IP Library Granted Patent US 9,537,872
Granted Patent B2
US 9,537,872 · App. 14/587,947 · Granted Jan 3, 2017

Secure neighbor discovery (SEND) using pre-shared key

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,537,872
App. No.
14/587,947
Granted
Jan 3, 2017
Kind
B2
Abstract

An extension is provided to the SEND protocol without requiring a CGA or third party trust anchor. A shared key is provided to both a sender and receiver of a neighbor discovery (ND) message. A digital signature option is contained in the ND message. A digital signature field is determined by the algorithm field in the option. When the ND message is received, the receiver may verify the digital signature field using the pre-shared key according to the algorithm field. If the ND message passes verification, the receiver may process the message.

Claims (54)

1. A method for verifying a neighbor discovery message, comprising:

receiving a neighbor discovery message from a first computer by a second computer, the neighbor discovery message including an algorithm identifier, an algorithm, and an encryption type identifier;

detecting the algorithm identifier;

accessing the algorithm identifier and algorithm from the neighbor discovery message;

identifying that the algorithm identifier corresponds to a value in an algorithm table at the second computer, wherein the value is in a row and in an algorithm field column of the algorithm table;

identifying an encryption type based on an entry appearing in the same row as the value and in a digital signature field column of the algorithm table;

identifying that the received neighbor discovery message is according to a standard Secure Network Discovery (SEND) protocol;

performing a verification of the received neighbor discovery message by the second computer based on the algorithm identifier, the algorithm, and a key; and

discarding, by the second computer, the received neighbor discovery message based on identifying that the message is according to the standard SEND protocol.

2. The method of claim 1 , wherein the key at the second computer is shared with the first computer, the first computer generating the message based on the key and the algorithm.

3. The method of claim 1 , wherein the algorithm identifier includes a value associated with a type of algorithm, the algorithm identifier stored in an algorithm field.

4. The method of claim 1 , wherein the verification is performed by a module operating at the link layer as an extension to the SEND protocol.

5. The method of claim 1 , the method further comprising:

identifying the received neighbor discovery message passes the verification.

6. The method of claim 1 , further comprising:

identifying the received neighbor discovery message fails the verification.

7. The method of claim 1 , further comprising:

detecting an option defined in a SEND protocol in the received neighbor discovery message.

8. A non-transitory computer readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for verifying a neighbor discovery message, the method comprising:

receiving a neighbor discovery message from a first computer by, the neighbor discovery message including an algorithm identifier, an algorithm, and an encryption type identifier;

detecting the algorithm identifier;

accessing the algorithm identifier and algorithm from the neighbor discovery message;

identifying that the algorithm identifier corresponds to a value in an algorithm table at the second computer, wherein the value is in a row and in an algorithm field column of the algorithm table;

identifying an encryption type based on an entry appearing in the same row as the value and in a digital signature field column of the algorithm table;

identifying that the received neighbor discovery message is according to a standard Secure Network Discovery (SEND) protocol;

performing a verification of the received neighbor discovery message based on the algorithm identifier, the algorithm, and a key; and

discarding, by the second computer, the received neighbor discovery message based on identifying that the message is according to the standard SEND protocol.

9. The non-transitory computer readable storage medium of claim 8 wherein the key is shared with the first computer, the first computer generating the message based on the key and the algorithm.

10. The non-transitory computer readable storage medium of claim 8 , wherein the algorithm identifier includes a value associated with a type of algorithm, the algorithm identifier stored in an algorithm field.

11. The non-transitory computer readable storage medium of claim 8 , wherein the verification is performed by a module operating at the link layer as an extension to the SEND protocol.

12. The non-transitory computer readable storage medium of claim 8 , the program further executable to:

identify that the received neighbor discovery message passes the verification.

13. The non-transitory computer readable storage medium of claim 8 , wherein the program is further executable to:

identify the received neighbor discovery message fails the verification.

14. The non-transitory computer readable storage medium of claim 8 , wherein the program is further executable to:

detect an option defined in a SEND protocol in the received neighbor discovery message.

15. A system for verifying a neighbor discovery message, the system comprising:

a server including a memory and a processor; and

one or more modules stored in the memory and executed by the processor to:

receive a neighbor discovery message from a first computer by a second computer, the neighbor discovery message including an algorithm identifier, an algorithm, and an encryption type identifier,

detect the algorithm identifier;

access the algorithm identifier and algorithm from the neighbor discovery message,

identify that the algorithm identifier corresponds to a value in an algorithm table at the second computer, wherein the value is in a row and in an algorithm field column of the algorithm table,

identify an encryption type based on an entry appearing in the same row as the value and in a digital signature field column of the algorithm table,

identify that the received neighbor discovery message is according to a standard Secure Network Discovery (SEND) protocol,

perform a verification of the received neighbor discovery message by the second computer based on the algorithm identifier, algorithm, and a key, and

discard, by the second computer, the received neighbor discovery message based on identifying that the message is according to the standard SEND protocol.

16. The system of claim 15 , wherein the key at the second computer is shared with the first computer, the first computer generating the message based on the key and the algorithm.

17. The system of claim 15 , wherein the algorithm identifier includes a value associated with a type of algorithm, the algorithm identifier stored in an algorithm field.

18. The system of claim 15 , wherein the verification is performed by a module operating at the link layer as an extension to the SEND protocol.

19. The system of claim 15 , the modules further executable to:

identify that the received neighbor discovery message passes the verification.

20. The system of claim 15 , the modules further executable to identify that the received neighbor discovery message fails the verification.

21. The system of claim 15 , the modules further executable to detect an option defined in a SEND protocol in the received neighbor discovery message.

Assignments (19)
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT RF 046321/0393 Recorded Jun 16, 2025
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SONICWALL US HOLDINGS INC.
Reel/Frame 071625/0887 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0414 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: SONICWALL US HOLDINGS INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 046321/0393 →
CHANGE OF NAME Recorded May 29, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 047058/0082 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded May 16, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046169/0718 →
CHANGE OF NAME Recorded May 15, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046163/0137 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED AT REEL: 041073 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE INTELLECTUAL PROPERTY ASSIGNMENT.. Recorded Apr 5, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS INC.
Reel/Frame 042168/0114 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 23, 2017
From: QUEST SOFTWARE INC.
To: SONICWALL US HOLDINGS, INC.
Reel/Frame 041073/0001 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
MERGER Recorded Dec 16, 2015
From: SONICWALL L.L.C.
To: DELL SOFTWARE INC.
Reel/Frame 037308/0976 →
CONVERSION AND NAME CHANGE Recorded Dec 16, 2015
From: SONICWALL, INC.
To: SONICWALL L.L.C.
Reel/Frame 037312/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2014
From: LIU, YUN FENG; CHEN, ZHONG; XIANG, ERIC; YANG, YANJUN
To: SONICWALL, INC.
Reel/Frame 034608/0559 →