Pre-negotiated Security Associations for Router Switchover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In networks with redundancy mechanisms, the switchover delay for secure data exchange between inactive and active routers can exceed seconds due to the need for re-establishing Security Associations (SAs) after a core router failure, leading to increased downtime.
Innovation Solution
Establishing pre-negotiated security parameters using a network layer protocol, such as IKE, between an inactive router and site routers via an indirect path, allowing for immediate secure data exchange upon failure of the active router.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Security Associations are established between inactive router and site routers only upon switchover, then security is maintained, but switchover delay increases
Solution Approach 1:
The patent applies preliminary action by establishing Security Associations between the inactive router and site routers before the active router fails. The inactive router proactively negotiates security parameters with site routers while it is in standby mode, so that when a switchover occurs, secure data exchange can resume immediately without waiting for post-failure SA establishment. This resolves the contradiction by preparing security credentials in advance, eliminating the delay between failure detection and secure communication resumption.
2Loss of time
If pre-negotiated security parameters are established via indirect path, then switchover time is reduced, but network complexity increases
Solution Approach 1:
The patent uses the active router as an intermediary to facilitate pre-negotiation of security parameters between the inactive router and site routers. When the inactive router needs to establish Security Associations with site routers, it routes these negotiation messages through the currently active router, which forwards them appropriately. This intermediary approach allows the inactive router to prepare security credentials without requiring direct active data links to site routers, thereby reducing switchover time while managing network complexity through the existing active router infrastructure.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A first network device implements a method for the secure exchange of data in a network. The network also includes a second network device and a remote device. The method includes establishing (204) an indirect path to the remote device and pre-negotiating (206) first security parameters with the remote device over the indirect path using a network layer protocol, when the second network device has an active first data link. The method further includes establishing (208) an active second data link with the remote device and exchanging (210) first data with the remote device over the active second data link using the first security parameters, when the first data link becomes inactive.