High-Bandwidth Encryption Engines Using 64-Bit PNs for VxLAN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption solutions for high-bandwidth VxLAN tunnels in datacenter networks face challenges due to rapid exhaustion of 32-bit packet numbers (PNs) used for generating per-packet initialization vectors, leading to frequent security association key rekeying and data packet recovery failures in multipathing IP networks.
Innovation Solution
Implementing a full 64-bit PN for generating per-packet unique initialization vectors in encryption and decryption engines at spine switches, ensuring secure and efficient encryption and decryption processes within VxLAN tunnels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If 32-bit PN is used for generating per-packet IV in high-speed VxLAN tunnels, then encryption performance is maintained, but PN exhaustion occurs quickly requiring frequent rekeying
Solution Approach 1:
The patent changes the parameter from 32-bit PN to 64-bit PN, thereby extending the PN exhaustion time from seconds to years while maintaining encryption performance. This parameter change directly addresses the contradiction by increasing the duration of action without sacrificing productivity.
2Productivity
If 32-bit PN is used for per-packet IV generation, then hardware encryption engines can process packets efficiently, but data packet recovery fails in multipathing IP networks
Solution Approach 1:
The patent changes the PN width from 32-bit to 64-bit, which resolves the data packet recovery failure issue in multipathing IP networks while maintaining hardware encryption engine efficiency. The extended PN space ensures unique IV generation across multiple paths.
3Reliability
If control plane performs frequent rekey and key distribution across multiple datacenter sites, then PN exhaustion is addressed, but software control plane cannot keep up with very short intervals
Solution Approach 1:
The patent changes the PN duration from seconds to years, which eliminates the need for frequent control plane rekeying operations. This parameter change reduces the control plane processing load while maintaining security association reliability.
Data Source
AI summary
Techniques for generating a per-packet initialization vector for high bandwidth encryption engines in a multipathing IP network are described herein. In examples, a network switch of a first datacenter site may receive a data packet to be sent to a second datacenter site over a network. The data packet may be encrypted according to a virtual extensible LAN (VxLAN) protocol and to be transmitted in a VxLAN tunnel created for the first datacenter site and the second datacenter site. An encryption engine implemented at the network switch may generate an initialization vector (IV) for the data packet based on a packet number (PN) associated with the data packet. The encryption engine may use the IV and information associated with a security association (SA) assigned to the packet to encrypt the data packet. In some examples, a full 64-bit PN may be used to compute the IV for the data packet.


