Overlay Network Security Association Decoupling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In overlay networks, existing technologies face challenges in efficiently decoupling security associations from location mappings, particularly in scenarios involving mobility and multicast traffic, where frequent updates of mappings and security associations are required, leading to resource inefficiencies and potential security vulnerabilities.
Innovation Solution
The proposed solution involves maintaining separate caches for location mappings and security associations, allowing for independent updates of these caches on different schedules, enabling pairwise unidirectional key calculation and optimized cryptographic resource usage, especially in mobility scenarios, while supporting encryption for both unicast and multicast traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If separate caches for location mappings and security associations are maintained with independent update schedules, then network efficiency and security are improved, but device complexity increases
Solution Approach 1:
The patent divides the unified cache into two separate caches: a location mapping cache and a security association cache. This segmentation allows independent management and update schedules for each cache type, enabling optimized cryptographic resource usage and improved network efficiency without requiring simultaneous updates of all cached data.
Solution Approach 2:
The patent extracts the security association data from the location mapping cache, creating a separate security association cache. This extraction allows the system to independently update security associations without triggering unnecessary location mapping updates, reducing overall system complexity and improving operational efficiency.
2Reliability
If frequent updates of mappings and security associations are performed in overlay networks, then security is improved, but resource efficiency deteriorates
Solution Approach 1:
The patent implements dynamic update schedules for the two separate caches, allowing the location mapping cache and security association cache to be updated at different frequencies based on their respective requirements. This dynamic approach ensures security is maintained through timely updates while optimizing resource efficiency by avoiding unnecessary frequent updates of both caches simultaneously.
3Use of energy by moving object
If separate caches with independent update schedules are implemented, then cryptographic resource usage is optimized, but device complexity increases
Solution Approach 1:
By segmenting the cache structure into separate location mapping and security association caches, the system can apply different update frequencies and cryptographic operations to each cache type. This segmentation optimizes cryptographic resource usage by performing intensive cryptographic operations only when security associations need updating, rather than on every location mapping change.
Solution Approach 2:
The patent changes the update schedule parameter for different cache types, allowing location mappings to be updated more frequently than security associations. This parameter differentiation optimizes cryptographic resource usage by reducing the frequency of computationally intensive security association updates while maintaining current location information.
Data Source
AI summary
A first map request message is sent from a source network device to a mapping network device to determine a destination network device associated with a destination endpoint device and a security association between the source network device and the destination network device. A first response message is received at the source network device that includes data indicating a mapping between the destination network device and the destination endpoint device and data indicating a security association between the source network device and the destination network device. The data is stored at the source network device. A second map request message is sent from the source network device to the mapping network device to update the data indicative of the mapping or the security association. A second response message is received at the source network device from the mapping network device.


