IPsec Gateway Label Translation for Cross-Realm Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual private networks (VPNs) lack a mechanism to translate IPsec-based labeling between different security realms, leading to inconsistent security label interpretations and a lack of effective access control policies for IPsec-labeled traffic across security realms.

Innovation Solution

Implementing a system that uses gateways to inspect and label IPsec traffic, determining security associations (SAs) and applying access control policies based on implicit security labels, with the ability to translate security labels between security realms for consistent policy enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPsec-based labeling is used to secure traffic across VPNs, then security and privacy are improved, but there is no mechanism to translate labels between different security realms, leading to inconsistent security policy enforcement

Engineering Contradiction:
Improvesecurity policy enforcement consistencyVSAvoidlabel translation capability between security realms
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a label translation mechanism that acts as an intermediary between different security realms. This translator converts security labels from one realm's format to another realm's format, enabling consistent security policy enforcement across VPNs with different labeling schemes without requiring direct integration between security realms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If different security realms use their own label representations and semantics, then each realm can maintain its own security policies, but there is no known mechanism to translate IPsec-based labeling between different security realms

Engineering Contradiction:
Improvesecurity realm independenceVSAvoidlabel meaning consistency
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent applies parameter changes by transforming security label parameters (representation format and semantic meaning) when translating between security realms. The label translation mechanism adjusts label parameters to match the target realm's requirements while preserving the essential security intent, enabling both realm independence and information consistency.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If MAC security is implemented with trusted operating systems, then access control is strengthened, but there is no firewall-equivalent method of controlling the flow of IPsec-labeled traffic between networks connected across a VPN

Engineering Contradiction:
Improveaccess control strengthVSAvoidtraffic flow control capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a gateway with multi-functionality that combines IPsec processing, label translation, and firewall-like traffic control capabilities. This universal gateway can handle multiple security functions including enforcing MAC policies, translating labels between realms, and controlling IPsec-labeled traffic flow, eliminating the need for separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8607302B2Method and system for sharing labeled information between different security realms
Publication Date: 2013.12.10 RED HAT INC
  • US8607302B2 patent drawing
  • US8607302B2 patent drawing
  • US8607302B2 patent drawing

AI summary

Embodiments of the present invention extend protection of network traffic between different security realms based on security labeling. In particular, embodiments of the present invention label provide for implicit labeling of traffic shared between different security realms. The traffic may be shared using IPsec protocols. A gateway inspects the IPsec traffic and identifies security associations (SAs) of the IPsec traffic. The gateway then determines a security label of the SA. Various access control policies may then be applied to the traffic based on its security label.