Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

137 results about "IPsec" patented technology

In computing, Internet Protocol Security (IPsec) is a secure network protocol suite that authenticates and encrypts the packets of data sent over an Internet Protocol network. It is used in virtual private networks (VPNs).

End-to-end encryption with per-hop path-selection based on unique edge identities for sd-wan and multi-hop networks

A system and associated methods provide solutions for end-to-end privacy and per-hop routing and policy decision in multi-hop and Software-Defined Wide Area Networks (SD-WANs) by leveraging unique SDWAN edge identities of edge devices. The system enables end-to-end encryption between traffic source and destination sites using IPsec ESP tunnel mode, with System IPs as the outer IP addresses. The system further enables per-hop integrity protection using IPsec AH transport mode, with WAN IPs as the outer IP addresses. By having some information encrypted between a source device and a destination device and other information encapsulated between hops (e.g., between source device and an intermediate device), the system enables route and policy lookup based on destination site System-IP, along with integrity protection based on SLA-class in packet metadata for independent path selection at intermediate hops.
Owner:CISCO TECHNOLOGY INC

Quantum key fused block encryption method, communication system and evaluation method thereof

The invention discloses a quantum key fused block encryption method, a communication system and an evaluation method thereof, and the method comprises the steps: fusing a quantum key generated by quantum key division into an Internet key exchange protocol of IPsec to form a mixed key; the sender and the receiver carry out message transmission through the mixed key, the authentication head and the packaging security load, so that the quantum key is integrated into the IPsec framework; and meanwhile, different quantum keys are used in each VPN channel, so that one-time pad is realized. In addition, the invention further provides a method for evaluating the performances such as the key consumption rate, the maximum supportable VPN tunnel number and the total throughput. According to the invention, the security and stability of data transmission in the quantum computer era can be improved.
Owner:NANJING UNIV OF POSTS & TELECOMM +1

IPSec VPN security gateway communication method based on post quantum cryptography

The invention discloses an IPSec VPN security gateway communication method based on a post quantum cryptography technology, and the method comprises the following steps: S1, replacing a conventional SM2 algorithm and a certificate with a PQC algorithm and a digital certificate in a first-stage main mode of IKE key negotiation; s2, the initiator and the responder respectively use the PQC key pair to complete key exchange and signature; s3, in the message 1, the initiator sends a security alliance load containing a PQC public key algorithm attribute to the responder; s4, in the message 2, the responder sends an SA load containing a PQC signature certificate and an encryption certificate, and a received SA proposal sent by the initiator is marked; s5, in the message 3 and the message 4, the initiator and the responder complete key exchange and verification; and S6, in the message 5 and the message 6, the initiator and the responder encrypt the transmitted information by using a symmetric cryptographic algorithm, and identify the previous exchange process. According to the invention, the security of the IPSec VPN security gateway is improved, and quantum computing attacks can be resisted.
Owner:HEBEI PRIME NUMBER INFORMATION SECURITY CO LTD +1

Methods and related devices for secure transmission of messages

This application provides a method for secure message transmission, a method for negotiating IPsec SAs, and related apparatus, applicable to wide area networks (WANs). In scenarios spanning multiple tunnel segments, by extending BGP routing and based on VRF granularity, an IPsec SA for end-to-end security protection is negotiated between a first edge and a second edge. After the first edge securely protects VPN service messages based on the IPsec SA, it sends the messages through the overlay end-to-end tunnel between the first and second edges. The second edge processes the messages based on the IPsec SA to obtain the VPN service messages. In this application, security protection only needs to be performed once at the first edge; intermediate nodes do not require encryption / decryption processing, thus ensuring secure message transmission while improving transmission efficiency and reducing transmission latency.
Owner:HUAWEI TECH CO LTD

