LISP Map-Request Key Refreshing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Virtual Private Network (VPN) technologies face complexity and latency issues due to the additional control plane required for Peer Introduction Protocol (PIP) exchanges, especially when used with IPsec and Locator/ID Separation Protocol (LISP) systems, which can lead to unsynchronized state settings and increased latency in establishing secure connections.

Innovation Solution

The proposed solution integrates a centralized key management (CKM) method with the LISP control plane, using a Map-Request/Map-Reply protocol to exchange cryptographic identities and nonces, eliminating the need for a separate PIP exchange and synchronizing mapping and keying information within the same message flow.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Peer Introduction Protocol (PIP) exchanges are used with IPsec and LISP systems, then secure connections can be established, but system complexity increases due to additional control plane requirements

Engineering Contradiction:
Improvesecure connection establishmentVSAvoidcontrol plane complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the PIP exchange process with the LISP Map-Request/Map-Reply protocol flow. Specifically, the peer introduction request is embedded within the Map-Request message, and the peer introduction reply is embedded within the Map-Reply message. This merging eliminates the need for separate PIP control plane messages, reducing system complexity while maintaining secure connection establishment.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If separate PIP exchange is implemented, then key material can be exchanged, but latency increases due to additional message flows

Engineering Contradiction:
Improvekey material exchangeVSAvoidconnection setup latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the key material exchange process into the LISP mapping protocol by embedding peer introduction requests and replies within Map-Request and Map-Reply messages. This integration allows key material to be exchanged simultaneously with mapping information, eliminating the need for separate PIP exchange message flows and reducing connection setup latency.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of manufacture

If separate PIP exchange and mapping protocols are used, then protocol functions are separated, but synchronization issues arise between control plane states

Engineering Contradiction:
Improveprotocol modularityVSAvoidstate synchronization
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent combines the PIP exchange and LISP mapping protocols into a unified message flow. The peer introduction request is included in the Map-Request, and the peer introduction reply is included in the Map-Reply. This merging ensures that mapping state and keying state are established simultaneously and remain synchronized, eliminating the desynchronization issues that arise from separate protocol exchanges.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10439993B2Mapping system assisted key refreshing
Publication Date: 2019.10.08 CISCO TECHNOLOGY INC
  • US10439993B2 patent drawing
  • US10439993B2 patent drawing
  • US10439993B2 patent drawing

AI summary

Presented herein is a system to set up a secure connection between nodes on two enterprise networks across a public network. The system includes a network element associated with each enterprise network. The first network element transmits a map request to a mapping server. The map request includes a destination address on the second enterprise network and a peer introduction request. The first network element includes a first key generation material in the peer introduction request. The second network element is configured to receive the map request forwarded from the mapping server, generate a map reply corresponding to the map request, and transmit the map reply to the first network element. The map reply includes a peer introduction reply with a second key generation material. The first network generates a secure key by inserting the second key generation material into a first key derivation function.