Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8 results about "Security Parameter Index" patented technology

The Security Parameter Index (SPI) is an identification tag added to the header while using IPsec for tunneling the IP traffic. This tag helps the kernel discern between two traffic streams where different encryption rules and algorithms may be in use.

A ship-to-shore information communication method and device

ActiveCN116346421BImprove data integrityimprove privacyData packOriginal data
This application discloses a ship-to-shore information communication method and apparatus, relating to the technical field of coastal communication. The method includes: responding to receiving an encrypted data packet from a ship-based or shore-based IPSec security gateway device; if the packet's message structure is an ESP protocol message, then searching for an encryption algorithm and security specification according to the security parameter index; after verifying the integrity of the ESP message in the data packet according to the encryption algorithm and security specification, detecting whether the data packet is a replay attack; if the data packet is not a replay attack, then decrypting the data packet in reverse according to the encryption algorithm and security specification, obtaining and sending the original IP data to the core network layer for subsequent processing and forwarding. This method ensures the integrity and privacy of transmitted data in high-security scenarios such as ship-to-shore communication.
Owner:THE QUARTERMASTER RES INST OF THE GENERAL LOGISTICS DEPT OF THE CPLA +1

Rekeying a security association using a security parameter index transform

Disclosed embodiments implement rekeying keys of a Security Association (SA) using an SPI Transform to provide secure data transfer in a computing environment. A disclosed method comprises detecting, by a local key manager (LKM) executing on a computing node, an expired rekey timer of an SA between an initiator channel on the computing node and a responder channel on a responder node. The LKM requests, based on the expired rekey timer, an SA Index from the initiator channel on a computing node. The LKM creates an SPI based on an SPI Transform using the new SA Index and SPI Transform values. The LKM builds an SKE SA Initialization Request message based on an authentication key of the SA and the SPI to obtain a new session key.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Message forwarding method, UPF selection method, electronic equipment and storage medium

Provided are a message forwarding method, a UPF selection method, an electronic device and a storage medium, the message forwarding method comprising: sending a first message to an evolved packet data gateway (ePDG), the first message carrying a communication capability identifier of a UE, the communication capability identifier being used for determining that the UE supports separation of a control plane and a media plane; a second message sent by the ePDG is received, the second message carries address information and a security parameter index SPI corresponding to a target user plane function UPF, and the target UPF supports separation of a control plane and a media plane; generating a first target message according to the SPI of the target UPF; and directly forwarding the first target message to the target UPF based on the address information of the target UPF. In this way, in the link of receiving the address information of the target UPF and the real-time call of the SPI, the UE can further directly send the first target message to the target UPF with the address information of the target UPF and the SPI as identifiers, and the message information in the actual call does not need to be forwarded through the ePDG, thereby effectively reducing the transmission delay in the message communication transmission.
Owner:ZTE CORP

Method for managing and controlling inter-vpn gateway key, quantum vpn controller and system

ActiveCN117201231Bavoid security threatsGuaranteed confidentialityCiphertextConfidentiality
The application discloses a VPN gateway inter-key management and control method, a quantum VPN controller and a system, and is applied to the quantum VPN controller. The method comprises the following steps: listening to a gateway communication group inter-key update period, and sending a session key acquisition request to a quantum key management system when the key update period reaches a set value; receiving session key ciphertext information issued by the quantum key management system, and generating a security parameter index SPI used by the gateway communication group in the current key update period dimension based on the session key ciphertext information; issuing the ciphertext information containing the security parameter index SPI to the gateway communication group to activate and use each gateway session key, and performing gateway data encryption forwarding; the security of the session key and the security index SPI information can be realized, the confidentiality of the session key is protected, and the security threat brought by the future quantum computer can be prevented.
Owner:CHINA TELECOM QUANTUM TECH CO LTD

Packet forwarding method, UPF selection method, electronic device, and storage medium

PCT designated stageWO2026040640A1Connection managementMessaging/mailboxes/announcementsEngineeringPacket data gateway
The present application provides a packet forwarding method, a user plane function (UPF) selection method, an electronic device, and a storage medium. The packet forwarding method comprises: sending a first message to an evolved packet data gateway (ePDG) (S110), wherein the first message carries a communication capability identifier of a UE, and the communication capability identifier is used for determining that the UE supports control plane and media plane separation; receiving a second message sent by the ePDG (S120), wherein the second message carries address information and a security parameter index (SPI) corresponding to a target UPF, and the target UPF supports control plane and media plane separation; generating a first target packet on the basis of the SPI of the target UPF (S130); and directly forwarding the first target packet to the target UPF on the basis of the address information of the target UPF (S140).
Owner:ZTE CORP

Maintaining quality of service processing for packets using security parameter index values

Techniques are described herein for load balancing encrypted traffic based on a security parameter index (SPI) value of a packet header and a set of five-tuple values of the packet header. In addition, techniques are described herein for including quality of service (QoS) type information in a SPI value field of a packet header. The QoS type information can indicate a particular traffic class that processing of the packet is to be subject to. In addition, techniques are described herein for preconfiguring a backend host such that encrypted traffic can be migrated from another backend host to the backend host without causing a temporary service interruption.
Owner:CISCO TECHNOLOGY INC

Tclas element for filtering ipsec traffic

To carry 5G QoS traffic flows over an IPsec Security Association (SA) within a WLAN network, a STA is configured to encode a frame to include a Traffic Classification (TCLAS) element that includes a frame classifier field. The frame classifier field can include a classifier type subfield and a classifier parameter subfield. To identify and filter 5G QoS traffic flows carried over an IPsec SA, the STA can set the classifier type subfield to a predetermined value (e.g., 11) to indicate that an IPsec SA parameter is included in the classifier parameter subfield, and include a Security Parameter Index (SPI), a destination IP address, and an IPsec protocol within the classifier parameter subfield.
Owner:INTEL CORP

Key updates for secure associations using secure

PendingCN121753298ASecuring communicationInternet privacySecurity association
The disclosed embodiments use SPI translations to enable key updates to keys of security associations (SAs) to provide secure data transmissions in a computing environment. The disclosed method includes detecting, by a local key manager (LKM) executing on a compute node, an expired key update timer of an SA between an initiator channel on the compute node and a responder channel on a responder node. The LKM requests an SA index from an initiator channel on the compute node based on the expired key update timer. The LKM creates the SPI based on the SPI translation using the new SA index and the SPI translation value. And the LKM constructs an SKE SA initialization request message based on the authentication key of the SA and the SPI to obtain a new session key.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION