Packet Proxy Encryptor for Secure VPN Control Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN technologies fail to secure control traffic across public networks, making them unsuitable for sensitive applications as control packets are unencrypted and vulnerable to unauthorized analysis.

Innovation Solution

A system and method for providing packet proxy services across virtual private networks, utilizing an encryptor element to receive and regenerate packets with altered source and destination addresses, ensuring secure communication by encrypting control messages and maintaining complex forwarding state information on encryptor network elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If control packets are exchanged across the public network without encryption, then routing and control traffic can be transmitted efficiently, but security is compromised and traffic analysis becomes possible

Engineering Contradiction:
Improverouting and control traffic transmission efficiencyVSAvoidtraffic analysis vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary mechanism where edge routers generate synthetic control packets that appear to originate from themselves rather than from private network hosts. These synthetic packets serve as mediators that carry routing information while masking the actual private network traffic patterns, thereby enabling efficient control traffic transmission while preventing traffic analysis by unauthorized persons.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If encryption protocols are applied to control packets, then security is improved, but complexity of the system increases

Engineering Contradiction:
Improvecontrol traffic securityVSAvoidencryption protocol complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent extracts the encryption function from the control packet processing by introducing a separate encryptor network element. This dedicated element handles all encryption operations for control traffic, allowing the main routing system to remain relatively simple while still providing secure control traffic transmission. The encryptor acts as a standalone security layer that can be independently configured and maintained.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If complex forwarding state information is maintained on encryptor network elements, then secure communication is achieved, but processing requirements and device complexity increase

Engineering Contradiction:
Improvesecure communication capabilityVSAvoidforwarding state information complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the encryptor network element multi-functional by having it perform both encryption operations and forwarding state management. This universal approach consolidates multiple functions into a single element, reducing the overall system complexity while maintaining secure communication capability. The encryptor handles diverse traffic types and routing scenarios through a unified processing architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8582468B2System and method for providing packet proxy services across virtual private networks
Publication Date: 2013.11.12 CISCO TECHNOLOGY INC
  • US8582468B2 patent drawing
  • US8582468B2 patent drawing
  • US8582468B2 patent drawing

AI summary

A method is provided for proxy services between a public network and a private network. Such a method includes receiving a first packet having a destination address and a first source address; generating a second packet having the destination address and a second source address; and transmitting the second packet.