IP Library › Granted Patent US 11,818,141
Granted Patent B2
US 11,818,141 · App. 17/546,492 · Granted Nov 14, 2023

Path validation checks for proof of security

Inventors: Craig Thomas Hill (Sterling, VA); Sujal Sheth (Ahmedabad, IN); Frank Brockners (Cologne, DE); Cesar Obediente (Apex, NC)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/123H04L9/0838H04L63/0464H04L63/20H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,818,141
App. No.
17/546,492
Granted
Nov 14, 2023
Kind
B2
Abstract

According to an embodiment, a node comprises one or more processors and one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the node to perform operations. The operations comprise determining security validation information that the node associates with a packet, inserting into the packet an identifier associated with the node and the security validation information that the node associates with the packet, and transmitting the packet comprising the identifier associated with the node and the security validation information that the node associates with the packet. The security validation information comprises one or more proof of security attributes and/or one or more proof of security level attributes.

Claims (41)

1. A node, the node comprising:

one or more processors; and

one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the node to perform operations comprising:

determining security validation information that the node associates with a packet, the security validation information comprising one or more proof of security attributes and/or one or more proof of security level attributes;

inserting into the packet an identifier associated with the node and the security validation information that the node associates with the packet;

transmitting the packet comprising the identifier associated with the node and the security validation information that the node associates with the packet.

2. The node of claim 1 , the operations further comprising:

prior to determining the security validation information, receiving the packet from a previous node, wherein the packet received from the previous node comprises a previous identifier associated with the previous node and previous security validation information that the previous node associates with the packet;

wherein the identifier associated with the node and the security validation information that the node associates with the packet are inserted before or after the previous identifier and the previous security validation information.

3. The node of claim 1 , wherein the security validation information comprises at least one proof of security attribute determined based on a header present in the packet when the node processes the packet, said at least one proof of security attribute indicating a security type or information associated with the security type.

4. The node of claim 1 , wherein the security validation information comprises one or more of the following proof of security level attributes: an encryption algorithm, a cipher, a cipher strength, or a key length.

5. The node of claim 1 , wherein the security validation information comprises one or more of the following proof of security level attributes: integrity algorithm, a rekey count indicating a number of times that a new key has been derived, a rekey time, anti-replay configuration, Perfect Forward Secrecy (PFS) configuration, Diffie-Hellman algorithm used in deriving session keys (enc, iv), or an authentication method.

6. The node of claim 1 , wherein the security validation information that the node associates with the packet comprises security validation information associated with a Layer 2 connection for a hop in a path traversed by the packet.

7. The node of claim 1 , wherein the security validation information that the node associates with the packet comprises security validation information associated with a Layer 3 connection spanning multiple hops in a path traversed by the packet.

8. The node of claim 1 , wherein the security validation information that the node associates with the packet is inserted in an in-situ Operation and Maintenance (iOAM) field within the packet.

9. The node of claim 1 , wherein the packet is transmitted to a next node configured to insert into the packet a next identifier associated with the next node and next security validation information that the next node associates with the packet.

10. The node of claim 1 , wherein the packet is transmitted to a security manager configured to analyze the security validation information inserted by the node together with additional security validation information inserted by other nodes of a path traversed by the packet.

11. A method performed by a node, the method comprising:

determining security validation information that the node associates with a packet, the security validation information comprising one or more proof of security attributes and/or one or more proof of security level attributes;

inserting into the packet an identifier associated with the node and the security validation information that the node associates with the packet;

transmitting the packet comprising the identifier associated with the node and the security validation information that the node associates with the packet.

12. The method of claim 11 , further comprising:

prior to determining the security validation information, receiving the packet from a previous node, wherein the packet received from the previous node comprises a previous identifier associated with the previous node and previous security validation information that the previous node associates with the packet;

wherein the identifier associated with the node and the security validation information that the node associates with the packet are inserted before or after the previous identifier and the previous security validation information.

13. The method of claim 11 , wherein the security validation information that the node associates with the packet is inserted in an in-situ Operation and Maintenance (iOAM) field within the packet and the security validation information comprises at least one proof of security attribute determined based on a header present in the packet when the node processes the packet, said at least one proof of security attribute indicating a security type or information associated with the security type.

14. The method of claim 11 , wherein the security validation information that the node associates with the packet is inserted in an in-situ Operation and Maintenance (iOAM) field within the packet and the security validation information comprises one or more of the following proof of security level attributes: an encryption algorithm, a cipher, a cipher strength, or a key length.

15. The method of claim 11 , wherein the security validation information that the node associates with the packet comprises one or more of the following:

security validation information associated with a Layer 2 connection for a hop in a path traversed by the packet; and/or

security validation information associated with a Layer 3 connection spanning multiple hops in the path traversed by the packet.

16. One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor of a node, cause the performance of operations comprising:

determining security validation information that the node associates with a packet, the security validation information comprising one or more proof of security attributes and/or one or more proof of security level attributes;

inserting into the packet an identifier associated with the node and the security validation information that the node associates with the packet;

transmitting the packet comprising the identifier associated with the node and the security validation information that the node associates with the packet.

17. The one or more computer-readable non-transitory storage media of claim 16 , the operations further comprising:

prior to determining the security validation information, receiving the packet from a previous node, wherein the packet received from the previous node comprises a previous identifier associated with the previous node and previous security validation information that the previous node associates with the packet;

wherein the identifier associated with the node and the security validation information that the node associates with the packet are inserted before or after the previous identifier and the previous security validation information.

18. The one or more computer-readable non-transitory storage media of claim 16 , wherein the security validation information that the node associates with the packet is inserted in an in-situ Operation and Maintenance (iOAM) field within the packet and the security validation information comprises at least one proof of security attribute determined based on a header present in the packet when the node processes the packet, said at least one proof of security attribute indicating a security type or information associated with the security type.

19. The one or more computer-readable non-transitory storage media of claim 16 , wherein the security validation information that the node associates with the packet is inserted in an in-situ Operation and Maintenance (iOAM) field within the packet and the security validation information comprises one or more of the following proof of security level attributes: an encryption algorithm, a cipher, a cipher strength, or a key length.

20. The one or more computer-readable non-transitory storage media of claim 16 , wherein the security validation information that the node associates with the packet comprises one or more of the following:

security validation information associated with a Layer 2 connection for a hop in a path traversed by the packet; and/or

security validation information associated with a Layer 3 connection spanning multiple hops in the path traversed by the packet.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2021
From: HILL, CRAIG THOMAS; SHETH, SUJAL; BROCKNERS, FRANK; OBEDIENTE, CESAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 058347/0803 →
Continuity (1)
Related Publication 20230188534A1 · Jun 15, 2023