IKE Node Dynamic Cryptographic Module Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud service delivery systems lack a mechanism to dynamically map customer requirements to specific VPN services, leading to increased operational costs and complexity due to the need for different IKE processing nodes and VPN devices to support varied IKE policies and services, and there is no efficient way to offload IPsec VPN services from private to public clouds during peak times.
Innovation Solution
A system that uses a single IKE processing node to dynamically map subscribers to appropriate cryptographic modules that support requested cloud capabilities, allowing for secure and prioritized cloud service delivery by offloading VPN tunnels to modules capable of handling specific encryption and quality of service requirements, and enabling transparent offloading of IPsec VPN services from private to public clouds during peak times.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple IKE processing nodes and VPN devices are used to support varied IKE policies and services, then service coverage and capability are improved, but device complexity and operational complexity increase
Solution Approach 1:
The patent implements a universal IKE processing node that can dynamically adapt to handle multiple IKE policies and service types through software-based cryptographic module selection, eliminating the need for dedicated hardware for each service type while maintaining full service coverage
Solution Approach 2:
The system employs dynamic mapping mechanisms that allow the IKE processing node to flexibly assign cryptographic modules based on real-time service requirements, enabling the system to adapt to varying IKE policies and service demands without reconfiguring hardware architecture
2Reliability
If cryptographic processing is handled by dedicated hardware modules, then processing reliability and security are improved, but system flexibility and scalability during peak times deteriorate
Solution Approach 1:
The patent segments cryptographic processing functions into separate, independently selectable modules that can be dynamically assigned to the IKE processing node, allowing the system to maintain reliable cryptographic processing while flexibly scaling capacity by adding or removing modules as needed
Solution Approach 2:
The IKE processing node acts as an intermediary that coordinates between service requirements and cryptographic module capabilities, dynamically selecting appropriate modules for each IKE policy while maintaining processing reliability through standardized interfaces and protocols
3Device complexity
If a single IKE processing node is used to manage diverse cloud capabilities, then device complexity is reduced, but the ability to support varied IKE policies and services may be compromised
Solution Approach 1:
The single IKE processing node employs dynamic module mapping capabilities that allow it to adapt its cryptographic processing configuration in real-time based on the specific IKE policy and service requirements, maintaining full service support while simplifying hardware deployment
Solution Approach 2:
The system changes operational parameters by selecting different cryptographic modules for different service scenarios, allowing a single hardware platform to support diverse IKE policies and services through software-based configuration rather than hardware variation
Data Source
AI summary
An example method includes receiving a request for a cloud capability set during an Internet Key Exchange negotiation associated with a virtual private network (VPN) tunnel between a subscriber and a cloud, wherein the cloud capability set comprises one or more cloud capabilities, mapping the request to one or more cryptographic modules that can support the cloud capability set, and offloading the VPN tunnel to the one or more cryptographic modules. The request can be an Internet Security Association and Key Management Protocol (ISAKMP) packet listing the one or more cloud capabilities in a private payload. The method may further include splitting the VPN tunnel between the cryptographic modules if no single cryptographic module can support substantially all the cloud capabilities in the cloud capability set. In some embodiments, the request is compared with a service catalog comprising authorized cloud capabilities.


