INTERNET PROTOCOL SECURITY (IPSEC) SECURITY ASSOCIATIONS (SA) BALANCE BETWEEN HETEROGENEOUS CORES IN A SYSTEM WITH MULTIPLE CONTROLLERS

The hybrid IPsec relocation method optimizes IPsec SA distribution across hardware and software accelerators, addressing resource constraints and enhancing performance in multi-controller networks by dynamically balancing IPsec SAs.

DE102022109192B4Active Publication Date: 2025-10-16HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102022109192
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-02-15
Filing Date
2022-04-14
Publication Date
2025-10-16
Estimated Expiration
2042-04-14

AI Technical Summary

Technical Problem

Existing IPsec relocation methods face limitations in supporting a large number of secure connections due to resource constraints, particularly in systems with multiple controllers, where hardware implementations are insufficient, and software implementations consume CPU resources, leading to performance bottlenecks.

Method used

A hybrid IPsec relocation approach that dynamically balances IPsec security associations (SAs) between hardware and software implementations, optimizing distribution based on network architecture and controller priorities, allowing flexible and efficient use of resources.

Benefits of technology

Enhances the capability to support a greater number of secure connections by efficiently utilizing both hardware and software IPsec accelerators, improving performance and resource utilization in networks with multiple controllers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A procedure that includes: Initiating an Internet Protocol Security (IPsec) session by an IPsec network device (106A-106C, 146, 210, 310, 410); Determining, by the IPsec network device, whether a resource limit for a hardware-based IPsec accelerator (190, 212, 312, 490) has been reached, wherein the hardware-based IPsec accelerator is enabled on the IPsec network device; and in response to determining that the resource limit for the hardware-based IPsec accelerator has been reached, offloading processing for the IPsec security association (SA) associated with the initiated IPsec session by the IPsec network device to a software-based IPsec accelerator (191, 211, 311, 491), wherein the software-based IPsec accelerator is enabled on the IPsec network device, wherein offloading the processing for the IPsec SA to the software-based IPsec accelerator comprises establishing an IPsec tunnel (197, 220a-220c, 230a-230c, 320a, 320b, 330a, 330b, 420a, 420b, 430a, 430b, 520a-520d) between the IPsec network device and a controller (104, 196A, 196B, 240A-240F, 340A-340D, 440A, 440B, 540a-540d) of a multi-controller system using the software-based IPsec accelerator, and where determining whether the resource limit for the hardware-based IPsec accelerator has been reached includes: Determine the current number of IPsec tunnels established by the hardware-based IPsec accelerator; Comparing the current number of IPsec tunnels with a maximum number of IPsec tunnels according to the resource limitation of the hardware-based IPsec accelerator; and in response to determining that the current number of IPsec tunnels has reached or exceeded the maximum number of IPsec tunnels, determining that the resource limit for the hardware-based IPsec accelerator has been reached.
Need to check novelty before this filing date? Find Prior Art

Description

background

[0001] Optical communication technology is used in some computer networks to increase the speed, cable length, and overall bandwidth for communication between different network devices (e.g., between a server device and a network router, or between network switches). One such network application that utilizes optical communication technology (e.g., optical cables, optical transceiver modules) is storage networking. In particular, storage area networks (SANs) can use fiber optic connections to achieve network communication over long distances. For example, when optical communication technologies and optical interfaces are used, a SAN can provide data transfer rates of up to 128 Gbps over distances of large cities (e.g., up to about 10 km). In addition, optical components, such as optical transceivers, are increasingly being integrated into network devices.For example, switches used in storage networks can be equipped with optical transceivers to leverage the enhanced capabilities of optical communication technology to meet the unique requirements of storage networks, such as data growth, demanding workloads, and high performance.

[0002] US 2013 / 0 124 930 A1 relates generally to network communication and in particular to techniques for controlling Internet Protocol Security (IPSec) offloads in the event of a hardware failure.

[0003] US 2016 / 0 197 836 A1 relates generally to packet switching and, more particularly, to a system and method for providing IP services in an integrated manner. Brief description of the drawings

[0004] The present disclosure will be described in detail in accordance with one or more various embodiments with reference to the following figures. The drawings are for illustrative purposes only and represent merely typical or exemplary embodiments. These drawings are intended to facilitate the reader's understanding of various embodiments and are not to be considered limiting the breadth, scope, or applicability of the present disclosure. It should be noted that these drawings are not necessarily to scale for clarity and simplicity of illustration. Fig. 1 shows an example of a network environment in which Internet Protocol Security (IPsec) Security Associations (SAs) and the disclosed IPsec SA balancing technology may be implemented in accordance with the disclosure. Fig. 2 shows an example of a multi-controller network environment for implementing the disclosed IPsec SA balancing technology according to the disclosure. Fig. 3 shows an example of a multi-cluster network environment for implementing the disclosed IPsec SA balancing technology according to the disclosure. Fig. 4 shows an example of an IPsec network device implementing an aspect of the disclosed IPsec SA Balancing T according to the disclosure. Fig. 5 shows an example of an IPsec network device implementing another aspect of the disclosed IPsec SA balancing technology according to the disclosure. Fig. 6 is an operational flow diagram illustrating an example method for implementing the disclosed IPsec SA balancing technology according to implementations of the disclosure. Fig. 7 shows a block diagram of an exemplary computer system in which various embodiments described herein may be implemented.

[0005] The illustrations are not intended to be exhaustive and do not limit the various embodiments to the precise form they disclose. It is understood that various embodiments may be implemented with modifications and changes. Detailed description

[0006] Internet Protocol Security (IPsec) encryption is used in some networks as a protocol that supports data encryption for security purposes. In an example of a network architecture using IPsec encryption, the access point (AP) can establish an encrypted IPsec tunnel with a controller. Uplink and / or downlink traffic is then sent through the established IPsec tunnel, enabling secure communication when transporting information packets across network boundaries. As network interface rates (e.g., 100 Gb / s) increase with the continuous expansion of distributed computing, there is a desire to minimize the processing overhead associated with IPsec.A number of available implementation options address this, focusing primarily on processing IPsec-related functions (referred to here as IPsec offloading), and can thus improve the processing efficiency of the overall system. For example, IPsec offloading can be used to reduce the CPU cycles spent on computationally intensive operations (e.g., encryption / decryption tasks are the most computationally intensive among IPsec processing tasks).

[0007] IPsec offloading implementations range from a software implementation with optimized CPU instructions to the use of hardware to offload various aspects of IPsec packet processing. For example, a hardware implementation for IPsec hardware offloading might use an integrated cryptography accelerator chip (e.g., on an expansion board) to offload the highly computationally intensive tasks of encryption / decryption and compression / decompression for IPsec, where IPsec might run on separate cores. By offloading IPsec processing from a host processor, either through a hardware- or software-assisted implementation, efficiency can be improved. For example, a system using a hardware implementation, such as a cryptographic accelerator chip, for IPsec offloading can achieve a throughput of 1 GB / s to 2 GB / s. A system with a software implementation (e.g.,For example, software modules that perform the encryption / decryption functions for IPsec can achieve a throughput of 100Mbps ~ 300Mbps.

