IPsec Tunnel Duplicate SA Detection During IKE Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IPsec systems consume extra security associations (SAs) due to duplicate SA detection occurring after successful programming, leading to redundant programming operations and reduced tunnel scale support in scaled setups.

Innovation Solution

Implement early duplicate SA management through capability notifications and nonce comparisons during IKE exchanges to prevent duplicate SAs, allowing each endpoint to initiate SAs independently, thus optimizing hardware resource consumption and reducing redundant programming.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If duplicate SA detection is performed after successful programming, then SA establishment is completed, but extra SAs are consumed and redundant programming operations occur

Engineering Contradiction:
ImproveSA establishment completenessVSAvoidhardware SA resource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent performs duplicate SA detection during the IKE exchange process before the SA is programmed into hardware. By checking for duplicates in the software domain early in the protocol handshake, the system prevents redundant programming operations and avoids consuming extra hardware SA resources, while still ensuring complete and reliable SA establishment.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If duplicate SA detection is performed after successful programming, then SA establishment is completed, but redundant programming operations occur

Engineering Contradiction:
ImproveSA establishment completenessVSAvoidprogramming operation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs duplicate SA detection during the IKE exchange process before the SA is programmed into hardware. By checking for duplicates in the software domain early in the protocol handshake, the system prevents redundant programming operations and avoids consuming extra hardware SA resources, while still ensuring complete and reliable SA establishment.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If each endpoint initiates SAs independently, then SA setup flexibility is improved, but duplicate SAs are more likely to occur

Engineering Contradiction:
ImproveSA initiation flexibilityVSAvoidduplicate SA occurrences
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent implements a feedback mechanism where each endpoint monitors and detects duplicate SA attempts during the IKE exchange. When a duplicate is detected, the system provides feedback by aborting the duplicate establishment and notifying the peer endpoint. This allows independent SA initiation to continue while preventing duplicate SAs from being created, maintaining both flexibility and resource efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12598169B2System and method for early detection of duplicate security association of IPsec tunnels
Publication Date: 2026.04.07 CISCO TECHNOLOGY INC
  • US12598169B2 patent drawing
  • US12598169B2 patent drawing
  • US12598169B2 patent drawing

AI summary

In an embodiment, a method includes transmitting an initiation request from a first electronic device to a second electronic device, the initiation request being associated with a notification that the first electronic device is capable of early detection of duplicate security associations (SAs), receiving an initiation request from the second electronic device at the first electronic device, the initiation request being associated with a capability notification that the second electronic device is capable of early detection of duplicate SAs, determining a possibility of duplicate SAs by the first electronic device, transmitting responses configured to prevent duplicate SAs from the first electronic device to the second electronic device, receiving responses at the first electronic device from the second electronic device, wherein the responses indicate no duplicate SAs created by the second electronic device, and establishing a non-duplicate SA for the first and second electronic devices.