FACILITATING HITLESS SECURITY KEY ROLLOVER USING DATA PLANE FEEDBACK

    公开(公告)号:US20220094534A1

    公开(公告)日:2022-03-24

    申请号:US17457951

    申请日:2021-12-07

    Abstract: A first network device may install a receiving key for decrypting traffic on protocol hardware associated with a data plane of the first network device. The first network device may receive, from the data plane, a first notification indicating that the receiving key is installed on the protocol hardware and may provide, to a second network device, a first message identifying the receiving key. The first network device may receive, from the second network device, an acknowledgment message indicating that the receiving key is installed on the second network device and may install a transmission key for encrypting traffic on the protocol hardware. The first network device may receive, from the data plane, a second notification indicating that the transmission key is installed on the protocol hardware and may provide, to the second network device, a second message identifying the transmission key.

    FACILITATING HITLESS SECURITY KEY ROLLOVER USING DATA PLANE FEEDBACK

    公开(公告)号:US20210351921A1

    公开(公告)日:2021-11-11

    申请号:US16907685

    申请日:2020-06-22

    Abstract: A first network device may install a receiving key for decrypting traffic on protocol hardware associated with a data plane of the first network device. The first network device may receive, from the data plane, a first notification indicating that the receiving key is installed on the protocol hardware and may provide, to a second network device, a first message identifying the receiving key. The first network device may receive, from the second network device, an acknowledgment message indicating that the receiving key is installed on the second network device and may install a transmission key for encrypting traffic on the protocol hardware. The first network device may receive, from the data plane, a second notification indicating that the transmission key is installed on the protocol hardware and may provide, to the second network device, a second message identifying the transmission key.

    DELETING STALE OR UNUSED KEYS TO GUARANTEE ZERO PACKET LOSS

    公开(公告)号:US20230361992A1

    公开(公告)日:2023-11-09

    申请号:US17662481

    申请日:2022-05-09

    Inventor: Sumeet MUNDRA

    CPC classification number: H04L9/0844 H04L63/0428 H04L9/0819

    Abstract: A first network device may install a new receive key on a data plane of the first network device, and may provide, to a second network device, a first request to install the new receive key. The first network device may receive a first indication that the new receive key is installed by the second network device, and may install a new transmit key on the data plane of the first network device based on the first indication. The first network device may provide, to the second network device, a second request to install the new transmit key, and may receive a second indication that the new transmit key is installed and that an old receive key is deleted by the second network device. The first network device may delete the old receive key from the data plane of the first network device based on the second indication.

Patent Agency Ranking