Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

76 results about "IPsec" patented technology

In computing, Internet Protocol Security (IPsec) is a secure network protocol suite that authenticates and encrypts the packets of data sent over an Internet Protocol network. It is used in virtual private networks (VPNs).

Anti-quantum computing IPSEC key exchange method

The invention relates to an IPSEC (Internet Protocol Security) key exchange method resistant to quantum computing. According to the invention, based on a lattice cryptographic algorithm and improved SM4-256 symmetric encryption, secure communication between a master mode and a fast mode is realized; in the main mode, an initiator sends an IKE first message through a UDP (User Datagram Protocol), negotiates SA parameters with a responder and exchanges a lattice password certificate; the two parties encapsulate a temporary 32-byte secret key by using the public key of the opposite party, generate a 512-bit random number through SM4-256 encryption, and sign and transmit the 512-bit random number to realize secure random number exchange and certificate verification; and the two parties calculate a first session key based on a PRF (Pseudo Random Function), and encrypt an exchange data HASH value to complete main mode key consistency confirmation. And after entering the fast mode, taking the main mode session key as an SM4-256 symmetric key to continue communication, sending an SA message carrying a 512-bit random number by the two parties, calculating to obtain a second session key, and establishing an ESP tunnel. According to the method, the security of IPSEC under the threat of quantum computing is improved through the lattice password.
Owner:JIANGSU IDEABANK MICROELECTRONICS TECH

Password algorithm adaptation and hardware encryption and decryption acceleration method suitable for gateway protocol

The invention discloses a cryptographic algorithm adaptation and hardware encryption and decryption acceleration method suitable for a gateway protocol, deep integration of a cryptographic algorithm is realized through protocol stack-level native transformation, software and hardware collaborative design is adopted, and through innovative mechanisms such as multi-thread concurrent encryption, asynchronous interrupt processing and DMA data interaction, the hardware encryption and decryption acceleration of the cryptographic algorithm is realized. The processing capability in a high throughput scene is improved; an intelligent strategy engine is introduced to realize data packet dynamic classification and encrypted resource optimization scheduling, and the system performance is maximized while the security is ensured; according to the technical scheme, key full-life-cycle management and control are achieved through the HSM, the requirement for equal insurance 2.0 is met, multi-platform deployment is supported by adopting modular design, and compared with the prior art, the method can be flexibly adapted to various application scenes such as various domestic chip architectures, embedded devices, security gateways and industrial controllers, and the method is suitable for large-scale popularization and application. The problems of high platform dependence, difficulty in transplantation and the like existing in national secret IPSec implementation are solved, and a better secure communication solution is provided for a localized environment.
Owner:XIDIAN UNIV HANGZHOU RES INST +1

System and method for early detection of duplicate security association of IPsec tunnels

ActiveUS12598169B2Securing communicationTelecommunicationsSecurity association
In an embodiment, a method includes transmitting an initiation request from a first electronic device to a second electronic device, the initiation request being associated with a notification that the first electronic device is capable of early detection of duplicate security associations (SAs), receiving an initiation request from the second electronic device at the first electronic device, the initiation request being associated with a capability notification that the second electronic device is capable of early detection of duplicate SAs, determining a possibility of duplicate SAs by the first electronic device, transmitting responses configured to prevent duplicate SAs from the first electronic device to the second electronic device, receiving responses at the first electronic device from the second electronic device, wherein the responses indicate no duplicate SAs created by the second electronic device, and establishing a non-duplicate SA for the first and second electronic devices.
Owner:CISCO TECHNOLOGY INC

IPSec anti-replay detection method based on multiple caches

The application relates to the field of network security, in particular to an IPSec anti-replay detection method based on multiple caches. The latest window information which has not been stored in DDR is cached by means of the cache space of FPGA. When the sn window information of the previous message is not updated in the algorithm decryption stage, the un-updated sn window information is stored in the cache space of FPGA, the anti-replay detection of the next message is not affected, the processing time of two messages is shortened to the algorithm processing time, the preparation time before the algorithm decryption is greatly compressed, the method has the characteristics of fast speed, less resource occupation and the like, and is suitable for devices which have strict performance requirements and need to perform anti-replay detection.
Owner:SHANDONG HUAYI MICRO ELECTRONICS

