Split Tunnel IPSec Router Black Hole Shunt Propagation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise network configurations that rely on non-split tunnel IPSec deployments introduce latency and increased network loading due to the need to route all packet traffic through the head-end for central policy enforcement, particularly when dealing with malicious websites and phishing attempts, as they require cooperation between enterprises and ISPs to block access.

Innovation Solution

Implementing a split tunnel configuration using the iBGP protocol to dynamically propagate the list of 'blackholed' website addresses from the enterprise head-end to remote routers, allowing remote offices to block return paths to malicious websites without routing third-party traffic through the head-end, thereby minimizing latency and network burden.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If non-split tunnel IPSec configuration is used to enforce central policy, then security policy control is improved, but latency increases and network loading increases

Engineering Contradiction:
Improvesecurity policy controlVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the network traffic into two paths: encrypted traffic for enterprise resources through the IPSec tunnel to the head-end, and unencrypted direct traffic for Internet access. This segmentation allows security policy enforcement only where necessary (enterprise resources) while enabling direct Internet access to reduce latency for non-enterprise traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements different traffic handling qualities at different locations: the head-end router enforces security policies and maintains the black hole shunt configuration, while remote access routers apply these policies locally through dynamic routing protocol propagation, eliminating the need to route all traffic through the head-end and reducing latency.

Inventive Principle:
Principle #3Local quality

2Reliability

If non-split tunnel IPSec configuration is used to enforce central policy, then security policy control is improved, but network loading increases

Engineering Contradiction:
Improvesecurity policy controlVSAvoidnetwork loading
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments network traffic into encrypted enterprise traffic and unencrypted Internet traffic, routing only necessary traffic through the IPSec tunnel to the head-end. This reduces unnecessary network loading on the head-end and WAN links while maintaining security policy enforcement for enterprise resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Remote access routers autonomously enforce security policies by dynamically receiving and applying black hole shunt configurations through routing protocols, eliminating the need to forward all traffic to the head-end for policy enforcement. This self-service capability reduces network loading on central infrastructure.

Inventive Principle:
Principle #25Self-service

3Loss of time

If black hole shunt is propagated dynamically to remote routers, then latency is reduced and network loading is reduced, but configuration complexity increases

Engineering Contradiction:
ImprovelatencyVSAvoidconfiguration complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the head-end router dynamically propagates black hole shunt configurations to remote routers using routing protocol feedback loops. When the head-end identifies malicious websites, it automatically pushes these configurations to remote routers, which then enforce them locally, reducing latency while maintaining centralized control through automated feedback.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent uses dynamic routing protocols as intermediaries to automatically propagate black hole shunt configurations from the head-end to remote routers. This intermediary mechanism eliminates manual configuration complexity while enabling rapid, automated distribution of security policies across the distributed network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If all traffic is routed through head-end for policy enforcement, then centralized security control is improved, but IPSec tunnel bandwidth utilization efficiency deteriorates

Engineering Contradiction:
Improvecentralized security controlVSAvoidIPSec tunnel bandwidth utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments traffic into encrypted enterprise traffic that uses the IPSec tunnel and unencrypted Internet traffic that bypasses it. This segmentation improves IPSec tunnel bandwidth utilization efficiency by eliminating unnecessary encrypted traffic while maintaining centralized security control for enterprise resources through policy propagation to remote routers.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7873993B2Propagating black hole shunts to remote routers with split tunnel and IPSec direct encapsulation
Publication Date: 2011.01.18 CISCO TECHNOLOGY INC
  • US7873993B2 patent drawing
  • US7873993B2 patent drawing
  • US7873993B2 patent drawing

AI summary

Remote routers are configured to block the return path to malicious websites with the use of split tunneling while allowing paths to third party resource websites. The iBGP protocol runs on the agent's router, advertises routes and enables the head-end to set up a policy at each remote router. Enterprise policies for blocking access to “blackholed” website addresses are centrally administered but third party website traffic is not routed to the enterprise's network resources. Since remote offices may connect directly to third party websites, latency is minimized and network resources at the enterprise are not unduly burdened.