Merging Security and Serving Gateways to Reduce IPsec Overhead

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The LTE architecture's reliance on an all-IP infrastructure for cost-effective open IP transport introduces security vulnerabilities and additional IPsec overhead, particularly in tunnel mode operations, which can lower throughput and cause fragmentation issues.

Innovation Solution

A multi-purpose security gateway (MPSG) is introduced to combine Security GW and Serving GW functionalities, allowing negotiation to switch from tunnel mode to transport mode, reducing IPsec overhead while maintaining security by determining identical IP addresses and renegotiating the IPsec session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tunnel mode is used for IPsec security between eNB and Security GW, then security is ensured, but packet overhead increases and throughput decreases

Engineering Contradiction:
ImprovesecurityVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the operational parameter of IPsec from tunnel mode to transport mode. This parameter change reduces packet overhead by eliminating encapsulation/decapsulation operations while maintaining security through transport mode encryption, thereby improving throughput without sacrificing security

Inventive Principle:
Principle #35Parameter changes

2Reliability

If tunnel mode is used for IPsec security, then security is provided, but additional processing overhead is introduced

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent changes the operational parameter of IPsec from tunnel mode to transport mode. This parameter change reduces packet overhead by eliminating encapsulation/decapsulation operations while maintaining security through transport mode encryption, thereby improving throughput without sacrificing security

Inventive Principle:
Principle #35Parameter changes

3Reliability

If Security GW and Serving GW are separate entities, then security functions are provided, but device complexity increases

Engineering Contradiction:
Improvesecurity functionalityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the Security Gateway and Serving Gateway into a single combined entity. This consolidation provides both security functions and serving gateway functions through one device, reducing network architecture complexity and the number of network nodes while maintaining all required functionalities

Inventive Principle:
Principle #5Merging (Combining)

4Ease of manufacture

If open IP transport is used for backhaul, then cost is reduced, but security vulnerabilities are introduced

Engineering Contradiction:
ImprovecostVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent uses IPsec encryption as an intermediary security layer over the open IP transport. This allows the system to benefit from cost-effective open IP backhaul while the IPsec tunnel mode or transport mode provides the necessary security protection, acting as a mediator between cost efficiency and security requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8423760B2Method and system for reducing packet overhead for an LTE architecture while securing traffic in an unsecured environment
Publication Date: 2013.04.16 MAVENIR SYST INC
  • US8423760B2 patent drawing
  • US8423760B2 patent drawing
  • US8423760B2 patent drawing

AI summary

A first packet is received at a network element from an E-UTRAN Node B (eNB) of an E-UTRAN access network via a secured communications tunnel of a secured connection, where the first packet encapsulates a second packet therein. It is determined whether the network element serves both a security gateway functionality and a serving gateway functionality of a core packet network based on the first packet and the second packet. The network element negotiates with the eNB to switch further communications from a tunnel mode to a transport mode of the secured connection if it is determined that the network element serves both the security gateway functionality and the serving gateway functionality. Thereafter, the network element exchanges further packets with the eNB via the transport mode of the secured connection after the eNB switches from the tunnel mode to the transport mode.