Communication method and communication apparatus

A communication method and a communication apparatus, which are used for implementing communication between a terminal and a core network by means of a unified non-3GPP access gateway, thereby reducing the complexity of network deployment. The method comprises: receiving a first message from a terminal, the first message being used for requesting authentication, connection establishment or connection release, and the first message being an internet protocol security (IPSec) message, or the first message being a quick user datagram protocol internet connection (QUIC) protocol message; and sending a second message to a control plane network element, the second message being a non-access stratum (NAS) message determined on the basis of the first message.
Owner:HUAWEI TECH CO LTD

System and method for networking and internet protocol security (IPSec) measures for mobile ad hoc network (MANET) waveforms

A node of a network communicating via mobile ad hoc network (MANET) waveforms and incorporating internet protocol (IP) security (IPSec) measures includes a plaintext (PT) user system or host, ciphertext (CT) communications module including a radio system for transmission and reception via MANET waveforms, IPSec cryptographic units, and PT and CT convergence modules. IPSec units provide encryption and decryption of data traffic as well as cross-layer exchange between PT and CT convergence modules. PT convergence modules map output traffic and decrypted input traffic to CT capabilities and exchange reachability information (e.g., addresses of reachable nodes or systems) with counterpart PT convergence modules of peer nodes of the MANET. CT convergence modules converge encrypted input and output traffic based on CT capabilities.
Owner:ROCKWELL COLLINS INC

Base station activation method, communication apparatus, and storage medium

The application provides a base station activation method, a communication device and a storage medium, and relates to the technical field of communication. The method comprises the following steps: when a base station starts base station activation, an access platform sends a first parameter to the base station; the first parameter comprises a first verification parameter and an authentication parameter; the access platform performs authentication and authentication operations based on the first parameter, and sends a second parameter to the base station; the second parameter comprises a second verification parameter, and the second parameter is used for base station registration; the access platform performs base station registration operations based on the second parameter through an Internet Protocol Security (IPsec) tunnel, and sends a third parameter to the base station; the third parameter comprises a third verification parameter and a cell configuration parameter, and the third parameter is used for base station activation; and the access platform performs base station activation operations based on the third parameter through the IPsec tunnel, so that the base station is activated in a core network device, and the security of the network is improved.
Owner:BAICELLS TECH CO LTD

Computer and Network Interface Controller Offloading Encryption Processing to the Network Interface Controller and Using Derived Encryption Keys

Encryption operations are securely offloaded to a network interface controller (NIC). Encryption keys are securely transferred from a virtual machine (VM) to the NIC and data is securely transferred from encrypted VM memory to secure buffers in the NIC. The NIC handles the encryption and decryption operations in hardware, greatly increasing encryption performance while not reducing security. This is especially useful in cloud server environments, so the cloud service provider does not have access to the encryption keys or the unencrypted data. The offloaded operations are performed with numerous different communication protocols, including RDMA, QUIC, IPsec underlay and WireGuard.
Owner:DREAMBIG SEMICON INC

Mapping of ipsec tunnels to sd-wan segmentation

Generally, Software-Defined Wide Area Networks (SD-WAN) generally do not support network segmentation. The concepts disclosed herein connects IPSec SD-WAN fabric to a Virtual Routing and Forwarding (VRF) router and make use of a Software Defined Cloud Interconnect (SDCI) Router to route traffic from IPSec SD-WAN to various cloud services from the SDCI Router in the fabric. The concepts disclosed herein also provides for tunnel multi-plexing that takes incoming and outgoing traffic and maps VPNs to any service VRF associated with the cloud based services.
Owner:CISCO TECHNOLOGY INC

