IP Library › Granted Patent US 12,432,059
Granted Patent B2
US 12,432,059 · App. 18/489,317 · Granted Sep 30, 2025

Decentralized internet protocol security key negotiation

Inventors: Kyle Mestery (Woodbury, MN); Grzegorz Boguslaw Duraj (Vancouver, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L9/0894H04L9/0891H04L9/16H04L12/4633H04L12/4641H04L45/24H04L63/0272H04L63/0428H04L63/061H04L63/164H04L67/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,059
App. No.
18/489,317
Granted
Sep 30, 2025
Kind
B2
Abstract

Methods are provided for decentralized key negotiation. One method includes initiating, by a first Internet Key Exchange (IKE) node from among a plurality of IKE nodes, a rekeying process for an Internet Protocol Security (IPSec) communication session established with a client device and serviced by a second IKE node from among the plurality of IKE nodes, and in which a first encryption key is used to encrypt traffic. The method further includes obtaining, by the first IKE node from a key value store, information about the IPSec communication session and performing, by the first IKE node, at least a part of the rekeying process in which the first encryption key is replaced with a second encryption key for the IPSec communication session.

Claims (48)

1. A method comprising:

performing a dead peer detection process for an Internet Protocol Security (IPSec) communication session that has no traffic and is stored in a key value store, wherein the dead peer detection process includes:

obtaining, by a first Internet Key Exchange (IKE) node of a plurality of IKE nodes, information about the IPSec communication session from the key value store,

locally installing, by the first IKE node, the IPSec communication session based on the information about the IPSec communication session, and

providing, by the first IKE node to a client device, a dead peer detection request, wherein at least one other IKE node obtains from the client device a response to the dead peer detection request and continues the dead peer detection process so as to remove the IPSec communication session from the key value store.

2. The method of claim 1 , further comprising:

initiating, by the first IKE node, the dead peer detection process; and

generating a dead peer detection packet that includes the dead peer detection request.

3. The method of claim 1 , wherein the dead peer detection process is initiated by the first IKE node, and further comprising:

obtaining, by the at least one other IKE node from the client device, the response for the IPSec communication session not installed locally and continuing the dead peer detection process.

4. The method of claim 3 , wherein the response is based on a dead peer detection packet that includes the dead peer detection request provided to the client device by the first IKE node.

5. The method of claim 3 , wherein the IPSec communication session is locally installed at the at least one other IKE node so as to exchange an IKE control traffic with the client device and so as to remove the IPSec communication session from the at first IKE node that initiated the dead peer detection process.

6. The method of claim 5 , further comprising:

exchanging, by the at least one other IKE node, the IKE control traffic with the client device, wherein the IKE control traffic relates to at least one of:

debugging the IPSec communication session, or

terminating the IPSec communication session.

7. The method of claim 1 , wherein initiating the dead peer detection process is based on detecting that the IPSec communication session remains idle or non-operational for a predetermined period of time.

8. The method of claim 1 , wherein the IPSec communication session is one of an IKE session or an encapsulating security payload session.

9. The method of claim 1 , further comprising:

removing the IPSec communication session from the first IKE node based on an event published to the key value store by the at least one other IKE node that is continuing the dead peer detection process.

10. The method of claim 1 , wherein the IPSec communication session is removed from the key value store based on the dead peer detection process.

11. An apparatus comprising:

a memory;

a network interface configured to enable network communications; and

a processor, wherein the processor is configured to perform operations comprising:

performing a dead peer detection process for an Internet Protocol Security (IPSec) communication session that has no traffic and is stored in a key value store, wherein the dead peer detection process includes:

obtaining information about the IPSec communication session from the key value store,

locally installing the IPSec communication session based on the information about the IPSec communication session, and

providing, to a client device, a dead peer detection request, wherein at least one Internet Key Exchange (IKE) node other than the apparatus from a plurality of IKE nodes obtains from the client device a response to the dead peer detection request and continues the dead peer detection process so as to remove the IPSec communication session from the key value store.

12. The apparatus of claim 11 , wherein the processor is configured to perform additional operations comprising:

initiating the dead peer detection process; and

generating a dead peer detection packet including the dead peer detection request.

13. The apparatus of claim 11 , wherein the dead peer detection process is initiated by the apparatus and the at least one IKE node obtains from the client device, the response for the IPSec communication session not installed locally and continues the dead peer detection process.

14. The apparatus of claim 13 , wherein the response is based on a dead peer detection packet that includes the dead peer detection request provided to the client device by the apparatus.

15. The apparatus of claim 11 , wherein the processor is further configured to perform:

removing the IPSec communication session from the apparatus based on an event published to the key value store by the at least one IKE node that is continuing the dead peer detection process.

16. The apparatus of claim 11 , wherein the IPSec communication session is removed from the key value store by performing the dead peer detection process by the processor and the at least one IKE node.

