Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

15 results about "Security Parameter Index" patented technology

The Security Parameter Index (SPI) is an identification tag added to the header while using IPsec for tunneling the IP traffic. This tag helps the kernel discern between two traffic streams where different encryption rules and algorithms may be in use.

Generating a secure key exchange authentication response using a security parameter index transform

Disclosed embodiments provide systems and methods for generating an SKE Authentication Response using a Security Parameter Index (SPI) Transform to provide secure data transfer in a computing environment. A disclosed method comprises receiving, from an initiator channel on an initiator node, a SKE Authentication Request message at a local key manager (LKM) executing a responder node to initiate a secure communication between the initiator channel and a responder channel. The LKM obtains a Security Parameter Index (SPI) Transform, an SA Index, and SPI Transform values. The LKM creates an SPI based on the SPI Transform using the SA Index and the SPI Transform values. The LKM builds an SKE Authentication Response message based on the SKE Authentication Request message and the SPI, which including the SPI and an encryption algorithm. The LKM transmits the SKE Authentication Response message to the initiator channel on the initiator node using the responder channel.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

A ship-to-shore information communication method and device

ActiveCN116346421BImprove data integrityimprove privacyData packOriginal data
This application discloses a ship-to-shore information communication method and apparatus, relating to the technical field of coastal communication. The method includes: responding to receiving an encrypted data packet from a ship-based or shore-based IPSec security gateway device; if the packet's message structure is an ESP protocol message, then searching for an encryption algorithm and security specification according to the security parameter index; after verifying the integrity of the ESP message in the data packet according to the encryption algorithm and security specification, detecting whether the data packet is a replay attack; if the data packet is not a replay attack, then decrypting the data packet in reverse according to the encryption algorithm and security specification, obtaining and sending the original IP data to the core network layer for subsequent processing and forwarding. This method ensures the integrity and privacy of transmitted data in high-security scenarios such as ship-to-shore communication.
Owner:THE QUARTERMASTER RES INST OF THE GENERAL LOGISTICS DEPT OF THE CPLA +1

Generating a secure key exchange authentication request using a security parameter index transform

Embodiments of the present disclosure provide systems and methods for generating a secure key exchange (SKE) Authentication Request using a Security Parameter Index (SPI) Transform to provide secure data transfer in a computing environment. A disclosed method comprises receiving an SKE SA Initialization Response message at a local key manager (LKM) executing on an initiator node to initiate a secure communication between an initiator channel on the initiator node and a responder channel on a responder node. The LKM creates an SPI based on an SPI Transform using an SA Index and SPI Transform values, and the LKM builds the SKE Authentication Request message, which comprises the SPI, a set of cryptographic keys, and a list of encryption algorithms supported by the initiator channel. The LKM sends the SKE Authentication Request message to the responder channel on the responder node using the initiator channel.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Rekeying a security association using a security parameter index transform

Disclosed embodiments implement rekeying keys of a Security Association (SA) using an SPI Transform to provide secure data transfer in a computing environment. A disclosed method comprises detecting, by a local key manager (LKM) executing on a computing node, an expired rekey timer of an SA between an initiator channel on the computing node and a responder channel on a responder node. The LKM requests, based on the expired rekey timer, an SA Index from the initiator channel on a computing node. The LKM creates an SPI based on an SPI Transform using the new SA Index and SPI Transform values. The LKM builds an SKE SA Initialization Request message based on an authentication key of the SA and the SPI to obtain a new session key.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Message forwarding method, UPF selection method, electronic equipment and storage medium

Provided are a message forwarding method, a UPF selection method, an electronic device and a storage medium, the message forwarding method comprising: sending a first message to an evolved packet data gateway (ePDG), the first message carrying a communication capability identifier of a UE, the communication capability identifier being used for determining that the UE supports separation of a control plane and a media plane; a second message sent by the ePDG is received, the second message carries address information and a security parameter index SPI corresponding to a target user plane function UPF, and the target UPF supports separation of a control plane and a media plane; generating a first target message according to the SPI of the target UPF; and directly forwarding the first target message to the target UPF based on the address information of the target UPF. In this way, in the link of receiving the address information of the target UPF and the real-time call of the SPI, the UE can further directly send the first target message to the target UPF with the address information of the target UPF and the SPI as identifiers, and the message information in the actual call does not need to be forwarded through the ePDG, thereby effectively reducing the transmission delay in the message communication transmission.
Owner:ZTE CORP

Internet protocol security and security parameter index summarization and data routing

Techniques for routing Internet Protocol security (IPsec) data packets. An index is assigned to a Security Parameter Index (SPI) header of the IPsec data packet. The index includes information for routing the data packet to a particular Encapsulating Security Payload (ESP) processor. The data packet can be routed using techniques that are analogous to conventional routing protocols such as IPv4 routing protocol. This allows the data packet to be routed using less expensive routing protocols rather than relying solely on more expensive load balancing techniques to route the data packet. This also advantageously allows the data packet to be routed employing routing techniques developed over decades of routing protocol development.
Owner:CISCO TECHNOLOGY INC

Load balancing based on security parameter index values

This paper describes techniques for load balancing encrypted traffic based on the Security Parameter Index (SPI) value and the set of 5-tuple values ​​in the packet header. Furthermore, this paper describes techniques for including Quality of Service (QoS) type information in the SPI value field of the packet header. QoS type information indicates the specific traffic category on which packets will be processed. Additionally, this paper describes techniques for pre-configuring backend hosts so that encrypted traffic can be migrated from one backend host to another without causing temporary service interruptions.
Owner:CISCO TECHNOLOGY INC

Method for managing and controlling inter-vpn gateway key, quantum vpn controller and system

