System and method for selecting internet protocol security tunnels during key exchange

By establishing multiple IPsec tunnels between endpoint devices and selecting high-quality tunnels based on metrics, the static nature of IPsec tunnel selection in existing technologies is solved, enabling optimization of computing resources and dynamic adjustment of communication paths, thereby improving network flexibility and efficiency.

CN116266795BActive Publication Date: 2025-12-16HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210127141.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-12-17
Filing Date
2022-02-11
Publication Date
2025-12-16
Estimated Expiration
2042-02-11

AI Technical Summary

Technical Problem

In existing technologies, endpoint devices lack a dynamic switching mechanism when selecting IPsec tunnels, which makes it impossible to optimize communication paths when the network is interrupted or the quality of service is reduced, resulting in a waste of computing resources.

Method used

By establishing multiple IPsec tunnels between endpoint devices and selecting high-quality tunnels for communication based on negotiated metrics, the tunnel selection is dynamically adjusted using configured payload switching and response mechanisms to optimize communication paths.

Benefits of technology

It achieves savings in computing resources during network outages or service quality degradation, improves the flexibility and efficiency of communication paths, and reduces business losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116266795B_ABST
    Figure CN116266795B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to systems and methods of selecting internet protocol security tunnels during a key exchange. In some implementations, a first endpoint device can assign a first metric to a first internet protocol security (IPsec) tunnel and a second metric to a second IPsec tunnel. The first IPsec tunnel can be a first communication channel for transmitting data between the first endpoint device and a second endpoint device, and the second IPsec tunnel can be a second communication channel for transmitting data between the first endpoint device and the second endpoint device. The first endpoint device can select the first IPsec tunnel or the second IPsec tunnel as a selected IPsec tunnel for transmitting data toward the second endpoint device based on the first metric and the second metric. The first endpoint device can transmit data toward the second endpoint device via the selected IPsec tunnel.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present disclosure relate to Internet Protocol Security. BACKGROUND

[0002] Internet Protocol Security (IPsec) is a suite of protocols for secure Internet Protocol (IP) communications that works by authenticating and encrypting each IP packet of a communication session. IPsec includes protocols for establishing mutual authentication between agents at the start of a session and negotiating cryptographic keys to be used during the session. IPsec can be used to protect data flows between a pair of hosts (host-to-host), between a pair of security gateways (network-to-network), or between a security gateway and a host (network-to-host). IPsec can include an end-to-end security scheme that operates in the Internet layer of the Internet Protocol suite. IPsec can differ from other Internet security systems, such as Transport Layer Security (TLS) and Secure Shell (SSH), in that TLS and SSH can operate in upper layers at the transport layer (TLS) and application layer (SSH). As such, IPsec protects all application traffic over IP networks. SUMMARY

[0003] Some implementations described herein relate to a method. The method can include assigning, by a first endpoint device, a first metric to a first Internet Protocol Security (IPsec) tunnel and a second metric to a second IPsec tunnel, wherein the first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and a second endpoint device and the second IPsec tunnel is a second communication channel for transmitting data between the first endpoint device and the second endpoint device. The method can include selecting, by the first endpoint device, the first IPsec tunnel or the second IPsec tunnel as a selected IPsec tunnel for transmitting data toward the second endpoint device based on the first metric and the second metric. The method can include transmitting, by the first endpoint device, data toward the second endpoint device via the selected IPsec tunnel.

[0004] Some implementations described herein relate to a first endpoint device. The first endpoint device can include one or more memories and one or more processors. The one or more processors can be configured to assign a first metric to a first IPsec tunnel and a second metric to a second IPsec tunnel, where the first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and a second endpoint device, and the second IPsec tunnel is a second communication channel for transmitting data between the first endpoint device and the second endpoint device. The one or more processors can be configured to select the first IPsec tunnel or the second IPsec tunnel as a selected IPsec tunnel for transmitting data toward the second endpoint device based on comparing the first metric and the second metric. The one or more processors can be configured to transmit data toward the second endpoint device via the selected IPsec tunnel.

[0005] Some implementations described herein relate to a non-transitory computer- readable medium storing a set of instructions for a first endpoint device. The set of instructions, when executed by one or more processors of the first endpoint device, can cause the first endpoint device to assign a first metric to a first IPsec tunnel and a second metric to a second IPsec tunnel, where the first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and a second endpoint device, and the second IPsec tunnel is a second communication channel for transmitting data between the first endpoint device and the second endpoint device. The set of instructions, when executed by the one or more processors of the first endpoint device, can cause the first endpoint device to select the first IPsec tunnel or the second IPsec tunnel as a selected IPsec tunnel for transmitting data toward the second endpoint device based on comparing a first value of the first metric and a second value of the second metric. The set of instructions, when executed by the one or more processors of the first endpoint device, can cause the first endpoint device to transmit data toward the second endpoint device via the selected IPsec tunnel. BRIEF DESCRIPTION OF DRAWINGS

[0006] Figures 1A to 1F is a diagram of example implementations described herein.

[0007] Figure 2 is a diagram of an example environment in which systems and / or methods described herein can be implemented.

[0008] Figure 3 is a diagram of example components of one or more devices of Figure 2

[0009] Figure 4 is a flow diagram of an example process related to selecting an Internet Protocol Security (IPsec) tunnel during a metric-based Internet Key Exchange (IKE). ​DETAILED DESCRIPTION

[0010] The following detailed description of example implementations refers to the accompanying drawings. The same reference numbers in different drawings can identify the same or similar elements.

[0011] In some cases, an entity (e.g., a business, a company, or an individual, among other examples) uses multiple Internet Service Providers (ISPs) to maintain connectivity between different locations (e.g., to maintain connectivity between offices located in different geographic regions).

[0012] Each ISP can use a different network path or a different autonomous system to maintain connectivity between the different locations. In some cases, the entity can use Internet Protocol Security (IPsec) for secure Internet Protocol (IP) communications between the different locations. For example, the entity can utilize an Internet Key Exchange (IKE) process to establish a first IPsec tunnel between endpoint devices (e.g., user devices, server devices, or network devices, among other examples) at a first location and an endpoint device at a second location via a network of a first ISP, and to establish a second IPsec tunnel between the endpoint devices at the first location and the endpoint device at the second location via a network of a second ISP. The entity can utilize multiple ISPs to reduce the risk of losing connectivity between the endpoint devices at the first and second locations due to a network disruption (e.g., due to a failure of a network path or an autonomous system). Further, a network disruption can result in a time delay from the time the network disruption is detected until a new IPsec tunnel is established, which can result in a loss of traffic during the time delay. Thus, instead of having a single IPsec tunnel following a single path in the network, the entity can have two or more IPsec tunnels between the endpoint devices. Each IPsec tunnel can follow a different network path and can be supported by a different ISP to achieve redundancy. Thus, each tunnel will follow a different path to reach the peer layer.

[0013] As an example, a network disruption associated with a first ISP can result in a failure of an IPsec tunnel between two endpoint devices via a network of the first ISP. The endpoint devices can detect the network disruption utilizing Dead Peer Detection (DPD) or any other similar method. Based on detecting the network disruption, the endpoint devices can close the IPsec tunnel established via the network of the first ISP and can attempt to renegotiate a new IPsec tunnel. For example, the endpoint devices can use a path to the other endpoint device that bypasses the failed network path or utilizes a network of another ISP to renegotiate the new IPsec tunnel.

