Multi-access Interface Driver for IPsec Tunnel Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network implementations face challenges in enabling a large number of systems to communicate directly using IPsec to protect traffic between them, particularly in terms of memory capacity and efficient network communication.

Innovation Solution

The method involves storing VPN topology in a routing table and implementing Level 2-type multicast delivery through a collection of Level 3 tunnels, along with providing a multi-access interface as a VPN interface with dynamic peer resolving, using a multi-access interface driver to enhance network communication efficiency and effectiveness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing IPsec implementations are used to enable direct communication between a large number of systems, then network security is provided, but memory requirements increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidmemory requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces a multi-access interface driver as an intermediary layer between the network interface and IPsec tunnels. This driver maintains a routing table that maps destination addresses to appropriate tunnels, eliminating the need for each system to maintain direct IPsec relationships with all other systems. The intermediary driver handles the complexity of multiple tunnel management, reducing memory requirements while maintaining security through centralized routing decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network communication into multiple logical layers: the multi-access interface driver layer that handles routing table lookups and tunnel selection, and the IPsec tunnel layer that handles encrypted communication. This segmentation allows the system to manage large numbers of connections through a centralized routing structure rather than requiring each endpoint to maintain all connection states in memory.

Inventive Principle:
Principle #1Segmentation

2Reliability

If direct IPsec communication is implemented between all systems, then secure point-to-point communication is achieved, but network communication efficiency decreases

Engineering Contradiction:
Improvesecure communicationVSAvoidnetwork communication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple IPsec tunnels into a single multi-access interface that appears as one network interface to upper layers. This consolidation allows the system to manage multiple secure tunnels through a unified interface with a single routing table, improving communication efficiency by eliminating the need for separate processing of each tunnel while maintaining secure point-to-point communication through the underlying tunnel structure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The multi-access interface driver provides universal functionality by handling routing decisions for multiple different tunnels through a single interface. Rather than requiring separate interface handling for each tunnel, the driver universally manages all tunnel communications through its routing table, improving efficiency while maintaining the security properties of individual tunnels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple IPsec tunnels are maintained for high availability communication, then communication reliability between endpoints is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication availabilityVSAvoidtunnel management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The multi-access interface driver acts as an intermediary that manages the complexity of multiple tunnels. It maintains a routing table that automatically determines which tunnel to use for each destination, abstracting away the complexity of tunnel management from the rest of the system. This intermediary layer provides high availability through multiple tunnels while hiding the complexity of tunnel selection and management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The routing table in the multi-access interface driver provides self-service functionality by automatically determining the appropriate tunnel for each destination address without requiring manual configuration or complex decision logic. The system self-manages the complexity of multiple tunnel relationships through automated routing table lookups, reducing the perceived complexity for users while maintaining high availability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11888818B2Multi-access interface for internet protocol security
Publication Date: 2024.01.30 FORCEPOINT LLC
  • US11888818B2 patent drawing
  • US11888818B2 patent drawing
  • US11888818B2 patent drawing

AI summary

A method may include providing a multi-access interface for network traffic, comprising: receiving information regarding topology of a virtual private network and storing the topology in the form of a routing table. A method may include providing an interface for network traffic, comprising: in a virtual private network comprising a plurality of tunnels delivering only information associated with OSI Level 3, receiving a network communication and performing multicast forwarding among the plurality of tunnels using multicast forwarding from OSI Level 2. A method may include providing an interface for network traffic, comprising, in a virtual private network: establishing a connection between a first node of the virtual private network and a second node serving as a virtual private network broker and fetching, by the first node from the virtual private network broker, information regarding one or more other nodes of the virtual private network.