Supporting unknown unicast traffic using policy-based encryption virtualized networks

US10476850B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10476850-B2
Application numberUS-201715675482-A
CountryUS
Kind codeB2
Filing dateAug 11, 2017
Priority dateJul 19, 2017
Publication dateNov 12, 2019
Grant dateNov 12, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Certain embodiments described herein are generally directed to enabling a group of host machines within a network to securely communicate an unknown unicast packet. In some embodiments, a key policy is defined exclusively for the secure communication of unknown unicast packets. The key policy is transmitted by a central controller to the group of host machines for negotiating session keys among each other when communicating unknown unicast packets.

First claim

Opening claim text (preview).

We claim: 1. A method for use by a first host machine for securely communicating an unknown unicast packet, the method comprising: storing, at the first host machine, a single key policy exclusively for communication of unknown unicast (UU) packets with a plurality of host machines within a network, wherein the key policy is different from one or more other key policies used by the first host machine for communication of packets other than UU packets to one or more host machines of the plurality of host machines; receiving, at a virtual switch on the first host machine, a UU packet on a logical overlay layer 2 network; negotiating a session key with a second host machine using the key policy; encrypting the UU packet using the session key; and transmitting the encrypted UU packet to the second host machine. 2. The method of claim 1 , wherein the first host machine receives the UU packet from a source virtual machine on the first host machine. 3. The method of claim 1 , further comprising: replicating the UU packet for transmission to a number of host machines from the plurality of host machines; negotiating a number of session keys with the number of host machines using the key policy, each of the number of session keys corresponding to a different one of the number of host machines; encrypting each replicated UU packet with a different session key from the number of session keys; and transmitting each encrypted UU packet to a host machine corresponding to the different session key. 4. The method of claim 1 , wherein the key policy includes information corresponding to a master key, and wherein the session key is generated based on the master key. 5. The method of claim 1 , wherein the key policy includes a flag for use by the plurality of host machines to identify the key policy for exclusively communicating UU packets. 6. The method of claim 1 , wherein the key policy is transmitted by a central controller to all host machines in the plurality of host machines. 7. The method of claim 1 , wherein the key policy is generated automatically by a manager entity. 8. A non-transitory computer readable medium comprising instructions to be executed in a first computer system, wherein the instructions when executed in the first computer system perform a method for securely communicating an unknown unicast packet, the method comprising: storing, at the first computer system, a single key policy exclusively for communication of unknown unicast (UU) packets with a plurality of computer systems within a network, wherein the key policy is different from one or more other key policies used by the first computer system for communication of packets other than UU packets to one or more computer systems of the plurality of computer systems; receiving, at a virtual switch on the first computer system, a UU packet on a logical overlay layer 2 network; negotiating a session key with a second computer system using the key policy; encrypting the UU packet using the session key; and transmitting the encrypted UU packet to the second computer system. 9. The non-transitory computer readable medium of claim 8 , wherein the first computer system receives the UU packet from a source virtual machine on the first computer system. 10. The non-transitory computer readable medium of claim 8 , wherein the method further comprises: replicating the UU packet for transmission to a number of computer systems from the plurality of computer systems; negotiating a number of session keys with the number of computer systems using the key policy, each of the number of session keys corresponding to a different one of the number of computer systems; encrypting each replicated UU packet with a different session key from the number of session keys; and transmitting each encrypted UU packet to a computer system corresponding to the different session key. 11. The non-transitory computer readable medium of claim 8 , wherein the key policy includes information corresponding to a master key, and wherein the session key is generated based on the master key. 12. The non-transitory computer readable medium of claim 8 , wherein the key policy includes a flag for use by the plurality of computer systems to identify the key policy for exclusively communicating UU packets. 13. The non-transitory computer readable medium of claim 8 , wherein the key policy is transmitted by a central controller to all computer systems in the plurality of computer systems. 14. The non-transitory computer readable medium of claim 8 , wherein the key policy is generated automatically by a manager entity. 15. A first computer system, comprising: a memory comprising executable instructions; and a processor in data communication with the memory and configured to execute the executable instructions to cause the first computer system to perform operations comprising: storing, at the first computer system, a single key policy exclusively for communication of unknown unicast (UU) packets with a plurality of computer systems within a network, wherein the key policy is different from one or more other key policies used by the first computer system for communication of packets other than UU packets to one or more computer systems of the plurality of computer systems; receiving, at the first computer system, a UU packet; negotiating a session key with a second computer system using the key policy; encrypting the UU packet using the session key; and transmitting the encrypted UU packet to the second computer system. 16. The computer system of claim 15 , wherein the first computer system receives the UU packet from a source virtual machine on the first computer system. 17. The computer system of claim 15 , wherein the method further comprises: replicating the UU packet for transmission to a number of computer systems from the plurality of computer systems; negotiating a number of session keys with the number of computer systems using the key policy, each of the number of session keys corresponding to a different one of the number of computer systems; encrypting each replicated UU packet with a different session key from the number of session keys; and transmitting each encrypted UU packet to a computer system corresponding to the different session key. 18. The computer system of claim 15 , wherein the key policy includes information corresponding to a master key, and wherein the session key is generated based on the master key. 19. The computer system of claim 15 , wherein the key policy includes a flag for use by the plurality of computer systems to identify the key policy for exclusively communicating UU packets. 20. The computer system of claim 15 , wherein the key policy is transmitted by a central controller to all computer systems in the plurality of computer systems.

Assignees

Inventors

Classifications

  • for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • involving Diffie-Hellman or related key agreement protocols · CPC title

  • Interconnection of networks using encapsulation techniques, e.g. tunneling · CPC title

  • Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage · CPC title

  • Multipoint routing · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10476850B2 cover?
Certain embodiments described herein are generally directed to enabling a group of host machines within a network to securely communicate an unknown unicast packet. In some embodiments, a key policy is defined exclusively for the secure communication of unknown unicast packets. The key policy is transmitted by a central controller to the group of host machines for negotiating session keys among…
Who is the assignee on this patent?
Nicira Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0428. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 12 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).