IKEv2 Security Association Rekeying Payload Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Internet Key Exchange Version-2 (IKEv2) protocols for rekeying security associations in IPsec tunnels are inefficient, particularly for devices with limited power and bandwidth, as they transmit unnecessary cryptographic suites during rekeying, increasing payload size and consuming excessive processing power and bandwidth.
Innovation Solution
The proposed method reduces payload size during rekeying by omitting the cryptographic suite in rekey responses when there is no change, using a new SPI notification payload to convey necessary information, thereby saving bandwidth and processing resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional IKEv2 rekeying protocol is used, then security association rekeying is achieved, but payload size increases and bandwidth consumption increases
Solution Approach 1:
The patent extracts and removes the cryptographic suite information from the rekey response message when there is no change in cryptographic suite. This is achieved by modifying the IKEv2 rekeying protocol to conditionally include only necessary fields, thereby reducing payload size while maintaining secure rekeying functionality.
Solution Approach 2:
The patent applies partial action by transmitting only the essential information (SPI values and key material) during rekeying operations, omitting redundant cryptographic suite information when unchanged. This partial transmission approach reduces bandwidth consumption while achieving the necessary rekeying objective.
2Reliability
If conventional IKEv2 rekeying protocol is used, then security association rekeying is achieved, but processing power consumption increases
Solution Approach 1:
The patent extracts unnecessary cryptographic suite data from the rekeying communication, reducing the amount of data that must be processed. This directly lowers processing power consumption while maintaining the security rekeying function.
Solution Approach 2:
The patent changes the message structure parameters by conditionally including fields based on whether cryptographic suite changes occur. This parameter modification reduces the data volume processed during rekeying operations, thereby reducing processing power consumption.
3Reliability
If conventional IKEv2 rekeying protocol is used, then security association rekeying is achieved, but bandwidth consumption increases
Solution Approach 1:
The patent removes redundant cryptographic suite information from rekey response messages, directly reducing bandwidth consumption. This extraction of unnecessary data maintains rekeying reliability while minimizing bandwidth usage.
Solution Approach 2:
The patent implements partial transmission by sending only essential rekeying information (SPI values and updated keys) rather than complete cryptographic suite information, thereby reducing bandwidth consumption while achieving secure rekeying.
Data Source
AI summary
In the IKE or IPSec SA rekeying, whether the rekey exchange includes the cryptographic suite in the payload depends on whether the cryptographic suite used in the old SA is changed on both ends, e.g., the initiator and the responder. If the cryptographic suite is not changed, then the rekey exchange does not include the cryptographic suite. Additionally, in the IPSec SA rekey, if the flowing information is not changed in either end, the rekey exchange further does not include the Traffic Selector (TS). As such, the size of the payload is decreased, which saves bandwidth, more processing time and power in the course of the IKE SA or the IPSec SA rekey.


