IPsec ESP Outer Header Authentication Merging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional authentication methods for IP packets are inadequate when network nodes are compromised, as they fail to protect sensitive information effectively, especially in scenarios involving Network Address Translation (NAT) traversal.

Innovation Solution

The proposed solution extends IP packet authentication by using information obtained during the negotiation process between IPSec peers, eliminating the need for the IPsec Authentication Header (AH) protocol, thereby reducing overhead and enhancing performance by authenticating the outer IP header without requiring an AH header.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for IP packets, then the authentication process is simpler, but the protection against compromised network nodes is insufficient

Engineering Contradiction:
Improveauthentication protectionVSAvoidauthentication method complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication of the outer IP header with the ESP authentication process. Instead of treating them as separate operations, the outer IP header is included in the ESP authentication data calculation, combining two authentication functions into a single integrated process that provides enhanced protection without proportionally increasing complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The ESP authentication mechanism is extended to serve multiple functions: it continues to authenticate the encrypted payload while simultaneously authenticating the outer IP header. This multi-functionality allows a single authentication process to provide both traditional ESP protection and extended outer header protection against compromised network nodes

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If the IPsec Authentication Header (AH) protocol is used to authenticate the outer IP header, then authentication coverage is improved, but overhead and processing complexity increase

Engineering Contradiction:
Improveouter IP header authenticationVSAvoidAH header overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent eliminates the need for a separate AH header by merging the outer IP header authentication into the existing ESP authentication process. The outer IP header is incorporated into the ESP authentication data, and a single authentication check verifies both the outer header and the encrypted payload, removing the redundant AH header structure while maintaining comprehensive authentication coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The ESP authentication mechanism is extended to perform the function previously requiring a dedicated AH protocol. By making ESP authentication multi-functional—capable of authenticating both the encrypted data and the outer IP header—the patent eliminates the need for separate AH protocol infrastructure, reducing overhead while maintaining authentication reliability

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive authentication checks are performed on all IP packet components, then security against compromised nodes is improved, but processing time and performance increase

Engineering Contradiction:
Improvepacket authentication securityVSAvoidIPsec processing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines multiple authentication operations into a single integrated check. By including the outer IP header in the ESP authentication data and performing one unified authentication verification, the system avoids the performance penalty of multiple separate authentication operations while maintaining comprehensive security coverage across all packet components

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11431730B2Systems and methods for extending authentication in IP packets
Publication Date: 2022.08.30 CISCO TECHNOLOGY INC
  • US11431730B2 patent drawing
  • US11431730B2 patent drawing
  • US11431730B2 patent drawing

AI summary

In one embodiment, a method includes negotiating, by a networking device, a security association with a peer and receiving, by the networking device, an Internet Protocol (IP) packet from the peer. The IP packet includes an outer IP header, an ESP header, a protocol header, data, an ESP trailer, and ESP authentication data. The method further includes performing, using an IP Security (IPSec) authentication algorithm, authentication checks for the outer IP header, the ESP header, the protocol header, the data, the ESP trailer, and the ESP authentication data of the IP packet.