Invention Grant
- Patent Title: Scalable replay counters for network security
- Patent Title (中): 可扩展的重播计数器,用于网络安全
-
Application No.: US13451897Application Date: 2012-04-20
-
Publication No.: US09077772B2Publication Date: 2015-07-07
- Inventor: Jonathan W. Hui , Anjum Ahuja , Krishna Kondaka , Wei Hong
- Applicant: Jonathan W. Hui , Anjum Ahuja , Krishna Kondaka , Wei Hong
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Parker Ibrahim & Berg LLC
- Agent James M. Behmke; Kenneth J. Heywood
- Main IPC: G06F7/04
- IPC: G06F7/04 ; H04L29/14 ; H04L29/08 ; H04L29/06 ; G06F15/16

Abstract:
In one embodiment, an authenticator in a communication network maintains a persistent authenticator epoch value that increments each time the authenticator restarts. The authenticator also maintains a persistent per-supplicant value for each supplicant of the authenticator, each per-supplicant value set to a current value of the authenticator epoch value each time the corresponding supplicant establishes a new security association with the authenticator. To communicate messages from the authenticator to a particular supplicant, each message uses a per-supplicant replay counter having a security association epoch counter and a message counter specific to the particular supplicant. In particular, the security association epoch counter for each message is set as a difference between the authenticator epoch value and the per-supplicant value for the particular supplicant when the message is communicated, while the message counter is incremented for each message communicated.
Public/Granted literature
- US20130283347A1 SCALABLE REPLAY COUNTERS FOR NETWORK SECURITY Public/Granted day:2013-10-24
Information query