ActiveCN117201231Bavoid security threatsGuaranteed confidentialityCiphertextConfidentiality
The application discloses a VPN gateway inter-key management and control method, a quantum VPN controller and a system, and is applied to the quantum VPN controller. The method comprises the following steps: listening to a gateway communication group inter-key update period, and sending a session key acquisition request to a quantum key management system when the key update period reaches a set value; receiving session key ciphertext information issued by the quantum key management system, and generating a security parameter index SPI used by the gateway communication group in the current key update period dimension based on the session key ciphertext information; issuing the ciphertext information containing the security parameter index SPI to the gateway communication group to activate and use each gateway session key, and performing gateway data encryption forwarding; the security of the session key and the security index SPI information can be realized, the confidentiality of the session key is protected, and the security threat brought by the future quantum computer can be prevented.
Owner:CHINA TELECOM QUANTUM TECH CO LTD

Packet forwarding method, UPF selection method, electronic device, and storage medium

PCT designated stageWO2026040640A1Connection managementMessaging/mailboxes/announcementsEngineeringPacket data gateway
The present application provides a packet forwarding method, a user plane function (UPF) selection method, an electronic device, and a storage medium. The packet forwarding method comprises: sending a first message to an evolved packet data gateway (ePDG) (S110), wherein the first message carries a communication capability identifier of a UE, and the communication capability identifier is used for determining that the UE supports control plane and media plane separation; receiving a second message sent by the ePDG (S120), wherein the second message carries address information and a security parameter index (SPI) corresponding to a target UPF, and the target UPF supports control plane and media plane separation; generating a first target packet on the basis of the SPI of the target UPF (S130); and directly forwarding the first target packet to the target UPF on the basis of the address information of the target UPF (S140).
Owner:ZTE CORP

Security association lookup in communication system deployments

To generate an encrypted packet, a transmitting endpoint in a communication system chooses the desired IPsec tunnel, then retrieves the SA linked to that tunnel from its Outbound SA table of its local SA database (SAD), and encrypts the packet using the retrieved SA. To decrypt the encrypted packet, the receiving endpoint extracts the Security Parameter Index (SPI) value, the source address, the destination address, and the source port number from the packet to retrieve the appropriate SA from its local SAD database and decrypts the encrypted packet using the retrieved SA. In this way, the transmitting and receiving endpoints can retrieve the appropriate SAs for situations in which either endpoint is one of multiple endpoints located behind a Carrier-Grade Network Address Translation (CG-NAT) function having a single public IP address shared by the multiple endpoints.
Owner:NOKIA SOLUTIONS & NETWORKS OY

Maintaining quality of service processing for packets using security parameter index values

Techniques are described herein for load balancing encrypted traffic based on a security parameter index (SPI) value of a packet header and a set of five-tuple values of the packet header. In addition, techniques are described herein for including quality of service (QoS) type information in a SPI value field of a packet header. The QoS type information can indicate a particular traffic class that processing of the packet is to be subject to. In addition, techniques are described herein for preconfiguring a backend host such that encrypted traffic can be migrated from another backend host to the backend host without causing a temporary service interruption.
Owner:CISCO TECHNOLOGY INC

Tclas element for filtering ipsec traffic

To carry 5G QoS traffic flows over an IPsec Security Association (SA) within a WLAN network, a STA is configured to encode a frame to include a Traffic Classification (TCLAS) element that includes a frame classifier field. The frame classifier field can include a classifier type subfield and a classifier parameter subfield. To identify and filter 5G QoS traffic flows carried over an IPsec SA, the STA can set the classifier type subfield to a predetermined value (e.g., 11) to indicate that an IPsec SA parameter is included in the classifier parameter subfield, and include a Security Parameter Index (SPI), a destination IP address, and an IPsec protocol within the classifier parameter subfield.
Owner:INTEL CORP

Key updates for secure associations using secure

The disclosed embodiments use SPI translations to enable key updates to keys of security associations (SAs) to provide secure data transmissions in a computing environment. The disclosed method includes detecting, by a local key manager (LKM) executing on a compute node, an expired key update timer of an SA between an initiator channel on the compute node and a responder channel on a responder node. The LKM requests an SA index from an initiator channel on the compute node based on the expired key update timer. The LKM creates the SPI based on the SPI translation using the new SA index and the SPI translation value. And the LKM constructs an SKE SA initialization request message based on the authentication key of the SA and the SPI to obtain a new session key.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

User plane IPSEC SA modification

A User Equipment (UE): establishes (602) a User Plane (UP) Internet Protocol Security (IPsec) Security Association (SA) with a network element; receiving (604), from the network element, a request to modify the UP IPsec SA, the request comprising a security parameter index (SPI) to identify the UP IPsec SA; and modifying (606) the UP IPsec SA in accordance with the request.
Owner:GOOGLE LLC

Data transmission method and device, electronic equipment and storage medium

The embodiment of the invention discloses a data transmission method and device, electronic equipment and a storage medium, and the method comprises the steps that after a target gateway node generates a first message containing a security parameter index of the target gateway node, the first message can be sent to a distributor, the security parameter index of the target gateway node contains the identification information of the gateway node, and the security parameter index of the target gateway node contains the identification information of the gateway node; the distributor can send the first message to an external network element; the external network element generates a second message containing the security parameter index of the target gateway node according to the first message and sends the second message to the distributor, and the distributor searches the identification information of the target gateway node from the security parameter index of the target gateway node contained in the second message, so that the target gateway node is sent to the external network element according to the searched identification information. And sending the second message to the target gateway node. According to the technical scheme, the data transmission complexity can be reduced, and the data transmission efficiency and accuracy can be improved.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD