Forwarding network traffic associated with a security class via a routing path associated with the security class
By updating routing tables and selecting appropriate routing paths between network devices, the complexity and latency issues of secure routing in multi-device networks are resolved, enabling efficient, low-latency security service forwarding and reducing the need for specialized hardware and computing resources.
Patent Information
- Application Number
- CN202210117853.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-12-08
- Filing Date
- 2022-02-08
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2042-02-08
AI Technical Summary
When securely routing network traffic between multiple network devices, existing technologies require specialized hardware and extensive computing resources, leading to complexity and latency, making it difficult to achieve proper security paths and efficient traffic forwarding.
By sending announcement messages between network devices to update the routing table, determining the routing paths associated with different security classifications, and selecting appropriate routing paths for network business forwarding based on the routing table, the business engineering process is avoided, the demand for computing resources and forwarding delay are reduced.
It achieves efficient, low-latency and secure routing between multiple network devices, reduces device complexity, reduces dependence on specialized hardware and computing resources, and ensures appropriate security for network services.
Smart Images

Figure CN116248572B_ABST
Abstract
Description
Background Art
[0001] Media Access Control Security (MACsec) provides secure communications for services on physical links such as Ethernet links. MACsec provides point-to-point security on links between directly connected devices. Summary of the Invention
[0002] Some implementations described herein relate to a network device. The network device may include one or more memories and one or more processors. The network device may be configured to receive a first message, a second message, and a third message from another network device. The network device may be configured to update a routing table based on the first message, the second message, and the third message. The network device may be configured to determine, based on the routing table, a first routing path associated with a first security classification from the network device to the other network device, a second routing path associated with a second security classification from the network device to the other network device, and a third routing path associated with a third security classification from the network device to the other network device. The network device may be configured to receive network traffic destined for the other network device and associated with a specific security classification among the first, second, or third security classifications. The network device may be configured to forward the network traffic based on a specific routing path associated with the other network device and the specific security classification among the first, second, or third routing paths.
[0003] Some implementations described herein relate to a non-transitory computer-readable medium storing an instruction set for a network device. The instruction set, when executed by one or more processors of the network device, may cause the network device to determine, based on a routing table, a first routing path associated with a first security classification from the network device to another network device. The instruction set, when executed by the one or more processors of the network device, may cause the network device to determine, based on the routing table, a second routing path associated with a second security classification from the network device to another network device. The instruction set, when executed by the one or more processors of the network device, may cause the network device to determine, based on the routing table, a third routing path associated with a third security classification from the network device to another network device. The instruction set, when executed by the one or more processors of the network device, may cause the network device to receive network traffic destined for another network device and associated with a specific security classification among the first, second, or third security classifications. The instruction set, when executed by the one or more processors of the network device, may cause the network device to forward the network traffic based on the specific routing path associated with the other network device and the specific security classification among the first, second, or third routing paths.
[0004] Some implementations described herein relate to a method. The method may include determining, by a network device, multiple routing paths from the network device to another network device based on a routing table, wherein the multiple routing paths are respectively associated with multiple security classifications. The method may include receiving, by the network device, network traffic destined for the other network device and associated with a specific security classification from among the multiple security classifications. The method may include forwarding, by the network device, the network traffic based on a specific routing path from the multiple routing paths that is associated with the other network device and the specific security classification. BRIEF DESCRIPTION OF THE DRAWINGS
[0005] Figure 1A-1D is a diagram of an example implementation described herein;
[0006] Figure 2 is a diagram of an example environment in which the systems and / or methods described herein may be implemented;
[0007] Figure 3 and Figure 4 yes Figure 2 diagrams of example components of one or more devices; and
[0008] Figure 5-Figure 6 is a flow diagram of an example process related to forwarding network traffic associated with a security classification via a routing path associated with the security classification. DETAILED DESCRIPTION
[0009] The following detailed description of example implementations refers to the accompanying drawings, in which the same reference numbers in different drawings may identify the same or similar elements.
[0010] In a network of network devices, media access control security (MACsec) can be used to provide point-to-point security on links between directly connected network devices. However, for network traffic that needs to be securely routed between more than two network devices, it can be challenging to ensure that the network traffic is transmitted via a routing path that only includes MACsec links. In some cases, before forwarding the network traffic, the network device can use a traffic engineering process (e.g., a Level 3 process in the Open Systems Interconnection (OSI) model) to process the network traffic to encapsulate the network traffic with information so that the network traffic is directed through the network via an appropriately secure routing path. However, in order to perform such a traffic engineering process, the network device must include specialized hardware. In addition, performing such processing typically uses a large amount of computing resources (e.g., processing resources, memory resources, communication resources, and / or power resources, etc.) and results in latency or delays associated with routing the network traffic through the network.
[0011] Some implementations described herein involve determining routing paths for network traffic associated with different security classifications, such as routing paths for public network traffic, routing paths for private network traffic, and / or routing paths for restricted network traffic. Public network traffic can be routed via any type of link. Private network traffic can be routed via links that support authentication (e.g., links that are authenticated using MACsec and links that are authenticated and encrypted using MACsec). Restricted network traffic can be routed via links that support authentication and encryption (e.g., links that are authenticated and encrypted using MACsec).
[0012] In some implementations, each network device in a network sends an announcement message to other network devices in the network, wherein each announcement message indicates a security classification of a link of the network device. Accordingly, the network device that receives the announcement message updates a routing table based on the announcement message and determines, based on the routing table, a routing path associated with each of a plurality of security classifications supported by the network (e.g., a public security classification, a private security classification, and / or a restricted security classification) from the network device to other network devices in the network. In this manner, the network device determines a plurality of routing paths to each of the other network devices in the network (where each of the plurality of routing paths is associated with a security classification).
[0013] In some implementations, a network device receives network traffic destined for another network device in a network and associated with a specific security classification among a plurality of security classifications. The network device selects a routing path associated with the specific security classification among a plurality of routing paths to the other network device, and forwards the network traffic to the other network device based on the specific routing path. This allows the network traffic to be routed through the network via links that provide appropriate security for the network traffic. For example, when the network traffic is public network traffic, the network traffic is routed through the network via any type of link in the network; when the network traffic is private network traffic, the network traffic is routed through the network via links that support authentication (e.g., links that are authenticated using MACsec and / or links that are authenticated and encrypted using MACsec); and when the network device is subject to network traffic restrictions, the network traffic is routed through the network via links that support authentication and encryption (e.g., links that are authenticated and encrypted using MACsec).
