IPsec SA Cluster Sub-Flow Segmentation for Eavesdropping Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IPsec protocols are limited in securing data flows across unsecured networks, as they can be vulnerable to eavesdropping and packet correlation, especially when using sequential transmission and single SA pairs, which can be defeated by monitoring a single network node.
Innovation Solution
The method involves dividing data flows into multiple sub-flows and transmitting them in parallel using unidirectional sub-SAs, forming an SA cluster with unique SPIs, which can employ different network paths, making it difficult for eavesdroppers to correlate and intercept all packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single SA pair is used for IPsec transmission, then the device complexity is reduced, but the security against eavesdropping and packet correlation is weakened
Solution Approach 1:
The patent divides a single data flow into multiple sub-flows, each protected by a separate unidirectional sub-SA within an SA cluster. This segmentation allows packets to be distributed across multiple security associations with different SPIs, preventing eavesdroppers from correlating all packets through a single SA while maintaining manageable complexity through structured organization of sub-SAs.
Solution Approach 2:
The patent transitions from a single-dimension SA structure to a multi-dimensional SA cluster structure by introducing multiple sub-SAs with unique SPIs for each direction. This dimensional expansion creates multiple transmission paths and security layers, making it difficult for attackers to intercept and correlate all packets while monitoring only a single network node.
2Device complexity
If data packets are transmitted sequentially through a single SA, then the device complexity is reduced, but the transmission efficiency and security are worsened
Solution Approach 1:
The patent segments a single data flow into multiple parallel sub-flows, each transmitted through separate sub-SAs. This enables simultaneous transmission of multiple packet streams, increasing throughput and transmission efficiency while maintaining structured management through the SA cluster framework that organizes sub-SA relationships.
Solution Approach 2:
The patent establishes multiple parallel transmission paths through sub-SAs that can operate simultaneously and continuously. By distributing packets across multiple sub-flows with unique SPIs, the system achieves continuous high-speed transmission without the bottlenecks of sequential processing, while the SA cluster maintains coordinated management of all active sub-SAs.
3Object-affected harmful factors
If multiple sub-SAs are used in an SA cluster, then the security against eavesdropping is improved, but the device complexity increases
Solution Approach 1:
The patent divides the security association into multiple unidirectional sub-SAs, each with a unique SPI, allowing packets to be distributed across multiple secure channels. This segmentation enhances security by preventing eavesdroppers from correlating all packets through a single SA, while the modular sub-SA structure keeps complexity manageable through standardized organization.
Solution Approach 2:
The patent introduces multiple dimensions to the SA structure by creating an SA cluster composed of multiple sub-SAs with unique SPIs for each direction. This multi-dimensional approach distributes security across multiple layers and paths, making it difficult for attackers to intercept and correlate all packets while monitoring only a single network node, with complexity managed through structured cluster organization.
4Device complexity
If a single transmission path is used, then the device complexity is reduced, but the reliability and security are worsened
Solution Approach 1:
The patent segments the network transmission path into multiple sub-paths corresponding to different sub-SAs within an SA cluster. Each sub-SA can utilize different network routes, creating redundant transmission paths that improve reliability. If one path fails or is compromised, other sub-SAs maintain secure communication, while the SA cluster coordinates management of all paths.
Solution Approach 2:
The patent transitions from a single network path to multiple parallel transmission paths by establishing sub-SAs that can traverse different network routes. This multi-path approach enhances reliability and security by distributing traffic across multiple independent channels, making it difficult for attackers to intercept all packets while monitoring only a single network node, with path management coordinated through the SA cluster structure.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A network element (NE) comprising a memory device configured to store instructions, and a processor configured to execute the instructions by dividing a first plurality of data packets of a data flow into a first plurality of sub-flows, and causing the first plurality of sub-flows to be transmitted to a second NE via a network, wherein the first plurality of sub-flows are transmitted using a first Internet Protocol Security (IPsec) security association (SA) cluster comprising a plurality of parallel sub-SAs. The disclosure also includes a NE comprising a processor configured to create an IPsec SA cluster comprising a first plurality of sub-SAs between the NE and a second NE using an internet key exchange (IKE) or an IKEv2, wherein the first sub-SAs are unidirectional, and wherein the first sub-SAs are configured to transport a first plurality of data packets in a common direction.