IP Library Granted Patent US 10,110,422
Granted Patent B2
US 10,110,422 · App. 14/856,482 · Granted Oct 23, 2018

Methods and systems for controller-based secure session key exchange over unsecured network paths

Inventors: Navneet Yadav (Cupertino, CA); Arivu Ramasamy (San Jose, CA); Aaron Edwards (Sunnyvale, CA)
Assignee: CLOUDGENIX, INC.
H04L41/0668G06F17/30598G06F17/30876H04L12/4633H04L12/4641H04L43/0817H04L45/28H04L47/781H04L47/825H04L63/061H04L69/40H04L43/0811H04L43/10H04L45/22H04L61/1511H04L61/1523H04L61/2503H04W84/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,110,422
App. No.
14/856,482
Granted
Oct 23, 2018
Kind
B2
Abstract

A method includes generating at a multi-tenant controller on a network a common shared secret for establishing a link between a first site and a second site, transmitting the shared secret to each of the first site and the second site over a secured channel, assigning a wall clock based start and end validity period for the shared secret, sending the shared secret with a future validity to allow secure link communication to continue if one or more elements in both sites cannot communicate with the multi-tenant controller and using a separate shared secret per link per VXWAN.

Claims (37)

1. A method comprising:

determining, by a multi-tenant controller on a network, that a link should be established between a first site and a second site on the network;

if a determination is made that a link should be established between the first site and the second site, then generating, by the multi-tenant controller on the network, a unique common shared secret for establishing a secure link between the first site and the second site;

transmitting, by the multi-tenant controller, the unique common shared secret to both the first site and the second site over a secured certificate authenticated channel;

assigning, by the multi-tenant controller, a wall clock based start and end validity period for the common shared secret;

wherein the common shared secret is transmitted with a validity period in the future to allow secure link communication between the first site and the second site to continue, using a secure session key derived from the common shared secret, if one or more elements in both the first and the second site cannot communicate with the multi-tenant controller; and

using a unique corresponding shared secret for each link per VXWAN (virtual extensible wide area network).

2. The method of claim 1 , wherein generation of the shared secret is performed by software.

3. The method of claim 1 , wherein generation of the shared secret is performed by hardware.

4. The method of claim 1 , wherein generation of the shared secret is performed by a software and hardware hybrid.

5. The method of claim 1 , wherein a network connectivity is physical.

6. The method of claim 1 , wherein a network connectivity is logical.

7. The method of claim 1 , wherein a network connectivity is hybrid.

8. A method comprising:

determining, by a multi-tenant controller on a network, that a link should be established between a first channel end point and a second channel end point on the network;

if a determination is made that a link should be established between the first channel end point and the second channel end point, then generating, by the multi-tenant controller, a unique plurality of shared secrets, each shared secret of the plurality of secrets having a corresponding validity period;

transmitting, by the multi-tenant controller, the unique plurality of shared secrets to both the first channel end point and the second channel end point over a secured certificate authenticated channel;

generating a plurality of nonce values for the first channel end point and the second channel end point;

exchanging the nonce values between the first and the second channel end points;

generating a plurality of session keys for secure communication on a channel between the first channel end point and the second channel end point, wherein each session key of the plurality of session keys is generated using a shared secret of the plurality of shared secrets during its corresponding validity period and a nonce value from the first channel end point and from the second channel end point; and

refreshing the plurality of session keys at a predetermined time interval using another shared secret of the plurality of shared secrets during its corresponding validity period.

9. The method of claim 8 , wherein the shared secret is generated by software.

10. The method of claim 8 , wherein the shared secret is generated by hardware.

11. The method of claim 8 , wherein the shared secret is generated by a software and hardware hybrid.

12. The method of claim 8 , wherein a network connectivity is physical.

13. The method of claim 8 , wherein a network connectivity is logical.

14. The method of claim 8 , wherein a network connectivity is hybrid.

15. A system comprising:

a first site;

a second site in communication with the first site via a network;

a non-transitory memory for storing program instructions; and

a multi-tenant controller configured to execute the program instructions, configured to determine that a link should be established between the first site and the second site, configured to generate a unique common shared secret if the multi-tenant controller determines that a link between the first site and the second site should be established, and configured to transmit the shared secret to both the first site and the second site over a secured certificate authenticated channel, wherein the common shared secret is used for generating a session key for secure communication on an established link between the first site and the second site, wherein the multi-tenant controller is configured to assign a wall clock based start and end validity period for the common shared secret, and wherein the session key is generated and valid during the validity period for the common shared secret.

16. The system of claim 15 , wherein the shared secret is generated by software.

17. The system of claim 15 , wherein the shared secret is generated by hardware.

18. The system of claim 15 , wherein the shared secret is generated by a software and hardware hybrid.

19. The system of claim 15 , wherein a network connectivity is physical.

20. The system of claim 15 , wherein a network connectivity is logical.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2021
From: CLOUDGENIX INC.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 058449/0010 →
RELEASE OF SECURITY INTEREST Recorded May 5, 2020
From: COMERICA BANK
To: CLOUDGENIX, INC.
Reel/Frame 052573/0502 →
SECURITY INTEREST Recorded Aug 22, 2018
From: CLOUDGENIX, INC.
To: COMERICA BANK
Reel/Frame 046668/0798 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2015
From: YADAV, NAVNEET; RAMASAMY, ARIVU; EDWARDS, AARON
To: CLOUDGENIX, INC.
Reel/Frame 036710/0269 →
Continuity (2)
Provisional Application 62051293 · Sep 16, 2014
Related Publication 20160080502A1 · Mar 17, 2016
Cited By (1)
US 12,556,443