US 12,238,079 B2
Upstream approach for secure cryptography key distribution and management for multi-site data centers
Govind Prasad Sharma, Union City, CA (US); Javed Asghar, Dublin, CA (US); Prabhu Balakannan, Milpitas, CA (US); and Sridhar Vallepalli, Fremont, CA (US)
Assigned to Cisco Technology, Inc., San Jose, CA (US)
Filed by Cisco Technology, Inc., San Jose, CA (US)
Filed on May 23, 2024, as Appl. No. 18/673,183.
Application 18/673,183 is a continuation of application No. 18/508,743, filed on Nov. 14, 2023.
Application 18/508,743 is a continuation of application No. 16/940,114, filed on Jul. 27, 2020, granted, now 11,895,100, issued on Feb. 6, 2024.
Application 16/940,114 is a continuation of application No. 16/166,973, filed on Oct. 22, 2018, granted, now 10,778,662, issued on Sep. 15, 2020.
Prior Publication US 2024/0314114 A1, Sep. 19, 2024
Int. Cl. H04L 9/40 (2022.01); H04L 9/08 (2006.01); H04L 12/46 (2006.01); H04L 69/14 (2022.01); H04L 69/22 (2022.01)
CPC H04L 63/062 (2013.01) [H04L 9/0891 (2013.01); H04L 12/4641 (2013.01); H04L 63/0428 (2013.01); H04L 63/166 (2013.01); H04L 69/14 (2013.01); H04L 69/22 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A system for distributing keys to a plurality of sites in a multi-site network, comprising:
a multi-site key distribution controller (MSKDC);
a first site of a multi-site network comprising a first local key management node;
a second site of the multi-site network comprising a second local key management node, wherein each of the first and second local key management nodes are operative to establish secure connections with the MSKDC;
the MSKDC being configured to coordinate key distribution between sites of the multi-site network by:
receiving, from the first local key management node of the first site of the multi-site network, a request to distribute key material to the second site of the multi-site network, wherein the request includes a security channel identifier value associated with at least the first site; and
sending, to the second local key management node of the second site, the key material based on the security channel identifier;
wherein:
the first local key management node is operative to provide an encryption key based at least in part on the key material to one or more network devices at the first site;
the encryption key is used by the one or more network devices at the first site to encrypt packets sent from the first site;
the second local key management node is operative to provide the encryption key based at least in part on the key material to one or more network devices at the second site; and
the encryption key is used by the one or more network devices at the second site to decrypt encrypted packets sent from the first site.