Security Gateway Offloads P-GANC URR Discovery to Reduce IPSec Tunnel Overhead

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In UMA or GAN networks, the frequent creation and teardown of multiple IPSec tunnels during client registration require significant processing power and incur high costs, especially due to the limited functions of P-GANC nodes.

Innovation Solution

Offloading the P-GANC functionality to a security gateway, which authenticates clients and determines registration information without communicating with a P-GANC, thereby eliminating the need for additional secure tunnels and reducing backhaul transit costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple IPSec tunnels are established with P-GANC and D-GANC during client registration, then authentication and registration functions are completed, but processing power consumption increases and costs increase

Engineering Contradiction:
Improveauthentication and registration function completionVSAvoidprocessing power consumption
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent extracts the P-GANC functionality from the traditional network architecture and relocates it to the security gateway. This allows the security gateway to handle URR discovery requests directly without requiring communication with a separate P-GANC, thereby eliminating the need for additional IPSec tunnels and reducing processing power consumption while maintaining authentication and registration functions

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the P-GANC functions with the security gateway by enabling the security gateway to process URR discovery requests locally. This consolidation eliminates the need for separate P-GANC nodes and reduces the number of IPSec tunnels required, directly addressing the processing power and cost issues while preserving necessary network control functions

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If multiple IPSec tunnels are created and torn down during registration, then client can connect to different GANC nodes, but processing power and time are consumed

Engineering Contradiction:
Improveclient connectivity to different GANC nodesVSAvoidregistration process time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the security gateway determine and prepare the D-GANC location information before the client actually needs to connect. The security gateway proactively resolves URR discovery requests and provides the necessary connection information in advance, eliminating the need for time-consuming on-demand P-GANC queries and reducing overall registration time while maintaining connectivity flexibility

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If P-GANC nodes are deployed to handle registration requests, then registration functions are available, but node maintenance costs increase

Engineering Contradiction:
Improveregistration function availabilityVSAvoidnode maintenance cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent extracts the P-GANC functional responsibilities and relocates them to existing security gateway infrastructure. This eliminates the need to deploy and maintain separate P-GANC nodes while preserving registration function availability, directly reducing maintenance costs and operational complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent enables the security gateway to perform multiple functions including both authentication and URR discovery/registration functions. This multi-functionality eliminates the need for dedicated P-GANC nodes, reducing the number of components that require maintenance while maintaining full registration service capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8018948B2P-GANC offload of URR discovery messages to a security gateway
Publication Date: 2011.09.13 CISCO TECHNOLOGY INC
  • US8018948B2 patent drawing
  • US8018948B2 patent drawing
  • US8018948B2 patent drawing

AI summary

In one embodiment, a security gateway receives an IPSec Initiation (IPSec INIT) request from a client. The security gateway may communicate with a AAA server to authenticate the client. After authentication, the security gateway intercepts a URR Discovery request from the client. The security gateway determines registration information for a response to the registration request. The registration information may be information on where the client can locate a D-GANC. A response is generated using the determined information and sent to the client. The response to the discovery request is performed without communicating with a P-GANC. Accordingly, a security gateway is used to authenticate the client and also to respond to the discovery request. This does not require that a P-GANC function be deployed in a network. Thus, cost and processing power may be saved.