Deterministic distribution of rekeying procedures for a scaling virtual private network (VPN)

    公开(公告)号:US10924274B1

    公开(公告)日:2021-02-16

    申请号:US15895773

    申请日:2018-02-13

    Abstract: A network device may determine that network traffic for a communication session between a first peer device and a second peer device is to be protected using a security protocol suite. The network device may establish, using one or more tunnels, multiple security associations that are to be used to securely provide the network traffic of the communication session over an unsecured medium. The network device may determine a rekey scheduling time for each security association, of the multiple security associations, based on a combination of configuration information and dynamic network device information. The network device may perform, at each rekey scheduling time, a rekeying procedure to rekey each security association of the multiple security associations.

    Deterministic distribution of rekeying procedures for a scaling virtual private network (VPN)

    公开(公告)号:US12289406B2

    公开(公告)日:2025-04-29

    申请号:US17248341

    申请日:2021-01-21

    Abstract: A network device may determine that network traffic for a communication session between a first peer device and a second peer device is to be protected using a security protocol suite. The network device may establish, using one or more tunnels, multiple security associations that are to be used to securely provide the network traffic of the communication session over an unsecured medium. The network device may determine a rekey scheduling time for each security association, of the multiple security associations, based on a combination of configuration information and dynamic network device information. The network device may perform, at each rekey scheduling time, a rekeying procedure to rekey each security association of the multiple security associations.

    Transport batching technique for network communications

    公开(公告)号:US10567284B1

    公开(公告)日:2020-02-18

    申请号:US15816420

    申请日:2017-11-17

    Abstract: A device may include one or more processors to receive, from at least one user device, multiple network packets. The device may identify, from the network packets, a set of individual network packets, the set including at least two of the received network packets that are destined for a particular destination device. The device may generate, based on the set of individual network packets, a batch packet, the batch packet including: the set of individual network packets, data identifying the number of individual network packets included in the set, and offset data for each of the individual network packets included in the batch packet. Based on the batch packet, the device may perform an action.

Patent Agency Ranking