IP Library › Granted Patent US 12,438,698
Granted Patent B2
US 12,438,698 · App. 18/360,338 · Granted Oct 7, 2025

Managing encryption keys of secure tunnels in multi-tenant edge devices

Inventors: Ajeet Pal Singh Gill (Fremont, CA); Srilatha Tangirala (San Jose, CA)
Assignee: Cisco Technology, Inc.
H04L9/0819H04L9/0861H04L9/14H04L63/029
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,698
App. No.
18/360,338
Granted
Oct 7, 2025
Kind
B2
Abstract

Disclosed are systems, apparatuses, methods, computer readable medium, and circuits for managing encryption keys in a multi-tenant network edge device. According to at least one example, a method includes: receiving tenant resource information at the multi-tenant network edge device; generating at least one parent encryption key; generating a plurality of child encryption keys; creating a routing connection to a network controller for each tenant in the plurality of tenants; transmitting the at least one parent encryption key and the plurality of child encryption keys to the network controller for distribution to the plurality of tenants; receiving a plurality of advertisements of transport locators from the network controller, wherein each advertisement includes a parent encryption key or a child encryption key; selecting a set of encryption keys from the plurality of advertisements; and forming a secure tunnel.

Claims (47)

1. A method for managing encryption keys in a multi-tenant network edge device, the method comprising:

receiving tenant resource information at the multi-tenant network edge device, wherein the multi-tenant network edge device is configured to send and receive network data for a plurality of tenants, and wherein the tenant resource information includes at least one network transport interface for a first tenant;

generating at least one parent encryption key based on a number of network interfaces supported by the plurality of tenants;

generating a plurality of child encryption keys, wherein at least one child encryption key is generated for each tenant in the plurality of tenants;

creating a routing connection to a network controller for each tenant in the plurality of tenants;

transmitting the at least one parent encryption key and the plurality of child encryption keys to the network controller for distribution to the plurality of tenants;

receiving a plurality of advertisements of transport locators from the network controller, wherein each advertisement includes a parent encryption key or a child encryption key;

selecting a set of encryption keys from the plurality of advertisements; and

forming a secure tunnel with each tenant of the plurality of tenants using child encryption keys included in the set of encryption keys.

2. The method of claim 1 , wherein the set of encryption keys is based on the number of tenants and the number of network interfaces.

3. The method of claim 1 , further comprising:

configuring a secure tunnel with another multi-tenant network edge device based on a parent encryption key and a key received from the another multi-tenant network edge device.

4. The method of claim 1 , wherein each transport locator in the plurality of advertisements includes a key type, a security parameter index, and a sequence number.

5. The method of claim 4 , wherein the set of encryption keys is selected based on a largest sequence number for the first tenant in the event multiple encryption keys for the first tenant are received.

6. The method of claim 1 , wherein each tenant is configured to interface with the multi-tenant network edge device using a different encryption key for each interface.

7. The method of claim 6 , wherein the network controller is configured to advertise the at least one parent encryption key to the multi-tenant network edge device and advertise the plurality of child encryption keys to the plurality of tenants.

8. A multi-tenant network edge device for managing encryption keys, comprising:

a storage configured to store instructions; and

a processor configured to execute the instructions and cause the processor to:

receive tenant resource information at the multi-tenant network edge device, wherein the multi-tenant network edge device is configured to send and receive network data for a plurality of tenants, and wherein the tenant resource information includes at least one network transport interface for a first tenant;

generate at least one parent encryption key based on a number of network interfaces supported by the plurality of tenants;

generate a plurality of child encryption keys, wherein at least one child encryption key is generated for each tenant in the plurality of tenants;

create a routing connection to a network controller for each tenant in the plurality of tenants;

transmit the at least one parent encryption key and the plurality of child encryption keys to the network controller for distribution to the plurality of tenants;

receive a plurality of advertisements of transport locators from the network controller, wherein each advertisement includes a parent encryption key or a child encryption key;

select a set of encryption keys from the plurality of advertisements; and

form a secure tunnel with each tenant of the plurality of tenants using child encryption keys included in the set of encryption keys.

9. The multi-tenant network edge device of claim 8 , wherein the set of encryption keys is based on the number of tenants and the number of network interfaces.

10. The multi-tenant network edge device of claim 8 , wherein the processor is configured to execute the instructions and cause the processor to: configure a secure tunnel with another multi-tenant network edge device based on a parent encryption key and a key received from the another multi-tenant network edge device.

11. The multi-tenant network edge device of claim 8 , wherein each transport locator in the plurality of advertisements includes a key type, a security parameter index, and a sequence number.

12. The multi-tenant network edge device of claim 11 , wherein the set of encryption keys is selected based on a largest sequence number for the first tenant in the event multiple encryption keys for the first tenant are received.