A Hybrid Quantum-Resistant Security Enhancement Method for IPSec VPN

PendingCN122372190AKey exchangeData pack
This invention proposes a hybrid quantum-resistant security enhancement method for IPSec VPNs. The method includes: intercepting Internet Key Exchange (ITE) packets and adding a proxy header between the transport layer header and the ISE payload of the packets; obtaining a quantum key from a key pool using quantum key distribution technology and generating a first-stage session key based on the quantum key; protecting the ISE key negotiation process using a quantum-resistant cryptographic algorithm to generate a second-stage session key; and using the first-stage and second-stage session keys as input parameters for a key derivation function to generate a final session key for encrypted data transmission. This invention, without modifying the original IPSec negotiation process, supports dynamic key combinations of different security levels, enhancing the quantum security protection capability of VPN data transmission while maintaining system flexibility and performance.
Owner:CHINA MOBILE COMM GRP CO LTD +3

Distributed IPsec gateway

The present disclosure provides technical solutions related to distributed IPSec gateway. A control plane and a data plane of the IPSec gateway are divided, a plurality of gateway processing nodes may be run in the data plane to process data packets of incoming ESP / AH traffic and / or data packets of outgoing IP traffic. IKE information interaction may be handled in the control plane and the traffic may be steered on each gateway processing node in the data plane.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Message processing methods, communication devices, storage media and program products

This application discloses a message processing method, communication device, storage medium, and program product, relating to the field of communications. The method includes: the communication device acquiring the sequence number of an IPsec packet to be processed; and then performing anti-replay processing on the IPsec packet based on a comparison between the sequence number of the IPsec packet to be processed and the sequence numbers recorded in a preset cache and within a sliding window. The preset cache is used to record sequence numbers that are not consecutive with the sequence numbers within the sliding window. This method allows the communication device to store the sequence numbers of out-of-order packets in the preset cache during anti-replay processing, avoiding sudden large-scale window expansion and thus preventing the accidental discarding of IPsec packets.
Owner:SHANGHAI HUAWEI TECH CO LTD

Data transmission method and device, electronic equipment, chip, storage medium and computer program product

The embodiment of the invention provides a data transmission method, a data transmission device, electronic equipment, a chip, a storage medium and a computer program product, the data transmission method is applied to a first function, and comprises the following steps: establishing a secure communication protocol IPSec tunnel with a second function; and based on the IPSec tunnel, performing data encryption transmission with the second function through a first IPSec module deployed in the first function.
Owner:CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1

Auto-grouping and routing platform

Systems and methods are provided for automatically grouping branch devices based on device information (e.g., IPSec tunnel connectivity, etc.). The devices with similar branch gateways which would customarily receive similar route information and / or properties (e.g., AS-PATH, cost, MED, Metric1, Metric2, community / extended community) and / or devices with similar connectivity graphs can be grouped together. This can reduce the number of electronic communications transmitted throughout the network and increase computational efficiency for the controller and devices.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Lightweight key exchange method and device based on SM2 algorithm

The invention discloses a lightweight key exchange method and device based on an SM2 algorithm, and the method comprises the steps: two IPSec negotiation parties generate respective negotiation parameters which comprise a pair of fixed elliptic curve public and private keys and a temporary elliptic curve public and private key; the two IPSec negotiation parties realize transmission of a key exchange material by exchanging loads in the negotiation process, and the key exchange material comprises two corresponding elliptic curve multiple points; the two IPSec negotiation parties adopt a set algorithm to calculate and generate a shared key through own negotiation parameters and key exchange materials transmitted by the opposite party, and IPSec negotiation is protected and completed; the method can replace the interaction of encrypted certificates, and the key security negotiation of the two parties can be realized only by transmitting the multiple points of the two SM2 elliptic curves in the key exchange load. And one multiple point is generated by the temporary random number, and the negotiation processes are different, so that the security risk caused by using a fixed public and private key pair like an encryption certificate is avoided, and the security of the system is greatly improved.
Owner:ANHUI WANTONG POSTS & TELECOMM CO LTD

IKE-based path identity

PendingUS20260067277A1Securing communicationPathPingSecurity association
The present technology uses the IKE protocol to establish a path identity on both sides of a peer connection. This is achieved by using IKE to exchange local and peer device identifiers along with transport identifiers. IKE then populates the path identity into the IPsec data plane by associating it with the transmit and receive security association databases (IPsec Tx & Rx SA DB). The device's data plane can monitor traffic sent or received through these IPsec SAs by using the path identity information linked with the IPsec SAs. This allows the creation of an application-to-path monitoring record, or matching traffic to the record for purposes such as statistics collection, troubleshooting, and performance evaluation.
Owner:CISCO TECHNOLOGY INC