[0008] However, using software or hardware implementations of IPsec offloading comes with disadvantages. For example, software implementations of IPsec offloading still consume the CPU cores of the host computer system (since they do not run on separate, dedicated hardware). Therefore, when using software implementations of IPsec offloading, the CPU can become a bottleneck and offer lower performance for data traffic (e.g., 100 Mbps–300 Mbps throughput) compared to hardware implementations. In contrast, the hardware implementation of IPsec offloading does not disrupt the CPU cores of the host computer system, as the IPsec encryption / decryption functions, for example, are executed within the cryptographic accelerator chip without consuming the processing resources of the cores on the host.With regard to hardware implementations of IPsec offloading, there are therefore limitations on the number of IPsec tunnels that can be supported simultaneously by controllers. As a result, some computer architectures, such as extensive systems with multiple controllers, require a larger number of secure connections than is supported by the IPsec tunneling capability of the hardware implementations of IPsec offloading. For example, the number of controllers requiring secure connections may exceed the number of IPsec tunnels that the hardware implementation of IPsec offloading can support simultaneously.

[0009] Against this background, it is the object of the present invention to at least partially improve the disadvantages of the prior art and in particular to improve IPsec relocation.

[0010] This object is achieved by the subject matter of claims 1, 2 and 10. Embodiments are the subject matter of the dependent claims.

[0011] To optimize IPsec offloading, the disclosed embodiments include methods and systems that support various distributions of IPsec functionality, e.g., in systems with multiple controllers, in a manner that is flexible and adaptively optimized for the particular network architecture deployed.

[0012] The disclosed embodiments may utilize a hybrid IPsec offloading approach that can leverage the advantages of both hardware and software implementations of IPsec offloading. In other words, the disclosed embodiments enable load balancing of IPsec Security Associations (SAs) between different heterogeneous cores in multiple controller systems using software implementations of IPsec offloading and / or hardware implementations of IPsec offloading. Accordingly, the disclosed embodiments may realize increased optimization, an improved user experience, and improved product performance in networks that use IPsec for security features.

[0013] An example network configuration 100 with which the IPsec SA load balancing systems and methods could be implemented in various applications is shown in Fig. 1. The network configuration 100 may be implemented, for example, for an organization such as a business, an educational institution, a government agency, a healthcare facility, or another organization. This diagram illustrates an example of a configuration implemented for an organization with multiple users (or at least multiple client devices 110) and possibly multiple physical or geographic locations 102, 132, 142. The network configuration 100 may include a primary site 102 that communicates with a network 120. The network configuration 100 may also include one or more remote sites 132, 142 that communicate with the network 120.

[0014] The primary site 102 may include a primary network, which may be, for example, an office network, a home network, or other network installation. The primary network 102 may be a private network, such as a network that may include security and access controls to restrict access to authorized users of the private network. Authorized users may include, for example, employees of a company at the primary site 102, residents of a home, customers of a company, etc.

[0015] In the example shown, primary site 102 includes a controller 104 that communicates with network 120. Controller 104 may provide communication with network 120 for primary site 102, although it need not be the sole point of communication with network 120 for primary site 102. A single controller 104 is illustrated, although the primary site may include multiple controllers and / or multiple points of communication with network 120. In some embodiments, controller 104 communicates with network 120 via a router (not shown). In other embodiments, controller 104 provides router functions to devices at primary site 102. Network configuration 100 also includes controllers 196A and 196B distributed at remote sites 132 and 142, respectively.Although a single controller 196a or 196b is shown at each location, the remote locations 132 and 142 may include multiple controllers and / or multiple points of communication with the network 120.

[0016] Controllers 104, 196A, 196B can be used to configure and manage network devices. For example, controller 104 manages the network devices at primary site 102 and can also manage network devices at remote sites 132, 134. Controllers 104, 196A, 196B can be operated to configure and / or manage switches, routers, access points, and / or client devices connected to a network. Controllers 104, 196A, 196B can themselves be an access point or provide the functionality of one.

[0017] Controllers 104, 196A, 196B may communicate with other network devices. As illustrated, controller 104 may communicate with one or more switches 108 and / or wireless access points (APs) 106A-C. Switches 108 and wireless APs 106A-C establish network connections to various client devices 110a-j. Through a connection to a switch 108 or AP 106A-C, a client device 110A-J may access network resources, including other devices on the network (primary site 102) and on the network 120.

[0018] Examples of client devices such as 110A-110J may include: desktop computers, laptops, servers, web servers, authentication servers, authentication authorization accounting (AAA) servers, domain name system (DNS) servers, dynamic host configuration protocol (DHCP) servers, internet protocol (IP) servers, virtual private network (VPN) servers, network policy servers, mainframe computers, tablet computers, e-readers, netbook computers, televisions and similar displays (e.g., smart TVs), content receivers, set-top boxes, personal digital assistants (PDAs), mobile phones, smart phones, intelligent terminals, silent terminals, virtual terminals, video game consoles, virtual assistants, Internet of Things (IOT) devices, and the like.

[0019] Within primary site 102, a switch 108 is included as an example of an access point to the network established at primary site 102 for wired client devices 110I-J. Client devices 110I-J can connect to switch 108 and access other devices within network configuration 100 through switch 108. Client devices 110I-J can also access network 120 through switch 108. Client devices 110I-J can communicate with switch 108 via a wired connection 112. In the illustrated example, switch 108 communicates with controller 104 via a wired connection 112, although this connection may also be wireless.

[0020] Wireless APs 106A-C are another example of an access point to the network established at primary site 102 for client devices 110A-H. Each of APs 106A-C may be a combination of hardware, software, and / or firmware configured to provide wireless network connectivity to wireless client devices 110A-H. In the illustrated example, APs 106A-C may be managed and configured by controller 104. APs 106A-V communicate with controller 104 and the network via connections 112, which may be either wired or wireless interfaces.

[0021] In addition, Fig. 1, the AP 106A may be configured to include: IPsec accelerator hardware 190, such as a coprocessor, specifically designed to offload IPsec-related functions from the AP's CPU resources; IPsec accelerator software 191, such as specialized processing software specifically designed to offload IPsec-related functions from the AP's CPU resources; and an IPsec load balancer 195 implementing the IPsec SA balancing aspects disclosed herein to distribute the IPsec functions between the IPsec accelerator hardware 190 and the IPsec accelerator software 191 in a manner that is optimally balanced based on the network deployment in use. In general, the IPsec SA Load Balancer 195 distributes the processing associated with establishing IPsec tunnels (e.g., encryption / decryption) between the IPsec accelerator software 191 (e.g.,Software implementation of IPsec offloading) and IPsec accelerator hardware 190 (e.g., hardware implementation of IPsec offloading). Accordingly, IPsec tunnels, such as IPsec tunnel 197, can establish a secure VPN over an otherwise insecure (e.g., public) network 120, such as the Internet. While the embodiment of [ . Fig. 1 as establishing IPsec tunnels with APs, it is to be understood that the disclosed technology can be used to orchestrate IPsec SAs and establish IPsec tunnels with any network points that can support this function, such as gateways, branch gateways, and controllers connected via a Layer 3 network.

