Per-Flow Symmetric Keying for Distributed Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for distributed networking, such as Software Defined Networking (SDN), face challenges including security vulnerabilities, computationally demanding operations, and cumbersome key distribution, particularly in large-scale and dynamic scenarios, where symmetric keying material distribution is inflexible and requires prior knowledge of network topology and communication patterns.

Innovation Solution

A method and system for providing symmetric keying material on a per-flow basis, where a network controller generates or selects symmetric keying material upon establishing a network flow, enabling secure communication between network endpoints without pre-provisioning, and allows for dynamic and automatic distribution, reducing computational demands and improving flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If symmetric keying material is pre-provisioned to network endpoints prior to communication, then security is established, but key distribution becomes cumbersome and inflexible in large-scale dynamic networks

Engineering Contradiction:
ImprovesecurityVSAvoidkey distribution
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-establishing secure control channels between the network controller and network endpoints before actual data communication begins. During the flow setup phase, the controller generates and distributes symmetric keying material through these pre-established secure channels, eliminating the need for separate key distribution operations and making the system scalable to large networks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network controller serves as an intermediary that centralizes key management functions. Instead of requiring direct peer-to-peer key distribution between endpoints, the controller generates symmetric keying material and distributes it through secure control channels, simplifying key management in large-scale dynamic networks while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic material is provisioned prior to virtual network endpoint instantiation, then security is ensured, but flexibility and adaptability to dynamic network conditions are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamics by generating symmetric keying material on-demand during the flow setup phase rather than pre-provisioning it. When a new network flow is established, the controller dynamically generates fresh symmetric keys and distributes them through secure control channels, allowing the system to adapt to dynamic network conditions, virtualization scenarios, and changing communication patterns while maintaining security.

Inventive Principle:
Principle #15Dynamics

3Reliability

If asymmetric public/private key pairs and digital certificates are used for secure communication, then security is established, but computational demands increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational demand
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies parameter changes by transitioning from asymmetric cryptography (public/private key pairs) to symmetric cryptography for data plane communication. The controller generates symmetric keying material and distributes it through secure control channels, leveraging the computational efficiency of symmetric algorithms while maintaining security through the layered approach of using asymmetric methods only for the control plane.

Inventive Principle:
Principle #35Parameter changes

4Ease of operation

If cryptographic material is injected as files to filesystems for external provisioning, then key distribution is achieved, but device complexity and maintenance burden increase

Engineering Contradiction:
Improvekey distributionVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the network controller to automatically generate and distribute symmetric keying material through secure control channels without requiring manual file injection or external provisioning systems. The controller autonomously manages the entire key distribution process, reducing device complexity and eliminating the need for separate key management infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11831622B2Security for distributed networking
Publication Date: 2023.11.28 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11831622B2 patent drawing
  • US11831622B2 patent drawing
  • US11831622B2 patent drawing

AI summary

There is provided a method of operating a network controller for enabling secure communication between network endpoints in a distributed network, as well as a network controller and a network switch and a method of operating a network switch. The network controller has a secure channel with each of the network endpoints. The network controller is providing, in connection with establishment of a network flow for communication between the network endpoints, symmetric keying material associated with and valid only for that network flow. The network controller is further enabling provisioning of the symmetric keying material to the network endpoints for allowing cryptographically secure communication between the network endpoints on a per-flow basis.