| CPC H04L 63/061 (2013.01) [H04L 63/0428 (2013.01)] | 25 Claims |

|
1. A method, comprising:
sending, by a first network device and to a second network device, an initial reauthentication request message when a time for an initial authentication associated with the first network device expires and when a first cryptographic suite associated with the first network device is not changed, wherein the initial reauthentication request message comprises a first notification message carrying a first security parameters index (SPI) value;
receiving, by the first network device, from the second network device, and in response to sending the initial reauthentication request message, an initial reauthentication response message, wherein the initial reauthentication response message carries a second notification message, and wherein the second notification message carries a second SPI value; and
reauthenticating, by the first network device and according to the first SPI value and the second SPI value, a security association associated with the first network device when the first cryptographic suite and a second cryptographic suite associated with the second network device are not changed, wherein the first cryptographic suite is the same as the second cryptographic suite.
|