Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

20 results about "Internet Key Exchange" patented technology

In computing, Internet Key Exchange (IKE, sometimes IKEv1 or IKEv2, depending on version) is the protocol used to set up a security association (SA) in the IPsec protocol suite. IKE builds upon the Oakley protocol and ISAKMP. IKE uses X.509 certificates for authentication ‒ either pre-shared or distributed using DNS (preferably with DNSSEC) ‒ and a Diffie–Hellman key exchange to set up a shared session secret from which cryptographic keys are derived. In addition, a security policy for every peer which will connect must be manually maintained.

Methods and apparatus for channel access in a multi-link wireless system

Methods and systems for securely sending user plane data from a base station to an Artificial Intelligence (AI) server via a mobile telecommunication network are disclosed herein. A method performed by the base station located in a Radio Access Network (RAN) includes: sending an interface setup request to the (AI) server, receiving an interface setup response from the AI server, establishing, by exchanging cryptographic keys using an Internet Key Exchange (IKE) protocol, a data transport tunnel between the base station and the AI server based on an Internet Protocol Security (IPSec) network protocol, and sending the user plane data from the base station to the AI server for training artificial intelligence based models.
Owner:ZTE CORP

A Hybrid Quantum-Resistant Security Enhancement Method for IPSec VPN

PendingCN122372190AKey exchangeData pack
This invention proposes a hybrid quantum-resistant security enhancement method for IPSec VPNs. The method includes: intercepting Internet Key Exchange (ITE) packets and adding a proxy header between the transport layer header and the ISE payload of the packets; obtaining a quantum key from a key pool using quantum key distribution technology and generating a first-stage session key based on the quantum key; protecting the ISE key negotiation process using a quantum-resistant cryptographic algorithm to generate a second-stage session key; and using the first-stage and second-stage session keys as input parameters for a key derivation function to generate a final session key for encrypted data transmission. This invention, without modifying the original IPSec negotiation process, supports dynamic key combinations of different security levels, enhancing the quantum security protection capability of VPN data transmission while maintaining system flexibility and performance.
Owner:CHINA MOBILE COMM GRP CO LTD +3

Data transmission method and device

The embodiment of the invention provides a data transmission method and device, and relates to the technical field of quantum communication, and the method applied to a first device in communication connection with a quantum server comprises the following steps: establishing an Internet Key Exchange Security Association (IKESA) with a second device, the second device being in communication connection with the quantum server; a key application request is sent to the quantum server, a first quantum key fed back by the quantum server is received, and the first quantum key is generated by the quantum server based on a quantum key distribution (QKD) protocol; establishing an internet protocol security association (IPSecSA) with the second equipment; and encrypting the first to-be-sent data based on the first quantum key, and sending the encrypted data to the second device through an IPSec tunnel formed after the IPSec SA is established. By applying the scheme provided by the embodiment of the invention, the security of data transmission between equipment can be improved.
Owner:NEW H3C TECH CO LTD

IPSEC traversal of dynamic NAT and DVPN network

This invention relates to the field of communication technology, providing a method for IPsec traversal of dynamic NAT and a DVPN network. The method includes: a central device establishing IPsec tunnels with a first branch device and a second branch device respectively, and recording the address and port information of these two branch devices before and after NAT translation; when the central device receives a request from the first branch device to obtain network information of the second branch device, it sends the address and port information of the second branch device before and after translation to the first branch device, and vice versa; upon receiving the information, the second branch device sends a UDP packet to the first NAT device, causing the NAT device to create an entry for the first branch device to connect the communication link between the two branch devices; upon receiving the information, the first branch device negotiates an Internet key exchange with the second branch device to establish the IPsec tunnel between the two branch devices. This achieves traversal of dynamic NAT in the MGRE over IPsec scenario.
Owner:MAIPU COMM TECH CO LTD

Decentralized internet protocol security key negotiation

Methods are provided for decentralized key negotiation. One method includes initiating, by a first Internet Key Exchange (IKE) node from among a plurality of IKE nodes, a rekeying process for an Internet Protocol Security (IPSec) communication session established with a client device and serviced by a second IKE node from among the plurality of IKE nodes, and in which a first encryption key is used to encrypt traffic. The method further includes obtaining, by the first IKE node from a key value store, information about the IPSec communication session and performing, by the first IKE node, at least a part of the rekeying process in which the first encryption key is replaced with a second encryption key for the IPSec communication session.
Owner:CISCO TECHNOLOGY INC

