BIER Route Distinguisher Advertising for Secure BIFT Computation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In BIER domains spread across a provider network where BRFs are not directly connected, sharing additional BIER information is resource-intensive, and in BIER VPNs, sharing this information compromises security and integrity, preventing widespread adoption.
Innovation Solution
A network device sends an advertisement including a BIER prefix, sub-domain information, and a route distinguisher (RD) to uniquely identify a BIER sub-domain, allowing other network devices to compute a bit index forwarding table (BIFT) without sharing sensitive information, thus conserving resources and ensuring security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If BIER information is shared across provider network to enable distributed BIER domain communication, then connectivity between non-directly-connected BRFs is improved, but resource consumption increases and security is compromised
Solution Approach 1:
The BIER domain is segmented into multiple BIER sub-domains, each identified by a unique BIER sub-domain identifier. This segmentation allows distributed BRFs to communicate by routing packets through intermediate network devices without requiring full BIER information sharing across the entire provider network, thereby reducing resource consumption while maintaining connectivity.
Solution Approach 2:
Intermediate network devices act as mediators that receive BIER packets from one BIER sub-domain and forward them to the appropriate BIER sub-domain. These intermediaries enable communication between non-directly-connected BRFs without requiring direct sharing of sensitive BIER information across the entire network, thus preserving security and reducing resource usage.
2Adaptability or versatility
If BIER information is shared across provider network to enable distributed BIER domain communication, then connectivity between non-directly-connected BRFs is improved, but security and integrity are compromised
Solution Approach 1:
By dividing the BIER domain into separate BIER sub-domains with unique identifiers, sensitive BIER information remains localized within each sub-domain. Intermediate network devices forward packets between sub-domains without accessing or requiring the full BIER information, thus maintaining security and integrity while enabling distributed connectivity.
Solution Approach 2:
Intermediate network devices serve as secure mediators that handle packet forwarding between BIER sub-domains. They process packets based on BIER sub-domain identifiers without exposing sensitive BIER information, thereby enabling communication across the provider network while preserving security and integrity constraints.
3Productivity
If traditional multicast protocols are used for large scale deployment, then multicast flow support is improved, but system complexity increases
Solution Approach 1:
The patent extracts the complex multicast routing logic from individual network devices and replaces it with the simplified BIER forwarding mechanism. Network devices only need to maintain BIFTs based on BIER sub-domain identifiers, eliminating the need for complex multicast protocol processing while supporting large scale deployments with numerous multicast flows.
Solution Approach 2:
The patent changes the fundamental parameter for packet forwarding from complex multicast group identifiers to simple BIER sub-domain identifiers. This parameter change simplifies the forwarding decision process at each network device, reducing system complexity while maintaining the ability to support large scale multicast deployments through the bit-indexed forwarding mechanism.
Data Source
AI summary
In some implementations, a network device may determine a route distinguisher (RD) that is associated with a bit index explicit replication (BIER) domain, wherein the network device participates in the BIER domain and one or more BIER sub-domains of the BIER domain. The network device may identify BIER sub-domain information associated with a BIER sub-domain of the one or more BIER sub-domains of the BIER domain. The network device may identify proxy information that is associated with the BIER sub-domain. The network device may send an advertisement that includes a BIER prefix of the network device, the BIER sub-domain information, the RD, and the proxy information. Sending the advertisement is to permit a receiving network device to store the proxy information in a bit index forwarding table (BIFT) of the receiving network device.