[0014] In this way, some implementations described herein enable network services associated with security classifications to be forwarded via routing paths associated with security classifications. Therefore, some implementations described herein provide (e.g., using level 2 techniques in the OSI model) appropriate security paths for routing network services without using service engineering processes (e.g., level 3 processes in the OSI model). This reduces the complexity of network devices for routing network services in the network (e.g., because network devices do not need to include specialized hardware to perform service engineering processes). In addition, the network devices described herein do not need to encapsulate network services before forwarding them, which reduces the amount of computing resources (e.g., processing resources, memory resources, communication resources, and / or power resources, etc.) required for forwarding network services (e.g., otherwise would be required when using service engineering processes). This also reduces or eliminates latency or delays associated with routing network services, which would otherwise be generated by using service engineering.
[0015] Figure 1A-1D FIG. 1 is a diagram of an example 100 associated with forwarding network traffic associated with a security classification via a routing path associated with the security classification. Figure 1A-1D As shown, example 100 includes an endpoint device and a plurality of network devices associated with a network (shown as network devices 1-4). Additional details of the endpoint device, the plurality of network devices, and the network are provided elsewhere herein.
[0016] In some implementations, a network device in the plurality of network devices may be connected to another network device in the plurality of network devices via a link, such as an Ethernet link. Figure 1A-1D As shown, network device 1 can be connected to network device 2 via link (1, 2), to network device 3 via link (1, 3), and to network device 4 via link (1, 4); network device 2 can be connected to network device 1 via link (1, 2), and to network device 4 via link (2, 4); network device 3 can be connected to network device 1 via link (1, 3), and to network device 4 via link (3, 4); and network device 4 can be connected to network device 1 via link (1, 4), to network device 2 via link (2, 4), and to network device 3 via link (3, 4). In some implementations, a network device in the plurality of network devices may not be connected to another network device in the plurality of network devices via a link. For example, further as Figure 1A-1D As shown, network device 2 may not be connected to network device 3 via a link. In this manner, multiple network devices may be connected to each other via a set of links (eg, one or more links), such as in a linked network topology.
[0017] In some implementations, each link in the set of links can be associated with a security classification from a plurality of security classifications. Figure 1A-1D As shown, link (1, 4) (shown in solid lines) can be associated with a first security classification, link (1, 2) and link (2, 4) (shown in dashed lines) can be associated with a second security classification, and link (1, 3) and link (3, 4) (shown in dotted lines) can be associated with a third security classification. The security classification can indicate the type of network traffic that can be transmitted via the links associated with the security classification. For example, the first security classification can be a public security classification, which can indicate that public (e.g., regular, non-confidential, or confidential) network traffic can be transmitted via the links associated with the first security classification (e.g., link (1, 4)); the second security classification can be a private security classification, which can indicate that private (e.g., confidential, but not confidential) network traffic can be transmitted via the links associated with the second security classification (e.g., link (1, 2) and link (2, 4)); and the third security classification can be a restricted security classification, which can indicate that restricted (e.g., confidential) network traffic can be transmitted via the links associated with the third security classification (e.g., link (1, 3) and link (3, 4)).
[0018] In some implementations, each security classification in the plurality of security classifications may have a security level (e.g., where the value of the security level indicates the strictness of the security classification, with lower values indicating less strictness and higher values indicating greater strictness). For example, the security level of a first security classification may be 1, the security level of a second security classification may be 2, and the security level of a third security classification may be 3. Thus, each link in the set of links may be associated with a security classification and a security level of the security classification. For example, Figure 1A-1D As shown, link (1, 4) (shown in solid lines) can be associated with a first security classification and security level 1, link (1, 2) and link (2, 4) (shown in dashed lines) can be associated with a second security classification and security level 2, and link (1, 3) and link (3, 4) (shown in dotted lines) can be associated with a third security classification and security level 3.
[0019] In some implementations, as further described herein, network traffic associated with a particular security classification among a plurality of security classifications may be transmitted via a set of links associated with one or more security classifications having corresponding security levels greater than or equal to the security level of the particular security classification. For example, network traffic associated with a first security classification and security level 1 may be transmitted via at least one of link (1, 4) (e.g., having security level 1), link (1, 2), or link (2, 4) (e.g., having security level 2), and / or at least one of link (1, 3) or link (3, 4) (e.g., having security level 3); network traffic associated with a second security classification and security level 2 may be transmitted via at least one of link (1, 2) or link (2, 4) (e.g., having security level 2), and / or at least one of link (1, 3) or link (3, 4) (e.g., having security level 3); and network traffic associated with a second security classification and security level 3 may be transmitted via link (1, 3) and / or link (3, 4) (e.g., having security level 3).
[0020] In some implementations, each link in the set of links may be a specific link type from among a plurality of link types (e.g., based on the link's association with a security classification). Figure 1A-1D As shown, links (1, 4) associated with a first security classification (shown in solid lines) may be links that do not utilize authentication and do not utilize encryption (e.g., links that do not utilize MACsec); links (1, 2) and links (2, 4) associated with a second security classification (shown in dashed lines) may be links that utilize authentication but do not utilize encryption (e.g., links that utilize MACsec for authentication); and links (1, 3) and links (3, 4) associated with a third security classification (shown in dot-dash lines) may be links that utilize authentication and utilize encryption (e.g., links that utilize MACsec for authentication and encryption). In this manner, in some implementations, a security classification may indicate the type of link associated with the security classification. For example, when associated with a link (e.g., link (1, 4)), a first security classification may indicate that the link does not utilize authentication and does not utilize encryption; when associated with a link (e.g., link (1, 2) or link (2, 4)), a second security classification may indicate that the link utilizes authentication and does not utilize encryption; and when associated with a link (e.g., link (1, 3) or link (3, 4)), a third security classification may indicate that the link utilizes authentication and utilizes encryption.
[0021] In some implementations, each link in the set of links can be associated with at least one cost metric. For example, a link can be associated with an interior gateway protocol (IGP) cost metric, a traffic engineering (TE) cost metric, and / or one or more other cost metrics. In some implementations, determining a routing path associated with a particular security classification from a network device in the plurality of network devices to another network device in the plurality of network devices can be based on a particular cost metric from at least one cost metric for each link in the set of links. For example, determining a first routing path associated with a first security classification can be based on a corresponding first cost metric associated with the set of links (e.g., an IGP cost metric), determining a second routing path associated with a second security classification can be based on a corresponding second cost metric associated with the set of links (e.g., a TE cost metric), determining a third routing path associated with a third security classification can be based on a corresponding third cost metric associated with the set of links (e.g., another cost metric), and so on.
[0022] In some implementations, a network device in the plurality of network devices may send one or more announcement messages to another network device in the plurality of network devices. Figure 1A As shown at 105, network device 4 may send one or more advertisement messages to each of network devices 1, 2, and 3 (e.g., each of network devices 1, 2, and 3 may receive an individual copy of the one or more advertisement messages). A network device may send an advertisement message to another network device for each link connected to the network device. For example, Figure 1A As shown, network device 4 can send a first announcement message associated with link (1, 4), a second announcement message associated with link (2, 4), and a third announcement message associated with link (3, 4) to each of network devices 1, network device 2, and network device 3.
