ISAKMP Tagged Security Attributes Bypass Gateway Reprogramming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ISAKMP Config Mode processes require reprogramming of security gateways for new security attributes, which is inefficient and difficult to synchronize across different devices and software versions, especially when these attributes do not affect the security association between the gateway and client.

Innovation Solution

Introducing a generic security configuration attribute type in ISAKMP messages that allows the security policy server and client to extend security policy attributes without modifying the gateway, by using a 'CFG_MODE_GENERIC_ATT' tag that passes opaque data through the gateway, enabling additional security attributes like firewall policies and software updates without interpretation by the gateway.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security gateways are reprogrammed for new security attributes, then the gateway can handle extended security policies, but the device complexity and synchronization difficulty increase

Engineering Contradiction:
Improvegateway capability for extended security attributesVSAvoidgateway reprogramming complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security attribute handling into two parts: standard security attributes are processed by the gateway, while extended security attributes are encapsulated in a separate container and passed through the gateway without interpretation. This segmentation allows the gateway to remain unchanged while still supporting extended attributes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the client directly communicates extended security attributes to the policy server through the gateway without the gateway interpreting them. The gateway acts as a transparent intermediary that forwards these attributes, eliminating the need for gateway reprogramming.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If security gateways are reprogrammed for new security attributes, then the gateway can process extended policies, but the time required for updates and synchronization increases

Engineering Contradiction:
Improvegateway capability for extended security attributesVSAvoidgateway update and synchronization time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

By segmenting attribute handling, the patent enables extended security attributes to be processed without gateway updates. The client and policy server handle the extended attributes directly, eliminating time-consuming gateway reprogramming and synchronization processes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway serves as a transparent intermediary that forwards extended security attributes without interpreting or processing them. This eliminates the need for gateway software updates, significantly reducing update and synchronization time across the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the gateway interprets and processes all security attributes, then the gateway has full control over security policies, but the gateway cannot remain unchanged when new attributes are added

Engineering Contradiction:
Improvegateway control over security policiesVSAvoidgateway flexibility for new attributes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by differentiating how different attribute types are handled: standard security attributes are interpreted and processed by the gateway to maintain control, while extended security attributes are passed through without interpretation, allowing the gateway to remain unchanged.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The gateway acts as an intermediary that maintains its existing control over standard security attributes while transparently forwarding extended attributes to the policy server, allowing the gateway to remain unchanged despite new attribute additions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7849495B1Method and apparatus for passing security configuration information between a client and a security policy server
Publication Date: 2010.12.07 CISCO TECHNOLOGY INC
  • US7849495B1 patent drawing
  • US7849495B1 patent drawing
  • US7849495B1 patent drawing

AI summary

Techniques for passing security configuration information between a security policy server and a client includes the client forming a request for security configuration information that configures the client for secure communications. The client is separated by an untrusted network from a trusted network that includes the security policy sever. A tag is generated that indicates a generic security configuration attribute. An Internet Security Association and Key Management Protocol (ISAKMP) configuration mode request message is sent to a security gateway on an edge of the trusted network connected to the untrusted network. The message includes the request in association with the tag. The gateway sends the request associated with the tag to the security policy server on the trusted network and does not interpret the request. The techniques allow client configuration extensions to be added by modifying the policy server or security client, or both, without modifying the gateway.