US2022150700A1PendingUtilityA1

Security association reuse for multiple connections

Assignee: ARISTA NETWORKS INCPriority: Oct 29, 2019Filed: Oct 6, 2021Published: May 12, 2022
Est. expiryOct 29, 2039(~13.3 yrs left)· nominal 20-yr term from priority
H04L 63/0428H04L 63/18H04L 63/20H04L 63/205H04L 63/061H04W 12/08H04L 63/0272H04W 12/0433
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In some embodiments, a method receives address information for two or more paths between a first network device and a second network device. A connection is established between the first network device and the second network device to determine one or more security keys for the first network device and the second network device. Then, the method installs the one or more security keys with the address information for the two or more paths. The one or more security keys are used to provide a security service on one or more packets that are sent or received between the first network device and the second network device using the address information for the two or more paths.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method to establish a secure connection between network devices, the method comprising:
 identifying, by an agent of a first networking device, a plurality of data paths between the first networking device and a second networking device, wherein a given data path connects an interface of the first device with an interface of the second networking device, each interface being uniquely identified by an associated Internet Protocol (IP) address;   establishing, by the agent, a secure connection, wherein establishing the secure connection includes:   establishing a connection between the first and second network devices using a first virtual IP address of the first network device and a second virtual IP address of the second network device;   negotiating one or more security keys to establish the secure connection, the one or more security keys including at least an encryption key and a decryption key;   generating an inbound security association and an outbound security association for each of the plurality of data paths, a given inbound security association including IP addresses associated with the given data path and the decryption key, a given outbound. security association including IP addresses associated with the given data path and the encryption key; and   installing the inbound security association and outbound security association of each of the plurality of data paths in a data plane of the first networking device.   
     
     
         2 . The method of  claim 1 , wherein a given inbound security association decrypts one or more packets that are received by the first network device from the second network device in a given path, wherein a given outbound security association encrypts one or more packets that are sent by the first network device to the second network device in the given path. 
     
     
         3 . The method of  claim 1 , wherein each of the plurality of data paths use the inbound security association and the outbound security association. 
     
     
         4 . The method of  claim 1 , wherein when one of the plurality of data paths becomes unoperational, renegotiation of the one or more security keys is not needed when the one of the plurality of data paths is operational. 
     
     
         5 . A method comprising:
 receiving, by a computing device, address information for two or more paths between a first network device and a second network device;   establishing, by the computing device, a connection between the first network device and the second network device to determine one or more security keys for the first network device and the second network device; and   installing, by the computing device, the one or more security keys with the address information for the two or more paths, wherein the one or more security keys are used to provide a security service on one or more packets that are sent or received between the first network device and the second network device using the address information for the two or more paths.   
     
     
         6 . The method of  claim 5 , wherein receiving the address information for two or more paths between the first network device and the second network device comprises:
 receiving a first set of addresses for a first set of interfaces on the first network device and a second set of addresses for a second set of interfaces on the second network device; and   generating the two or more paths based on connections between the first set of addresses for the first set of interfaces and the second set of addresses for the second set of interfaces.   
     
     
         7 . The method of  claim 5 , wherein when one of the two or more paths becomes unoperational, renegotiation of the one or more security keys is not needed when one of the two or more paths is operational. 
     
     
         8 . The method of  claim 5 , wherein:
 the two or more paths are between a first set of addresses for the first network device and a second set of addresses for the second network device, and   a third set of addresses that are not part of the two or more paths are used to determine the one or more security keys.   
     
     
         9 . The method of  claim 8 , wherein:
 when determining one or more new security keys, using the third set of addresses to determine the one or more new security keys for the first network device and the second network device.   
     
     
         10 . The method of  claim 8 , wherein:
 the third set of addresses are private addresses,   the third set of addresses are changed to a fourth set of addresses, wherein the fourth set of addresses are used to establish the connection, and   the second network device converts the fourth set of addresses to the third set of addresses to determine one or more security keys for the first network device and the second network device.

Join the waitlist — get patent alerts

Track US2022150700A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.