GET VPN Key Server SA Policy Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Group Encrypted Transport Virtual Private Network (GET VPN) systems face compatibility and scalability issues due to the need for all Group Members (GMs) to support new encryption or authentication algorithms, leading to registration failures when GMs in different areas have varying capabilities, especially when algorithms like AES256 are not supported.
Innovation Solution
The Key Server (KS) in the GET VPN system sends a Security Association (SA) policy based on the capability of each GM, allowing GMs to register successfully by matching their supported algorithms with the KS's policy list, eliminating the need for all GMs to upgrade to new algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the KS requires all GMs to support new encryption or authentication algorithms, then security policy management is centralized and standardized, but compatibility and scalability deteriorate when GMs in different areas have varying capabilities
Solution Approach 1:
The patent applies local quality by allowing different GMs to have different capability profiles (supported algorithms) while the KS maintains centralized policy management. Each GM's registration includes its supported algorithms, and the KS matches GMs with appropriate groups based on their specific capabilities rather than requiring uniform support for all algorithms across all GMs.
Solution Approach 2:
The patent changes the parameter of algorithm support from a binary (supported/not supported) to a configurable list of supported algorithms for each GM. The KS stores multiple SA policies with different algorithm requirements and selects the appropriate policy based on the GM's capability parameters, enabling flexible matching without requiring all GMs to upgrade to the latest algorithms.
2Reliability
If the KS requires all GMs to upgrade to new algorithms, then security is improved, but device complexity and upgrade overhead increase
Solution Approach 1:
The patent applies partial action by allowing GMs to support only a subset of available algorithms. Not all GMs need to support all algorithms - each GM supports what it needs, and the KS matches them with appropriate SA policies. This avoids the excessive requirement of universal algorithm support while maintaining security through appropriate policy selection.
Solution Approach 2:
The patent introduces dynamics by making the SA policy selection adaptive to each GM's capabilities. The KS dynamically selects which SA policy to apply based on the GM's supported algorithms rather than enforcing a static, uniform policy. This allows the system to adapt to different GM capabilities without requiring upgrades.
3Ease of operation
If the KS uses a fixed SA policy for all groups, then policy management is simplified, but adaptability to different GM capabilities is reduced
Solution Approach 1:
The patent segments the SA policy into multiple policy options, each with different algorithm requirements. Instead of one fixed policy, the KS maintains a set of segmented policies that can be matched to different GM capabilities. This segmentation allows simplified management of individual policies while providing adaptability through policy selection.
Solution Approach 2:
The KS serves multiple functions: it acts as a policy repository, a capability assessor, and a policy selector. By storing multiple SA policies with different characteristics, the KS can universally serve GMs with varying capabilities through appropriate policy matching, combining simplicity of centralized management with adaptability to diverse requirements.
Data Source
AI summary
An example of the present disclosure includes a Group Member (GM) registering on a Key Server (KS) in a Group Encrypted Transport Virtual Private Network (GET VPN). The KS is to manage at least one group, and GMs belonging to the same group have the same group ID. The KS receives a group ID and a Security Association, SA, policy list supported by a GM sent by the GM. The KS, according to the group ID, determines a KS SA policy list corresponding to the group, and matches the SA policy list supported by the GM with the KS SA policy list according to a priority. A group SA policy with the highest priority is sent the GM.