[0014] However, endpoint devices may not be able to choose between different IPsec tunnels used to transmit traffic to another endpoint device. For example, if a first IPsec tunnel established via a first ISP's network has better Quality of Service (QoS) than other IPsec tunnels established between endpoint devices, it may be beneficial to consistently choose the first IPsec tunnel for transmitting traffic between endpoint devices until service is interrupted or QoS is degraded. If service is interrupted or QoS is degraded, then the endpoint device should utilize a second IPsec tunnel established via a second ISP's network based on the second IPsec tunnel having better QoS than the remaining IPsec tunnels. However, when using static routing, there is no mechanism available for selecting / switching between IPsec tunnels for traffic intended to be transmitted toward the same destination (e.g., between the same endpoint devices).

[0015] Some implementations described in this paper enable endpoint devices to select an IPsec tunnel from multiple IPsec tunnels established between the endpoint device and another endpoint device for transmitting services to the other endpoint device. In some implementations, a corresponding metric can be negotiated by the endpoint device and the other endpoint device for each IPsec tunnel, and the endpoint device can select an IPsec tunnel based on the corresponding metric negotiated for the IPsec tunnel. In some implementations, the IPsec tunnel metric can indicate the QoS associated with the IPsec tunnel, and the endpoint device can select an IPsec tunnel based on the metric associated with the IPsec tunnel, which represents a better QoS relative to another IPsec tunnel. In this way, the endpoint device can optimize the communication of services transmitted between the endpoint device and the other endpoint device, which can result in savings in computational resources (e.g., processing resources, memory resources, or communication resources, and others) relative to the computational resources used to transmit services between the endpoint device and the other endpoint device via IPsec tunnels with lower QoS.

[0016] Figures 1A to 1F This is a diagram illustrating an example implementation 100 associated with selecting an IPsec tunnel during metric-based IKE. (See diagram for example.) Figures 1A to 1F As shown, example implementation 100 includes a first endpoint device 105 and a second endpoint device 110. The following is in conjunction with... Figure 2 and Figure 3 These devices are described in more detail.

[0017] As in Figure 1AAs shown by reference numeral 115 in the attached diagram, the first endpoint device 105 can establish multiple IPsec tunnels between the first endpoint device 105 and the second endpoint device 110. For example, the first endpoint device 105 can establish multiple IPsec tunnels (e.g., N IPsec tunnels, where N is an integer greater than 2, such as...). Figure 1A (as shown in the figure) for transmitting services between the first endpoint device 105 and the second endpoint device 105.

[0018] In some implementations, multiple IPsec tunnels can be established via one or more networks associated with one or more ISPs. For example, a first IPsec tunnel (e.g., IPsec tunnel 1, as shown) can be established via the network of a first ISP, a second IPsec tunnel (e.g., IPsec tunnel 2, as shown) can be established via the network of a second ISP, and a third IPsec tunnel (e.g., IPsec tunnel N, as shown) can be established via the network of a third ISP.

[0019] In some implementations, the first ISP may be the same as or different from the second ISP. In some implementations, the third ISP may be the same as or different from the first ISP and / or the second ISP.

[0020] In some implementations, each of the multiple IPsec tunnels may include a different network path between the first endpoint device 105 and the second endpoint device 110 relative to the other IPsec tunnels in the multiple IPsec tunnels. For example, the first IPsec tunnel may include a first network path between the first endpoint device 105 and the second endpoint device 110, and the second IPsec tunnel may include a second network path between the first endpoint device 105 and the second endpoint device 110, which is different from the first network path (e.g., traffic transmitted via the second network path is transmitted via one or more network devices not included in the first network path).

[0021] As in Figure 1B As shown by reference numeral 120 in the attached diagram, the first endpoint device 105 can determine a corresponding metric associated with each of the multiple IPsec tunnels. The metric can indicate a preference among the multiple IPsec tunnels for IPsec tunnel-transmitted services relative to those transmitted via other IPsec tunnels.

[0022] In some implementations, the metric indicates a QoS associated with the IPsec tunnel. In some implementations, the QoS can be a QoS indicated by a service level agreement between an entity associated with the first endpoint device 105 and an ISP associated with a network via which the IPsec tunnel is established. For example, the first endpoint device 105 can receive information indicating the QoS indicated by the service level agreement from another device (e.g., a client device, a server device, or a network device associated with the first endpoint device 105, among other examples), a memory of the first endpoint device 105, or via a user input, among other examples.

[0023] In some implementations, the QoS is a QoS determined by the first endpoint device. For example, the first endpoint device 105 can determine a bandwidth, a latency, a jitter, and / or a number of network devices included along a network path that includes the IPsec tunnel, among other examples. The first endpoint device 105 can determine the QoS based on the bandwidth, the latency, the jitter, and / or the number of network devices. The first endpoint device 105 can determine the metric based on the determined QoS.

[0024] In some implementations, the metric indicates a weight associated with the IPsec tunnel. In some implementations, the weight can indicate a priority associated with the IPsec tunnel. In some implementations, the weight can indicate that a particular percentage of all traffic transmitted to the second endpoint device 110 (e.g., 70%, 80%, or 90% of all traffic transmitted to the second endpoint device 110, among other examples) will be transmitted via the IPsec tunnel.

[0025] In some implementations, the weight can be determined based on one or more characteristics associated with the IPsec tunnel. For example, the weight can be determined based on a QoS associated with the IPsec tunnel, a bandwidth associated with the IPsec tunnel, a latency associated with the IPsec tunnel, or a jitter associated with the IPsec tunnel, among other examples.

[0026] In some implementations, the metric is a metric configured by a user. For example, a user can input information indicating a QoS indicated by a service level agreement, a weight or percentage of traffic to be transmitted via the IPsec tunnel, and / or a metric indicating a priority of the IPsec tunnel relative to other IPsec tunnels, among other examples.

[0027] As shown with reference number 125, the first endpoint device 105 can provide a configuration payload indicating the determined metric to the second endpoint device 110. In some implementations, the first endpoint device 105 can provide a configuration payload indicating a respective metric determined for each IPsec tunnel.

[0028] In some implementations, the first endpoint device 105 can provide a separate configuration payload for each of the plurality of IPsec tunnels. In some implementations, each of the separate configuration payloads for each of the plurality of IPsec tunnels can indicate the metric determined for the IPsec tunnel indicated by the configuration payload.

[0029] In some implementations, the first endpoint device 105 can provide the configuration payload as part of a process to negotiate the metric associated with the IPsec tunnel. In some implementations, the first endpoint device 105 can provide the configuration payload to negotiate the metric during a process to establish the IPsec tunnel between the first endpoint device 105 and the second endpoint device 110. For example, the first endpoint device 105 can transmit a request message indicating the metric determined for the IPsec tunnel during a process to establish the IPsec tunnel between the first endpoint device 105 and the second endpoint device 110.

