Cloud Survivability Systems and Methods for Cloud Orchestrated Internet Protocol Security (IPSEC) Security Associations (SA)

The implementation of survivability tunnels with factory authentication addresses the vulnerability of IPsec tunnels in cloud environments by ensuring continuous secure communication through failover mechanisms, even when cloud service connections fail.

DE102021127360B4Active Publication Date: 2025-07-31HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
DE102021127360
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-04-01
Filing Date
2021-10-21
Publication Date
2025-07-31
Estimated Expiration
2041-10-21

AI Technical Summary

Technical Problem

Existing IPsec tunnel connections in cloud environments are vulnerable to disruption due to the expiration of security keys when the connection to the cloud service fails, leading to unintended tunnel failures and network interruptions.

Method used

Implementing survivability tunnels that function as a failover mechanism, allowing secure communication to continue even when the connection to the cloud service is lost by using legacy IKE/IPsec tunnels with factory authentication, enabling devices to maintain connectivity without relying on continuous cloud service access.

Benefits of technology

Ensures uninterrupted secure communication by automatically switching to survivability tunnels when cloud connectivity is compromised, preventing network disruptions and maintaining IPsec tunnel functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method comprising:establishing, by an initiator device (208a, 208b), an encrypted tunnel between the initiator device and a responder device (206a, 206b) of a cloud service based on a set of parameters received from the cloud service;determining, by the initiator device, whether there is a loss of connectivity of the initiator device or the responder device to the cloud service, wherein the cloud service supports respective communication connections (215a, 215b, 216a, 216b) to the responder device and the initiator device via a network (210) associated with the cloud service;In response to determining the loss of connectivity due to not receiving a response from the cloud service to a message sent by the initiator device or the responder device for rekeying the encrypted tunnel, establishing a survivability tunnel (270a, 270b) between the initiator device and the responder device, bypassing the network associated with the cloud service by the initiator device using the encrypted tunnel parameter set; and In response to determining that the survivability tunnel is successfully established, communicatively coupling the initiator device and the responder device via the survivability tunnel as a failover to the encrypted tunnel.
Need to check novelty before this filing date? Find Prior Art

