-
公开(公告)号:US20240223544A1
公开(公告)日:2024-07-04
申请号:US18147369
申请日:2022-12-28
Applicant: Cisco Technology, Inc.
Inventor: Govind Prasad Sharma , Prabhu Balakannan , Sivakumar Kailas
CPC classification number: H04L63/0478 , H04L12/4633
Abstract: Techniques for generating a per-packet initialization vector for high bandwidth encryption engines in a multipathing IP network are described herein. In examples, a network switch of a first datacenter site may receive a data packet to be sent to a second datacenter site over a network. The data packet may be encrypted according to a virtual extensible LAN (VxLAN) protocol and to be transmitted in a VxLAN tunnel created for the first datacenter site and the second datacenter site. An encryption engine implemented at the network switch may generate an initialization vector (IV) for the data packet based on a packet number (PN) associated with the data packet. The encryption engine may use the IV and information associated with a security association (SA) assigned to the packet to encrypt the data packet. In some examples, a full 64-bit PN may be used to compute the IV for the data packet.
-
12.
公开(公告)号:US11757935B2
公开(公告)日:2023-09-12
申请号:US17736748
申请日:2022-05-04
Applicant: Cisco Technology, Inc.
Inventor: Govind Prasad Sharma , Eshwar Rao Yedavalli , Mohammed Javed Asghar , Ashwath Kumar Chandrasekaran , Swapnil Mankar , Umamaheswararao Karyampudi
IPC: H04L9/40 , G06F9/455 , H04L61/103 , H04L101/622
CPC classification number: H04L63/1483 , G06F9/45558 , H04L61/103 , H04L63/10 , G06F2009/4557 , G06F2009/45595 , H04L2101/622
Abstract: Methods to secure against IP address thefts by rogue devices in a virtualized datacenter are provided. Rogue devices are detected and distinguished from a migration of an endpoint in a virtualized datacenter. A first hop network element in a one or more network fabrics intercepts a request that includes an identity of an endpoint and performs a local lookup for the endpoint entity identifier. Based on the lookup not finding the endpoint entity identifier, the first hop network element broadcasts a message such as a remote media access address (MAC) query to other network elements in the one or more network fabrics. Based on the received response, which may include an IP address associated with the MAC address, the first hop network element performs a theft validation process to determine whether the request originated from a migrated endpoint or a rogue device.
-
13.
公开(公告)号:US10778662B2
公开(公告)日:2020-09-15
申请号:US16166973
申请日:2018-10-22
Applicant: Cisco Technology, Inc.
Inventor: Govind Prasad Sharma , Javed Asghar , Prabhu Balakannan , Sridhar Vallepalli
Abstract: A Software-Defined Networking (SDN)-based “upstream” approach is a controller-based solution that provides secure key distribution and management for multi-site data centers. The approach uses an SDN Multi-Site Controller (MSC) that acts as an intermediary between SDN controllers at sites in a multi-site data center and manages the distribution of keys to sites. The approach is not dependent upon any particular routing protocol, such as the Border Gateway Protocol (BGP), and is well suited for multicast stream encryption by allowing the same key to be used for all replicated packets sent to downstream sites from an upstream source site. The approach distributes keys in a secure manner, ensures that data transferred between sites is done in a secure manner, and supports re-keying with error handling.
-
公开(公告)号:US20140105029A1
公开(公告)日:2014-04-17
申请号:US13653129
申请日:2012-10-16
Applicant: CISCO TECHNOLOGY, INC.
Inventor: Vipin Jain , Govind Prasad Sharma , Dhananjaya Rao , Herman Levenson
IPC: H04L12/26
CPC classification number: H04L43/0811 , H04L41/12 , H04L43/10 , Y02D30/30
Abstract: In one embodiment, a method at a network device includes receiving a link layer advertisement, comparing information in the link layer advertisement with connectivity information stored at the network device, and based on the comparison, determining if there is a cabling error between the network device and a link peer transmitting the link layer advertisement. An apparatus and logic are also disclosed herein.
Abstract translation: 在一个实施例中,网络设备的方法包括接收链路层通告,将链路层广告中的信息与存储在网络设备中的连接性信息进行比较,并且基于该比较,确定网络设备之间是否存在布线错误 以及发送链路层广告的链路对等体。 本文还公开了一种装置和逻辑。
-
-
-