[0030] In some implementations, the first endpoint device 105 can provide the configuration payload as part of an INFORMATIONAL exchange after the initial exchange. In some implementations, the first endpoint device 105 can provide the configuration payload to negotiate the metric after a process to establish the IPsec tunnel between the first endpoint device 105 and the second endpoint device 110. For example, the first endpoint device 105 can transmit an INFORMATIONAL exchange request message indicating the metric determined for the IPsec tunnel after a process to establish the IPsec tunnel between the first endpoint device 105 and the second endpoint device 110.

[0031] In some implementations, the configuration payload includes a new configuration payload type for IKE exchange messages (e.g., a configuration payload type associated with an IKE AUTH or CREATE CHILD SA or INFORMATIONAL exchange message). In some implementations, the form of the configuration payload can correspond to:

[0032] CP (CFG SET) = IPSEC_TUNNEL_METRIC (x),

[0033] where x is a metric determined for the IPsec tunnel. In some implementations, "CFG SET" and "CFG ACK" can allow the first endpoint device 105 to exchange metric values. In some implementations, the attribute type "IPSEC_TUNNEL_METRIC" can include an IKEv2 configuration payload attribute type. In some implementations, the attribute type "IPSEC_TUNNEL_METRIC" can have a preconfigured attribute type. For example, the attribute type "IPSEC_TUNNEL_METRIC" can have attribute values defined by user input or applicable communication standards, among other examples.

[0034] In some implementations, the second endpoint device 10 can receive the configuration payload and can generate a response to the configuration payload. The response to the configuration payload can indicate acceptance of the metric indicated in the configuration payload, rejection of the metric indicated in the configuration payload, and / or a new metric for the IPsec tunnel indicated in the configuration payload.

[0035] In some implementations, the second endpoint device 10 can determine a metric associated with the IPsec tunnel indicated in the configuration payload. In some implementations, the second endpoint device 10 can determine the metric associated with the IPsec tunnel indicated in the configuration payload in a manner similar to that described above. The second endpoint device 110 can compare the metric indicated in the configuration payload and the metric determined by the second endpoint device 110. The second endpoint device 110 can select one of the metric indicated in the configuration payload or the metric determined by the second endpoint device 110 based on the comparison. The second endpoint device 10 can generate a response to the configuration payload indicating the selected metric.

[0036] As an example, the second endpoint device 110 can compare the metric indicated in the configuration payload and the metric determined by the second endpoint device 110. The second endpoint device 110 can determine whether the metric determined by the second endpoint device 110 is less than (or greater than) the metric indicated in the configuration payload based on the comparison. When the metric determined by the second endpoint device 110 is less than (or greater than) the metric indicated in the configuration payload, the second endpoint device 110 can generate a response indicating the metric determined by the second endpoint device 110. When the metric determined by the second endpoint device 110 is greater than (or less than) the metric indicated in the configuration payload, the second endpoint device 110 can generate a response indicating the metric indicated in the response.

[0037] In some implementations, the first endpoint device 105 can not send a configuration payload indicating the metrics determined for the IPsec tunnel. For example, the first endpoint device 105 and the second endpoint device 110 can determine the metrics for the IPsec tunnel based on user input. In some implementations, the user input can indicate that the second endpoint device 110 determined the metrics for the IPsec tunnel based on the user input, and the first endpoint device 105 can not provide a configuration payload to the second endpoint device 110 based on the second endpoint device 110 determining the metrics for the IPsec tunnel based on the user input.

[0038] As shown with reference number 130, the first endpoint device 105 can receive a response to the configuration payload from the second endpoint device 110. In some implementations, the response can be associated with a single IPsec tunnel and can indicate acceptance of the metrics determined by the first endpoint device 105 for the IPsec tunnel, rejection of the metrics determined by the first endpoint device 105 for the IPsec tunnel, and / or new metrics for the IPsec tunnel. Figure 1C

[0039] In some implementations, the first endpoint device 105 can receive a separate response for each IPsec tunnel for which the configuration payload was transmitted. Each separate response can indicate acceptance of the metrics determined by the first endpoint device 105, rejection of the metrics determined by the first endpoint device 105, and / or new metrics for each IPsec tunnel for which the configuration payload was transmitted to the second endpoint device 110.

[0040] As shown with reference number 135, the first endpoint device 105 can assign respective metrics to each of the plurality of IPsec tunnels based on the response. In some implementations, the response can indicate acceptance of the metrics determined by the first endpoint device 105 for the IPsec tunnel. The first endpoint device 105 can assign the metrics determined by the first endpoint device 105 to the IPsec tunnel based on the response indicating acceptance of the metrics.

[0041] In some implementations, the response can indicate rejection of the metrics determined by the first endpoint device 105 for the IPsec tunnel. The first endpoint device 105 can assign metrics other than the metrics determined by the first endpoint device 105 for the IPsec tunnel based on the response indicating rejection of the metrics.

[0042] ​In some implementations, the first endpoint device 105 determines a new metric for the IPsec tunnel and assigns the new metric to the IPsec tunnel based on a response indicating rejection of the metric. For example, the first endpoint device 105 may determine a new metric for the IPsec tunnel, transmit a new configuration payload indicating the new metric to the second endpoint device 110, and / or may receive a new response to the new configuration payload in a manner similar to that described above. The new response may indicate acceptance of the new metric, and the first endpoint device 105 may assign the new metric to the IPsec tunnel based on the response indicating acceptance of the new metric.

[0043] In some implementations, the response indicates a metric determined by the second endpoint device 110. The metric determined by the second endpoint device 110 may be the same as or different from the metric determined by the first endpoint device 105 for the IPsec tunnel. The first endpoint device 105 may assign the metric indicated in the response to the IPsec tunnel based on the metric indicated in the response.

[0044] As illustrated using reference numeral 140, the first endpoint device 105 can rank (e.g., prioritize) multiple IPsec tunnels based on the corresponding metric assigned to each IPsec tunnel. For example, the first endpoint device 105 can identify the IPsec tunnel assigned the lowest (or highest) metric relative to the metrics assigned to other IPsec tunnels among the multiple IPsec tunnels. The first endpoint device 105 can prioritize ranking the IPsec tunnels based on the IPsec tunnel assigned the lowest (or highest) metric relative to the metrics assigned to other IPsec tunnels (e.g., associating the IPsec tunnel with the highest ranking). The first endpoint device 105 can similarly rank the remaining IPsec tunnels based on the corresponding metrics assigned to the remaining IPsec tunnels to generate a ranked list of IPsec tunnels.

[0045] As in Figure 1D As illustrated by reference numeral 145 in the attached diagram, the first endpoint device 105 can receive data to be transmitted to the second endpoint device 110. For example, the first endpoint device 105 can receive a request to access a server device associated with the second endpoint device 110 from a client device.

[0046] As shown by reference numeral 150, the first endpoint device 105 can select an IPsec tunnel from multiple IPsec tunnels based on a ranking of the IPsec tunnels. For example, the first endpoint device 105 can select the IPsec tunnel that is ranked highest relative to other IPsec tunnels based on a ranking list of IPsec tunnels generated by the first endpoint device 105. As shown by reference numeral 155, the first endpoint device 105 can transmit data to the second endpoint device 110 via the selected IPsec tunnel.