Anti-quantum computing IPSEC key exchange method

The invention relates to an IPSEC (Internet Protocol Security) key exchange method resistant to quantum computing. According to the invention, based on a lattice cryptographic algorithm and improved SM4-256 symmetric encryption, secure communication between a master mode and a fast mode is realized; in the main mode, an initiator sends an IKE first message through a UDP (User Datagram Protocol), negotiates SA parameters with a responder and exchanges a lattice password certificate; the two parties encapsulate a temporary 32-byte secret key by using the public key of the opposite party, generate a 512-bit random number through SM4-256 encryption, and sign and transmit the 512-bit random number to realize secure random number exchange and certificate verification; and the two parties calculate a first session key based on a PRF (Pseudo Random Function), and encrypt an exchange data HASH value to complete main mode key consistency confirmation. And after entering the fast mode, taking the main mode session key as an SM4-256 symmetric key to continue communication, sending an SA message carrying a 512-bit random number by the two parties, calculating to obtain a second session key, and establishing an ESP tunnel. According to the method, the security of IPSEC under the threat of quantum computing is improved through the lattice password.
Owner:JIANGSU IDEABANK MICROELECTRONICS TECH

Password algorithm adaptation and hardware encryption and decryption acceleration method suitable for gateway protocol

The invention discloses a cryptographic algorithm adaptation and hardware encryption and decryption acceleration method suitable for a gateway protocol, deep integration of a cryptographic algorithm is realized through protocol stack-level native transformation, software and hardware collaborative design is adopted, and through innovative mechanisms such as multi-thread concurrent encryption, asynchronous interrupt processing and DMA data interaction, the hardware encryption and decryption acceleration of the cryptographic algorithm is realized. The processing capability in a high throughput scene is improved; an intelligent strategy engine is introduced to realize data packet dynamic classification and encrypted resource optimization scheduling, and the system performance is maximized while the security is ensured; according to the technical scheme, key full-life-cycle management and control are achieved through the HSM, the requirement for equal insurance 2.0 is met, multi-platform deployment is supported by adopting modular design, and compared with the prior art, the method can be flexibly adapted to various application scenes such as various domestic chip architectures, embedded devices, security gateways and industrial controllers, and the method is suitable for large-scale popularization and application. The problems of high platform dependence, difficulty in transplantation and the like existing in national secret IPSec implementation are solved, and a better secure communication solution is provided for a localized environment.
Owner:XIDIAN UNIV HANGZHOU RES INST +1

Methods and apparatus for channel access in a multi-link wireless system

Methods and systems for securely sending user plane data from a base station to an Artificial Intelligence (AI) server via a mobile telecommunication network are disclosed herein. A method performed by the base station located in a Radio Access Network (RAN) includes: sending an interface setup request to the (AI) server, receiving an interface setup response from the AI server, establishing, by exchanging cryptographic keys using an Internet Key Exchange (IKE) protocol, a data transport tunnel between the base station and the AI server based on an Internet Protocol Security (IPSec) network protocol, and sending the user plane data from the base station to the AI server for training artificial intelligence based models.
Owner:ZTE CORP

Main and standby switching function implementation method for cloud platform IPsec VPN gateway

PendingCN120785728ATransmissionIPsecEngineering
The invention discloses a main-standby switching function implementation method for a cloud platform IPsec VPN gateway, and relates to the technical field of cloud computing. The method comprises the following steps of: establishing a main / standby switching system, automatically deploying an IPsec VPN server group in a VPC (Virtual Private Controller) needing to use an IPsec VPN service through a server deployment module according to a service specification required by a user, configuring a public network IP (Internet Protocol) for the IPsec VPN server group, and configuring main / standby switching parameters of the IPsec VPN server group after establishing the IPsec VPN server group through a main / standby switching initialization module; iPsec VPN gateway service configuration is issued to an IPsec VPN gateway server group through a configuration issuing module; the IPsec VPN servers in the IPsec VPN server group are polled through the configuration maintenance module, it is guaranteed that service configuration in the IPsec VPN servers is consistent with that of the IPsec VPN main server, and when the IPsec VPN main server breaks down, the main server and the standby server are switched through the main and standby switching module, so that the service configuration of the IPsec VPN servers in the IPsec VPN server group is ensured to be consistent with that of the IPsec VPN main server. The IPsec VPN server recovered from the fault is added into the IPsec VPN server group again through a fault recovery module; and the log alarm module is responsible for log recording and alarm work during IPsec VPN main / standby switching.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

System and method for early detection of duplicate security association of IPsec tunnels

