Ethernet Encryption Over VPLS Using Centralized Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current encryption methods for Ethernet traffic over resilient Multi-Protocol Layer Switching (MPLS) Layer 2 Virtual Private Networks (VPNs) are limited by point-to-point key negotiation, which prevents the design of redundant mesh network architectures and does not support point-to-multipoint or multipoint-to-multipoint connections.
Innovation Solution
A three-layer approach is introduced, comprising Policy Enforcement Points (PEPs), a Key Authority Point (KAP), and a Management and Policy Server (MAP), where security policies and encryption keys are generated and distributed centrally, allowing multiple PEPs to use common keys for secure data transmission over multiple paths, enabling Ethernet encryption from end-to-end between remote sites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If point-to-point key negotiation is used for Ethernet encryption, then security is provided between two endpoints, but redundant mesh network architectures cannot be designed and point-to-multipoint or multipoint-to-multipoint connections are not supported
Solution Approach 1:
The patent introduces a Key Management Server (KMS) as an intermediary component that centralizes key generation, distribution, and management. This mediator enables multiple PEPs to obtain encryption keys from a central authority, allowing point-to-multipoint and multipoint-to-multipoint connections while maintaining security. The KMS resolves the contradiction by providing a scalable key management infrastructure that supports complex network topologies without requiring complex peer-to-peer key negotiation between all endpoints.
Solution Approach 2:
The Key Management Server provides universal key management services that can handle multiple network scenarios (point-to-point, point-to-multipoint, multipoint-to-multipoint) through a single centralized system. This multi-functional approach allows the same key management infrastructure to support various network architectures, enhancing adaptability without proportionally increasing complexity.
2Reliability
If Ethernet encryption is applied at the edge of enterprise network over resilient VPLS, then secure end-to-end encryption is achieved, but integration with service provider MPLS network management becomes challenging
Solution Approach 1:
The patent segments the encryption system into independent components: Policy Enforcement Points (PEPs) at the enterprise edge that apply encryption/decryption, and a separate Key Management Server that handles key distribution. This segmentation allows the encryption functionality to be integrated into the VPLS network without requiring the service provider's MPLS network to manage encryption keys or policies, reducing integration complexity while maintaining security.
Solution Approach 2:
The Key Management Server acts as an intermediary between the enterprise's encrypted traffic and the service provider's MPLS network. It manages all cryptographic operations independently, allowing secure Ethernet encryption to operate over the provider's infrastructure without direct integration complexity. The KMS mediates key distribution to PEPs while the MPLS network simply transports the encrypted packets.
Data Source
AI summary
Encryption of Ethernet/IEEE 802.3 packet data units (PDUs) at the edge of the enterprise network, in such a way as to support resilient Virtual Private LAN Services (VPLS) network designs. The Ethernet traffic is securely tunneled within encrypted Ethernet tunnels from the edge to the edge of the enterprise network. The encrypted Ethernet traffic is also tunneled within Multi-Protocol Layer Switching (MPLS) tunnels from the edge to the edge of the service provider network. The enterprise network thus manages its own Ethernet site-to-site Virtual Private Network (VPN). The service provider thus independently manages its own MPLS network. The result provides a VPLS or Layer 2 MPLS VPN to the enterprise; the enterprise Ethernet encrypted network can thus be considered as an overlay to the MPLS service provider network.


