IPsec Key Exchange via Blockchain for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IPsec networks require each peer to maintain multiple unique security associations and policies, leading to scalability limitations and performance issues due to the need for extensive key negotiations and lookups, especially in VPN environments.
Innovation Solution
Implementing a blockchain network to share a single unique incoming security key among peers, reducing the number of IPsec security associations and policies required, and using a blockchain to manage key updates and verifications, thereby simplifying configuration and improving performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional IPsec networks use multiple unique security associations and policies for each peer, then security and authentication are ensured, but system complexity and scalability are limited
Solution Approach 1:
The patent applies universality by creating a shared security association that serves multiple peers simultaneously. Instead of each peer having unique security associations, a single shared SA is established that can authenticate and secure communications for multiple peers, thereby reducing overall system complexity while maintaining security.
Solution Approach 2:
The patent introduces a blockchain as an intermediary mechanism to manage security key exchanges. The blockchain acts as a mediator that enables peers to exchange and verify security keys without requiring traditional complex IPsec key negotiation protocols, simplifying the security association management process.
2Reliability
If conventional IPsec networks maintain extensive key negotiations and lookups, then authentication is thorough, but system performance deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-establishing and publishing security keys on the blockchain before actual communication occurs. This allows peers to retrieve authentication information in advance without performing complex real-time key negotiations, thereby improving system performance while maintaining thorough authentication.
Solution Approach 2:
The patent replaces the traditional mechanical IPsec key negotiation mechanism with a blockchain-based system. Instead of performing complex cryptographic negotiations between peers, the system uses blockchain's distributed ledger to store and verify security keys, significantly improving authentication speed and system performance.
3Reliability
If conventional IPsec networks perform extensive key negotiations, then security associations are established, but latency increases
Solution Approach 1:
The patent applies copying by creating a replicated copy of the security key distribution system on the blockchain. Multiple nodes in the blockchain network store copies of the same security keys, allowing any peer to quickly retrieve authentication information from any node without waiting for complex key negotiations, thereby reducing latency.
4Adaptability or versatility
If conventional IPsec networks require extensive configuration, then security policies are customized, but ease of operation decreases
Solution Approach 1:
The patent applies self-service by enabling the blockchain network to automatically manage security key distribution and verification without requiring manual configuration. Peers can autonomously retrieve and verify security keys from the blockchain, eliminating the need for complex manual configuration while maintaining customizable security policies.
Data Source
AI summary
In some implementations, a method includes: preparing, at a first networking device, an incoming security key update request transaction, the incoming security key update request transaction including a request by the first networking device to use an incoming security key for incoming communications with other networking devices during an IPsec session, where the first networking device and the other networking devices communicate over a blockchain network including a blockchain; transmitting the incoming security key update request transaction from the first networking device to the blockchain network for validation; updating a copy of the blockchain with a block, the block including a validation of the incoming security key update request transaction that was transmitted to the blockchain network; and using at least the updated blockchain to update an IPsec security association (SA) or an IPsec security policy (SP) used by the first networking device.


