encrypted tunnel
A network boundary protection mechanism — in the same class as firewalls, gateways, and routers — that encapsulates and cryptographically secures data packets in transit across an untrusted or shared network, so that the payload is unintelligible to any party outside the tunnel endpoints. In NIST SP 800-53 (SC-7), encrypted tunnels are listed alongside gateways, routers, firewalls, guards, and virtualization systems as forms of managed interface implemented within a security architecture to enforce boundary protection. They are used to transport data securely across non-secure networks such as the Internet, with a common deployment being VPNs where traffic is encrypted in a private network and transmitted across public infrastructure so that the encrypted data remains protected. Operationally, a tunnel transports a packet using encapsulation across a network by wrapping the original packet into a tunnel format and delivering the encapsulated packet using a different protocol, with encryption applied to that payload to ensure confidentiality and integrity end-to-end.
Framework senses
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A network boundary protection mechanism — in the same class as firewalls, gateways, and routers — that encapsulates and cryptographically secures data packets in transit across an untrusted or shared network, so that the payload is unintelligible to any party outside the tunnel endpoints. In NIST SP 800-53 (SC-7), encrypted tunnels are listed alongside gateways, routers, firewalls, guards, and virtualization systems as forms of managed interface implemented within a security architecture to enforce boundary protection. They are used to transport data securely across non-secure networks such as the Internet, with a common deployment being VPNs where traffic is encrypted in a private network and transmitted across public infrastructure so that the encrypted data remains protected. Operationally, a tunnel transports a packet using encapsulation across a network by wrapping the original packet into a tunnel format and delivering the encapsulated packet using a different protocol, with encryption applied to that payload to ensure confidentiality and integrity end-to-end.DR-088 backfill from the noun definition column