×

Simplifying IKE process in a gateway to enable datapath scaling using a two tier cache configuration

  • US 9,473,298 B2
  • Filed: 01/08/2015
  • Issued: 10/18/2016
  • Est. Priority Date: 08/15/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method of communicating through a virtual private network (VPN) tunnel between a first application (app) on a device and a Virtual Private Network (VPN) gateway having an Internet Key Exchange (IKE) which performs cryptographic operations on data packets comprising:

  • transmitting from the gateway a first range of ports to the first app, wherein the first app uses a port in the first port range as a source port for data transmission from the first app to the VPN gateway, wherein the first port range comprises a plurality of ports not included in a second port range transmitted to a second app having a same internally unique IP address as the first app;

    receiving, at the VPN gateway, data packets from the first app; and

    determining, at the VPN gateway, that the data transmission originated from the first app based on the source port;

    searching a local cache in an IPSec component of a datapath for security associations for the data packet;

    searching a security policy and security association cache for security associations for the data packet; and

    performing cryptographic operations on the data packet using the security associations outside of the IKE process in the gateway.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×