[0022] IPsec describes a set of standards for secure network protocols that use cryptography to secure communication over Internet Protocol (IP) networks. It can be used to authenticate endpoint hosts and ensure data confidentiality and integrity. IPsec can use the Internet Key Exchange Protocol (IKE) to authenticate each peer in an IPsec session, negotiate security associations (SAs) between peers, and manage the exchange of session keys. IKE is a component of IPsec used for mutual authentication and establishing and maintaining SAs.

[0023] An IPsec data exchange between two peers can consist of five steps: i) initiation of an IPsec session; ii) IKE Phase 1; iii) IKE Phase 2; iv) data transfer; and v) termination of the IPsec session. An IPsec session initiation (e.g., a VPN tunnel) can be triggered when network traffic is marked as requiring protection according to an IPsec security policy (SP) configured in the IPsec peers. For example, network traffic of a certain type can be marked as requiring protection based on a security policy, while other traffic can flow normally through a public network. After session initiation, an IKE process can begin. During IKE Phase 1, security parameters and keys required to establish an IKE Security Association (SA) can be negotiated.IKE Phase 1 may include: authenticating the identities of IPsec peers; negotiating a shared IKE SA policy between peers to protect the IKE exchange; Diffie-Hellman (DH) key exchange to create shared secret keys; and establishing a secure tunnel to negotiate IKE Phase 2 parameters.

[0024] In IKE Phase 2, the two peers can negotiate a common IPsec policy and the security parameters and inbound and outbound security keys required to establish two unidirectional IPsec SAs (e.g., one for inbound and one for outbound traffic). Traffic can then be exchanged during the IPsec session, with packets being encrypted and decrypted at the remote sites using the encryption specified in an IPsec SA. Additionally, the traffic can be authenticated.

[0025] The devices at both ends of an IPsec tunnel are called IPsec peers. Back to Fig. 1: AP 106a and Controller 196A, connected via IPsec tunnel 197, can be considered IPsec peers. To establish IPsec tunnel 197, the IPsec peers, such as AP 106A and Controller 196A, exchange a series of messages regarding encryption and authentication and attempt to agree on many different parameters during the VPN negotiation process, as described in detail above. One of the IPsec peers acts as the initiator in the negotiation sequence, while the other device acts as the responder. For example, AP 106a can be the initiator in the negotiation sequence, while Controller 196a acts as the responder.

[0026] The IPsec SA load balancer 195 may be implemented as a combination of hardware, software, and / or firmware of an AP, such as AP 106A. The IPsec SA load balancer 195 may be configured to selectively distribute IPsec functions between the IPsec hardware accelerator 190 and the IPsec software accelerator 191. Furthermore, the IPsec hardware accelerator 190 may be one or more hardware implementations, including, but not limited to, an integrated circuit chip, a processor, a special-purpose CPU (e.g., a core), and a coprocessor. Furthermore, the IPsec software accelerator 191 may be one or more software implementations, including, but not limited to, software module(s), instruction set, application, and firmware.

[0027] For example, the IPsec SA load balancer 195 can establish a specific number of IPsec tunnels (or IPsec SAs) using the IPsec accelerator hardware 190 and then transfer the IPsec offloading to the IPsec accelerator software 191. The IPsec accelerator software 191 can then be used to establish any additional number of IPsec tunnels (or IPsec SAs), for example, in networks with a large number of heterogeneous controllers. The IPsec SA load balancer 195 is configured to prioritize the use of the IPsec hardware accelerator 190 and also to prioritize the establishment of IPsec tunnels with specific controllers. For example, a controller with high performance requirements or a controller involved in the IPsec data process can be given preferential treatment by the IPsec SA load balancer 195. By prioritizing the higher efficiency of hardware-based IPsec offloading implementations (e.g.By limiting the use of the IPsec hardware accelerator 190 until a maximum threshold of hardware resource limitations is reached, the IPsec SA load balancer 195 can therefore realize improved utilization of the AP 106A in terms of IPsec capabilities.

[0028] The network configuration 100 may include one or more remote sites 132. A remote site 132 may be located at a different physical or geographical location than the primary site 102. In some cases, the remote site 132 may be located at the same geographical location or possibly in the same building as the primary site 102, but does not have a direct connection to the network of the primary site 102. Instead, the remote site 132 may utilize a connection through another network, such as the network 120. A remote site 132, as described in Fig. 1 may be, for example, a satellite office, a different floor or suite in a building, etc. The remote location 132 may include a gateway device 134 for communicating with the network 120. A gateway device 134 may be a router, a digital-to-analog modem, a cable modem, a DSL modem, or other network device configured to communicate with the network 120. The remote location 132 may also include a switch 138 and / or an AP 136 that communicates with the gateway device 134 via either wired or wireless connections. The switch 138 and the AP 136 provide connectivity to the network for various client devices 140A-140D.

[0029] In various embodiments, the remote site 132 may be in direct communication with the primary site 102, such that client devices 140A-D at the remote site 132 access the network resources at the primary site 102 as if those client devices 140a-d were located at the primary site 102. In such embodiments, the remote site 132 is managed by the controller 104 at the primary site 102, and the controller 104 provides the necessary connectivity, security, and accessibility to enable communication between the remote site 132 and the primary site 102. Once connected to the primary site 102, the remote site 132 may function as part of a private network provided by the primary site 102.

[0030] In various embodiments, the network configuration 100 may include one or more smaller remote sites 142 that include only a gateway device 144 for communicating with the network 120 and a wireless AP 146 through which various client devices 150a-b access the network 120. Such a remote site 142 may be, for example, the home of an individual employee or a temporary remote office. The remote site 142 may also communicate with the primary site 102 so that the client devices 150A-B at the remote site 142 access the network resources at the primary site 102 as if those client devices 150A-150B were located at the primary site 102. The remote site 142 may be managed by the controller 104 at the primary site 102 to enable this transparency.Once connected to the primary site 102, the remote site 142 may function as part of a private network provided by the primary site 102.

[0031] Network 120 may be a public wide area network (WAN) such as the Internet or other communications network that provides interconnection between the various locations 102, 130-142, and access to servers 160A-B. Network 120 may include third-party telecommunications lines such as telephone lines, broadcast coaxial cable, fiber optic cable, satellite communications, cellular communications, and the like. Network 120 may include any number of intermediate network devices, such as switches, routers, gateways, servers, and / or controllers, that are not directly part of network configuration 100 but facilitate communication between the various parts of network configuration 100 and between network configuration 100 and other entities connected to the network. Network 120 may include various content servers 160a-b.Content servers 160a-b may include various providers of downloadable multimedia and / or streaming content, including audio, video, graphics, and / or text content, or any combination thereof. Examples of content servers 160a-b include web servers, streaming radio and video providers, and cable and satellite television providers. Client devices 110A-J, 140A-D, and 150A-B may request and access the multimedia content provided by content servers 160A-B.

