Intermediary Network Device Virtual Machine for IPsec Tunnel Decryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intermediary network devices in cellular communication networks cannot participate in security gateway communications due to their inability to decrypt encrypted messages, limiting their ability to perform processing tasks and affect network performance.
Innovation Solution
A method and system that establish a secure channel between an intermediary network device and a security gateway, using a virtual machine to instantiate session keys for IPsec tunnel establishment, allowing the intermediary device to process encrypted messages and inject traffic within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an IPsec tunnel is established between base stations and core network portion, then security of communications is improved, but intermediary network devices cannot decrypt encrypted messages and thus cannot perform processing tasks
Solution Approach 1:
The patent segments the security gateway functionality by instantiating a virtual machine on the intermediary network device that handles decryption and processing separately from the main IPsec tunnel establishment. This allows the intermediary device to have decryption capabilities without compromising the overall security architecture.
Solution Approach 2:
The virtual machine instantiated on the intermediary network device acts as an intermediary that receives encrypted messages, decrypts them using session keys, performs processing tasks, and re-encrypts them for forwarding. This mediator capability enables the intermediary device to participate in the secure communication without breaking the IPsec tunnel security.
2Productivity
If intermediary network devices are placed near base stations, then network performance is improved, but they cannot see traffic inside the IPsec tunnel and thus cannot perform content caching
Solution Approach 1:
The patent segments the traffic handling by creating a separate virtual machine instance on the intermediary device that processes decrypted traffic. This allows the intermediary to be positioned near the base station for performance optimization while still having the capability to perform content caching on visible traffic.
Solution Approach 2:
The patent adds a virtualization dimension by instantiating a virtual machine on the intermediary network device. This virtual machine operates in a separate computational dimension, allowing the intermediary to process and cache content while the physical IPsec tunnel maintains its security integrity.
3Adaptability or versatility
If session keys are transmitted to intermediary network devices, then they can decrypt and process encrypted messages, but security of the key transmission must be maintained
Solution Approach 1:
The patent implements preliminary action by establishing a secure channel and instantiating the virtual machine before transmitting encrypted messages. The session keys are transmitted through this pre-established secure channel, ensuring that key transmission itself is secured while enabling the intermediary device to decrypt and process messages.
Data Source
AI summary
A method for facilitating participation of an intermediary network device in a security gateway communication including: establishing a secure channel between the intermediary network device and a security gateway; transmitting a virtual machine instantiation command generated by software running in the security gateway to the intermediary network device; instantiating a virtual machine on the intermediary network device; when establishing a secure communication session between the at least one base station and the core network portion via the security gateway for the first time, establishing an Internet Key Exchange communication between the virtual machine and the security gateway and transmitting session keys from the security gateway to the virtual machine during the Internet Key Exchange communication; establishing an IPsec tunnel between the virtual machine and the security gateway.


