IPSec Encapsulation Mode Negotiation for Firewall Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security protocols like IPSec complicate deployment features for intermediaries such as firewalls by encapsulating messages, which can prevent the implementation of security features like message filtering.
Innovation Solution
Negotiating an encapsulation mode between an initiator and a responder to allow packets to be sent without encapsulation, enabling intermediaries to easily inspect and filter packets, while establishing a secure connection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPSec encapsulation is implemented to secure messages, then message integrity and authentication are improved, but intermediary deployment features such as firewall message filtering become more complex or unavailable
Solution Approach 1:
The patent applies dynamics by making the encapsulation mode negotiable and configurable between communicating parties. The system can dynamically switch between encapsulated and non-encapsulated modes based on network conditions and intermediary requirements, allowing firewalls to operate effectively while maintaining security where needed
Solution Approach 2:
The patent changes the parameter of encapsulation mode from fixed to variable. By allowing the encapsulation mode to be negotiated and changed based on network conditions, the system can adapt between secure encapsulated communication and firewall-compatible non-encapsulated communication, resolving the contradiction between security and intermediary functionality
2Reliability
If IPSec encapsulation is used to authenticate computers, then security against malicious users is improved, but the ability of intermediaries to inspect and filter messages is reduced
Solution Approach 1:
The system dynamically adjusts the encapsulation mode based on the communication context. When intermediaries need to inspect messages, the system can operate in non-encapsulated mode while maintaining authentication through other means, thus preserving intermediary operability without sacrificing security
Solution Approach 2:
The encapsulation parameter is made changeable based on network requirements. The system can switch between encapsulated and non-encapsulated modes, allowing intermediaries to perform message inspection when needed while maintaining authentication security when encapsulation is used
Data Source
AI summary
Described are embodiments directed to negotiating an encapsulation mode between an initiator and a responder. As part of the negotiation of the security association, an encapsulation mode is negotiated that allows packets to be sent between the initiator and responder without encapsulation. The ability to send packets without encapsulation allows intermediaries, such as a firewall, at the responder to easily inspect the packets and implement additional features such as security filtering.