[0032] As an example, referring to Fig. 1, IPsec can be enabled as a network layer security protocol in network configuration 100. Fig. Figure 1 shows how AP 106A establishes an IPsec tunnel 197 with controller 196A for secure communication. Accordingly, AP 106A must perform additional processing to ensure encryption and integrity protection of IPsec packets transmitted over IPsec tunnel 197. However, network configuration 100 could include a large number of controllers to provide connectivity, security, and accessibility to separate networks, such as remote sites 132, 142. As a result, AP 106A may need to support multiple IPsec tunnels simultaneously during operation (e.g., an individual IPsec tunnel for each controller) to ensure secure communication with the controllers of the respective networks. As already described, the AP 196A is equipped with both the IPsec hardware accelerator 190 and the IPsec software accelerator 191 for establishing IPsec SAs.For example, the IPsec tunnel 197 may belong to a group of IPsec tunnels (not shown) managed by the AP 106. After establishing the IPsec tunnel 197, the IPsec SA load balancer 195 may determine that the AP 106A has now reached a limit on the number of IPsec tunnels that can be supported by the IPsec hardware accelerator 190.

[0033] Continuing the example, AP 106A may need to establish another IPsec tunnel with controller 196B for secure communication with remote site 142. However, because IPsec SA load balancer 195 knows that IPsec hardware accelerator 190 has reached the maximum of its resource limits, attempting to establish additional IPsec tunnels using hardware-based IPsec offloading may be detrimental. A key aspect of the disclosed embodiments is the ability to switch an AP's IPsec offloading between hardware and software implementations as needed. In this example, IPsec SA load balancer 195 may begin utilizing AP 106A's IPsec software accelerator 191 to establish subsequent IPsec SAs after IPsec hardware accelerator 190 reaches a maximum threshold of its resource limit.Consequently, the IPsec SA load balancer 195 can direct the AP 106A to begin executing the IPsec software accelerator 191 and establish the IPsec SA with the controller 196B. The IPsec tunnel to the controller 196B is supported by the IPsec software accelerator 191, e.g., by using the IPsec software accelerator 191 to perform encryption / decryption. The disclosed IPsec SA load balancing techniques enable the APs in the network configuration 100 to deploy IPsec in a multi-controller system in a flexible and adaptable manner without violating and / or overwhelming the resource constraints of a single IPsec offloading implementation. It should be noted that the implementations described herein are not limited to the implementations described in . Fig. 1. For example, in an enterprise context, IPsec may be implemented to provide remote access VPNs for individual user devices, to provide intranet VPNs for connecting remote locations, and / or to provide extranet VPNs. If remote VPN access is provided to a user device (e.g., the user's laptop), the user device itself may include a VPN client configured to run an IPsec application and may function as an IPsec network device according to the disclosure.

[0034] Fig. 2 shows an example environment 200 in which the disclosed IPsec SA balancing techniques may be deployed, particularly in a non-clustered multiple controller network configuration. Fig. 2 contains essentially similar elements and functions as described above with reference to Fig. 1. Therefore, the general structure and function of these elements are described in Fig. 2, such as the 240A-240F controllers, AP 210, IPsec Software Accelerator 211, and IPsec Hardware Accelerator 212, are not described in detail again. In the example, an AP 210 has established secure communication with multiple controllers, represented as controllers 240A-240F. The 240A-240F controllers are considered non-clusters because each of the 240A-240D controllers can correspond to a separate network, in contrast to multiple controllers grouped or clustered within the same site (as in Fig. 3).

[0035] In accordance with the IPsec SA balancing techniques disclosed herein, the AP 210 is configured to identify an IPsec priority corresponding to each of the controllers 240A-240F. For illustrative purposes, the IPsec priority values ​​described herein include high priority and low priority. However, embodiments may use various forms of priority designations, such as parameters, numerical values, conditions, levels, ranges, and the like. In some embodiments, each controller 240A-240F has a previously assigned IPsec priority. For example, the controllers 240A-240F may be assigned either a low or high priority during network setup (e.g., by a network administrator). In some embodiments, the IPsec priority for each of the controllers 240A-240F may be determined dynamically based on various network performance-related characteristics, such as:Traffic volume, airslice quality, QOS requirements, etc. For example, IPsec priority may be assigned to a controller to improve IPsec traffic performance for that controller, in turn improving voice or video quality. In some embodiments, IPsec priorities may be determined based on a combination of static and dynamic characteristics, as described above.

[0036] For example, the IPsec priority for each of the controllers 240a-240f may be dynamically determined by the AP 210. For example, when traffic flows are communicated between the AP 210 and the controllers 240A-240F, the AP 210 may determine whether any of the controllers 240A-240F have a traffic volume that is considered "high traffic" (e.g., traffic above a threshold, traffic within a high traffic range, etc.). In the example of Fig. 2, the AP 210 can detect that controllers 240A, 240C, and 240D are handling a high volume of traffic. The AP 210 can then automatically assign a "high" IPsec priority to controllers 240A, 240C, and 240D. Conversely, the AP 210 can determine if any of the controllers 240A-240F have a traffic volume that is considered "low traffic" (e.g., traffic below a threshold, traffic within a low traffic range, etc.). For example, the AP 210 detects that controllers 240B, 240E, and 240F are handling a low volume of traffic and can therefore automatically assign a "low" IPsec priority to controllers 240B, 240E, and 240F.

[0037] The AP 210 can be configured to offload the processing for establishing IPsec SAs for "high" priority controllers to the hardware IPsec accelerator 212. Conversely, the AP 210 is configured to offload the processing for establishing IPsec SAs for "low" priority controllers to the software IPsec accelerator 211 when the hardware IPsec accelerator 212 has reached its resource limit. Under this scheme, controllers 240A, 240C, and 240D that manage a larger percentage of network traffic (e.g., during high traffic periods) receive the more efficient IPsec offload implementation that supports higher throughput, namely the IPsec hardware accelerator 212. In addition, the AP 210 may detect that the hardware IPsec software accelerator 212 has reached its resource limit in supporting the IPsec tunnels 220a-220c.The AP 210 can then switch to using the IPsec software accelerator 211. This allows controllers 240B, 240E, and 240F that handle less traffic on the network (e.g., during low traffic conditions) to have their IPsec SAs orchestrated using the IPsec software accelerator 212. This is illustrated in accordance with this diagram. Fig. 2, that the AP 210 has established an IPsec tunnel 220a with the controller 240A, an IPsec tunnel 220b with the controller 240C, and an IPsec tunnel 220c with the controller 240D via the hardware IPsec accelerator 212; and an IPsec tunnel 230a with the controller 240B, an IPsec tunnel 230b with the controller 240E, and an IPsec tunnel 230c with the controller 240F via the software IPsec accelerator 211.

[0038] There may be scenarios where the AP 210 can offload IPsec SAs for all high-priority IPsec controllers in use without reaching the hardware resource limit. In this case, the AP 210 is configured to continue using the IPsec hardware accelerator 212, including to establish IPsec SAs for controllers assigned a low IPsec priority. In other words, the AP 210 only switches IPsec offloading to the software-based implementation when the hardware-based implementation is fully utilized.