[0047] As in Figure 1E As illustrated by reference numeral 160 in the attached diagram, the first endpoint device 105 can determine problems associated with the selected IPsec tunnel. For example, after transmitting data to the second endpoint device 110, the first endpoint device 105 can determine network outages associated with the network (via which the selected IPsec tunnel was established), QoS degradation associated with the selected IPsec tunnel, or failures of network devices associated with the IPsec tunnel, among other examples.

[0048] As illustrated by reference numeral 165 in the accompanying drawings, the first endpoint device 105 may determine a modified metric associated with another IPsec tunnel besides the selected IPsec tunnel based on issues associated with the selected IPsec tunnel. In some implementations, the first endpoint device 105 may determine the modified metric in a manner similar to that described above with respect to the metric for determining the IPsec tunnel by the first endpoint device 105.

[0049] As shown with reference number 170, the first endpoint device 105 can provide a configuration payload indicating a modified metric associated with another IPsec tunnel to the second endpoint device 110. In some implementations, the configuration payload can indicate that the modified metric is less than (or greater than) the metric determined for another IPsec tunnel of the plurality of IPsec tunnels. In some implementations, the configuration payload indicating the modified metric can be included in an IKE INFORMATIONAL exchange message. In some implementations, the first endpoint device 105 can provide the configuration payload indicating the modified metric to the second endpoint device 110 in a manner similar to that described above. In some implementations, the first endpoint device 105 can receive a response from the second endpoint device 110 to the configuration payload indicating the modified metric. In some implementations, the response can indicate acceptance of the modified metric, rejection of the modified metric, and / or a new modified metric for the IPsec tunnel. The first endpoint device 105 can assign the modified metric or the new modified metric to the other IPsec tunnel based on the response. In some implementations, the first endpoint device 105 can assign the modified metric or the new modified metric to the other IPsec tunnel in a manner similar to that described above.

[0050] As shown with reference number 175, the first endpoint device 105 can re-rank the plurality of IPsec tunnels based on the modified metric associated with another IPsec tunnel other than the selected IPsec tunnel. For example, the first endpoint device 105 can generate a new ranked list of IPsec tunnels based on assigning the modified metric or the new modified metric to the other IPsec tunnel. In some implementations, the first endpoint device 105 can generate the new ranked list of IPsec tunnels in a manner similar to that described above. Figure 1F

[0051] As shown with reference number 180, the first endpoint device 105 can select a new IPsec tunnel from the plurality of IPsec tunnels for transmitting traffic between the first endpoint device 105 and the second endpoint device 110 based on re-ranking the plurality of IPsec tunnels. For example, the first endpoint device 105 can receive new data to transmit to the second endpoint device 110. The first endpoint device 105 can select a highest ranked IPsec tunnel of the plurality of IPsec tunnels based on the new ranked list of IPsec tunnels. In some implementations, the first endpoint device 105 can select the highest ranked IPsec tunnel based on the new ranked list of IPsec tunnels in a manner similar to that described above. The first endpoint device 105 can transmit the new data to the second endpoint device 110 via the selected IPsec tunnel. ​

[0052] As indicated above, Figures 1A to 1F are provided as examples. Other examples can differ from what is described. Figures 1A to 1F The number and arrangement of devices shown in Figures 1A to 1F may vary from that shown in Figures 1A to 1F . Additionally or alternatively, Figures 1A to 1F Two or more devices shown in Figures 1A to 1F may be implemented within a single device, or Figures 1A to 1F A single device shown in Figure 2 may be implemented as multiple, distributed devices. Additionally or alternatively, A set of devices (e.g., one or more devices) shown in

[0053] may perform one or more functions described as being performed by another set of devices. Figure 2 Figure 2

[0054] The endpoint devices 210 include one or more devices capable of receiving, generating, storing, processing, and / or providing information, such as information described herein. For example, the endpoint devices 210 can include a mobile phone (e.g., a smart phone or a wireless phone), a laptop computer, a tablet computer, a desktop computer, a handheld computer, a gaming device, a wearable communication device (e.g., a smart watch, a pair of smart glasses, a heart rate monitor, a fitness tracker, smart clothing, smart jewelry, or a head-mounted display), a network appliance, or a similar type of device. In some implementations, the endpoint devices 210 can receive network traffic from and / or can provide network traffic to other endpoint devices 210 via the network 230 (e.g., by routing packets through the network devices 220 as intermediaries). In some implementations, the endpoint devices 210 can correspond to the first endpoint device 105 and / or the second endpoint device 100.

[0055] In some implementations, the endpoint device 210 includes a server device. The server device can include one or more devices capable of receiving, generating, storing, processing, and / or providing information, such as information described herein. For example, the server device can include a laptop computer, a tablet computer, a desktop computer, a group of server devices, or a similar type of device associated with multicast traffic. In some implementations, the server device can receive information (e.g., multicast traffic) from and / or transmit information (e.g., multicast traffic) to the endpoint device 210 via the network 230 (e.g., by routing packets through the network device 220 as an intermediary). In some implementations, the endpoint device 210 includes the network device 220.

[0056] The network device 220 includes one or more devices capable of receiving, processing, storing, routing, and / or providing traffic (e.g., packets or other information or metadata) in the manner described herein. For example, the network device 220 can include a router, such as a label-switching router (LSR), a label edge router (LER), an ingress router, an egress router, a provider router (e.g., a provider edge router or a provider core router), a virtual router, or another type of router. Additionally or alternatively, the network device 220 can include a gateway, a switch, a firewall, a hub, a bridge, a reverse proxy, a server (e.g., a proxy server, a cloud server, or a data center server), a load balancer, and / or a similar device. In some implementations, the network device 220 can be a physical device implemented within a housing, such as a rack. In some implementations, the network device 220 can be a virtual device implemented by one or more computer devices of a cloud computing environment or a data center. In some implementations, a group of network devices 220 can be a group of data center nodes for routing traffic flows through the network 230.

[0057] The network 230 includes one or more wired and / or wireless networks. For example, the network 230 can include a packet-switched network, a cellular network (e.g., a fifth generation (5G) network, a fourth generation (4G) network (such as a Long Term Evolution (LTE) network), a third generation (3G) network, a code division multiple access (CDMA) network, a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., a

[0058] Figure 2 The number and arrangement of devices and networks shown in FIG. 1 are provided as an example. In practice, there can be additional devices and / or networks, fewer devices and / or networks, many more devices and / or networks, and / or different devices and / or networks, depending on specific implementation requirements. Figure 2Compared to the devices and / or networks shown, there may be additional devices and / or networks, fewer devices and / or networks, different devices and / or networks, or devices and / or networks arranged in a different manner. Furthermore, Figure 2 The two or more devices shown can be implemented within a single device, or Figure 3 The single device shown can be implemented as multiple distributed devices. Additionally or alternatively, the set of devices in environment 200 (e.g., one or more devices) can perform one or more functions described as being performed by another set of devices in environment 200.

[0059] Figure 3 This is a diagram illustrating an example component of device 300, which may correspond to endpoint device 210 and / or network device 220. In some implementations, endpoint device 210 and / or network device 220 includes one or more components of device 300. Figure 3 As shown, device 300 may include bus 310, processor 320, memory 330, input component 340, output component 350 and communication component 360.

