Merging Security and Serving Gateways to Reduce IPsec Overhead
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The LTE architecture's reliance on an all-IP infrastructure for cost-effective open IP transport introduces security vulnerabilities and additional IPsec overhead, particularly in tunnel mode operations, which can lower throughput and cause fragmentation issues.
Innovation Solution
A multi-purpose security gateway (MPSG) is introduced to combine Security GW and Serving GW functionalities, allowing negotiation to switch from tunnel mode to transport mode, reducing IPsec overhead while maintaining security by determining identical IP addresses and renegotiating the IPsec session.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If tunnel mode is used for IPsec security between eNB and Security GW, then security is ensured, but packet overhead increases and throughput decreases
Solution Approach 1:
The patent changes the operational parameter of IPsec from tunnel mode to transport mode. This parameter change reduces packet overhead by eliminating encapsulation/decapsulation operations while maintaining security through transport mode encryption, thereby improving throughput without sacrificing security
2Reliability
If tunnel mode is used for IPsec security, then security is provided, but additional processing overhead is introduced
Solution Approach 1:
The patent changes the operational parameter of IPsec from tunnel mode to transport mode. This parameter change reduces packet overhead by eliminating encapsulation/decapsulation operations while maintaining security through transport mode encryption, thereby improving throughput without sacrificing security
3Reliability
If Security GW and Serving GW are separate entities, then security functions are provided, but device complexity increases
Solution Approach 1:
The patent merges the Security Gateway and Serving Gateway into a single combined entity. This consolidation provides both security functions and serving gateway functions through one device, reducing network architecture complexity and the number of network nodes while maintaining all required functionalities
4Ease of manufacture
If open IP transport is used for backhaul, then cost is reduced, but security vulnerabilities are introduced
Solution Approach 1:
The patent uses IPsec encryption as an intermediary security layer over the open IP transport. This allows the system to benefit from cost-effective open IP backhaul while the IPsec tunnel mode or transport mode provides the necessary security protection, acting as a mediator between cost efficiency and security requirements
Data Source
AI summary
A first packet is received at a network element from an E-UTRAN Node B (eNB) of an E-UTRAN access network via a secured communications tunnel of a secured connection, where the first packet encapsulates a second packet therein. It is determined whether the network element serves both a security gateway functionality and a serving gateway functionality of a core packet network based on the first packet and the second packet. The network element negotiates with the eNB to switch further communications from a tunnel mode to a transport mode of the secured connection if it is determined that the network element serves both the security gateway functionality and the serving gateway functionality. Thereafter, the network element exchanges further packets with the eNB via the transport mode of the secured connection after the eNB switches from the tunnel mode to the transport mode.


