IP Library Granted Patent US 12706885
Granted Patent B2
US 12706885 · App. 18/704,530 · Granted Aug 11, 2026

Communication device and method therein for facilitating IPsec communications

Inventors: Daiying Liu (Beijing, CN); Congjie Zhang (Beijing, CN); Qiang Fu (Beijing, CN); Gang Yang (Beijing, CN)
Assignee: Telefonaktiebolaget LM Ericsson (PUBL)
H04L63/029H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12706885
App. No.
18/704,530
Granted
Aug 11, 2026
Kind
B2
Abstract

The present disclosure provides a method ( 100 ) performed by a communication device. The method ( 100 ) includes: establishing ( 110 ) a first Internet Protocol Security, IPsec, tunnel with a first peer communication device and a second IPsec tunnel with a second peer communication device, the first IPsec tunnel being configured with a first Traffic Selector, TS, that specifies a source address range and a destination address range and has a first priority, and the second IPsec tunnel being configured with a second TS that specifies the source address range and the destination address range and has a second priority lower than the first priority; detecting ( 120 ) a failure of the first IPsec tunnel; and removing ( 130 ) the first TS for the first IPsec tunnel in response to the failure.

Claims (14)

1 . A method performed by a communication device, comprising:

establishing a first Internet Protocol Security, IPsec, tunnel with a first peer communication device and a second IPsec tunnel with a second peer communication device, the first IPsec tunnel being configured with a first Traffic Selector, TS, that specifies a source address range and a destination address range and has a first priority, and the second IPsec tunnel being configured with a second TS that specifies the source address range and the destination address range and has a second priority lower than the first priority;

detecting a failure of the first IPsec tunnel; and

removing the first TS for the first IPsec tunnel in response to the failure.

2 . The method of claim 1 , wherein the first TS and the second TS specify one or more of a same protocol identifier, a same source port identifier, and a same destination port identifier.

3 . The method of claim 1 , wherein the failure is detected by detecting a reachability of an IP address of the first peer communication device that is used for the first IPsec tunnel.

4 . The method of claim 3 , wherein the reachability is detected by means of Bidirectional Forwarding Detection, BFD.

5 . The method of claim 1 , wherein

said establishing the first IPsec tunnel comprises creating a first Access Control List, ACL, entry corresponding to the first TS, the first ACL entry having the first priority,

said establishing the second IPsec tunnel comprises creating a second ACL entry corresponding to the second TS, the second ACL entry having the second priority.

6 . The method of claim 5 , further comprising:

removing the first ACL entry in response to the first TS being removed.

7 . A communication device, comprising a communication interface, a processor and a memory, the memory comprising instructions executable by the processor ( 420 ) whereby the communication device is operative to perform the method according to claim 1 .

8 . A computer program comprising instructions which, when executed by a processor of a communication device, configure the communication device to perform the method according to claim 1 .