encrypted tunnel
163550·updated Aug 30, 2026A network boundary protection mechanism — in the same class as firewalls, gateways, and routers — that encapsulates and cryptographically secures data packets in transit across an untrusted or shared network, so that the payload is unintelligible to any party outside the tunnel endpoints. In NIST SP 800-53 (SC-7), encrypted tunnels are listed alongside gateways, routers, firewalls, guards, and virtualization systems as forms of managed interface implemented within a security architecture to enforce boundary protection. They are used to transport data securely across non-secure networks such as the Internet, with a common deployment being VPNs where traffic is encrypted in a private network and transmitted across public infrastructure so that the encrypted data remains protected. Operationally, a tunnel transports a packet using encapsulation across a network by wrapping the original packet into a tunnel format and delivering the encapsulated packet using a different protocol, with encryption applied to that payload to ensure confidentiality and integrity end-to-end.
Source
(e.g., encrypted tunnels, routers, gateways, and firewalls) that use rule sets or establishthe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: term of art.
- SC-7: Boundary Protection - CSF Tools
- Partial packet encryption for encrypted tunnels
- Method for establishing IPSEC tunnels
- – SC-7 BOUNDARY PROTECTION | NIST SP 800-53
- 3.13.1: Monitor, control, and protect communications (i.e., information transmitted or received by organizational systems) at the external boundaries and key internal boundaries of organizational syst
- NIST SP 800-171 Series: System and Communications Protection - CampusGuard
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A network security mechanism that combines protocol-level encapsulation with cryptographic encryption to create a logically isolated, confidential communication path between two endpoints—such as hosts, gateways, or routers—over an untrusted or public network. It works by encapsulating packets into a tunneling format and transporting them across the network, with the encapsulated payload protected against interception. Used widely in VPNs and similar constructs, encrypted tunnels transport data securely across non-secure networks such as the Internet, with traffic encrypted at one endpoint and decrypted at the other. In standards practice (e.g., NIST SP 800-77), the concept underpins network-layer security controls—such as IPsec—that protect communications over public networks and provide a secure communication mechanism for data and control information between computers or networks.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- encrypted tunnels
- possessive
- encrypted tunnel's
- pluralpossessive
- encrypted tunnels'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A network boundary protection mechanism — in the same class as firewalls, gateways, and routers — that encapsulates and cryptographically secures data packets in transit across an untrusted or shared network, so that the payload is unintelligible to any party outside the tunnel endpoints. In NIST SP 800-53 (SC-7), encrypted tunnels are listed alongside gateways, routers, firewalls, guards, and virtualization systems as forms of managed interface implemented within a security architecture to enforce boundary protection. They are used to transport data securely across non-secure networks such as the Internet, with a common deployment being VPNs where traffic is encrypted in a private network and transmitted across public infrastructure so that the encrypted data remains protected. Operationally, a tunnel transports a packet using encapsulation across a network by wrapping the original packet into a tunnel format and delivering the encapsulated packet using a different protocol, with encryption applied to that payload to ensure confidentiality and integrity end-to-end.DR-088 backfill from the noun definition column