Systems and methods for random connectivity association key negotiation for media access control security

US11985166B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11985166-B2
Application numberUS-202217655454-A
CountryUS
Kind codeB2
Filing dateMar 18, 2022
Priority dateMar 18, 2022
Publication dateMay 14, 2024
Grant dateMay 14, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In some implementations, a network device may establish a secure connection between the network device and another network device based on a first set of keys generated by the network device, wherein the first set of keys are generated based on a first connectivity association key (CAK) and the secure connection is established based on a media access control security (MACsec) protocol. The network device may transmit a message to the other network device, wherein the message includes an indication of a second CAK. The network device may communicate data via the secure connection based on a second set of keys, wherein the second set of keys are generated based on the second CAK.

First claim

Opening claim text (preview).

What is claimed is: 1. A method, comprising: establishing, by a network device, a secure connection between the network device and another network device based on a first set of keys generated by the network device, wherein the first set of keys are generated based on a first connectivity association key (CAK) and the secure connection is established based on a media access control security (MACsec) protocol; transmitting, by the network device, a message to the other network device, wherein the message includes an indication of a second CAK, wherein the network device selects the second CAK from a first CAK database associated with the network device; and communicating, by the network device, data via the secure connection based on a second set of keys, wherein the second set of keys are generated based on the second CAK based on the other network device identifying the second CAK in a second CAK database associated with the other network device. 2. The method of claim 1 , wherein the indication includes a pattern of data followed by an identifier associated with the second CAK. 3. The method of claim 2 , wherein the identifier associated with the second CAK includes one or more of a key identifier or a key name. 4. The method of claim 2 , wherein the indication further includes an identifier associated with the first CAK. 5. The method of claim 4 , wherein the pattern of data followed by the identifier associated with the second CAK is located at an end of the identifier associated with the first CAK. 6. The method of claim 1 , further comprising: receiving another message that includes information indicating a third CAK; obtaining the third CAK from a database storing a plurality of CAKs; generating a third set of keys based on the third CAK; and communicating additional data via the secure connection based on the third set of keys. 7. The method of claim 1 , wherein the message comprises a first message, the method further comprising: transmitting a second message that includes information indicating a third CAK; receiving, based on transmitting the second message, a third message that includes information indicating the second CAK; and continuing, based on the third message including the information indicating the second CAK, to communicate via the secure connection based on the second set of keys. 8. A network device, comprising: one or more memories storing instructions; and one or more processors configured to execute the instructions to: establish a secure connection between the network device and another network device based on a first set of keys generated by the network device, wherein the first set of keys are generated based on a first connectivity association key (CAK) and the secure connection is established based on a media access control security (MACsec) protocol; transmit a message to the other network device, wherein the message includes an indication of a second CAK, wherein the network device selects the second CAK from a first CAK database associated with the network device; and communicate data via the secure connection based on a second set of keys, wherein the second set of keys are generated based on the second CAK based on the other network device identifying the second CAK in a second CAK database associated with the other network device. 9. The network device of claim 8 , wherein the indication includes a pattern of data followed by an identifier associated with the second CAK. 10. The network device of claim 9 , wherein the identifier associated with the second CAK includes one or more of a key identifier or a key name. 11. The network device of claim 8 , wherein the indication includes an identifier associated with the first CAK and a pattern of data followed by an identifier associated with the second CAK. 12. The network device of claim 11 , wherein the pattern of data followed by the identifier associated with the second CAK is located at an end of the identifier associated with the first CAK. 13. The network device of claim 8 , wherein the one or more processors are further to: receive another message that includes information indicating a third CAK; obtain the third CAK from a database storing a plurality of CAKs; generate a third set of keys based on the third CAK; and communicate additional data via the secure connection based on the third set of keys. 14. The network device of claim 8 , wherein the message comprises a first message, and wherein the one or more processors are further to: transmit a second message that includes information indicating a third CAK; receive, based on transmitting the second message, a third message that includes information indicating the second CAK; and continue, based on the third message including the information indicating the second CAK, to communicate via the secure connection based on the second set of keys. 15. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: one or more instructions that, when executed by one or more processors of a network device, cause the network device to: establish a secure connection between the network device and another network device based on a first set of keys generated by the network device, wherein the first set of keys are generated based on a first connectivity association key (CAK) and the secure connection is established based on a media access control security (MACsec) protocol; transmit a message to the other network device, wherein the message includes an indication of a second CAK, wherein the network device selects the second CAK from a first CAK database associated with the network device; and communicate data via the secure connection based on a second set of keys, wherein the second set of keys are generated based on the second CAK based on the other network device identifying the second CAK in a second CAK database associated with the other network device. 16. The non-transitory computer-readable medium of claim 15 , wherein the indication includes a pattern of data followed by an identifier associated with the second CAK. 17. The non-transitory computer-readable medium of claim 15 , wherein the indication includes an identifier associated with the first CAK and a pattern of data followed by an identifier associated with the second CAK. 18. The non-transitory computer-readable medium of claim 17 , wherein the pattern of data followed by the identifier associated with the second CAK is located at an end of the identifier associated with the first CAK. 19. The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions further cause the network device to: receive another message that includes information indicating a third CAK; obtain the third CAK from a database storing a plurality of CAKs; generate a third set of keys based on the third CAK; and communicate additional data via the secure connection based on the third set of keys. 20. The non-transitory computer-readable medium of claim 15 , wherein the message comprises a first message, and wherein the one or more instructions further cause the network device to: transmit a second message that includes information indicating a third CAK; receive, based on transmitting the second message, a third message that includes information indicating the second CAK; and continue, based on the third message including the information indicating the second CAK, to communicate via the secure connection based

Assignees

Inventors

Classifications

  • H04L63/162Primary

    at the data link layer · CPC title

  • for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • using time-dependent keys, e.g. periodically changing keys (cryptographic mechanisms or cryptographic arrangements for controlling usage of secret information H04L9/088) · CPC title

  • H04L63/12Primary

    Applying verification of the received information (cryptographic mechanisms or cryptographic arrangements for data integrity or data verification H04L9/32) · CPC title

  • applying further key derivation, e.g. deriving traffic keys from a pair-wise master key · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11985166B2 cover?
In some implementations, a network device may establish a secure connection between the network device and another network device based on a first set of keys generated by the network device, wherein the first set of keys are generated based on a first connectivity association key (CAK) and the secure connection is established based on a media access control security (MACsec) protocol. The netw…
Who is the assignee on this patent?
Juniper Networks Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/162. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 14 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).