IP Library Granted Patent US 12,348,486
Granted Patent B2
US 12,348,486 · App. 18/610,074 · Granted Jul 1, 2025

Randomized SPI for distributed IPsec

Inventors: Ayan Chattopadhyay (Bangalore, IN); Vikram Menon (Bangalore, IN)
Assignee: Parallel Wireless, Inc.
H04L63/0236H04L9/0643H04L63/029H04L63/0485
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,486
App. No.
18/610,074
Granted
Jul 1, 2025
Kind
B2
Abstract

A method and computer readable software for providing randomized Security Parameter Index (SPI) for distributed Internet Protocol security (IPsec) are disclosed. In one embodiment a method includes designating each IPsec node with a unique node identifier, the IPsec node; performing a hash function on a random SPI to provide a randomized SPI; and assigning the randomized SPI to an IPsec tunnel associated with an IPsec node.

Claims (25)

1. A method for providing randomized Security Parameter Index (SPI) for distributed Internet Protocol security (IPsec) in a cellular telecommunications network, comprising:

designating each IPsec node with a unique node identifier;

performing a hash function on a random SPI to provide a randomized SPI, wherein the random SPI is a generated number over SPI space, the random SPI having a length corresponding to a full space available for use by the SPI space, and wherein the hashing is performed using a hash collision resistant algorithm;

assigning the randomized SPI to an IPsec tunnel associated with the each IPsec node;

splitting an IPsec subsystem into multiple IPsec virtual nodes, each of the multiple IPsec virtual node being a logical unit that will be associated with a set of IPsec tunnels, and

distributing tunnels associated with the split IPsec subsystem among the multiple IPsec virtual nodes,

wherein the multiple IPsec virtual nodes are thereby configured to act in a failover configuration in a cellular telecommunications network.

2. The method of claim 1 , further comprising assigning to a load balancer an IPsec node associated with the incoming IPsec packet, then forwarding the packet to the assigned IPsec node.

3. The method of claim 1 , further comprising generating the randomized SPI uniformly for statistically uniform distribution of SPIs over IPsec nodes.

4. The method of claim 1 , wherein a plurality of the IPsec nodes are eNodeBs in a Long Term Evolution (LTE) telecommunications network, and wherein the IPsec tunnels provide traffic security between the eNodeBs and an LTE core network.

5. The method of claim 1 , further comprising using a modulo operation on the randomized SPI to designate the unique node identifier.

6. The method of claim 1 , further comprising, at an IPsec terminating node, assigning the randomized SPI to the IPsec tunnel associated with the each IPsec node.

7. The method of claim 1 , further comprising, at an IPsec terminating node, splitting the IPsec subsystem into multiple IPsec virtual nodes each associated with a set of IPsec tunnels with a random SPI generated using random numbers having lengths equal to the full space available for use by the SPI space.

8. The method of claim 1 , wherein a first IPsec terminating node and a second IPsec terminating node are nodes in a Long Term Evolution (LTE) telecommunications network.

9. A non-transitory computer-readable medium containing instructions for randomized Security Parameter Index (SPI) for distributed Internet Protocol security (IPsec), which, when executed, cause a system to perform steps comprising:

designating each IPsec node with a unique node identifier;

performing a hash function on a random SPI to provide a randomized SPI wherein the random SPI is a generated number over SPI space, the random SPI having a length corresponding to a full space available for use by the SPI space, and wherein the hashing is performed using a hash collision resistant algorithm;

assigning the randomized SPI to an IPsec tunnel associated with the each IPsec node;

splitting an IPsec subsystem into multiple IPsec virtual nodes, each of the multiple IPsec virtual node being a logical unit that will be associated with a set of IPsec tunnels, and

distributing tunnels associated with the split IPsec subsystem among the multiple IPsec virtual nodes,

wherein the multiple IPsec virtual nodes are thereby configured to act in a failover configuration in a cellular telecommunications network.

10. The computer-readable medium of claim 9 , the steps further comprising assigning to a load balancer a node associated with the incoming IPsec packet, then forwarding the packet to the IPsec node.

11. The computer-readable medium of claim 9 , wherein a plurality of the IPsec nodes are eNodeBs in a Long Term Evolution (LTE) telecommunications network, and wherein the IPsec tunnels provide traffic security between the eNodeBs and an LTE core network.

12. The computer-readable medium of claim 9 , the steps further comprising using a modulo operation on the randomized SPI to designate the unique node identifier.

13. The computer-readable medium of claim 9 , the steps further comprising generating the randomized SPI uniformly to ensure statistically uniform distribution of SPIs over IPsec nodes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2025
From: CHATTOPADHYAY, AYAN; MENON, VIKRAM
To: PARALLEL WIRELESS, INC.
Reel/Frame 071042/0744 →
Continuity (3)
Continuation 17080836 · Oct 26, 2020
Provisional Application 62926160 · Oct 25, 2019
Related Publication 20240236042A1 · Jul 11, 2024
References Cited (5)
US 7181612B1 · Pellacuru · 2007 [cited by examiner]
US 9356912B2 · Hu · 2016 [cited by examiner]
US 20070133467A1 · Hsu · 2007 [cited by examiner]
US 20170374025A1 · Pan · 2017 [cited by examiner]
US 20190166109A1 · Wang · 2019 [cited by examiner]