Perfect forward secrecy (pfs) protected media access control security (macsec) key distribution

US2021218717A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2021218717-A1
Application numberUS-202016738722-A
CountryUS
Kind codeA1
Filing dateJan 9, 2020
Priority dateJan 9, 2020
Publication dateJul 15, 2021
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A non-transitory computer readable medium including instructions stored thereon, when executed, the instructions being effective to cause at least one processor of a first network device to: derive a private key encryption key based on a public key, a first private key of the first network device, a second private key of a live peer device, and a Connectivity Association Key (CAK); transmit a secret key encrypted by the private key encryption key to the live peer device; and receive a communication from the live peer device, the communication being encrypted by the secret key.

First claim

Opening claim text (preview).

We claim: 1 . A non-transitory computer readable medium comprising instructions stored thereon, when executed, the instructions being effective to cause at least one processor of a first network device to: derive a private key encryption key based on a public key, a first private key of the first network device, a second private key of a live peer device, and a Connectivity Association Key (CAK); transmit a secret key encrypted by the private key encryption key to the live peer device; and receive a communication from the live peer device, the communication being encrypted by the secret key. 2 . The non-transitory computer readable medium of claim 1 , wherein the secret key is a MACsec Secret Key (SAK). 3 . The non-transitory computer readable medium of claim 1 , wherein the private encryption key is a Key Encrypting Key (KEK). 4 . The non-transitory computer readable medium of claim 1 , wherein the instructions are further effective to cause at least one processor of a first network device to: prior to the derivation of the private key encryption key, establish a second network device as the live peer device by confirming common possession of the Connectivity Association Key (CAK) between the first network device and the second network device. 5 . The non-transitory computer readable medium of claim 4 , wherein the second network device is one a plurality of network devices, and wherein the Connectivity Association Key (CAK) is shared between the first network device and each the plurality of network devices to be established as a respective live peer device. 6 . The non-transitory computer readable medium of claim 2 , wherein the communication from the live peer device comprises at least one session between the first network device and the live peer device, each of the at least one session is encrypted by a corresponding MACsec Secret Key (SAK). 7 . The non-transitory computer readable medium of claim 6 , wherein the private key encryption key is unique for each of the at least one session between the first network device and the live peer device. 8 . The non-transitory computer readable medium of claim 6 , wherein the secret key is unique for each of the at least one session between the first network device and the live peer device. 9 . The non-transitory computer readable medium of claim 2 , the secret key is encrypted under an Advanced Encryption Standard (AES). 10 . The non-transitory computer readable medium of claim 1 , wherein the private key encryption key is used for Perfect Forward Secrecy (PFS) key distribution. 11 . The non-transitory computer readable medium of claim 1 , wherein the secret key is used to encrypt a MAC Security Standard (MACsec) session. 12 . The non-transitory computer readable medium of claim 3 , wherein a Diffie-Hellman (DH) key comprises the public key, the first private key of the first network device, and the second private key of the live peer device, and the Key Encrypting Key (KEK) is derived from the Connectivity Association Key (CAK) and the Diffie-Hellman (DH) key. 13 . The non-transitory computer readable medium of claim 12 , wherein derive the private encryption key further comprises an announcement Type-Length-Value (TLV) for an announcement parameter set, to carry parameter set of the Diffie-Hellman (DH) key. 14 . A method comprising: deriving, by a first network device, a private key encryption key based on a Diffie-Hellman Key, and a Connectivity Association Key (CAK); transmitting, by the first network device, a secret key encrypted by the private key encryption key to the live peer device; and receiving, by the first network device, a communication from the live peer, the communication being encrypted by the secret key. 15 . The method of claim 14 , wherein the private key encryption key is used for Perfect Forward Secrecy (PFS) key distribution, wherein the secret key is used to encrypt a MAC Security Standard (MACsec) session. 16 . The method of claim 14 , wherein the private key encryption key is a Key Encrypting Key (KEK). 17 . The method of claim 14 , wherein the communication from the live peer device comprises at least one session between the first network device and the live peer device, each of the at least one session is encrypted by a corresponding MACsec Secret Key (SAK). 18 . The method of claim 17 , wherein the private key encryption key is unique for each of the at least one session between the first network device and the live peer device. 19 . The method of claim 17 , wherein the secret key is unique for each of the at least one session between the first network device and the live peer device. 20 . The method of claim 16 , wherein the Diffie-Hellman (DH) key comprises a public key, a first private key of the first network device, a the second private key of the live peer device, and the Key Encrypting Key (KEK) is derived from the Connectivity Association Key (CAK) and the Diffie-Hellman (DH) key.

Assignees

Inventors

Classifications

  • for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • at the data link layer · CPC title

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • involving Diffie-Hellman or related key agreement protocols · CPC title

  • involving conference or group key (network architectures or network communication protocols for key management in group communication in a packet data network H04L63/065) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2021218717A1 cover?
A non-transitory computer readable medium including instructions stored thereon, when executed, the instructions being effective to cause at least one processor of a first network device to: derive a private key encryption key based on a public key, a first private key of the first network device, a second private key of a live peer device, and a Connectivity Association Key (CAK); transmit a s…
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L9/0822. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jul 15 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).