Enhanced processing for IPSEC flows

ActiveCN115085962BSecuring communicationSecurity associationIPsec
Embodiments of the present disclosure relate to methods, apparatuses, and computer readable storage media for processing Internet Protocol Security (IPsec) flows. One method includes determining a security association for an incoming flow, the incoming flow comprising a plurality of packets; performing pre-processing on the plurality of packets based on the security association; and in response to performing the pre-processing on at least one packet of the plurality of packets, performing parallel processing on the at least one packet of the plurality of packets.
Owner:NOKIA NETWORKS OY

An IPSec VPN security gateway access management system

ActiveCN121509060BSecurity specificationIPsec
The application discloses an IPSec VPN security gateway access management system and relates to the technical field of security gateways, and the technical solution points of the application include the following: an extraction module: extracting access subject information and target data identification of a data access request; setting a security access benchmark set, wherein the security access benchmark set contains protocol standards, key level rules and hardware acceleration configuration parameters, the protocol standards correspond to compliance intervals, the key level rules correspond to key life cycle thresholds, and the hardware acceleration configuration parameters correspond to computing power adaptation ranges; comparing and analyzing access characteristic parameters corresponding to the access subject information and the target data identification with the compliance intervals of the protocol standards and the key life cycle thresholds of the key level rules in the security access benchmark set respectively to obtain a target authentication mechanism in line with the protocol standards and a target key system in line with the key level rules; and the effect is to promote efficient operation of data access under security specifications.
Owner:WUHAN SANJIANG SPACE NETWORK COMM CO LTD

IPSec VPN data packet processing method and system in bridging domain environment

The invention discloses an IPSec (Internet Protocol Security) VPN (Virtual Private Network) data packet processing method and system in a bridging domain environment, and the method comprises the steps: starting an IPSec network bridge mode in a two-layer forwarding module of a VPP (Virtual Private Protocol) framework, and configuring endpoint address information of an IPSec tunnel; based on the starting state of the IPSec network bridge mode and data packet characteristics, in a two-layer forwarding processing process, screening out a to-be-processed data packet needing IPSec processing and forwarding the to-be-processed data packet to a bridging virtual interface; performing encryption or decryption processing on the to-be-processed data packet based on an IPSec security policy database at the bridging virtual interface to obtain a processed data packet; and based on the endpoint address information of the IPSec tunnel, screening the processed data packet by setting a multi-layer filtering mechanism, thereby preventing the processed data packet from entering the IPSec processing flow again, and avoiding repeated encryption or decryption. According to the invention, the problem that the VPP framework cannot support the IPSec VPN under the bridging domain environment due to layering limitation is solved.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD +1

Computer with virtual private network security gateway system graphical user interface

1. The name of the design product: computer with virtual private network security gateway system graphical user interface. 2. The use of the design product: for running programs. 3. The design points of the design product: the content of the graphical user interface in the screen of the product. 4. The picture or photo that best indicates the design points: interface change state diagram. 5. The computer is a conventional design, omitting the rear view, left view, right view, top view, and bottom view. 6. The use of the graphical user interface: users enter the virtual private network security gateway system through the interface of the present design, which is a software system compatible with IPSec VPN encryption transmission equipment. Users use the system to view the current running status of the equipment. 7. Explanation of the change state of the graphical user interface: enter the relevant user information in the main view interface and click the "initialize" button. The interface jumps to the interface change state diagram.
Owner:MATRICTIME DIGITAL TECH CO LTD

Identity authentication system of industrial control system based on domestic commercial cryptographic algorithm