Decentralized internet protocol security key negotiation

Methods are provided for decentralized key negotiation. One method includes initiating, by a first Internet Key Exchange (IKE) node from among a plurality of IKE nodes, a rekeying process for an Internet Protocol Security (IPSec) communication session established with a client device and serviced by a second IKE node from among the plurality of IKE nodes, and in which a first encryption key is used to encrypt traffic. The method further includes obtaining, by the first IKE node from a key value store, information about the IPSec communication session and performing, by the first IKE node, at least a part of the rekeying process in which the first encryption key is replaced with a second encryption key for the IPSec communication session.
Owner:CISCO TECHNOLOGY INC

Network key exchange negotiation method, apparatus and network device

ActiveCN115941171BKey distribution for secure communicationInternet Key ExchangeNetwork key
The present disclosure provides a network key exchange negotiation method, device and network equipment. The method comprises: obtaining user configuration information, the user configuration information comprising negotiation role information, negotiation policy information and SA information; the negotiation policy information being used to indicate a first policy adopted in negotiation, a policy effective time of the first policy, at least one second policy adopted in negotiation and a policy update time and a policy invalidation time of each second policy; when the negotiation role is an initiator and the policy effective time is reached, performing an Internet Key Exchange (IKE) negotiation based on the first policy to determine an SA; saving the SA in a database; whenever the policy update time is reached, performing an IKE negotiation based on the second policy corresponding to the policy update time to update the SA in the database; and when the policy invalidation time is reached, performing invalidation processing on the first policy, the second policy and the SA in the database.
Owner:WUHAN MARITIME COMMUNICATION RESEARCH INSTITUTE

Network attack protection method and device, electronic equipment and storage medium

The present disclosure relates to a network attack protection method and device, electronic equipment and storage medium, the method comprising: obtaining an initial message to be sent and a random payload, the payload type of the random payload being one of the Internet Key Exchange (IKE) payload reserved types; generating a new message based on the initial message and the random payload; and sending the new message to a receiving end. The present disclosure achieves the fuzzing of the IKE message, so that a malicious terminal cannot identify the IKE message without knowing the IP of the network device. Furthermore, even if the intercepted message is identified as an IKE message, the network device cannot be accurately located, increasing the difficulty of identifying the network device, thereby avoiding the risk of malicious cracking and attack on the network device.
Owner:COMBA TELECOM SYST CHINA LTD

Method for quantum-resistant security enhancement to internet key exchange protocol

PCT designated stageWO2026020566A1Multiple keys/algorithms usageCryptographic attack countermeasuresKey exchangeInternet Key Exchange
A method for quantum-resistant security enhancement to an Internet key exchange protocol, comprising: (011) performing key agreement with a second network device to generate an initial key; (012) acquiring a quantum key from a first network node; (013) performing post-quantum password encryption on the quantum key, and sending to the second network device a first encryption result that has undergone encryption; (014) performing decryption on a received second encryption result, and obtaining a second decryption result; and, (015) on the basis of a first quantum key, a first encryption key, a first verification key, a first derivation key, the first encryption result, and the second decryption result, generating a second encryption key, a second verification key, and a second derivation key, so as to encrypt communication between a first network device and the second network device.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

System and method for optimized authentication in communication networks

PCT designated stageWO2025235753A1Security arrangementSecuring communicationKey exchangeInternet Key Exchange
The disclosed method and system optimize IPSec connectivity and security association establishment in trusted and / or untrusted non-3GPP access scenarios, such as non-3GPP access with a Trusted Non-3GPP Gateway Function (TNGF) and / or Non-3GPP Interworking Function (N3IWF) in a 5G network architecture. The method involves initiating an Internet Key Exchange (IKE) protocol initiation communication from the User Equipment (UE) to the TNGF or N3IWF, which includes a MOBIKE_SUPPORT indicator to signal the UE's MOBIKE capability. The TNGF or N3IWF, in response to the MOBIKE_SUPPORT indicator, enables the use of MOBIKE to optimize an Internet Protocol Security (IPSec) session re- establishment when the UE moves to a different Trusted Non-3GPP Access Point (TNAP) connected to the same TNGF. The system includes the UE and TNGF configured to perform the method. The method and system minimize disruptions and latency during IPSec session re- establishment.
Owner:CHARTER COMM OPERATING LLC

