IP Library Granted Patent US 12,034,694
Granted Patent B2
US 12,034,694 · App. 18/238,177 · Granted Jul 9, 2024

Performance improvement of IPsec traffic using SA-groups and mixed-mode SAs

Inventor: Sudesh Pawar (Pune, IN)
Assignee: VMware LLC
H04L61/251H04L12/4633H04L61/2571
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,034,694
App. No.
18/238,177
Granted
Jul 9, 2024
Kind
B2
Abstract

Some embodiments provide a method of load balancing data message flows across multiple secure connections. The method receives a data message having source and destination addresses formatted according to a first protocol. Based on the source and destination addresses, the method selects one of the multiple secure connections for the data message. Each of the secure connections handles a first set of connections formatted according to the first protocol and a second set of connections formatted according to a second protocol that is an alternative to the first protocol. The method securely encapsulates the data message and forwards the encapsulated data message onto a network. The encapsulation includes an identifier for the selected secure connection.

Claims (40)

1. A method of forwarding encrypted packets between a source and a destination, the method comprising:

receiving a data message flow that uses an IPv4 (Internet Protocol version 4) protocol or an IPv6 (version 6) protocol;

selecting one mixed-mode security association (SA) from a plurality of mixed-mode SAs, each mixed-mode SA for use to encrypt IPv4 or IPv6 data message flows;

using the selected mixed-mode SA to encrypt and encapsulate the data message flow; and

forwarding the encapsulated data message flow to the destination, wherein the encapsulation comprises an identifier for the selected SA.

2. The method of claim 1 , wherein selecting the mixed-mode SA comprises performing a load balancing operation to select the mixed-mode SA from the plurality of SA.

3. The method of claim 2 , wherein performing the load balancing operation comprises using a set of attributes of the data message flow to perform the load balancing operation.

4. The method of claim 3 , wherein the set of attributes comprises a set of one or more header values of the data message flow.

5. The method of claim 4 , wherein using the set of attributes comprises:

generating a hash value from the set of header values;

using the generated hash value to select the mixed-mode SA from the plurality mixed-mode SAs.

6. The method of claim 1 , wherein the method is performed by a first gateway device of a first site that includes a source machine from which the data message flow originates.

7. The method of claim 6 further comprising:

before receiving the data message:

during a key exchange session with a second gateway device of a second site that includes a destination machine to which the data message flow is destined;

creating the plurality of SAs; and

enabling a mixed mode for each of the plurality of SAs to allow each SA to be useable for encrypting IPv4 or IPv6 flows.

8. The method of claim 6 , wherein each encapsulated data message of the flow has an outer destination address of a second gateway device that receives the encapsulated data message and assigns the data message to a particular one of its processing cores based on the identifier for the selected SA.

9. The method of claim 1 further comprising, prior to selecting one of the plurality of SAs, performing a routing operation by using an IPv4 or an IPv6 routing table based on whether the data message flow is an IPv4 or IPv6 flow.

10. The method of claim 1 , wherein the identifier comprises a security parameter index (SPI).

11. A non-transitory machine readable medium storing a program for execution by a set of processing units to forward encrypted packets between a source and a destination, the program comprising sets of instructions for:

receiving a data message flow that uses an IPv4 (Internet Protocol version 4) protocol or an IPv6 (version 6) protocol;

selecting one mixed-mode security association (SA) from a plurality of mixed-mode SAs, each mixed-mode SA for use to encrypt IPv4 or IPv6 data message flows;

using the selected mixed-mode SA to encrypt and encapsulate the data message flow; and

forwarding the encapsulated data message flow to the destination, wherein the encapsulation comprises an identifier for the selected SA.

12. The non-transitory machine readable medium of claim 11 , wherein the set of instructions for selecting the mixed-mode SA comprises a set of instructions for performing a load balancing operation to select the mixed-mode SA from the plurality of SA.

13. The non-transitory machine readable medium of claim 12 , wherein the set of instructions for performing the load balancing operation comprises a set of instructions for using a set of attributes of the data message flow to perform the load balancing operation.

14. The non-transitory machine readable medium of claim 13 , wherein the set of attributes comprises a set of one or more header values of the data message flow.

15. The non-transitory machine readable medium of claim 14 , wherein the set of instructions for using the set of attributes comprises sets of instructions for:

generating a hash value from the set of header values;

using the generated hash value to select the mixed-mode SA from the plurality mixed-mode SAs.

16. The non-transitory machine readable medium of claim 11 , wherein the program executes on a first gateway device of a first site that includes a source machine from which the data message flow originates.

17. The non-transitory machine readable medium of claim 16 , where the program further comprises sets of instructions for:

before receiving the data message:

during a key exchange session with a second gateway device of a second site that includes a destination machine to which the data message flow is destined;

creating the plurality of SAs; and

enabling a mixed mode for each of the plurality of SAs to allow each SA to be useable for encrypting IPv4 or IPv6 flows.

18. The non-transitory machine readable medium of claim 16 , wherein each encapsulated data message of the flow has an outer destination address of a second gateway device that receives the encapsulated data message and assigns the data message to a particular one of its processing cores based on the identifier for the selected SA.

19. The non-transitory machine readable medium of claim 11 , wherein the program further comprises a set of instructions for, prior to selecting one of the plurality of SAs, performing a routing operation by using an IPv4 or an IPv6 routing table based on whether the data message flow is an IPv4 or IPv6 flow.

20. The non-transitory machine readable medium of claim 11 , wherein the identifier comprises a security parameter index (SPI).

Assignments (1)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
Priority Claims (1)
IN 202241002279 · Jan 14, 2022 · national
Continuity (2)
Continuation 17715510 · Apr 7, 2022
Related Publication 20230403252A1 · Dec 14, 2023