IP Library › Granted Patent US 12,316,623
Granted Patent B2
US 12,316,623 · App. 18/314,436 · Granted May 27, 2025

Verifying the authenticity of internet key exchange messages in a virtual private network

Inventors: Ravi Suhane (Bangalore, IN); Amit Agrawal (Bangalore, IN); Nagendra Babu Rapaka (Bangalore, IN)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/0823H04L9/0819H04L9/3073H04L9/3268H04L63/0272H04L63/0485H04L63/123H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,623
App. No.
18/314,436
Granted
May 27, 2025
Kind
B2
Abstract

Some examples relate to a verifying the authenticity of IKE exchange messages in a VPN. In an example, a VPN client sends a VPN server profile request message to a VPN server for establishing a VPN connection. In response, the VPN server provides a VPN server profile to the VPN client. The VPN server profile comprises a cryptographic public key associated with a server certificate of the VPN server. The VPN client stores the VPN server profile and sends an IKE message to the VPN server. In response to the IKE message, the VPN server sends a signed IKE response message. Upon receipt, the VPN client verifies the authenticity of the signed IKE response message. If the signed IKE message is successfully verified, the VPN client sends an identity of the VPN client to the VPN server.

Claims (45)

1. A method comprising:

sending, by a virtual private network (VPN) client, a VPN server profile request message to a VPN server during a first log in by the VPN client to the VPN server;

in response to the VPN server profile request message, receiving, by the VPN client, from the VPN server, a VPN server profile comprising a public key of a public-private key pair associated with a server certificate of the VPN server;

storing, by the VPN client, the VPN server profile;

sending, by the VPN client, an Internet Key Exchange (IKE) message to the VPN server;

in response to the IKE message, receiving, by the VPN client, from the VPN server, a signed IKE response message signed using a private key of the public-private key pair associated with the server certificate;

verifying, by the VPN client, authenticity of the signed IKE response message received from the VPN server, wherein verifying comprises:

retrieving, by the VPN client, from the VPN server profile, the public key of the public-private key pair associated with the server certificate; and

verifying, by the VPN client, the signed IKE response message using the public key; and

in response to successfully verifying the signed IKE response message, sending, by the VPN client, an identity of the VPN client to the VPN server.

2. The method of claim 1 , further comprising:

establishing, by the VPN client, a VPN connection with the VPN server.

3. The method of claim 2 , wherein establishing the VPN connection comprises creating an Internet Protocol Security (IPsec) tunnel between the VPN client and the VPN server.

4. The method of claim 1 , further comprising:

receiving, by the VPN client, from the VPN server, additional signed IKE response messages signed using the private key of the public-private key pair associated with the server certificate; and

verifying, by the VPN client, authenticity of each of the additional signed IKE response messages comprising:

retrieving, by the VPN client, from the VPN server profile, the public key of the public-private key pair associated with the server certificate; and

verifying, by the VPN client, each of the additional signed IKE response messages using the public key.

5. The method of claim 1 , further comprising:

in response to unsuccessfully verifying the signed IKE response message, abstaining, by the VPN client, to send an identity of the VPN client to the VPN server.

6. The method of claim 1 , wherein the VPN server profile is received one time from the VPN server.

7. The method of claim 1 , wherein:

the VPN server profile request message and the VPN server profile are exchanged over a first port on the VPN client; and

the IKE message and the signed IKE response message are exchanged over a second port on the VPN client.

8. The method of claim 1 , wherein the VPN server profile comprises a pre-shared key (PSK).

9. The method of claim 8 , wherein the PSK is a shared PSK that is provided to other VPN clients that log in to the VPN server.

10. The method of claim 1 , wherein the VPN server profile request is sent over an authenticated connection.

11. The method of claim 10 , wherein the authenticated connection is a Transport Layer Security (TLS) connection.

12. A non-transitory machine-readable storage medium comprising instructions that upon execution cause a virtual private network (VPN) client to:

send a VPN server profile request message to a VPN server during a first log in by the VPN client to the VPN server;

in response to the VPN server profile request message, receive from the VPN server, a VPN server profile comprising a public key of a public-private key pair associated with a server certificate of the VPN server;

store the VPN server profile;

send an Internet Key Exchange (IKE) message to the VPN server;

in response to the IKE message, receive from the VPN server, a signed IKE response message signed using a private key of the public-private key pair associated with the server certificate;

verify authenticity of the signed IKE response message received from the VPN server, wherein to verify comprises:

retrieve from the VPN server profile, the public key of the public-private key pair associated with the server certificate; and

verify the signed IKE response message using the public key; and

in response to a successful verification of the signed IKE response message, send an identity of the VPN client to the VPN server.

13. The non-transitory machine-readable storage medium of claim 12 , wherein the IKE message is an IKE tunnel negotiation message.

14. The non-transitory machine-readable storage medium of claim 12 , wherein the VPN server profile is received over an authenticated connection.

15. The non-transitory machine-readable storage medium of claim 14 , wherein the authenticated connection is a Transport Layer Security (TLS) connection.

16. The non-transitory machine-readable storage medium of claim 12 , wherein the identity of the VPN client comprises a media access control (MAC) address of the VPN client.

17. The non-transitory machine-readable storage medium of claim 12 , wherein the identity of the VPN client comprises a user name provided through the VPN client.

18. The non-transitory machine-readable storage medium of claim 12 , wherein the identity of the VPN client comprises a string of characters assigned to the VPN client.

19. The non-transitory machine-readable storage medium of claim 12 , further comprising instructions to establish an IPsec tunnel between the VPN client and the VPN server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2023
From: SUHANE, RAVI; AGRAWAL, AMIT; RAPAKA, NAGENDRA BABU
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 064105/0833 →
Priority Claims (1)
IN 202341012031 · Feb 22, 2023 · national
Continuity (1)
Related Publication 20240283776A1 · Aug 22, 2024
References Cited (9)
US 8738897B2 · Mukkara · 2014 [cited by applicant]
US 9350708B2 · Wong et al. · 2016 [cited by applicant]
US 10149166B2 · Mazzuca et al. · 2018 [cited by applicant]
US 10270603B2 · Yang et al. · 2019 [cited by applicant]
US 20030145227A1 · Boden · 2003 [cited by examiner]
US 20090041006A1 · Chiu · 2009 [cited by examiner]
US 20160191478A1 · Pruss · 2016 [cited by examiner]
US 20160285627A1 · Sedlacek · 2016 [cited by examiner]
US 20200320199A1 · Sheth et al. · 2020 [cited by applicant]