Self-Organizing Layer-2 Network Node Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large enterprise networks, the manual configuration of thousands of layer-2 network elements is error-prone and difficult to manage, especially in distributed environments, where changes in configuration can have significant implications.

Innovation Solution

An apparatus and method where network nodes automatically authenticate, discover their addresses, and receive configuration information through control-plane tunnels, allowing them to self-organize and configure without administrator intervention, using a core network node to manage both wired and wireless elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration is used for each layer-2 network element, then network control and configuration capability is maintained, but configuration burden and error rate increase significantly with network scale

Engineering Contradiction:
Improveconfiguration burdenVSAvoidnetwork management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Network elements automatically perform configuration tasks through self-registration with the controller, self-identification of addresses, and self-configuration based on received policies. The system eliminates manual configuration by enabling network elements to service themselves through automated authentication, discovery, and configuration processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A centralized controller acts as an intermediary between network administrators and distributed layer-2 network elements. The controller receives configuration intent from administrators, processes it into specific configuration policies, and distributes them to appropriate network elements, thereby simplifying management while maintaining control capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If manual configuration changes are made in distributed enterprise networks, then configuration flexibility is maintained, but understanding implications and effectiveness becomes difficult

Engineering Contradiction:
Improveconfiguration implication visibilityVSAvoidself-organization capability
Core Design Contradiction:
Loss of informationVSExtent of automation

Solution Approach 1:

The system establishes bidirectional communication between the controller and network elements through control-plane tunnels. The controller sends configuration policies to network elements and receives status information, acknowledgments, and operational data back, enabling the administrator to understand the implications and effectiveness of configuration changes through centralized visibility.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The centralized controller serves as an intermediary that provides centralized visibility into distributed configuration changes. All configuration implications and effectiveness information is funneled through the controller, which maintains a unified view of the network state and can report back to administrators about the impact of configuration changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If self-organization is implemented for network nodes, then configuration accuracy and scalability improve, but authentication and discovery mechanisms are required

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Network elements perform preliminary authentication and address discovery actions before configuration is applied. The authentication mechanism verifies node identities in advance, and the discovery process determines appropriate configuration parameters beforehand, ensuring configuration accuracy is established before deployment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3425945B1Methods and apparatus for a self-organized layer-2 enterprise network architecture
Publication Date: 2022.01.26 JUNIPER NETWORKS INC
  • EP3425945B1 patent drawingFigure 1
  • EP3425945B1 patent drawingFigure 2
  • EP3425945B1 patent drawingFigure 3~4

AI summary

In some examples, an apparatus comprises a network node operatively coupled within a network including a set of network nodes and a core network node. The network node is configured to send a first authentication message upon boot up, and receive a second authentication message in response to the first authentication message. The network node is configured to be authenticated based on the second authentication message. The network node is configured to send a first discovery message, and receive a second discovery message based on the first discovery message. The network node is configured to identify an address of the network node and an address of the core network node based on the second discovery message. The network node is configured to set up a control-plane tunnel to the core network node based on the address of the network node and the address for the core network node and receive configuration information from the core network node through the control-plane tunnel.