IPsec Key Exchange via Blockchain for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IPsec networks require each peer to maintain multiple unique security associations and policies, leading to scalability limitations and performance issues due to the need for extensive key negotiations and lookups, especially in VPN environments.

Innovation Solution

Implementing a blockchain network to share a single unique incoming security key among peers, reducing the number of IPsec security associations and policies required, and using a blockchain to manage key updates and verifications, thereby simplifying configuration and improving performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional IPsec networks use multiple unique security associations and policies for each peer, then security and authentication are ensured, but system complexity and scalability are limited

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of security associations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a shared security association that serves multiple peers simultaneously. Instead of each peer having unique security associations, a single shared SA is established that can authenticate and secure communications for multiple peers, thereby reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a blockchain as an intermediary mechanism to manage security key exchanges. The blockchain acts as a mediator that enables peers to exchange and verify security keys without requiring traditional complex IPsec key negotiation protocols, simplifying the security association management process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional IPsec networks maintain extensive key negotiations and lookups, then authentication is thorough, but system performance deteriorates

Engineering Contradiction:
ImproveauthenticationVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-establishing and publishing security keys on the blockchain before actual communication occurs. This allows peers to retrieve authentication information in advance without performing complex real-time key negotiations, thereby improving system performance while maintaining thorough authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the traditional mechanical IPsec key negotiation mechanism with a blockchain-based system. Instead of performing complex cryptographic negotiations between peers, the system uses blockchain's distributed ledger to store and verify security keys, significantly improving authentication speed and system performance.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If conventional IPsec networks perform extensive key negotiations, then security associations are established, but latency increases

Engineering Contradiction:
Improvesecurity association establishmentVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies copying by creating a replicated copy of the security key distribution system on the blockchain. Multiple nodes in the blockchain network store copies of the same security keys, allowing any peer to quickly retrieve authentication information from any node without waiting for complex key negotiations, thereby reducing latency.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If conventional IPsec networks require extensive configuration, then security policies are customized, but ease of operation decreases

Engineering Contradiction:
Improvesecurity policy customizationVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent applies self-service by enabling the blockchain network to automatically manage security key distribution and verification without requiring manual configuration. Peers can autonomously retrieve and verify security keys from the blockchain, eliminating the need for complex manual configuration while maintaining customizable security policies.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11349653B2Multiple-site private network secured by IPsec using blockchain network for key exchange
Publication Date: 2022.05.31 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11349653B2 patent drawing
  • US11349653B2 patent drawing
  • US11349653B2 patent drawing

AI summary

In some implementations, a method includes: preparing, at a first networking device, an incoming security key update request transaction, the incoming security key update request transaction including a request by the first networking device to use an incoming security key for incoming communications with other networking devices during an IPsec session, where the first networking device and the other networking devices communicate over a blockchain network including a blockchain; transmitting the incoming security key update request transaction from the first networking device to the blockchain network for validation; updating a copy of the blockchain with a block, the block including a validation of the incoming security key update request transaction that was transmitted to the blockchain network; and using at least the updated blockchain to update an IPsec security association (SA) or an IPsec security policy (SP) used by the first networking device.