Methods, apparatus, system and computer program are provided for
concealing the identity of a network device transmitting a datagram
having a network layer header. A unique local identifier and broadcast
address are determined in accordance with a next-hop address. A partially
encrypted network layer header is determined by encrypting a plurality of
identifying portions of the network layer header, where one portion of
the network layer header is the unique local identifier. The datagram is
encapsulated with another network layer header whose address is set to
the broadcast address. The encapsulated datagram can be received and
detunneled, and an address of a recipient can be extracted from the
network layer header. The datagram is then admitted into a network
domain.