BGP Synchronization of Client IP Binding Databases

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In extended networks, there is no standard technique to synchronize client IP binding databases across switches, leading to legitimate clients being incorrectly denied access as untrusted or unauthorized, especially when migrating between switches or adding new hosts, due to the lack of shared validated IP binding information.

Innovation Solution

A system and method that utilize Border Gateway Protocol (BGP) to synchronize client IP binding databases by defining a new extended communities path attribute in BGP update messages, which includes a Client IP Binding Synchronization Identifier, allowing validated MAC and IP information to be shared across switches, thereby ensuring correct access permissions and expedited migration processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If local IP binding databases are maintained at each switch, then security validation can be performed locally, but client IP binding information cannot be shared across switches in the extended network

Engineering Contradiction:
Improvesecurity validationVSAvoidIP binding information sharing
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent merges the previously distributed local IP binding databases into a synchronized database system across multiple switches. By implementing a database synchronization mechanism that allows switches to share and validate IP binding information collectively, the system maintains local security validation capabilities while enabling information sharing across the extended network, thus resolving the contradiction between local security and information sharing.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a database synchronization mechanism as an intermediary between individual switch databases. This intermediary enables switches to exchange and synchronize IP binding information without compromising local security validation, allowing information to flow between switches while maintaining the reliability of local security checks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If client IP binding information is stored locally at each switch, then access control can be enforced at each switch, but legitimate clients migrating between switches are incorrectly denied access

Engineering Contradiction:
Improveaccess controlVSAvoidaccess permission validation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines local access control capabilities with a synchronized IP binding database system. When a client migrates between switches, the new switch can query the synchronized database to obtain the client's valid IP binding information, thereby maintaining access control enforcement while preventing false denial of access to legitimate migrating clients.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements preliminary synchronization of IP binding information across switches before clients migrate. By maintaining an up-to-date synchronized database that proactively contains valid client binding information, switches are prepared to recognize and allow access for migrating clients before they attempt connection, preventing incorrect access denials.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If no synchronization mechanism is implemented, then switch database complexity remains low, but network bandwidth is wasted due to repeated access denials and re-validation

Engineering Contradiction:
Improvedatabase synchronizationVSAvoidnetwork bandwidth usage
Core Design Contradiction:
Device complexityVSLoss of energy

Solution Approach 1:

The patent implements a selective synchronization approach where switches only exchange and synchronize relevant IP binding information that is necessary for access validation. Rather than synchronizing all possible data, the system performs partial synchronization of only the critical IP binding records, thereby limiting database complexity while preventing bandwidth waste from repeated access denials and re-validation attempts.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11909819B1Synchronization of client IP binding database across extended networks leveraging BGP control plane
Publication Date: 2024.02.20 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11909819B1 patent drawing
  • US11909819B1 patent drawing
  • US11909819B1 patent drawing

AI summary

A method and system are provided which facilitate synchronization of client IP binding databases across an extended network by leveraging the BGP control plane. During operation, a switch configures a first synchronization identifier indicating validated Internet Protocol (IP) binding information of an associated client. The switch receives a Border Gateway Protocol (BGP) update message associated with a first client, wherein the BGP update message includes a second synchronization identifier. Responsive to determining that the second synchronization identifier matches the first synchronization identifier, the switch: extracts from the BGP update message reachability information, which includes media access control (MAC) and IP information associated with the first client; validates the MAC and IP information based on security policies; and adds the MAC and IP information to a local IP binding database, thereby allowing synchronization of the validated IP binding information of the first client between the switch and other switches.