Decentralized IPSec Key Negotiation Across IKE Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Internet Protocol Security (IPsec) environments face scaling limitations due to single-host rekeying processes for IKE and ESP security associations, which restrict distribution and cloud-native scalability.

Innovation Solution

Decentralized rekeying processes are implemented across multiple IKE nodes, utilizing a key value store to distribute and manage IPSec sessions, allowing any IKE node to initiate and complete rekeying events, thus enabling horizontal scaling and treating IKE nodes as 'cattle' rather than 'pets'.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single host performs rekeying for IKE and ESP security associations, then security key negotiation is simplified and centralized, but scaling is limited and the system cannot distribute rekeying across multiple nodes

Engineering Contradiction:
Improverekeying process complexityVSAvoidscaling capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the rekeying process into separate components that can be distributed across multiple IKE nodes. Instead of a single host handling all rekeying operations, the system divides rekeying responsibilities among multiple nodes, allowing each node to independently perform rekeying for specific security associations. This segmentation enables horizontal scaling while maintaining the security benefits of centralized key management.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If rekeying is centralized on a single host, then key management is simplified, but the system experiences scaling limitations and cannot treat IKE nodes as interchangeable units

Engineering Contradiction:
Improvekey management simplicityVSAvoidsystem scalability
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent makes IKE nodes universal by enabling any node to perform rekeying operations for any security association. Instead of dedicating specific nodes to specific rekeying tasks, the system allows any IKE node to take over rekeying responsibilities dynamically. This multi-functionality enables nodes to be treated as interchangeable units (cattle rather than pets) while maintaining simplified key management through standardized protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a single host handles all rekeying operations, then session continuity is maintained through centralized control, but the system cannot dynamically distribute rekeying events across multiple nodes

Engineering Contradiction:
Improvesession continuityVSAvoidrekeying flexibility
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent introduces dynamic behavior to the rekeying process by allowing the system to adaptively select which IKE node performs rekeying operations based on current system state and load conditions. Instead of static assignment where a single host always handles rekeying, the system dynamically distributes rekeying events across multiple nodes while maintaining session continuity through coordinated key exchange protocols and state synchronization.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250330312A1Decentralized internet protocol security key negotiation
Publication Date: 2025.10.23 CISCO TECHNOLOGY INC
  • US20250330312A1 patent drawing
  • US20250330312A1 patent drawing
  • US20250330312A1 patent drawing

AI summary

Methods are provided for decentralized key negotiation. One method includes initiating, by a first Internet Key Exchange (IKE) node from among a plurality of IKE nodes, a rekeying process for an Internet Protocol Security (IPSec) communication session established with a client device and serviced by a second IKE node from among the plurality of IKE nodes, and in which a first encryption key is used to encrypt traffic. The method further includes obtaining, by the first IKE node from a key value store, information about the IPSec communication session and performing, by the first IKE node, at least a part of the rekeying process in which the first encryption key is replaced with a second encryption key for the IPSec communication session.