Secure Session Link Failure Detection Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computer networks, communication links with associated secure sessions can remain undetected as inoperable for extended periods due to the lack of synchronization between fast detection processes and key agreement processes, leading to sub-second convergence failures, routing instability, and security anomalies.

Innovation Solution

Implementing link security synchronization logic that synchronizes fast detection processes with key agreement processes, using protocols like MACsec and IPsec, to enable immediate detection of link failures and terminate secure sessions, ensuring sub-second convergence and stable routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure communication functions use traditional detection methods, then security protocols are maintained, but link failure detection time increases significantly

Engineering Contradiction:
Improvesecure session reliabilityVSAvoidlink failure detection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the secure communication function proactively query the link status at predetermined intervals and immediately terminate the secure session upon detecting link failure, rather than waiting for traditional timeout-based detection. This proactive approach reduces detection time while maintaining security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by establishing a closed-loop communication where the secure communication function continuously monitors link status through status queries and receives real-time feedback about link operability. This feedback mechanism enables rapid response to link failures while maintaining secure session integrity.

Inventive Principle:
Principle #23Feedback

2Speed

If fast convergence techniques are implemented, then re-routing speed improves, but synchronization with secure sessions becomes problematic

Engineering Contradiction:
Improvere-routing speedVSAvoidsession-link synchronization
Core Design Contradiction:
SpeedVSStability of the object's composition

Solution Approach 1:

The patent merges the secure communication function with the fast convergence detection mechanism by having the secure communication function directly query link status and terminate sessions based on link failures. This integration ensures that secure sessions are synchronized with link status changes, maintaining stability while enabling fast re-routing.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent applies preliminary action by pre-establishing the secure communication function's ability to detect link failures before they impact routing. The secure session is proactively terminated upon link failure detection, preventing desynchronization between routing changes and secure session states.

Inventive Principle:
Principle #10Preliminary action

3Duration of action of stationary object

If secure sessions continue after link failure, then session continuity is maintained, but routing brownouts and blackouts occur

Engineering Contradiction:
Improvesecure session durationVSAvoidrouting stability
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The patent implements feedback by having the secure communication function continuously monitor link status and immediately terminate the secure session upon detecting link failure. This real-time feedback prevents secure sessions from continuing after link failure, eliminating routing brownouts and blackouts while maintaining appropriate session duration.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11128663B2Synchronizing link and event detection mechanisms with a secure session associated with the link
Publication Date: 2021.09.21 CISCO TECHNOLOGY INC
  • US11128663B2 patent drawing
  • US11128663B2 patent drawing
  • US11128663B2 patent drawing

AI summary

A first network element, such as a router, in a computer network may have established a communication link with a second network element in the computer network. A secure session associated with the communication link between the first and second network elements may then be established. The secure session may use a secure communication function on each of the first network element and the second network element. The first network element may then detect that the first network element cannot communicate with the second network element over the communication link. When the first network element cannot communicate with the second network element, the first network element may terminate the communication link and the secure session associated with the communication link.