QoS Control in Secure IPsec Networks via Header Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing Quality of Service (QoS) functions in secure communication networks, such as those using IPsec, is challenging due to encryption of packet header information, which prevents measurement of QoS performance and requires access to unencrypted data, compromising security and restricting communication across security barriers.

Innovation Solution

A method and system for performing QoS functions in secure networks by determining bandwidth allocation, communicating control information across security barriers, and modifying communication behavior, using techniques like packet order modulation and ECN bits to convey control information without breaching security protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If packet header information is encrypted to maintain security, then security is improved, but QoS performance measurement becomes impossible

Engineering Contradiction:
ImprovesecurityVSAvoidQoS performance measurement
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the packet into different parts with different security treatments. The payload is encrypted for security, while the header contains unencrypted QoS fields that allow performance measurement. This segmentation enables both security and QoS monitoring to coexist without compromising either.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary QoS monitoring mechanism that operates at the network layer using unencrypted header fields. This intermediary layer allows QoS performance measurement without requiring access to the encrypted payload, thus maintaining security while enabling measurement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access to unencrypted data is required for QoS management, then QoS management capability is improved, but network security is compromised

Engineering Contradiction:
ImproveQoS management capabilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by providing different levels of data accessibility in different parts of the packet. The header has high accessibility for QoS management purposes, while the payload maintains strong encryption for security. This localized differentiation allows QoS management without compromising overall security.

Inventive Principle:
Principle #3Local quality

3Reliability

If communication is restricted across security barriers to maintain security, then security integrity is improved, but QoS control information transmission is blocked

Engineering Contradiction:
Improvesecurity integrityVSAvoidQoS control information transmission
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent makes the security barrier universally permeable to specific unencrypted header fields while maintaining protection for encrypted data. The security infrastructure is designed to handle multiple functions: it blocks unauthorized access to encrypted payloads while simultaneously allowing passage of unencrypted QoS control information in header fields, thus achieving multi-functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8549135B1Method and apparatus for performing quality of service in secure networks
Publication Date: 2013.10.01 RAYTHEON CO
  • US8549135B1 patent drawing
  • US8549135B1 patent drawing
  • US8549135B1 patent drawing

AI summary

A method is provided for performing control functions in a secure network where security prohibits the transmission of control information beyond secure networks and/or their associated systems. A method is provided for permitting proxy servers to communicate within full DBRA schemes without compromising security. According to various embodiments, methods for IPsec communication are provided that permit systems to move information across secure gateways. In one embodiment, IPsec communication and full DBRA bandwidth/QoS control is provided without compromising security. Although various aspects relate to satellite networks, it should be appreciated that aspects relate to other types of secure networks.