EVPN MACsec Key Agreement via BGP to Reduce CE Burden
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current MACsec deployments in Layer 2 Ethernet Virtual Private Network (EVPN) environments face inefficiencies due to the computational burden on Customer Edge (CE) devices, which lack sufficient hardware resources for encrypting traffic at line rate and require repeated flooding of keepalive messages, leading to scalability challenges.
Innovation Solution
Leveraging Border Gateway Protocol (BGP) signaling for MACsec Key Agreement (MKA) negotiations between Provider Edge (PE) routers, using a new BGP-EVPN route type to communicate MKA information and enable encryption/decryption at PE devices, reducing the burden on CE devices and improving resource allocation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACsec encryption is implemented at Customer Edge (CE) devices in Layer 2 Ethernet Virtual Private Network (EVPN) environments, then security is provided, but computational burden on CE devices increases and scalability is limited due to hardware resource constraints
Solution Approach 1:
The patent introduces Provider Edge (PE) devices as intermediaries between CE devices and the encryption infrastructure. PE devices perform MKA negotiations and MACsec encryption/decryption operations, acting as mediators that relieve the computational burden from CE devices while maintaining security. The PE devices handle key management and encryption tasks that were previously required at CE devices, enabling CE devices to function with simpler hardware.
2Reliability
If MACsec Key Agreement (MKA) negotiations are performed between CE devices, then security keys are established, but bandwidth is consumed through repeated flooding of keepalive messages and scalability is reduced
Solution Approach 1:
PE devices serve as intermediaries for MKA negotiations, establishing security keys between CE devices without requiring direct MKA communication between them. The PE devices handle keepalive message exchanges and key management, eliminating the need for repeated flooding of keepalive messages between CE devices while maintaining secure key establishment.
3Reliability
If MACsec encryption is deployed at CE devices, then security is achieved, but hardware resource requirements limit deployment scalability
Solution Approach 1:
By introducing PE devices as intermediaries that perform encryption and key management functions, the patent enables deployment in environments with resource-constrained CE devices. The PE devices, which typically have more robust hardware resources, handle the computationally intensive MACsec operations, thereby improving scalability and adaptability of MACsec deployment across diverse network configurations.
Solution Approach 2:
The patent enables PE devices to autonomously perform MKA negotiations, key generation, and encryption/decryption operations without requiring advanced hardware capabilities at CE devices. The PE devices self-manage the security infrastructure, including automatic key distribution to CE devices and maintenance of security associations, thereby reducing deployment complexity and improving scalability.
Data Source
AI summary
Techniques described herein provide procedures for reducing MACsec Key Agreement (MKA)-related traffic and improving resource allocation for MKA protocol through an EVPN environment. Techniques include leveraging Border Gateway Protocol (BGP) signaling for MKA between Provider Edge (PE) routers instead of between Customer Edge (CE) routers, which mitigates both hardware restrictions and scalability challenges with a new Xaas enablement. A new BGP-EVPN route type is defined that can communicate a set of MKA information along with an address destination associated with a provider edge device to establish a BGP MKA session and enable MACsec encryption/decryption at the provider edge device.


