Geneve Header Options Field SPI Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In software-defined networking (SDN) environments, the stripping of IPSec headers from data packets at destination endpoints prevents other modules in the operating system from accessing the Security Parameter Index (SPI) values, which are essential for performing security functionalities, such as policy enforcement by firewalls.
Innovation Solution
The proposed method involves encapsulating data packets using the Geneve encapsulation frame format, storing the SPI value in the options field of the encapsulation header, and further encrypting them using security protocols like ESP, ensuring the SPI value is accessible even after the IPSec header is stripped off.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the IPSec header is stripped from the data packet after decryption, then the decryption function is completed, but the SPI value becomes inaccessible to other modules such as firewalls
Solution Approach 1:
The solution separates the SPI value from the IPSec header by copying it to the Geneve header. This segmentation allows the SPI value to be accessed independently from the header structure, enabling firewall modules to retrieve it even after the IPSec header is stripped for decryption purposes.
Solution Approach 2:
The Geneve header acts as an intermediary structure that carries the SPI value. By placing the SPI in the Geneve header (which has an options field), the system creates a mediator that preserves the SPI value through the decryption process and makes it accessible to multiple modules including firewalls, without requiring the original IPSec header to remain intact.
2Ease of operation
If the SPI value is stored only in the IPSec header, then the header structure is simple, but other modules cannot access the SPI value after header stripping
Solution Approach 1:
The Geneve header's options field is utilized for a dual purpose: its standard function and as a carrier for the SPI value. This multi-functionality allows the same data structure to serve both its original encapsulation purpose and the additional function of preserving security parameter information for firewall access.
Data Source
AI summary
Certain embodiments described herein are generally directed to a first host machine exchanging a Security Parameter Index (SPI) value with a second host machine by storing the SPI in an options field of an encapsulation header of an encapsulated packet.


