Unicast Key Distribution Service for VPN Rekeying

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN rekeying techniques are limited by the need for multicasting, which not all networks support, resulting in restricted accessibility and efficiency, especially for participants without multicasting capabilities.

Innovation Solution

Implementing a key distribution service that uses unicast messages to individually send new encryption keys to each VPN member, allowing for more efficient and globally accessible key distribution, with rate control and acknowledgment management, and optional encryption and digital signing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multicasting is used to distribute VPN keys, then key distribution efficiency is improved, but network compatibility is worsened because not all networks support multicasting

Engineering Contradiction:
Improvekey distribution efficiencyVSAvoidnetwork compatibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments the key distribution process by sending individual unicast messages to each VPN member instead of using a single multicast message. This segmentation allows the system to work with any network protocol without requiring multicast support, as each member can receive keys through standard unicast communication channels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key distribution service as an intermediary that manages the key distribution process. This service sends unicast messages to each member individually, acting as a mediator that translates the need for efficient key distribution into a form compatible with networks that don't support multicasting.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If unicast messages are sent to each VPN member individually, then network compatibility is improved, but communication overhead increases

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidcommunication overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent applies partial action by sending unicast messages only to members who need key updates, rather than attempting to reach all members simultaneously through multicast. This selective approach reduces the total communication load while maintaining compatibility with networks that lack multicast capabilities.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements continuous key distribution through systematic unicast messaging to all VPN members. The key distribution service continuously monitors and updates members, ensuring that key changes are propagated reliably without requiring the network to support multicast operations.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If keys are changed frequently to enhance security, then security is improved, but key distribution complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by having the key distribution service automatically manage the entire key distribution process. When keys need to be changed for security reasons, the service autonomously generates new keys, sends unicast messages to all members, and tracks distribution status without requiring manual intervention or complex coordination between members.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the key distribution service monitors which members have received key updates and tracks their status. This feedback allows the system to manage frequent key changes efficiently by knowing which members are up-to-date and which need retransmission, simplifying the distribution complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8347376B2Techniques for distributing a new communication key within a virtual private network
Publication Date: 2013.01.01 CISCO TECHNOLOGY INC
  • US8347376B2 patent drawing
  • US8347376B2 patent drawing
  • US8347376B2 patent drawing

AI summary

Techniques for distributing a new communication key within a group virtual private network (VPN) are provided. A key distribution service determines that a new communication key for a VPN is to be distributed to members of the VPN. The new communication key is sent individually in a unique and separate message to each of the members. The key distribution service also maintains records to determine which of the members have and have not successfully received the new communication key.