Preventing Leaf-to-Leaf Traffic in Ethernet Tree Services
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Provider edge devices in Ethernet Tree services struggle to prevent leaf-to-leaf communications across multiple virtual local area networks (VLANs) due to the association of tree node type indicators with Layer 2 device identifiers, making it difficult to identify customer devices as root or leaf devices and thus failing to prohibit unauthorized communications.
Innovation Solution
Associating tree node type indicators with Layer 3 information, such as Internet Protocol (IP) addresses, allows provider edge devices to determine and prevent leaf-to-leaf communications by categorizing devices within the Ethernet Tree service, thereby enhancing security and customer privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If tree node type indicators are associated with Layer 2 device identifiers, then Ethernet Tree service can be provided, but provider edge devices cannot accurately identify customer devices as root or leaf devices across VLANs
Solution Approach 1:
The patent introduces Layer 3 address information as an intermediary carrier for tree node type indicators. Instead of directly using Layer 2 device identifiers which are lost during inter-VLAN routing, the invention associates tree node type indicators with Layer 3 addresses that persist through routing operations. This intermediary approach allows provider edge devices to identify root and leaf devices across VLAN boundaries without exposing complex Layer 2 identifier structures.
2Productivity
If Layer 2 information is removed from traffic transmitted between provider edge devices, then routing efficiency improves, but ability to identify device categories is lost
Solution Approach 1:
The patent shifts the information carrier from Layer 2 (data link layer) to Layer 3 (network layer), effectively moving to another dimensional plane in the OSI model. By associating tree node type indicators with Layer 3 address information rather than Layer 2 identifiers, the invention enables device category identification to persist through Layer 3 routing operations where Layer 2 information is stripped away. This dimensional transition resolves the conflict between routing efficiency and information retention.
3Ease of operation
If provider edge devices cannot identify leaf devices, then Ethernet Tree service operates, but unauthorized leaf-to-leaf communications cannot be prevented
Solution Approach 1:
The patent implements preliminary action by pre-associating tree node type indicators with Layer 3 address information before routing decisions are made. Provider edge devices perform lookups of tree node type indicators using Layer 3 addresses in advance of forwarding decisions, enabling them to identify whether destination devices are root or leaf devices. This preliminary identification allows security policies to be enforced by dropping packets from leaf devices destined for other leaf devices, thereby preventing unauthorized communications while maintaining ease of service operation.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
A device may receive, from a first device associated with a first LAN, network traffic destined for a second LAN. The device may provide the first LAN with access to a core network. The device may not provide the second LAN with access to the core network. The device may identify, based on the network traffic, a Layer 3 address associated with a second device. The second device may be associated with the second LAN. The device may determine that the first device is categorized as a leaf device within an Ethernet Tree provided by the device. The device may determine, based on the Layer 3 address, that the second device is categorized as a leaf device within the Ethernet Tree. The device may drop the network traffic based on determining that the first device and the second device are categorized as leaf devices within the Ethernet Tree.