17. One or more non-transitory computer readable storage media encoded with instructions that, when executed by a processor, cause the processor to execute a method comprising:

performing a dead peer detection process for an Internet Protocol Security (IPSec) communication session that has no traffic and is stored in a key value store, wherein the dead peer detection process includes:

obtaining information about the IPSec communication session from the key value store,

locally installing the IPSec communication session based on the information about the IPSec communication session, and

providing, to a client device, a dead peer detection request, wherein at least one Internet Key Exchange (IKE) node from a plurality of IKE nodes other than a node that includes the processor obtains a response to the dead peer detection request and continues the dead peer detection process so as to remove the IPSec communication session from the key value store.

18. The one or more non-transitory computer readable storage media of claim 17 , wherein the method further comprises:

initiating the dead peer detection process; and

generating a dead peer detection packet that includes the dead peer detection request.

19. The one or more non-transitory computer readable storage media of claim 17 , wherein the method further comprises:

removing the IPSec communication session that is locally installed based on an event published to the key value store by the at least one IKE node that is continuing the dead peer detection process.

20. The one or more non-transitory computer readable storage media of claim 17 , wherein the IPSec communication session is removed from the key value store by performing the dead peer detection process by the processor and the at least one IKE node.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2023
From: MESTERY, KYLE; DURAJ, GRZEGORZ BOGUSLAW
To: CISCO TECHNOLOGY, INC.
Reel/Frame 065271/0687 →
Continuity (4)
Continuation 17705810 · Mar 28, 2022
Division 16569930 · Sep 13, 2019
Provisional Application 62848692 · May 16, 2019
Related Publication 20250132910A1 · Apr 24, 2025
References Cited (98)
US 7689722B1 · Timms et al. · 2010 [cited by applicant]
US 9063866B1 · Tati et al. · 2015 [cited by applicant]
US 9424117B1 · Bono et al. · 2016 [cited by applicant]
US 9438566B2 · Zhang et al. · 2016 [cited by applicant]
US 9516065B2 · Suram et al. · 2016 [cited by applicant]
US 9544282B2 · Akhter et al. · 2017 [cited by applicant]
US 10397189B1 · Hashmi · 2019 [cited by examiner]
US 10623372B2 · Wang et al. · 2020 [cited by applicant]
US 11025483B1 · Hashmi · 2021 [cited by applicant]
US 11159366B1 · Gawade et al. · 2021 [cited by applicant]
US 11563601B1 · Vishnu et al. · 2023 [cited by applicant]
US 20030165139A1 · Chen et al. · 2003 [cited by applicant]
US 20040019645A1 · Goodman et al. · 2004 [cited by applicant]
US 20040088537A1 · Swander et al. · 2004 [cited by applicant]
US 20060007903A1 · Hammell et al. · 2006 [cited by applicant]
US 20060010320A1 · Chuang · 2006 [cited by applicant]
US 20060146991A1 · Thompson et al. · 2006 [cited by applicant]
US 20060167894A1 · Wunner · 2006 [cited by applicant]
US 20060248583A1 · Inoue · 2006 [cited by examiner]
US 20070038853A1 · Day et al. · 2007 [cited by applicant]
US 20070113275A1 · Khanna · 2007 [cited by examiner]
US 20070288585A1 · Sekiguchi et al. · 2007 [cited by applicant]
US 20080033845A1 · McBride et al. · 2008 [cited by applicant]
US 20080127337A1 · Dawson et al. · 2008 [cited by applicant]
US 20080137863A1 · Thomas · 2008 [cited by applicant]
US 20080162924A1 · Chinitz · 2008 [cited by examiner]
US 20090150668A1 · Liu et al. · 2009 [cited by applicant]
US 20100057849A1 · Ji · 2010 [cited by applicant]
US 20100162383A1 · Linden · 2010 [cited by examiner]
US 20100223458A1 · McGrew et al. · 2010 [cited by applicant]
US 20100228962A1 · Simon et al. · 2010 [cited by applicant]
US 20100268935A1 · Rodgers · 2010 [cited by examiner]
US 20100281251A1 · Arauz Rosado · 2010 [cited by applicant]
US 20100318800A1 · Simon et al. · 2010 [cited by applicant]
US 20110035796A1 · Khalid et al. · 2011 [cited by applicant]
US 20120023241A1 · Goel · 2012 [cited by examiner]
US 20120096269A1 · McAlister · 2012 [cited by examiner]
US 20120143829A1 · Fontenot et al. · 2012 [cited by applicant]
US 20120304276A1 · Legacy et al. · 2012 [cited by applicant]
US 20130003975A1 · Fukuda et al. · 2013 [cited by applicant]
US 20130125125A1 · Karino et al. · 2013 [cited by applicant]
US 20130201909A1 · Bosch et al. · 2013 [cited by applicant]
US 20130238794A1 · Ng et al. · 2013 [cited by applicant]