[0039] In Fig. 3 illustrates an example of another environment 300, specifically a clustered multi-controller network configuration in which the disclosed IPsec SA balancing techniques may be employed. Fig. 3 contains essentially similar elements and functions as described above with reference to Fig. 1. Therefore, the general structure and function of these elements are described in Fig. 3, such as the controllers 340, the AP 310, the IPsec software accelerator 311, and the IPsec hardware accelerator 312, will not be described in detail again. In particular, in the example, there are a plurality of controllers 340 grouped into respective clusters 350a-350d. That is, each of the clusters 350A-350D comprises a grouping of multiple controllers 340 distributed therein. For example, each of the clusters 350A-350D may be a group of controllers 340 located at the same network location. For example, each of the clusters 350A-350D may be arranged in a respective local area network (LAN). Furthermore, the AP 310 has established secure communication with the multiple controllers 340 in each of the clusters 350A-350D. Fig. Figure 3 shows that in the cluster multi-controller environment 300, the AP 310 balances all IPsec client traffic within a cluster. Therefore, the AP 310 establishes the same type of IPsec tunnel established by either the IPsec software accelerator 311 or the IPsec hardware accelerator 312 for all controllers 340 within one of the respective clusters 350A-350D. As shown in Fig. For example, as shown in Figure 3, the multiple IPsec tunnels 320a and 320b from AP 310 to clusters 350A and 350C are all orchestrated via hardware-based IPsec offloading and supported by IPsec hardware accelerator 312. The multiple IPsec tunnels 330a, 330b from AP 310 to clusters 350B and 350D, respectively, are managed via software-based IPsec offloading and supported by IPsec software accelerator 312.

[0040] In the cluster multicontroller environment 300, the AP 310 can be configured to identify an IPsec priority associated with each of the clusters 350a-350d, rather than an IPsec priority for each individual controller as in the non-cluster multicontroller installation of Fig. 2 is the case. Each of the clusters 350A-350D may have a corresponding IPsec priority that is previously defined or dynamically determined by the AP 310 in the same manner as described above with reference to Fig. 2. For example, AP 310 may identify clusters 350A, 350C as having a "high" IPsec priority (e.g., if they have a traffic volume considered "high traffic"). Furthermore, AP 310 may identify clusters 350B, 350D as having a "low" IPsec priority (e.g., if they have a traffic volume considered "high traffic").

[0041] As a result, the AP 310 establishes the IPsec SAs for all controllers 340 in the "high" priority clusters 350A, 350C using the hardware IPsec accelerator 212. If the resource limit for the hardware IPsec accelerator 212 is reached, the AP 310 may also establish the IPsec SAs for all controllers 340 in the "low" priority clusters 350B, 350D using the software IPsec accelerator 211.

[0042] According to the embodiments, one aspect of the IPsec SA balancing techniques includes actively "upgrading" a connection for a controller from an IPsec tunnel supported by software-based IPsec offloading to an IPsec tunnel supported by hardware-based IPsec offloading. As previously mentioned, hardware-based IPsec offloading implementations may have advantages (in terms of processing efficiency) over software-based IPsec offloading implementations. Due to these advantages, such as end-to-end performance gains, IPsec tunnels orchestrated with IPsec hardware accelerators may, for example, provide better traffic performance (compared to software-based IPsec offloading implementations). To this end, Fig. 4 an AP 410 configured to perform the “upgrade” function of the disclosed IPsec SA balancing. Fig. 4 contains essentially similar elements and functions as described above with reference to Fig. 1. In particular, Fig. 4 shows an AP 410 which contains the IPsec SA load balancer 195, the IPsec software accelerator 190 and the IPsec hardware accelerator 191, which are Fig. 1 are described in detail.

[0043] There are several scenarios in which it may be optimal to "upgrade" a controller that originally had an IPsec tunnel supported via the IPsec software accelerator 190 to an IPsec tunnel supported via the IPsec hardware accelerator 191. For example, the AP 410 may need to orchestrate an IPsec SA for a controller with a "high" IPsec priority. However, the IPsec hardware accelerator 191 may be approaching the number of IPsec tunnels it can support due to its resource limitations. In another example, the IPsec hardware accelerator 191 may have already reached its resource limit.However, a controller currently using an IPsec tunnel from the IPsec software accelerator 190 may need to "upgrade" to an IPsec tunnel from the IPsec hardware accelerator 191, for example, because the controller now has a high traffic volume or now supports traffic with higher QOS requirements, or other conditions that may be related to the IPsec priority described previously. In these cases, the AP 410 can "downgrade" a controller that has an IPsec tunnel supported by the hardware-based IPsec offloading implementations despite a "low" IPsec priority. The AP 410 can then "upgrade" a controller that has an IPsec tunnel supported by the software-based IPsec offloading implementations despite having a "high" IPsec priority.

[0044] Fig. In particular, Figure 4 shows that the IPsec SA load balancer 195 implemented on the AP 410 may include several internal components, including, but not limited to: tunnel traffic monitor 416; traffic quality monitor 417; configuration module 418; a user application 413; an IPsec tunnel manager 414 that manages the IPsec tunnels established and supported by the AP 410; and a kernel 415 that enables command and / or control communication between the IPsec tunnel manager 414, the IPsec software accelerator 190, and the IPsec hardware accelerator 191. These components of the IPsec SA load balancer 195 may be implemented as hardware, software, firmware, or a combination thereof.

[0045] Accordingly, the AP 410 is able to determine whether the controllers 440A, 440B are in a state that would trigger the disclosed "upgrade" scheme, such as QOS or high traffic. In operation, the AP 410 may first establish the IPsec tunnel 430a for the controller 440A using the IPsec software accelerator 190. Furthermore, the AP 410 has previously established an IPsec tunnel 420a for the controller 440B using the IPsec hardware accelerator 191, with the controller 440B identified as a "low" IPsec priority device. The AP 410 may then determine that the IPsec hardware accelerator 191 has reached the maximum number of IPsec tunnels for its resource limit. The AP 410 can also detect that the Controller 440A is now experiencing high traffic, e.g.using the tunnel traffic monitor 416, and therefore needs to be "upgraded" from its current software-assisted IPsec tunnel 430a to a hardware-assisted IPsec tunnel to ensure good performance for this larger volume of traffic being processed by the controller 440A.

[0046] The AP 410 is capable of examining the configuration of the IPsec SA balancing in use (e.g., the IPsec tunnel types, IPsec tunnel end nodes, etc.). Based on the configuration, the AP 410 can also detect which controllers with a "low" IPsec priority also have an IPsec tunnel established using the hardware IPsec offloading implementation in order to downgrade one or more of these controllers to a secondary or "standby" IPsec tunnel established using the software IPsec offloading implementation. In this example, the AP 410 can detect that controller 440B has a "low" IPsec priority but is using the IPsec tunnel 420a supported by the IPsec hardware accelerator 190. The AP 410 can then “downgrade” the controller 440B by setting up the second IPsec tunnel 430B as a standby IPsec tunnel to the controller 440B.The IPsec SAs of this standby IPsec tunnel 430b are managed by the IPsec software accelerator 191. After the standby IPsec tunnel 430b is successfully established, traffic can be routed through the standby IPsec tunnel 430b instead of the original IPsec tunnel 420a. Since the IPsec tunnel 420a is not actively used by the controller 440b, the AP 410 can terminate this IPsec tunnel 420, thereby releasing the IPsec SAs in the IPsec hardware accelerator 190. An IPsec tunnel is closed when its IPsec SAs end due to deletion (or timeout). By releasing IPsec tunnels, the IPsec hardware accelerator 190 therefore operates below its resource limit and has processing capacity to support subsequent IPsec SAs.