[0023] Each of the one or more announcement messages may include information identifying the network device, information identifying a link of the network device (e.g., associated with the announcement message), information indicating at least one cost metric of the link (e.g., an IGP cost metric, a TE cost metric, and / or one or more other cost metrics), information indicating that the link is associated with a security classification from a plurality of security classifications, and / or other information. For example, a first announcement message sent by network device 4 may include information identifying network device 4, information identifying link (1, 4), information indicating at least one cost metric of link (1, 4), and information indicating that link (1, 4) is associated with a first security classification; a second announcement message sent by network device 4 may include information identifying network device 4, information identifying link (2, 4), information indicating at least one cost metric of link (2, 4), and information indicating that link (2, 4) is associated with a second security classification; and a third announcement message sent by network device 4 may include information identifying network device 4, information identifying link (3, 4), information indicating at least one cost metric of link (3, 4), and information indicating that link (3, 4) is associated with a third security classification.
[0024] In some implementations, a network device in the plurality of network devices may update a routing table (e.g., stored and / or maintained by the network device) based on one or more advertisement messages received by the network device from another network device in the plurality of network devices. Figure 1B As shown in FIG. 110 , the network device 1 may update the routing table based on one or more advertisement messages received by the network device 1 from the network device 4 (eg, as described herein with respect to FIG. 110 ). Figure 1A The network device may update the routing table by including at least some of the information included in the one or more announcement messages in the routing table. Figure 1B As shown, network device 1 may update the routing table to include or modify entries associated with link (1, 4), link (2, 4), and link (3, 4), wherein the entries include at least some information from the first announcement message, the second announcement message, and the third announcement message, respectively (e.g., sent from network device 4 to network device 1). The routing table may include, for example, an entry associated with each link of a plurality of network devices, and each entry may include information indicating the link, information indicating at least one cost metric for the link, information indicating a security classification associated with the link from a plurality of security classifications, and / or other information.
[0025] In some implementations, a network device among the plurality of network devices may determine a plurality of routing paths from the network device to another network device. The plurality of routing paths may be associated with a plurality of security classifications, respectively. For example, Figure 1CAs shown at 115, network device 1 may determine multiple routing paths (e.g., a first routing path, a second routing path, and a third routing path) from network device 1 to network device 4. The first routing path (indicated by a solid arrow) may be associated with a first security classification, the second routing path (indicated by a dashed arrow) may be associated with a second security classification, and the third routing path (indicated by a dashed arrow) may be associated with a third security classification.
[0026] The network device may determine a plurality of routing paths based on a routing table (e.g., stored and / or maintained by the network device). In some implementations, to determine a particular routing path associated with a particular security classification, the network device may identify a set of links associated with one or more security classifications having corresponding security levels greater than or equal to the security level of the particular security classification (e.g., by searching and / or reading a routing table). Accordingly, the network device may determine (e.g., based on corresponding cost metrics of the set of links and using a path calculation technique such as a shortest path first (SPF) technique) the particular routing path.
[0027] For example, to determine a first routing path (e.g., associated with a first security classification having a security level of 1), network device 1 may identify a first set of links (e.g., by searching and / or reading a routing table) that are associated with at least one of a plurality of security classifications, such as at least one of the first security classification (e.g., having a security level of 1), the second security classification (e.g., having a security level of 2), or the third security classification (e.g., having a security level of 3). Network device 1 may determine the first routing path (e.g., based on corresponding cost metrics of the first set of links and using a path calculation technique, such as an SPF technique). In this manner, the first routing path may include at least one of links that do not utilize authentication and do not utilize encryption (e.g., links that do not utilize MACsec), links that utilize authentication but not encryption (e.g., links that utilize MACsec for authentication), or links that utilize authentication and utilize encryption (e.g., links that utilize MACsec for both authentication and encryption).
[0028] As another example, to determine a second routing path (e.g., associated with a second security classification having a security level of 2), network device 1 may identify a second set of links (e.g., by searching and / or reading a routing table) that are associated with at least one security classification from the first portion of the plurality of security classifications (but not the second portion of the plurality of security classifications), such as the second security classification (e.g., having a security level of 2) or the third security classification (e.g., having a security level of 3) (but not at least one security classification from the first security classification (e.g., having a security level of 1)). Network device 1 may determine the second routing path (e.g., based on corresponding cost metrics of the second set of links and using a path computation technique such as SPF). In this manner, the second routing path may include at least one of links that utilize authentication but not encryption (e.g., links that utilize MACsec for authentication) or links that utilize both authentication and encryption (e.g., links that utilize MACsec for authentication and encryption), and may not include links that do not utilize authentication and do not utilize encryption (e.g., links that do not utilize MACsec).
[0029] In an additional example, to determine a third routing path (e.g., associated with a third security classification having a security level of 3), network device 1 may identify a third set of links (e.g., by searching and / or reading a routing table) that are associated with the third security classification (e.g., having a security level of 3) but not associated with the first security classification (e.g., having a security level of 1) and the second security classification (e.g., having a security level of 2). Network device 1 may determine the third routing path (e.g., based on corresponding cost metrics of the third set of links and using a path computation technique such as an SPF technique). In this manner, the third routing path may include links that utilize authentication and utilize encryption (e.g., links that utilize MACsec for authentication and encryption), and the third routing path may exclude links that do not utilize authentication and do not utilize encryption (e.g., links that do not utilize MACsec), as well as links that utilize authentication but do not utilize encryption (e.g., links that utilize MACsec for authentication).
[0030] In some implementations, a network device among the plurality of network devices may receive network traffic destined for another network device among the plurality of network devices and associated with a particular security classification among the plurality of security classifications. Figure 1D As shown at 120, network device 1 may receive network traffic (eg, from an endpoint device). The network traffic may be destined for network device 4 and may be associated with a particular security classification of the first, second, or third security classifications.
[0031] In some implementations, a network device may forward network traffic based on a particular routing path among a plurality of routing paths that is associated with another network device and a particular security classification. Figure 1D As further shown by reference numeral 125 , network device 1 may forward network traffic based on a specific routing path (shown as the second routing path) associated with network device 4 and a specific security classification of the network traffic among the first routing path, the second routing path, or the third routing path.
[0032] In some implementations, to forward network traffic, a network device may process the network traffic to determine that the destination of the network traffic is another network device and that the network traffic is associated with a specific security classification. Accordingly, the network device may select a specific routing path associated with the other network device and the specific security classification based on information identifying the other network device and the specific security classification. The network device may determine a next hop for the network traffic (e.g., as indicated by the specific routing path) and may forward the network traffic to the next hop. In this manner, the network device may cause the network traffic to be forwarded according to the specific routing path.
