Seamless Switchover for Anti-Replay Connections in Network Processors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IPSec connections are vulnerable to replay attacks, where malicious users can intercept and replay encrypted packets, leading to authentication issues due to the need for re-keying and sequence number verification, which can result in packet discards during switchover processes.
Innovation Solution
A method for network devices to perform seamless switchover of anti-replay connections by presetting a sequence number in a second network processor to a value greater than or equal to the re-key threshold, ensuring that packets are not discarded during switchover and triggering re-keying when necessary, thereby maintaining connection security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sequence number verification is performed to prevent replay attacks, then connection security is improved, but packet discards occur during switchover processes
Solution Approach 1:
The patent applies preliminary action by presetting the sequence number in the second network processor to a value greater than or equal to the re-key threshold value before the switchover occurs. This advance preparation ensures that when the second network processor takes over, the sequence number is already in a valid state that will not trigger packet discards, thus maintaining both security and continuity during the transition.
2Reliability
If re-keying is triggered by sequence number threshold to maintain security, then anti-replay protection is improved, but connection continuity is disrupted
Solution Approach 1:
The patent performs the re-keying operation in advance by presetting the sequence number to a value that is greater than or equal to the re-key threshold. This causes the re-keying to be triggered proactively before the switchover, ensuring that the new security parameters are ready and the connection can continue uninterrupted after the transition.
Solution Approach 2:
The patent skips the security validation check that would normally cause packet discards by ensuring the preset sequence number is already beyond the re-key threshold. This allows the switchover to proceed without triggering the anti-replay discard mechanism, effectively rushing through the critical transition period.
3Reliability
If sequence number is reset during switchover to maintain security state, then security integrity is improved, but packet loss occurs
Solution Approach 1:
The patent applies preliminary action by presetting the sequence number in the second network processor before switchover occurs. This advance configuration ensures that the sequence number continuity is maintained across the transition, preventing packet loss while still allowing security state management through controlled re-keying.
Data Source
AI summary
Various exemplary embodiments relate to a method, network node, and non-transitory machine-readable storage medium including one or more of the following: receiving, at the network device, an ownership indication that a first network processor is currently serving an anti-replay connection; and in response to receiving the ownership indication, effecting a presetting in a second network processor of a current sequence number (SN) for the anti-replay connection to a first value that is greater than or equal to a re-key threshold value, wherein the network device includes at least one of the first network processor and the second network processor wherein the re-key threshold value is a value beyond which an SN triggers re-keying of the anti-replay connection, and wherein the second network processor utilizes the current sequence number upon beginning to serve the anti-replay connection.


