CFM Security Mode Using Isolated CCM Databases
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Connectivity Fault Management (CFM) protocol in Ethernet networks is vulnerable to malicious attacks due to Maintenance-association End Points (MEPs) being designed as 'always ON' receivers, which can lead to spurious CCMs causing network chaos and resource wastage.
Innovation Solution
Implementing an isolated database in NEs/MEPs to store untrusted CCMs, allowing a safety mode where CCMs are reviewed before being processed, and an active database for trusted CCMs to handle connectivity faults.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MEPs are designed as always ON receivers to continuously monitor connectivity, then connectivity fault detection capability is improved, but vulnerability to malicious attacks increases
Solution Approach 1:
The patent segments the database into two distinct parts: a trusted database for legitimate CCMs and an untrusted database for suspicious CCMs. This segmentation allows the system to maintain continuous monitoring capability while isolating malicious messages, preventing them from causing network disruption.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of a message evaluation function that assesses CCMs before processing. This intermediary layer filters and categorizes incoming messages, directing trusted messages to the trusted database and untrusted messages to the untrusted database, thereby protecting the system from malicious attacks.
2Measurement precision
If all received CCMs are processed and stored in the database, then connectivity monitoring accuracy is improved, but database exhaustion and CPU load increase
Solution Approach 1:
The patent divides the database storage into two separate databases: trusted database and untrusted database. This segmentation prevents malicious or spurious CCMs from consuming excessive storage resources, while still maintaining accurate connectivity monitoring by processing only trusted messages.
Solution Approach 2:
The patent extracts and isolates untrusted CCMs into a separate untrusted database, removing them from the main processing flow. This extraction prevents database exhaustion attacks while maintaining monitoring accuracy by continuing to process trusted messages normally.
3Reliability
If untrusted CCMs are processed like trusted CCMs, then fault detection completeness is improved, but network stability deteriorates
Solution Approach 1:
The patent segments the message processing path into two distinct flows: one for trusted CCMs that triggers fault detection and protection switching, and another for untrusted CCMs that are logged but not processed for fault detection. This segmentation ensures complete fault detection capability while preventing network instability caused by malicious messages.
Solution Approach 2:
The patent implements a feedback mechanism where the message evaluation function continuously assesses incoming CCMs and dynamically determines their trustworthiness. This feedback loop allows the system to maintain complete fault detection for legitimate messages while automatically filtering out malicious messages that would cause network instability.
Data Source
AI summary
Systems and methods for enhancing the Connectivity Fault Management (CFM) protocol defined in IEEE 802.1Q are provided. In particular, a method includes receiving one or more messages associated with a link connectivity protocol that for detecting link connectivity issues of an Ethernet service in a section of a network and responding to the link connectivity issues; and maintaining two databases for learning nodes in the network based on the received one or more messages, the two databases including an active database and an isolated database.


