IPsec Dynamic Routing Compatibility via SPD SAD Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IPsec and dynamic routing technologies are incompatible, leading to issues such as packet loss or VPN failure due to IPsec's disregard for reachability information, and existing solutions like IIPtran compromise access control and scalability.

Innovation Solution

Integrate reachability information into IPsec data structures, specifically the Security Policy Database (SPD) and Security Association Database (SAD), to enable IPsec to utilize dynamic routing information without modifying datagram processing or requiring additional IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPsec processes datagrams independently of dynamic routing information, then IPsec security processing is simple and fast, but reachability information is ignored causing packet loss or VPN failure

Engineering Contradiction:
ImproveVPN connectivity reliabilityVSAvoidIPsec processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the routing information integration function directly into the IPsec processing path by having the IPsec module consult the routing table and select appropriate Security Associations based on destination IP addresses from the routing information, eliminating the need for separate routing decision modules while ensuring packets are forwarded through valid tunnels

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary actions by pre-establishing Security Associations and organizing them in the Security Association Database indexed by destination IP addresses before actual data transmission occurs. When routing information changes, the system proactively updates the SAD to reflect new reachable networks, so that when packets arrive, the correct SA is already in place without requiring complex real-time decisions

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If IIPtran solution is used to enable IPsec with dynamic routing, then reachability information is utilized, but access control is compromised and additional IP addresses are required

Engineering Contradiction:
ImproveDynamic routing compatibilityVSAvoidAccess control security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the Security Association selection process into two independent parts: (1) routing information determines which destination networks are reachable through which gateways, and (2) IPsec security policies determine which SAs to use for those destinations. This segmentation allows the routing module to provide reachability information without interfering with the security policy enforcement, maintaining both dynamic routing compatibility and access control integrity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes the Security Association Database universal by organizing SAs in a standardized structure indexed by destination IP address that can serve both dynamic routing integration and traditional IPsec access control functions. The same SAD structure supports static policy-based selection and dynamic routing-based selection, eliminating the need for separate IP address schemes or access control mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple IPsec tunnels are established for redundancy, then VPN reliability improves, but IPsec cannot automatically switch to backup tunnels when primary tunnel fails

Engineering Contradiction:
ImproveVPN redundancyVSAvoidAutomatic failover capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback by continuously monitoring routing information from dynamic routing protocols to detect when destination networks become unreachable through current tunnels. When routing information indicates a tunnel failure or network unreachability, the system automatically updates the Security Association Database to reflect the new routing state, enabling automatic failover to backup tunnels without manual intervention or complex failure detection mechanisms

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7945666B2Method, system and storage medium for establishing compatibility between IPsec and dynamic routing
Publication Date: 2011.05.17 WUNNER LUKAS
  • US7945666B2 patent drawing
  • US7945666B2 patent drawing
  • US7945666B2 patent drawing

AI summary

A method, system and storage medium wherein reachability information is exchanged over IPsec tunnels by means of a dynamic routing protocol, but instead of incorporating it into the normal routing table, it is incorporated into the IPsec data structures SPD and SAD by performing a set of steps.1 Thereby, disadvantages of prior art efforts to establish compatibility between IPsec and dynamic routing, for instance IIPtran (RFC 3884), are overcome in that compatibility is established without modifying the processing of datagrams by IPsec.2 This may be implemented by extending the routing daemon so that it supports inserting or removing entries in the SPD and SAD using the PF KEY API.3 Further embodiments feature cryptographically signing and filtering advertised reachability information, redistribution of reachability information between the dynamic routing in the base network and the overlay network, a new routing protocol tailored specifically to IPsec and load sharing over multiple IPsec tunnels.41 [0043-0054]2 [0009-0023]3 [0064-0068]4 [0055-0059], [0061-0063], [0069-0079] and [0080-0081]