IPSec Encapsulation Mode Negotiation for Firewall Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security protocols like IPSec complicate deployment features for intermediaries such as firewalls by encapsulating messages, which can prevent the implementation of security features like message filtering.

Innovation Solution

Negotiating an encapsulation mode between an initiator and a responder to allow packets to be sent without encapsulation, enabling intermediaries to easily inspect and filter packets, while establishing a secure connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPSec encapsulation is implemented to secure messages, then message integrity and authentication are improved, but intermediary deployment features such as firewall message filtering become more complex or unavailable

Engineering Contradiction:
Improvemessage integrityVSAvoidfirewall deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by making the encapsulation mode negotiable and configurable between communicating parties. The system can dynamically switch between encapsulated and non-encapsulated modes based on network conditions and intermediary requirements, allowing firewalls to operate effectively while maintaining security where needed

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of encapsulation mode from fixed to variable. By allowing the encapsulation mode to be negotiated and changed based on network conditions, the system can adapt between secure encapsulated communication and firewall-compatible non-encapsulated communication, resolving the contradiction between security and intermediary functionality

Inventive Principle:
Principle #35Parameter changes

2Reliability

If IPSec encapsulation is used to authenticate computers, then security against malicious users is improved, but the ability of intermediaries to inspect and filter messages is reduced

Engineering Contradiction:
Improveauthentication securityVSAvoidintermediary message inspection
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts the encapsulation mode based on the communication context. When intermediaries need to inspect messages, the system can operate in non-encapsulated mode while maintaining authentication through other means, thus preserving intermediary operability without sacrificing security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The encapsulation parameter is made changeable based on network requirements. The system can switch between encapsulated and non-encapsulated modes, allowing intermediaries to perform message inspection when needed while maintaining authentication security when encapsulation is used

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8289970B2IPSec encapsulation mode
Publication Date: 2012.10.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8289970B2 patent drawing
  • US8289970B2 patent drawing
  • US8289970B2 patent drawing

AI summary

Described are embodiments directed to negotiating an encapsulation mode between an initiator and a responder. As part of the negotiation of the security association, an encapsulation mode is negotiated that allows packets to be sent between the initiator and responder without encapsulation. The ability to send packets without encapsulation allows intermediaries, such as a firewall, at the responder to easily inspect the packets and implement additional features such as security filtering.