Security Protocol Partitioning for Independent Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security protocols lack efficient partitioning and virtualization of security associations and policies, leading to limitations in implementing multiple security policies independently on a single computer system and managing secure connections effectively.
Innovation Solution
The implementation of multiple security association database (SADB) partitions and security policy database (SPD) partitions for a single cryptographic offload engine, allowing each partition to be associated with specific packet destinations and enabling independent security policy enforcement, with each partition managed by an internet key exchange (IKE) daemon and destination policy database respectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single security association database (SADB) and security policy database (SPD) are used for cryptographic processing, then the system structure is simple, but multiple security policies cannot be implemented independently on a single computer system
Solution Approach 1:
The patent divides the security association database (SADB) and security policy database (SPD) into multiple independent partitions. Each partition can store and enforce a separate security policy, allowing multiple security policies to be implemented independently on a single computer system. The cryptographic offload engine is configured to access specific partitions based on packet destination, enabling policy isolation and independent management.
2Ease of operation
If multiple security associations are managed in a single database, then database management is simplified, but security associations cannot be isolated and managed effectively for different destinations
Solution Approach 1:
The SADB is segmented into multiple partitions, with each partition dedicated to specific packet destinations or security contexts. This segmentation enables effective isolation and management of security associations for different destinations while maintaining simplified access through partition-specific management interfaces.
Solution Approach 2:
The patent introduces an intermediary mechanism (the partitioned database structure with associated management interfaces) that mediates between the cryptographic offload engine and the security associations. This intermediary enables effective management and isolation of security associations for different destinations while presenting a unified interface to the engine.
3Productivity
If security policies are enforced centrally without partitioning, then system complexity is reduced, but independent enforcement of multiple security policies is limited
Solution Approach 1:
The patent implements partitioning of security databases to enable independent enforcement of multiple security policies. Each partition can be enforced independently by the cryptographic offload engine based on packet destination, improving productivity by allowing parallel policy enforcement while managing complexity through structured partition organization.
Solution Approach 2:
The partitioned database structure allows dynamic selection of appropriate security policy partitions based on packet destination. The system can dynamically route packets to the appropriate partition for enforcement, improving efficiency by avoiding unnecessary policy checks while maintaining the ability to enforce multiple policies independently.
Data Source
AI summary
A method for implementing a security protocol, involving receiving a packet from a network connection, obtaining an identifier for one of a plurality of security association database (SADB) partitions associated with the packet, wherein each of the plurality of SADB partitions is associated with one of a plurality of packet destinations, applying a security association from the one of the plurality of SADB partitions to the packet, and sending the packet to the one of the plurality of packet destinations associated with the SADB partition, wherein the packet is processed at the one of the plurality of packet destinations.