The invention provides an identity authentication system of an industrial control system based on a domestic commercial cryptographic algorithm, and aims to solve the problems that an existing industrial control system is low in safety in the identity authentication process, depends on a foreign cryptographic algorithm, does not meet the national commercial password compliance requirement and the like. The system adopts a smart key UKey as a user identity carrier, combines an SM2 digital signature, an SM3 hash algorithm and an SM4 symmetric encryption algorithm, and realizes high-strength identity authentication through a challenge-response mechanism; and meanwhile, a GMTLS protocol and IPSec encryption communication are supported, and the security of network access and data transmission is ensured. The method has the advantages of high identity authentication strength, high attack resistance, accordance with national secret standards, policies and regulations, high expandability and the like, is suitable for industrial control system environments in key infrastructure fields such as electric power, energy, water conservancy and the like, and has good application prospects and popularization values.
Owner:HUANENG LANCANG RIVER HYDROPOWER CO LTD

VPN (Virtual Private Network) cross-device migration method and device for public cloud and available interval

PendingCN121603513ATransmissionPrivate networkDevice migration
The invention relates to a VPN (Virtual Private Network) cross-device migration method and device for a public cloud and an available interval. The method comprises the following steps: acquiring VPN configuration information of source equipment, wherein the VPN configuration information comprises SSL VPN configuration information and IPsec VPN configuration information; generating VPN configuration parameters of target equipment according to the VPN information of the source equipment; carrying out simulation issuing operation on a page of the target equipment based on the VPN configuration parameters; updating table items related to the VPN configuration information in a database; issuing a virtual system to the target device; and performing configuration cleaning operation on the source equipment to complete VPN cross-equipment migration between the public cloud and the available interval. According to the application, IPSec VPN and SSL VPN services can be simultaneously and automatically migrated to the target equipment from the source equipment in a lossless manner in the same available area of the public cloud, so that the service continuity and the network security are ensured.
Owner:HANGZHOU DPTECH TECH

System and method for securing network traffic using internet protocol security tunnels in a communications network

A base station for securing network traffic using Internet Protocol Security (IPSec) tunnels in a communications network is disclosed. The base station includes a transport manager container that handles network traffic termination at a network interface. The base station further includes an Internet Protocol (IP) security tunnel management container that exchanges one or more IKE parameters between a source IKE daemon unit deployed in at least one POD and a target IKE daemon unit deployed in a peer node. The IP security tunnel management container further (a) authenticates the peer node based on the extracted IKE parameters, (b) configures the source IKE daemon unit based on the extracted one or more IKE parameters in response to successful authentication of the peer node, and (c) creates at least one IP security tunnel between the at least one POD and the peer node based on a security data table updated in a network kernel.
Owner:RAKUTEN SYMPHONY INC

Bypassing IKE firewall for cloud-managed IPSec keys in SDWAN fabric

Systems and methods are provided for effectuating overlay tunnels between software-defined wide area network (SD-WAN) end-point devices despite the use of IPSec passthrough in one or more network devices, such as modems or routers that exist between the end-point devices. In particular, the Internet Key Exchange (IKE) protocol can be allowed to progress until a modem / router is able to establish an IKE tunnel, after which overlay packets using cloud-managed keys can be allowed to pass through the modem / router. An overlay tunnel may then be established between the end-point devices, and the IKE tunnel can be taken down.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Apparatus and method for supporting l4s in no-3GPP access environments

The present disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate, and to a method performed by a non-3GPP interworking function (N3IWF) entity of a wireless communication system, the method comprising the steps of: receiving session management information from a session management function (SMF) entity via an access and mobility management function (AMF) entity, the session management information includes an explicit congestion notification (ECN) flag indication for supporting low latency, low loss, and scalable throughput (L4S) in non-3GPP access; determining a connection of an Internet Protocol Security (IPsec) sub-security association (SA) supporting a Quality of Service (QoS) flow of the L4S; and sending a message for requesting the IPsec sub-SA connection to the terminal.
Owner:SAMSUNG ELECTRONICS CO LTD

