IPsec Tunnel Packet Outer Header Copying for Load Balancing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Standard IPsec implementations are not compatible with networking functions that modify IP addresses, such as network load balancing and resilient routing, due to the requirement of including IP addresses in the Integrity Check Value (ICV), which prevents intermediate devices from re-computing the ICV and limits IPsec usage to scenarios where source and destination networks do not modify IP addresses.

Innovation Solution

The solution involves copying the original source and destination IP addresses of an encrypted outgoing packet to the outer header of an IPsec tunnel mode packet, creating an IPsec-like packet that can be routed according to its original addresses, enhancing flexibility and compatibility with various networking situations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP addresses are included in the ICV for authentication, then security and authentication integrity are improved, but compatibility with networking functions that modify IP addresses (such as load balancing and resilient routing) deteriorates

Engineering Contradiction:
Improveauthentication integrityVSAvoidcompatibility with networking functions
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the IP header into two parts: the outer IP header (which may be modified by networking devices) and the inner IP header (which is authenticated via ICV). This segmentation allows intermediate devices to modify the outer header for load balancing and routing while the inner header maintains authentication integrity through the ICV mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the inner IP header acts as a mediator between the authenticated data and the modified outer IP header. This allows the system to maintain authentication while accommodating modifications by intermediate networking devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the secured network identity is made known through copied IP addresses in the outer header, then routing flexibility is improved, but network security and anonymity deteriorate

Engineering Contradiction:
Improverouting flexibilityVSAvoidnetwork security vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent uses copying of the inner IP header to create the outer IP header, allowing the packet to be routed based on original addresses while maintaining the ability to hide the secured network identity when needed. The copied header enables routing flexibility without permanently exposing the network identity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent applies different quality requirements to different parts of the packet: the outer header is optimized for routing flexibility and visibility to intermediate devices, while the inner header maintains security and authenticity. This local differentiation allows simultaneous achievement of routing flexibility and network security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8104082B2Virtual security interface
Publication Date: 2012.01.24 CERTES NETWORKS INC
  • US8104082B2 patent drawing
  • US8104082B2 patent drawing
  • US8104082B2 patent drawing

AI summary

In some networking situations, securing an inner packet of a tunnel packet requires an intermediary networking device knowing a destination address of the secured inner packet. Consequently, an identity of a secured network is known to others and presents a security risk. The provided technique addresses this risk by: i) establishing at a first security interface a first secured network connection between a first and second secured network, the connection established for a first packet addressed to a virtual security interface and destined for the second secured network; and ii) responding to a network condition by establishing at a second security interface at least one second secured network connection between the first and second secured network, the connection established for a second packet addressed to the virtual security interface and destined for the second secured network.