Group VPN Key Authority Point for Resilient Enterprise Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in securing IP traffic with IPSec, as manual key management is complex, and IKE's connection-oriented nature limits key negotiation in resilient networks, while balancing data protection and availability is difficult due to varying security requirements across different user groups and complex network boundaries.

Innovation Solution

The deployment of Group Virtual Private Networks (VPNs) using a three-layer approach with a Key Authority Point (KAP) generating and distributing encryption keys and security policies, allowing secure partitioning of networks and leveraging existing security infrastructure across different user groups, enabling secure communication over point-to-multipoint and multipoint-to-multipoint networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IKE protocol is used for key negotiation between two PEPs, then security association is established, but connection-oriented nature prevents key negotiation in resilient networks with multiple paths

Engineering Contradiction:
Improvenetwork resilienceVSAvoidkey negotiation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a Key Distribution Center (KDC) as an intermediary that mediates key distribution to multiple Policy Enforcement Points (PEPs). Instead of requiring direct peer-to-peer key negotiation between PEPs, the KDC centrally manages and distributes keys to all PEPs in the security group, enabling resilient multi-path communication without complex pairwise key negotiations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical IKE key negotiation process (which requires direct connection between two PEPs) with a centralized key distribution mechanism. The KDC uses a different approach - distributing keys from a central location to multiple PEPs simultaneously, substituting the peer-to-peer negotiation mechanism with a star-topology distribution system that works naturally with multi-path networks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If different security policies are applied to different user groups, then data protection is improved, but network management complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidnetwork management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal Key Distribution Center (KDC) that serves multiple security groups and multiple PEPs simultaneously. The KDC implements a unified key distribution mechanism that can handle different security groups with different policies through a single centralized system, rather than requiring separate key management systems for each security group, thus reducing overall management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the network into security groups with distinct policies while maintaining centralized management. Each security group can have its own key distribution parameters and policies, but the KDC manages all these segmented groups through a unified interface, allowing fine-grained security segmentation without proportionally increasing management complexity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If manual key management is used in IPSec, then security control is precise, but configuration challenges and re-key requirements increase in large networks

Engineering Contradiction:
Improvesecurity controlVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements an automated key distribution system where the Key Distribution Center (KDC) automatically generates, manages, and distributes keys to Policy Enforcement Points (PEPs) without manual intervention. The system provides self-service key management, automatically handling key generation, distribution, rotation, and revocation, thereby maintaining precise security control while eliminating the configuration challenges and re-key burdens of manual key management in large networks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8607301B2Deploying group VPNS and security groups over an end-to-end enterprise network
Publication Date: 2013.12.10 CERTES NETWORKS INC
  • US8607301B2 patent drawing
  • US8607301B2 patent drawing
  • US8607301B2 patent drawing

AI summary

Group Virtual Private Networks (Group VPNS) are provided for different types of machines in a data processing network. Security groups are defined by a security policy for each member. Security policies and encryption keys are deployed to members of a security group using an IPSec network infrastructure with authentication via VPN mechanisms. The group VPNs provide a trusted IP network that can leverage and co-exist with security access control technologies, such as endpoint security that controls client network access or application security that controls user access to enterprise applications.