Bypassing the IKE firewall for cloud-managed IPSEC keys in the SDWAN fabric

ActiveDE102022108628B4Data taking preventionNetworks interconnectionData packInternet Key Exchange
A procedure that includes: at a first network device (120, 122) between a second network device (112) and a third network device (154), detecting an Internet Key Exchange Protocol (IKE) key negotiation between the second network device and the third network device; based on the detection of the IKE key negotiation! between the second network device and the third network device, creating a firewall session in the first network device between the second and the third network device, wherein a first Internet Protocol Security (IPSec) tunnel (212) is established by the first network device between the second and the third network device using the IKE key negotiation, the first tunnel being compliant with the firewall session and allowing the passage of IPSec data packets through the first network device between the second and the third network device; Passing the IPSec data packets exchanged between the second and third network devices through the first network device based on the establishment of the first tunnel using cloud-managed IPSec keys from a cloud-based orchestrator (142), wherein the IPSec data packets are exchanged as part of a handshake operation that results in the establishment of a second tunnel between the second and third network devices according to the cloud-managed IPSec keys, the second tunnel being an overlay tunnel (218) on an underlay network; and After the second tunnel has been established and the cloud-managed IPSec keys are active, discard the negotiated IKE and carefully dismantle the first IPSec tunnel without disrupting encrypted communication between the second and third network devices.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Method and apparatus for secure connection between artificial intelligence server and base station node

Disclosed herein are methods and systems for securely sending user plane data from a base station to an artificial intelligence (AI) server via a mobile telecommunication network. In one embodiment, a method performed by a base station located in a radio access network (RAN) includes sending an interface setup request to an (AI) server, receiving an interface setup response from the AI server, establishing an Internet Protocol Security (IPSec) network protocol based data transfer tunnel between the base station and the AI server by exchanging encryption keys using an Internet Key Exchange (IKE) protocol, and sending user plane data from the base station to the AI server for training an artificial intelligence based model.
Owner:ZTE CORP

Scalable IPSec services

An Internet Key Exchange protocol message indicating a first Internet Protocol Security traffic flow is to be established via a first device is obtained at the first device. The Internet Key Exchange protocol message is forwarded from the first device to a second device. An encryption key used to transmit traffic via the first Internet Protocol Security Traffic flow is received at the first device from a key value store. The key value store is populated with the encryption key in response to the second device obtaining the Internet Key Exchange protocol message. A first data packet to be transmitted via the first Internet Protocol Security traffic flow is obtained at the first device. The first device provides the first data packet encrypted with the encryption key of the first Internet Protocol Security traffic flow.
Owner:CISCO TECHNOLOGY INC

Methods for enhancements on message coding in secured communication session over non-3GPP access

Various solutions for enhancements on message coding in secured communication session over non-third generation partnership project (3GPP) access are described. An apparatus may connect to a non-3GPP access network. Then, the apparatus may receive an internet key exchange (IKE) authentication response message from a network node in a 3GPP network via the non-3GPP access network. Also, the apparatus may transmit an IKE authentication request message to the network node in the 3GPP network via the non-3GPP access network. The IKE authentication request message may include an extensible authentication protocol (EAP) response or a fifth generation (5G) non-access stratum (NAS) message which includes a first indication of whether an access network (AN)-parameters field is absent or present in the EAP response or the 5G NAS message.
Owner:MEDIATEK INC

Method for simplified atsss operations using null encryption over non-3GPP access

PendingUS20260075663A1Connection managementSecurity arrangementSession managementInternet Key Exchange
Various systems, apparatuses, and methods for Establishment of multi-access (MA) protocol data unit (PDU) Sessions using multipath (MP) QUIC based steering, switching, and splitting are provided. A user equipment (UE) requests a MA PDU Session. A session management function (SMF) determines that only MP QUIC steering is used. The SMF signals a non-third generation partnership project (non-3GPP) interworking function (N3IWF) to set up one or more user plane resources over one or more internet protocol (IP) security (IP Sec) tunnels with null encryption. The MA PDU session excludes standard IPSec encryption for user data. The N3IWF performs internet key exchange (IKE) signaling with the UE to negotiate the one or more IP Sec tunnels with null encryption. The N3IWF transparently transmits user data without applying IPSec encryption.
Owner:CABLE TELEVISION LAB INC

