VXLAN Packet Authentication via Dynamic Token Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

VXLAN encapsulation lacks security protection, making networks vulnerable to attacks where attackers can send fake packets, leading to network congestion and other negative impacts due to the lack of packet authentication.

Innovation Solution

Implementing a dynamic VXLAN packet authentication mechanism on both control and data panels using tokens to authenticate packets, where tokens are generated and verified across VXLAN Tunnel Endpoints (VTEPs) supporting both Ethernet and VXLAN formats, ensuring only valid packets are forwarded.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If VXLAN encapsulation is used to transmit packets in a network system, then network scalability and flexibility are improved, but network security deteriorates due to lack of packet authentication

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authentication code as an intermediary element between the VXLAN encapsulation mechanism and the packet transmission process. This authentication code, generated based on packet characteristics and cryptographic keys, acts as a mediator that verifies packet legitimacy without altering the core VXLAN encapsulation functionality, thus maintaining scalability while enhancing security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent modifies the VXLAN packet structure by adding an authentication code field and changes the packet processing parameters to include authentication verification. This parameter change allows the system to maintain compatibility with existing VXLAN infrastructure while implementing security checks that prevent fake packet injection

Inventive Principle:
Principle #35Parameter changes

2Reliability

If packet authentication is implemented in a VXLAN system, then network security is improved, but device complexity increases due to additional authentication processing

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication code is generated in advance during the packet encapsulation process, before transmission. This preliminary action ensures that authentication verification at the receiving end is a simple comparison operation rather than a complex computation, reducing the processing complexity burden on network devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication mechanism uses cryptographic copying where the same authentication code generation algorithm and key pair are distributed to all VTEPs in the network. This allows each device to independently verify packets without requiring complex centralized authentication logic, simplifying device complexity while maintaining security

Inventive Principle:
Principle #26Copying

3Measurement precision

If dynamic token-based authentication is implemented across VTEPs, then packet verification accuracy is improved, but processing time increases due to token generation and verification operations

Engineering Contradiction:
Improvepacket verification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The authentication keys are updated periodically rather than being static, and the authentication code generation uses periodic cryptographic operations. This periodic action maintains high verification accuracy through frequent key rotation while keeping processing time manageable through efficient cryptographic algorithms and pre-computed key materials

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

Cryptographic key pairs are established and cached in advance before packet transmission occurs. This preliminary preparation of authentication materials allows the actual packet verification to use simple comparison operations rather than complex real-time cryptographic computations, reducing processing time while maintaining verification accuracy

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11652825B2Packet authentication in a VXLAN system
Publication Date: 2023.05.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11652825B2 patent drawing
  • US11652825B2 patent drawing
  • US11652825B2 patent drawing

AI summary

Embodiments of the present disclosure relate to methods, systems, and computer program products for event management. In a method, a token is obtained at a first agent device that is included in a network system, the token is for authenticating a first packet that is transmitted in the network system, and the first packet is generated according to a first network format. A second packet is generated based on the first packet and the token according to a second network format. The second packet is transmitted to a second agent device that is included in the network system, here both of the first and second agent devices support the first and second network formats. With these embodiments, the packet may be authenticated in a more effective way.