IP Library Granted Patent US 12,199,868
Granted Patent B2
US 12,199,868 · App. 17/804,333 · Granted Jan 14, 2025

Optimizing IPSec for hierarchical SD-WAN

Inventors: Samir Thoria (Saratoga, CA); Ram Dular Singh (Cupertino, CA); Laxmikantha Reddy Ponnuru (San Ramon, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L45/76H04L45/50H04L45/64H04L63/0485
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,199,868
App. No.
17/804,333
Granted
Jan 14, 2025
Kind
B2
Abstract

According to some embodiments, a method is performed by a software defined wide area network (SD-WAN) edge router in a hierarchical SD-WAN network comprising a plurality of edge routers and a plurality of border routers. The method comprises: originating a SD-WAN system route for advertising reachability to the edge router, the system route comprising an encryption key associated with the edge router; and transmitting the system route to one or more SD-WAN border routers. The method may further comprise: receiving a packet destined for the edge router from one of the one or more SD-WAN border routers, wherein the packet is at least partially encrypted with the encryption key associated with the edge router; and decrypting the received packet.

Claims (47)

1. A method performed by a software defined wide area network (SD-WAN) edge router in a hierarchical SD-WAN network comprising a plurality of edge routers and a plurality of border routers, the method comprising:

originating a SD-WAN system route for advertising reachability to the SD-WAN edge router, the SD-WAN system route comprising an encryption key associated with the SD-WAN edge router; and

transmitting the SD-WAN system route to one or more SD-WAN border routers.

2. The method of claim 1 , further comprising:

receiving a packet destined for the SD-WAN edge router from one of the one or more SD-WAN border routers, wherein the packet is at least partially encrypted with the encryption key associated with the SD-WAN edge router, and wherein the encryption key associated with the SD-WAN edge router is unaltered in transit across the one or more SD-WAN border routers; and

decrypting the packet.

3. The method of claim 1 , wherein the SD-WAN system route comprises a SD-WAN Overlay Management Protocol (OMP) route.

4. The method of claim 1 , wherein the encryption key associated with the SD-WAN edge router comprises an Internet Protocol Security (IPSec) Encapsulating Security Payload (ESP) protocol encryption key.

5. The method of claim 1 , wherein the SD-WAN edge router is communicably coupled to one or more of the plurality of border routers via one or more Internet Protocol Security (IPSec) tunnels.

6. A method performed by a software defined wide area network (SD-WAN) border router in a hierarchical SD-WAN network comprising a plurality of edge routers and a plurality of border routers, the method comprising:

receiving a first SD-WAN system route for advertising reachability to an SD-WAN edge router, the first SD-WAN system route comprising an encryption key associated with the SD-WAN edge router;

allocating a local label for the SD-WAN edge router;

originating a second SD-WAN system route for advertising reachability to the SD-WAN edge router, the second SD-WAN system route comprising the local label for the SD-WAN edge router, the encryption key associated with the SD-WAN edge router, and an authentication key associated with the SD-WAN border router; and

transmitting the second SD-WAN system route to one or more SD-WAN border routers or edge routers.

7. The method of claim 6 , further comprising:

receiving a packet destined for the SD-WAN edge router from one of the one or more SD-WAN border routers or edge routers, wherein the packet is at least partially encrypted with the encryption key associated with the SD-WAN edge router and the packet comprises a local transport label, and wherein the encryption key associated with the SD-WAN edge router is unaltered in transit across the one or more SD-WAN border routers;

authenticating the packet using the authentication key associated with the SD-WAN border router;

updating one or more of a local transport label, source address, and destination address associated with the packet; and

forwarding the packet to one of the one or more SD-WAN border routers or edge routers based on the local transport label without decrypting the packet.

8. The method of claim 6 , wherein the second SD-WAN system route comprises a SD-WAN Overlay Management Protocol (OMP) route.

9. The method of claim 6 , wherein the encryption key associated with the SD-WAN edge router comprises an Internet Protocol Security (IPSec) Encapsulating Security Payload (ESP) protocol encryption key.

10. The method of claim 6 , wherein the authentication key associated with the SD-WAN border router comprises an Internet Protocol Security (IPSec) Security Authentication Header (AH) protocol authentication key.

11. The method of claim 6 , wherein the SD-WAN border router is communicably coupled to the one or more border routers or edge routers via one or more Internet Protocol Security (IPSec) tunnels.