US 20130263249A1 · Song et al. · 2013 [cited by applicant]
US 20130311778A1 · Cherukuri et al. · 2013 [cited by applicant]
US 20140108781A1 · Zhang et al. · 2014 [cited by applicant]
US 20140281508A1 · Akhter et al. · 2014 [cited by applicant]
US 20140365621A1 · Vieira · 2014 [cited by applicant]
US 20140369204A1 · Anand et al. · 2014 [cited by applicant]
US 20150101012A1 · White et al. · 2015 [cited by applicant]
US 20150195265A1 · Chen · 2015 [cited by examiner]
US 20150215300A1 · Buonacuore et al. · 2015 [cited by applicant]
US 20150288765A1 · Skraparlis · 2015 [cited by examiner]
US 20150304282A1 · Xu et al. · 2015 [cited by applicant]
US 20160021194A1 · Prabhakar · 2016 [cited by examiner]
US 20160105401A1 · Vemulapalli et al. · 2016 [cited by applicant]
US 20160197831A1 · De Foy et al. · 2016 [cited by applicant]
US 20160373300A1 · Liu · 2016 [cited by applicant]
US 20170063808A1 · Manapragada et al. · 2017 [cited by applicant]
US 20180034643A1 · Yang · 2018 [cited by examiner]
US 20180092140A1 · Dong · 2018 [cited by examiner]
US 20180167206A1 · Raza et al. · 2018 [cited by applicant]
US 20180262454A1 · Zandi et al. · 2018 [cited by applicant]
US 20180262598A1 · Zhang et al. · 2018 [cited by applicant]
US 20180316500A1 · Xu et al. · 2018 [cited by applicant]
US 20180352036A1 · Baid et al. · 2018 [cited by applicant]
US 20190190710A1 · Chopra et al. · 2019 [cited by applicant]
US 20190306116A1 · Paul et al. · 2019 [cited by applicant]
US 20190372936A1 · Sullenberger · 2019 [cited by examiner]
US 20190372948A1 · Varghese et al. · 2019 [cited by applicant]
US 20200036679A1 · Chand · 2020 [cited by examiner]
US 20200120078A1 · Mao et al. · 2020 [cited by applicant]
US 20200351254A1 · Xiong et al. · 2020 [cited by applicant]
US 20210152518A1 · Pawar · 2021 [cited by examiner]
US 20210250193A1 · Hojsik et al. · 2021 [cited by applicant]
CN 1714560A · 2005 [cited by applicant]
CN 103155512A · 2013 [cited by applicant]
CN 104219217A · 2014 [cited by applicant]
CN 104660603A · 2015 [cited by applicant]
CN 106533881A · 2017 [cited by applicant]
CN 108293058A · 2018 [cited by applicant]
EP 2720438A1 · 2014 [cited by applicant]
EP 3301852A1 · 2018 [cited by applicant]
TW 200637255A · 2006 [cited by applicant]
Lang, Y., “Defect Analysis and Improvement of IKE Protocol”, China Academic Journal Electronic Publishing House, http://www.cnki.net, Apr. 15, 2005, 9 pages. [cited by applicant]
Notice of Intention to Grant for counterpart Chinese Application No. 202080036244.9, dated Sep. 2, 2024, 10 pages. [cited by applicant]
Shaheen, S.H., et al., “Source Specific Centralized Secure Multicast Scheme based on IPSec”, 2015 Conference on Information Assurance and Cyber Security (CIACS), IEEE, Dec. 18, 2015, 6 pages. [cited by applicant]
First Examination Report for counterpart Indian Application No. 202147050033, mailed on Nov. 7, 2023, 7 pages. [cited by applicant]
Huang G., et al., “A Traffic-Based Method of Detecting Dead Internet Key Exchange (IKE) Peers,” The Internet Society, Network Working Group, RFC: 3706, Category: Informational, Feb. 2004, 13 pages. [cited by applicant]
International Search Report and Written Opinion in counterpart International Application No. PCT/US2020/032002, mailed Jul. 27, 2020, 14 pages. [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/US2020/032002, mailed Nov. 25, 2021, 9 pages. [cited by applicant]
Kaufman, C. et al., “Internet Key Exchange Protocol Version 2 (IKEv2)”, Internet Engineering Task Force (IETF), RFC 5996, ISSN: 2070-1721, Sep. 2010, 138 pages. [cited by applicant]
Son, J. et al., “Protego: Cloud-Scale Multitenant IPsec Gateway”, Proceedings of the 2017 USENIX Annual Technical Conference (USENIX ATC '17), Jul. 12-14, 2017, ISBN 978-1-931971-38-6, 15 pages. [cited by applicant]
Vajaranta M., et al., “IPsec and IKE as Functions in SDN Controlled Network,” Springer, LNCS 10394, Network and System Security 11th International Conference, NSS Aug. 2017, 13 pages. [cited by applicant]
Xenakis C., et al., “Dynamic Network-Based Secure VPN Deployment in GPRS,” https://www.researchgate.net/publication/3974770_Dynamic_network-based_secure_VPN_deployment_in_GPRS, Oct. 2002, 7 pages. [cited by applicant]
Zheng, Y. et al., “Network and System Security”, 11th International Conference, NSS 2017 Helsinki, Finland, Aug. 21-23, 2017, Proceedings, Springer, 13 pages. [cited by applicant]
Office Action for counterpart Chinese Application No. 202080036244.9, mailed May 11, 2024, 28 pages. [cited by applicant]
Office Action for European Application No. 20729402.6, dated Mar. 4, 2025, 5 pages. [cited by applicant]