Optimizing IPSec for hierarchical SD-WAN

US12199868B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12199868-B2
Application numberUS-202217804333-A
CountryUS
Kind codeB2
Filing dateMay 27, 2022
Priority dateMay 27, 2022
Publication dateJan 14, 2025
Grant dateJan 14, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

According to some embodiments, a method is performed by a software defined wide area network (SD-WAN) edge router in a hierarchical SD-WAN network comprising a plurality of edge routers and a plurality of border routers. The method comprises: originating a SD-WAN system route for advertising reachability to the edge router, the system route comprising an encryption key associated with the edge router; and transmitting the system route to one or more SD-WAN border routers. The method may further comprise: receiving a packet destined for the edge router from one of the one or more SD-WAN border routers, wherein the packet is at least partially encrypted with the encryption key associated with the edge router; and decrypting the received packet.

First claim

Opening claim text (preview).

What is claimed is: 1. A method performed by a software defined wide area network (SD-WAN) edge router in a hierarchical SD-WAN network comprising a plurality of edge routers and a plurality of border routers, the method comprising: originating a SD-WAN system route for advertising reachability to the SD-WAN edge router, the SD-WAN system route comprising an encryption key associated with the SD-WAN edge router; and transmitting the SD-WAN system route to one or more SD-WAN border routers. 2. The method of claim 1 , further comprising: receiving a packet destined for the SD-WAN edge router from one of the one or more SD-WAN border routers, wherein the packet is at least partially encrypted with the encryption key associated with the SD-WAN edge router, and wherein the encryption key associated with the SD-WAN edge router is unaltered in transit across the one or more SD-WAN border routers; and decrypting the packet. 3. The method of claim 1 , wherein the SD-WAN system route comprises a SD-WAN Overlay Management Protocol (OMP) route. 4. The method of claim 1 , wherein the encryption key associated with the SD-WAN edge router comprises an Internet Protocol Security (IPSec) Encapsulating Security Payload (ESP) protocol encryption key. 5. The method of claim 1 , wherein the SD-WAN edge router is communicably coupled to one or more of the plurality of border routers via one or more Internet Protocol Security (IPSec) tunnels. 6. A method performed by a software defined wide area network (SD-WAN) border router in a hierarchical SD-WAN network comprising a plurality of edge routers and a plurality of border routers, the method comprising: receiving a first SD-WAN system route for advertising reachability to an SD-WAN edge router, the first SD-WAN system route comprising an encryption key associated with the SD-WAN edge router; allocating a local label for the SD-WAN edge router; originating a second SD-WAN system route for advertising reachability to the SD-WAN edge router, the second SD-WAN system route comprising the local label for the SD-WAN edge router, the encryption key associated with the SD-WAN edge router, and an authentication key associated with the SD-WAN border router; and transmitting the second SD-WAN system route to one or more SD-WAN border routers or edge routers. 7. The method of claim 6 , further comprising: receiving a packet destined for the SD-WAN edge router from one of the one or more SD-WAN border routers or edge routers, wherein the packet is at least partially encrypted with the encryption key associated with the SD-WAN edge router and the packet comprises a local transport label, and wherein the encryption key associated with the SD-WAN edge router is unaltered in transit across the one or more SD-WAN border routers; authenticating the packet using the authentication key associated with the SD-WAN border router; updating one or more of a local transport label, source address, and destination address associated with the packet; and forwarding the packet to one of the one or more SD-WAN border routers or edge routers based on the local transport label without decrypting the packet. 8. The method of claim 6 , wherein the second SD-WAN system route comprises a SD-WAN Overlay Management Protocol (OMP) route. 9. The method of claim 6 , wherein the encryption key associated with the SD-WAN edge router comprises an Internet Protocol Security (IPSec) Encapsulating Security Payload (ESP) protocol encryption key. 10. The method of claim 6 , wherein the authentication key associated with the SD-WAN border router comprises an Internet Protocol Security (IPSec) Security Authentication Header (AH) protocol authentication key. 11. The method of claim 6 , wherein the SD-WAN border router is communicably coupled to the one or more border routers or edge routers via one or more Internet Protocol Security (IPSec) tunnels. 12. A software defined wide area network (SD-WAN) system comprising a first edge router communicably coupled to a first border router: the first edge router comprising a memory comprising instructions and a hardware processor, wherein the first edge router, when executing its instructions at its hardware processor, is configured to: originate a first SD-WAN system route for advertising reachability to the first edge router, the first SD-WAN system route comprising an encryption key associated with the first edge router; and transmit the first SD-WAN system route to the first border router; and the first border router comprising a memory comprising instructions and a hardware processor, wherein the first border router, when executing its instructions at its hardware processor, is configured to: receive the first SD-WAN system route for advertising reachability to the first edge router; allocate a local label for the first edge router; originate a second SD-WAN system route for advertising reachability to the first edge router, the second SD-WAN system route comprising the local label for the first edge router, the encryption key associated with the first edge router, and an authentication key associated with the first border router; and transmit the second SD-WAN system route to one or more SD-WAN border routers or edge routers. 13. The SD-WAN system of claim 12 , wherein the first edge router is further configured to: receive a packet destined for the first edge router from the first border router, wherein the packet is at least partially encrypted with the encryption key associated with the first edge router, and wherein the encryption key associated with the first edge router is unaltered in transit across the one or more SD-WAN border routers; and decrypt the packet. 14. The SD-WAN system of claim 12 , wherein the first border router is further configured to: receive a packet destined for the first edge router from one of one or more SD-WAN border routers or edge routers, wherein the packet is at least partially encrypted with the encryption key associated with the first edge router and the packet comprises a local transport label; authenticate the packet using the authentication key associated with the first border router; update one or more of a local transport label, source address, and destination address associated with the packet; and forward the packet to one of the one or more SD-WAN border routers or edge routers based on the local transport label without decrypting the packet. 15. The SD-WAN system of claim 12 , wherein the first SD-WAN system route comprises a SD-WAN Overlay Management Protocol (OMP) route. 16. The SD-WAN system of claim 12 , wherein the encryption key associated with the first edge router comprises an Internet Protocol Security (IPSec) Encapsulating Security Payload (ESP) protocol encryption key. 17. The SD-WAN system of claim 12 , wherein the authentication key associated with the first border router comprises an Internet Protocol Security (IPSec) Security Authentication Header (AH) protocol authentication key. 18. The SD-WAN system of claim 12 , wherein the first edge router is communicably coupled to the first border router via an Internet Protocol Security (IPSec) tunnel. 19. The SD-WAN system of claim 12 , wherein the first edge router is further configured to: encrypt a packet for transmission to a second edge router, wherein the packet is encrypted with an encryption key associated with the second edge router received via a system route originated from the second edge router; and transmit the packet to the first border router.

Assignees

Inventors

Classifications

  • using an overlay routing layer · CPC title

  • using label swapping, e.g. multi-protocol label switch [MPLS] · CPC title

  • Networking architectures for enhanced packet encryption processing, e.g. offloading of IPsec packet processing or efficient security association look-up · CPC title

  • Interdomain routing, e.g. hierarchical routing · CPC title

  • Virtual private networks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12199868B2 cover?
According to some embodiments, a method is performed by a software defined wide area network (SD-WAN) edge router in a hierarchical SD-WAN network comprising a plurality of edge routers and a plurality of border routers. The method comprises: originating a SD-WAN system route for advertising reachability to the edge router, the system route comprising an encryption key associated with the edge …
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L45/76. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 14 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).