Per-Flow Symmetric Keying for Distributed Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security solutions for distributed networking, such as Software Defined Networking (SDN), face challenges including security vulnerabilities, computationally demanding operations, and cumbersome key distribution, particularly in large-scale and dynamic scenarios, where symmetric keying material distribution is inflexible and requires prior knowledge of network topology and communication patterns.
Innovation Solution
A method and system for providing symmetric keying material on a per-flow basis, where a network controller generates or selects symmetric keying material upon establishing a network flow, enabling secure communication between network endpoints without pre-provisioning, and allows for dynamic and automatic distribution, reducing computational demands and improving flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If symmetric keying material is pre-provisioned to network endpoints prior to communication, then security is established, but key distribution becomes cumbersome and inflexible in large-scale dynamic networks
Solution Approach 1:
The patent applies preliminary action by pre-establishing secure control channels between the network controller and network endpoints before actual data communication begins. During the flow setup phase, the controller generates and distributes symmetric keying material through these pre-established secure channels, eliminating the need for separate key distribution operations and making the system scalable to large networks.
Solution Approach 2:
The network controller serves as an intermediary that centralizes key management functions. Instead of requiring direct peer-to-peer key distribution between endpoints, the controller generates symmetric keying material and distributes it through secure control channels, simplifying key management in large-scale dynamic networks while maintaining security.
2Reliability
If cryptographic material is provisioned prior to virtual network endpoint instantiation, then security is ensured, but flexibility and adaptability to dynamic network conditions are reduced
Solution Approach 1:
The patent implements dynamics by generating symmetric keying material on-demand during the flow setup phase rather than pre-provisioning it. When a new network flow is established, the controller dynamically generates fresh symmetric keys and distributes them through secure control channels, allowing the system to adapt to dynamic network conditions, virtualization scenarios, and changing communication patterns while maintaining security.
3Reliability
If asymmetric public/private key pairs and digital certificates are used for secure communication, then security is established, but computational demands increase
Solution Approach 1:
The patent applies parameter changes by transitioning from asymmetric cryptography (public/private key pairs) to symmetric cryptography for data plane communication. The controller generates symmetric keying material and distributes it through secure control channels, leveraging the computational efficiency of symmetric algorithms while maintaining security through the layered approach of using asymmetric methods only for the control plane.
4Ease of operation
If cryptographic material is injected as files to filesystems for external provisioning, then key distribution is achieved, but device complexity and maintenance burden increase
Solution Approach 1:
The patent implements self-service by enabling the network controller to automatically generate and distribute symmetric keying material through secure control channels without requiring manual file injection or external provisioning systems. The controller autonomously manages the entire key distribution process, reducing device complexity and eliminating the need for separate key management infrastructure.
Data Source
AI summary
There is provided a method of operating a network controller for enabling secure communication between network endpoints in a distributed network, as well as a network controller and a network switch and a method of operating a network switch. The network controller has a secure channel with each of the network endpoints. The network controller is providing, in connection with establishment of a network flow for communication between the network endpoints, symmetric keying material associated with and valid only for that network flow. The network controller is further enabling provisioning of the symmetric keying material to the network endpoints for allowing cryptographically secure communication between the network endpoints on a per-flow basis.