[0060] Bus 310 includes one or more components that enable wired and / or wireless communication between components of device 300. Bus 310 can connect components such as via operative coupling, communicative coupling, electronic coupling, and / or electrical coupling. Figure 3 Two or more components are coupled together. Processor 320 includes a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a field-programmable gate array, an application-specific integrated circuit, and / or another type of processing component. Processor 320 is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, processor 320 includes one or more processors capable of being programmed to perform one or more operations or processes described elsewhere herein.

[0061] Memory 330 includes volatile and / or non-volatile memory. For example, memory 330 may include random access memory (RAM), read-only memory (ROM), hard disk drive, and / or another type of memory (e.g., flash memory, magnetic memory, and / or optical memory). Memory 330 may include internal memory (e.g., RAM, ROM, or hard disk drive) and / or removable memory (e.g., removable via a universal serial bus). Memory 330 may be a non-transient computer-readable medium. Memory 330 stores information, instructions, and / or software (e.g., one or more software applications) related to the operation of device 300. In some implementations, memory 330 includes one or more memories, such as those coupled to one or more processors (e.g., processor 320) via bus 310.

[0062] Input component 340 enables device 300 to receive input, such as user input and / or sensory input. For example, input component 340 can include a touch screen, a keyboard, a keypad, a mouse, a button, a microphone, a switch, a sensor, a global positioning system sensor, an accelerometer, a gyroscope, and / or an actuator. Output component 350 enables device 300 to provide outputs, such as via a display, a speaker, and / or a light emitting diode. Communication component 360 enables device 300 to communicate with other devices via wired and / or wireless connections. For example, communication component 360 can include a receiver, a transmitter, a transceiver, a modem, a network interface card, and / or an antenna.

[0063] Device 300 can perform one or more operations or processes described herein. For example, a non-transitory computer-readable medium (e.g., memory 330) can store a set of instructions (e.g., one or more instructions or code) for execution by processor 320. Processor 320 can execute the set of instructions to perform one or more operations or processes described herein. In some implementations, execution of the set of instructions by one or more processors 320 causes one or more processors 320 and / or device 300 to perform one or more operations or processes described herein. In some implementations, one or more operations or processes described herein are performed using hardwired circuitry instead of, or in combination with, the set of instructions and / or software. Additionally, or alternatively, processor 320 can be configured to perform one or more operations or processes described herein. Thus, implementations described herein are not limited to any specific combination of hardware circuitry and software.

[0064] Figure 3 The number and arrangement of components shown in FIG. 10 are provided as an example. Device 300 can include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 10. Additionally, or alternatively, a set of components (e.g., one or more components) of device 300 can perform one or more functions described as being performed by another set of components of device 300. Figure 4 Device 300 can include additional components, fewer components, different components, or differently arranged components than those shown in FIG. 10. Additionally or alternatively, a set of components (e.g., one or more components) of device 300 can perform one or more functions described as being performed by another set of components of device 300.

[0065] Figure 4 is a schematic diagram of an example process 400 associated with a system and method for selecting an IPsec tunnel during metric-based IKE. In some implementations, one or more process blocks of process 400 are performed by a first endpoint device (e.g., first endpoint device 105). In some implementations, one or more process blocks of process 400 are performed by a second endpoint device (e.g., second endpoint device 110). Figure 4 One or more process blocks of process 400 are performed by a first endpoint device (e.g., first endpoint device 105). In some implementations, one or more process blocks of process 400 are performed by a second endpoint device (e.g., second endpoint device 110). Figure 4One or more of the process blocks are performed by another device or set of devices separate from or including the first endpoint device, such as another endpoint device (e.g., the second endpoint device 110) and / or a network device (e.g., the network device 220). Additionally or alternatively, Figure 4 One or more of the process blocks can be performed by one or more components of the device 300, such as the processor 320, the memory 330, the input component 340, the output component 350, and / or the communication component 360.

[0066] As shown in Figure 4 The process 400 can include assigning a first metric to a first IPsec tunnel and a second metric to a second IPsec tunnel, where the first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and a second endpoint device and the second IPsec tunnel is a second communication channel for transmitting data between the first endpoint device and the second endpoint device (block 410). For example, as described above, the first endpoint device can assign a first metric to a first IPsec tunnel and a second metric to a second IPsec tunnel, where the first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and a second endpoint device and the second IPsec tunnel is a second communication channel for transmitting data between the first endpoint device and the second endpoint device.

[0067] As further shown in Figure 4 The process 400 can include selecting the first IPsec tunnel or the second IPsec tunnel as a selected IPsec tunnel for transmitting data toward the second endpoint device based on the first metric and the second metric (block 420). For example, as described above, the first endpoint device can select the first IPsec tunnel or the second IPsec tunnel as a selected IPsec tunnel for transmitting data toward the second endpoint device based on the first metric and the second metric.

[0068] As further shown in Figure 4 The process 400 can include transmitting data toward the second endpoint device via the selected IPsec tunnel. For example, as described above, the first endpoint device can transmit data toward the second endpoint device via the selected IPsec tunnel.

[0069] As further shown in Figure 4 The process 400 can include determining an issue associated with the selected IPsec tunnel (block 440). For example, as described above, the first endpoint device can determine an issue associated with the selected IPsec tunnel.

[0070] As further shown in Figure 4Further to the foregoing, the process 400 can include determining, based on the problem, a modified metric for the remaining IPsec tunnel that does not correspond to the selected IPsec tunnel (block 450). For example, as described above, the first endpoint device can determine, based on the problem, a modified metric for the remaining IPsec tunnel that does not correspond to the selected IPsec tunnel.

[0071] As Figure 4 Further to the foregoing, the process 400 can include providing, to the second endpoint device, a configuration payload indicating the modified metric (block 460). For example, as described above, the first endpoint device can provide, to the second endpoint device, a configuration payload indicating the modified metric. The second endpoint device can provide a response indicating acceptance of the modified metric, rejection of the modified metric, and / or a new modified metric for the IPsec tunnel. The first endpoint device can assign the modified metric or the new modified metric to the IPsec tunnel.

[0072] As Figure 4 Further to the foregoing, the process 400 can include re-ranking the first IPsec tunnel or the second IPsec tunnel based on the modified metric associated with the remaining IPsec tunnel (block 470). For example, the first endpoint device can select a highest ranked IPsec tunnel based on re-ranking the first IPsec tunnel or the second IPsec tunnel.

[0073] As Figure 4 Further to the foregoing, the process 400 can include transmitting new data toward the second endpoint device via the selected IPsec tunnel (block 480). For example, the first endpoint device can transmit new data toward the second endpoint device via the selected IPsec tunnel.

[0074] The process 400 can include additional implementations, such as any single implementation or any combination of implementations described below and / or in connection with one or more other processes described elsewhere herein.

[0075] In a first implementation, the first endpoint device selects the first IPsec tunnel or the second IPsec tunnel as a new selected IPsec tunnel for transmitting data toward the second endpoint device, the method further comprising selecting based on a modified metric associated with the first IPsec tunnel or the second IPsec tunnel.

[0076] In a second implementation, alone or in combination with the first implementation, the configuration payload is included in an IKE INFORMATIONAL exchange message.