[0033] Furthermore, in this manner, a network device can cause network traffic to be transmitted from the network device to another network device via one or more links associated with one or more security classifications having corresponding security levels greater than or equal to the security level of a particular security classification. Figure 1D , network device 1 can enable network services to be transmitted from network device 1 to network device 4 via one or more links associated with one or more security classifications (e.g., a second security classification with security level 2 and / or a third security classification with security level 3) whose corresponding security levels are greater than or equal to a specific security classification (e.g., a second security classification with security level 2).
[0034] As mentioned above, Figure 1A-1D are provided as examples. Other examples may be related to Figure 1A-1D Different than described. Figure 1A-1D The number and arrangement of devices shown are provided as examples. Figure 1A-1D There may be more devices, fewer devices, different devices, or devices arranged differently than shown. Figure 1A-1D Two or more of the devices shown may be implemented in a single device, or Figure 1A-1D The single device shown may be implemented as multiple distributed devices. Additionally or alternatively, Figure 1A-1D The illustrated set of devices (e.g., one or more devices) may perform the operations described as being performed by Figure 1A-1D Another group of devices is shown performing one or more functions.
[0035] Figure 2 2 is a diagram of an example environment 200 in which the systems and / or methods described herein may be implemented. Figure 2 As shown, environment 200 may include one or more endpoint devices 210, a set of network devices 220 (shown as network device 220-1 through network device 220-N, where N≥2), and a network 230. The devices of environment 200 may be interconnected via wired connections, wireless connections, or a combination of wired and wireless connections.
[0036] Endpoint device 210 includes one or more devices capable of receiving, generating, storing, processing, and / or providing information (such as the information described herein). For example, endpoint device 210 may include a mobile phone (e.g., a smartphone or wireless phone), a laptop computer, a tablet computer, a desktop computer, a handheld computer, a gaming device, a wearable communication device (e.g., a smartwatch, smart glasses, a heart rate monitor, a fitness tracker, smart clothing, smart jewelry, or a head-mounted display), a network device, or a similar type of device. In some implementations, endpoint device 210 may provide network services to other endpoint devices 210 via network 230 and / or may receive network services (e.g., by using network device 220 as an intermediary to route network services).
[0037] The network device 220 includes one or more devices that can receive, process, store, route and / or provide network services in the manner described herein. For example, the network device 220 may include a router, such as a label switching router (LSR), a label edge router (LER), an ingress router, an egress router, a provider router (e.g., a provider edge router or a provider core router), a virtual router, or other types of routers. Additionally or alternatively, the network device 220 may include a gateway, a switch, a firewall, a hub, a bridge, a reverse proxy, a server (e.g., a proxy server, a cloud server or a data center server), a load balancer and / or similar devices. In some implementations, the network device 220 may be a physical device implemented in a housing such as a chassis. In some implementations, the network device 220 may be a virtual device implemented by one or more computer devices in a cloud computing environment or a data center. In some implementations, a group of network devices 220 may be a group of data center nodes for routing network services through the network 230. In some implementations, the network device 220 may receive (e.g., from the endpoint device 210 or another network device 220) a business network associated with a particular security classification among a plurality of security classifications; determine a plurality of routing paths from the network device 220 to the other network device 220 (e.g., where the plurality of routing paths are respectively associated with a plurality of security classifications); and / or may forward the network device based on a particular routing path among the plurality of routing paths that is associated with the other network device and the particular security classification.
[0038] The network 230 includes one or more wired and / or wireless networks. For example, the network 230 may include a packet-switched network, a cellular network (e.g., a fifth-generation (5G) network, a fourth-generation (4G) network such as a Long Term Evolution (LTE) network, a third-generation (3G) network, or a Code Division Multiple Access (CDMA) network), a public land mobile network (PLMN), a local area network (LAN), a wide area network (WAN), a metropolitan area network (MAN), a telephone network (e.g., a public switched telephone network (PSTN)), a private network, an ad hoc network, an intranet, the Internet, a fiber-optic-based network, a cloud computing network, etc., and / or combinations of these or other types of networks.
[0039] Figure 2 The number and arrangement of devices and networks shown are provided as examples. Figure 2 There may be more devices and / or networks, fewer devices and / or networks, different devices and / or networks, or differently arranged devices and / or networks than shown. Figure 2 Two or more of the devices shown may be implemented in a single device, or Figure 2The single device shown may be implemented as multiple distributed devices. Additionally or alternatively, one set of devices (eg, one or more devices) of environment 200 may perform one or more functions described as being performed by another set of devices of environment 200.
[0040] Figure 3 is a diagram of example components of a device 300 that may correspond to an endpoint device 210 and / or a network device 220. In some implementations, the endpoint device 210 and / or the network device 220 includes one or more devices 300 and / or one or more components of a device 300. Figure 3 As shown, device 300 may include a bus 310 , a processor 320 , a memory 330 , an input component 340 , an output component 350 , and a communication component 360 .
[0041] The bus 310 includes one or more components that enable wired and / or wireless communication between components of the device 300. The bus 310 may Figure 3 The processor 320 may be a computer program product or a processor that is coupled together, such as via operational coupling, communicative coupling, electronic coupling, and / or electrical coupling. The processor 320 may include a central processing unit, a graphics processing unit, a microprocessor, a controller, a microcontroller, a digital signal processor, a field programmable gate array, an application specific integrated circuit, and / or another type of processing component. The processor 320 may be implemented in hardware, firmware, or a combination of hardware and software. In some implementations, the processor 320 may include one or more processors that can be programmed to perform one or more operations or processes described elsewhere herein.
[0042] Memory 330 includes volatile and / or non-volatile memory. For example, memory 330 may include random access memory (RAM), read-only memory (ROM), a hard drive and / or another type of memory (e.g., flash memory, magnetic memory and / or optical memory). Memory 330 may include internal memory (e.g., RAM, ROM or hard drive) and / or removable memory (e.g., removable via a universal serial bus connection). Memory 330 may be a non-transitory computer-readable medium. Memory 330 stores information, instructions and / or software (e.g., one or more software applications) related to the operation of device 300. In some implementations, memory 330 includes one or more memories such as coupled to one or more processors (e.g., processor 320) via bus 310.
[0043] Input component 340 enables device 300 to receive input, such as user input and / or sensory input. For example, input component 340 can include a touch screen, keyboard, keypad, mouse, button, microphone, switch, sensor, global positioning system sensor, accelerometer, gyroscope and / or actuator. Output component 350 enables device 300 to provide output, such as via a display, speaker and / or light emitting diode. Communication component 360 enables device 300 to communicate with other devices via wired connection and / or wireless connection. For example, communication component 360 can include a receiver, transmitter, transceiver, modem, network interface card and / or antenna.
