DYNAMIC GROUP CREATION AND TRAFFIC FLOW REGISTRATION UNDER A GROUP IN A GROUP KEY INFRASTRUCTURE
First Claim
1. A method, comprising:
- receiving a registration request to dynamically register a traffic flow, wherein the registration request is sent from a registration node;
determining whether to accept the registration request; and
performing the registration request, in response to a determination to accept the registration request.
1 Assignment
0 Petitions
Accused Products
Abstract
Upon detection of a new traffic flow, a registration node can dynamically register the new traffic flow with a key server policy manager by sending a registration request on behalf of the new traffic flow. A registration request indicates the new traffic flow should be protected by a security group. A registration request may also include a request to dynamically generate a new security group to protect the traffic flow. The registration request is received by a key server policy manager, which performs authentication and authorization checks of the requesting registration node, and determines whether to accept or reject the registration request. If accepted, the key server policy manager registers the new traffic flow by including a description of the traffic flow in a group policy of an existing security group or a newly created security group, depending on the registration request.
-
Citations
22 Claims
-
1. A method, comprising:
-
receiving a registration request to dynamically register a traffic flow, wherein the registration request is sent from a registration node; determining whether to accept the registration request; and performing the registration request, in response to a determination to accept the registration request. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A method, comprising:
-
detecting a new traffic flow; and sending a registration request to a key server policy manager, wherein the registration request comprises a traffic flow identifier that identifies the new traffic flow. - View Dependent Claims (9, 10)
-
-
11. A system comprising:
a policy manager configured to receive a registration request to dynamically register a traffic flow, wherein the registration request is sent from a registration node, determine whether to accept the registration request, and perform the registration request, in response to a determination to accept the registration request. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
21. An apparatus comprising:
-
a line card configured to receive a registration request to dynamically register a traffic flow, wherein the registration request is sent from a registration node; and a control module coupled to the line card, the control module configured to determine whether to accept the registration request, and perform the registration request, in response to a determination to accept the registration request.
-
-
22. An apparatus comprising:
-
a line card configured to receive packets; and a control module coupled to the line card, the control module configured to detect packets of a new traffic flow, and send a registration request to a key server policy manager, wherein the registration request comprises a traffic flow identifier that identifies the new traffic flow.
-
Specification