QUANTUM CRYPTOGRAM IN AN INTERNET KEY EXCHANGE METHOD

ActiveDE602022040124T2Internet Key ExchangeThe Internet
Owner:JUNIPER NETWORKS INC

A method and apparatus for establishing a VPN tunnel based on traffic triggering

This application belongs to the field of network encryption technology, specifically disclosing a VPN tunnel establishment method and apparatus based on traffic triggering. This application, through minor modifications to the existing IKE negotiation process, sends a first negotiation probe packet to a first terminal, enabling a second VPN encryption device to intercept the first negotiation probe packet and initiate an Internet Key Exchange (IKEY) process with the first VPN encryption device. The first VPN encryption device, by responding to the IKEY process, configures its interoperability policy with the second VPN encryption device or extends the interoperability policy, obtaining a third negotiation probe packet. This allows the second VPN encryption device to obtain its session key with the first VPN encryption device based on the third negotiation probe packet, completing the VPN tunnel establishment. This achieves configuration-free interoperability policy configuration between VPN encryption devices, reducing the complexity of manual configuration and improving configuration efficiency.
Owner:WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)

System and method to securely distribute authenticated and trusted data streams to ai systems

The method provides for dynamic retrieval of certificates, with remote, secure, and scalable lifecycle management. It enables the importation, distribution, renewal, and rekey of leaf certificates and associated private keys to applications executing on devices with two-factor authentication for devices. It is an agentless method to achieve device protection, application security, and data protection with data authenticity and confidentiality in intra-device, inter-device, device-to-edge, and device-to-cloud communications. It helps Transport Layer Security (TLS) and Internet Key Exchange (IKE) enabled applications retrieve leaf certificates and the associated private key, and verify certificates, programmatically for certificate-based authentication during protocol handshake, with policy-based authorization of trusted applications. It enables applications and command line utilities retrieve and use leaf certificates for mutual authentication, data signing with digital signatures, and key unwrapping. It further enables dynamic retrieval of trusted intermediate and root certificates.
Owner:SYMMERA INC

System and method for optimized authentication in communication networks

PendingUS20250351013A1Wireless network protocolsTransmissionInternet Key ExchangeSecurity association
The disclosed method and system optimize IPSec connectivity and security association establishment in trusted and / or untrusted non-3GPP access scenarios, such as non-3GPP access with a Trusted Non-3GPP Gateway Function (TNGF) and / or Non-3GPP Interworking Function (N3IWF) in a 5G network architecture. The method involves initiating an Internet Key Exchange (IKE) protocol initiation communication from the User Equipment (UE) to the TNGF or N3IWF, which includes a MOBIKE_SUPPORT indicator to signal the UE's MOBIKE capability. The TNGF or N3IWF, in response to the MOBIKE_SUPPORT indicator, enables the use of MOBIKE to optimize an Internet Protocol Security (IPSec) session re-establishment when the UE moves to a different Trusted Non-3GPP Access Point (TNAP) connected to the same TNGF. The system includes the UE and TNGF configured to perform the method. The method and system minimize disruptions and latency during IPSec session re-establishment.
Owner:CHARTER COMM OPERATING LLC

Methods and apparatuses for managing internet key exchange between internet protocol security endpoints

PCT designated stageWO2026082282A1Securing communicationAccess networkInternet Key Exchange
Embodiments descried herein relate to a method and apparatus for managing internet key exchange between internet protocol security endpoints. A method, performed by a first Radio Access Network, RAN, entity, for applying transport security in transmitting data between the first RAN entity and a second RAN entity, the first RAN entity being associated with a plurality of first entity IP addresses, and the second RAN entity being associated with a plurality of second entity IP addresses. The method comprises setting up a first internet key exchange, IKE, security association, SA, between a first Internet Protocol, IP, address of the first entity IP addresses and a second IP address of the second entity IP addresses; and utilizing the first IKE SA to negotiate a plurality of first child SA pairs, wherein the plurality of first child SA pairs are set up between first child IP addresses of the plurality of first entity IP addresses and second child IP addresses of the plurality of second entity IP addresses.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)