Encryption Device Address Mapping for Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing IPsec tunnel mode separates networks completely, preventing direct address mapping between black and red networks, which hinders simultaneous routing and increases signaling overhead, especially in dynamic wireless environments with limited resources.

Innovation Solution

Implementing a look-up table in encryption devices to map black device identifiers to red network addresses, allowing derivation of red network topology from black network topology, thereby reducing the need for the IPsec discovery protocol and minimizing signaling effort.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tunnel mode is used for encrypted communication, then security and confidentiality are improved, but network architecture complexity and signaling overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a mapping server as an intermediary component that maintains address mapping tables between red network addresses and black network addresses. This intermediary enables the routing function without requiring complex signaling between encryption devices, thus maintaining security while reducing network architecture complexity and signaling overhead.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complete network separation is implemented with tunnel mode, then data security is improved, but routing efficiency deteriorates due to inability to perform direct address mapping

Engineering Contradiction:
Improvedata securityVSAvoidrouting efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the addressing function into two independent parts: red network addresses for secure communication within confidential networks, and black network addresses for routing in the public network. The mapping server maintains separate address mapping tables that enable efficient translation between these segmented address spaces without compromising data security or routing efficiency.

Inventive Principle:
Principle #1Segmentation

3Extent of automation

If IPsec discovery protocol is used to exchange routing information, then automatic routing setup is improved, but signaling overhead and resource consumption increase

Engineering Contradiction:
Improveautomatic routing setupVSAvoidsignaling overhead
Core Design Contradiction:
Extent of automationVSLoss of energy

Solution Approach 1:

The patent implements preliminary action by pre-configuring address mapping tables in the mapping server before communication occurs. This allows routing information to be readily available when needed, eliminating the need for runtime IPsec discovery protocol exchanges and significantly reducing signaling overhead while maintaining automatic routing setup capability.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If encryption devices are shared by multiple end devices, then resource utilization is improved, but address mapping complexity increases

Engineering Contradiction:
Improveresource utilizationVSAvoidaddress mapping complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses copying by maintaining virtual address mapping entries in the mapping server that represent multiple end devices sharing a single encryption device. Each end device has its own red network address that maps to the same black network address (the encryption device's address), allowing the mapping server to manage multiple-to-one mappings efficiently without increasing actual device complexity.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2062400B1Method and system for addressing and routing in encrypted communications links
Publication Date: 2012.11.14 ROHDE & SCHWARZ GMBH & CO KG
  • EP2062400B1 patent drawingFigure 1
  • EP2062400B1 patent drawingFigure 2~3
  • EP2062400B1 patent drawingFigure 4

AI summary

The invention relates to a method and a system (11) for addressing and routing using encrypted communications links (1) in at least two different network layers (2, 3) of a network which are separated from each other by different routing layers. A first network layer (2) with the associated first routing layer is demarcated relative to a second network layer (3) with a second routing layer by means of at least one encryption device (4). In the at least two routing layers, a network topology of both network layers (2, 3) is worked out independently of one another and stored in corresponding routing tables (17). An interface (7) in the at least one encryption device (4) is provided with a unique assignment of addresses (8) of the second routing layer to addresses (8) of the first routing layer, in order to derive the topology of the second network layer (3) from the first network layer (2) efficiently.