Virtual Security Gateway IPsec SA Synchronization Failover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IPsec/IKE systems lack resilience mechanisms, leading to interruptions in encrypted traffic when an IPsec/IKE peer fails, as all security associations are deleted and renegotiated, causing potential hours or days of service disruption without immediate failover.
Innovation Solution
The introduction of a virtualized IPsec/IKE system using a Virtual Security Gateway (V-SEG) with sub-second VRRP and IPsec/IKE SA Transfer Protocol (SATP) for near real-time synchronization and failover, ensuring continuous encrypted traffic by maintaining and transferring IKE and IPsec SAs between cooperating physical security gateways.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPsec/IKE security associations are established between SEG nodes, then encrypted communication is secured, but when a SEG node fails, all packets are black-holed and communication stops completely
Solution Approach 1:
The patent segments the SEG node functionality by introducing a virtualization layer that separates the control plane (IKE/IPsec SA management) from the data plane (encrypted traffic forwarding). This allows the control plane to detect failures and trigger failover while the data plane continues operating through pre-established SAs on backup nodes
Solution Approach 2:
The patent implements preliminary action by pre-establishing Security Associations on backup SEG nodes before failures occur. When a primary SEG node fails, the backup nodes already have valid SAs in place, enabling immediate failover without requiring SA re-negotiation, thus preventing complete communication stoppage
2Loss of time
If dead peer detection scheme is implemented, then failure detection time is reduced to seconds or minutes, but encrypted traffic interruption still occurs for almost a minute or minutes
Solution Approach 1:
The patent performs preliminary action by pre-synchronizing Security Associations to backup SEG nodes before failures occur. This ensures that when failover is triggered, the backup nodes immediately have valid SAs ready, eliminating the traffic interruption period that occurs in conventional systems during SA re-negotiation
Solution Approach 2:
The patent maintains continuity of useful action by keeping Security Associations active and synchronized on backup nodes even while the primary node is operational. This allows the backup nodes to immediately take over encrypted traffic forwarding upon failure detection, maintaining continuous useful action without interruption
3Reliability
If IPsec SA time limits are imposed, then key usage is limited and security is improved, but upon expiration all SAs must be renegotiated causing hours or days of interruption
Solution Approach 1:
The patent implements preliminary action by pre-generating and synchronizing new Security Associations to backup SEG nodes before the current SAs expire. When the primary node's SAs expire or are revoked, the backup nodes already have fresh SAs ready, enabling immediate failover without the hours or days of interruption that would occur during re-negotiation
Solution Approach 2:
The patent uses copying by replicating Security Association data from the primary SEG node to backup SEG nodes. This copying mechanism ensures that backup nodes have identical or near-identical SAs ready for immediate activation, eliminating the need for time-consuming re-negotiation upon failure
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A method and apparatus adapting a Virtual Router Redundancy Protocol (VRRP) between a set of physical SEGs that realize a V-SEG function towards a remote IPsec/IKE Peer. In tandem with the VRRP, a new protocol, referred to herein as the IPsec/IKE SA Transfer Protocol (SATP), is introduced to exchange IKE and IPsec SA information between VRRP capable SEGs. SATP synchronizes all participating SEGs with respect to dynamic IPsec state information in near real time. Thus, in the event of a master VRRP SEG failure, one of the hot-standby SEGs takes over the V-SEG function. This allows the V-SEG function to remain functional despite the possible failure of one or more participating SEGs.