In an embodiment, a method includes transmitting an initiation request from a first electronic device to a second electronic device, the initiation request being associated with a notification that the first electronic device is capable of early detection of duplicate security associations (SAs), receiving an initiation request from the second electronic device at the first electronic device, the initiation request being associated with a capability notification that the second electronic device is capable of early detection of duplicate SAs, determining a possibility of duplicate SAs by the first electronic device, transmitting responses configured to prevent duplicate SAs from the first electronic device to the second electronic device, receiving responses at the first electronic device from the second electronic device, wherein the responses indicate no duplicate SAs created by the second electronic device, and establishing a non-duplicate SA for the first and second electronic devices.
Owner:CISCO TECHNOLOGY INC

A high-performance IPSEC cache management device and management method

The application provides a high-performance IPSEC cache management device and method. The device comprises an input queue management module, a cache pool module, an IPSEC core module and an output queue management module. The method comprises: adding a first Cell containing a message header and message parsing information into a message header queue to be encrypted or decrypted by the input queue management module, and storing the remaining message content into a shared cache space of the cache pool module; performing encryption and decryption and hash operation on the message to be encrypted or decrypted by the IPSEC core module, and backfilling the encrypted and decrypted data into the shared cache of the cache pool module; and outputting the message data processed by the IPSEC core module from the cache pool module based on an output queue by the output queue management module. The technical scheme of the application realizes flexible scalability of IPSEC cache performance.
Owner:WUXI STARS MICRO SYSTEM TECHNOLOGIES CO LTD

IPSec anti-replay detection method based on multiple caches

The application relates to the field of network security, in particular to an IPSec anti-replay detection method based on multiple caches. The latest window information which has not been stored in DDR is cached by means of the cache space of FPGA. When the sn window information of the previous message is not updated in the algorithm decryption stage, the un-updated sn window information is stored in the cache space of FPGA, the anti-replay detection of the next message is not affected, the processing time of two messages is shortened to the algorithm processing time, the preparation time before the algorithm decryption is greatly compressed, the method has the characteristics of fast speed, less resource occupation and the like, and is suitable for devices which have strict performance requirements and need to perform anti-replay detection.
Owner:SHANDONG HUAYI MICRO ELECTRONICS

Communication method and communication apparatus

A communication method and a communication apparatus, which are used for implementing communication between a terminal and a core network by means of a unified non-3GPP access gateway, thereby reducing the complexity of network deployment. The method comprises: receiving a first message from a terminal, the first message being used for requesting authentication, connection establishment or connection release, and the first message being an internet protocol security (IPSec) message, or the first message being a quick user datagram protocol internet connection (QUIC) protocol message; and sending a second message to a control plane network element, the second message being a non-access stratum (NAS) message determined on the basis of the first message.
Owner:HUAWEI TECH CO LTD

Anti-replay window setting method, device, storage medium and electronic device

The present invention discloses a method, device, storage medium and electronic device for setting an anti-replay window. The method includes: receiving a target data packet; determining a target traffic throughput corresponding to the target data packet; obtaining a target window value from an analysis result table based on the target traffic throughput and a packet loss rate threshold, wherein the packet loss rate threshold is used to characterize the maximum packet loss rate corresponding to the first data packet discarded by the anti-replay window during verification of the target data packet, wherein the sequence number of the first data packet is less than the sequence number corresponding to the left boundary of the anti-replay window, and the anti-replay window is an IPsec VPN anti-replay window. The analysis result table includes at least multiple traffic throughputs, multiple window values, and the packet loss rate corresponding to each window value at each traffic throughput; and setting a target anti-replay window based on the target window value. The present invention solves the technical problem in the prior art of high network failure rate caused by the inability of the anti-replay window to adapt to changes in communication traffic.
Owner:HILLSTONE NETWORKS CO LTD +1

Computer and Network Interface Controller Securely Offloading Encryption Keys and Underlay IPsec Encryption Processing to the Network Interface Controller