[0044] The device 300 can perform one or more operations or processes described herein. For example, a non-transitory computer-readable medium (e.g., memory 330) can store an instruction set (e.g., one or more instructions or codes) executed by the processor 320. The processor 320 can execute the instruction set to perform one or more operations or processes described herein. In some implementations, the execution of the instruction set by one or more processors 320 causes the one or more processors 320 and / or device 300 to perform one or more operations or processes described herein. In some implementations, a hard-wired circuit system can replace the instruction or be used in combination with the instruction to perform one or more operations or processes described herein. Additionally or alternatively, the processor 320 can be configured to perform one or more operations or processes described herein. Therefore, the implementation described herein is not limited to any particular combination of hardware circuit system and software.
[0045] Figure 3 The number and arrangement of components shown are provided as examples. Figure 3 Compared to the shown, device 300 may include more components, fewer components, different components, or components arranged differently. Additionally or alternatively, one or more components of device 300 (e.g., one or more components) may perform one or more functions described as being performed by another group of components of device 300.
[0046] Figure 4 4 is a diagram of example components of a device 400. Device 400 may correspond to endpoint device 210 and / or network device 220. In some implementations, endpoint device 210 and / or network device 220 may include one or more devices 400 and / or one or more components of device 400. Figure 4As shown, the device 400 may include one or more input components 410-1 to 410-B (B≥1) (hereinafter collectively referred to as input components 410 and individually referred to as input components 410), a switching component 420, one or more output components 430-1 to 430-C (C≥1) (hereinafter collectively referred to as output components 430 and individually referred to as output components 430), and a controller 440.
[0047] The input component 410 can be one or more attachment points for a physical link and can be one or more entry points for incoming traffic (such as packets). The input component 410 can process incoming traffic, such as by performing data link layer encapsulation or decapsulation. In some implementations, the input component 410 can transmit and / or receive packets. In some implementations, the input component 410 can include an input line card that includes one or more packet processing components (e.g., in the form of an integrated circuit), such as one or more interface cards (IFCs), a packet forwarding component, a line card controller component, an input port, a processor, a memory, and / or an input queue. In some implementations, the device 400 can include one or more input components 410.
[0048] The switching component 420 can interconnect the input component 410 with the output component 430. In some implementations, the switching component 420 can be implemented via one or more crossbar switches, via a bus, and / or through a shared memory. The shared memory can act as a temporary buffer to store packets from the input component 410 before they are ultimately scheduled for transmission to the output component 430. In some implementations, the switching component 420 can enable the input component 410, the output component 430, and / or the controller 440 to communicate with each other.
[0049] The output component 430 can store packets and can schedule packets for transmission on an output physical link. The output component 430 can support data link layer encapsulation or decapsulation, and / or various higher-level protocols. In some implementations, the output component 430 can transmit packets and / or receive packets. In some implementations, the output component 430 can include an output line card that includes one or more packet processing components (e.g., in the form of an integrated circuit), such as one or more IFCs, packet forwarding components, line card controller components, output ports, processors, memories, and / or output queues. In some implementations, the device 400 can include one or more output components 430. In some implementations, the input component 410 and the output component 430 can be implemented by the same set of components (e.g., the input component / output component can be a combination of the input component 410 and the output component 430).
[0050] Controller 440 includes, for example, a processor in the form of a CPU, GPU, APU, microprocessor, microcontroller, DSP, FPGA, ASIC, and / or other types of processors. The processor is implemented in hardware, firmware, or a combination of hardware and software. In some implementations, controller 440 may include one or more processors that can be programmed to perform functions.
[0051] In some implementations, controller 440 may include RAM, ROM, and / or another type of dynamic or static storage device (eg, flash memory, magnetic memory, optical memory, etc.) that stores information and / or instructions for use by controller 440 .
[0052] In some implementations, the controller 440 can communicate with other devices, networks, and / or systems connected to the device 400 to exchange information about the network topology. The controller 440 can create a routing table based on the network topology information, can create a forwarding table based on the routing table, and can forward the forwarding table to the input component 410 and / or the output component 430. The input component 410 and / or the output component 430 can use the forwarding table to perform route lookups for incoming and / or outgoing packets.
[0053] The controller 440 may perform one or more of the processes described herein. The controller 440 may perform these processes in response to executing software instructions stored by a non-transitory computer-readable medium. A computer-readable medium is defined herein as a non-transitory memory device. A memory device includes memory space within a single physical storage device or memory space across multiple physical storage devices.
[0054] The software instructions may be read into the memory and / or storage components associated with the controller 440 from another computer-readable medium or from another device via a communication interface. When executed, the software instructions stored in the memory and / or storage components associated with the controller 440 may cause the controller 440 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry may be used in place of or in combination with software instructions to perform one or more processes described herein. Thus, the implementations described herein are not limited to any specific combination of hardware circuitry and software.
[0055] Figure 4 The number and arrangement of components shown are provided as examples. Figure 4 Compared to the shown, device 400 may include more components, fewer components, different components, or components arranged differently. Additionally or alternatively, one or more components of device 400 (e.g., one or more components) may perform one or more functions described as being performed by another group of components of device 400.
[0056] Figure 5 is a flow diagram of an example process 500 associated with forwarding network traffic associated with a security classification via a routing path associated with the security classification. Figure 5 One or more process blocks of are performed by a network device (e.g., network device 220). In some implementations, Figure 5 One or more process blocks of are performed by another device or group of devices, separate from or including the network device, such as an endpoint device (e.g., endpoint device 210). Additionally or alternatively, Figure 5 One or more process blocks may be performed by one or more components of device 300, such as processor 320, memory 330, input component 340, output component 350, and / or communication component 360; by one or more components of device 400, such as input component 410, switching component 420, output component 430, and / or controller 440; and / or by one or more components of another device.
[0057] like Figure 5 As shown, process 500 may include determining, based on a routing table, a plurality of routing paths from a network device to another network device, wherein the plurality of routing paths are respectively associated with a plurality of security classifications (block 510). For example, the network device may determine, based on a routing table, a plurality of routing paths from the network device to another network device, wherein the plurality of routing paths are respectively associated with a plurality of security classifications, as described above. In some implementations, the plurality of routing paths are respectively associated with a plurality of security classifications.
[0058] like Figure 5 As further shown, process 500 may include receiving network traffic destined for another network device and associated with a particular security classification among a plurality of security classifications (block 520). For example, a network device may receive network traffic destined for another network device and associated with a particular security classification among a plurality of security classifications, as described above.
