Adaptive Security Association Assignment in Redundant Gateways
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In redundant gateway configurations, coordinating sequence numbers for encrypted packets across network gateways is complex, leading to increased overhead and inefficiencies, particularly in thwarting replay attacks, due to the need for inter-gateway communication and managing active and standby SA instances.
Innovation Solution
Implementing an adaptive assignment method for active security association (SA) instances, where individual SA instances can be dynamically designated as active or standby based on traffic load and processor utilization, allowing multiple gateways to collaborate and distribute the load, thereby reducing inter-gateway forwarding and enhancing reliability and performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If redundant gateway configuration is used to increase reliability and performance, then system availability is improved, but inter-gateway communication overhead increases
Solution Approach 1:
The patent segments the security association management by introducing the concept of active and standby SA instances across multiple gateways. Each gateway maintains specific SA instances in active or standby state, dividing the overall security management task among multiple nodes rather than requiring all gateways to coordinate all SA instances, thus reducing communication overhead while maintaining reliability
Solution Approach 2:
Instead of having each gateway independently manage its own SA instances and coordinate with peers, the patent inverts the approach by designating specific gateways as active or standby for specific SA instances. This role assignment reduces the need for continuous inter-gateway coordination, as the standby gateway simply waits to be activated rather than continuously communicating sequence number status
2Object-affected harmful factors
If sequence numbers are coordinated across redundant gateways to thwart replay attacks, then security is improved, but device complexity increases
Solution Approach 1:
The patent extracts the sequence number management responsibility from the gateway coordination layer and places it at the SA instance level. The active SA instance gateway is solely responsible for sequence number generation and management, while standby gateways simply forward packets without needing to track sequence numbers, thereby reducing device complexity while maintaining security
Solution Approach 2:
The patent introduces the active SA instance as an intermediary between the standby gateway and the external network. The standby gateway forwards packets to the active SA instance gateway, which then handles sequence number assignment and replay attack detection. This intermediary approach allows security functionality to be maintained without requiring complex peer-to-peer coordination between gateways
3Productivity
If multiple gateways share SA instances, then load balancing is improved, but inter-gateway forwarding requirements increase
Solution Approach 1:
The patent implements dynamic role assignment where gateways can transition between active and standby states for specific SA instances based on load conditions. This dynamic adjustment allows the system to optimize for load balancing while minimizing forwarding requirements, as the active gateway is typically co-located with the gateway receiving the incoming traffic, reducing or eliminating inter-gateway forwarding needs
Data Source
AI summary
According to one aspect, the subject matter described herein includes a method for communicating an encrypted data packet. The method includes steps occurring at a first gateway node. The method also includes receiving a data packet from a first host. The method further includes determining that a first security association (SA) instance associated with the data packet is in an inactive state. The method further includes identifying a second SA instance that is both associated with the data packet and in an active state. The method further includes forwarding the data packet to the second SA instance.


