US2023099263A1PendingUtilityA1

Secure link aggregation

Assignee: FORTINET INCPriority: Sep 30, 2020Filed: Dec 2, 2022Published: Mar 30, 2023
Est. expirySep 30, 2040(~14.2 yrs left)· nominal 20-yr term from priority
H04L 41/0893H04W 12/069H04W 80/02Y02D30/00H04L 63/0428H04L 41/12H04W 76/10H04L 43/0876H04W 76/15H04W 76/14H04W 48/16H04W 12/037H04L 63/0823
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are for securing link aggregation are provided. According to an embodiment, a network device in a secure domain discovers device information associated with a peer network device in an untrusted domain that is connected through a first link directly connecting a first interface of the network device to a first interface of the peer network device, and authenticates the peer while allowing at least some network traffic to continue to be transmitted through the first interface. The network device establishes a secure session between the network device and the peer over the first link when the peer network device is successfully authenticated. The network device then allows the first link to operate as part of a single aggregated logical link, including a second link coupling a second interface of the network device to a second interface of the peer network device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 discovering, by a processing resource of a network device within a secure domain, device information associated with a peer network device in an untrusted domain, wherein an interface of the network device is directly connected to an interface of the peer network device;   while allowing at least some network traffic to be transmitted through the interface of the network device, authenticating, by the processing resource, the peer network device; and   when the peer network device is successfully authenticated, establishing, by the processing resource, a secure session between the network device and the peer network device over a first link coupling the interface of the network device to the interface of the peer network device.   
     
     
         2 . The method of  claim 1 , wherein the interface is a first interface, the method further comprising:
 allowing, by the processing resource, the first link to operate as part of a single aggregated logical link including a second link coupling a second interface of the network device to a second interface of the peer network device.   
     
     
         3 . The method of  claim 1 , wherein the discovering is done via a layer 2 neighbor discovery protocol that comprises Link Layer Discovery Protocol (LLDP). 
     
     
         4 . The method of  claim 1 , wherein the device information includes a hostname of the peer network device, an address of the peer network device, or a capability of the peer network device. 
     
     
         5 . The method of  claim 1 , wherein said authenticating comprises:
 establishing, by the processing resource, a Datagram Transport Layer Security (DTLS) connection between the network device and the peer network device via the first link;   receiving, by the processing resource, a signed certificate from the peer network device via the DTLS connection; and   confirming, by the processing resource, the signed certificate is from a trusted certificate authority.   
     
     
         6 . The method of  claim 1 , wherein said authenticating comprises:
 determining whether the peer network device is known to the network device as a result of having a previously validated peering session with the network device via the second link.   
     
     
         7 . The method of  claim 6 , wherein information indicative of the previously validated peering session is maintained within a database of the network device. 
     
     
         8 . The method of  claim 1 , wherein said authenticating comprises subjecting the peer network device to a challenge-response authentication mechanism. 
     
     
         9 . The method of  claim 1 , further comprising selectively encrypting, by the processing resource, packets transmitted on the single aggregated logical link. 
     
     
         10 . A network device comprising:
 a processing resource; and   a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to:
 discover via a layer 2 neighbor discovery protocol device information associated with a peer network device in an untrusted domain, wherein a first interface of the network device is directly connected to a first interface of the peer network device; 
 while allowing at least some network traffic to continue to be transmitted through the first interface, authenticate the peer network device; and 
 when the peer network device is successfully authenticated, establish a secure session between the network device and the peer network device over a first link coupling the first interface of the network device to the first interface of the peer network device. 
   
     
     
         11 . The network device of  claim 10 , allow the first link to operate as part of a single aggregated logical link including a second link coupling a second interface of the network device to a second interface of the peer network device. 
     
     
         12 . The network device of  claim 10 , wherein the layer 2 neighbor discovery protocol comprises Link Layer Discovery Protocol (LLDP). 
     
     
         13 . The network device of  claim 10 , wherein the device information includes a hostname of the peer network device, an address of the peer network device, or a capability of the peer network device. 
     
     
         14 . The network device of  claim 10 , wherein the peer network device is authenticated by:
 establishing a Datagram Transport Layer Security (DTLS) connection between the network device and the peer network device via the first link;   receiving a signed certificate from the peer network device via the DTLS connection; and   confirming the signed certificate is from a trusted certificate authority.   
     
     
         15 . The network device of  claim 10 , wherein the peer network device is authenticated by determining whether the peer network device is known to the network device as a result of having a previously validated peering session with the network device via the second link. 
     
     
         16 . The network device of  claim 15 , wherein information indicative of the previously validated peering session is maintained within a database of the network device. 
     
     
         17 . The network device of  claim 10 , wherein the peer network device is authenticated by subjecting the peer network device to a challenge-response authentication mechanism. 
     
     
         18 . The network device of  claim 10 , wherein the instructions further cause the processing resource to selectively encrypt packets transmitted on the single aggregated logical link. 
     
     
         19 . The network device of  claim 18 , wherein selective encryption of the packets involves encrypting control traffic and not encrypting user traffic. 
     
     
         20 . A non-transitory computer-readable medium having stored therein instructions that when executed by a processing resource cause the processing resource to:
 discover via a layer 2 neighbor discovery protocol device information associated with a peer network device in an untrusted domain, wherein a first interface of the network device is directly connected to a first interface of the peer network device;   while allowing at least some network traffic to continue to be transmitted through the first interface, authenticate the peer network device;   when the peer network device is successfully authenticated, establish a secure session between the network device and the peer network device over a first link coupling the first interface of the network device to the first interface of the peer network device; and   allow the first link to operate as part of a single aggregated logical link including a second link coupling a second interface of the network device to a second interface of the peer network device.

Join the waitlist — get patent alerts

Track US2023099263A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.