Intermediary Network Device Virtual Machine for IPsec Tunnel Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Intermediary network devices in cellular communication networks cannot participate in security gateway communications due to their inability to decrypt encrypted messages, limiting their ability to perform processing tasks and affect network performance.

Innovation Solution

A method and system that establish a secure channel between an intermediary network device and a security gateway, using a virtual machine to instantiate session keys for IPsec tunnel establishment, allowing the intermediary device to process encrypted messages and inject traffic within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an IPsec tunnel is established between base stations and core network portion, then security of communications is improved, but intermediary network devices cannot decrypt encrypted messages and thus cannot perform processing tasks

Engineering Contradiction:
Improvesecurity of communicationsVSAvoidability of intermediary devices to process messages
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security gateway functionality by instantiating a virtual machine on the intermediary network device that handles decryption and processing separately from the main IPsec tunnel establishment. This allows the intermediary device to have decryption capabilities without compromising the overall security architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual machine instantiated on the intermediary network device acts as an intermediary that receives encrypted messages, decrypts them using session keys, performs processing tasks, and re-encrypts them for forwarding. This mediator capability enables the intermediary device to participate in the secure communication without breaking the IPsec tunnel security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If intermediary network devices are placed near base stations, then network performance is improved, but they cannot see traffic inside the IPsec tunnel and thus cannot perform content caching

Engineering Contradiction:
Improvenetwork performanceVSAvoidability to perform content caching
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the traffic handling by creating a separate virtual machine instance on the intermediary device that processes decrypted traffic. This allows the intermediary to be positioned near the base station for performance optimization while still having the capability to perform content caching on visible traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a virtualization dimension by instantiating a virtual machine on the intermediary network device. This virtual machine operates in a separate computational dimension, allowing the intermediary to process and cache content while the physical IPsec tunnel maintains its security integrity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If session keys are transmitted to intermediary network devices, then they can decrypt and process encrypted messages, but security of the key transmission must be maintained

Engineering Contradiction:
Improveability to decrypt and process messagesVSAvoidsecurity of key transmission
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing a secure channel and instantiating the virtual machine before transmitting encrypted messages. The session keys are transmitted through this pre-established secure channel, ensuring that key transmission itself is secured while enabling the intermediary device to decrypt and process messages.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10313877B2Method and system for facilitating participation of an intermediary network device in a security gateway communication between at least one base station and a core network portion in a cellular communication network
Publication Date: 2019.06.04 ADTRAN NETWORKS SE
  • US10313877B2 patent drawing
  • US10313877B2 patent drawing
  • US10313877B2 patent drawing

AI summary

A method for facilitating participation of an intermediary network device in a security gateway communication including: establishing a secure channel between the intermediary network device and a security gateway; transmitting a virtual machine instantiation command generated by software running in the security gateway to the intermediary network device; instantiating a virtual machine on the intermediary network device; when establishing a secure communication session between the at least one base station and the core network portion via the security gateway for the first time, establishing an Internet Key Exchange communication between the virtual machine and the security gateway and transmitting session keys from the security gateway to the virtual machine during the Internet Key Exchange communication; establishing an IPsec tunnel between the virtual machine and the security gateway.