IPsec Traffic Engineering via Trusted Third-Party Node

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment of IPsec in existing network infrastructures is challenging due to incompatibility issues and costs, as well as the encryption of packet headers and payloads, which complicates traffic engineering and management.

Innovation Solution

A system and method for traffic engineering in IPsec secured networks, where a trusted third-party node is authenticated to acquire and parse security information, including session keys, to inspect and manage IPsec traffic while maintaining end-to-end security associations, using protocols like Kerberos for key negotiation and NetFlow for flow information communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPsec is deployed to enhance network security, then data confidentiality and integrity are improved, but device compatibility and deployment ease deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces a trusted third-party node as an intermediary that facilitates key distribution and traffic engineering in IPsec networks. This mediator enables secure communication between endpoints by managing security associations and distributing encryption keys, thereby improving deployment ease while maintaining network security. The intermediary resolves compatibility issues by providing a centralized coordination point for IPsec parameter negotiation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IPsec encryption is applied to protect data, then data confidentiality is improved, but traffic engineering and management capability deteriorate

Engineering Contradiction:
Improvedata confidentialityVSAvoidtraffic engineering capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trusted third-party node acts as an intermediary that can observe and manage encrypted IPsec traffic without compromising confidentiality. It performs traffic engineering functions such as flow classification, quality of service management, and traffic monitoring by analyzing metadata and flow patterns rather than decrypting payload content. This enables traffic engineering capability while preserving data confidentiality through selective decryption of only necessary control information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments traffic management functions from data encryption operations. The trusted third party handles traffic engineering tasks by analyzing segmented flow information (source/destination addresses, ports, protocols) without requiring decryption of the actual data payload. This segmentation allows independent optimization of security and traffic management capabilities.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If a trusted third-party node is introduced to manage IPsec traffic, then traffic engineering capability is improved, but system complexity increases

Engineering Contradiction:
Improvetraffic engineering capabilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The trusted third-party node is designed with multi-functionality, serving simultaneously as a key distribution center, traffic engineering controller, and security association manager. By consolidating these functions into a single universal node, the patent reduces overall system complexity compared to having separate specialized components for each function. The node performs multiple roles including Kerberos authentication, IPsec key management, and NetFlow-based traffic analysis.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If session keys are distributed to enable traffic inspection, then traffic analysis capability is improved, but security risk increases

Engineering Contradiction:
Improvetraffic analysis capabilityVSAvoidsecurity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication and authorization actions before key distribution. The trusted third party verifies the identity and credentials of requesting nodes using Kerberos authentication, and pre-establishes security policies that limit key usage to specific traffic flows and purposes. This preliminary action ensures that only authorized entities receive session keys for traffic analysis, reducing security risks while enabling precise traffic measurement and monitoring capabilities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9461975B2Method and system for traffic engineering in secured networks
Publication Date: 2016.10.04 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US9461975B2 patent drawing
  • US9461975B2 patent drawing
  • US9461975B2 patent drawing

AI summary

Aspects of a method and system for traffic engineering in an IPSec secured network are provided. In this regard, a node in a network may be authenticated as a trusted third party and that trusted third party may be enabled to acquire security information shared between or among a plurality of network entities. In this manner, the trusted third party may parse, access and operate on IPSec encrypted traffic communicated between or among the plurality of network entities. Shared security information may comprise one or more session keys utilized for encrypting and/or decrypting the IPSec secured traffic. The node may parse IPSec traffic and identify a flow associated with the IPsec traffic. In this manner, the node may generate and/or communicate statistics pertaining to said IPSec secured traffic based on the flow with which the traffic is associated.