Encryption operations are securely offloaded to a network interface controller (NIC). Encryption keys are securely transferred from a virtual machine (VM) to the NIC and data is securely transferred from encrypted VM memory to secure buffers in the NIC. The NIC handles the encryption and decryption operations in hardware, greatly increasing encryption performance while not reducing security. This is especially useful in cloud server environments, so the cloud service provider does not have access to the encryption keys or the unencrypted data. The offloaded operations are performed with numerous different communication protocols, including RDMA, QUIC, IPsec underlay and WireGuard.
Owner:DREAMBIG SEMICON INC

System and method for networking and internet protocol security (IPSec) measures for mobile ad hoc network (MANET) waveforms

A node of a network communicating via mobile ad hoc network (MANET) waveforms and incorporating internet protocol (IP) security (IPSec) measures includes a plaintext (PT) user system or host, ciphertext (CT) communications module including a radio system for transmission and reception via MANET waveforms, IPSec cryptographic units, and PT and CT convergence modules. IPSec units provide encryption and decryption of data traffic as well as cross-layer exchange between PT and CT convergence modules. PT convergence modules map output traffic and decrypted input traffic to CT capabilities and exchange reachability information (e.g., addresses of reachable nodes or systems) with counterpart PT convergence modules of peer nodes of the MANET. CT convergence modules converge encrypted input and output traffic based on CT capabilities.
Owner:ROCKWELL COLLINS INC

Base station activation method, communication apparatus, and storage medium

The application provides a base station activation method, a communication device and a storage medium, and relates to the technical field of communication. The method comprises the following steps: when a base station starts base station activation, an access platform sends a first parameter to the base station; the first parameter comprises a first verification parameter and an authentication parameter; the access platform performs authentication and authentication operations based on the first parameter, and sends a second parameter to the base station; the second parameter comprises a second verification parameter, and the second parameter is used for base station registration; the access platform performs base station registration operations based on the second parameter through an Internet Protocol Security (IPsec) tunnel, and sends a third parameter to the base station; the third parameter comprises a third verification parameter and a cell configuration parameter, and the third parameter is used for base station activation; and the access platform performs base station activation operations based on the third parameter through the IPsec tunnel, so that the base station is activated in a core network device, and the security of the network is improved.
Owner:BAICELLS TECH CO LTD

Continuous authentication of peers in networks using post-quantum pre-shared keys

PCT designated stage expiredWO2025183766A2Security arrangementSecuring communicationIPsecEngineering
Techniques and architecture are described for reauthentication of two IPsec peers,, during a key refresh process. The peers may reauthenticate each other based upon a shared secret, which in configurations, is a PPK. In configurations the PPKs are stirred (mixed with DH / ECDH) during key derivation while refreshing the session keys during IKE_v2 and IPsec rekey. This may involve communicating the PPK-ID from a rekey initiator to a rekey responder by adding a PPK_ID payload in the rekey message exchange. This enables stronger quantum safe session keys, when dynamic PPK is used or when the manual PPK is rotated frequently. In configurations, the knowledge of the shared PPK is proved by having both peers exchange authentication payloads signed with a PPK. This involves exchanging a IKEv2 NOTIFY payload "AUTH_PPK" to carry PPK-signed authentication data. This serves the purpose of frequent re-authentication of the peers as part of the key refreshes.
Owner:CISCO TECHNOLOGY INC

Computer and Network Interface Controller Offloading Encryption Processing to the Network Interface Controller and Using Derived Encryption Keys

Encryption operations are securely offloaded to a network interface controller (NIC). Encryption keys are securely transferred from a virtual machine (VM) to the NIC and data is securely transferred from encrypted VM memory to secure buffers in the NIC. The NIC handles the encryption and decryption operations in hardware, greatly increasing encryption performance while not reducing security. This is especially useful in cloud server environments, so the cloud service provider does not have access to the encryption keys or the unencrypted data. The offloaded operations are performed with numerous different communication protocols, including RDMA, QUIC, IPsec underlay and WireGuard.
Owner:DREAMBIG SEMICON INC

Mapping of ipsec tunnels to sd-wan segmentation

Generally, Software-Defined Wide Area Networks (SD-WAN) generally do not support network segmentation. The concepts disclosed herein connects IPSec SD-WAN fabric to a Virtual Routing and Forwarding (VRF) router and make use of a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec SD-WAN to various cloud services from the SDCI Router in the fabric. The concepts disclosed herein also provides for tunnel multi-plexing that takes incoming and outgoing traffic and maps VPNs to any service VRF associated with the cloud based services.
Owner:CISCO TECHNOLOGY INC