13. The multi-tenant network edge device of claim 8 , wherein each tenant is configured to interface with the multi-tenant network edge device using a different encryption key for each interface.

14. The multi-tenant network edge device of claim 12 , wherein the network controller is configured to advertise the at least one parent encryption key to the multi-tenant network edge device and advertise the plurality of child encryption keys to the plurality of tenants.

15. A non-transitory computer readable medium comprising instructions, the instructions, when executed by a computing system, cause the computing system to:

receive tenant resource information at a multi-tenant network edge device, wherein the multi-tenant network edge device is configured to send and receive network data for a plurality of tenants, and wherein the tenant resource information includes at least one network transport interface for a first tenant;

generate at least one parent encryption key based on a number of network interfaces supported by the plurality of tenants;

generate a plurality of child encryption keys, wherein at least one child encryption key is generated for each tenant in the plurality of tenants;

create a routing connection to a network controller for each tenant in the plurality of tenants;

transmit the at least one parent encryption key and the plurality of child encryption keys to the network controller for distribution to the plurality of tenants;

receive a plurality of advertisements of transport locators from the network controller, wherein each advertisement includes a parent encryption key or a child encryption key;

select a set of encryption keys from the plurality of advertisements; and

form a secure tunnel with each tenant of the plurality of tenants using child encryption keys included in the set of encryption keys.

16. The computer readable medium of claim 15 , wherein the set of encryption keys is based on the number of tenants and the number of network interfaces.

17. The computer readable medium of claim 15 , wherein the computer readable medium further comprises instructions that, when executed by the computing system, cause the computing system to: configure a secure tunnel with another multi-tenant network edge device based on a parent encryption key and a key received from the another multi-tenant network edge device.

18. The computer readable medium of claim 15 , each transport locator in the plurality of advertisements includes a key type, a security parameter index, and a sequence number.

19. The computer readable medium of claim 15 , wherein each tenant is configured to interface with the multi-tenant network edge device using a different encryption key for each interface.

20. The computer readable medium of claim 19 , wherein the network controller is configured to advertise the at least one parent encryption key to the multi-tenant network edge device and advertise the plurality of child encryption keys to the plurality of tenants.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2023
From: GILL, AJEET PAL SINGH; TANGIRALA, SRILATHA
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064405/0681 →
Continuity (1)
Related Publication 20250038957A1 · Jan 30, 2025
References Cited (32)
US 10826775B1 · Moreno · 2020 [cited by examiner]
US 11323363B1 · Sanchez · 2022 [cited by examiner]
US 20120237033A1 · Tanaka et al. · 2012 [cited by applicant]
US 20140283010A1 · Rutkowski et al. · 2014 [cited by applicant]
US 20180062835A1 · Hamel · 2018 [cited by examiner]
US 20180109493A1 · Khan · 2018 [cited by examiner]
US 20180316495A1 · Wall · 2018 [cited by examiner]
US 20190140826A1 · Carrel · 2019 [cited by examiner]
US 20190140955A1 · Hemige · 2019 [cited by examiner]
US 20190296896A1 · Resch · 2019 [cited by examiner]
US 20190303951A1 · Bakalis · 2019 [cited by examiner]
US 20190356475A1 · Resch · 2019 [cited by examiner]
US 20200092094A1 · Resch · 2020 [cited by examiner]
US 20200127983A1 · Asghar et al. · 2020 [cited by applicant]
US 20200169390A1 · Raza · 2020 [cited by examiner]
US 20200177503A1 · Hooda · 2020 [cited by examiner]
US 20200177550A1 · Valluri · 2020 [cited by examiner]
US 20200177606A1 · Valluri · 2020 [cited by examiner]
US 20200322230A1 · Natal · 2020 [cited by examiner]
US 20200403821A1 · Dev · 2020 [cited by examiner]
US 20210044565A1 · Moreno · 2021 [cited by examiner]
US 20210099360A1 · Parsons et al. · 2021 [cited by applicant]
US 20210112034A1 · Sundararajan · 2021 [cited by examiner]
US 20210258268A1 · Yu et al. · 2021 [cited by applicant]
US 20220052947A1 · Baruah · 2022 [cited by examiner]
US 20220239507A1 · Smith et al. · 2022 [cited by applicant]
US 20220329540A1 · Tangirala · 2022 [cited by examiner]
US 20220417332A1 · Chiganmi · 2022 [cited by examiner]
US 20230030403A1 · Jeuk · 2023 [cited by examiner]
US 20230409597A1 · Kashi Visvanathan · 2023 [cited by examiner]
US 20240340687A1 · Shen · 2024 [cited by examiner]
CN 113169930A · 2021 [cited by examiner]