Patent · US Active

Method and system for protecting data flow between pairs of branch nodes in a software-defined wide-area network

US10142298B2 · kind B2 · utility

1Cited by
3References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 26, 2016
Grant dateNov 27, 2018
Priority date
Expiry dateMay 27, 2037

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/083
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method for protecting data flows between pairs of branch nodes in a software-defined wide-area network (SD-WAN) is disclosed. In an embodiment, the method involves establishing secure connections between a SD-WAN controller and branch nodes in a plurality of branch nodes, wherein each branch node advertises a half-key to the SD-WAN controller via its secure connection, distributing advertised half-keys to branch nodes in the plurality of branch nodes via the established secure connections, wherein the advertised half-keys distributed to each branch node are the half-keys advertised by peer branch nodes of the branch node, and encrypting payloads for transmission from a first branch node in the plurality of branch nodes to a peer branch node in the plurality of branch nodes using a shared secret key, the shared secret key generated using the half-key of the first branch node and the distributed half-key of the peer branch node.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.