Seamless IPsec Tunnel Switching With Child SA Rekeying

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IPsec tunnel switching methods cause latency issues and security risks, particularly when transitioning between different subsystems within a device, due to the need for multiple handshakes and complete cessation of the tunnel, which can lead to data loss and increased latency.

Innovation Solution

Implement a seamless IPsec tunnel switching method that initiates a child Security Association (SA) rekeying process, allowing both existing and new tunnels to coexist temporarily, ensuring continuous data transfer and maintaining security measures like anti-replay checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional IPsec tunnel switching is used, then the tunnel can be re-established on a new subsystem, but data transmission is interrupted and latency increases

Engineering Contradiction:
Improvesubsystem switching capabilityVSAvoiddata transmission interruption time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by initiating the child SA rekeying process and establishing the new IPsec tunnel on the second subsystem before completely deactivating the first tunnel. This allows the new tunnel to be ready to receive data immediately, eliminating transmission interruptions during subsystem switching.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuity of useful action by maintaining overlapping operation of both the first and second IPsec tunnels during the transition period. Data packets are continuously transmitted through both tunnels simultaneously, with the system gradually migrating traffic from the first to the second tunnel, thus eliminating any interruption in data transmission.

Inventive Principle:
Principle #20Continuity of useful action

2Adaptability or versatility

If traditional IPsec tunnel switching is used, then the tunnel can be re-established, but security measures like anti-replay checks may be compromised

Engineering Contradiction:
Improvetunnel re-establishment capabilityVSAvoidsecurity measure effectiveness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-establishing the new child SA and IPsec tunnel on the second subsystem before switching. This ensures that security parameters, sequence numbers, and anti-replay checks are already configured and validated in the new tunnel, so when data migration begins, security measures remain effective without interruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuity of security checks by having both tunnels operate simultaneously during the transition. The first tunnel continues to process data with its security checks active, while the second tunnel simultaneously validates packets with its own security measures. This overlapping operation ensures that anti-replay checks and other security mechanisms remain effective throughout the switching process.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If multiple handshakes are required for tunnel switching, then the new tunnel can be securely established, but latency and processing overhead increase

Engineering Contradiction:
Improvetunnel establishment securityVSAvoidhandshake time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing the IKE rekeying process and child SA establishment in advance before the actual data migration. The new tunnel is fully configured, validated, and ready to receive traffic before the switching event, eliminating the need for handshakes during data transmission and reducing overall latency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250301391A1Seamless Switching of IPsec Tunnels
Publication Date: 2025.09.25 GOOGLE LLC
  • US20250301391A1 patent drawing
  • US20250301391A1 patent drawing
  • US20250301391A1 patent drawing

AI summary

This document describes aspects of seamless switching of Internet Protocol security (IPsec) tunnels between subsystems within a user device. In aspects, the described systems and methods can initiate a child Security Association (SA) rekeying process to establish a new IPsec tunnel without interrupting a data exchange on an active IPsec tunnel. The described aspects may enable continuous communication while the data exchanged is migrated between the IPsec tunnels. In some cases, both the old and new child SAs coexist temporarily during the rekeying process, allowing for uninterrupted data flow and ensuring that security measures, such as anti-replay checks, remain effective. As such, the transitions of the data can be completed without data loss, as the subsystems handle the transfer of data packets over both IPsec tunnels. The described aspects are particularly beneficial for devices that switch between high-performance and low-power hardware subsystems, enabling the optimization of performance and energy efficiency.