IPSec Route Injection in Multi-Topology Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Multi-Topology Routing (MTR) systems do not support IPSec-aware topologies, preventing secure transmission of network traffic across IPSec tunnels, which limits service differentiation and path diversity for different classes of traffic.

Innovation Solution

Implementing Reverse Route Injection (RRI) in the control plane of IPSec to configure IPSec routes within MTR topologies, allowing secure transmission by injecting routes into pre-selected MTR topologies on IPSec gateway routers, enabling secure forwarding of traffic based on packet attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If MTR systems use conventional routing without IPSec integration, then routing flexibility and path diversity are improved, but security and data integrity protection are lost

Engineering Contradiction:
Improverouting flexibilityVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent combines MTR routing functionality with IPSec security protocols by integrating security policy processing into the MTR decision-making framework. The system merges topology selection with security association selection, allowing routes to be chosen based on both performance requirements and security policy requirements simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal routing framework that handles both secure and non-secure traffic through a single MTR system. The enhanced forwarding table can store both traditional routing information and IPSec-specific information, allowing the same routing infrastructure to serve multiple purposes including encrypted tunnel routing, unencrypted direct routing, and policy-based routing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If IPSec routes are injected into MTR topologies, then secure transmission is enabled, but system complexity increases

Engineering Contradiction:
Improvesecure transmissionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary security policy processing mechanism that acts as a mediator between the routing system and IPSec protocols. This intermediary component translates security policies into routing decisions without requiring complete integration of IPSec complexity into the entire MTR system. The forwarding table serves as an intermediary data structure that consolidates both routing and security information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the routing and security functions into distinct but coordinated components: the security policy processing module, the enhanced forwarding table, and the MTR decision-making module. This segmentation allows each component to handle its specific function independently while working together to achieve secure routing, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple MTR topologies are configured for different traffic types, then service differentiation is improved, but configuration and management complexity increases

Engineering Contradiction:
Improveservice differentiationVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The enhanced forwarding table provides a universal data structure that handles both traditional MTR topology information and IPSec security information in a unified manner. This universal structure allows the system to manage multiple topologies with different security requirements through a single configuration interface, reducing operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7944854B2IP security within multi-topology routing
Publication Date: 2011.05.17 CISCO TECHNOLOGY INC
  • US7944854B2 patent drawing
  • US7944854B2 patent drawing
  • US7944854B2 patent drawing

AI summary

A method for IP Security within Multi-Topology Routing is disclosed. Disclosed methods may also include IKE extensions. A route eligible for IPSec protection is injected into a topology routing table. Network traffic can then be protected in accordance with a security session, such as an IPSec session, between a first network node and a second network node and forwarded through a selected topology to take advantage of the service-differentiation capabilities of MTR.