-
公开(公告)号:US20150295899A1
公开(公告)日:2015-10-15
申请号:US14248399
申请日:2014-04-09
Applicant: Cisco Technology, Inc.
Inventor: Lewis Chen , Scott Fluhrer , Warren Scott Wainner , Brian Weis
IPC: H04L29/06
CPC classification number: H04L63/061 , H04L63/0272 , H04L63/0428 , H04L63/06 , H04L63/104
Abstract: Techniques are presented for optimizing secure communications in a network. A first router receives from a second router an encrypted packet with an unknown security association. The first router examines the packet to determine whether the counter value is in a range of predicted counter values. Additionally, a key server is configured to provision routers that are part of a virtual private network. The key server selects a counter value that is part of a security association and calculates a key value. The key server sends the key value together with the security association to enable routers to exchange encrypted packets with each other in the virtual private network using the key value and the security association. The key server increments the counter value to a value within a range of counter values capable of being predicted by the routers.
Abstract translation: 呈现技术来优化网络中的安全通信。 第一路由器从第二路由器接收具有未知安全关联的加密分组。 第一个路由器检查数据包,以确定计数器值是否在预测的计数器值的范围内。 另外,密钥服务器被配置为配置作为虚拟专用网络一部分的路由器。 密钥服务器选择作为安全关联的一部分的计数器值,并计算密钥值。 密钥服务器将密钥值与安全关联一起发送,以使路由器能够使用密钥值和安全关联在虚拟专用网络中彼此交换加密的数据包。 密钥服务器将计数器值递增到可由路由器预测的计数器值范围内的值。