITY LTD.
    Inventors: Tero Kivinen, Tatu Ylonen
  • Publication number: 20060256815
    Abstract: This invention provides a method for providing network security services, such as those provided by the IPSEC protocol, through network address translation (NAT). The method is based on determining the transformations that occur on a packet and compensating for the transformations. Because only TCP and UDP protocols work through NATs, the IPSEC AH/ESP packets are encapsulated into UDP packets for transport. Special operations are performed to allow reliable communications in such environments.
    Type: Application
    Filed: May 12, 2005
    Publication date: November 16, 2006
    Applicant: SSH Communications Security Ltd
    Inventors: Tero Kivinen, Tatu Ylonen
  • Patent number: 6957346
    Abstract: This invention provides a method for providing network security services, such as those provided by the IPSEC protocol, through network address translation (NAT). The method is based on determining the transformations that occur on a packet and compensating for the transformations. Because only TCP and UDP protocols work through NATs, the IPSEC AH/ESP packets are encapsulated into UDP packets for transport. Special operations are performed to allow reliable communications in such environments.
    Type: Grant
    Filed: June 15, 1999
    Date of Patent: October 18, 2005
    Assignee: SSH Communications Security Ltd.
    Inventors: Tero Kivinen, Tatu Ylonen
  • Patent number: 6795917
    Abstract: For achieving packet authentication according to an applicable security policy between a sending node (903) and a receiving node (902) in a network, the following steps are taken: the transformations occurring to a packet en route between the sending node and the receiving node are discovered dynamically (1003, 1004), the discovered transformations are checked (1004) to be acceptable based on the applicable security policy, and the dynamically discovered, acceptable transformations are compensated for (1004, 1006) before authenticating packets transmitted from the sending node to the receiving node.
    Type: Grant
    Filed: October 21, 1999
    Date of Patent: September 21, 2004
    Assignee: SSH Communications Security LTD
    Inventor: Tatu Ylonen
  • Patent number: 6782474
    Abstract: A network device (100, 300) is connected to a network (102) having also a management station (107) connected thereto. The method for configuring the network device comprises the steps of transmitting from the management station a configuration packet to the network device (201), authenticating at the network device the management station as the genuine transmitter of the configuration packet (202) and decoding the configuration parameters contained in said configuration packet and storing them as the configuration parameters of the network device (203).
    Type: Grant
    Filed: June 4, 1999
    Date of Patent: August 24, 2004
    Assignee: SSH Communication Security Ltd.
    Inventor: Tatu Ylonen
  • Patent number: 6678734
    Abstract: A method is provided for intercepting network packets in a computer system, where a number of functions are used to communicate network packets between a network adapter and a protocols entity. A first network adapter and a first protocols entity installed in the computer system are identified. A set of replacement functions is provided within a packet interceptor module. At least one function used for transmitting network packets from said first protocols entity to said first network adapter is hooked into a first replacement function. At least one function used for transmitting network packets from said first network adapter to said first protocols entity is hooked into a second replacement function. At least one function used for receiving information about the status of the network interface implemented by said first network adapter is hooked into a third replacement function.
    Type: Grant
    Filed: November 13, 1999
    Date of Patent: January 13, 2004
    Assignee: SSH Communications Security Ltd.
    Inventors: Niko Haatainen, Tero Kivinen, Jussi Kukkonen, Tatu Ylönen
  • Patent number: 6438612
    Abstract: Data packets are communicated between a transmitting virtual router in a transmitting computer device and a receiving virtual router in a receiving computer device. A security association is established for the secure transmission of data packets between the transmitting computer device and the receiving computer device. The transmitting virtual router and the receiving virtual router are identified within said security association. In the transmitting computer device, the security association for processing a data packet coming from the transmitting virtual router is selected on the basis of the identification of the transmitting virtual router within the security association. In the receiving computer device, the security association for processing a data packet coming from the transmitting computer device is selected on the basis of values contained within the data packet.
    Type: Grant
    Filed: September 11, 1998
    Date of Patent: August 20, 2002
    Assignee: SSH Communications Security, Ltd.
    Inventors: Tatu Ylonen, Tero Kivinen
  • Patent number: 6253321
    Abstract: A data processing system implements a security protocol based on processing data in packets. The data processing system comprises processing packets for storing filter code and processing data packets according to stored filter code, and a policy managing function for generating filter code and communicating generated filter code for packet processing. The packet processing function is arranged to examine, whether the stored filter code is applicable for processing a certain packet. If the stored filter code is not applicable for the processing of a packet, the packet is communicated to the policy managing function, which generates filter code applicable for the processing of the packet and communicates the generated filter code for packet processing.
    Type: Grant
    Filed: June 19, 1998
    Date of Patent: June 26, 2001
    Assignee: SSH Communications Security Ltd.
    Inventors: Pekka Nikander, Tatu Ylonen