Claims

[1] A method comprising: Establishing, by an initiator device (208a, 208b), an encrypted tunnel between the initiator device and a responder device (206a, 206b) of a cloud service based on a set of parameters received from the cloud service; Determining, by the initiator device, whether there is a loss of connectivity of the initiator device or the responder device to the cloud service, wherein the cloud service supports communication connections (215a, 215b, 216a, 216b) to the responder device and the initiator device, respectively, via a network (210) associated with the cloud service; in response to determining the loss of connectivity due to not receiving a response from the cloud service to a message sent by the initiator device or the responder device for re-keying the encrypted tunnel, establishing a survivability tunnel (270a, 270b) between the initiator device and the responder device, bypassing the network associated with the cloud service by the initiator device using the encrypted tunnel parameter set; and in response to determining that the survivability tunnel is successfully established, communicatively coupling the initiator device and the responder device via the survivability tunnel as a failover to the encrypted tunnel. [2] The method of claim 1, wherein the encrypted tunnel is a cloud-based Internet Protocol Security (IPsec) tunnel (260a, 260b) established via the cloud service. [3] The method of claim 1, wherein the survivability tunnel is a legacy IPsec tunnel established using Internet Key Exchange (IKE) authentication. [4] The method of claim 3, further comprising detecting an error in establishing a new cloud-based security association (SA) using a tunnel configuration provided by the cloud service before expiration of a current key associated with the encrypted tunnel. [5] The method of claim 1, further comprising: Determining the loss of connectivity to the cloud service by identifying failed attempts to reestablish a connection between the initiator device and the cloud service or the responder device and the cloud service; and Establishing the survivability tunnel between the initiator device and the responder device, bypassing the network associated with the cloud service by the initiator device using the encrypted tunnel parameter set. [6] The method of claim 1, wherein manufacturing the survivability tunnel further comprises: Creating a legacy encrypted tunnel using the parameter set received from the cloud service, bypassing the network associated with the cloud service; and Authenticate the responder device using certificate-based authentication. [7] The method of claim 1, further comprising forwarding traffic from the initiator device to the responder device via the survivability tunnel. [8] The method of claim 1, further comprising: Determine whether connectivity to the cloud service has been restored; and in response to determining that connectivity to the cloud service has been restored, switching from the survivability tunnel to the encrypted tunnel for communication between the initiator device and the responder device. [9] The method according to claim 1 further comprises: in response to the determination that the survivability tunnel was not successfully constructed, make an additional attempt to construct the survivability tunnel. [10] A computer system (500) comprising: a processor (302, 402, 504); a storage device (510); a non-transitory computer-readable storage medium (301, 404, 506) storing instructions that, when executed by the processor, cause the processor to: to operate as a first network device associated with a cloud service; establish an encrypted tunnel between the first network device and a second network device connected to the cloud service based on a set of parameters received from the cloud service; determine whether there is a loss of connectivity to the cloud service from the first or second network device, wherein the cloud service supports respective communication connections (215a, 215b, 216a, 216b) to the first and second network devices via a network (120, 210) associated with the cloud service; in response to determining the loss of connectivity due to not receiving a response from the cloud service for a message sent from the first or second network device for re-keying the encrypted tunnel, establishing a survivability tunnel (270a, 270b) between the first and second network devices bypassing the network associated with the cloud service using the set of parameters; and in response to determining that the survivability tunnel has been successfully established, communicatively couple the first network device and the second network device to the encrypted tunnel via the survivability tunnel as a failover. [11] The computer system of claim 10, wherein the parameter set is received from a tunnel orchestration (250) of the cloud service. [12] The computer system of claim 10, wherein the survivability tunnel comprises a legacy Internet Protocol Security (IPSec) tunnel (260a, 260b) established using Internet Key Exchange (IKE) authentication. [13] The computer system of claim 12, wherein the survivability tunnel structure further comprises: Creating a legacy encrypted tunnel using the parameter set received from the cloud service, bypassing the network associated with the cloud service; and Authenticating the second network device using certificate-based authentication. [14] The computer system of claim 10, wherein the first or second network device comprises at least one of the following devices: a gateway (134, 144), a branch gateway (208a, 208b), a virtual private network (VPN) concentrator (206a, 206b), a switch (108, 138), a firewall device, a server (160, 204, 206), and a workstation. [15] A non-transitory, computer-readable storage medium (301, 404, 506) having stored thereon executable instructions which, when executed by a processor (302, 402, 504), perform the following operations: Establishing an encrypted tunnel between an initiator device (208a, 208b) and a responder device (206a, 206b) of a cloud service based on a set of parameters received from the cloud service; Determining whether there is a loss of connectivity from an initiator device or a responder device to the cloud service, wherein the cloud service supports communication connections (215a, 215b, 216a, 216b) to the initiator device and the responder device, respectively, via a network (120, 210) associated with the cloud service; in response to determining the loss of connectivity due to not receiving a response from the cloud service to a message sent by the initiator device or the responder device for re-keying the encrypted tunnel, establishing a survivability tunnel (270a, 270b) using the parameter set between the initiator device and the responder device, bypassing the network associated with the cloud service; and in response to determining that the survivability tunnel is successfully established, communicatively coupling the initiator device and the responder device via the survivability tunnel as a failover to the encrypted tunnel. [16] The non-transitory computer-readable storage medium of claim 15, wherein the instructions further comprise: Determining the loss of connectivity to the cloud service by detecting failed attempts to reestablish a connection between the initiator device and the cloud service or the responder device and the cloud service; and Establishing the survivability tunnel between the initiator device and the responder device, bypassing the network associated with the cloud service by the initiator device using the encrypted tunnel parameter set. [17] The non-transitory computer-readable storage medium of claim 16, wherein the instructions further comprise detecting an error in establishing a new cloud-based security association (SA) using a tunnel configuration provided by the cloud service before expiration of a current key associated with the encrypted tunnel. [18] The non-transitory computer-readable storage medium of claim 15, wherein the survivability tunnel comprises a legacy Internet Protocol Security (IPsec) tunnel (260a, 260b) established using Internet Key Exchange (IKE) authentication. [19] The non-transitory computer-readable storage medium of claim 15, wherein forming the survivability tunnel further comprises: Creating a legacy encrypted tunnel using the parameter set received from the cloud service, bypassing the network associated with the cloud service; and Authenticate the responder device using certificate-based authentication. [20] The non-transitory computer-readable storage medium of claim 15, wherein the instructions further comprise: Determine whether connectivity to the cloud service has been restored; and in response to determining that connectivity to the cloud service has been restored, switching from the survivability tunnel to the encrypted tunnel for communication between the initiator device and the responder device.

Citation Information

Patent Citations

  • US000010887284B1

  • Method and apparatus for automatic configuration and management of a virtual private network

    US20050193103A1

  • System and method for secure cloud service delivery with prioritized services in a network environment

    US20130311778A1

  • High availability and failover

    US20160210209A1

  • Method and system of resiliency in cloud-delivered sd-wan

    US20200127905A1