Nested VPN Shared Rekey Service Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN systems require separate and independent rekey and consistency services for multiple VPNs, leading to increased complexity and operational burden in key management and security operations.

Innovation Solution

Implementing a common rekey and consistency service shared between nested VPNs, where a first key server generates and refreshes cryptographic keys for the first VPN and cooperates with a second key server to refresh keys for the second VPN, reducing the need for separate services and enhancing security through double-encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate and independent rekey and consistency services are used for multiple VPNs, then security and independence of each VPN is maintained, but system complexity and operational burden increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges separate rekey services and consistency services into a shared common service infrastructure that can serve multiple nested VPNs simultaneously. The common rekey service distributes cryptographic keys to multiple VPNs through a unified mechanism, while the common consistency service maintains synchronization across key servers for multiple VPNs, thereby reducing system complexity while maintaining security through standardized protocols

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates universal rekey and consistency services that can serve multiple different VPNs with different security requirements through a single infrastructure. The common service implements protocol translation and adaptation layers that allow it to accommodate various VPN types and security policies while maintaining a unified service architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If separate rekey services are used for each VPN, then key management independence is maintained, but operational complexity increases

Engineering Contradiction:
Improvekey management independenceVSAvoidoperational complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the key management functionality into modular components within the common service architecture. Each VPN can have its own key generation policies and distribution mechanisms while sharing the underlying infrastructure. The service implements separate key derivation functions and distribution protocols for each VPN type while using a unified service framework, thereby maintaining independence without requiring separate operational systems

Inventive Principle:
Principle #1Segmentation

3Reliability

If independent consistency services are used for each VPN, then failover reliability is ensured, but system complexity increases

Engineering Contradiction:
Improvefailover reliabilityVSAvoidservice infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple consistency services into a single common consistency service that handles failover for multiple nested VPNs. The service implements a unified synchronization protocol that can translate and adapt to different VPN requirements while maintaining a single infrastructure. Key servers for different VPNs can participate in a common failover mechanism where backup key servers can take over for multiple VPNs if primary servers fail, reducing the number of redundant components needed

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9374340B2Nested independent virtual private networks with shared rekey and consistency services
Publication Date: 2016.06.21 CISCO TECHNOLOGY INC
  • US9374340B2 patent drawing
  • US9374340B2 patent drawing
  • US9374340B2 patent drawing

AI summary

First and second nested virtual private networks share a common rekey service. A first key server generates first cryptographic keys and policies for use by gateways of the VPN to encrypt and decrypt data packets. The key server establishes a connection with a second key server to generate second cryptographic keys and policies independently of the first key server for use by encryption units of a second VPN that is nested with and operates independently of the first VPN. The first key server refreshes the first cryptographic keys in the first VPN gateways using a common rekey service, and cooperates with the second key server to refresh the second cryptographic keys in the second VPN encryption units using the common rekey service.