Preventing Leaf-to-Leaf Traffic in Ethernet Tree Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Provider edge devices in Ethernet Tree services struggle to prevent leaf-to-leaf communications across multiple virtual local area networks (VLANs) due to the association of tree node type indicators with Layer 2 device identifiers, making it difficult to identify customer devices as root or leaf devices and thus failing to prohibit unauthorized communications.

Innovation Solution

Associating tree node type indicators with Layer 3 information, such as Internet Protocol (IP) addresses, allows provider edge devices to determine and prevent leaf-to-leaf communications by categorizing devices within the Ethernet Tree service, thereby enhancing security and customer privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If tree node type indicators are associated with Layer 2 device identifiers, then Ethernet Tree service can be provided, but provider edge devices cannot accurately identify customer devices as root or leaf devices across VLANs

Engineering Contradiction:
Improvetree node type indicator informationVSAvoiddevice identification complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces Layer 3 address information as an intermediary carrier for tree node type indicators. Instead of directly using Layer 2 device identifiers which are lost during inter-VLAN routing, the invention associates tree node type indicators with Layer 3 addresses that persist through routing operations. This intermediary approach allows provider edge devices to identify root and leaf devices across VLAN boundaries without exposing complex Layer 2 identifier structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If Layer 2 information is removed from traffic transmitted between provider edge devices, then routing efficiency improves, but ability to identify device categories is lost

Engineering Contradiction:
Improverouting efficiencyVSAvoiddevice category information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent shifts the information carrier from Layer 2 (data link layer) to Layer 3 (network layer), effectively moving to another dimensional plane in the OSI model. By associating tree node type indicators with Layer 3 address information rather than Layer 2 identifiers, the invention enables device category identification to persist through Layer 3 routing operations where Layer 2 information is stripped away. This dimensional transition resolves the conflict between routing efficiency and information retention.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If provider edge devices cannot identify leaf devices, then Ethernet Tree service operates, but unauthorized leaf-to-leaf communications cannot be prevented

Engineering Contradiction:
ImproveEthernet Tree service operationVSAvoidsecurity enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-associating tree node type indicators with Layer 3 address information before routing decisions are made. Provider edge devices perform lookups of tree node type indicators using Layer 3 addresses in advance of forwarding decisions, enabling them to identify whether destination devices are root or leaf devices. This preliminary identification allows security policies to be enforced by dropping packets from leaf devices destined for other leaf devices, thereby preventing unauthorized communications while maintaining ease of service operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3214799B1Processing inter-VLAN traffic in an ethernet tree
Publication Date: 2019.01.23 JUNIPER NETWORKS INC
  • EP3214799B1 patent drawingFigure 1A
  • EP3214799B1 patent drawingFigure 1B
  • EP3214799B1 patent drawingFigure 1C

AI summary

A device may receive, from a first device associated with a first LAN, network traffic destined for a second LAN. The device may provide the first LAN with access to a core network. The device may not provide the second LAN with access to the core network. The device may identify, based on the network traffic, a Layer 3 address associated with a second device. The second device may be associated with the second LAN. The device may determine that the first device is categorized as a leaf device within an Ethernet Tree provided by the device. The device may determine, based on the Layer 3 address, that the second device is categorized as a leaf device within the Ethernet Tree. The device may drop the network traffic based on determining that the first device and the second device are categorized as leaf devices within the Ethernet Tree.