EVPN MAC Route Authentication for Metro Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current metropolitan transport networks lack effective mechanisms for authenticating layer two (L2) network addresses and enforcing fine-grained policy control, which are essential for secure and managed communication topologies.
Innovation Solution
Implementing Ethernet Virtual Private Network (EVPN) technology within metro transport networks to authenticate L2 network addresses and provide fine-grained policy control through MAC address validation and advertisement, using access routers and a network address authentication device to validate and manage L2 addresses, and applying policies to ensure secure and controlled communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EVPN technology is implemented for L2 network address authentication and policy control, then security and management capability are improved, but device complexity and implementation difficulty increase
Solution Approach 1:
The patent introduces an authentication server as an intermediary component that handles the complex authentication and policy control functions. The access router forwards authentication requests to this server, which maintains a database of valid L2 network addresses and returns authentication results. This mediator approach allows the security functionality to be implemented without requiring complex changes to the core EVPN routing logic in each router.
Solution Approach 2:
The system segments the authentication and policy control functionality from the EVPN routing function. The EVPN route advertisement process is separated into: (1) receiving L2 packets from customer devices, (2) forwarding authentication requests to the authentication server, (3) receiving authentication results, and (4) conditionally advertising routes based on authentication status. This segmentation allows each component to focus on a specific function, reducing overall system complexity.
2Reliability
If authentication validation is performed for each L2 network address, then security is improved, but processing time and network overhead increase
Solution Approach 1:
The authentication server pre-loads and maintains a database of valid L2 network addresses (MAC addresses) associated with customer devices before authentication is needed. When an access router receives a packet, it extracts the source L2 address and immediately queries the authentication server, which can quickly determine validity from its pre-populated database without performing complex real-time analysis.
Solution Approach 2:
The authentication server creates and maintains a copy of the valid L2 network address database that can be quickly queried. Instead of requiring the access router to perform complex authentication protocols for each packet, the system uses a simplified query-response mechanism where the authentication server returns pre-determined authentication results based on its stored copy of valid addresses.
3Adaptability or versatility
If fine-grained policy control is implemented at L2 level, then network management capability is improved, but system complexity and configuration difficulty increase
Solution Approach 1:
The authentication server is designed as a universal platform that handles multiple functions: (1) authenticating L2 network addresses, (2) maintaining the database of valid addresses, (3) enforcing policy control decisions, and (4) providing authentication results to access routers. This multi-functional design consolidates what could be separate complex systems into a single unified platform, reducing overall system complexity.
Solution Approach 2:
The system implements a feedback mechanism where the authentication server returns authentication results and policy decisions to the access router, which then uses this information to determine whether to advertise EVPN routes. This feedback loop allows fine-grained policy control to be implemented through simple route advertisement decisions rather than complex per-packet processing rules at each router.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques are described that enable MAC (L2) address authentication within an L2 switching network, such as a metro transport network. Moreover, when used in an EVPN, the techniques provide fine grain policy control over the L2 switching network so as to enable carrier networks to specify and control topologies for transporting packet-based communications. Access routers of the EVPN communicate utilizes enhanced EVPN MAC route advertisements that include an additional attribute indicating a request that L2 network address(es) being advertised be validated by a network address authentication device. A route controller relays the EVPN MAC advertisement upon validation of the L2 networks address. Moreover, the route controller may utilize the EVPN MAC route advertisements to distribute MAC-level policies to control topologies and MAC learning within the EVPN and provide services such as per-MAC traffic quota limits.