Reverse Crypto Map for Simplified Multi-Tenant Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption schemes for protecting data transmitted across networks, such as VPNs and VLANs, often require complex configuration and management, particularly at customer edge devices, which can lead to increased costs and security risks due to the need for multiple devices to handle encryption and decryption processes.

Innovation Solution

Implementing a reverse cryptographic map (reverse crypto map) on provider edge devices to handle encryption and decryption, reducing the complexity and number of devices needed for customer edge devices and allowing full management by the service provider, while maintaining security by limiting access to the group key and policy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and decryption are handled at customer edge devices, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption and decryption functions from customer edge devices and relocates them to provider edge devices. This is achieved by implementing a reverse cryptographic map at the provider edge, which handles all cryptographic operations centrally, thereby reducing complexity at customer premises while maintaining security through provider-controlled key management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The provider edge device acts as an intermediary between customer edge devices and the encryption/decryption process. The reverse cryptographic map at the provider edge mediates all cryptographic operations, allowing customer devices to simply forward encrypted traffic without needing to perform complex cryptographic functions themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple customer edge devices handle encryption, then security is improved, but cost and management complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges multiple encryption/decryption functions into a single centralized location at the provider edge device. Instead of requiring multiple customer edge devices to perform cryptographic operations, all encryption and decryption is combined and handled by the reverse cryptographic map at the provider edge, reducing the number of required devices and associated costs.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The provider edge device is designed to perform multiple functions including routing, encryption, and decryption through the reverse cryptographic map. This multi-functional approach eliminates the need for dedicated encryption appliances at customer premises, reducing overall system cost while maintaining security through a unified security model.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If customer edge devices are configured with encryption, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The reverse cryptographic map at the provider edge automatically performs encryption and decryption operations without requiring manual configuration or intervention at customer edge devices. The system self-manages the cryptographic processes, simplifying operation for customers while maintaining strong security through automated key management and encryption/decryption at the provider edge.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9258282B2Simplified mechanism for multi-tenant encrypted virtual networks
Publication Date: 2016.02.09 CISCO TECHNOLOGY INC
  • US9258282B2 patent drawing
  • US9258282B2 patent drawing
  • US9258282B2 patent drawing

AI summary

The present disclosure provides protection of customer data traveling across a network. A reverse cryptographic map (also referred to herein as a reverse crypto map) can be defined for a customer, where the reverse crypto map indicates how customer data should be protected. A reverse crypto map for a customer is applied to an interface of an edge device that is coupled to that customer's private subnet (or customer-facing interface). A reverse crypto map can be configured by a network administrator on a provider edge device, or can be pushed from a key server as part of group policy. A provider edge device can protect customer data by encrypting and decrypting the customer data according to the reverse crypto map. A provider edge device can also be configured with virtual routing and forwarding (VRF) tables that can be used to forward the VPN traffic flow across a provider network.