IP Library Granted Patent US 10,841,840
Granted Patent B2
US 10,841,840 · App. 16/289,771 · Granted Nov 17, 2020

Processing packets in a computer system

Inventors: Antti-Pekka Liedes (Helsinki, FI); Markus Stenberg (Helsinki, FI)
Assignee: SSH Communications Security OYJ
H04W28/10H04L1/1642H04L29/06H04L47/14H04L69/04H04L69/161
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,841,840
App. No.
16/289,771
Granted
Nov 17, 2020
Kind
B2
Abstract

There is provided a method for determining a sequence number for transmitting a packet from a first apparatus to a second apparatus as part of a flow of packets, determining a flow identifier for identifying a security association for the flow, wherein the flow identifier is determined in dependence on the sequence number, and transmitting the packet includes transmitting the sequence number and the flow identifier to the second apparatus.

Claims (48)

1. A method comprising:

determining a sequence number for transmitting a packet from a first apparatus to a second apparatus as part of a flow of packets;

determining a flow identifier for identifying a security association for the flow, wherein the flow identifier is determined in dependence on the sequence number; and

transmitting said packet comprising the sequence number and the flow identifier to the second apparatus;

wherein said determining a flow identifier comprises at least one of setting the n least significant bits of the flow identifier as a function of the n most significant bits of the sequence number, and determining the flow identifier in dependence on an original identifier of the security association that was determined when the security association was initialised.

2. The method as claimed in claim 1 , wherein said determining a flow identifier comprises setting the n least significant bits of the flow identifier as a function of the n least significant bits of the sequence number.

3. The method as claimed in claim 2 , comprising determining n, wherein n is a function of a number of independent processing entities in the second apparatus that are arranged to process the flow.

4. A method comprising:

receiving a first packet as part of a flow of packets between a first apparatus and a second apparatus, wherein said first packet comprises a sequence number and a flow identifier for identifying a security association for the flow, wherein the flow identifier is a function of the sequence number; and

selecting a processing entity of the second apparatus for processing the first packet in dependence on the flow identifier;

wherein said flow identifier of the first packet is a function of an original identifier of the security association that was determined when the security association was initialised.

5. The method as claimed in claim 4 , wherein the n least significant bits of the sequence number or the n most significant bits of the sequence number are a function of the n least significant bits of the flow identifier.

6. The method as claimed in claim 5 , wherein said selecting comprises selecting a processing entity out of m independent processing entities in the second apparatus that are arranged to process the flow.

7. The method as claimed in claim 5 , wherein the second apparatus comprises the selected processing entity, the method further comprising:

receiving a second packet as part of the flow of packets, wherein said second packet comprises a sequence number and a flow identifier for identifying the security association, wherein the flow identifier of the second packet is a function of the sequence number of the second packet;

selecting the processing entity of the second apparatus for processing the second packet in dependence on the flow identifier; and

checking, by the selected processing entity, all bar the n least significant bits of the sequence number comprised within the first packet to all bar the n least significant bits of the sequence number comprised within the second packet.

8. An apparatus comprising at least one processor and at least one memory comprising computer code that, when executed by the at least one processor, causes the apparatus to:

determine a sequence number for transmitting a packet from a first apparatus to a second apparatus as part of a flow of packets;

determine a flow identifier for identifying a security association for the flow, wherein the flow identifier is determined in dependence on the sequence number; and

transmit said packet comprising the sequence number and the flow identifier to the second apparatus;

configure to determine the flow identifier in dependence on an original identifier of the security association that was determined when the security association was initialised.

9. The apparatus as claimed in claim 8 , configured to set the n least significant bits of the flow identifier as a function of the n least significant bits of the sequence number.

10. An apparatus comprising at least one processor and at least one memory comprising computer code that, when executed by the at least one processor, causes the apparatus to:

determine a sequence number for transmitting a packet from a first apparatus to a second apparatus as part of a flow of packets;

determine a flow identifier for identifying a security association for the flow, wherein the flow identifier is determined in dependence on the sequence number; and

transmit said packet comprising the sequence number and the flow identifier to the second appartus;

determine the flow identifier in dependence on an original identifier of the security association that was determined when the security association was initialised.

11. The apparatus as claimed in claim 8 , configured to set the n least significant bits of the flow identifier as a function of the n most significant bits of the sequence number.

12. An apparatus comprising at least one processor and at least one memory comprising computer code that, when executed by the at least one processor, causes the apparatus to:

receive a first packet as part of a flow of packets between a first apparatus and a second apparatus, wherein said first packet comprises a sequence number and a flow identifier for identifying a security association for the flow, wherein the flow identifier is a function of the sequence number; and

select a processing entity of the second apparatus for processing the first packet in dependence on the flow identifier;

wherein said flow identifier of the first packet is a function of an original identifier of the security association that was determined when the security association was initialised.

13. The apparatus as claimed in claim 12 , wherein the n least significant bits of the sequence number or the n most significant bits of the sequence number are a function of the n least significant bits of the flow identifier.

14. The apparatus as claimed in claim 13 , configured to select a processing entity out of n independent processing entities in the second apparatus that are arranged to process the flow.

15. The apparatus as claimed in claim 13 , wherein the second apparatus comprises the selected processing entity, the apparatus being configured to:

receive a second packet as part of the flow of packets, wherein said first packet comprises a sequence number and a flow identifier for identifying the security association, wherein the flow identifier of the second packet is a function of the sequence number of the second packet;

select the processing entity of the second apparatus for processing the first packet in dependence on the flow identifier; and

check, by the selected processing entity, all bar the n least significant bits of the sequence number comprised within the first packet to all bar the n least significant bits of the sequence number comprised within the second packet.

16. A non-transitory computer readable media comprising program code for causing a processor to perform instructions for a method in a computerized network, the method performed comprising:

determining a sequence number for transmitting a packet from a first apparatus to a second apparatus as part of a flow of packets;

determining a flow identifier for identifying a security association for the flow, wherein the flow identifier is determined in dependence on the sequence number; and

transmitting said packet comprising the sequence number and the flow identifier to the second apparatus;

wherein said determining a flow identifier comprises at least one of setting the n least significant bits of the flow identifier as a function of the n most significant bits of the sequence number, and determining the flow identifier in dependence on an original identifier of the security association that was determined when the security association was initialised.

17. A non-transitory computer readable media comprising program code for causing a processor to perform instructions for a method in a computerized network, the method performed comprising:

receiving a first packet as part of a flow of packets between a first apparatus and a second apparatus, wherein said first packet comprises a sequence number and a flow identifier for identifying a security association for the flow, wherein the flow identifier is a function of the sequence number; and

selecting a processing entity of the second apparatus for processing the first packet in dependence on the flow identifier;

wherein said flow identifier of the first packet is a function of an original identifier of the security association that was determined when the security association was initialised.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2019
From: LIEDES, ANTTI-PEKKA; STENBERG, MARKUS
To: SSH COMMUNICATIONS SECURITY OYJ
Reel/Frame 049153/0580 →
Priority Claims (1)
GB 1803432.2 · Mar 2, 2018 · national
Continuity (1)
Related Publication 20190297533A1 · Sep 26, 2019