Selective IPsec SA Recovery Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IPsec security association (SA) recovery methods incur significant processing overhead and network latencies when recovering large quantities of SAs during security enforcement point outages, such as power outages or network faults.

Innovation Solution

A method and system for selective IPsec SA recovery, which involves compiling a listing of valid SAs, monitoring for outages, and only re-establishing contextually valid SAs using an SA recovery database and selective recovery logic, thereby reducing unnecessary re-establishments and processing overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all IPsec SAs are re-established during security enforcement point recovery, then complete SA restoration is achieved, but processing overhead and network latency increase significantly

Engineering Contradiction:
ImproveSA restoration completenessVSAvoidprocessing overhead and network latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the necessary SAs for re-establishment by maintaining a list of SAs at the initiator and selectively recovering only those SAs where the initiator is the local endpoint. This extraction principle filters out SAs that don't require re-establishment, thereby reducing processing overhead and network latency while maintaining reliable restoration of necessary security associations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of re-establishing all SAs (excessive action), the patent implements partial action by re-establishing only the subset of SAs that are contextually valid and necessary. This partial approach reduces the scope of recovery operations, minimizing processing overhead and network latency while achieving sufficient restoration for operational continuity.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If comprehensive SA recovery is performed, then all security associations are restored, but processing overhead increases

Engineering Contradiction:
ImproveSA recovery completenessVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies the extraction principle by maintaining a local list of SAs at the initiator and comparing it against received SA notifications. Only SAs present in the initiator's list are re-established, extracting the essential subset from the complete set of SAs. This reduces processing overhead by avoiding unnecessary re-establishment operations while ensuring all critical SAs are restored.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial action by performing recovery operations on only the necessary subset of SAs rather than all SAs. This partial recovery approach reduces processing overhead and improves productivity during security enforcement point recovery, while still achieving sufficient restoration for maintaining secure communications.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8141126B2Selective IPsec security association recovery
Publication Date: 2012.03.20 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8141126B2 patent drawing
  • US8141126B2 patent drawing
  • US8141126B2 patent drawing

AI summary

Embodiments of the present invention address deficiencies of the art in respect to IPsec SA recovery and provide a novel and non-obvious method, system and computer program product for selective IPsec SA recovery from security enforcement point outages. In one embodiment of the invention, a security enforcement point outage recovery method can be provided. The method can include compiling a listing of SAs for a security enforcement point and monitoring the security enforcement point for an outage. Responsive to detecting an outage in the security enforcement point, the listing can be pruned to include SAs that remain contextually valid or are utilized by the peer of the security enforcement point. Thereafter, only SAs in the pruned list can be re-established.