Virtual Security Gateway IPsec SA Synchronization Failover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IPsec/IKE systems lack resilience mechanisms, leading to interruptions in encrypted traffic when an IPsec/IKE peer fails, as all security associations are deleted and renegotiated, causing potential hours or days of service disruption without immediate failover.

Innovation Solution

The introduction of a virtualized IPsec/IKE system using a Virtual Security Gateway (V-SEG) with sub-second VRRP and IPsec/IKE SA Transfer Protocol (SATP) for near real-time synchronization and failover, ensuring continuous encrypted traffic by maintaining and transferring IKE and IPsec SAs between cooperating physical security gateways.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPsec/IKE security associations are established between SEG nodes, then encrypted communication is secured, but when a SEG node fails, all packets are black-holed and communication stops completely

Engineering Contradiction:
Improveencrypted communication continuityVSAvoidSEG node failure handling
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the SEG node functionality by introducing a virtualization layer that separates the control plane (IKE/IPsec SA management) from the data plane (encrypted traffic forwarding). This allows the control plane to detect failures and trigger failover while the data plane continues operating through pre-established SAs on backup nodes

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-establishing Security Associations on backup SEG nodes before failures occur. When a primary SEG node fails, the backup nodes already have valid SAs in place, enabling immediate failover without requiring SA re-negotiation, thus preventing complete communication stoppage

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If dead peer detection scheme is implemented, then failure detection time is reduced to seconds or minutes, but encrypted traffic interruption still occurs for almost a minute or minutes

Engineering Contradiction:
Improvefailure detection timeVSAvoidencrypted traffic continuity
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent performs preliminary action by pre-synchronizing Security Associations to backup SEG nodes before failures occur. This ensures that when failover is triggered, the backup nodes immediately have valid SAs ready, eliminating the traffic interruption period that occurs in conventional systems during SA re-negotiation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuity of useful action by keeping Security Associations active and synchronized on backup nodes even while the primary node is operational. This allows the backup nodes to immediately take over encrypted traffic forwarding upon failure detection, maintaining continuous useful action without interruption

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If IPsec SA time limits are imposed, then key usage is limited and security is improved, but upon expiration all SAs must be renegotiated causing hours or days of interruption

Engineering Contradiction:
Improveencryption key securityVSAvoidSA renegotiation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-generating and synchronizing new Security Associations to backup SEG nodes before the current SAs expire. When the primary node's SAs expire or are revoked, the backup nodes already have fresh SAs ready, enabling immediate failover without the hours or days of interruption that would occur during re-negotiation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by replicating Security Association data from the primary SEG node to backup SEG nodes. This copying mechanism ensures that backup nodes have identical or near-identical SAs ready for immediate activation, eliminating the need for time-consuming re-negotiation upon failure

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3322150B1Apparatus and method for resilient IP security/internet key exchange security gateway
Publication Date: 2021.03.31 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3322150B1 patent drawingFigure 1~2
  • EP3322150B1 patent drawingFigure 3
  • EP3322150B1 patent drawingFigure 4

AI summary

A method and apparatus adapting a Virtual Router Redundancy Protocol (VRRP) between a set of physical SEGs that realize a V-SEG function towards a remote IPsec/IKE Peer. In tandem with the VRRP, a new protocol, referred to herein as the IPsec/IKE SA Transfer Protocol (SATP), is introduced to exchange IKE and IPsec SA information between VRRP capable SEGs. SATP synchronizes all participating SEGs with respect to dynamic IPsec state information in near real time. Thus, in the event of a master VRRP SEG failure, one of the hot-standby SEGs takes over the V-SEG function. This allows the V-SEG function to remain functional despite the possible failure of one or more participating SEGs.