QoS Control in Secure IPsec Networks via Header Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing Quality of Service (QoS) functions in secure communication networks, such as those using IPsec, is challenging due to encryption of packet header information, which prevents measurement of QoS performance and requires access to unencrypted data, compromising security and restricting communication across security barriers.
Innovation Solution
A method and system for performing QoS functions in secure networks by determining bandwidth allocation, communicating control information across security barriers, and modifying communication behavior, using techniques like packet order modulation and ECN bits to convey control information without breaching security protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packet header information is encrypted to maintain security, then security is improved, but QoS performance measurement becomes impossible
Solution Approach 1:
The patent segments the packet into different parts with different security treatments. The payload is encrypted for security, while the header contains unencrypted QoS fields that allow performance measurement. This segmentation enables both security and QoS monitoring to coexist without compromising either.
Solution Approach 2:
The patent introduces an intermediary QoS monitoring mechanism that operates at the network layer using unencrypted header fields. This intermediary layer allows QoS performance measurement without requiring access to the encrypted payload, thus maintaining security while enabling measurement.
2Ease of operation
If access to unencrypted data is required for QoS management, then QoS management capability is improved, but network security is compromised
Solution Approach 1:
The patent applies local quality by providing different levels of data accessibility in different parts of the packet. The header has high accessibility for QoS management purposes, while the payload maintains strong encryption for security. This localized differentiation allows QoS management without compromising overall security.
3Reliability
If communication is restricted across security barriers to maintain security, then security integrity is improved, but QoS control information transmission is blocked
Solution Approach 1:
The patent makes the security barrier universally permeable to specific unencrypted header fields while maintaining protection for encrypted data. The security infrastructure is designed to handle multiple functions: it blocks unauthorized access to encrypted payloads while simultaneously allowing passage of unencrypted QoS control information in header fields, thus achieving multi-functionality.
Data Source
AI summary
A method is provided for performing control functions in a secure network where security prohibits the transmission of control information beyond secure networks and/or their associated systems. A method is provided for permitting proxy servers to communicate within full DBRA schemes without compromising security. According to various embodiments, methods for IPsec communication are provided that permit systems to move information across secure gateways. In one embodiment, IPsec communication and full DBRA bandwidth/QoS control is provided without compromising security. Although various aspects relate to satellite networks, it should be appreciated that aspects relate to other types of secure networks.


