Security Association Management for Dynamic Endpoint Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security protocols, such as IPsec and IKE, face challenges in efficiently managing security associations for large numbers of endpoints, particularly in systems with dynamic addresses and narrowband links, leading to increased radio frequency resources and bandwidth usage, as well as unmanageable Security Association Databases.

Innovation Solution

A method that involves defining a set of destination host addresses for a security association, calculating a security endpoint address range using an address offset, and applying the security association to encrypted data packets, thereby minimizing key management messages and optimizing network load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dynamic provisioning using IKE protocol is implemented to support large numbers of endpoints, then the system can accommodate more users, but radio frequency resources and bandwidth are adversely affected due to the number of messages exchanged

Engineering Contradiction:
Improvenumber of supported endpointsVSAvoidradio frequency resources
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent segments the Security Association Database into multiple groups, where each group is associated with a different group ID. This allows the infrastructure endpoint to maintain separate SAD groups for different endpoint types or purposes, reducing the overhead of managing a single large database and minimizing the messages required for SA establishment across all endpoints.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal SA template that can be applied to multiple endpoints simultaneously. Instead of creating individual SAs for each endpoint, a single SA template with group ID can serve multiple endpoints, reducing the number of key management messages and radio frequency resources required.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If dynamic provisioning using IKE protocol is implemented to support large numbers of endpoints, then the system can accommodate more users, but the Security Association Database becomes unmanageable

Engineering Contradiction:
Improvenumber of supported endpointsVSAvoidSecurity Association Database management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The SAD is segmented into multiple groups using group IDs, allowing the infrastructure endpoint to organize and manage SAs in a structured manner. This segmentation makes the database manageable even with thousands of endpoints by dividing it into smaller, organized units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses SA templates that can be copied and applied to multiple endpoints. Instead of manually configuring each SA individually, a template can be replicated across numerous endpoints, significantly reducing the complexity of database management.

Inventive Principle:
Principle #26Copying

3Reliability

If symmetric key management is used with tunnel mode encryption for thousands of endpoints, then security can be provided, but thousands of individual association settings are required which is impractical

Engineering Contradiction:
Improvesecurity provisionVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal SA template that can be applied to multiple endpoints simultaneously. This single template serves multiple purposes and endpoints, eliminating the need for thousands of individual configuration settings while maintaining security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameter approach by introducing group IDs as a key parameter. Instead of configuring each endpoint individually with unique parameters, the system uses group ID parameters to efficiently manage security associations across thousands of endpoints.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2494760B8Method for providing security associations for encrypted packet data
Publication Date: 2015.10.07 MOTOROLA SOLUTIONS INC

AI summary

A method provides security associations for one or more encrypted data packets by operating a source endpoint to define a set of destination host addresses for a security association to apply, define a security endpoint address range, and apply the security association to one or more encrypted data packets destined for at least one destination host address which is to be sent via a calculated security endpoint in the security endpoint address range. The security address range can be determined by determining an address offset, and calculating a security endpoint address range from the destination host address range using the address offset. Alternatively, a start address for a security endpoint address range can be identified in another manner.