Adaptive Encryption for SD-WAN Header-less Tunnel Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Double encryption of internet traffic in software-defined wide area networks (SD-WANs) leads to performance degradation and reduced throughput due to unnecessary encryption of already encrypted traffic.

Innovation Solution

Implementing adaptive encryption by identifying encrypted conversational flows and routing them over a header-less tunnel when the duration exceeds a threshold, instead of using an SD-WAN IPsec tunnel, which allows for improved performance and throughput by avoiding redundant encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted traffic is routed over an SD-WAN IPsec tunnel, then security is maintained, but performance and throughput degrade due to double encryption

Engineering Contradiction:
ImprovesecurityVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different tunnel types based on the encryption status of the traffic flow. Encrypted flows are routed over header-less tunnels to avoid double encryption, while unencrypted flows use IPsec tunnels for security. This local differentiation resolves the contradiction by optimizing each flow's path according to its specific security requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically determines whether to use an IPsec tunnel or a header-less tunnel based on real-time analysis of the conversational flow's encryption status. The router examines packet characteristics and flow duration to adaptively select the appropriate tunnel type, allowing the system to switch between security-focused and performance-focused modes as needed.

Inventive Principle:
Principle #15Dynamics

2Reliability

If encrypted traffic is routed over an SD-WAN IPsec tunnel, then security protocols are followed, but operational efficiency decreases due to redundant encryption processing

Engineering Contradiction:
Improvesecurity protocol complianceVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the tunnel type parameter based on the encryption status of the traffic. By detecting whether a flow is already encrypted and adjusting the tunnel selection accordingly (IPsec for unencrypted, header-less for encrypted), the system maintains security protocol compliance for unencrypted traffic while eliminating redundant encryption processing for already-encrypted traffic, thereby improving operational efficiency.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system segments traffic flows into two categories: encrypted and unencrypted. Each segment is then routed through the appropriate tunnel type. This segmentation allows the system to apply security protocols only where necessary while avoiding redundant processing, thus resolving the contradiction between security compliance and operational efficiency.

Inventive Principle:
Principle #1Segmentation

3Reliability

If all traffic is encrypted through IPsec tunnel, then security is ensured, but link-bandwidth and throughput are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidlink-bandwidth
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adapts the encryption approach based on the incoming traffic's encryption status. For traffic that is already encrypted, the system switches to a header-less tunnel that does not apply additional IPsec encryption, thereby preserving link-bandwidth and throughput while maintaining security. For unencrypted traffic, IPsec encryption is applied to ensure security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240422140A1System and Method for Adaptive Encryption for SD-WAN
Publication Date: 2024.12.19 CISCO TECHNOLOGY INC
  • US20240422140A1 patent drawing
  • US20240422140A1 patent drawing
  • US20240422140A1 patent drawing

AI summary

A system and method for adaptive encryption for SD-WAN includes identifying an encrypted conversational flow and determining whether a duration of the encrypted conversational flow exceeds a threshold. The method also includes selecting a header-less tunnel for the encrypted conversational flow when the duration is more than the threshold. The method further includes transmitting the encrypted conversational flow to an egress router over the selected header-less tunnel.