ISAKMP Tagged Security Attributes Bypass Gateway Reprogramming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing ISAKMP Config Mode processes require reprogramming of security gateways for new security attributes, which is inefficient and difficult to synchronize across different devices and software versions, especially when these attributes do not affect the security association between the gateway and client.
Innovation Solution
Introducing a generic security configuration attribute type in ISAKMP messages that allows the security policy server and client to extend security policy attributes without modifying the gateway, by using a 'CFG_MODE_GENERIC_ATT' tag that passes opaque data through the gateway, enabling additional security attributes like firewall policies and software updates without interpretation by the gateway.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If security gateways are reprogrammed for new security attributes, then the gateway can handle extended security policies, but the device complexity and synchronization difficulty increase
Solution Approach 1:
The patent segments the security attribute handling into two parts: standard security attributes are processed by the gateway, while extended security attributes are encapsulated in a separate container and passed through the gateway without interpretation. This segmentation allows the gateway to remain unchanged while still supporting extended attributes.
Solution Approach 2:
The patent introduces an intermediary mechanism where the client directly communicates extended security attributes to the policy server through the gateway without the gateway interpreting them. The gateway acts as a transparent intermediary that forwards these attributes, eliminating the need for gateway reprogramming.
2Adaptability or versatility
If security gateways are reprogrammed for new security attributes, then the gateway can process extended policies, but the time required for updates and synchronization increases
Solution Approach 1:
By segmenting attribute handling, the patent enables extended security attributes to be processed without gateway updates. The client and policy server handle the extended attributes directly, eliminating time-consuming gateway reprogramming and synchronization processes.
Solution Approach 2:
The gateway serves as a transparent intermediary that forwards extended security attributes without interpreting or processing them. This eliminates the need for gateway software updates, significantly reducing update and synchronization time across the network.
3Reliability
If the gateway interprets and processes all security attributes, then the gateway has full control over security policies, but the gateway cannot remain unchanged when new attributes are added
Solution Approach 1:
The patent applies local quality by differentiating how different attribute types are handled: standard security attributes are interpreted and processed by the gateway to maintain control, while extended security attributes are passed through without interpretation, allowing the gateway to remain unchanged.
Solution Approach 2:
The gateway acts as an intermediary that maintains its existing control over standard security attributes while transparently forwarding extended attributes to the policy server, allowing the gateway to remain unchanged despite new attribute additions.
Data Source
AI summary
Techniques for passing security configuration information between a security policy server and a client includes the client forming a request for security configuration information that configures the client for secure communications. The client is separated by an untrusted network from a trusted network that includes the security policy sever. A tag is generated that indicates a generic security configuration attribute. An Internet Security Association and Key Management Protocol (ISAKMP) configuration mode request message is sent to a security gateway on an edge of the trusted network connected to the untrusted network. The message includes the request in association with the tag. The gateway sends the request associated with the tag to the security policy server on the trusted network and does not interpret the request. The techniques allow client configuration extensions to be added by modifying the policy server or security client, or both, without modifying the gateway.


