Nested VPN Shared Rekey Service Architecture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing VPN systems require separate and independent rekey and consistency services for multiple VPNs, leading to increased complexity and operational burden in key management and security operations.
Innovation Solution
Implementing a common rekey and consistency service shared between nested VPNs, where a first key server generates and refreshes cryptographic keys for the first VPN and cooperates with a second key server to refresh keys for the second VPN, reducing the need for separate services and enhancing security through double-encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate and independent rekey and consistency services are used for multiple VPNs, then security and independence of each VPN is maintained, but system complexity and operational burden increase
Solution Approach 1:
The patent merges separate rekey services and consistency services into a shared common service infrastructure that can serve multiple nested VPNs simultaneously. The common rekey service distributes cryptographic keys to multiple VPNs through a unified mechanism, while the common consistency service maintains synchronization across key servers for multiple VPNs, thereby reducing system complexity while maintaining security through standardized protocols
Solution Approach 2:
The patent creates universal rekey and consistency services that can serve multiple different VPNs with different security requirements through a single infrastructure. The common service implements protocol translation and adaptation layers that allow it to accommodate various VPN types and security policies while maintaining a unified service architecture
2Adaptability or versatility
If separate rekey services are used for each VPN, then key management independence is maintained, but operational complexity increases
Solution Approach 1:
The patent segments the key management functionality into modular components within the common service architecture. Each VPN can have its own key generation policies and distribution mechanisms while sharing the underlying infrastructure. The service implements separate key derivation functions and distribution protocols for each VPN type while using a unified service framework, thereby maintaining independence without requiring separate operational systems
3Reliability
If independent consistency services are used for each VPN, then failover reliability is ensured, but system complexity increases
Solution Approach 1:
The patent combines multiple consistency services into a single common consistency service that handles failover for multiple nested VPNs. The service implements a unified synchronization protocol that can translate and adapt to different VPN requirements while maintaining a single infrastructure. Key servers for different VPNs can participate in a common failover mechanism where backup key servers can take over for multiple VPNs if primary servers fail, reducing the number of redundant components needed
Data Source
AI summary
First and second nested virtual private networks share a common rekey service. A first key server generates first cryptographic keys and policies for use by gateways of the VPN to encrypt and decrypt data packets. The key server establishes a connection with a second key server to generate second cryptographic keys and policies independently of the first key server for use by encryption units of a second VPN that is nested with and operates independently of the first VPN. The first key server refreshes the first cryptographic keys in the first VPN gateways using a common rekey service, and cooperates with the second key server to refresh the second cryptographic keys in the second VPN encryption units using the common rekey service.


