Flow-Based Secure Forwarding with Token-Validated Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security in Software-Defined Networking (SDN) environments is susceptible to security attacks due to inadequate packet forwarding mechanisms, particularly in complex distributed applications spanning multiple networks with shared services, where conventional VPN endpoint authentication is insufficient for secure segmentation.

Innovation Solution

Implement flow-based secure packet forwarding by assessing the validity of security tokens associated with packet flows and negotiating dedicated security associations (SAs) for each flow, enhancing encryption and encapsulation to ensure secure communication between endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional VPN endpoint authentication is used, then device complexity is reduced, but network security is insufficient and susceptible to attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidpacket forwarding mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments network security into flow-level security associations (SAs) rather than relying solely on endpoint authentication. Each packet flow establishes its own SA with the network function, dividing the security management into granular flow-based units that can be independently managed and secured.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security tokens as intermediary elements that mediate between packet flows and the network function. These tokens enable authentication and authorization at the flow level without requiring complex endpoint authentication mechanisms, thereby improving security while managing complexity through token-based intermediaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If flow-based security associations are negotiated for each packet flow, then network security is improved through secure segmentation, but device complexity increases due to dynamic security policy management

Engineering Contradiction:
Improvesecure segmentationVSAvoidsecurity policy management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where packet flows automatically negotiate security associations with the network function using flow identifiers and security tokens. This automated negotiation eliminates manual security policy configuration, reducing operational complexity while maintaining robust flow-level security segmentation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the security management parameters from static endpoint-based policies to dynamic flow-based parameters. By using flow identifiers, security tokens, and automated SA negotiation, the system adapts security policies to individual packet flows, improving secure segmentation while managing complexity through parameterization rather than manual configuration.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If encryption and encapsulation are performed for each packet flow, then packet communication security is enhanced, but processing time increases

Engineering Contradiction:
Improvepacket communication securityVSAvoidpacket processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs security association negotiation and encryption key preparation in advance before packet processing. By establishing SAs and obtaining security tokens beforehand, the actual packet encryption and encapsulation operations are accelerated, reducing processing time while maintaining enhanced packet communication security through pre-negotiated security parameters.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12432184B2Flow-based secure packet forwarding
Publication Date: 2025.09.30 VMWARE INC
  • US12432184B2 patent drawing
  • US12432184B2 patent drawing
  • US12432184B2 patent drawing

AI summary

Example methods and systems for flow-based secure packet forwarding are described. In one example, a first computer system may assess validity of a security token associated with a flow of one or more packets. In response to determination that the security token is valid, a security association associated with the flow and the security token may be negotiated with a second computer system. The first computer system may process a packet associated with the flow and the security token to generate an encapsulated encrypted packet by performing encryption and encapsulation based on the security association. The encapsulated encrypted packet may be forwarded towards the second computer system to cause the second computer system to perform decapsulation and decryption, and to forward a decapsulated and decrypted packet towards the destination.