IP Library Granted Patent US 9,225,699
Granted Patent B2
US 9,225,699 · App. 13/631,983 · Granted Dec 29, 2015

Security key generation in link aggregation group topologies

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,225,699
App. No.
13/631,983
Granted
Dec 29, 2015
Kind
B2
Abstract

A method, system and computer readable medium for security key generation in link aggregation group topologies. The method can include performing, using one or more processors, authentication on each port of a plurality of ports in a link aggregation group. The method can also include deriving, using the one or more processors, a connectivity association key for the link aggregation group. The method can further include computing, using the one or more processors, a security association key for each port in the plurality of ports, the security association key being based on the connectivity association key for the link aggregation group.

Claims (30)

1. A method for security key generation in link aggregation group topologies, the method comprising:

performing, using one or more processors, authentication on each port of a plurality of ports in a link aggregation group;

deriving, using the one or more processors, a connectivity association key for the link aggregation group on a per link aggregation group basis; and

computing, using the one or more processors, a security association key for each port in the plurality of ports, the security association key being based on the connectivity association key for the link aggregation group.

2. The method of claim 1 , wherein the deriving includes performing a key derivation function.

3. The method of claim 2 , wherein the key derivation function receives a master session key and a plurality of link aggregation group media access control addresses.

4. The method of claim 1 , wherein the computing includes performing a key derivation function.

5. The method of claim 4 , wherein the key derivation function receives a link aggregation group connectivity association key, a label, a member identifier and a key length.

6. The method of claim 1 , further comprising re-authenticating at a predetermined time interval, wherein the re-authenticating includes repeating the performing, deriving and computing.

7. A system comprising:

one or more processors coupled to a nontransitory computer readable medium having stored thereon software instructions that, when executed by the one or more processors, cause the one or more processors to perform a series of operations, the series of operations including:

performing authentication on each port of a plurality of ports in a link aggregation group;

deriving a connectivity association key for the link aggregation group; and

computing a security association key for each port in the plurality of ports, the security association key being based on the connectivity association key for the link aggregation group.

8. The system of claim 7 , wherein the deriving includes performing a key derivation function.

9. The system of claim 8 , wherein the key derivation function receives a master session key and a plurality of link aggregation group media access control addresses.

10. The system of claim 7 , wherein the computing includes performing a key derivation function.

11. The system of claim 10 , wherein the key derivation function receives a link aggregation group connectivity association key, a label, a member identifier and a key length.

12. The system of claim 7 , wherein the operations further include re-authenticating at a predetermined time interval, and wherein the re-authenticating includes repeating the performing, deriving and computing.

13. A nontransitory computer readable medium having stored thereon software instructions that, when executed by a processor, cause the processor to perform a series of operations comprising:

performing authentication on each port of a plurality of ports in a link aggregation group;

deriving a connectivity association key for the link aggregation group; and

computing a security association key for each port in the plurality of ports, the security association key being based on the connectivity association key for the link aggregation group.

14. The nontransitory computer readable medium of claim 13 , wherein the deriving includes performing a key derivation function.

15. The nontransitory computer readable medium of claim 14 , wherein the key derivation function receives a master session key and a plurality of link aggregation group media access control addresses.

16. The nontransitory computer readable medium of claim 13 , wherein the computing includes performing a key derivation function.

17. The nontransitory computer readable medium of claim 16 , wherein the key derivation function receives a link aggregation group connectivity association key, a label, a member identifier and a key length.

18. The nontransitory computer readable medium of claim 13 , wherein the operations further include re-authenticating at a predetermined time interval.

19. The nontransitory computer readable medium of claim 18 , wherein the re-authenticating includes repeating the performing, deriving and computing.

20. The nontransitory computer readable medium of claim 13 , wherein the operations further include deriving a connectivity association key for each of a plurality of link aggregation groups on a single switch, each connectivity association key being derived on a per link aggregation group basis.

Assignments (13)
AMENDED SECURITY AGREEMENT Recorded Aug 18, 2023
From: EXTREME NETWORKS, INC.; AEROHIVE NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 064782/0971 →
SECURITY INTEREST Recorded May 1, 2018
From: EXTREME NETWORKS, INC.
To: BANK OF MONTREAL
Reel/Frame 046050/0546 →
RELEASE OF SECURITY INTEREST Recorded May 1, 2018
From: SILICON VALLEY BANK
To: EXTREME NETWORKS, INC.
Reel/Frame 046051/0775 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 029608/0256 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 044891/0801 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
THIRD AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Oct 31, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 044639/0300 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: AVAYA INC.; AVAYA COMMUNICATION ISRAEL LTD; AVAYA HOLDINGS LIMITED
To: EXTREME NETWORKS, INC.
Reel/Frame 043569/0047 →
SECOND AMENDED AND RESTATED PATENT AND TRADEMARK SECURITY AGREEMENT Recorded Jul 14, 2017
From: EXTREME NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 043200/0614 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Jan 10, 2013
From: AVAYA, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 029608/0256 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2012
From: BIRADAR, SUDHAKAR; RAMESH, DEEPAK
To: AVAYA INC.
Reel/Frame 029294/0827 →