ISIS Neighbor Authentication via Extended UDL LSP Packets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In ISIS networks, unidirectional links create a security risk due to incomplete authentication when establishing neighbor relationships, as a neighbor relationship can be established even if only one party enables authentication.

Innovation Solution

A method where network devices send hello packets with authentication information over unidirectional links, and only establish a neighbor relationship if both parties successfully authenticate through extended UDL LSP packets, ensuring mutual authentication is enabled.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is enabled in unidirectional link scenarios, then security is improved, but neighbor relationship establishment fails when only one party enables authentication

Engineering Contradiction:
Improveauthentication securityVSAvoidneighbor establishment compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by requiring both parties to pre-configure authentication capabilities before establishing a neighbor relationship. The system checks authentication status in advance during the hello packet exchange phase, preventing incompatible connections from being established. This ensures that authentication security is maintained while avoiding compatibility issues by filtering out mismatched pairs before full neighbor establishment occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms through the hello packet and extended UDL LSP packet exchange, where authentication status information is communicated between parties. The system provides feedback about authentication capability mismatches and adjusts the neighbor establishment process accordingly, allowing the network to adapt to different authentication configurations while maintaining security requirements.

Inventive Principle:
Principle #23Feedback

2Reliability

If authentication information is exchanged in hello packets, then authentication completeness is improved, but protocol complexity increases

Engineering Contradiction:
Improveauthentication completenessVSAvoidprotocol processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by using the existing hello packet and UDL LSP packet structures to carry both traditional ISIS protocol information and authentication information simultaneously. This multi-functional approach allows authentication to be integrated into already-established packet types rather than requiring separate dedicated authentication packets, thereby improving authentication completeness while minimizing additional protocol complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges authentication functionality with existing neighbor establishment packets (hello packets and UDL LSP packets). By combining authentication information exchange with the regular neighbor discovery and establishment process, the system achieves complete authentication without significantly increasing protocol complexity, as the same packet infrastructure serves dual purposes.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3319286B1Neighbor relationship establishment method, device and system
Publication Date: 2021.03.24 HUAWEI TECH CO LTD
  • EP3319286B1 patent drawingFigure 1~2
  • EP3319286B1 patent drawingFigure 3~4
  • EP3319286B1 patent drawingFigure 5~6

AI summary

Embodiments of the present invention disclose a neighbor establishment method and system, and a device. According to the method, corresponding authentication information is added, according to whether a first network device and a second network device enable authentication, to packets that are sent by the first network device and the second network device to each other. The first network device sends a hello packet to the second network device. The second network device receives the hello packet, performs authentication, and when the authentication succeeds, responds to the hello packet by using an extended UDL LSP packet. The first network device receives the extended UDL LSP packet, and performs authentication. When an authentication result is that both the first network device and the second network device enable authentication and the authentication succeeds, a neighbor relationship between the first network device and the second network device may be established. According to the foregoing process, a case in which a neighbor relationship may still be established when authentication of only one party succeeds can be avoided. In this way, a problem of incomplete authentication during neighbor establishment is resolved, and security and reliability when a neighbor between network devices is established are improved.