[0047] The AP 410 can then use the IPsec hardware accelerator 190 to establish the IPsec tunnel 420b as a standby IPsec tunnel for the controller 440A. The AP 410 tears down the previous IPsec tunnel 430a established by the IPsec software accelerator 191 so that the controller 440A, which has a "high" IPsec priority, can now transmit its traffic over the IPsec tunnel 430b to improve performance. The IPsec "upgrade" aspects of the Fig. The IPsec SA balancing techniques presented in Figure 4 may be suitable for scenarios where the CPU load on the AP is not high. Alternatively, in cases where the CPU load on the AP is high (which is less conducive to relying on software-based IPsec offloading implementations that consume CPU resources), a different scheme for loading IPsec SAs can be used, which includes dedicated and shared hardware crypto channels (see Fig. 5).

[0048] Fig. Figure 5 shows an example of an AP 510 implementing multiple channels that command and / or control the data sent to the IPsec offloading hardware, such as an IPsec hardware accelerator (not shown), for processing. In the illustrated example, the AP 510 includes dedicated hardware channels 560a, 560b and a shared hardware channel 550. The AP 510 is configured to distribute the IPsec SAs for traffic based on the characteristics of the controller and / or the IPsec tunnel. For example, if the AP 510 detects that an IPsec tunnel is handling a high traffic load, a dedicated hardware crypto channel is assigned to that IPsec tunnel. Fig. Figure 5 shows the dedicated hardware channel 560b used for the IPsec tunnel 520d to the controller 540d, and the dedicated hardware channel 560a used for the IPsec tunnel 520c to the controller 540c. In other words, the dedicated hardware channels 560a and 560b are configured to process the data for one IPsec tunnel and one controller, respectively, so that the corresponding IPsec SAs can be processed by the IPsec hardware accelerator.

[0049] In addition, the AP 510 has a shared hardware crypto channel 550 that is used by multiple IPsec tunnels 520a, 520b to the respective controllers 540a, 540b. Regarding the shared hardware crypto channel 550, the AP 510 (using the IPsec tunnel manager of the IPsec SA load balancing) can apply a queue 570 to appropriately handle the traffic corresponding to the controllers 540a, 540b, which both use the shared hardware crypto channel 550. According to a scheduling scheme (e.g., FIFO, LIFO, etc.) of the queue 570, the hardware, such as the controller 540a, 540b, switches the traffic to the shared hardware crypto channel 550. B. the IPsec hardware accelerator, and begins processing the IPsec SA for the traffic / IPsec tunnel for the communication from queue 570. For example, queue 570 may first output traffic 580b for IPsec tunnel 520b.Accordingly, the hardware processes the IPsec SAs to enable the shared crypto channel 550 for secure communication of traffic 580b to the controller 540b via the IPsec tunnel 520b. Queue 570 may then switch and begin outputting traffic 580a for the IPsec tunnel 520a. As a result, the shared crypto channel 550 is enabled for transmission of traffic 580a via the IPsec tunnel 520a to the controller 540a. Consequently, the packet size specified in [ ] may be greater than [ ]. Fig. 5 can utilize hardware channels in such a way that the IPsec hardware accelerator can be shared, e.g., by switching between different controllers for more efficient traffic processing (e.g., by reducing the amount of software-based IPsec offloading used).

[0050] Fig. 6 is an operational flow diagram illustrating an example method 600 for implementing an IPsec SA balancing scheme as disclosed herein. The method 600 is represented as a series of executable operations in a machine-readable storage medium 601 executed by a hardware processor 602. The computing component 603 may be a computing device that is an IPsec network device, such as an AP (in Fig. 1), as previously described.

[0051] In one example, IPsec peers might want to authenticate and establish a secure connection across a network by initiating an IPsec data exchange to connect to a secure IPsec tunnel. As part of the IPsec data exchange, inbound and outbound security keys and IPsec SAs can be initialized and updated over time. The IPsec network device, such as an AP, can process and forward information transparently, according to an IPsec protocol. Thus, IPsec can be used to establish a virtual private network (VPN) for remote sites over a public network (such as the Internet).

[0052] Process 600 may begin with the initiation of an IP session in operation 610. An IPsec session initiation, which involves establishing an IPsec tunnel, may be triggered by network traffic. For example, a specific type of traffic transmitted to the controller may be marked as worthy of protection. To execute the initiated IPsec session, the IPsec network device begins processing to perform IPsec-related functions. For example, an IPsec tunnel must be configured between the IPsec peers and established for an IPsec session. In addition, there are encryption / decryption functions and the negotiation of keys and other parameters for the IPsec SAs, all of which are involved in the IPsec session.Therefore, after initiating the IPsec session, process 600 may continue with operation 615 to ultimately offload IPsec processing to either a software-based IPsec accelerator or a hardware-based IPsec accelerator.

[0053] As previously described, an IPsec network device, such as an AP, can be enabled with both an IPsec hardware accelerator and an IPsec software accelerator. According to one of the IPsec SA loading schemes, the use of the IPsec hardware accelerator is prioritized over the IPsec software accelerator. In other words, process 600 utilizes the IPsec hardware accelerator until it is deemed potentially critical, such as upon reaching a hardware resource limit. Therefore, in operation 615, the IPsec network device performs a conditional check to determine whether the IPsec hardware accelerator has reached its resource limit. For example, the IPsec hardware accelerator may have design features that limit the hardware to supporting a certain number of IPsec tunnels simultaneously.Consequently, operation 615 may include detecting a current number of IPsec tunnels established and / or supported by the IPsec hardware accelerator. Although operation 615 is discussed in terms of the number of active IPsec tunnels, there are other forms of comparisons, checks, and calculations that may be performed to determine whether the IPsec hardware accelerator's resource limitations have been reached (e.g., CPU cycle cost, CPU processing cost, latency, etc.), which are not described in detail for the sake of brevity.

[0054] If the current number of IPsec tunnels is less than the number of IPsec tunnels allowed by the resource limit of the IPsec hardware accelerator, this indicates that the hardware is operating below its available capacity and the resource limit has not been reached and / or exceeded (represented as “No” in Fig. 6). Consequently, process 600 can continue to use the IPsec hardware accelerator without the risk of IPsec performance being negatively impacted by operating beyond the hardware limitation. Afterward, process 600 proceeds to operation 625. In operation 625, the IPsec network device can offload IPsec SA-related processing for the initiated IPsec session to the IPsec hardware accelerator. Subsequently, the IPsec session can be established between the IPsec peers, i.e., the AP and the controller, to ensure secure communication over the network.

[0055] Returning to Operation 615: Alternatively, the IPsec network device may determine that the current number of IPsec tunnels is equal to and / or greater than the number of IPsec tunnels allowed by the IPsec hardware accelerator's resource limit. In this case, the result of Operation 615 indicates that the hardware is operating at (or above) its available capacity and the resource limit has been reached and / or exceeded (represented as "Yes" in Fig. 6). Thus, process 600 has determined that continued use of the IPsec hardware accelerator may tax the hardware beyond its capabilities and greatly increases the potential for negative impact on IPsec processing. In this case, it is advantageous to use the IPsec software accelerator, which is also enabled on the IPsec network device. As previously indicated, the IPsec software accelerator still utilizes host CPU resources but is not limited to a specific number of IPsec tunnels, as is the case with the hardware-based implementation. The IPsec software accelerator thus provides flexibility that may be advantageous in larger systems. Consequently, process 600 proceeds to operation 620 to deploy the IPsec software accelerator.