[0059] like Figure 5 As further shown, process 500 may include forwarding the network traffic based on a particular routing path in the plurality of routing paths that is associated with another network device and a particular security classification (block 530). For example, the network device may forward the network traffic based on a particular routing path in the plurality of routing paths that is associated with another network device and a particular security classification, as described above.
[0060] Process 500 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in conjunction with one or more other processes described elsewhere herein.
[0061] In a first implementation, process 500 includes receiving one or more announcement messages from another network device before determining multiple routing paths, wherein each of the one or more announcement messages includes at least one of the following: information identifying the other network device, information identifying a link of the other network device, information indicating at least one cost metric of the link, or information indicating that the link is associated with a security classification in a plurality of security classifications; and updating a routing table based on the one or more announcement messages.
[0062] In a second implementation, either alone or in combination with the first implementation, a first routing path among the plurality of routing paths includes at least one of a link that does not utilize authentication and does not utilize encryption, a link that utilizes authentication but does not utilize encryption, or a link that utilizes authentication and utilizes encryption, and a second routing path among the plurality of routing paths includes at least one of a link that utilizes authentication but does not utilize encryption or a link that utilizes authentication and utilizes encryption, and does not include a link that does not utilize authentication and does not utilize encryption.
[0063] In a third implementation, alone or in combination with one or more of the first and second implementations, a first routing path in the plurality of routing paths includes a set of links associated with at least one security classification in the plurality of security classifications, and a second routing path in the plurality of routing paths includes a set of links associated with at least one security classification in the first set of the plurality of security classifications and not associated with a second set of the plurality of security classifications.
[0064] In a fourth implementation, alone or in combination with one or more of the first to third implementations, network traffic is forwarded based on a specific routing path so that the network traffic is transmitted from a network device to another network device via one or more links associated with a security classification having a corresponding security level greater than or equal to the security level of a specific security classification.
[0065] although Figure 5 Example blocks of process 500 are shown, but in some implementations, Figure 5 Process 500 may include more blocks, fewer blocks, different blocks, or blocks arranged differently than shown. Additionally or alternatively, two or more of the blocks in process 500 may be executed in parallel.
[0066] Figure 6 is a flow diagram of an example process 600 associated with forwarding network traffic associated with a security classification via a routing path associated with the security classification. Figure 6 One or more process blocks of are performed by a network device (e.g., network device 220). In some implementations, Figure 6One or more process blocks of are performed by another device or group of devices, separate from or including the network device, such as an endpoint device (e.g., endpoint device 210). Additionally or alternatively, Figure 6 One or more process blocks may be performed by one or more components of device 300, such as processor 320, memory 330, input component 340, output component 350, and / or communication component 360; by one or more components of device 400, such as input component 410, switching component 420, output component 430, and / or controller 440; and / or by one or more components of another device.
[0067] like Figure 6 As shown, process 600 may include receiving a first announcement message, a second announcement message, and a third announcement message from another network device (block 610). For example, the network device may receive the first announcement message, the second announcement message, and the third announcement message from the other network device, as described above. In some implementations, the first announcement message includes information indicating that a first link of the other network device is associated with a first security classification, the second announcement message includes information indicating that a second link of the other network device is associated with a second security classification, and the third announcement message includes information indicating that a third link of the other network device is associated with a third security classification.
[0068] like Figure 6 As further shown, process 600 may include updating a routing table based on the first, second, and third announcement messages (block 620). For example, the network device may update a routing table based on the first, second, and third announcement messages, as described above.
[0069] like Figure 6 As further shown, process 600 may include determining, based on the routing table, a first routing path associated with a first security classification from the network device to another network device, a second routing path associated with a second security classification from the network device to another network device, and a third routing path associated with a third security classification from the network device to another network device (block 630). For example, the network device may determine, based on the routing table, the first routing path associated with the first security classification from the network device to another network device, the second routing path associated with the second security classification from the network device to another network device, and the third routing path associated with the third security classification from the network device to another network device, as described above.
[0070] like Figure 6As further shown, process 600 may include receiving network traffic destined for another network device and associated with a particular security classification among the first security classification, the second security classification, or the third security classification (block 640). For example, a network device may receive network traffic destined for another network device and associated with a particular security classification among the first security classification, the second security classification, or the third security classification, as described above.
[0071] like Figure 6 As further shown, process 600 may include forwarding the network traffic based on a particular routing path among the first routing path, the second routing path, or the third routing path that is associated with another network device and a particular security classification (block 650). For example, the network device may forward the network traffic based on a particular routing path among the first routing path, the second routing path, or the third routing path that is associated with another network device and a particular security classification, as described above.
[0072] Process 600 may include additional implementations, such as any single implementation or any combination of implementations described below and / or in conjunction with one or more other processes described elsewhere herein.
[0073] In a first implementation, the first announcement message also includes at least one of the following: information identifying another network device, information identifying a first link of another network device, or information indicating at least one cost measurement of the first link, and the second announcement message also includes at least one of the following: information identifying another network device, information identifying a second link of another network device, or information indicating at least one cost measurement of the second link, and the third announcement message also includes at least one of the following: information identifying another network device, information identifying a third link of another network device, or information indicating at least one cost measurement of the third link.
[0074] In a second implementation, alone or in combination with the first implementation, the first security classification is associated with a public security classification, the second security classification is associated with a private security classification, and the third security classification is associated with a restricted security classification.
[0075] In a third implementation, alone or in combination with one or more of the first and second implementations, the first link of the other network device is a link that does not utilize MACsec, the second link of the other network device is a link that utilizes MACsec for authentication, and the third link of the other network device is a link that utilizes MACsec for authentication and encryption.
[0076] In a fourth implementation, alone or in combination with one or more of the first to third implementations, the first routing path includes at least one of a link that does not utilize MACsec, a link that utilizes MACsec for authentication, or a link that utilizes MACsec for authentication and encryption; the second routing path includes at least one of a link that utilizes MACsec for authentication, or a link that utilizes MACsec for authentication and encryption, and does not include a link that does not utilize MACsec; and the third routing path includes a link that utilizes MACsec for authentication and encryption, and does not include a link that does not utilize MACsec and a link that utilizes MACsec for authentication.
[0077] In a fifth implementation, alone or in combination with one or more of the first to fourth implementations, determining the first routing path, the second routing path, and the third routing path includes identifying a first group of links associated with at least one of the first security classification, the second security classification, or the third security classification based on a routing table; determining the first routing path based on the first group of links using a path computation technique; identifying a second group of links associated with at least one of the second security classification or the third security classification based on the routing table; determining the second routing path based on the second group of links using a path computation technique; identifying a third group of links associated with the third security classification based on the routing table; and determining the third routing path based on the third group of links using a path computation technique.
