Hierarchical SD-WAN IPSec Optimization via Edge Router Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional WAN architectures are limited in available bandwidth, security, and complexity management, which hinders business productivity, especially in mobile and cloud-based environments. In hierarchical SD-WAN, intermediate border routers face high IPSec throughput requirements, leading to increased costs and inefficiencies.

Innovation Solution

The solution optimizes IPSec operation on intermediate SD-WAN routers in a hierarchical overlay model by eliminating the need for IPSec encryption/decryption on these routers. Instead, IPSec encryption is performed only at the source edge router, and decryption occurs only at the destination edge router, while intermediate border routers provide integrity checks without decrypting or encrypting the packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPSec encryption/decryption is performed at intermediate border routers in hierarchical SD-WAN, then security and confidentiality are maintained, but device complexity and cost increase due to high throughput requirements

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the IPSec encryption/decryption function from intermediate border routers and relocates it to edge routers. This segmentation allows intermediate routers to focus on routing functions while edge routers handle security processing, reducing device complexity at critical intermediate nodes while maintaining end-to-end security through preserved encryption keys at edge routers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the IPSec encryption/decryption operation from intermediate border routers and removes it from the data path at these nodes. By taking out this computationally intensive function from intermediate routers, the system reduces their throughput requirements and device complexity while maintaining security through end-to-end encryption established at edge routers.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If IPSec encryption/decryption is performed at intermediate border routers, then security is maintained, but productivity decreases due to compute intensive operations

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments security processing from intermediate routing functions, allowing parallel optimization where edge routers handle encryption and intermediate routers handle high-speed forwarding without decryption overhead, thereby improving overall network productivity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs IPSec encryption/decryption in advance at edge routers before traffic enters the intermediate routing path. This preliminary action ensures security is established upfront, allowing intermediate routers to forward traffic without computationally intensive operations, thus improving productivity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If IPSec throughput is increased at border routers, then security is maintained, but cost increases due to hardware accelerator requirements

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the requirement for high IPSec throughput from intermediate border routers by removing encryption/decryption operations from these nodes. This extraction eliminates the need for expensive hardware accelerators at intermediate routers, reducing overall system cost while maintaining security through end-to-end encryption at edge routers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces expensive hardware accelerator requirements at intermediate routers with a software-based or simplified security model where encryption is handled at edge routers. This substitution uses more economical solutions at intermediate nodes while maintaining security functionality through the overall system architecture.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20250133022A1Optimizing IPSec for Hierarchical SD-WAN
Publication Date: 2025.04.24 CISCO TECHNOLOGY INC
  • US20250133022A1 patent drawing
  • US20250133022A1 patent drawing
  • US20250133022A1 patent drawing

AI summary

According to some embodiments, a method is performed by a software defined wide area network (SD-WAN) edge router in a hierarchical SD-WAN network comprising a plurality of edge routers and a plurality of border routers. The method comprises: originating a SD-WAN system route for advertising reachability to the edge router, the system route comprising an encryption key associated with the edge router; and transmitting the system route to one or more SD-WAN border routers. The method may further comprise: receiving a packet destined for the edge router from one of the one or more SD-WAN border routers, wherein the packet is at least partially encrypted with the encryption key associated with the edge router; and decrypting the received packet.