IPsec SA Cluster Sub-Flow Segmentation for Eavesdropping Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IPsec protocols are limited in securing data flows across unsecured networks, as they can be vulnerable to eavesdropping and packet correlation, especially when using sequential transmission and single SA pairs, which can be defeated by monitoring a single network node.

Innovation Solution

The method involves dividing data flows into multiple sub-flows and transmitting them in parallel using unidirectional sub-SAs, forming an SA cluster with unique SPIs, which can employ different network paths, making it difficult for eavesdroppers to correlate and intercept all packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single SA pair is used for IPsec transmission, then the device complexity is reduced, but the security against eavesdropping and packet correlation is weakened

Engineering Contradiction:
ImproveIPsec security association structureVSAvoidvulnerability to eavesdropping and packet correlation
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent divides a single data flow into multiple sub-flows, each protected by a separate unidirectional sub-SA within an SA cluster. This segmentation allows packets to be distributed across multiple security associations with different SPIs, preventing eavesdroppers from correlating all packets through a single SA while maintaining manageable complexity through structured organization of sub-SAs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimension SA structure to a multi-dimensional SA cluster structure by introducing multiple sub-SAs with unique SPIs for each direction. This dimensional expansion creates multiple transmission paths and security layers, making it difficult for attackers to intercept and correlate all packets while monitoring only a single network node.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If data packets are transmitted sequentially through a single SA, then the device complexity is reduced, but the transmission efficiency and security are worsened

Engineering Contradiction:
ImproveIPsec transmission structureVSAvoidtransmission efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments a single data flow into multiple parallel sub-flows, each transmitted through separate sub-SAs. This enables simultaneous transmission of multiple packet streams, increasing throughput and transmission efficiency while maintaining structured management through the SA cluster framework that organizes sub-SA relationships.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent establishes multiple parallel transmission paths through sub-SAs that can operate simultaneously and continuously. By distributing packets across multiple sub-flows with unique SPIs, the system achieves continuous high-speed transmission without the bottlenecks of sequential processing, while the SA cluster maintains coordinated management of all active sub-SAs.

Inventive Principle:
Principle #20Continuity of useful action

3Object-affected harmful factors

If multiple sub-SAs are used in an SA cluster, then the security against eavesdropping is improved, but the device complexity increases

Engineering Contradiction:
Improveresistance to eavesdropping and packet correlationVSAvoidIPsec security association structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent divides the security association into multiple unidirectional sub-SAs, each with a unique SPI, allowing packets to be distributed across multiple secure channels. This segmentation enhances security by preventing eavesdroppers from correlating all packets through a single SA, while the modular sub-SA structure keeps complexity manageable through standardized organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multiple dimensions to the SA structure by creating an SA cluster composed of multiple sub-SAs with unique SPIs for each direction. This multi-dimensional approach distributes security across multiple layers and paths, making it difficult for attackers to intercept and correlate all packets while monitoring only a single network node, with complexity managed through structured cluster organization.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Device complexity

If a single transmission path is used, then the device complexity is reduced, but the reliability and security are worsened

Engineering Contradiction:
Improvenetwork path structureVSAvoidtransmission reliability and security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the network transmission path into multiple sub-paths corresponding to different sub-SAs within an SA cluster. Each sub-SA can utilize different network routes, creating redundant transmission paths that improve reliability. If one path fails or is compromised, other sub-SAs maintain secure communication, while the SA cluster coordinates management of all paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single network path to multiple parallel transmission paths by establishing sub-SAs that can traverse different network routes. This multi-path approach enhances reliability and security by distributing traffic across multiple independent channels, making it difficult for attackers to intercept all packets while monitoring only a single network node, with path management coordinated through the SA cluster structure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP2823620B1Enhancing ipsec performance and security against eavesdropping
Publication Date: 2016.03.23 HUAWEI TECH CO LTD
  • EP2823620B1 patent drawingFigure 1~2
  • EP2823620B1 patent drawingFigure 3
  • EP2823620B1 patent drawingFigure 4

AI summary

A network element (NE) comprising a memory device configured to store instructions, and a processor configured to execute the instructions by dividing a first plurality of data packets of a data flow into a first plurality of sub-flows, and causing the first plurality of sub-flows to be transmitted to a second NE via a network, wherein the first plurality of sub-flows are transmitted using a first Internet Protocol Security (IPsec) security association (SA) cluster comprising a plurality of parallel sub-SAs. The disclosure also includes a NE comprising a processor configured to create an IPsec SA cluster comprising a first plurality of sub-SAs between the NE and a second NE using an internet key exchange (IKE) or an IKEv2, wherein the first sub-SAs are unidirectional, and wherein the first sub-SAs are configured to transport a first plurality of data packets in a common direction.