Invention Grant
- Patent Title: Dynamic rekeying of IPSec security associations
-
Application No.: US17012235Application Date: 2020-09-04
-
Publication No.: US11770389B2Publication Date: 2023-09-26
- Inventor: Sourabh Bhattacharya , Yong Wang , Awan Kumar Sharma , Bhargav Puvvada , Mayur Katke
- Applicant: VMWARE, INC.
- Applicant Address: US CA Palo Alto
- Assignee: VMWARE, INC.
- Current Assignee: VMWARE, INC.
- Current Assignee Address: US CA Palo Alto
- Agency: Patterson + Sheridan, LLP
- Priority: IN 2041030417 2020.07.16
- Main IPC: H04L9/40
- IPC: H04L9/40 ; H04L47/125 ; H04L9/08

Abstract:
Certain embodiments described herein are relate to a method for dynamically rekeying a security association. The method includes establishing, by a destination tunnel endpoint (TEP), an in-bound security association with a source TEP, with a first security parameter index (SPI) value, for encrypting data packets communicated between the source TEP and the destination TEP. The method further includes rekeying, by the destination TEP, the in-bound security association, the rekeying including generating a second SPI value for replacing the first SPI value based on a trigger event relating to at least one of a real-time security score of the in-bound security association, a number of security associations assigned to a compute resource that the in-bound security resource is assigned to, an amount of load managed by the compute resource that the in-bound security resource is assigned to, and an indication received from an administrator.
Public/Granted literature
- US20220021687A1 DYNAMIC REKEYING OF IPSEC SECURITY ASSOCIATIONS Public/Granted day:2022-01-20
Information query