[0056] At operation 620, the IPsec network device switches from the IPsec hardware accelerator to the IPsec software accelerator to establish the initiated IPsec session and transfers processing for this IPsec SA to the IPsec software accelerator. All previously established IPsec SAs (and IPsec tunnels) configured with the IPsec hardware accelerator can continue to operate with the IPsec hardware accelerator. Therefore, process 600 does not incur any additional overhead associated with switching an already active IPsec session between the software implementation and the hardware implementation. Instead, operation 620 shifts management of the IPsec SAs for the currently initiated IPsec session to the IPsec software accelerator. The IPsec session can then be established between the IPsec peers, i.e. the AP and the controller, to ensure secure communication over the network.

[0057] Fig. Figure 7 shows a block diagram of an example computer system 700 in which the IPsec SA loading techniques described herein can be implemented. Computer system 700 may be, for example, an IPsec network device, such as an AP (in Fig. 1), as described in detail above. Computer system 700 includes a fabric 702 or other communication mechanism for conveying information, and one or more hardware processors 704 connected to fabric 702 to process information. For example, hardware processor(s) 704 may be one or more general-purpose microprocessors.

[0058] Computer system 700 also includes a main memory 706, such as random access memory (RAM), a cache, and / or other dynamic storage devices connected to fabric 702, for storing information and instructions to be executed by processor 704. Main memory 706 may also be used to store temporary variables or other intermediate information during the execution of instructions to be executed by processor 704. When such instructions are stored in storage media accessible to processor 704, computer system 700 becomes a special-purpose machine adapted to perform the operations specified in the instructions.

[0059] Computer system 700 also includes storage devices 710, such as a read-only memory (ROM) or other static storage device, connected to fabric 702 to store static information and instructions for processor 704. A storage device 710, such as a magnetic disk, an optical disk, or a USB stick (flash drive), etc., is provided and connected to fabric 702 to store information and instructions.

[0060] Computer system 700 may be connected via fabric 702 to a display 712, such as a liquid crystal display (LCD) (or a touchscreen), for displaying information to a computer user. An input device 714, including alphanumeric and other keys, is connected to fabric 702 to communicate information and command selections to processor 704. Another type of user input device is cursor control 516, such as a mouse, trackball, or cursor direction keys for communicating direction information and command selections to processor 504 and controlling cursor movement on display 712. In some embodiments, the same direction information and command selections as with cursor control may be implemented via receiving touches on a touchscreen without a cursor.

[0061] Computer system 700 may include a user interface module for implementing a graphical user interface, which may be stored on a mass storage device as executable software code executed by the computing device(s). This and other modules may include, for example, components such as software components, object-oriented software components, class components and task components, processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables.

[0062] In general, the terms "component," "engine," "system," "database," "data store," and the like, as used herein, may refer to logic embodied in hardware or firmware, or to a collection of software instructions that may have entry and exit points and may be written in a programming language such as Java, C, or C++. A software component may be compiled and linked into an executable program, installed in a dynamic link library, or written in an interpreted programming language such as BASIC, Perl, or Python. It is understood that software components may be callable by other components or by themselves, and / or may be called in response to detected events or interrupts. Software components configured to run on computing devices may be embodied on a computer-readable medium, such as a hard disk.a compact disc, digital video disc, flash drive, magnetic disk, or other tangible medium, or as a digital download (and may be originally stored in a compressed or installable format that must be installed, decompressed, or decrypted before execution). Such software code may be stored partially or entirely in a memory of the executing computing device for execution by the computing device. Software instructions may be embedded in firmware, such as an EPROM. In addition, the hardware components may consist of interconnected logic units, such as gates and flip-flops, and / or programmable units, such as programmable gate arrays or processors.

[0063] Computer system 700 may implement the techniques described herein using custom hard-wired logic, one or more ASICs or FPGAs, firmware, and / or program logic that, in combination with the computer system, makes or programs computer system 700 into a special-purpose machine. According to one embodiment, the techniques described herein are performed by computer system 700 in response to processor(s) 704 executing one or more sequences of one or more instructions contained in main memory 706. Such instructions may be read into main memory 706 from another storage medium, such as storage device 710. Execution of the instruction sequences contained in main memory 706 causes processor(s) 704 to perform the process steps described herein.In alternative embodiments, hard-wired circuits may be used instead of or in combination with software instructions.

[0064] As used herein, a circuit may be implemented in any form of hardware, software, or a combination thereof. For example, one or more processors, controllers, ASICs, PLAs, PALs, CPLDs, FPGAs, logic components, software routines, or other mechanisms may be implemented to form a circuit. In implementation, the various circuits described herein may be implemented as discrete circuits, or the described functions and features may be distributed, in part or in whole, among one or more circuits.Although various features or functional elements are individually described or claimed as separate circuits, these features and functions may be shared by one or more common circuits, and such description is not intended to assume or imply that separate circuits are required to implement these features or functions. If a circuit is implemented in whole or in part with software, that software may be implemented to operate with a computer or processing system capable of performing the described functionality, such as computer system 700.

[0065] As used herein, the term "or" can be interpreted both inclusively and exclusively. Furthermore, descriptions of resources, acts, or structures in the singular should not be construed as excluding the plural. Conditional expressions such as "may," "could," "might," or "may," unless expressly stated otherwise or understood by context, are generally intended to convey that certain embodiments include certain features, elements, and / or steps, while other embodiments do not.

[0066] Unless expressly stated otherwise, the terms and expressions used in this document, as well as their variations, are not to be interpreted as limiting but as open-ended. Adjectives such as "conventional," "traditional," "normal," "standard," "known," and terms of similar import are not to be construed as limiting the subject matter described to a particular period of time or to a subject matter available at a particular time, but should be understood to include conventional, traditional, normal, or standard technologies that may be available or known now or at any time in the future.The presence of broader words and phrases such as “one or more,” “at least,” “but not limited to,” or similar phrases in some cases should not be construed as meaning that the narrower case is intended or required in the absence of such broader phrases.

