BGP Synchronization of Client IP Binding Databases
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In extended networks, there is no standard technique to synchronize client IP binding databases across switches, leading to legitimate clients being incorrectly denied access as untrusted or unauthorized, especially when migrating between switches or adding new hosts, due to the lack of shared validated IP binding information.
Innovation Solution
A system and method that utilize Border Gateway Protocol (BGP) to synchronize client IP binding databases by defining a new extended communities path attribute in BGP update messages, which includes a Client IP Binding Synchronization Identifier, allowing validated MAC and IP information to be shared across switches, thereby ensuring correct access permissions and expedited migration processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If local IP binding databases are maintained at each switch, then security validation can be performed locally, but client IP binding information cannot be shared across switches in the extended network
Solution Approach 1:
The patent merges the previously distributed local IP binding databases into a synchronized database system across multiple switches. By implementing a database synchronization mechanism that allows switches to share and validate IP binding information collectively, the system maintains local security validation capabilities while enabling information sharing across the extended network, thus resolving the contradiction between local security and information sharing.
Solution Approach 2:
The patent introduces a database synchronization mechanism as an intermediary between individual switch databases. This intermediary enables switches to exchange and synchronize IP binding information without compromising local security validation, allowing information to flow between switches while maintaining the reliability of local security checks.
2Ease of operation
If client IP binding information is stored locally at each switch, then access control can be enforced at each switch, but legitimate clients migrating between switches are incorrectly denied access
Solution Approach 1:
The patent combines local access control capabilities with a synchronized IP binding database system. When a client migrates between switches, the new switch can query the synchronized database to obtain the client's valid IP binding information, thereby maintaining access control enforcement while preventing false denial of access to legitimate migrating clients.
Solution Approach 2:
The patent implements preliminary synchronization of IP binding information across switches before clients migrate. By maintaining an up-to-date synchronized database that proactively contains valid client binding information, switches are prepared to recognize and allow access for migrating clients before they attempt connection, preventing incorrect access denials.
3Device complexity
If no synchronization mechanism is implemented, then switch database complexity remains low, but network bandwidth is wasted due to repeated access denials and re-validation
Solution Approach 1:
The patent implements a selective synchronization approach where switches only exchange and synchronize relevant IP binding information that is necessary for access validation. Rather than synchronizing all possible data, the system performs partial synchronization of only the critical IP binding records, thereby limiting database complexity while preventing bandwidth waste from repeated access denials and re-validation attempts.
Data Source
AI summary
A method and system are provided which facilitate synchronization of client IP binding databases across an extended network by leveraging the BGP control plane. During operation, a switch configures a first synchronization identifier indicating validated Internet Protocol (IP) binding information of an associated client. The switch receives a Border Gateway Protocol (BGP) update message associated with a first client, wherein the BGP update message includes a second synchronization identifier. Responsive to determining that the second synchronization identifier matches the first synchronization identifier, the switch: extracts from the BGP update message reachability information, which includes media access control (MAC) and IP information associated with the first client; validates the MAC and IP information based on security policies; and adds the MAC and IP information to a local IP binding database, thereby allowing synchronization of the validated IP binding information of the first client between the switch and other switches.


