Secure Communication Channel Establishment via Encryption Capability Negotiation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing secure communication channels between peer devices is challenging when one or both devices lack support for security protocols or when WAN optimizers degrade performance by adding unnecessary latency through double encryption.
Innovation Solution
The method involves performing an encryption capability negotiation between peer devices to determine if they support secure communication protocols, marking links as encryption capable only if the negotiation is successful, and establishing separate security associations for each communication channel to prevent redundant secure channels and mitigate performance degradation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure communication channels are established between all peer devices, then communication security is improved, but performance degrades due to double encryption when WAN optimizers are involved
Solution Approach 1:
The system dynamically changes the encryption parameter by establishing secure channels only on links that successfully complete encryption capability negotiation. This selective approach maintains security where needed while avoiding double encryption on links where it would degrade performance.
Solution Approach 2:
The system performs preliminary encryption capability negotiation before establishing secure communication channels. This preliminary action identifies which peer devices support encryption, preventing subsequent performance degradation from attempting to establish secure channels with incompatible devices or through WAN optimizers.
2Reliability
If secure communication channels are established without capability negotiation, then security coverage is improved, but device compatibility deteriorates when peer devices lack security protocol support
Solution Approach 1:
The system performs preliminary encryption capability negotiation to assess peer device compatibility before attempting to establish secure channels. This ensures that security protocols are only applied where supported, maintaining both security coverage and device compatibility.
Solution Approach 2:
The system changes the security parameter dynamically based on negotiation outcomes. Links are marked as encryption-capable or non-capable based on peer device responses, allowing the system to adapt security application to actual device capabilities rather than applying a uniform security policy.
3Reliability
If encryption is applied on all communication links, then security reliability is improved, but system complexity increases due to separate security associations required for each channel
Solution Approach 1:
The system changes the security association parameter by creating separate associations only for links that are marked as encryption-capable. This selective approach maintains high security reliability on capable links while reducing overall system complexity by avoiding unnecessary security associations on non-capable links.
Data Source
AI summary
Embodiments described herein relate to techniques for establishing a secure communication channel. The techniques may include performing an encryption capability negotiation between peer devices, wherein a first peer device and a second peer device are connected by a communication channel comprising a first link of the first peer device and a second link of the second peer device; marking, when the encryption capability negotiation is successful, the first link and the second link as encryption capable; performing, based on the marking, a security negotiation between the first peer device and the second peer device; based on the security negotiation: establishing a first security association on the first peer device; and establishing a second security association on the second peer device; programming the first security association to hardware of the first peer device; and programming the second security association to hardware of the second peer device.


