EP1869865B1

Method and apparatus for distributing group data in a tunneled encrypted virtual private network

Abstract

A packet forwarding process, on a data communications device, forwards a packet to a plurality of destinations within a network from that data communications device using an “encrypt, then replicate” method. The packet forwarding process receives a packet that is to be transmitted to the plurality of destinations, and applies a security association to the packet using security information shared between the data communications device, and the plurality of destinations, to create a secured packet. The secured packet contains a header that has a source address and a destination address. The source address is inserted into the header, and then the packet forwarding process replicates the secured packet, once for each of the plurality of destinations. After replication, the destination address is inserted into the header, and the packet forwarding process transmits each replicated secured packet to each of the plurality of destinations authorized to maintain the security association.

EP1869865B1, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Expired 13 April 2026, 0.4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

14 claims: 3 independent, 11 dependent

  1. 1
    A method of forwarding a packet to a plurality of destinations within a network from a data communications device, wherein the network is a non-broadcast multi-access (NBMA) network, the method comprising:receiving (200) a packet that is to be transmitted to the plurality of destinations;applying (201) a security association to the packet using security information shared between the data communications device and the plurality of destinations to create a secured packet;after said applying, replicating (221) the secured packet for each of the plurality of destinations;and transmitting (222) each replicated secured packet from the data communications device to each of the plurality of destinations authorized to maintain the security association;and maintaining (225) a list of destinations that share the security association, the list based on a successful completion of secure packet transmission between the data communications device and each of the plurality of destinations.
  2. 2
    The method of Claim 1 wherein applying (201) a security association to the packet using security information shared between the data communications device and the plurality of destinations comprises:identifying (202) an encryption key for that packet based on a data stream associated with the packet;and determining (207) which of the plurality of destinations is authorized to have the encryption key.
  3. 3
    The method of Claim 2 wherein identifying an encryption key for that packet based on a data stream associated with the packet comprises:registering (203) with a key distribution management system;receiving (205) the encryption key from the key distribution management system;and installing (206) the encryption key supplied by the key distribution management system;and wherein determining (207) which of the plurality of destinations is authorized to have the encryption key comprises: receiving notification (208) from each of the plurality of destinations indicating that each of the plurality of destinations has received the encryption key from the key distribution management system.
  4. 4
    The method of Claim 3 wherein the key distribution management system is located on a device other than the data communications device, and wherein registering (203) with a key distribution management system comprises:performing an authentication technique with the key distribution management system;and wherein receiving (208) notification from each of the plurality of destinations comprises: utilizing (209) a tunnel mapping protocol to determine which of the plurality of destinations indicate successful receipt of the encryption key.
  5. 5
    The method of Claim 4 wherein utilizing (209) a tunnel mapping protocol comprises:identifying (210) at least one destination that does not maintain a shared security association with the plurality of destinations;applying (211) a security association exclusive to the identified destination to the packet to create an exclusive secured packet that is to be transmitted exclusively to the identified destination;and transmitting (212) the exclusive secured packet to the identified destination.
  6. 6
    The method of Claim 1 wherein applying (201) a security association to the packet using security information shared between the data communications device and the plurality of destinations to create a secured packet comprises:encapsulating (213) the packet for transmission throughout the network;creating (214) a header for the encapsulated packet, the header containing a source address location for indicating an originating location of the packet, and a destination address location for indicating a final location of the packet;and inserting (215) a source address into the source address location within the header of the packet, the source address indicating the origination location of the packet.
  7. 7
    The method of Claim 1 wherein applying (201) a security association to the packet using security information shared between the data communications device and the plurality of destinations to create a secured packet comprises:creating (216) a plurality of the secured packet, one for each of the plurality of destinations;and inserting (217) a respective destination address into a header within each of the plurality of the secured packet, the respective destination address indicating a network address of a respective one of the plurality of destinations.
  8. 8
    The method of Claim 1 wherein the packet is a multicast packet containing a multicast address of a multicast group and wherein applying (201) a security association to the packet using security information shared between the data communications device and the plurality of destinations to create a secured packet comprises:selecting security information that is shared between the data communications device and any of the plurality of destinations that is a member of the multicast group corresponding to the multicast address of the packet;and encrypting the packet using the selected shared security information such that any downstream devices in the plurality of destinations that receive the transmitted replicated encrypted packet are able to decrypt the packet using the same shared security information.
  9. 9
    The method of Claim 1 wherein the security associations include shared encryption information available to each destination and to the data communications device and wherein applying (201) a security association to the packet using security information shared between the data communications device and the plurality of destinations to create a secured packet comprises:applying the shared encryption information to encrypt the packet once regardless of the number of destinations to which the packet is transmitted.
  10. 10
    The method of Claim 1 wherein transmitting (222) each replicated secured packet from the data communications device to each of the plurality of destinations authorized to maintain the security association comprises:transmitting the replicated secured packet to an unauthorized destination.
  11. 11
    The method of Claim 1 comprising:repeating operations of receiving (200) a packet, applying (201) a security association to the packet, replicating (221) the secured packet for each of the plurality of destinations, and transmitting (222) each replicated secured packet, such that for each individually received packet, the security association is only applied once prior to replication of that packet to each of the plurality of destinations.
  12. 12
    The method of Claim 1 comprising:receiving (226) a new security association via a key distribution management system, the new security association to be used for future packet transmissions between the data communications device and each of the plurality of destinations on the list of destinations that share the security association.
  13. 13
    A computerized device comprising:a memory (112);a processor (113);a communications interface (115);an interconnection mechanism (111) coupling the memory, the processor and the communications interface;where the memory is encoded with a packet forwarding application (140-1) that when executed on the processor produces a packet forwarding process that causes the computerized device to forward a packet to a plurality of destinations within a network from that computerized device by performing the operations of a method according to any of claims 1 to 12.
  14. 14
    A computer readable medium encoded with compute programming logic that when executed on a processor (113) in a computerized device (110) produces a process that forwards a packet to a plurality of destinations within a network by causing the computerized device to perform the operations of a method according to any of claims 1 to 12.