[0077] In a third implementation, alone or in combination with one or more of the first and second implementations, assigning the first metric to the first IPsec tunnel and the second metric to the second IPsec tunnel includes determining a first quality of service associated with the first IPsec tunnel, assigning the first metric to the first IPsec tunnel based on the first quality of service, determining a second quality of service associated with the second IPsec tunnel, assigning the second metric to the second IPsec tunnel based on the second quality of service, and transmitting a configuration payload to the second endpoint device indicating the first metric and the second metric.

[0078] In a fourth implementation, alone or in combination with one or more of the first through third implementations, the first metric includes a first weight and the second metric includes a second weight, the method further comprising transmitting a first percentage of data toward the second endpoint device via the first IPsec tunnel, wherein the first percentage is determined based on the first weight, and transmitting a second percentage of data toward the second endpoint device via the second IPsec tunnel, wherein the second percentage is based on the second weight.

[0079] In a fifth implementation, alone or in combination with one or more of the first through fourth implementations, the process 400 includes determining the first weight based on a first bandwidth associated with the first IPsec tunnel and determining the second weight based on a second bandwidth associated with the second IPsec tunnel.

[0080] Although Figure 4 An example process 400 is shown, but in some implementations, the process 400 includes additional blocks, fewer blocks, different blocks, or differently arranged blocks than those depicted in FIG. 4. Additionally, or alternatively, two or more blocks of the process 400 can be performed in parallel. Figure 4

[0081] According to some implementations, the following examples are disclosed.

[0082] Example 1. A method comprising: assigning, by a first endpoint device, a first metric to a first Internet Protocol Security (IPsec) tunnel and a second metric to a second IPsec tunnel, wherein the first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and a second endpoint device, and the second IPsec tunnel is a second communication channel for transmitting data between the first endpoint device and the second endpoint device; selecting, by the first endpoint device, the first IPsec tunnel or the second IPsec tunnel as a selected IPsec tunnel for transmitting data toward the second endpoint device based on the first metric and the second metric; and transmitting, by the first endpoint device, data toward the second endpoint device via the selected IPsec tunnel.

[0083] ​Example 2. The method of example 1, wherein the first endpoint device selects the first IPsec tunnel as the selected IPsec tunnel, the method further comprising: determining an issue associated with the first IPsec tunnel; modifying the second metric to generate a modified second metric based on the issue associated with the first IPsec tunnel; and selecting the first IPsec tunnel or the second IPsec tunnel as a new selected IPsec tunnel for transmitting data toward the second endpoint device based on the first metric and the modified second metric.

[0084] Example 3. The method of example 2, further comprising: transmitting, to the second endpoint device, a configuration payload indicating the modified second metric.

[0085] Example 4. The method of example 3, wherein the configuration payload comprises an Internet Key Exchange configuration payload.

[0086] Example 5. The method of example 1, wherein assigning the first metric to the first IPsec tunnel and assigning the second metric to the second IPsec tunnel comprises: determining a first quality of service associated with the first IPsec tunnel; assigning the first metric to the first IPsec tunnel based on the first quality of service; determining a second quality of service associated with the second IPsec tunnel; assigning the second metric to the second IPsec tunnel based on the second quality of service; and transmitting, to the second endpoint device, a first configuration payload for the first IPsec tunnel and indicating the first metric and a second configuration payload for the second IPsec tunnel and indicating the second metric.

[0087] Example 6. The method of example 1, wherein the first metric comprises a first weight and the second metric comprises a second weight, the method further comprising: transmitting a first percentage of data toward the second endpoint device via the first IPsec tunnel, wherein the first percentage is determined based on the first weight; and transmitting a second percentage of data toward the second endpoint device via the second IPsec tunnel, wherein the second percentage is based on the second weight.

[0088] Example 7. The method of example 6, further comprising: determining the first weight based on a first bandwidth associated with the first IPsec tunnel; and determining the second weight based on a second bandwidth associated with the second IPsec tunnel.

[0089] Example 8. A first endpoint device comprising: one or more memories; and one or more processors to: assign a first metric to a first Internet Protocol Security, IPsec, tunnel and a second metric to a second IPsec tunnel, wherein the first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and a second endpoint device and the second IPsec tunnel is a second communication channel for transmitting data between the first endpoint device and the second endpoint device; select the first IPsec tunnel or the second IPsec tunnel as a selected IPsec tunnel for transmitting data toward the second endpoint device based on comparing the first metric and the second metric; and transmit data toward the second endpoint device via the selected IPsec tunnel.

[0090] Example 9. The first endpoint device of example 8, wherein the first endpoint device selects the first IPsec tunnel as the selected IPsec tunnel, and wherein the one or more processors are further to: determine an issue associated with the first IPsec tunnel; modify the second metric based on the issue associated with the first IPsec tunnel to generate a modified second metric; and select the first IPsec tunnel or the second IPsec tunnel as a new selected IPsec tunnel for transmitting data toward the second endpoint device based on comparing the first metric and the modified second metric.

[0091] Example 10. The first endpoint device of example 8, wherein to assign the first metric to the first IPsec tunnel and the second metric to the second IPsec tunnel, the one or more processors are to: determine a first quality of service associated with the first IPsec tunnel; assign the first metric to the first IPsec tunnel based on the first quality of service; determine a second quality of service associated with the second IPsec tunnel; and assign the second metric to the second IPsec tunnel based on the second quality of service.

[0092] Example 11. The first endpoint device of example 8, wherein the one or more processors are further to: transmit, to the second endpoint device, a first configuration payload for the first IPsec tunnel and a second configuration payload for the second IPsec tunnel, the first configuration payload indicating the first metric, the second configuration payload indicating the second metric.

[0093] Example 12. The first endpoint device of example 8, wherein the first metric comprises a first weight and the second metric comprises a second weight, and wherein the one or more processors are further to: transmit a first percentage of data toward the second endpoint device via the first IPsec tunnel, wherein the first percentage is determined based on the first weight; and transmit a second percentage of data toward the second endpoint device via the second IPsec tunnel, wherein the second percentage is based on the second weight.

[0094] Example 13. The first endpoint device of example 12, wherein the one or more processors are further to: determine a first weight based on a first bandwidth associated with the first IPsec tunnel; and determine a second weight based on a second bandwidth associated with the second IPsec tunnel.

[0095] Example 14. The first endpoint device of example 8, wherein to assign the first metric to the first IPsec tunnel and the second metric to the second IPsec tunnel, the one or more processors are to: transmit, to the second endpoint device, a first configuration payload for the first IPsec tunnel and a second configuration payload for the second IPsec tunnel, the first configuration payload indicating the first metric, the second configuration payload indicating the second metric; receive a response to the first configuration payload, wherein the response indicates a new first metric associated with the first IPsec tunnel; and assign the new first metric to the first IPsec tunnel.

[0096] Example 15. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a first endpoint device, cause the first endpoint device to: assign a first metric to a first Internet Protocol Security (IPsec) tunnel and a second metric to a second IPsec tunnel, wherein the first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and a second endpoint device, and the second IPsec tunnel is a second communication channel for transmitting data between the first endpoint device and the second endpoint device; select the first IPsec tunnel or the second IPsec tunnel as a selected IPsec tunnel for transmitting data toward the second endpoint device based on comparing a first value of the first metric and a second value of the second metric; and transmit data toward the second endpoint device via the selected IPsec tunnel.

