Partial Payload Encryption for IPSec Throughput

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional IPSec tunnel encryption methods are resource-intensive and bottlenecked by limited computing power, especially in remote AP or microbranch AP deployments, leading to performance issues with faster transmission rates.

Innovation Solution

Implementing a system that selectively encrypts only portions of network traffic payloads instead of the entire payload, using a tunnel management module, security level determination module, and encryption/decryption module to optimize encryption performance and conserve computing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional IPSec tunnel encryption methods are used to secure network traffic, then security is maintained, but computing resources and processing time are excessively consumed

Engineering Contradiction:
ImprovesecurityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent divides the network traffic into multiple segments or flows, applying different encryption methods to different segments. This allows critical traffic to receive full encryption while less critical traffic uses lighter encryption, reducing overall computing resource consumption while maintaining security for important data

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different encryption strengths or methods to different portions of network traffic based on local requirements. High-priority or sensitive traffic receives strong encryption, while routine traffic uses weaker encryption, optimizing the balance between security and resource usage

Inventive Principle:
Principle #3Local quality

2Reliability

If traditional IPSec tunnel encryption methods are used to secure network traffic, then security is maintained, but encryption throughput and performance are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidencryption throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments network traffic into multiple parallel encryption streams that can be processed simultaneously. This parallelization increases encryption throughput while maintaining security standards for each segment

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies encryption selectively to only the necessary portions of network traffic rather than encrypting everything at maximum strength. This partial action approach maintains adequate security while significantly improving encryption throughput and performance

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If full payload encryption is applied to all network traffic, then maximum security is achieved, but processing time and computational overhead increase significantly

Engineering Contradiction:
Improvesecurity levelVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides network traffic into segments and applies different processing times based on segment priority. Critical segments receive immediate full encryption, while non-critical segments are processed with lower priority, reducing overall processing time while maintaining security for important data

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different encryption intensities to different parts of the payload based on local security requirements. Only the necessary portions of each packet are encrypted at full strength, reducing processing time while maintaining adequate security

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12166745B2Performance improvement for encrypted traffic over IPSEC
Publication Date: 2024.12.10 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12166745B2 patent drawing
  • US12166745B2 patent drawing
  • US12166745B2 patent drawing

AI summary

A packet that includes a header and a payload can be acquired. A first portion of the payload can be selected such that the first portion that is smaller than the payload. The header and the first portion of the payload can be encrypted based on an encryption algorithm to generate an encrypted packet. The encrypted packet can be transmitted to a node on a network.