Time-Based Anti-Replay Window Adaptation for QoS Reordering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In software-defined wide area networks (SD-WANs), IPSec encapsulated packets can be forwarded out of sequence and dropped during congestion due to varying Quality of Service (QoS) policies, necessitating a fixed anti-replay window size that fails to accommodate diverse network conditions and security attack risks.

Innovation Solution

A network node dynamically adjusts the time-based anti-replay window size based on sequence-based, time-based, and selective anti-replay checks, using anti-replay engines to detect packet duplication and adapt the window size according to network conditions, thereby mitigating security risks and optimizing QoS deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a fixed anti-replay window size is used, then security protection is provided, but the system cannot adapt to diverse network conditions and QoS policies

Engineering Contradiction:
Improveadaptability to network conditionsVSAvoidcomplexity of anti-replay mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic adjustment of the anti-replay window size based on real-time network conditions. The system monitors packet arrival patterns, sequence numbers, and timing information to automatically resize the window, transitioning from a static fixed-size approach to a dynamic adaptive mechanism that responds to changing network states and QoS requirements

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of anti-replay window size based on observed network conditions. By monitoring packet timing, sequence continuity, and network congestion levels, the system adjusts the window size parameter to optimize both security protection and compatibility with diverse QoS policies, allowing legitimate out-of-sequence packets to pass while maintaining replay attack detection

Inventive Principle:
Principle #35Parameter changes

2Productivity

If QoS policies prioritize packets based on forwarding class, then bandwidth management is improved, but packets may be forwarded out of sequence and dropped by anti-replay checks

Engineering Contradiction:
Improvebandwidth utilizationVSAvoidpacket delivery reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The anti-replay window size is dynamically adjusted to accommodate QoS-induced packet reordering. When network monitoring detects out-of-sequence arrivals consistent with QoS policy operation, the system expands the window to include these legitimate packets, preventing unnecessary drops while maintaining protection against replay attacks that exhibit different patterns

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms that monitor packet arrival patterns and sequence continuity. When QoS policies cause out-of-sequence forwarding, the feedback loop detects this pattern and adjusts the anti-replay window accordingly, allowing the system to adapt to the reordering while maintaining reliability for legitimate traffic

Inventive Principle:
Principle #23Feedback

3Reliability

If the anti-replay window size is increased to accommodate out-of-sequence packets, then packet delivery is improved, but security protection against replay attacks is weakened

Engineering Contradiction:
Improvepacket acceptance rateVSAvoidvulnerability to replay attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts the anti-replay window size based on real-time analysis of packet patterns. Rather than using a permanently large window that would weaken security, the system expands the window only when and where QoS-induced reordering is detected, and maintains a smaller window size during normal conditions to preserve strong replay attack protection

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies different anti-replay window sizes to different traffic flows or time periods based on local network conditions. Legitimate QoS-affected flows receive accommodative window sizing, while maintaining strict replay protection for other traffic, thereby achieving both reliability improvement and security preservation through localized adaptation

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250219949A1Systems and Methods for Automatically Adjusting a Time-Based Anti-Replay Window Size
Publication Date: 2025.07.03 CISCO TECHNOLOGY INC
  • US20250219949A1 patent drawing
  • US20250219949A1 patent drawing
  • US20250219949A1 patent drawing

AI summary

In one embodiment, a method includes receiving, by a network node, a packet associated with a session. The method also includes performing, by the network node, a sequence-based anti-replay check and determining, by the network node, that the sequence-based anti-replay check rejected the packet. The method further includes performing, by the network node, a time-based anti-replay check, performing, by the network node, a selective anti-replay check, and determining, by the network node, whether to dynamically adjust a time-based anti-replay window size.