Invention Grant
- Patent Title: Cryptographic micro-segmentation using IKEv2
-
Application No.: US17657211Application Date: 2022-03-30
-
Publication No.: US12113779B2Publication Date: 2024-10-08
- Inventor: Sean D. Everson , Ganesh Murugesan
- Applicant: Certes Networks, Inc.
- Applicant Address: US PA Pittsburgh
- Assignee: Certes Networks, Inc.
- Current Assignee: Certes Networks, Inc.
- Current Assignee Address: US PA Pittsburgh
- Agency: Hamilton, Brook, Smith & Reynolds, P.C.
- Main IPC: H04L9/40
- IPC: H04L9/40 ; H04L67/146

Abstract:
A method of establishing one or more secure channels between network devices comprises exchanging a base key pair between a first network device and a second network device, and for each of a plurality of policies, providing a nonce corresponding to that policy to the first and second devices. The method further comprises generating, for each of the plurality of policies, a session key that is a function of the base key pair and the policy nonce. The method comprises determining, at the first device, that a data packet matches a rule associated with a policy, encrypting the data with a session key that corresponds to the policy to produce an encrypted packet, and conveying the encrypted packet to the second device. At the second device, determining that the encrypted packet matches the rule associated with the policy, and decrypting the encrypted packet with the session key.
Public/Granted literature
- US20220321545A1 Cryptographic Micro-Segmentation Using IKEv2 Public/Granted day:2022-10-06
Information query