WO2014176046A2

Community of interest-based secured communications over ipsec

Abstract

A method and system for establishing secure communications between endpoints includes transmitting a first message including a token having one or more entries each corresponding to a community of interest associated with a user of the first endpoint and including an encryption key and a validation key associated with the first endpoint. The method includes receiving a second, message including a second authorization token including one or more entries, each entry corresponding to a community of interest associated with a second user and including an encryption key and a validation key associated with the second endpoint. The method includes, for each community of interest associated with both users, decrypting an associated entry in the second authorization token to obtain the encryption key and validation key associated with the second endpoint. The method also includes generating a shared secret based on the key pair, transmitting a third message including the created key pair to the second, endpoint, and initializing a tunnel using the shared secret to derive encryption keys used for IPsec-secured communications between the endpoints.

WO2014176046A2, drawing sheet 1
Sheet 1 of 19

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 3 independent, 17 dependent

  1. 1
    Claims:1. A method of establishing secure communications between endpoints, the method comprising: transmitting from a first endpoint to a second endpoint a first message including a token, the token including one or more entries, each entry corresponding to a community of interest associated with a user of the first endpoint and including an encryption key and a validation key associated with the first endpomt and encrypted with the corresponding community of interest key;receiving from the second endpoint a second message including a second authorization token at the first endpoint, the second authorization token including one or more entries, each entry corresponding to a community of interest associated with a second user of the second endpoint and including an encryption key and. a validation key associated with the second endpoint and encxypted with the corresponding community of interest key ;for each community of interest associated with both the first user and the second user, decrypting an associated entry in the second authorization token to obtain the encryption key and validation key associated with the second endpoint;creating a key pair at the first endpoint and generating a shared secret based on the key pair;transmitting a third, message including the created key pair to the second endpoint, thereby allowing the second endpoint to derive the shared secret;initializing a tunnel between the first and second endpoints, the tunnel using the shared secret to derive encryption keys used for IPsec-secured communications between the first and second endpoints.
  2. 11
    1 1 . A method of establishing secure communications between endpoints, the method comprising:receiving from a first endpoint at a second endpoint a first message including a token, the token including one or more entries, each entry corresponding to a community of interest associated with a user of the first endpoint and including an encryption key and a validation key associated with the first endpomt and encrypted with the corresponding community of interest key;for each community of interest associated with both the first user and the second user, decrypting an associated entry in the first authorization token to obtain the encryption key and validation key associated with, the first endpomt;creating a key pair at the second endpoint;transmitting to the first endpoint from the second endpoint a second message including a second authorization token, the second authorization token including one or more entries, each entry corresponding to a commimity of interest associated with a second user of the second endpoint and including an encryption key and a validation key associated with the second endpoint and encrypted with, the corresponding community of interest key;receiving at the second endpoint a third message including a key pair created at the first endpoint encrypted with the encryption key of the second endpoint;deriving at the second endpoint the shared secret from the key pair created at the first endpoint and the key pair created, at the second endpoint;and initializing a tunnel between the first and second endpoints, the tunnel using the shared secret to derive encryption keys used for IPsec-secured communications between the first and second endpoints.
  3. 20
    20, A system comprising:a first endpoint comprising a computing system configured to: transmit a first message to a second endpoint, the first message including a token, the token including one or more entries, each entry corresponding to a community of interest associated, with a user of the first endpoint and including an encryption key and a validation key associated with the first endpoint and encrypted with the corresponding community of interest key;receive from the second endpoint a second message including a second authorization token, the second authorization token including one or more entries, each entry corresponding to a community of interest associated with a second user of the second endpoint and including an encryption key and a validation key associated with the second endpoint and encrypted with the corresponding community of interest key;for each community of interest associated with both the first user and the second user, decrypt an associated entry in the second authorization token to obtain the encryption key and validation key associated with the second endpoint;create a key pair and generating a shared secret based on the key pair;transmit a third message including the created key pair to the second endpoint, thereby allowing the second endpoint to derive the shared, secret;and initialize a tunnel to the second endpoint, the tunnel using the shared secret to derive encryption keys used for IPsee-secured communications by the first endpoint;and the second endpoint including a second computing system communicatively connected to the computing system at the first endpoint, the second computing system configured to: receive the first message: for each community of interest associated with both the first user and the second user, decrypt an associated entry in the token to obtain the encryption key and validation key associated with the first endpoint;create a second key pair transmit the second message to the first endpoint, the second message including the second authorization token and the second key pair;receive the third message;derive at the second endpoint the shared secret from the key pair created at the first endpoint and the key pair created at the second endpoint;and initialize a tunnel to the first endpoint using the shared secret to derive encryption keys used for IPsec -secured communications by the second endpoint.