LISP Map-Request Key Refreshing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Virtual Private Network (VPN) technologies face complexity and latency issues due to the additional control plane required for Peer Introduction Protocol (PIP) exchanges, especially when used with IPsec and Locator/ID Separation Protocol (LISP) systems, which can lead to unsynchronized state settings and increased latency in establishing secure connections.
Innovation Solution
The proposed solution integrates a centralized key management (CKM) method with the LISP control plane, using a Map-Request/Map-Reply protocol to exchange cryptographic identities and nonces, eliminating the need for a separate PIP exchange and synchronizing mapping and keying information within the same message flow.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Peer Introduction Protocol (PIP) exchanges are used with IPsec and LISP systems, then secure connections can be established, but system complexity increases due to additional control plane requirements
Solution Approach 1:
The patent combines the PIP exchange process with the LISP Map-Request/Map-Reply protocol flow. Specifically, the peer introduction request is embedded within the Map-Request message, and the peer introduction reply is embedded within the Map-Reply message. This merging eliminates the need for separate PIP control plane messages, reducing system complexity while maintaining secure connection establishment.
2Reliability
If separate PIP exchange is implemented, then key material can be exchanged, but latency increases due to additional message flows
Solution Approach 1:
The patent merges the key material exchange process into the LISP mapping protocol by embedding peer introduction requests and replies within Map-Request and Map-Reply messages. This integration allows key material to be exchanged simultaneously with mapping information, eliminating the need for separate PIP exchange message flows and reducing connection setup latency.
3Ease of manufacture
If separate PIP exchange and mapping protocols are used, then protocol functions are separated, but synchronization issues arise between control plane states
Solution Approach 1:
The patent combines the PIP exchange and LISP mapping protocols into a unified message flow. The peer introduction request is included in the Map-Request, and the peer introduction reply is included in the Map-Reply. This merging ensures that mapping state and keying state are established simultaneously and remain synchronized, eliminating the desynchronization issues that arise from separate protocol exchanges.
Data Source
AI summary
Presented herein is a system to set up a secure connection between nodes on two enterprise networks across a public network. The system includes a network element associated with each enterprise network. The first network element transmits a map request to a mapping server. The map request includes a destination address on the second enterprise network and a peer introduction request. The first network element includes a first key generation material in the peer introduction request. The second network element is configured to receive the map request forwarded from the mapping server, generate a map reply corresponding to the map request, and transmit the map reply to the first network element. The map reply includes a peer introduction reply with a second key generation material. The first network generates a secure key by inserting the second key generation material into a first key derivation function.


