IPsec Phase 1 Lifetime Configuration for Rapid DPD Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IPsec implementations experience prolonged periods of non-communication due to service disruptions, particularly when a phase 1 SA expires, leading to extended interruptions in secure communication as Dead Peer Detection (DPD) cannot be implemented until the soft phase 2 SA timer expires, which can take several hours.
Innovation Solution
Configuring phase 1 and phase 2 lifetimes using the equation Phase 1 lifetime = (Phase 2 soft-lifetime) * N, where N is a positive integer, ensures that phase 1 SA remains available during secure communication, allowing for immediate recovery via DPD and minimizing communication disruptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If phase 1 SA lifetime is set independently from phase 2 SA lifetime, then configuration flexibility is improved, but communication disruption time increases when phase 1 SA expires
Solution Approach 1:
The patent applies preliminary action by configuring the phase 1 SA lifetime to be an integer multiple of the phase 2 soft SA lifetime before communication occurs. This pre-configured relationship ensures that phase 1 SA remains available when phase 2 SA needs renewal, preventing communication disruptions without requiring independent configuration adjustments.
Solution Approach 2:
The patent changes the parameter relationship between phase 1 and phase 2 SA lifetimes from independent values to a dependent relationship where phase 1 lifetime = N × phase 2 soft lifetime. This parameter transformation resolves the contradiction by maintaining configuration simplicity while ensuring continuous phase 1 SA availability for DPD operations.
2Duration of action of stationary object
If phase 1 SA lifetime is extended to prevent expiration, then communication continuity is improved, but security key renewal frequency decreases
Solution Approach 1:
The patent uses preliminary action by pre-configuring phase 1 SA lifetime as an integer multiple of phase 2 soft SA lifetime. This ensures phase 1 SA remains available in advance for DPD operations while allowing phase 2 SA to be renewed multiple times within the phase 1 lifetime, maintaining both continuity and security renewal.
Solution Approach 2:
The patent implements periodic action through the integer multiple relationship, allowing phase 2 SA to be renewed periodically (N times) within the phase 1 SA lifetime. This periodic renewal maintains security while ensuring phase 1 SA remains available for the entire duration.
3Speed
If Dead Peer Detection is implemented immediately upon service disruption, then recovery speed is improved, but phase 1 SA must remain available
Solution Approach 1:
The patent applies preliminary action by configuring phase 1 SA lifetime to extend through multiple phase 2 SA renewals. This pre-established availability allows DPD to be implemented immediately upon service disruption without waiting for phase 1 SA expiration, enabling fast recovery while maintaining phase 1 SA for the required duration.
4Reliability
If phase 2 soft SA lifetime is shortened to enable faster renewal, then security is improved, but configuration complexity increases
Solution Approach 1:
The patent transforms the configuration complexity issue by establishing a simple parameter relationship: phase 1 lifetime = N × phase 2 soft lifetime. This single integer parameter N controls both the security renewal frequency and phase 1 availability, simplifying configuration while achieving multiple objectives simultaneously.
Data Source
AI summary
A method for configuring Internet Protocol Security (IPsec) protocol. The method includes configuring IPsec phase 1 Security Associations (SA) lifetimes and soft phase 2 SA lifetimes in a manner enabling efficient Dead Peer Detection recovery of secure communication between client and server in the event of a communication disruption and thereby preventing undesirable sustained periods of non-communication between client and server.


