IP Library Granted Patent US 9,185,097
Granted Patent B2
US 9,185,097 · App. 13/858,266 · Granted Nov 10, 2015

Method and system for traffic engineering in secured networks

Inventor: Uri Elzur (Irvine, CA)
Assignee: Broadcom Corporation
H04L63/08H04L9/083H04L9/321H04L9/3215H04L9/3263H04L63/0823H04L63/164H04L2209/76H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,185,097
App. No.
13/858,266
Granted
Nov 10, 2015
Kind
B2
Abstract

Aspects of a method and system for traffic engineering in an IPSec secured network are provided. In this regard, a node in a network may be authenticated as a trusted third party and that trusted third party may be enabled to acquire security information shared between or among a plurality of network entities. In this manner, the trusted third party may parse, access and operate on IPSec encrypted traffic communicated between or among the plurality of network entities. Shared security information may comprise one or more session keys utilized for encrypting and/or decrypting the IPSec secured traffic. The node may parse IPSec traffic and identify a flow associated with the IPsec traffic. In this manner, the node may generate and/or communicate statistics pertaining to said IPSec secured traffic based on the flow with which the traffic is associated.

Claims (38)

1. A method for computer networking, the method comprising:

authenticating a node in a network as being a trusted third party;

receiving encrypted IPSec secured traffic at the authenticated node;

receiving flow information pertaining to the encrypted IPSec secured traffic at the authenticated node for handling the encrypted IPSec secured traffic; and

forwarding, by the node, the encrypted IPSec secured traffic without decrypting the encrypted IPSec secured traffic based at least in part on the flow information.

2. The method of claim 1 , further comprising registering the node with a directory service in the network, the directory service separate from a server.

3. The method of claim 2 , further comprising receiving authentication for authenticating the node from the directory service.

4. The method of claim 1 , further comprising receiving a certificate from a directory service for the authenticating of the node, the directory service separate from a server.

5. The method of claim 1 , further comprising processing the parsed IPSec secured traffic based at least in part on the identified flow information associated with the parsed IPSec secured traffic.

6. The method of claim 1 , further comprising time division multiplexing the parsed IPSec secured traffic.

7. The method of claim 1 , further comprising exchanging security information with a plurality of network entities via a three-way key negotiation protocol.

8. The method of claim 1 , further comprising sharing security information with a plurality of network entities via a bilateral negotiation.

9. The method of claim 1 , further comprising establishing an end-to-end trust between the node and at least one of a plurality of network entities without security information.

10. The method of claim 1 , wherein the flow information comprises at least one of a source IP address or a destination IP address.

11. The method of claim 1 , wherein the flow information comprises at least one of upper protocol ports or a requested bandwidth.

12. The method of claim 1 , wherein the flow information comprises at least one of a keyword used in data included in a payload of the encrypted IPSec secured traffic or a result of a search for a keyword of the payload of the encrypted IPSec secured traffic prior to encryption.

13. The method of claim 1 , wherein a header and a payload of the IPSec secured traffic is encrypted, and the flow information is distinct from header information included in the header of the IPSec secured traffic.

14. The method of claim 13 , further comprising:

performing, by the node, at least one of enforcing network policies, providing traffic statistics and communicating with management entities based at least in part on the flow information pertaining to the encrypted IPSec secured traffic.

15. A system for computer networking, the system comprising one or more circuits in a node in a network, the one or more circuits operable to:

authenticate a node in a network as being a trusted third party;

receive encrypted IPSec secured traffic at the authenticated node;

receive flow information pertaining to the encrypted IPSec secured traffic at the authenticated node for handling the encrypted IPSec secured traffic; and

forward, by the node, the encrypted IPSec secured traffic without decrypting the encrypted IPSec secured traffic based at least in part on the flow information.

16. The system of claim 15 , wherein the one or more circuits are operable to register the node with a directory service in the network, the directory service separate from a server.

17. The system of claim 16 , wherein the one or more circuits are operable to receive authentication for authenticating the node from the directory service.

18. The system of claim 15 , wherein the one or more circuits are operable to receive a certificate from a directory service for the authenticating of the node, the directory service separate from a server.

19. The system of claim 15 , wherein the one or more circuits are operable to process the parsed IPSec secured traffic based at least in part on the identified flow information associated with the parsed IPSec secured traffic.

20. The system of claim 15 , wherein the one or more circuits are operable to time division multiplex the parsed IPSec secured traffic.

21. A non-transitory computer-readable medium embodying a program executable in at least one computing device, the program comprising code that configures one or more processors to:

authenticate a node in a network as being a trusted third party;

receive encrypted IPSec secured traffic at the authenticated node;

receive flow information pertaining to the encrypted IPSec secured traffic at the authenticated node for handling the encrypted IPSec secured traffic; and

forward, by the node, the encrypted IPSec secured traffic without decrypting the encrypted IPSec secured traffic based at least in part on the flow information.

22. The computer-readable medium of claim 21 , the program further comprising code that configures the one or more processors to exchange security information with a plurality of network entities via a three-way key negotiation protocol.

23. The computer-readable medium of claim 21 , the program further comprising code that configures the one or more processors to share security information with a plurality of network entities via a bilateral negotiation.

24. The computer-readable medium of claim 21 , the program further comprising code that configures the one or more processors to establish an end-to-end trust between the node and at least one of a plurality of network entities without security information.

25. The computer-readable medium of claim 21 , the program further comprising code that configures the one or more processors to receive a certificate from a directory service for the authenticating of the node, the directory service separate from a server.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT NUMBER 9,385,856 TO 9,385,756 PREVIOUSLY RECORDED AT REEL: 47349 FRAME: 001. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER. Recorded Mar 22, 2019
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 051144/0648 →
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE PREVIOUSLY RECORDED ON REEL 047229 FRAME 0408. ASSIGNOR(S) HEREBY CONFIRMS THE THE EFFECTIVE DATE IS 09/05/2018. Recorded Oct 29, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047349/0001 →
MERGER Recorded Oct 4, 2018
From: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047229/0408 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 041712/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: BROADCOM CORPORATION
To: AVAGO TECHNOLOGIES GENERAL IP (SINGAPORE) PTE. LTD.
Reel/Frame 041706/0001 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: BROADCOM CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037806/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2013
From: ELZUR, URI
To: BROADCOM CORPORATION
Reel/Frame 030547/0867 →
Continuity (5)
Continuation 11939910 · Nov 14, 2007
Provisional Application 60865725 · Nov 14, 2006
Provisional Application 60884349 · Jan 10, 2007
Provisional Application 60896590 · Mar 23, 2007
Related Publication 20130227669A1 · Aug 29, 2013