The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 17, 2022

Filed:

Sep. 30, 2020
Applicant:

Juniper Networks, Inc., Sunnyvale, CA (US);

Inventors:

Manish Talwar, Lunenburg, MA (US);

Ajay Kachrani, Nashua, NH (US);

Gert Grammel, Ditzingen, DE;

Hao Wang, Kanata, CA;

Tanweer Biswas, Ottawa, CA;

Assignee:

Juniper Networks, Inc., Sunnyvale, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 65/1069 (2022.01); H04L 101/622 (2022.01); H04L 41/0604 (2022.01); H04L 45/00 (2022.01); H04L 43/16 (2022.01);
U.S. Cl.
CPC ...
H04L 63/0876 (2013.01); H04L 41/0627 (2013.01); H04L 43/16 (2013.01); H04L 45/22 (2013.01); H04L 61/6022 (2013.01); H04L 63/061 (2013.01); H04L 63/162 (2013.01); H04L 65/1069 (2013.01);
Abstract

Embodiments improve error detection and recovery in media access control security sessions. A MACsec session is torn down after three liveness time intervals elapse without receiving a MACsec key exchange protocol data unit (MKPDU) from a remote peer. This delay between a cessation of effective network communication over the MACsec session and the expiration of the three 'liveness' intervals results in increased packet loss and an increased network convergence time as a network continues to route/forward data over the MACsec session for a period of time after the MACsec session has entered secure block mode. To solve this problem, embodiments define a new alarm, called a MACsec link alert, which is raised earlier than a MACsec session timeout generated by traditional embodiments. The MACsec link alert is raised, by at least some embodiments, after a failure to successfully receive an MKPDU from the remote peer after a single MACsec 'liveness' timeout interval elapses.


Find Patent Forward Citations

Loading…