High-Bandwidth Encryption Engines Using 64-Bit PNs for VxLAN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encryption solutions for high-bandwidth VxLAN tunnels in datacenter networks face challenges due to rapid exhaustion of 32-bit packet numbers (PNs) used for generating per-packet initialization vectors, leading to frequent security association key rekeying and data packet recovery failures in multipathing IP networks.

Innovation Solution

Implementing a full 64-bit PN for generating per-packet unique initialization vectors in encryption and decryption engines at spine switches, ensuring secure and efficient encryption and decryption processes within VxLAN tunnels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If 32-bit PN is used for generating per-packet IV in high-speed VxLAN tunnels, then encryption performance is maintained, but PN exhaustion occurs quickly requiring frequent rekeying

Engineering Contradiction:
Improveencryption performanceVSAvoidPN exhaustion time
Core Design Contradiction:
ProductivityVSDuration of action of moving object

Solution Approach 1:

The patent changes the parameter from 32-bit PN to 64-bit PN, thereby extending the PN exhaustion time from seconds to years while maintaining encryption performance. This parameter change directly addresses the contradiction by increasing the duration of action without sacrificing productivity.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If 32-bit PN is used for per-packet IV generation, then hardware encryption engines can process packets efficiently, but data packet recovery fails in multipathing IP networks

Engineering Contradiction:
Improvepacket processing efficiencyVSAvoiddata packet recovery
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent changes the PN width from 32-bit to 64-bit, which resolves the data packet recovery failure issue in multipathing IP networks while maintaining hardware encryption engine efficiency. The extended PN space ensures unique IV generation across multiple paths.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If control plane performs frequent rekey and key distribution across multiple datacenter sites, then PN exhaustion is addressed, but software control plane cannot keep up with very short intervals

Engineering Contradiction:
Improvesecurity association maintenanceVSAvoidcontrol plane processing load
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the PN duration from seconds to years, which eliminates the need for frequent control plane rekeying operations. This parameter change reduces the control plane processing load while maintaining security association reliability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250310310A1High bandwidth encryption engines in a multipathing IP network
Publication Date: 2025.10.02 CISCO TECHNOLOGY INC
  • US20250310310A1 patent drawing
  • US20250310310A1 patent drawing
  • US20250310310A1 patent drawing

AI summary

Techniques for generating a per-packet initialization vector for high bandwidth encryption engines in a multipathing IP network are described herein. In examples, a network switch of a first datacenter site may receive a data packet to be sent to a second datacenter site over a network. The data packet may be encrypted according to a virtual extensible LAN (VxLAN) protocol and to be transmitted in a VxLAN tunnel created for the first datacenter site and the second datacenter site. An encryption engine implemented at the network switch may generate an initialization vector (IV) for the data packet based on a packet number (PN) associated with the data packet. The encryption engine may use the IV and information associated with a security association (SA) assigned to the packet to encrypt the data packet. In some examples, a full 64-bit PN may be used to compute the IV for the data packet.