Security Protocol Partitioning for Independent Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security protocols lack efficient partitioning and virtualization of security associations and policies, leading to limitations in implementing multiple security policies independently on a single computer system and managing secure connections effectively.

Innovation Solution

The implementation of multiple security association database (SADB) partitions and security policy database (SPD) partitions for a single cryptographic offload engine, allowing each partition to be associated with specific packet destinations and enabling independent security policy enforcement, with each partition managed by an internet key exchange (IKE) daemon and destination policy database respectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single security association database (SADB) and security policy database (SPD) are used for cryptographic processing, then the system structure is simple, but multiple security policies cannot be implemented independently on a single computer system

Engineering Contradiction:
ImproveAbility to implement multiple security policies independentlyVSAvoidStructure of security association database and security policy database
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the security association database (SADB) and security policy database (SPD) into multiple independent partitions. Each partition can store and enforce a separate security policy, allowing multiple security policies to be implemented independently on a single computer system. The cryptographic offload engine is configured to access specific partitions based on packet destination, enabling policy isolation and independent management.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If multiple security associations are managed in a single database, then database management is simplified, but security associations cannot be isolated and managed effectively for different destinations

Engineering Contradiction:
ImproveManagement of security associations and policiesVSAvoidIsolation and management of security associations for different destinations
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The SADB is segmented into multiple partitions, with each partition dedicated to specific packet destinations or security contexts. This segmentation enables effective isolation and management of security associations for different destinations while maintaining simplified access through partition-specific management interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (the partitioned database structure with associated management interfaces) that mediates between the cryptographic offload engine and the security associations. This intermediary enables effective management and isolation of security associations for different destinations while presenting a unified interface to the engine.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If security policies are enforced centrally without partitioning, then system complexity is reduced, but independent enforcement of multiple security policies is limited

Engineering Contradiction:
ImproveEfficiency of security policy enforcementVSAvoidPartitioning structure of security databases
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements partitioning of security databases to enable independent enforcement of multiple security policies. Each partition can be enforced independently by the cryptographic offload engine based on packet destination, improving productivity by allowing parallel policy enforcement while managing complexity through structured partition organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The partitioned database structure allows dynamic selection of appropriate security policy partitions based on packet destination. The system can dynamically route packets to the appropriate partition for enforcement, improving efficiency by avoiding unnecessary policy checks while maintaining the ability to enforce multiple policies independently.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8175271B2Method and system for security protocol partitioning and virtualization
Publication Date: 2012.05.08 ORACLE AMERICAN INC
  • US8175271B2 patent drawing
  • US8175271B2 patent drawing
  • US8175271B2 patent drawing

AI summary

A method for implementing a security protocol, involving receiving a packet from a network connection, obtaining an identifier for one of a plurality of security association database (SADB) partitions associated with the packet, wherein each of the plurality of SADB partitions is associated with one of a plurality of packet destinations, applying a security association from the one of the plurality of SADB partitions to the packet, and sending the packet to the one of the plurality of packet destinations associated with the SADB partition, wherein the packet is processed at the one of the plurality of packet destinations.