Reverse Crypto Map for Simplified Multi-Tenant Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current encryption schemes for protecting data transmitted across networks, such as VPNs and VLANs, often require complex configuration and management, particularly at customer edge devices, which can lead to increased costs and security risks due to the need for multiple devices to handle encryption and decryption processes.
Innovation Solution
Implementing a reverse cryptographic map (reverse crypto map) on provider edge devices to handle encryption and decryption, reducing the complexity and number of devices needed for customer edge devices and allowing full management by the service provider, while maintaining security by limiting access to the group key and policy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption and decryption are handled at customer edge devices, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the encryption and decryption functions from customer edge devices and relocates them to provider edge devices. This is achieved by implementing a reverse cryptographic map at the provider edge, which handles all cryptographic operations centrally, thereby reducing complexity at customer premises while maintaining security through provider-controlled key management.
Solution Approach 2:
The provider edge device acts as an intermediary between customer edge devices and the encryption/decryption process. The reverse cryptographic map at the provider edge mediates all cryptographic operations, allowing customer devices to simply forward encrypted traffic without needing to perform complex cryptographic functions themselves.
2Reliability
If multiple customer edge devices handle encryption, then security is improved, but cost and management complexity increase
Solution Approach 1:
The patent merges multiple encryption/decryption functions into a single centralized location at the provider edge device. Instead of requiring multiple customer edge devices to perform cryptographic operations, all encryption and decryption is combined and handled by the reverse cryptographic map at the provider edge, reducing the number of required devices and associated costs.
Solution Approach 2:
The provider edge device is designed to perform multiple functions including routing, encryption, and decryption through the reverse cryptographic map. This multi-functional approach eliminates the need for dedicated encryption appliances at customer premises, reducing overall system cost while maintaining security through a unified security model.
3Reliability
If customer edge devices are configured with encryption, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The reverse cryptographic map at the provider edge automatically performs encryption and decryption operations without requiring manual configuration or intervention at customer edge devices. The system self-manages the cryptographic processes, simplifying operation for customers while maintaining strong security through automated key management and encryption/decryption at the provider edge.
Data Source
AI summary
The present disclosure provides protection of customer data traveling across a network. A reverse cryptographic map (also referred to herein as a reverse crypto map) can be defined for a customer, where the reverse crypto map indicates how customer data should be protected. A reverse crypto map for a customer is applied to an interface of an edge device that is coupled to that customer's private subnet (or customer-facing interface). A reverse crypto map can be configured by a network administrator on a provider edge device, or can be pushed from a key server as part of group policy. A provider edge device can protect customer data by encrypting and decrypting the customer data according to the reverse crypto map. A provider edge device can also be configured with virtual routing and forwarding (VRF) tables that can be used to forward the VPN traffic flow across a provider network.


