Hierarchical IPsec Policy Distribution via Secure Tunnels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IPsec implementations face challenges such as complex configuration and management, inability to secure multicast/broadcast traffic, load balancing, network address translation, firewall/IDS conflicts, and limitations in providing high-speed, low-latency encryption across large networks, particularly in scenarios requiring end-to-end security and resilient network traffic.

Innovation Solution

The solution involves dividing security policy definition, key generation, and distribution into separate components, allowing for logical separation of IKE and IPsec functionality, with policies and keys generated and distributed in a distributed manner using Key Generation and Distribution Points (KGDPs), Policy Enforcement Points (PEPs), and Security Policy Managers (SPMs) over secure tunnels, enabling secure policy enforcement and key sharing across devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPsec security policies are configured at each Security Gateway individually, then security can be enforced at each device, but configuration complexity and management burden increase significantly

Engineering Contradiction:
Improvesecurity enforcementVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A central Security Policy Manager is introduced as an intermediary between network administrators and distributed Security Gateways. This central manager handles policy creation, storage, and distribution to multiple gateways, eliminating the need for administrators to manually configure each gateway individually while maintaining security enforcement at the edge devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system separates policy management functions into two segments: a central Security Policy Manager that handles high-level policy definition and distribution, and distributed Security Gateways that handle local policy enforcement. This segmentation allows complex management tasks to be centralized while keeping enforcement distributed and efficient.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security policies are distributed to all Security Gateways, then comprehensive security coverage is achieved, but network bandwidth is consumed by policy transmission

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system implements local quality by allowing each Security Gateway to store and enforce only the security policies relevant to its specific location and traffic patterns, rather than distributing all possible policies to all gateways. This reduces unnecessary network bandwidth consumption while maintaining comprehensive security coverage where needed.

Inventive Principle:
Principle #3Local quality

3Reliability

If IPsec encryption is applied to all network traffic, then security is enhanced, but processing speed and latency are degraded

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies IPsec encryption selectively rather than universally - only to traffic that matches defined security policies requiring protection. This partial application of encryption maintains security for sensitive traffic while avoiding the performance penalty of encrypting all network traffic, thus preserving processing speed for non-sensitive data.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If Security Gateways are deployed throughout the network, then security enforcement is improved, but device management and key distribution become more difficult

Engineering Contradiction:
Improvesecurity enforcementVSAvoiddevice management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The central Security Policy Manager acts as an intermediary that automatically handles key generation, storage, and distribution to multiple Security Gateways. This eliminates the need for manual key management at each gateway, making it easy to deploy and manage distributed security enforcement while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8327437B2Securing network traffic by distributing policies in a hierarchy over secure tunnels
Publication Date: 2012.12.04 CERTES NETWORKS INC
  • US8327437B2 patent drawing
  • US8327437B2 patent drawing
  • US8327437B2 patent drawing

AI summary

A technique for securing message traffic in a data network using a protocol such as IPsec, and more particularly various methods for distributing security policies among peer entities in a network while minimizing the passing and storage of detailed policy or key information except at the lowest levels of a hierarchy.