Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8 results about "Internet Key Exchange" patented technology

In computing, Internet Key Exchange (IKE, sometimes IKEv1 or IKEv2, depending on version) is the protocol used to set up a security association (SA) in the IPsec protocol suite. IKE builds upon the Oakley protocol and ISAKMP. IKE uses X.509 certificates for authentication ‒ either pre-shared or distributed using DNS (preferably with DNSSEC) ‒ and a Diffie–Hellman key exchange to set up a shared session secret from which cryptographic keys are derived. In addition, a security policy for every peer which will connect must be manually maintained.

A Hybrid Quantum-Resistant Security Enhancement Method for IPSec VPN

PendingCN122372190AKey exchangeData pack
This invention proposes a hybrid quantum-resistant security enhancement method for IPSec VPNs. The method includes: intercepting Internet Key Exchange (ITE) packets and adding a proxy header between the transport layer header and the ISE payload of the packets; obtaining a quantum key from a key pool using quantum key distribution technology and generating a first-stage session key based on the quantum key; protecting the ISE key negotiation process using a quantum-resistant cryptographic algorithm to generate a second-stage session key; and using the first-stage and second-stage session keys as input parameters for a key derivation function to generate a final session key for encrypted data transmission. This invention, without modifying the original IPSec negotiation process, supports dynamic key combinations of different security levels, enhancing the quantum security protection capability of VPN data transmission while maintaining system flexibility and performance.
Owner:CHINA MOBILE COMM GRP CO LTD +3

Network key exchange negotiation method, apparatus and network device

ActiveCN115941171BKey distribution for secure communicationInternet Key ExchangeNetwork key
The present disclosure provides a network key exchange negotiation method, device and network equipment. The method comprises: obtaining user configuration information, the user configuration information comprising negotiation role information, negotiation policy information and SA information; the negotiation policy information being used to indicate a first policy adopted in negotiation, a policy effective time of the first policy, at least one second policy adopted in negotiation and a policy update time and a policy invalidation time of each second policy; when the negotiation role is an initiator and the policy effective time is reached, performing an Internet Key Exchange (IKE) negotiation based on the first policy to determine an SA; saving the SA in a database; whenever the policy update time is reached, performing an IKE negotiation based on the second policy corresponding to the policy update time to update the SA in the database; and when the policy invalidation time is reached, performing invalidation processing on the first policy, the second policy and the SA in the database.
Owner:WUHAN MARITIME COMMUNICATION RESEARCH INSTITUTE

Method for quantum-resistant security enhancement to internet key exchange protocol

PCT designated stageWO2026020566A1Multiple keys/algorithms usageCryptographic attack countermeasuresKey exchangeInternet Key Exchange
A method for quantum-resistant security enhancement to an Internet key exchange protocol, comprising: (011) performing key agreement with a second network device to generate an initial key; (012) acquiring a quantum key from a first network node; (013) performing post-quantum password encryption on the quantum key, and sending to the second network device a first encryption result that has undergone encryption; (014) performing decryption on a received second encryption result, and obtaining a second decryption result; and, (015) on the basis of a first quantum key, a first encryption key, a first verification key, a first derivation key, the first encryption result, and the second decryption result, generating a second encryption key, a second verification key, and a second derivation key, so as to encrypt communication between a first network device and the second network device.
Owner:CHINA TELECOM QUANTUM INFORMATION TECH GRP CO LTD

Scalable IPSec services

An Internet Key Exchange protocol message indicating a first Internet Protocol Security traffic flow is to be established via a first device is obtained at the first device. The Internet Key Exchange protocol message is forwarded from the first device to a second device. An encryption key used to transmit traffic via the first Internet Protocol Security Traffic flow is received at the first device from a key value store. The key value store is populated with the encryption key in response to the second device obtaining the Internet Key Exchange protocol message. A first data packet to be transmitted via the first Internet Protocol Security traffic flow is obtained at the first device. The first device provides the first data packet encrypted with the encryption key of the first Internet Protocol Security traffic flow.
Owner:CISCO TECHNOLOGY INC

Method for simplified atsss operations using null encryption over non-3GPP access

PendingUS20260075663A1Connection managementSecurity arrangementSession managementInternet Key Exchange
Various systems, apparatuses, and methods for Establishment of multi-access (MA) protocol data unit (PDU) Sessions using multipath (MP) QUIC based steering, switching, and splitting are provided. A user equipment (UE) requests a MA PDU Session. A session management function (SMF) determines that only MP QUIC steering is used. The SMF signals a non-third generation partnership project (non-3GPP) interworking function (N3IWF) to set up one or more user plane resources over one or more internet protocol (IP) security (IP Sec) tunnels with null encryption. The MA PDU session excludes standard IPSec encryption for user data. The N3IWF performs internet key exchange (IKE) signaling with the UE to negotiate the one or more IP Sec tunnels with null encryption. The N3IWF transparently transmits user data without applying IPSec encryption.
Owner:CABLE TELEVISION LAB INC

QUANTUM CRYPTOGRAM IN AN INTERNET KEY EXCHANGE METHOD

ActiveDE602022040124T2Internet Key ExchangeThe Internet
Owner:JUNIPER NETWORKS INC

System and method to securely distribute authenticated and trusted data streams to ai systems

The method provides for dynamic retrieval of certificates, with remote, secure, and scalable lifecycle management. It enables the importation, distribution, renewal, and rekey of leaf certificates and associated private keys to applications executing on devices with two-factor authentication for devices. It is an agentless method to achieve device protection, application security, and data protection with data authenticity and confidentiality in intra-device, inter-device, device-to-edge, and device-to-cloud communications. It helps Transport Layer Security (TLS) and Internet Key Exchange (IKE) enabled applications retrieve leaf certificates and the associated private key, and verify certificates, programmatically for certificate-based authentication during protocol handshake, with policy-based authorization of trusted applications. It enables applications and command line utilities retrieve and use leaf certificates for mutual authentication, data signing with digital signatures, and key unwrapping. It further enables dynamic retrieval of trusted intermediate and root certificates.
Owner:SYMMERA INC

Methods and apparatuses for managing internet key exchange between internet protocol security endpoints

PCT designated stageWO2026082282A1Securing communicationAccess networkInternet Key Exchange
Embodiments descried herein relate to a method and apparatus for managing internet key exchange between internet protocol security endpoints. A method, performed by a first Radio Access Network, RAN, entity, for applying transport security in transmitting data between the first RAN entity and a second RAN entity, the first RAN entity being associated with a plurality of first entity IP addresses, and the second RAN entity being associated with a plurality of second entity IP addresses. The method comprises setting up a first internet key exchange, IKE, security association, SA, between a first Internet Protocol, IP, address of the first entity IP addresses and a second IP address of the second entity IP addresses; and utilizing the first IKE SA to negotiate a plurality of first child SA pairs, wherein the plurality of first child SA pairs are set up between first child IP addresses of the plurality of first entity IP addresses and second child IP addresses of the plurality of second entity IP addresses.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)