Security Parameter Index Bit Space Allocation for Key Policy Scalability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing IPsec security protocol's 32-bit SPI values are limited in scalability due to inefficient allocation of bits, allowing only 8,192 key policies, which restricts the ability to manage and scale security associations effectively in large networks.

Innovation Solution

A method is introduced to derive SPI values using a formula that allocates fewer bits for identifying TEPs associated with a key policy, allowing more bits for bank indices, thereby increasing the number of key policies that can be created, up to 1,048,576, by using a central unit to generate and distribute encryption keys and SPI values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If 17 bits are allocated for TEP labels in SPI values, then TEP identification capability is improved, but the number of identifiable key policies is limited to 8,192

Engineering Contradiction:
ImproveTEP identification capabilityVSAvoidkey policy scalability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the SPI value structure into distinct fields: a reduced TEP label field (fewer than 17 bits), a bank index field, and a key policy field. This segmentation allows the TEP label to be identified through a combination of bank index and reduced label rather than requiring a large dedicated field, thereby freeing up bits for key policy identification while maintaining TEP identification capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension (bank index) to the SPI value structure. Instead of relying solely on the TEP label field for TEP identification, the system adds a bank index field that works in conjunction with a reduced TEP label field. This dimensional addition allows the system to maintain TEP identification capability while reallocating bits to increase key policy scalability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If only 13 bits are allocated for key policy identification in SPI values, then SPI value structure simplicity is maintained, but the maximum number of key policies is restricted to 8,192

Engineering Contradiction:
ImproveSPI value structureVSAvoidkey policy quantity
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the key policy identification capability across multiple fields in the SPI value structure. Instead of relying on a single 13-bit key policy field, the system uses a combination of the bank index field and the key policy field together to provide enhanced key policy identification capability, allowing support for up to 1,048,576 key policies while maintaining structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds the bank index field as an additional dimension to the SPI value structure. This new dimension works in conjunction with the key policy field to exponentially increase the number of identifiable key policies without creating a single overly complex field, thereby distributing the complexity across multiple organized fields.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If a central unit is introduced to generate and distribute SPI values, then SPI value allocation control is improved, but system complexity increases

Engineering Contradiction:
ImproveSPI value allocation controlVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a central unit as an intermediary between TEPs and the key policy management system. This central unit receives requests from TEPs for SPI values, generates appropriate SPI values based on the optimized format, and distributes them to TEPs. This intermediary approach centralizes control over SPI allocation while managing the complexity of the SPI value generation and distribution process in one dedicated component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10659440B2Optimizing utilization of security parameter index (SPI) space
Publication Date: 2020.05.19 VMWARE INC
  • US10659440B2 patent drawing
  • US10659440B2 patent drawing
  • US10659440B2 patent drawing

AI summary

Certain embodiments described herein are generally directed to methods and apparatus for providing a security parameter index (SPI) value for use in establishing a security association between a source tunnel endpoint and a destination tunnel endpoint. In some embodiments, utilization of the SPI bit space is optimized to allow the scaling of key policies within a network. In some embodiment, using an SPI derivation formula, a server in the network is able to generate SPI values whose bit spaces are optimized to allow key policies to scale out.