US2017180123A1PendingUtilityA1

Discovery of secure network enclaves

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Jun 11, 2009Filed: Mar 8, 2017Published: Jun 22, 2017
Est. expiryJun 11, 2029(~2.9 yrs left)· nominal 20-yr term from priority
H04L 63/164H04L 63/0464H04L 9/0861H04L 9/0836H04L 9/32H04L 63/064H04L 63/061H04L 63/0272H04L 63/0281H04L 9/14H04L 2463/061
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A hierarchical key generation and distribution mechanism for a computer system in which devices are organized into secure enclaves. The mechanism enables network access to be tailored to approximate minimum needed privileges for each device. At the lowest level of the hierarchy, keys are used to form security associations between devices. Keys at each level of the hierarchy are generated from keys at a higher level of the hierarchy and key derivation information. Key derivation information is readily ascertainable, either from identifiers for devices or from within messages, supporting hardware offload of cryptographic functions. Because keys may be generated based on the enclaves in which the hosts participating in a security association are located, the system includes a mechanism by which devices can discover the enclave in which they are located.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A device for providing secure communications, comprising:
 a memory and a processor that are respectively configured to store and execute instructions, including instructions for causing the device to:
 receive a control packet during an exchange, between the device and a second device, to establish a security association with the second device; 
 determine an identity of an enclave in which the second device is located based at least on two or more markers indicative of enclaves associated with intermediary devices that processed the control packet; 
 determine an identity of another enclave; and 
 employ the determined identity of the enclave to establish a security association with the second device, including:
 selecting a key based at least on the determined identity of the enclave and the determined identity of the other enclave. 
 
   
     
     
         2 . The device of  claim 1 , wherein the instructions are also for causing the device to:
 determine the identity of the other enclave based at least on the two or more markers.   
     
     
         3 . The device of  claim 2 , wherein the device is located in the other enclave. 
     
     
         4 . The device of  claim 1 , wherein the instructions for causing the device to employ the determined identity to establish a security association also cause the device to:
 select a pair-wise enclave key from a plurality of pair-wise enclave keys based at least on the determined identity of the enclave.   
     
     
         5 . The device of  claim 1 , wherein the control packet is an Internet Key Exchange (IKE) or an AuthIP packet. 
     
     
         6 . The device of  claim 1 , wherein the instructions are also for causing the device to:
 transmit another control packet to the second device, the other control packet including a request for the intermediary devices between the device and the second device to place markers in packets addressed to the device.   
     
     
         7 . The device of  claim 1 , wherein the control packet includes key derivation information for establishing the security association with the second device. 
     
     
         8 . The device of  claim 7 , wherein the key derivation information includes an identifier of a server device that generated a first key and a security parameter index (SPI) that indicates how a second key for the security association with the second device is to be derived from the first key. 
     
     
         9 . A method, comprising:
 receiving a control packet transmitted by a first host device to a second host device as part of an establishment of a security association;   determining whether the control packet contains a request for intermediary devices to place markers in at least some packets addressed to the first host device; and   in response to a determination that the control packet contains the request:
 storing an indication that the first host device is seeking information relating to enclaves between the first host device and the second host device; and 
 inserting a marker that indicates an enclave to which the first host device belongs into at least one other packet addressed to the first host device, wherein the enclave is associated with one or more keys from which a security association between the first host device and the second host device may be generated. 
   
     
     
         10 . The method of  claim 9 , further comprising:
 routing packets between the first host device and the second host device.   
     
     
         11 . The method of  claim 9 , wherein the inserting the marker includes:
 inserting the marker in the at least one other packet, wherein the marker indicates an enclave to which a device performing the method belongs.   
     
     
         12 . The method of  claim 9 , further comprising:
 generating a security association key for the security association between the first host device and the second host device.   
     
     
         13 . The method of  claim 9 , further comprising:
 deriving a security association key for the security association between the first host device and the second host device based on information from at least one of the control packet or the at least one other packet.   
     
     
         14 . A host computing device, comprising:
 a memory and a processor, wherein the memory and the processor are respectively configured to store and execute instructions, including instructions for causing the host computing device to perform operations, the operations including:
 generating a first packet that includes a request for intermediary devices between the host computing device and another host computing device to provide enclave membership information to the host computing device; 
 transmitting the first packet to the other host computing device via at least one intermediary device; 
 receiving a second packet transmitted from the other host computing device, wherein the second packet includes at least one indication of enclave membership, added by the at least one intermediary device; 
 determining an enclave to which the host computing device belongs based at least upon the at least one indication; and 
 establishing a security association with the other host computing device based on the determined enclave. 
   
     
     
         15 . The host computing device of  claim 14 , wherein the operations further comprise:
 selecting a key based at least on the determined enclave, and wherein   establishing the security association with the other host commuting device includes establishing the security association using the selected key.   
     
     
         16 . The host computing device of  claim 15 , wherein selecting the key includes:
 selecting a server key from a set of server keys, where each server key of the set of server keys was derived from a different key of a set of keys.   
     
     
         17 . The host computing device of  claim 14 , wherein the operations further comprise:
 determining an enclave to which the other host computing device belongs based at least upon the at least one indication; and   selecting a key based at least on the determined enclave to which the host computing device belongs and on the determined enclave to which the other host computing device belongs.   
     
     
         18 . The host computing device of  claim 17 , wherein the operations further comprise:
 generating a security association key based at least on the selected server key and key derivation information.   
     
     
         19 . The host computing device of  claim 18 , wherein the key derivation information includes an identifier of a server device that generated the selected key and a security parameter index (SPI) that indicates how to generate the security association key from the selected key. 
     
     
         20 . The host computing device of  claim 14 , wherein the first packet is an Internet Key Exchange (IKE) or an AuthIP control packet.

Join the waitlist — get patent alerts

Track US2017180123A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.