IPsec Flow Multiplexing via Embedded Identifiers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IPsec protocols face challenges in identifying and managing multiple data flows within a single IPsec channel, leading to increased signaling load and complexity in network security management, particularly when deploying load balancing or middlebox functions.

Innovation Solution

The method involves performing lookups in security policy and SPI databases to identify and process packets using traffic selectors and SPI values, allowing multiple data flows to be multiplexed within a single Security Association, enabling efficient identification and management of flows by network elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each data flow is associated with a distinct Security Association (SA) and Security Parameters Index (SPI), then data flow identification and security management are achieved, but signaling load and system complexity increase

Engineering Contradiction:
Improvedata flow identificationVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple data flows into a single Security Association (SA) by introducing flow identifier fields (such as 5-tuple or 6-tuple parameters) within the ESP packet payload. This allows multiple flows to share one SA and one SPI, eliminating the need for separate SAs for each flow and thereby reducing signaling load and management complexity while maintaining reliable flow identification through the embedded flow identifier fields.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If multiple data flows are multiplexed within a single Security Association, then signaling load is reduced, but flow identification and verification complexity increases

Engineering Contradiction:
Improvesignaling efficiencyVSAvoidflow identification complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the security management function by separating the SA-level identification (using SPI) from the flow-level identification (using embedded flow identifier fields in the packet payload). This segmentation allows efficient multiplexing of multiple flows within a single SA while maintaining clear and distinct identification mechanisms at each level, avoiding the need for complex verification processes.

Inventive Principle:
Principle #1Segmentation

3Reliability

If conventional IPsec protocols are used with one SPI per flow, then security is maintained, but the number of security contexts and cryptographic keys increases

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of security contexts
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent makes the single Security Association universal by enabling it to handle multiple data flows simultaneously. By embedding flow identifier fields within the ESP packet payload and using a single SPI to identify the SA, the system achieves multi-functionality where one SA serves multiple flows, thereby reducing the total number of security contexts and cryptographic keys required while maintaining security through the flow-specific identifier verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11240214B2Flow multiplexing in IPsec
Publication Date: 2022.02.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11240214B2 patent drawing
  • US11240214B2 patent drawing
  • US11240214B2 patent drawing

AI summary

Systems and methods for processing inbound and outbound secure packet traffic are provided herein. A first lookup operation can be performed to identify a security association corresponding to a received packet. A second lookup operation can be performed to determine a security parameters index associated with the packet and the identified security association. The packet can be processed in accordance with the security association and the security parameters index.