GET VPN Key Server SA Policy Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Group Encrypted Transport Virtual Private Network (GET VPN) systems face compatibility and scalability issues due to the need for all Group Members (GMs) to support new encryption or authentication algorithms, leading to registration failures when GMs in different areas have varying capabilities, especially when algorithms like AES256 are not supported.

Innovation Solution

The Key Server (KS) in the GET VPN system sends a Security Association (SA) policy based on the capability of each GM, allowing GMs to register successfully by matching their supported algorithms with the KS's policy list, eliminating the need for all GMs to upgrade to new algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the KS requires all GMs to support new encryption or authentication algorithms, then security policy management is centralized and standardized, but compatibility and scalability deteriorate when GMs in different areas have varying capabilities

Engineering Contradiction:
Improvesecurity policy managementVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by allowing different GMs to have different capability profiles (supported algorithms) while the KS maintains centralized policy management. Each GM's registration includes its supported algorithms, and the KS matches GMs with appropriate groups based on their specific capabilities rather than requiring uniform support for all algorithms across all GMs.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of algorithm support from a binary (supported/not supported) to a configurable list of supported algorithms for each GM. The KS stores multiple SA policies with different algorithm requirements and selects the appropriate policy based on the GM's capability parameters, enabling flexible matching without requiring all GMs to upgrade to the latest algorithms.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the KS requires all GMs to upgrade to new algorithms, then security is improved, but device complexity and upgrade overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidupgrade overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies partial action by allowing GMs to support only a subset of available algorithms. Not all GMs need to support all algorithms - each GM supports what it needs, and the KS matches them with appropriate SA policies. This avoids the excessive requirement of universal algorithm support while maintaining security through appropriate policy selection.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent introduces dynamics by making the SA policy selection adaptive to each GM's capabilities. The KS dynamically selects which SA policy to apply based on the GM's supported algorithms rather than enforcing a static, uniform policy. This allows the system to adapt to different GM capabilities without requiring upgrades.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If the KS uses a fixed SA policy for all groups, then policy management is simplified, but adaptability to different GM capabilities is reduced

Engineering Contradiction:
Improvepolicy managementVSAvoidcapability matching
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments the SA policy into multiple policy options, each with different algorithm requirements. Instead of one fixed policy, the KS maintains a set of segmented policies that can be matched to different GM capabilities. This segmentation allows simplified management of individual policies while providing adaptability through policy selection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The KS serves multiple functions: it acts as a policy repository, a capability assessor, and a policy selector. By storing multiple SA policies with different characteristics, the KS can universally serve GMs with varying capabilities through appropriate policy matching, combining simplicity of centralized management with adaptability to diverse requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9344434B2GET VPN group member registration
Publication Date: 2016.05.17 UBER TECHNOLOGIES INC
  • US9344434B2 patent drawing
  • US9344434B2 patent drawing
  • US9344434B2 patent drawing

AI summary

An example of the present disclosure includes a Group Member (GM) registering on a Key Server (KS) in a Group Encrypted Transport Virtual Private Network (GET VPN). The KS is to manage at least one group, and GMs belonging to the same group have the same group ID. The KS receives a group ID and a Security Association, SA, policy list supported by a GM sent by the GM. The KS, according to the group ID, determines a KS SA policy list corresponding to the group, and matches the SA policy list supported by the GM with the KS SA policy list according to a priority. A group SA policy with the highest priority is sent the GM.