Communication method and device, communication equipment and storage medium

The invention relates to a communication method and device, communication equipment and a storage medium. The method comprises the following steps: acquiring a to-be-sent message corresponding to each application flow; the message to be sent comprises an inner layer differential service code point DSCP value; the inner-layer DSCP value represents the service priority of the application flow; for each to-be-sent message, according to the inner-layer DSCP value, determining a target Internet security protocol IPsec sub-tunnel matched with the to-be-sent message, and determining a DSCP value corresponding to the target IPsec sub-tunnel; and adding the DSCP value of the target IPsec sub-tunnel to an outer-layer internet interconnection protocol header of the message to be sent, and transmitting the message to be sent based on a priority sequence represented by the DSCP value of the target IPsec sub-tunnel. By adopting the method, the timely transmission of the application data of the high-priority service can be realized, and the high-priority service is ensured.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

A method and system for realizing data transmission encryption of a signal creation environment container

The present application relates to the technical field of cloud native Kubernetes container, in particular to a method and system for realizing data transmission encryption of a container in a national security environment, comprising the following steps: deploying a Calico VPP component and enabling an architecture design of an IPSec function to realize data transmission encryption of the container in the national security environment; using an IPIP mode by the Calico to deploy the Calico VPP through a mode of deploying a component in a cluster; enabling the IPSec function through parameter setting to enable the function of the IPSec, and then realizing the data transmission encryption of the container in the national security environment; the method and system for realizing the data transmission encryption of the container in the national security environment are unitary in data encryption in the national security environment, which is based on a data packet instead of an entire data stream, which is not only flexible but also helps to further improve the security of IP data packets, and can effectively prevent network attacks; in the national security environment, the data transmission encryption of the container is realized, the IPSec can carry all traffic by establishing a tunnel, and can support different TCP services.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Software-Defined Wide Area Network Self-Service for Service Assurance

The concepts and technologies disclosed herein are directed to software-defined wide-area network (“SD-WAN”) self-service for service assurance. The proposed SD-WAN self-service solution can be used for any policy-driven system that automatically troubleshoots the problems resulting from hybrid SD-WAN network activities, including virtual private network (“VPN”), IP tunnel, IPSec, and security policies. According to one aspect disclosed herein, a method can check network configurations, analyze switch responses, and locate network problems quickly. Moreover, the method can test the functionality of a rules-based troubleshooting software effectively without employing expensive testing equipment and with minimal human intervention. Without the disclosed solution, telecommunications service providers may have to hire more software engineers who understand SDN and cloud technologies to effectively troubleshoot SD-WAN network connectivity issues, including issues caused by virtual network function (“VNF”), virtual machine (“VM”), and SDN switches. Thus, this labor-intensive solution is not only expensive, but also not immune to human error.
Owner:AT&T INTELLECTUAL PROPERTY I L P

User equipment access method and device, equipment, storage medium and program product

The invention relates to the technical field of communication, and provides a user equipment access method, device and equipment, a storage medium and a program product, and the user equipment access method applied to user equipment comprises the following steps: under the condition that a message based on an IKE protocol and an N3IWF network element complete quantum key agreement, sending the message to the N3IWF network element; generating a key seed based on the quantum key determined by negotiation and a pseudo-random function; the quantum key is generated based on a QKD network; constructing an IPSec tunnel based on the key seed; and performing network access based on the IPSec tunnel. According to the invention, the user equipment can access the 5G core network based on the non-trusted non-3GPP network under the condition that the network security and the network protection cost are considered.
Owner:CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD +1

Packet processing method, communication apparatus, storage medium and program product

The present application relates to the field of communications. Disclosed are a packet processing method, a communication apparatus, a storage medium and a program product. The method comprises: a communication apparatus acquires a sequence number of an Internet protocol security (IPsec) packet to be processed, and then, on the basis of comparison results between the sequence number of said IPsec packet and sequence numbers recorded in a preset buffer and between the sequence number of said IPsec packet and sequence numbers in a sliding window, performs anti-replay processing on said IPsec packet, the preset buffer being used for recording sequence numbers that are currently discontinuous with the sequence numbers in the sliding window. In the method, when the communication apparatus performs anti-replay processing, sequence numbers of out-of-order packets can be stored in the preset buffer, so as to avoid sudden large window advancements, thus avoiding erroneous drops of IPsec packets.
Owner:HUAWEI TECH CO LTD