Overlay Network Security Association Decoupling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In overlay networks, existing technologies face challenges in efficiently decoupling security associations from location mappings, particularly in scenarios involving mobility and multicast traffic, where frequent updates of mappings and security associations are required, leading to resource inefficiencies and potential security vulnerabilities.

Innovation Solution

The proposed solution involves maintaining separate caches for location mappings and security associations, allowing for independent updates of these caches on different schedules, enabling pairwise unidirectional key calculation and optimized cryptographic resource usage, especially in mobility scenarios, while supporting encryption for both unicast and multicast traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If separate caches for location mappings and security associations are maintained with independent update schedules, then network efficiency and security are improved, but device complexity increases

Engineering Contradiction:
Improvenetwork efficiencyVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent divides the unified cache into two separate caches: a location mapping cache and a security association cache. This segmentation allows independent management and update schedules for each cache type, enabling optimized cryptographic resource usage and improved network efficiency without requiring simultaneous updates of all cached data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the security association data from the location mapping cache, creating a separate security association cache. This extraction allows the system to independently update security associations without triggering unnecessary location mapping updates, reducing overall system complexity and improving operational efficiency.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If frequent updates of mappings and security associations are performed in overlay networks, then security is improved, but resource efficiency deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements dynamic update schedules for the two separate caches, allowing the location mapping cache and security association cache to be updated at different frequencies based on their respective requirements. This dynamic approach ensures security is maintained through timely updates while optimizing resource efficiency by avoiding unnecessary frequent updates of both caches simultaneously.

Inventive Principle:
Principle #15Dynamics

3Use of energy by moving object

If separate caches with independent update schedules are implemented, then cryptographic resource usage is optimized, but device complexity increases

Engineering Contradiction:
Improvecryptographic resource usageVSAvoiddevice complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

By segmenting the cache structure into separate location mapping and security association caches, the system can apply different update frequencies and cryptographic operations to each cache type. This segmentation optimizes cryptographic resource usage by performing intensive cryptographic operations only when security associations need updating, rather than on every location mapping change.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the update schedule parameter for different cache types, allowing location mappings to be updated more frequently than security associations. This parameter differentiation optimizes cryptographic resource usage by reducing the frequency of computationally intensive security association updates while maintaining current location information.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10917343B2Security association and location mapping decoupling in overlay networks
Publication Date: 2021.02.09 CISCO TECHNOLOGY INC
  • US10917343B2 patent drawing
  • US10917343B2 patent drawing
  • US10917343B2 patent drawing

AI summary

A first map request message is sent from a source network device to a mapping network device to determine a destination network device associated with a destination endpoint device and a security association between the source network device and the destination network device. A first response message is received at the source network device that includes data indicating a mapping between the destination network device and the destination endpoint device and data indicating a security association between the source network device and the destination network device. The data is stored at the source network device. A second map request message is sent from the source network device to the mapping network device to update the data indicative of the mapping or the security association. A second response message is received at the source network device from the mapping network device.