IPsec SPI Prefix Routing for ESP Processor Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for distributing IPsec data packets are inefficient and costly, particularly when using load balancing, which involves frequent state changes and requires more computing power than traditional routing.

Innovation Solution

Assign a prefix to the Security Parameter Index (SPI) header of IPsec data packets to facilitate routing using established routing protocols like IPv4, eliminating the need for costly load balancing by employing techniques such as Border Gateway Protocol (BGP) and Equal Cost Multi-Path (ECMP) routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If load balancing is used to distribute IPsec data packets, then traffic can be distributed to multiple ESP processors, but the system becomes more expensive and less efficient due to frequent state changes and higher computing power requirements

Engineering Contradiction:
Improvepacket distribution efficiencyVSAvoidstate management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the SPI address space into multiple prefixes, where each prefix is assigned to a specific ESP processor. This segmentation allows routing decisions to be made based on simple prefix matching rather than complex load balancing state management, thereby improving packet distribution efficiency while reducing device complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary action by pre-assigning SPI prefixes to specific ESP processors before traffic arrives. This preconfiguration enables routers to distribute packets efficiently using standard routing protocols without requiring dynamic state management during operation, reducing both complexity and computational overhead

Inventive Principle:
Principle #10Preliminary action

2Productivity

If load balancing is used to distribute IPsec data packets, then traffic distribution is achieved, but computing power requirements increase due to frequent state changes

Engineering Contradiction:
Improvepacket distribution capabilityVSAvoidcomputing power consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

By segmenting the SPI space into fixed prefixes and assigning each prefix to a specific ESP processor, the system enables routers to use simple prefix-based routing instead of complex load balancing algorithms. This segmentation maintains packet distribution capability while dramatically reducing computing power consumption for routing decisions

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces expensive, complex load balancing state management with simple, static prefix routing information. The prefix-based routing acts as a lightweight, disposable mechanism that requires minimal computational resources compared to traditional load balancing approaches

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12375463B2Internet protocol security and security parameter index summarization and data routing
Publication Date: 2025.07.29 CISCO TECHNOLOGY INC
  • US12375463B2 patent drawing
  • US12375463B2 patent drawing
  • US12375463B2 patent drawing

AI summary

Techniques for routing Internet Protocol security (IPsec) data packets. An index is assigned to a Security Parameter Index (SPI) header of the IPsec data packet. The index includes information for routing the data packet to a particular Encapsulating Security Payload (ESP) processor. The data packet can be routed using techniques that are analogous to conventional routing protocols such as IPv4 routing protocol. This allows the data packet to be routed using less expensive routing protocols rather than relying solely on more expensive load balancing techniques to route the data packet. This also advantageously allows the data packet to be routed employing routing techniques developed over decades of routing protocol development.