[0097] Example 16. The non-transitory computer-readable medium of example 15, wherein the one or more instructions further cause the first endpoint device to: determine an issue associated with the first IPsec tunnel; modify the second metric based on the issue associated with the first IPsec tunnel to generate a modified second metric; and select the first IPsec tunnel or the second IPsec tunnel as a new selected IPsec tunnel for transmitting data toward the second endpoint device based on comparing the value of the first metric and the modified second metric.

[0098] Example 17. The non-transitory computer-readable medium of example 16, wherein the one or more instructions further cause the first endpoint device to: transmit, to the second endpoint device, a configuration payload indicating the modified second metric.

[0099] Example 18. The non-transitory computer-readable medium of example 15, wherein the one or more instructions that cause the first endpoint device to assign the first metric to the first IPsec tunnel and the second metric to the second IPsec tunnel cause the first endpoint device to: determine a first quality of service associated with the first IPsec tunnel; assign the first metric to the first IPsec tunnel based on the first quality of service; determine a second quality of service associated with the second IPsec tunnel; assign the second metric to the second IPsec tunnel based on the second quality of service; and transmit, to the second endpoint device, a first configuration payload for the first IPsec tunnel and a second configuration payload for the second IPsec tunnel, the first configuration payload indicating the first metric and the second configuration payload indicating the second metric.

[0100] Example 19. The non-transitory computer-readable medium of example 15, wherein the first metric comprises a first weight and the second metric comprises a second weight, and wherein the one or more instructions further cause the first endpoint device to: transmit a first percentage of data toward the second endpoint device via the first IPsec tunnel, wherein the first percentage is determined based on the first weight; and transmit a second percentage of data toward the second endpoint device via the second IPsec tunnel, wherein the second percentage is based on the second weight.

[0101] Example 20. The non-transitory computer-readable medium of example 19, wherein the one or more instructions further cause the first endpoint device to: determine the first weight based on a first bandwidth associated with the first IPsec tunnel; and determine the second weight based on a second bandwidth associated with the second IPsec tunnel.

[0102] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit implementations to the precise form disclosed. Modifications and variations can be possible in light of the above disclosure or can be acquired from practice of the implementations. It will be apparent that systems and / or methods, described herein, can be implemented in various forms. For example, this disclosure includes both a product and a process. Specifically, the product can be implemented as a system, apparatus, or device (e.g., a computer program product) that includes functional units (e.g., modules or components) to perform one or more functions described herein. The process can be implemented as one or more operations performed by one or more devices (e.g., a computer program product) to perform one or more functions described herein.

[0103] As used herein, traffic or content can include a set of packets. A packet can refer to a communication structure used to convey information, such as a protocol data unit (PDU), a service data unit (SDU), a network packet, a datagram, a segment, a message, a box, a frame (e.g., an Ethernet frame), a portion of any of the above, and / or another type of formatted or unformatted data unit capable of being transmitted via a network.

[0104] As used herein, the term "component" is intended to be broadly construed as hardware, firmware, or a combination of hardware and software. It will be apparent that systems and / or methods described herein can be implemented in different forms of hardware, firmware, and / or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not limiting of the implementations. Thus, the operation and behavior of the systems and / or methods were described herein without reference to specific software code — it is understood that software and hardware can be used to implement the systems and / or methods based on the description herein.

[0105] Even if a particular feature is described in connection with a particular combination of features, that does not mean that the feature is not combinable with other features. For instance, features described in conjunction with one implementation can be combined with features described in conjunction with another implementation. The various implementations described herein can be combined in order to provide additional implementations. Unless otherwise stated, all combinations of claim limitations are hereby expressly contemplated regardless of whether the alternative was specifically and explicitly stated in the claims. For instance, even if particular combinations of claim limitations are not explicitly stated in the claims, they are still expressly contemplated. Also, any incorporation by reference of any external documents is not intended to imply an incorporation by reference of any item in the external document that can contradict any definitions provided herein. Also, any external document is expressly disclaimed as incorporated by reference only to the extent that it is not in conflict with any definitions provided herein.

[0106] Accordingly, unless clearly indicated otherwise, any of the elements, acts, or instructions described herein should not be construed as critical or essential to the implementations. Furthermore, unless specifically stated otherwise, the terms "a," "an," and "one" are intended to encompass one or more items. Additionally, the term "set" is intended to encompass one or more items (e.g., related items, unrelated items, or a combination of related and unrelated items). Further, unless specifically stated otherwise, the term "or" is intended to encompass both a conjunctive and disjunctive meaning.

Claims

1. A method comprising: The first endpoint device assigns a first metric to the first Internet Protocol Security (IPsec) tunnel and a second metric to the second IPsec tunnel. The first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and the second endpoint device, and the second IPsec tunnel is a second communication channel for transmitting the data between the first endpoint device and the second endpoint device. The first IPsec tunnel and the second IPsec tunnel originate from multiple IPsec tunnels between the first endpoint device and the second endpoint device; The first endpoint device ranks the plurality of IPsec tunnels based on the first metric and the second metric. The first endpoint device selects either the first IPsec tunnel or the second IPsec tunnel as the selected IPsec tunnel for transmitting the data toward the second endpoint device based on the ranking. The first endpoint device modifies the second metric to generate a modified second metric when it determines a problem associated with the first IPsec tunnel; The first endpoint device re-ranks the plurality of IPsec tunnels based on the modified second metric. The first endpoint device selects a specific IPsec tunnel from the plurality of IPsec tunnels in response to the re-ranking. as well as The data is transmitted from the first endpoint device to the second endpoint device via the specific IPsec tunnel.

2. The method of claim 1, wherein the first endpoint device selects the first IPsec tunnel as the selected IPsec tunnel, and wherein the method further comprises: Based on the issues associated with the first IPsec tunnel, the second metric is modified to generate a modified second metric; Based on the first metric and the modified second metric, either the first IPsec tunnel or the second IPsec tunnel is selected as a new selected IPsec tunnel for transmitting data toward the second endpoint device; as well as Transmit a configuration payload indicating the modified second metric to the second endpoint device.

3. The method of claim 2, wherein the configuration payload includes an Internet key exchange configuration payload.

4. The method of claim 1, wherein assigning the first metric to the first IPsec tunnel and assigning the second metric to the second IPsec tunnel comprises: Determine the first quality of service associated with the first IPsec tunnel; The first metric is assigned to the first IPsec tunnel based on the first quality of service. Determine the second quality of service associated with the second IPsec tunnel; The second metric is assigned to the second IPsec tunnel based on the second quality of service; as well as A first configuration payload and a second configuration payload are transmitted to the second endpoint device. The first configuration payload is used for the first IPsec tunnel and indicates the first metric. The second configuration payload is used for the second IPsec tunnel and indicates the second metric.

5. The method of claim 1, wherein the first metric includes a first weight and the second metric includes a second weight, the method further comprising: A first percentage of the data is transmitted to the second endpoint device via the first IPsec tunnel, wherein the first percentage is determined based on the first weight; as well as A second percentage of the data is transmitted to the second endpoint device via the second IPsec tunnel, wherein the second percentage is based on the second weight.

6. The method according to claim 5, further comprising: The first weight is determined based on the first bandwidth associated with the first IPsec tunnel; as well as The second weight is determined based on the second bandwidth associated with the second IPsec tunnel.