A Hybrid Quantum-Resistant Security Enhancement Method for IPSec VPN

PendingCN122372190AKey exchangeData pack
This invention proposes a hybrid quantum-resistant security enhancement method for IPSec VPNs. The method includes: intercepting Internet Key Exchange (ITE) packets and adding a proxy header between the transport layer header and the ISE payload of the packets; obtaining a quantum key from a key pool using quantum key distribution technology and generating a first-stage session key based on the quantum key; protecting the ISE key negotiation process using a quantum-resistant cryptographic algorithm to generate a second-stage session key; and using the first-stage and second-stage session keys as input parameters for a key derivation function to generate a final session key for encrypted data transmission. This invention, without modifying the original IPSec negotiation process, supports dynamic key combinations of different security levels, enhancing the quantum security protection capability of VPN data transmission while maintaining system flexibility and performance.
Owner:CHINA MOBILE COMM GRP CO LTD +3

Distributed IPsec gateway

The present disclosure provides technical solutions related to distributed IPSec gateway. A control plane and a data plane of the IPSec gateway are divided, a plurality of gateway processing nodes may be run in the data plane to process data packets of incoming ESP / AH traffic and / or data packets of outgoing IP traffic. IKE information interaction may be handled in the control plane and the traffic may be steered on each gateway processing node in the data plane.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

System and method for selecting internet protocol security tunnels during key exchange

Embodiments of the present disclosure relate to systems and methods of selecting internet protocol security tunnels during a key exchange. In some implementations, a first endpoint device can assign a first metric to a first internet protocol security (IPsec) tunnel and a second metric to a second IPsec tunnel. The first IPsec tunnel can be a first communication channel for transmitting data between the first endpoint device and a second endpoint device, and the second IPsec tunnel can be a second communication channel for transmitting data between the first endpoint device and the second endpoint device. The first endpoint device can select the first IPsec tunnel or the second IPsec tunnel as a selected IPsec tunnel for transmitting data toward the second endpoint device based on the first metric and the second metric. The first endpoint device can transmit data toward the second endpoint device via the selected IPsec tunnel.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Message processing methods, communication devices, storage media and program products

This application discloses a message processing method, communication device, storage medium, and program product, relating to the field of communications. The method includes: the communication device acquiring the sequence number of an IPsec packet to be processed; and then performing anti-replay processing on the IPsec packet based on a comparison between the sequence number of the IPsec packet to be processed and the sequence numbers recorded in a preset cache and within a sliding window. The preset cache is used to record sequence numbers that are not consecutive with the sequence numbers within the sliding window. This method allows the communication device to store the sequence numbers of out-of-order packets in the preset cache during anti-replay processing, avoiding sudden large-scale window expansion and thus preventing the accidental discarding of IPsec packets.
Owner:SHANGHAI HUAWEI TECH CO LTD

Data transmission method and device, electronic equipment, chip, storage medium and computer program product

The embodiment of the invention provides a data transmission method, a data transmission device, electronic equipment, a chip, a storage medium and a computer program product, the data transmission method is applied to a first function, and comprises the following steps: establishing a secure communication protocol IPSec tunnel with a second function; and based on the IPSec tunnel, performing data encryption transmission with the second function through a first IPSec module deployed in the first function.
Owner:CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1

Method for optimizing IPSEC networking, electronic equipment, storage medium and program product

The embodiment of the invention discloses a method for optimizing IPSEC (Internet Protocol Security) networking, electronic equipment, a storage medium and a program product. The method comprises the following steps: starting a pre-configured source protection subnet aggregation function at a headquarters, and starting a target protection subnet aggregation function at any branch; the first default route and the j protection subnets are used in the headquarters for cross mapping, and j route resources, j SA resources and j route resources are generated; and performing cross mapping on any branch by using j protection subnets and a second default route to generate k route resources, j SA resources and j route resources. According to the invention, when the IPSEC tunnel is established, an asymmetric resource allocation design mode is realized by adopting a mode of source protection subnet aggregation and target protection subnet aggregation, and the consumption of SA and route resources is reduced, so that the tunnel performance consumption caused by concurrency is remarkably reduced.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Protocol data unit set information identification for end-to-end encrypted traffic

