EVPN Route Distribution Control via Role Attributes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Ethernet Virtual Private Networks (EVPN), there is a lack of control over route distribution between different branch networks, leading to potential intercommunication and compromising service confidentiality and security.

Innovation Solution

Implementing a method where EVPN routes are controlled by adding a role attribute, allowing the main VTEP device to manage the distribution of EVPN routes based on a set route synchronization control strategy, ensuring that only authorized routes are shared between VTEP devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If EVPN routes are freely distributed between VTEP devices to enable mutual access between branches, then network connectivity and flexibility are improved, but service confidentiality and security deteriorate due to unauthorized intercommunication

Engineering Contradiction:
Improvenetwork connectivityVSAvoidservice confidentiality
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by assigning different role attributes (first role attribute value for branches requiring isolation, second role attribute value for branches allowing communication) to different VTEP devices. This enables selective route distribution where each branch's EVPN routes are treated differently based on their specific security requirements, rather than applying a uniform distribution policy across all branches.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of route distribution by introducing role attributes as a controlling variable. The main VTEP device modifies its routing behavior based on the role attribute value: when the attribute indicates isolation requirements, route distribution is restricted; when it indicates allowed communication, route distribution proceeds. This parameter-based control resolves the contradiction between connectivity and security.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If EVPN routes are synchronized to all branch VTEP devices to achieve mutual access, then network flexibility is improved, but route control and security management become complex

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidroute control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces role attributes as an intermediary mechanism between route generation and route distribution. Instead of implementing complex control logic at each VTEP device to determine which routes to distribute, the system uses the role attribute as a simplified intermediary that automatically guides the main VTEP device's routing decisions, reducing overall system complexity while maintaining flexible control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3598705B1Routing control
Publication Date: 2023.07.05 NEW H3C TECH CO LTD
  • EP3598705B1 patent drawingFigure 1A~1B
  • EP3598705B1 patent drawingFigure 2~3A
  • EP3598705B1 patent drawingFigure 3B~4

AI summary

Disclosed are a method and a device for controlling an EVPN route. According to an example of the method, when receiving an EVPN route from a second VTEP device, a first VTEP device checks whether the EVPN route carries a role attribute. When determining that the EVPN route carries a role attribute and the carried role attribute is a specified first role attribute value, the first VTEP device controls the distribution of the EVPN route according to a set route synchronization control strategy.