Invention Grant
- Patent Title: Defeating man-in-the-middle attacks in one leg of 1+1 redundant network paths
-
Application No.: US15920651Application Date: 2018-03-14
-
Publication No.: US10771476B2Publication Date: 2020-09-08
- Inventor: Pascal Thubert , Patrick Wetterwald , Eric Levy-Abegnoli , Jean-Philippe Vasseur
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Behmke Innovation Group LLC
- Agent Kenneth J. Heywood; James J. Wong
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/823 ; H04W12/12 ; H04L9/32 ; H04L12/28

Abstract:
In one embodiment, an elimination point device in a network obtains a master secret from a network controller. The elimination point device assesses, using the master secret, whether an incoming packet received by the elimination point device from a redundant path between the elimination point device and a replication point device in the network includes a valid message integrity check (MIC). The elimination point device determines whether the incoming packet was injected maliciously into the redundant path, based on the assessment of the incoming packet. The elimination point device initiates performance of a mitigation action in the network, when the elimination point device determines that the incoming packet was injected maliciously into the redundant path.
Public/Granted literature
- US20190289022A1 DEFEATING MAN-IN-THE-MIDDLE ATTACKS IN ONE LEG OF 1+1 REDUNDANT NETWORK PATHS Public/Granted day:2019-09-19
Information query