[0078] In a sixth implementation, alone or in combination with one or more of the first to fifth implementations, forwarding the network traffic includes processing the network traffic to determine that the destination of the network traffic is another network device and that the network traffic is associated with a specific security classification; selecting a specific routing path associated with the other network device and the specific security classification based on information identifying the other network device and the specific security classification; determining a next hop of the network traffic based on the specific routing path; and forwarding the network traffic to the next hop.
[0079] In a seventh implementation, alone or in combination with one or more implementations of the first to sixth implementations, network traffic is forwarded based on a specific routing path so that the network traffic is transmitted from a network device to another network device via one or more links associated with a security classification whose corresponding security level is greater than or equal to the security level of a specific security classification.
[0080] In an eighth implementation, alone or in combination with one or more of the first to seventh implementations, the first routing path includes at least one of a link that does not utilize authentication and does not utilize encryption, a link that utilizes authentication but does not utilize encryption, or a link that utilizes authentication and utilizes encryption; the second routing path includes a link that utilizes authentication but does not utilize encryption, or at least one of a link that utilizes authentication and encryption, and does not include a link that does not utilize authentication and does not utilize encryption; and the third routing path includes a link that utilizes authentication and encryption, and does not include a link that does not utilize authentication and does not utilize encryption, and a link that utilizes authentication but does not utilize encryption.
[0081] In a ninth implementation, alone or in combination with one or more of the first to eighth implementations, the first routing path includes a group of links associated with at least one of the first security classification, the second security classification, and the third security classification; the second routing path includes a group of links associated with at least one of the second security classification or the third security classification but not associated with the first security classification; and the third routing path includes a group of links associated with the third security classification but not associated with the first security classification and the second security classification.
[0082] In a tenth implementation, alone or in combination with one or more of the first to ninth implementations, forwarding the network traffic includes processing the network traffic to determine that the destination of the network traffic is another network device and that the network traffic is associated with a specific security classification; selecting a specific routing path associated with the other network device and the specific security classification based on information identifying the other network device and the specific security classification; and forwarding the network traffic to a next hop indicated by the specific routing path.
[0083] although Figure 6 Example blocks of process 600 are shown, but in some implementations, Figure 5 Compared to what is shown, process 600 includes more blocks, fewer blocks, different blocks, or blocks arranged differently. Additionally or alternatively, two or more of the blocks in process 600 can be executed in parallel.
[0084] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit the implementation to the precise form disclosed. Modifications and variations are possible in light of the above disclosure, and modifications and variations can also be acquired from practice of the implementation.
[0085] As used herein, network traffic may include a set of packets. A packet may refer to a communication structure for transmitting information, such as a protocol data unit (PDU), a service data unit (SDU), a network packet, a datagram, a segment, a message, a block, a frame (e.g., an Ethernet frame), a portion of any of the foregoing, and / or another type of formatted or unformatted data unit capable of transmission over a network.
[0086] As used herein, the term "component" is intended to be broadly interpreted as hardware, firmware, or a combination of hardware and software. Obviously, the systems and / or methods described herein can be implemented in different forms of hardware, firmware, and / or a combination of hardware and software. The actual dedicated control hardware or software code used to implement these systems and / or methods does not limit the implementation. Therefore, the operation and behavior of the systems and / or methods are described herein without reference to specific software code - it should be understood that software and hardware can be used to implement the systems and / or methods based on the description herein.
[0087] Even if particular feature combinations are described in the claims and / or disclosed in the specification, these combinations are not intended to limit the disclosure of the various implementations. In fact, many of these features can be combined in ways that are not specifically described in the claims and / or disclosed in the specification. Although each dependent claim listed below may directly be dependent on only one claim, the disclosure of the various implementations includes the combination of each dependent claim with each other claim in the claim set. As used herein, a phrase referring to "at least one" in a list of items refers to any combination of these items, including single members. For example, "at least one of a, b, or c" is intended to cover any combination of a, b, c, ab, ac, bc, and abc, as well as a plurality of these items.
[0088] Any element, action or instruction used herein should not be interpreted as key or necessary, unless so clearly stated. Moreover, as used herein, the article "one" and "an" are intended to include one or more projects, and can be used interchangeably with "one or more". In addition, as used herein, the article "the" is intended to include one or more projects quoted in combination with the article "the", and can be used interchangeably with "the one or more". In addition, as used herein, the term "set" is intended to include one or more projects (for example, related projects, unrelated projects or the combination of related and unrelated projects), and can be used interchangeably with "one or more". If only intended to a project, phrase "only one" or similar language is used. In addition, as used herein, the term "have", "with", "have" etc. are intended to be open terms. In addition, unless otherwise clearly stated, phrase "based on" is intended to represent "at least partially based on". Furthermore, as used herein, the term "or" when used in a serial form is intended to be inclusive and interchangeable with "and / or" unless expressly stated otherwise (e.g., if used in conjunction with "either" or "only one of").
Claims
1. A network device comprising: one or more memories; as well as One or more processors to: A first message, a second message, and a third message are received from another network device, wherein: The first message includes information indicating that a first link of the other network device is associated with a first security classification based on a first cost metric, The second message includes information indicating that a second link of the another network device is associated with a second security classification based on a second cost metric, and the third message including information indicating that a third link of the another network device is associated with a third security classification based on a third cost metric, wherein the first cost metric, the second cost metric, and the third cost metric are different, and The first cost metric, the second cost metric, or the third cost metric is one or more of the following: Interior Gateway Protocol (IGP) cost metric, or Business Engineering TE cost measurement; updating a routing table based on the first message, the second message, and the third message; determining, based on the routing table, a first routing path associated with the first security classification from the network device to the other network device, a second routing path associated with the second security classification from the network device to the other network device, and a third routing path associated with the third security classification from the network device to the other network device; receiving network traffic destined for the other network device and associated with a particular security classification among the first security classification, the second security classification, or the third security classification; and The network traffic is forwarded based on a specific routing path among the first routing path, the second routing path, or the third routing path that is associated with the other network device and the specific security classification.
2. The network device according to claim 1, wherein: The first message further includes at least one of information identifying the other network device or information identifying the first link of the other network device; The second message further includes at least one of information identifying the other network device or information identifying the second link of the other network device; and The third message further includes at least one of information identifying the other network device or information identifying the third link of the other network device.
3. The network device according to claim 1, wherein: The first security classification is associated with a public security classification; The second security class is associated with a private security class; and The third security classification is associated with a restricted security classification.
4. The network device according to claim 1, wherein: The first link of the other network device is a link that does not utilize Media Access Control Security (MACsec); The second link of the other network device is a link authenticated by using MACsec; as well as The third link of the other network device is a link that is authenticated and encrypted using MACsec.
