Security association reuse for multiple connections
Abstract
In some embodiments, a method receives address information for two or more paths between a first network device and a second network device. A connection is established between the first network device and the second network device to determine one or more security keys for the first network device and the second network device. Then, the method installs the one or more security keys with the address information for the two or more paths. The one or more security keys are used to provide a security service on one or more packets that are sent or received between the first network device and the second network device using the address information for the two or more paths.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method to establish a secure connection between network devices, the method comprising:
identifying, by an agent of a first networking device, a plurality of data paths between the first networking device and a second networking device, wherein a given data path connects an interface of the first device with an interface of the second networking device, each interface being uniquely identified by an associated Internet Protocol (IP) address; establishing, by the agent, a secure connection, wherein establishing the secure connection includes: establishing a connection between the first and second network devices using a first virtual IP address of the first network device and a second virtual IP address of the second network device; negotiating one or more security keys to establish the secure connection, the one or more security keys including at least an encryption key and a decryption key; generating an inbound security association and an outbound security association for each of the plurality of data paths, a given inbound security association including IP addresses associated with the given data path and the decryption key, a given outbound. security association including IP addresses associated with the given data path and the encryption key; and installing the inbound security association and outbound security association of each of the plurality of data paths in a data plane of the first networking device.
2 . The method of claim 1 , wherein a given inbound security association decrypts one or more packets that are received by the first network device from the second network device in a given path, wherein a given outbound security association encrypts one or more packets that are sent by the first network device to the second network device in the given path.
3 . The method of claim 1 , wherein each of the plurality of data paths use the inbound security association and the outbound security association.
4 . The method of claim 1 , wherein when one of the plurality of data paths becomes unoperational, renegotiation of the one or more security keys is not needed when the one of the plurality of data paths is operational.
5 . A method comprising:
receiving, by a computing device, address information for two or more paths between a first network device and a second network device; establishing, by the computing device, a connection between the first network device and the second network device to determine one or more security keys for the first network device and the second network device; and installing, by the computing device, the one or more security keys with the address information for the two or more paths, wherein the one or more security keys are used to provide a security service on one or more packets that are sent or received between the first network device and the second network device using the address information for the two or more paths.
6 . The method of claim 5 , wherein receiving the address information for two or more paths between the first network device and the second network device comprises:
receiving a first set of addresses for a first set of interfaces on the first network device and a second set of addresses for a second set of interfaces on the second network device; and generating the two or more paths based on connections between the first set of addresses for the first set of interfaces and the second set of addresses for the second set of interfaces.
7 . The method of claim 5 , wherein when one of the two or more paths becomes unoperational, renegotiation of the one or more security keys is not needed when one of the two or more paths is operational.
8 . The method of claim 5 , wherein:
the two or more paths are between a first set of addresses for the first network device and a second set of addresses for the second network device, and a third set of addresses that are not part of the two or more paths are used to determine the one or more security keys.
9 . The method of claim 8 , wherein:
when determining one or more new security keys, using the third set of addresses to determine the one or more new security keys for the first network device and the second network device.
10 . The method of claim 8 , wherein:
the third set of addresses are private addresses, the third set of addresses are changed to a fourth set of addresses, wherein the fourth set of addresses are used to establish the connection, and the second network device converts the fourth set of addresses to the third set of addresses to determine one or more security keys for the first network device and the second network device.Join the waitlist — get patent alerts
Track US2022150700A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.