发明名称 REKEY SCHEME ON HIGH SPEED LINKS
摘要 In one embodiment, apparatus and methods for a rekey process are disclosed. In certain rekey embodiments, when a key-generation protocol exchange is executed, instead of generating a single new security relationship, such as a Security Association or SA, a multiple set (e.g., 10) of new security relationships (e.g., SAs) are generated. An authorized device can then individually use these security relationships (e.g., SAs) as needed to securely communicate with each other. For example, a set of SAs can be efficiently programmed into an 802.1ae protocol ASIC for handling transmitted and received data packets. In the description herein, embodiments of the invention are described with respect to SA's, and this “SA” term is generally defined as any type of security relation that can be formed to allow a particular node to securely transmit packets or frames to another receiving node.
申请公布号 US2014215216(A1) 申请公布日期 2014.07.31
申请号 US201414229986 申请日期 2014.03.30
申请人 Cisco Technology, Inc. 发明人 Mishra Chandan
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method of establishing a secure link from a first node, the method comprising: obtaining at the first node key generation information that includes one or more current security associations; transmitting a first set of secure packets that each include one of the one or more current security associations, wherein the first set of secure packets includes a corresponding first set of related packet identifiers; and transmitting a next set of secure packets that each include one of the one or more current security associations, wherein the next set of secure packets includes a corresponding next set of related packet identifiers, wherein transmitting the next set of secure packets is accomplished without the first node reiterating a portion of the key generation exchange or transmitting the next one of the plurality of security associations.
地址 San Jose CA US