IKE Node Dynamic Cryptographic Module Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud service delivery systems lack a mechanism to dynamically map customer requirements to specific VPN services, leading to increased operational costs and complexity due to the need for different IKE processing nodes and VPN devices to support varied IKE policies and services, and there is no efficient way to offload IPsec VPN services from private to public clouds during peak times.

Innovation Solution

A system that uses a single IKE processing node to dynamically map subscribers to appropriate cryptographic modules that support requested cloud capabilities, allowing for secure and prioritized cloud service delivery by offloading VPN tunnels to modules capable of handling specific encryption and quality of service requirements, and enabling transparent offloading of IPsec VPN services from private to public clouds during peak times.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple IKE processing nodes and VPN devices are used to support varied IKE policies and services, then service coverage and capability are improved, but device complexity and operational complexity increase

Engineering Contradiction:
Improveservice coverageVSAvoidoperational complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal IKE processing node that can dynamically adapt to handle multiple IKE policies and service types through software-based cryptographic module selection, eliminating the need for dedicated hardware for each service type while maintaining full service coverage

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs dynamic mapping mechanisms that allow the IKE processing node to flexibly assign cryptographic modules based on real-time service requirements, enabling the system to adapt to varying IKE policies and service demands without reconfiguring hardware architecture

Inventive Principle:
Principle #15Dynamics

2Reliability

If cryptographic processing is handled by dedicated hardware modules, then processing reliability and security are improved, but system flexibility and scalability during peak times deteriorate

Engineering Contradiction:
Improveprocessing reliabilityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments cryptographic processing functions into separate, independently selectable modules that can be dynamically assigned to the IKE processing node, allowing the system to maintain reliable cryptographic processing while flexibly scaling capacity by adding or removing modules as needed

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The IKE processing node acts as an intermediary that coordinates between service requirements and cryptographic module capabilities, dynamically selecting appropriate modules for each IKE policy while maintaining processing reliability through standardized interfaces and protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If a single IKE processing node is used to manage diverse cloud capabilities, then device complexity is reduced, but the ability to support varied IKE policies and services may be compromised

Engineering Contradiction:
Improvedeployment simplicityVSAvoidservice support capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The single IKE processing node employs dynamic module mapping capabilities that allow it to adapt its cryptographic processing configuration in real-time based on the specific IKE policy and service requirements, maintaining full service support while simplifying hardware deployment

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters by selecting different cryptographic modules for different service scenarios, allowing a single hardware platform to support diverse IKE policies and services through software-based configuration rather than hardware variation

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8862883B2System and method for secure cloud service delivery with prioritized services in a network environment
Publication Date: 2014.10.14 CISCO TECHNOLOGY INC
  • US8862883B2 patent drawing
  • US8862883B2 patent drawing
  • US8862883B2 patent drawing

AI summary

An example method includes receiving a request for a cloud capability set during an Internet Key Exchange negotiation associated with a virtual private network (VPN) tunnel between a subscriber and a cloud, wherein the cloud capability set comprises one or more cloud capabilities, mapping the request to one or more cryptographic modules that can support the cloud capability set, and offloading the VPN tunnel to the one or more cryptographic modules. The request can be an Internet Security Association and Key Management Protocol (ISAKMP) packet listing the one or more cloud capabilities in a private payload. The method may further include splitting the VPN tunnel between the cryptographic modules if no single cryptographic module can support substantially all the cloud capabilities in the cloud capability set. In some embodiments, the request is compared with a service catalog comprising authorized cloud capabilities.