5. The network device according to claim 1, wherein: The first routing path includes at least one of a link that does not utilize Media Access Control Security (MACsec), a link that utilizes MACsec for authentication, or a link that utilizes MACsec for authentication and encryption; The second routing path includes at least one of a link that utilizes MACsec for authentication or a link that utilizes MACsec for authentication and encryption, and does not include a link that does not utilize MACsec; as well as The third routing path includes a link that uses MACsec for authentication and encryption, and excludes a link that does not use MACsec and a link that uses MACsec for authentication.
6. The network device of claim 1 , wherein to determine the first routing path, the second routing path, and the third routing path, the one or more processors are configured to: identifying, based on the routing table, a first group of links, the first group of links being associated with at least one of the first security classification, the second security classification, or the third security classification; determining the first routing path based on the first set of links and using a path computation technique; identifying, based on the routing table, a second group of links, the second group of links being associated with at least one of the second security classification or the third security classification; determining the second routing path based on the second set of links and using the path computation technique; identifying, based on the routing table, a third group of links, the third group of links being associated with the third security classification; as well as The third routing path is determined based on the third set of links and using the path computation technique.
7. The network device of claim 1 , wherein to forward the network traffic, the one or more processors are configured to: processing the network traffic to determine that the network traffic is destined for the other network device and that the network traffic is associated with the particular security classification; selecting the particular routing path associated with the another network device and the particular security classification based on the information identifying the another network device and the particular security classification; Determining a next hop for the network service based on the specific routing path; as well as Forward the network service to the next hop.
8. The network device of claim 1 , wherein the network traffic is forwarded based on the specific routing path so that the network traffic is transmitted from the network device to the other network device via one or more links associated with a security classification having a corresponding security level greater than or equal to a security level of the specific security classification.
9. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising: One or more instructions that, when executed by one or more processors of a network device, cause the network device to: determining, based on the routing table, a first routing path from the network device to another network device that is associated with a first security classification and is based on a first cost metric; determining, based on the routing table, a second routing path from the network device to the other network device that is associated with a second security classification and is based on a second cost metric; determining, based on the routing table, a third routing path associated with a third security classification from the network device to the other network device based on a third cost metric, wherein the first cost metric, the second cost metric, and the third cost metric are different, and The first cost metric, the second cost metric, or the third cost metric is one or more of the following: Interior Gateway Protocol (IGP) cost metric, or Business Engineering TE cost measurement; receiving network traffic destined for the other network device and associated with a specific security classification among the first security classification, the second security classification, or the third security classification; as well as The network traffic is forwarded based on a specific routing path among the first routing path, the second routing path, or the third routing path that is associated with the other network device and the specific security classification.
10. The non-transitory computer-readable medium of claim 9, wherein the one or more instructions, when executed by the one or more processors, further cause the network device to: receiving one or more messages from the other network device before determining the first routing path, the second routing path, and the third routing path, Each of the one or more messages includes at least one of the following: Information identifying the other network device; Information identifying a link of the other network device; or Information indicating that the link is associated with a security classification of the first security classification, the second security classification, or the third security classification.
11. The non-transitory computer-readable medium of claim 10, wherein the one or more instructions, when executed by the one or more processors, further cause the network device to: Based on the one or more messages, the routing table is updated.
12. The non-transitory computer-readable medium of claim 9, wherein: The first routing path includes at least one of a link that does not utilize authentication and does not utilize encryption, a link that utilizes authentication but does not utilize encryption, or a link that utilizes authentication and utilizes encryption; The second routing path includes at least one of a link that utilizes authentication but not encryption, or a link that utilizes authentication and encryption, and does not include a link that does not utilize authentication and does not utilize encryption; as well as The third routing path includes a link that utilizes authentication and utilizes encryption, and excludes a link that does not utilize authentication and does not utilize encryption and a link that utilizes authentication but does not utilize encryption.
13. The non-transitory computer-readable medium of claim 9, wherein: the first routing path comprising a set of links associated with at least one of the first security classification, the second security classification, or the third security classification; the second routing path includes a set of links associated with at least one of the second security classification or the third security classification and not associated with the first security classification; and The third routing path includes a set of links associated with the third security classification and not associated with the first security classification and the second security classification.
14. The non-transitory computer-readable medium of claim 9, wherein the one or more instructions that cause the network device to forward the network traffic cause the network device to: processing the network traffic to determine that the network traffic is destined for the other network device and that the network traffic is associated with the particular security classification; selecting the particular routing path associated with the another network device and the particular security classification based on the information identifying the another network device and the particular security classification; and The network traffic is forwarded to a next hop indicated by the specific routing path.
15. The non-transitory computer-readable medium of claim 9, wherein the network traffic is forwarded based on the specific routing path so that the network traffic is transmitted from the network device to the other network device via one or more links associated with a security classification having a corresponding security level greater than or equal to a security level of the specific security classification.
16. A method for forwarding network services, comprising: determining, by a network device, a plurality of routing paths from the network device to another network device based on a routing table, wherein the plurality of routing paths are respectively associated with a plurality of security categories, wherein the plurality of routing paths are each associated with a different cost metric; and The cost metrics among the multiple cost metrics are: Interior Gateway Protocol (IGP) cost metric, or Traffic engineering TE cost metric; receiving, by the network device, network traffic destined for the other network device and associated with a particular security classification among the plurality of security classifications; as well as The network traffic is forwarded by the network device based on a particular routing path of the plurality of routing paths that is associated with the other network device and the particular security classification.
17. The method according to claim 16, further comprising: prior to determining the plurality of routing paths, receiving one or more messages from the other network device, Each of the one or more messages includes at least one of the following: information identifying the other network device, information identifying a link of the other network device, information indicative of at least one cost metric of said link, or information indicating that the link is associated with a security classification among the plurality of security classifications; as well as Based on the one or more messages, the routing table is updated.
18. The method of claim 16, wherein: A first routing path of the plurality of routing paths includes at least one of a link that does not utilize authentication and does not utilize encryption, a link that utilizes authentication but does not utilize encryption, or a link that utilizes authentication and utilizes encryption; and A second routing path among the plurality of routing paths includes at least one of a link utilizing authentication but not encryption or a link utilizing authentication and encryption, and does not include a link utilizing neither authentication nor encryption.
19. The method of claim 16, wherein: A first routing path of the plurality of routing paths includes a set of links associated with at least one security classification of the plurality of security classifications; and A second routing path of the plurality of routing paths includes a set of links associated with at least one security classification of a first set of security classifications of the plurality of security classifications and not associated with a second set of security classifications of the plurality of security classifications.
20. The method of claim 16, wherein the network traffic is forwarded based on the specific routing path so that the network traffic is transmitted from the network device to the other network device via one or more links associated with security classifications having corresponding security levels greater than or equal to a security level of the specific security classification.
Citation Information
Patent Citations
Routing data within a communications network
EP2797267A1
Secure application routing
US20100031019A1