Security Parameter Generator for IKE Key Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In complex mesh networks, standard IKE is insufficient for distributing keys to multiple PEPs and cannot detect NAT devices, making it difficult to maintain network security and manage policies effectively.
Innovation Solution
A method and apparatus that configure a remote network to engage in network security negotiation with a local network, using a security component and security parameter generator to establish a secure association and distribute policies and keys, allowing IPsec tunnel traffic to pass through PEPs even when addressed to an IKE device behind them, and supporting NAT traversal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard IKE protocol is used for key distribution, then point-to-point security is achieved, but key distribution to multiple PEPs in complex mesh networks becomes insufficient and management becomes difficult
Solution Approach 1:
The patent introduces an intermediary key distribution mechanism that acts as a mediator between the IKE protocol and multiple PEPs. This intermediary component receives security parameters from the IKE negotiation and distributes them to multiple Policy Enforcement Points, enabling one-to-many key distribution while maintaining the standard IKE interface. This resolves the contradiction by adding an intermediary layer that handles the complexity of multi-PEP key distribution without requiring changes to the standard IKE protocol itself.
2Ease of operation
If data protection managing technology is used to simplify policy management, then key distribution to multiple PEPs is improved, but interface to standard IKE systems and NAT detection capability is lost
Solution Approach 1:
The patent implements a multi-functional security gateway that simultaneously provides data protection management capabilities and standard IKE protocol support. The system is designed to perform multiple functions: it acts as both a data protection manager for simplified policy management and as a standard IKE endpoint for compatibility with legacy systems. Additionally, it incorporates NAT detection capabilities alongside key distribution functions. This universal design resolves the contradiction by enabling a single system to provide both simplified management and broad compatibility without requiring separate specialized systems.
3Reliability
If manual key establishment is used in IPsec, then security is provided, but the number of policies required on each PEP becomes extremely large in highly complex mesh networks
Solution Approach 1:
The patent merges the key distribution function with the existing IKE negotiation process. Instead of treating key establishment as a separate manual process for each PEP pair, the system combines key distribution into the automated IKE protocol flow. A single IKE negotiation can generate security parameters that are then merged and distributed to multiple PEPs simultaneously. This merging approach reduces the number of individual policies required on each PEP from potentially dozens or hundreds to a manageable set of grouped policies, while maintaining the security guarantees of manual key establishment.
Data Source
AI summary
A method for providing network security comprising a step of configuring a remote network to engage network security negotiation with a local network. The method includes a step of configuring a first security policy of a security component within the local network to pass through a network security negotiating communication between the local network and the remote network, and a step of establishing a network security negotiation between the remote network and a security parameter generator via the security component. The security parameter generator can be located within the local network and configured to provide secure communication with the remote network.