12. A software defined wide area network (SD-WAN) system comprising a first edge router communicably coupled to a first border router:

the first edge router comprising a memory comprising instructions and a hardware processor, wherein the first edge router, when executing its instructions at its hardware processor, is configured to:

originate a first SD-WAN system route for advertising reachability to the first edge router, the first SD-WAN system route comprising an encryption key associated with the first edge router; and

transmit the first SD-WAN system route to the first border router; and

the first border router comprising a memory comprising instructions and a hardware processor, wherein the first border router, when executing its instructions at its hardware processor, is configured to:

receive the first SD-WAN system route for advertising reachability to the first edge router;

allocate a local label for the first edge router;

originate a second SD-WAN system route for advertising reachability to the first edge router, the second SD-WAN system route comprising the local label for the first edge router, the encryption key associated with the first edge router, and an authentication key associated with the first border router; and

transmit the second SD-WAN system route to one or more SD-WAN border routers or edge routers.

13. The SD-WAN system of claim 12 , wherein the first edge router is further configured to:

receive a packet destined for the first edge router from the first border router, wherein the packet is at least partially encrypted with the encryption key associated with the first edge router, and wherein the encryption key associated with the first edge router is unaltered in transit across the one or more SD-WAN border routers; and

decrypt the packet.

14. The SD-WAN system of claim 12 , wherein the first border router is further configured to:

receive a packet destined for the first edge router from one of one or more SD-WAN border routers or edge routers, wherein the packet is at least partially encrypted with the encryption key associated with the first edge router and the packet comprises a local transport label;

authenticate the packet using the authentication key associated with the first border router;

update one or more of a local transport label, source address, and destination address associated with the packet; and

forward the packet to one of the one or more SD-WAN border routers or edge routers based on the local transport label without decrypting the packet.

15. The SD-WAN system of claim 12 , wherein the first SD-WAN system route comprises a SD-WAN Overlay Management Protocol (OMP) route.

16. The SD-WAN system of claim 12 , wherein the encryption key associated with the first edge router comprises an Internet Protocol Security (IPSec) Encapsulating Security Payload (ESP) protocol encryption key.

17. The SD-WAN system of claim 12 , wherein the authentication key associated with the first border router comprises an Internet Protocol Security (IPSec) Security Authentication Header (AH) protocol authentication key.

18. The SD-WAN system of claim 12 , wherein the first edge router is communicably coupled to the first border router via an Internet Protocol Security (IPSec) tunnel.

19. The SD-WAN system of claim 12 , wherein the first edge router is further configured to:

encrypt a packet for transmission to a second edge router, wherein the packet is encrypted with an encryption key associated with the second edge router received via a system route originated from the second edge router; and

transmit the packet to the first border router.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2022
From: THORIA, SAMIR; SINGH, RAM DULAR; PONNURU, LAXMIKANTHA REDDY
To: CISCO TECHNOLOGY, INC.
Reel/Frame 060035/0725 →
Continuity (1)
Related Publication 20230388233A1 · Nov 30, 2023
References Cited (26)
US 11863443B2 · Kulkarni · 2024 [cited by examiner]
US 20040093521A1 · Hamadeh · 2004 [cited by examiner]
US 20150023357A1 · Imai · 2015 [cited by examiner]
US 20160218917A1 · Zhang · 2016 [cited by examiner]
US 20170279710A1 · Khan · 2017 [cited by examiner]
US 20180109493A1 · Khan · 2018 [cited by examiner]
US 20190058657A1 · Chunduri · 2019 [cited by examiner]
US 20190372891A1 · Smith · 2019 [cited by examiner]
US 20200250009A1 · Jaeger · 2020 [cited by examiner]
US 20200274794A1 · Zhang · 2020 [cited by examiner]
US 20210092050A1 · Williams · 2021 [cited by examiner]
US 20210160213A1 · Dees · 2021 [cited by examiner]
US 20210243053A1 · Dunbar · 2021 [cited by examiner]
US 20210314411A1 · Madden · 2021 [cited by examiner]
US 20210377154A1 · Dutta · 2021 [cited by examiner]
US 20220070146A1 · Gerstel · 2022 [cited by examiner]
US 20220078103A1 · Prajapat · 2022 [cited by examiner]
US 20220103470A1 · Kulkarni · 2022 [cited by examiner]
US 20220382615A1 · Turk · 2022 [cited by examiner]
US 20230116163A1 · Scholz · 2023 [cited by examiner]
US 20230116881A1 · Mehta · 2023 [cited by examiner]
US 20230246950A1 · Kaimal · 2023 [cited by examiner]
US 20230246960A1 · Kaimal · 2023 [cited by examiner]
US 20230261945A1 · Wang · 2023 [cited by examiner]
IPsec Configuration Guide, Cisco IOS XE 16 (Cisco ASR 920 Series), Cisco Systems, Inc., Jul. 31, 2019. [cited by applicant]
Cisco SD-WAN Security Configuration Guide, Cisco IOS XE Release 17.x, Cisco Systems, Inc., Nov. 22, 2019. [cited by applicant]