Protocol data unit set information identification for end-to-end encryption traffic. A method is provided that includes accessing an encrypted application stream, the encrypted application stream including encrypted protocol data units (PDUs). For each encrypted PDU of the one or more encrypted PDUs, the method includes performing an Internet Protocol Security (IPSec) process of the encrypted PDU, where an IPSec packet is configured to include the encrypted PDU and carry metadata including at least one of: a media type indicator of the encrypted PDU, or PDU set information on at least one PDU set to which the encrypted PDU belongs. The method further comprises transmitting the IPSec packet to a network function at which metadata can be accessed from the IPSec packet for PDU set identification and for mapping encrypted PDUs to a quality of service (QoS) flow for classification and QoS differentiation of encrypted PDUs.
Owner:NOKIA TECHNOLOGIES OY

IPsec tunnel recovery method, device and readable storage medium

The present invention discloses an IPSec tunnel recovery method, device, and readable storage medium. The method includes, after an IPSec tunnel negotiation process is initiated, detecting, through the IPSec tunnel negotiation process, whether a designated database contains target tunnel data, wherein the designated database records historical data of successful IPSec tunnel negotiations; if the target tunnel data exists in the designated database and query data related to the target tunnel data exists, creating a structure corresponding to the target tunnel based on the query data; and resuming IPSec negotiation based on the created structure. The disclosed method can resume IPSec negotiation based on the created structure as needed. Because the designated database records historical data of successful IPSec tunnel negotiations, only one gateway device is required to quickly restore the IPSec tunnel state. This method also solves the problem of service data packet loss caused by tunnel renegotiation when state synchronization fails in the prior art.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Auto-grouping and routing platform

Systems and methods are provided for automatically grouping branch devices based on device information (e.g., IPSec tunnel connectivity, etc.). The devices with similar branch gateways which would customarily receive similar route information and / or properties (e.g., AS-PATH, cost, MED, Metric1, Metric2, community / extended community) and / or devices with similar connectivity graphs can be grouped together. This can reduce the number of electronic communications transmitted throughout the network and increase computational efficiency for the controller and devices.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Method and device for transmitting service in network

The embodiment of the present application discloses a method and device for transmitting services in a network, the method comprising: a first network device receives a first service message of a first service flow; in response to receiving the first service message, the first network device establishes a first IPSec tunnel directly connected to a second network device; then, when the first network device receives a second service message of the first service flow, the second service message can be sent to the second network device through the first IPSec tunnel. In this way, when the controller establishes an IPSec tunnel in the network, it no longer establishes a fully connected IPSec tunnel, but reasonably establishes IPSec tunnels between some network devices. IPSec tunnels between other network devices are only established when there is a service demand, which can reduce the demand for storage and processing capabilities of some network devices in the network to a certain extent, thereby effectively saving the deployment cost of the network.
Owner:HUAWEI TECH CO LTD

Lightweight key exchange method and device based on SM2 algorithm

The invention discloses a lightweight key exchange method and device based on an SM2 algorithm, and the method comprises the steps: two IPSec negotiation parties generate respective negotiation parameters which comprise a pair of fixed elliptic curve public and private keys and a temporary elliptic curve public and private key; the two IPSec negotiation parties realize transmission of a key exchange material by exchanging loads in the negotiation process, and the key exchange material comprises two corresponding elliptic curve multiple points; the two IPSec negotiation parties adopt a set algorithm to calculate and generate a shared key through own negotiation parameters and key exchange materials transmitted by the opposite party, and IPSec negotiation is protected and completed; the method can replace the interaction of encrypted certificates, and the key security negotiation of the two parties can be realized only by transmitting the multiple points of the two SM2 elliptic curves in the key exchange load. And one multiple point is generated by the temporary random number, and the negotiation processes are different, so that the security risk caused by using a fixed public and private key pair like an encryption certificate is avoided, and the security of the system is greatly improved.
Owner:ANHUI WANTONG POSTS & TELECOMM CO LTD