Cloud Survivable IPsec Tunnels for SD-WAN Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud connectivity disruptions cause IPsec tunnels to expire, leading to network traffic disruptions due to the loss of secure communication between devices, as existing technologies rely on continuous connectivity to the cloud service for key management and rekeying.

Innovation Solution

Implementing cloud survivability techniques that allow devices to establish survivability tunnels, which are independent of cloud services, using factory-cert authentication and pre-configured tunnel data to maintain secure communication even if cloud connectivity is lost, thereby ensuring continuous operation of IPsec tunnels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud service is used for key management and rekeying, then secure communication can be maintained through centralized control, but network disruptions occur when cloud connectivity is lost

Engineering Contradiction:
Improvesecure communication continuityVSAvoidcloud dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent pre-loads configuration data and cryptographic keys into local storage before cloud connectivity is lost. This preliminary action enables the network device to autonomously establish secure communications without real-time cloud intervention, resolving the contradiction between centralized control and cloud dependency by preparing resources in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the key management functionality into cloud-based orchestration and local execution. The cloud service maintains centralized control for initial setup and policy management, while local devices store configuration data and perform autonomous rekeying operations. This segmentation eliminates cloud dependency for critical operations while preserving centralized security management.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cloud connectivity is required for rekeying, then centralized key management is maintained, but IPsec tunnels expire during cloud outages

Engineering Contradiction:
Improvekey management consistencyVSAvoidtunnel uptime
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The system pre-loads cryptographic keys and configuration data into local storage before they are needed. This allows the network device to perform rekeying operations autonomously during cloud outages, maintaining tunnel uptime while ensuring key management consistency through pre-synchronized data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a local cache of configuration data and keys that acts as a cushion against cloud connectivity disruptions. This cached data provides a buffer that allows the system to maintain secure communications during outages, preventing tunnel expiration while ensuring eventual consistency with the cloud service.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If continuous cloud connection is maintained for IPsec orchestration, then secure communication is ensured, but network disruptions occur during cloud service unavailability

Engineering Contradiction:
Improvecommunication securityVSAvoidcloud independence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments orchestration functions into cloud-based policy management and local autonomous execution. The cloud service provides centralized security policies and initial configuration, while local devices independently manage key storage and rekeying operations. This segmentation enables cloud independence for critical operations while maintaining communication security through centralized policy enforcement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network device is empowered to autonomously perform rekeying operations using locally stored configuration data and cryptographic keys. This self-service capability eliminates the need for continuous cloud connection while maintaining security through pre-synchronized configuration data, providing both security and cloud independence.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11856063B2Systems and methods for cloud survivability for cloud orchestrated internet protocol security (IPsec) security associations (SA)
Publication Date: 2023.12.26 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11856063B2 patent drawing
  • US11856063B2 patent drawing
  • US11856063B2 patent drawing

AI summary

Systems are methods are provided for implementing cloud survivability which mitigates the loss of secure communication via a cloud orchestrated IPsec tunnel, due to a loss of connectivity to a cloud service. For example, devices can establish IPsec tunnels which are orchestrated by a cloud service, such as SD-WAN Tunnel Orchestration. Then, according to the disclosed cloud survivability techniques, if the connection to the cloud service fails, a cloud survivability phase can be triggered which fails-over from IPsec tunnel to a survivability tunnel. In some implementations, a method includes: determining, by an initiator device, whether there is a loss of connectivity of the initiator device or the responder device with a cloud service. Further, in response to determining that there is a loss of connectivity, automatically establishing a survivability communication link between the initiator device and the responder device.