Claims

[1] A procedure comprising the following: Initiating an Internet Protocol Security (IPsec) session by an IPsec network device (106A-106C, 146, 210, 310, 410); Determine, via the IPsec network device, whether a resource limit for a hardware-based IPsec accelerator (190, 212, 312, 490) has been reached, with the hardware-based IPsec accelerator enabled on the IPsec network device; and In response to the detection that the resource limit for the hardware-based IPsec accelerator has been reached, the IPsec network device offloads the processing for the IPsec Security Association (SA) associated with the initiated IPsec session to a software-based IPsec accelerator (191, 211, 311, 491), with the software-based IPsec accelerator enabled on the IPsec network device. wherein shifting the processing for the IPsec SA to the software-based IPsec accelerator includes setting up an IPsec tunnel (197, 220a-220c, 230a-230c, 320a, 320b, 330a, 330b, 420a, 420b, 430a, 430b, 520a-520d) between the IPsec network device and a controller (104, 196A, 196B, 240A-240F, 340A-340D, 440A, 440B, 540a-540d) of a multi-controller system using the software-based IPsec accelerator, and the determination of whether the resource limit for the hardware-based IPsec accelerator has been reached includes: Determine the current number of IPsec tunnels established by the hardware-based IPsec accelerator; Comparing the current number of IPsec tunnels with the maximum number of IPsec tunnels according to the resource limit of the hardware-based IPsec accelerator; and In response to the finding that the current number of IPsec tunnels has reached or exceeded the maximum number of IPsec tunnels, determine that the resource limit for the hardware-based IPsec accelerator has been reached. [2] A system that includes the following; a plurality of controllers (104, 196A, 196B, 240A-240F, 340A-340D, 440A, 440B, 540a-540d); a communication network (120); An Internet Protocol Security (IPsec) network device (106A-106C, 146, 210, 310, 410) that communicates with the majority of controllers via the communication network and includes a machine-readable storage medium (601, 706, 708, 710) containing instructions that can be executed by the IPsec network device to: Initiating an Internet Protocol Security (IPsec) session for a first controller from a plurality of controllers; Determine whether a resource limit has been reached for a hardware-based IPsec accelerator (190, 212, 312, 490); and In response to the finding that the limit for the hardware-based IPsec accelerator has been reached, an initial IPsec SA is set up for the first controller according to the initiated IPsec session using a software-based IPsec accelerator (191, 211, 311, 491); in response to the finding that the resource limit for the hardware-based IPsec accelerator had been reached and that the initiated IPsec session is associated with a first controller that has a high IPsec priority, Identifying a second controller from the plurality of controllers that is associated with a low IPsec priority, wherein a hardware-based IPsec accelerator has established an initial IPsec security association (SA) corresponding to the second controller, including an initial IPsec tunnel to the second controller, Setting up a secondary IPsec SA for the second controller, including a secondary IPsec tunnel (430b) to the second controller, using the software-based IPsec accelerator, Forwarding traffic corresponding to the second controller using the secondary IPsec tunnel to the second controller and Disconnecting the initial IPsec tunnel to the second controller. [3] The system according to claim 2, wherein the instructions include those that can be executed by the IPsec network device to: Setting up a secondary IPsec SA for the first controller using the hardware-based IPsec accelerator. [4] The system according to claim 3, wherein the instructions include those that can be executed by the IPsec network device to: Establishing a secondary IPsec tunnel to the first controller, corresponding to the secondary IPsec SA, through the hardware-based IPsec accelerator. [5] The system according to claim 4, wherein the instructions include those that can be executed by the IPsec network device to: Disconnecting the initial IPsec tunnel to the first controller and Forwarding the traffic corresponding to the initial IPsec session via the secondary IPsec tunnel to the first controller. [6] The system according to claim 2, wherein an IPsec priority associated with the controller corresponding to the first IPsec session is set from a low IPsec priority to a high IPsec priority. [7] The system according to claim 2, wherein the IPsec network device comprises an access point (AP). [8] The system according to claim 7, wherein the hardware-based IPsec accelerator and the software-based IPsec accelerator are enabled on the AP. [9] The system according to claim 2, wherein the instructions for determining whether the resource limit for the hardware-based IPsec accelerator has been reached include instructions for: Determine the current number of IPsec tunnels (197, 220a-220c, 230a-230c, 320a, 320b, 330a, 330b, 420a, 420b, 430a, 430b, 520a-520d) established by the hardware-based IPsec accelerator; Comparing the current number of IPsec tunnels with a maximum number of IPsec tunnels according to the resource limit of the hardware-based IPsec accelerator; and in response to the finding that the current number of IPsec tunnels has reached or exceeded the maximum number of IPsec tunnels, determining that the resource limit for the hardware-based IPsec accelerator has been reached. [10] A non-transitory computer-readable storage medium (601, 706, 708, 710) containing instructions that can be executed by a processor (602, 704) of an Internet Protocol Security (IPsec) network device (106A-106C, 146, 210, 310, 410) for: Initiating an IPsec session; Determine if a resource limit has been reached for a hardware-based IPsec accelerator (190, 212, 312, 490); Identifying an IPsec priority associated with a controller (104, 196A, 196B, 240A-240F, 340A-340D, 440A, 440B, 540a-540d) of an IPsec tunnel (197, 220a-220c, 230a-230c, 320a, 320b, 330a, 330b, 420a, 420b, 430a, 430b, 520a-520d); and In response to the finding that the IPsec priority associated with the controller is low and that the resource limit for the hardware-based IPsec accelerator has not been reached: Offloading the processing for an IPsec Security Association (SA) associated with the initiated IPsec session to the hardware-based IPsec accelerator; and in response to the finding that the resource limit for the hardware-based IPsec accelerator had been reached, Shifting the processing for the IPsec SA associated with the initiated IPsec session to a software-based IPsec accelerator (191, 211, 311, 491); where shifting the processing for the IPsec SA to the software-based IPsec accelerator involves setting up an IPsec tunnel between the IPsec network device and a controller of a multi-controller system using the software-based IPsec accelerator. [11] The non-transitory computer-readable storage medium according to claim 10, wherein the instructions include those that can be executed by the processor of the IPsec network device to: In response to the finding that the IPsec priority associated with the controller is high and the resource limit for the hardware-based IPsec accelerator has not been reached: Offloading the processing for the IPsec SA associated with the initiated IPsec session to the hardware-based IPsec accelerator. [12] The non-transitory computer-readable storage medium according to claim 11, wherein the transfer of processing for the IPsec SA to the hardware-based IPsec accelerator comprises establishing an IPsec tunnel between the IPsec network device and a controller of a multi-controller system using the hardware-based IPsec accelerator. [13] The non-transitory computer-readable storage medium according to claim 10, wherein the IPsec priority is determined by the IPsec network device based on at least one of the following: a quantity of traffic associated with the controller for the IPsec session, the type of traffic, and the quality of service (QoS). [14] The non-transitory computer-readable storage medium according to claim 10, wherein the IPsec priority is assigned to the controller of the multi-controller system. [15] The non-transient computer-readable storage medium according to claim 10, wherein: the controller is one of a plurality of controllers of a cluster (350a-350d) of controllers in the multi-controller system and The IPsec priority is assigned to the cluster that includes the controller. [16] The non-transitory computer-readable storage medium according to claim 10, wherein the instructions for determining whether the resource limit for the hardware-based IPsec accelerator has been reached comprise instructions for the following: Determine the current number of IPsec tunnels established by the hardware-based IPsec accelerator; Comparing the current number of IPsec tunnels with the maximum number of IPsec tunnels according to the resource limit of the hardware-based IPsec accelerator; and In response to the finding that the current number of IPsec tunnels has reached or exceeded the maximum number of IPsec tunnels, determine that the resource limit for the hardware-based IPsec accelerator has been reached.

Citation Information

Patent Citations

  • Controlling ipsec offload enablement during hardware failures

    US20130124930A1

  • Service processing switch

    US20160197836A1