IKEv2 Security Association Rekeying Payload Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet Key Exchange Version-2 (IKEv2) protocols for rekeying security associations in IPsec tunnels are inefficient, particularly for devices with limited power and bandwidth, as they transmit unnecessary cryptographic suites during rekeying, increasing payload size and consuming excessive processing power and bandwidth.

Innovation Solution

The proposed method reduces payload size during rekeying by omitting the cryptographic suite in rekey responses when there is no change, using a new SPI notification payload to convey necessary information, thereby saving bandwidth and processing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional IKEv2 rekeying protocol is used, then security association rekeying is achieved, but payload size increases and bandwidth consumption increases

Engineering Contradiction:
Improvesecurity association rekeyingVSAvoidpayload size
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts and removes the cryptographic suite information from the rekey response message when there is no change in cryptographic suite. This is achieved by modifying the IKEv2 rekeying protocol to conditionally include only necessary fields, thereby reducing payload size while maintaining secure rekeying functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by transmitting only the essential information (SPI values and key material) during rekeying operations, omitting redundant cryptographic suite information when unchanged. This partial transmission approach reduces bandwidth consumption while achieving the necessary rekeying objective.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If conventional IKEv2 rekeying protocol is used, then security association rekeying is achieved, but processing power consumption increases

Engineering Contradiction:
Improvesecurity association rekeyingVSAvoidprocessing power consumption
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts unnecessary cryptographic suite data from the rekeying communication, reducing the amount of data that must be processed. This directly lowers processing power consumption while maintaining the security rekeying function.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the message structure parameters by conditionally including fields based on whether cryptographic suite changes occur. This parameter modification reduces the data volume processed during rekeying operations, thereby reducing processing power consumption.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If conventional IKEv2 rekeying protocol is used, then security association rekeying is achieved, but bandwidth consumption increases

Engineering Contradiction:
Improvesecurity association rekeyingVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent removes redundant cryptographic suite information from rekey response messages, directly reducing bandwidth consumption. This extraction of unnecessary data maintains rekeying reliability while minimizing bandwidth usage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial transmission by sending only essential rekeying information (SPI values and updated keys) rather than complete cryptographic suite information, thereby reducing bandwidth consumption while achieving secure rekeying.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11943209B2Rekeying a security association SA
Publication Date: 2024.03.26 HUAWEI TECH CO LTD
  • US11943209B2 patent drawing
  • US11943209B2 patent drawing
  • US11943209B2 patent drawing

AI summary

In the IKE or IPSec SA rekeying, whether the rekey exchange includes the cryptographic suite in the payload depends on whether the cryptographic suite used in the old SA is changed on both ends, e.g., the initiator and the responder. If the cryptographic suite is not changed, then the rekey exchange does not include the cryptographic suite. Additionally, in the IPSec SA rekey, if the flowing information is not changed in either end, the rekey exchange further does not include the Traffic Selector (TS). As such, the size of the payload is decreased, which saves bandwidth, more processing time and power in the course of the IKE SA or the IPSec SA rekey.