Secure Session Link Failure Detection Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In computer networks, communication links with associated secure sessions can remain undetected as inoperable for extended periods due to the lack of synchronization between fast detection processes and key agreement processes, leading to sub-second convergence failures, routing instability, and security anomalies.
Innovation Solution
Implementing link security synchronization logic that synchronizes fast detection processes with key agreement processes, using protocols like MACsec and IPsec, to enable immediate detection of link failures and terminate secure sessions, ensuring sub-second convergence and stable routing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure communication functions use traditional detection methods, then security protocols are maintained, but link failure detection time increases significantly
Solution Approach 1:
The patent implements preliminary action by having the secure communication function proactively query the link status at predetermined intervals and immediately terminate the secure session upon detecting link failure, rather than waiting for traditional timeout-based detection. This proactive approach reduces detection time while maintaining security reliability.
Solution Approach 2:
The patent implements feedback by establishing a closed-loop communication where the secure communication function continuously monitors link status through status queries and receives real-time feedback about link operability. This feedback mechanism enables rapid response to link failures while maintaining secure session integrity.
2Speed
If fast convergence techniques are implemented, then re-routing speed improves, but synchronization with secure sessions becomes problematic
Solution Approach 1:
The patent merges the secure communication function with the fast convergence detection mechanism by having the secure communication function directly query link status and terminate sessions based on link failures. This integration ensures that secure sessions are synchronized with link status changes, maintaining stability while enabling fast re-routing.
Solution Approach 2:
The patent applies preliminary action by pre-establishing the secure communication function's ability to detect link failures before they impact routing. The secure session is proactively terminated upon link failure detection, preventing desynchronization between routing changes and secure session states.
3Duration of action of stationary object
If secure sessions continue after link failure, then session continuity is maintained, but routing brownouts and blackouts occur
Solution Approach 1:
The patent implements feedback by having the secure communication function continuously monitor link status and immediately terminate the secure session upon detecting link failure. This real-time feedback prevents secure sessions from continuing after link failure, eliminating routing brownouts and blackouts while maintaining appropriate session duration.
Data Source
AI summary
A first network element, such as a router, in a computer network may have established a communication link with a second network element in the computer network. A secure session associated with the communication link between the first and second network elements may then be established. The secure session may use a secure communication function on each of the first network element and the second network element. The first network element may then detect that the first network element cannot communicate with the second network element over the communication link. When the first network element cannot communicate with the second network element, the first network element may terminate the communication link and the secure session associated with the communication link.


