Network Service Header Security via Selective Authentication Tags

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service Function Chaining (SFC) networks face challenges in securing Network Service Headers (NSH) due to unauthenticated and unencrypted metadata, which requires additional security measures like IPsec for transport encapsulation, but these solutions are not scalable for dynamic service function paths and credential management.

Innovation Solution

A network service packet header security system that includes an NSH imposer, a key management service, and service functions, which analyzes packets, identifies security functions, requests and applies encryption keys, and generates authentication tags to secure NSH data, using a ticket-based key management system to ensure only authorized service functions access encrypted metadata.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If transport encapsulation features like IPsec are used to secure NSH data, then security is improved, but scalability and adaptability to dynamic service function paths deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security mechanism into modular components: authentication tags are applied selectively to specific NSH fields rather than requiring full packet encryption. This allows individual fields to be secured based on their sensitivity and the specific service function path requirements, enabling scalable security that adapts to dynamic service chains without requiring comprehensive re-encryption of all data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security treatments to different parts of the NSH structure. Critical fields such as service path identifier and metadata are authenticated using security tags, while other fields may remain unauthenticated. This local quality approach allows the system to provide security where needed while maintaining scalability and avoiding the overhead of encrypting entire packets, thus resolving the contradiction between security and adaptability.

Inventive Principle:
Principle #3Local quality

2Reliability

If authentication and encryption are applied to NSH metadata, then security is improved, but processing complexity and overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements partial authentication by applying security tags only to critical NSH fields rather than authenticating the entire packet. This partial action approach provides sufficient security for the most important metadata fields while significantly reducing processing complexity and overhead compared to full packet authentication, thus resolving the contradiction between security and processing complexity.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If credentials are pre-distributed to service functions, then security is improved, but adaptability to dynamic service function paths deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability to dynamic paths
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security tagging where authentication tags are applied to NSH fields based on the specific service function path being traversed. Rather than pre-distributing static credentials, the system dynamically determines which fields require authentication for each service function path, allowing the security mechanism to adapt to dynamic service chains while maintaining strong security through context-aware authentication tag application.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9912480B2Network service packet header security
Publication Date: 2018.03.06 CISCO TECHNOLOGY INC
  • US9912480B2 patent drawing
  • US9912480B2 patent drawing
  • US9912480B2 patent drawing

AI summary

A network service packet (NSP) header security method includes receiving an NSP on a communication interface, analyzing, by a processor, the NSP in order to identify a plurality of service functions and an associated service function path for the plurality of service functions, identifying, by the processor, which security function or functions may be performed by each of the plurality of service functions on an NSP header to be generated for the NSP, requesting, by the processor, at least one key for securing at least part of the NSP header, receiving the at least one key on the communication interface, generating, by the processor, the NSP header for the NSP, securing, by the processor, the NSP header based on the at least one key, and sending, on the communication interface, the NSP with the NSP header to one of the plurality of service functions.