Ethernet Encryption Over VPLS Using Centralized Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption methods for Ethernet traffic over resilient Multi-Protocol Layer Switching (MPLS) Layer 2 Virtual Private Networks (VPNs) are limited by point-to-point key negotiation, which prevents the design of redundant mesh network architectures and does not support point-to-multipoint or multipoint-to-multipoint connections.

Innovation Solution

A three-layer approach is introduced, comprising Policy Enforcement Points (PEPs), a Key Authority Point (KAP), and a Management and Policy Server (MAP), where security policies and encryption keys are generated and distributed centrally, allowing multiple PEPs to use common keys for secure data transmission over multiple paths, enabling Ethernet encryption from end-to-end between remote sites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If point-to-point key negotiation is used for Ethernet encryption, then security is provided between two endpoints, but redundant mesh network architectures cannot be designed and point-to-multipoint or multipoint-to-multipoint connections are not supported

Engineering Contradiction:
Improvenetwork architecture flexibilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a Key Management Server (KMS) as an intermediary component that centralizes key generation, distribution, and management. This mediator enables multiple PEPs to obtain encryption keys from a central authority, allowing point-to-multipoint and multipoint-to-multipoint connections while maintaining security. The KMS resolves the contradiction by providing a scalable key management infrastructure that supports complex network topologies without requiring complex peer-to-peer key negotiation between all endpoints.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The Key Management Server provides universal key management services that can handle multiple network scenarios (point-to-point, point-to-multipoint, multipoint-to-multipoint) through a single centralized system. This multi-functional approach allows the same key management infrastructure to support various network architectures, enhancing adaptability without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If Ethernet encryption is applied at the edge of enterprise network over resilient VPLS, then secure end-to-end encryption is achieved, but integration with service provider MPLS network management becomes challenging

Engineering Contradiction:
Improveencryption securityVSAvoidnetwork integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption system into independent components: Policy Enforcement Points (PEPs) at the enterprise edge that apply encryption/decryption, and a separate Key Management Server that handles key distribution. This segmentation allows the encryption functionality to be integrated into the VPLS network without requiring the service provider's MPLS network to manage encryption keys or policies, reducing integration complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Key Management Server acts as an intermediary between the enterprise's encrypted traffic and the service provider's MPLS network. It manages all cryptographic operations independently, allowing secure Ethernet encryption to operate over the provider's infrastructure without direct integration complexity. The KMS mediates key distribution to PEPs while the MPLS network simply transports the encrypted packets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7864762B2Ethernet encryption over resilient virtual private LAN services
Publication Date: 2011.01.04 CERTES NETWORKS INC
  • US7864762B2 patent drawing
  • US7864762B2 patent drawing
  • US7864762B2 patent drawing

AI summary

Encryption of Ethernet/IEEE 802.3 packet data units (PDUs) at the edge of the enterprise network, in such a way as to support resilient Virtual Private LAN Services (VPLS) network designs. The Ethernet traffic is securely tunneled within encrypted Ethernet tunnels from the edge to the edge of the enterprise network. The encrypted Ethernet traffic is also tunneled within Multi-Protocol Layer Switching (MPLS) tunnels from the edge to the edge of the service provider network. The enterprise network thus manages its own Ethernet site-to-site Virtual Private Network (VPN). The service provider thus independently manages its own MPLS network. The result provides a VPLS or Layer 2 MPLS VPN to the enterprise; the enterprise Ethernet encrypted network can thus be considered as an overlay to the MPLS service provider network.