EVPN MAC Route Authentication for Metro Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current metropolitan transport networks lack effective mechanisms for authenticating layer two (L2) network addresses and enforcing fine-grained policy control, which are essential for secure and managed communication topologies.

Innovation Solution

Implementing Ethernet Virtual Private Network (EVPN) technology within metro transport networks to authenticate L2 network addresses and provide fine-grained policy control through MAC address validation and advertisement, using access routers and a network address authentication device to validate and manage L2 addresses, and applying policies to ensure secure and controlled communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If EVPN technology is implemented for L2 network address authentication and policy control, then security and management capability are improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary component that handles the complex authentication and policy control functions. The access router forwards authentication requests to this server, which maintains a database of valid L2 network addresses and returns authentication results. This mediator approach allows the security functionality to be implemented without requiring complex changes to the core EVPN routing logic in each router.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the authentication and policy control functionality from the EVPN routing function. The EVPN route advertisement process is separated into: (1) receiving L2 packets from customer devices, (2) forwarding authentication requests to the authentication server, (3) receiving authentication results, and (4) conditionally advertising routes based on authentication status. This segmentation allows each component to focus on a specific function, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication validation is performed for each L2 network address, then security is improved, but processing time and network overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication server pre-loads and maintains a database of valid L2 network addresses (MAC addresses) associated with customer devices before authentication is needed. When an access router receives a packet, it extracts the source L2 address and immediately queries the authentication server, which can quickly determine validity from its pre-populated database without performing complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server creates and maintains a copy of the valid L2 network address database that can be quickly queried. Instead of requiring the access router to perform complex authentication protocols for each packet, the system uses a simplified query-response mechanism where the authentication server returns pre-determined authentication results based on its stored copy of valid addresses.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If fine-grained policy control is implemented at L2 level, then network management capability is improved, but system complexity and configuration difficulty increase

Engineering Contradiction:
Improvepolicy control capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication server is designed as a universal platform that handles multiple functions: (1) authenticating L2 network addresses, (2) maintaining the database of valid addresses, (3) enforcing policy control decisions, and (4) providing authentication results to access routers. This multi-functional design consolidates what could be separate complex systems into a single unified platform, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements a feedback mechanism where the authentication server returns authentication results and policy decisions to the access router, which then uses this information to determine whether to advertise EVPN routes. This feedback loop allows fine-grained policy control to be implemented through simple route advertisement decisions rather than complex per-packet processing rules at each router.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3151509B1Enhanced EVPN mac route advertisement having mac (L2) level authentication, security and policy control
Publication Date: 2019.11.06 JUNIPER NETWORKS INC
  • EP3151509B1 patent drawingFigure 1
  • EP3151509B1 patent drawingFigure 2
  • EP3151509B1 patent drawingFigure 3

AI summary

Techniques are described that enable MAC (L2) address authentication within an L2 switching network, such as a metro transport network. Moreover, when used in an EVPN, the techniques provide fine grain policy control over the L2 switching network so as to enable carrier networks to specify and control topologies for transporting packet-based communications. Access routers of the EVPN communicate utilizes enhanced EVPN MAC route advertisements that include an additional attribute indicating a request that L2 network address(es) being advertised be validated by a network address authentication device. A route controller relays the EVPN MAC advertisement upon validation of the L2 networks address. Moreover, the route controller may utilize the EVPN MAC route advertisements to distribute MAC-level policies to control topologies and MAC learning within the EVPN and provide services such as per-MAC traffic quota limits.