7. A first endpoint device, comprising: One or more memory units; as well as One or more processors, used to: The first metric is assigned to the first Internet Protocol Security (IPsec) tunnel, and the second metric is assigned to the second IPsec tunnel. The first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and the second endpoint device, and the second IPsec tunnel is a second communication channel for transmitting the data between the first endpoint device and the second endpoint device. The first IPsec tunnel and the second IPsec tunnel originate from multiple IPsec tunnels between the first endpoint device and the second endpoint device; In response to comparing the first metric and the second metric, the plurality of IPsec tunnels are ranked; Based on the ranking, either the first IPsec tunnel or the second IPsec tunnel is selected as the chosen IPsec tunnel for transmitting the data toward the second endpoint device; When a problem is identified that is associated with the first IPsec tunnel, the second metric is modified to generate a modified second metric; The plurality of IPsec tunnels are re-ranked based on the modified second metric. In response to the re-ranking, a specific IPsec tunnel is selected from the plurality of IPsec tunnels; as well as The data is transmitted toward the second endpoint device via the specific IPsec tunnel.

8. The first endpoint device of claim 7, wherein the first endpoint device selects the first IPsec tunnel as the selected IPsec tunnel, and wherein the one or more processors are further configured to: Identify the issues associated with the first IPsec tunnel; The second metric is modified based on the issues associated with the first IPsec tunnel to generate a modified second metric; as well as The first IPsec tunnel or the second IPsec tunnel is selected as a new selected IPsec tunnel for transmitting data toward the second endpoint device based on a comparison of the first metric and the second metric.

9. The first endpoint device of claim 7, wherein, in order to assign the first metric to the first IPsec tunnel and the second metric to the second IPsec tunnel, the one or more processors are configured to: Determine the first quality of service associated with the first IPsec tunnel; The first metric is assigned to the first IPsec tunnel based on the first quality of service. Determine the second quality of service associated with the second IPsec tunnel; as well as The second metric is assigned to the second IPsec tunnel based on the second quality of service.

10. The first endpoint device of claim 7, wherein the one or more processors are further configured to: The first configuration payload for the first IPsec tunnel and the second configuration payload for the second IPsec tunnel are transmitted to the second endpoint device, wherein the first configuration payload indicates the first metric and the second configuration payload indicates the second metric.

11. The first endpoint device of claim 7, wherein the first metric includes a first weight and the second metric includes a second weight, and wherein the one or more processors are further configured to: Transmit a first percentage of the data toward the second endpoint device via the first IPsec tunnel, wherein the first percentage is determined based on the first weight; and A second percentage of the data is transmitted to the second endpoint device via the second IPsec tunnel, wherein the second percentage is based on the second weight.

12. The first endpoint device of claim 11, wherein the one or more processors are further configured to: The first weight is determined based on the first bandwidth associated with the first IPsec tunnel; and The second weight is determined based on the second bandwidth associated with the second IPsec tunnel.

13. The first endpoint device of claim 7, wherein, in order to assign the first metric to the first IPsec tunnel and the second metric to the second IPsec tunnel, the one or more processors are configured to: Transmit a first configuration payload for the first IPsec tunnel and a second configuration payload for the second IPsec tunnel to the second endpoint device, wherein the first configuration payload indicates the first metric and the second configuration payload indicates the second metric; Receive a response to the first configured payload, wherein the response indicates a new first metric associated with the first IPsec tunnel; as well as The new first metric is assigned to the first IPsec tunnel.

14. The first endpoint device of claim 7, wherein the one or more processors are further configured to: Transmit a first configuration payload for a first IPsec tunnel and a second configuration payload for a second IPsec tunnel, wherein the first configuration payload indicates the first metric value, and the second configuration payload indicates the second metric value. The first configuration payload and the second configuration payload include a new configuration payload type for Internet Key Exchange (IKE) exchange messages.

15. A non-transient computer-readable medium storing an instruction set, the instruction set comprising: One or more instructions, which, when executed by one or more processors of the first endpoint device, cause the first endpoint device to: The first metric is assigned to the first Internet Protocol Security (IPsec) tunnel, and the second metric is assigned to the second IPsec tunnel. The first IPsec tunnel is a first communication channel for transmitting data between the first endpoint device and the second endpoint device, and the second IPsec tunnel is a second communication channel for transmitting the data between the first endpoint device and the second endpoint device. The first IPsec tunnel and the second IPsec tunnel originate from multiple IPsec tunnels between the first endpoint device and the second endpoint device; In response to comparing a first value of the first metric with a second value of the second metric, the plurality of IPsec tunnels are ranked; Based on the ranking, either the first IPsec tunnel or the second IPsec tunnel is selected as the chosen IPsec tunnel for transmitting the data toward the second endpoint device; When a problem is identified that is associated with the first IPsec tunnel, the second metric is modified to generate a modified second metric; The plurality of IPsec tunnels are re-ranked based on the modified second metric. In response to the re-ranking, a specific IPsec tunnel is selected from the plurality of IPsec tunnels; as well as The data is transmitted toward the second endpoint device via the specific IPsec tunnel.

16. The non-transient computer-readable medium of claim 15, wherein one or more instructions further cause the first endpoint device to: Identify the issues associated with the first IPsec tunnel; The second metric is modified based on the issues associated with the first IPsec tunnel to generate a modified second metric; and The first IPsec tunnel or the second IPsec tunnel is selected as a new selected IPsec tunnel for transmitting data toward the second endpoint device based on a comparison of the value of the first metric and the modified second metric.

17. The non-transient computer-readable medium of claim 16, wherein one or more instructions further cause the first endpoint device to: Transmit a configuration payload indicating the modified second metric to the second endpoint device.

18. The non-transient computer-readable medium of claim 15, wherein the one or more instructions that cause the first endpoint device to assign the first metric to the first IPsec tunnel and the second metric to the second IPsec tunnel cause the first endpoint device to: Determine the first quality of service associated with the first IPsec tunnel; The first metric is assigned to the first IPsec tunnel based on the first quality of service. Determine the second quality of service associated with the second IPsec tunnel; The second metric is assigned to the second IPsec tunnel based on the second quality of service; as well as The first configuration payload for the first IPsec tunnel and the second configuration payload for the second IPsec tunnel are transmitted to the second endpoint device, wherein the first configuration payload indicates the first metric and the second configuration payload indicates the second metric.

19. The non-transient computer-readable medium of claim 15, wherein the first metric includes a first weight and the second metric includes a second weight, and wherein the one or more instructions further cause the first endpoint device to: Transmit a first percentage of the data toward the second endpoint device via the first IPsec tunnel, wherein the first percentage is determined based on the first weight; and A second percentage of the data is transmitted to the second endpoint device via the second IPsec tunnel, wherein the second percentage is based on the second weight.

20. The non-transient computer-readable medium of claim 19, wherein one or more instructions further cause the first endpoint device to: The first weight is determined based on the first bandwidth associated with the first IPsec tunnel; and The second weight is determined based on the second bandwidth associated with the second IPsec tunnel.

Citation Information

Patent Citations

  • Data transmission guaranteeing method and communication equipment

    CN111182540A

  • Method and system for selecting tunnels to send network traffic through

    US20180062875A1