Pre-negotiated Security Associations for Router Switchover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In networks with redundancy mechanisms, the switchover delay for secure data exchange between inactive and active routers can exceed seconds due to the need for re-establishing Security Associations (SAs) after a core router failure, leading to increased downtime.

Innovation Solution

Establishing pre-negotiated security parameters using a network layer protocol, such as IKE, between an inactive router and site routers via an indirect path, allowing for immediate secure data exchange upon failure of the active router.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Security Associations are established between inactive router and site routers only upon switchover, then security is maintained, but switchover delay increases

Engineering Contradiction:
ImprovesecurityVSAvoidswitchover delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by establishing Security Associations between the inactive router and site routers before the active router fails. The inactive router proactively negotiates security parameters with site routers while it is in standby mode, so that when a switchover occurs, secure data exchange can resume immediately without waiting for post-failure SA establishment. This resolves the contradiction by preparing security credentials in advance, eliminating the delay between failure detection and secure communication resumption.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If pre-negotiated security parameters are established via indirect path, then switchover time is reduced, but network complexity increases

Engineering Contradiction:
Improveswitchover timeVSAvoidnetwork complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent uses the active router as an intermediary to facilitate pre-negotiation of security parameters between the inactive router and site routers. When the inactive router needs to establish Security Associations with site routers, it routes these negotiation messages through the currently active router, which forwards them appropriately. This intermediary approach allows the inactive router to prepare security credentials without requiring direct active data links to site routers, thereby reducing switchover time while managing network complexity through the existing active router infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2223463B1Method and system for secure exchange of data in a network
Publication Date: 2017.05.24 MOTOROLA SOLUTIONS INC
  • EP2223463B1 patent drawingFigure 1
  • EP2223463B1 patent drawingFigure 2
  • EP2223463B1 patent drawingFigure 3

AI summary

A first network device implements a method for the secure exchange of data in a network. The network also includes a second network device and a remote device. The method includes establishing (204) an indirect path to the remote device and pre-negotiating (206) first security parameters with the remote device over the indirect path using a network layer protocol, when the second network device has an active first data link. The method further includes establishing (208) an active second data link with the remote device and exchanging (210) first data with the remote device over the active second data link using the first security parameters, when the first data link becomes inactive.