Flow-Based Secure Forwarding with Token-Validated Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security in Software-Defined Networking (SDN) environments is susceptible to security attacks due to inadequate packet forwarding mechanisms, particularly in complex distributed applications spanning multiple networks with shared services, where conventional VPN endpoint authentication is insufficient for secure segmentation.
Innovation Solution
Implement flow-based secure packet forwarding by assessing the validity of security tokens associated with packet flows and negotiating dedicated security associations (SAs) for each flow, enhancing encryption and encapsulation to ensure secure communication between endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional VPN endpoint authentication is used, then device complexity is reduced, but network security is insufficient and susceptible to attacks
Solution Approach 1:
The patent segments network security into flow-level security associations (SAs) rather than relying solely on endpoint authentication. Each packet flow establishes its own SA with the network function, dividing the security management into granular flow-based units that can be independently managed and secured.
Solution Approach 2:
The patent introduces security tokens as intermediary elements that mediate between packet flows and the network function. These tokens enable authentication and authorization at the flow level without requiring complex endpoint authentication mechanisms, thereby improving security while managing complexity through token-based intermediaries.
2Reliability
If flow-based security associations are negotiated for each packet flow, then network security is improved through secure segmentation, but device complexity increases due to dynamic security policy management
Solution Approach 1:
The patent implements self-service mechanisms where packet flows automatically negotiate security associations with the network function using flow identifiers and security tokens. This automated negotiation eliminates manual security policy configuration, reducing operational complexity while maintaining robust flow-level security segmentation.
Solution Approach 2:
The patent changes the security management parameters from static endpoint-based policies to dynamic flow-based parameters. By using flow identifiers, security tokens, and automated SA negotiation, the system adapts security policies to individual packet flows, improving secure segmentation while managing complexity through parameterization rather than manual configuration.
3Reliability
If encryption and encapsulation are performed for each packet flow, then packet communication security is enhanced, but processing time increases
Solution Approach 1:
The patent performs security association negotiation and encryption key preparation in advance before packet processing. By establishing SAs and obtaining security tokens beforehand, the actual packet encryption and encapsulation operations are accelerated, reducing processing time while maintaining enhanced packet communication security through pre-negotiated security parameters.
Data Source
AI summary
Example methods and systems for flow-based secure packet forwarding are described. In one example, a first computer system may assess validity of a security token associated with a flow of one or more packets. In response to determination that the security token is valid, a security association associated with the flow and the security token may be negotiated with a second computer system. The first computer system may process a packet associated with the flow and the security token to generate an encapsulated encrypted packet by performing encryption and encapsulation based on the security association. The encapsulated encrypted packet may be forwarded towards the second computer system to cause the second computer system to perform decapsulation and decryption, and to forward a decapsulated and decrypted packet towards the destination.


