Seamless IPsec Tunnel Switching With Child SA Rekeying
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IPsec tunnel switching methods cause latency issues and security risks, particularly when transitioning between different subsystems within a device, due to the need for multiple handshakes and complete cessation of the tunnel, which can lead to data loss and increased latency.
Innovation Solution
Implement a seamless IPsec tunnel switching method that initiates a child Security Association (SA) rekeying process, allowing both existing and new tunnels to coexist temporarily, ensuring continuous data transfer and maintaining security measures like anti-replay checks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional IPsec tunnel switching is used, then the tunnel can be re-established on a new subsystem, but data transmission is interrupted and latency increases
Solution Approach 1:
The patent applies preliminary action by initiating the child SA rekeying process and establishing the new IPsec tunnel on the second subsystem before completely deactivating the first tunnel. This allows the new tunnel to be ready to receive data immediately, eliminating transmission interruptions during subsystem switching.
Solution Approach 2:
The patent ensures continuity of useful action by maintaining overlapping operation of both the first and second IPsec tunnels during the transition period. Data packets are continuously transmitted through both tunnels simultaneously, with the system gradually migrating traffic from the first to the second tunnel, thus eliminating any interruption in data transmission.
2Adaptability or versatility
If traditional IPsec tunnel switching is used, then the tunnel can be re-established, but security measures like anti-replay checks may be compromised
Solution Approach 1:
The patent applies preliminary action by pre-establishing the new child SA and IPsec tunnel on the second subsystem before switching. This ensures that security parameters, sequence numbers, and anti-replay checks are already configured and validated in the new tunnel, so when data migration begins, security measures remain effective without interruption.
Solution Approach 2:
The patent maintains continuity of security checks by having both tunnels operate simultaneously during the transition. The first tunnel continues to process data with its security checks active, while the second tunnel simultaneously validates packets with its own security measures. This overlapping operation ensures that anti-replay checks and other security mechanisms remain effective throughout the switching process.
3Reliability
If multiple handshakes are required for tunnel switching, then the new tunnel can be securely established, but latency and processing overhead increase
Solution Approach 1:
The patent applies preliminary action by performing the IKE rekeying process and child SA establishment in advance before the actual data migration. The new tunnel is fully configured, validated, and ready to receive traffic before the switching event, eliminating the need for handshakes during data transmission and reducing overall latency.
Data Source
AI summary
This document describes aspects of seamless switching of Internet Protocol security (IPsec) tunnels between subsystems within a user device. In aspects, the described systems and methods can initiate a child Security Association (SA) rekeying process to establish a new IPsec tunnel without interrupting a data exchange on an active IPsec tunnel. The described aspects may enable continuous communication while the data exchanged is migrated between the IPsec tunnels. In some cases, both the old and new child SAs coexist temporarily during the rekeying process, allowing for uninterrupted data flow and ensuring that security measures, such as anti-replay checks, remain effective. As such, the transitions of the data can be completed without data loss, as the subsystems handle the transfer of data packets over both IPsec tunnels. The described aspects are particularly beneficial for devices that switch between high-performance and low-power hardware subsystems, enabling the optimization of performance and energy efficiency.


