Hierarchical SD-WAN IPSec Optimization via Edge Router Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional WAN architectures are limited in available bandwidth, security, and complexity management, which hinders business productivity, especially in mobile and cloud-based environments. In hierarchical SD-WAN, intermediate border routers face high IPSec throughput requirements, leading to increased costs and inefficiencies.
Innovation Solution
The solution optimizes IPSec operation on intermediate SD-WAN routers in a hierarchical overlay model by eliminating the need for IPSec encryption/decryption on these routers. Instead, IPSec encryption is performed only at the source edge router, and decryption occurs only at the destination edge router, while intermediate border routers provide integrity checks without decrypting or encrypting the packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPSec encryption/decryption is performed at intermediate border routers in hierarchical SD-WAN, then security and confidentiality are maintained, but device complexity and cost increase due to high throughput requirements
Solution Approach 1:
The patent segments the IPSec encryption/decryption function from intermediate border routers and relocates it to edge routers. This segmentation allows intermediate routers to focus on routing functions while edge routers handle security processing, reducing device complexity at critical intermediate nodes while maintaining end-to-end security through preserved encryption keys at edge routers.
Solution Approach 2:
The patent extracts the IPSec encryption/decryption operation from intermediate border routers and removes it from the data path at these nodes. By taking out this computationally intensive function from intermediate routers, the system reduces their throughput requirements and device complexity while maintaining security through end-to-end encryption established at edge routers.
2Reliability
If IPSec encryption/decryption is performed at intermediate border routers, then security is maintained, but productivity decreases due to compute intensive operations
Solution Approach 1:
The patent segments security processing from intermediate routing functions, allowing parallel optimization where edge routers handle encryption and intermediate routers handle high-speed forwarding without decryption overhead, thereby improving overall network productivity while maintaining security.
Solution Approach 2:
The patent performs IPSec encryption/decryption in advance at edge routers before traffic enters the intermediate routing path. This preliminary action ensures security is established upfront, allowing intermediate routers to forward traffic without computationally intensive operations, thus improving productivity.
3Reliability
If IPSec throughput is increased at border routers, then security is maintained, but cost increases due to hardware accelerator requirements
Solution Approach 1:
The patent extracts the requirement for high IPSec throughput from intermediate border routers by removing encryption/decryption operations from these nodes. This extraction eliminates the need for expensive hardware accelerators at intermediate routers, reducing overall system cost while maintaining security through end-to-end encryption at edge routers.
Solution Approach 2:
The patent replaces expensive hardware accelerator requirements at intermediate routers with a software-based or simplified security model where encryption is handled at edge routers. This substitution uses more economical solutions at intermediate nodes while maintaining security functionality through the overall system architecture.
Data Source
AI summary
According to some embodiments, a method is performed by a software defined wide area network (SD-WAN) edge router in a hierarchical SD-WAN network comprising a plurality of edge routers and a plurality of border routers. The method comprises: originating a SD-WAN system route for advertising reachability to the edge router, the system route comprising an encryption key associated with the edge router; and transmitting the system route to one or more SD-WAN border routers. The method may further comprise: receiving a packet destined for the edge router from one of the one or more SD-WAN border routers, wherein the packet is at least partially encrypted with the encryption key associated with the edge router; and decrypting the received packet.


