IP Library › Granted Patent US 8,131,994
Granted Patent B2
US 8,131,994 · App. 11/756,783 · Granted Mar 6, 2012

Dual cryptographic keying

Assignee: Cisco Technology, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,131,994
App. No.
11/756,783
Granted
Mar 6, 2012
Kind
B2
Abstract

A dual cryptographic keying system. In particular implementations, a method includes responsive to an initial session key negotiation, storing security association information for a tunnel in a security association memory; responsive to a session key renegotiation, storing security association information for the tunnel in a cache; decrypting received packets associated with the tunnel conditionally using the security association information in the cache or the security association information in the security association memory; and upon an expiration condition, overwriting the security association information, for the tunnel, in the security association memory with the security association information, for the tunnel, copied from the cache.

Claims (53)

1. A non-transitory computer-readable medium comprising executable instructions operable, when executed, to:

responsive to an initial session key negotiation, store a first security association information, comprising a first encryption key, for a tunnel in a security association memory;

responsive to a session key renegotiation, store a second security association information different from the first security association, comprising a second encryption key, for the same tunnel in a cache;

prior to an expiration condition, decrypt received packets associated with the tunnel conditionally using the second security association information in the cache or the first security association information in the security association memory based on identifiers associated with each of the received packets; and

upon the expiration condition, overwrite the security association information, for the tunnel, in the security association memory with the security association information, for the tunnel, copied from the cache;

wherein, before storing security association information for the tunnel in a cache, if the cache is full and if one or more expiration conditions have occurred, the executable instructions further operable, when executed, to:

select an expired entry in the security association memory; and write the security association data from a corresponding cache entry to the selected expired entry in the security association memory.

2. The non-transitory computer-readable medium of claim 1 wherein, before storing security association information for the tunnel in a cache, if the cache is full and if no expiration conditions have occurred, the executable instructions further operable, when executed, to notify an administrator.

3. The non-transitory computer-readable medium of claim 1 wherein, after storing security association information for the tunnel in a cache, the executable instructions further operable, when executed, to indicate in an index that the security association information for the tunnel is stored in the cache.

4. The non-transitory computer-readable medium of claim 1 wherein the executable instructions further operable, when executed, to:

set a time threshold upon storing security association information for the tunnel in the cache; and

start a timer based on the time threshold, wherein the expiration condition is based on the time threshold.

5. The non-transitory computer-readable medium of claim 1 wherein the executable instructions further operable, when executed, to cause hardware to perform the storing of the security association information for the tunnel in the cache.

6. The non-transitory computer-readable medium of claim 1 wherein the executable instructions further operable, when executed, to transmit a hardware interrupt to cause software to perform the storing of the security association information for the tunnel in the cache.

7. The non-transitory computer-readable medium of claim 1 wherein the security association information comprises an encryption algorithm based on Transport Layer Security.

8. The non-transitory computer-readable medium of claim 1 wherein the security association information comprises an encryption algorithm based on Datagram Transport Layer Security.

9. A method comprising:

storing a first security association information comprising a first encryption key for a tunnel in a security association memory responsive to an initial session key negotiation;

storing a second security association information different from the first security association information, comprising a second encryption key, for the same tunnel in a cache responsive to a session key renegotiation;

prior to an expiration condition, decrypting received packets associated with the tunnel conditionally using the second security association information in the cache or the first security association information in the security association memory based on identifiers associated with each of the received packets; and

overwriting, upon the expiration condition, the security association information, for the tunnel, in the security association memory with the security association information, for the tunnel, copied from the cache

wherein, before storing security association information for the tunnel in a cache, if the cache is full and if one or more expiration conditions have occurred, the method further comprises:

selecting an expired entry in the security association memory; and

writing the security association data from a corresponding cache entry to the selected expired entry in the security association memory.

10. The method of claim 9 wherein, before storing security association information for the tunnel in a cache, if the cache is full and if no expiration conditions have occurred, the method further comprises notifying an administrator.

11. The method of claim 10 wherein, after storing security association information for the tunnel in a cache, the method further comprises indicating in an index that the security association information for the tunnel is stored in the cache.

12. The method of claim 9 further comprising:

setting a time threshold upon storing security association information for the tunnel in the cache; and

starting a timer based on the time threshold, wherein the expiration condition is based on the time threshold.

13. The method of claim 9 further comprising causing hardware to perform the storing of the security association information for the tunnel in the cache.

14. The method of claim 9 further comprising transmitting a hardware interrupt to cause software to perform the storing of the security association information for the tunnel in the cache.

15. The method of claim 9 wherein the security association information comprises an encryption algorithm based on Transport Layer Security.

16. The method of claim 9 wherein the security association information comprises an encryption algorithm based on Datagram Transport Layer Security.

17. An apparatus comprising:

one or more processors;

a memory operative to store security association information for one or more tunnels; and

executable instructions encoded on non-transitory computer-readable media, the executable instructions operable when executed to:

responsive to an initial session key negotiation, store a first security association information, comprising a first encryption key, for a tunnel in a security association memory;

responsive to a session key renegotiation, store a second security association information different from the first security association information, comprising a second encryption key, for the same tunnel in a cache;

prior to an expiration condition, decrypt received packets associated with the tunnel conditionally using the second security association information in the cache or the first security association information in the security association memory based on identifiers associated with each of the received packets; and

upon the expiration condition, overwrite the security association information, for the tunnel, in the security association memory with the security association information, for the tunnel, copied from the cache

wherein, before storing security association information for the tunnel in a cache, if the cache is full and if one or more expiration conditions have occurred, the executable instructions further operable, when executed, to:

select an expired entry in the security association memory; and

write the security association data from a corresponding cache entry to the selected expired entry in the security association memory.

18. The apparatus of claim 17 wherein, before storing security association information for the tunnel in a cache, if the cache is full and if no expiration conditions have occurred, the executable instructions further operable, when executed, to notify an administrator.

19. The apparatus of claim 17 wherein, after storing security association information for the tunnel in a cache, the executable instructions further operable, when executed, to indicate in an index that the security association information for the tunnel is stored in the cache.

20. The apparatus of claim 17 wherein the executable instructions further operable, when executed, to:

set a time threshold upon storing security association information for the tunnel in the cache; and

start a timer based on the time threshold, wherein the expiration condition is based on the time threshold.

21. The apparatus of claim 17 wherein the executable instructions further operable, when executed, to cause hardware to perform the storing of the security association information for the tunnel in the cache.

22. The apparatus of claim 17 wherein the executable instructions further operable, when executed, to transmit a hardware interrupt to cause software to perform the storing of the security association information for the tunnel in the cache.

23. The apparatus of claim 17 wherein the security association information comprises an encryption algorithm based on Transport Layer Security.

24. The apparatus of claim 17 wherein the security association information comprises an encryption algorithm based on Datagram Transport Layer Security.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE FIRST INVENTOR'S NAME PREVIOUSLY RECORDED ON REEL 019369 FRAME 0417. ASSIGNOR(S) HEREBY CONFIRMS THE THE FIRST INVENTOR'S NAME SHOULD BE SINHA, SANTANU. Recorded Jul 23, 2008
From: SINHA, SANTANU
To: CISCO TECHNOLOGY, INC.
Reel/Frame 021282/0990 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2007
From: SANTANU, SINHA; BATCHER, KENNETH WILLIAM
To: CISCO TECHNOLOGY, INC.
Reel/Frame 019369/0417 →
Continuity (1)
Related Publication 20080301429A1 · Dec 4, 2008