Layer 2 Encryption Selective Tunneling Data Center Interconnectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for securing data center interconnectivity across public networks through layer 2 encryption are inefficient due to unnecessary encapsulation, especially when not all traffic needs to be encrypted, leading to decreased efficiency and increased bandwidth usage.
Innovation Solution
Implementing layer 2 encryption that selectively encrypts data frames only when necessary and adds headers for tunneling, allowing for multicast communications while maintaining security through the use of protocols like GRE, thereby reducing unnecessary encapsulation and optimizing network usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If L3 encapsulation is performed before encryption to secure data center interconnectivity, then security is improved, but network efficiency deteriorates due to unnecessary encapsulation of all traffic
Solution Approach 1:
The patent applies local quality by performing encryption at the L2 layer before selective traffic types, allowing different parts of the network traffic to be treated differently. Only specific traffic requiring security is encrypted, while other traffic bypasses encryption, thus improving network efficiency while maintaining security where needed.
Solution Approach 2:
The patent segments the encryption process from the tunneling process. By performing L2 encryption first and then applying L3 tunneling only when necessary, the patent divides the security and transport functions into separate stages, allowing optimized handling of different traffic types and improving overall network efficiency.
2Reliability
If L3 encapsulation creates a point to point tunnel for encryption peers, then security is improved, but bandwidth usage increases due to unnecessary encapsulation
Solution Approach 1:
The patent applies partial action by encrypting only the necessary portion of traffic at L2 before tunneling. Instead of encapsulating all traffic through L3 tunnels, the system selectively applies encryption and tunneling only where security is required, reducing unnecessary bandwidth consumption while maintaining security for sensitive traffic.
3Adaptability or versatility
If IP tunneling is used for transparent LAN service, then data center interconnectivity is improved, but network efficiency deteriorates due to unnecessary encapsulation
Solution Approach 1:
The patent introduces dynamic decision-making at the L2 layer to determine whether traffic requires encryption and tunneling. Instead of statically applying IP tunneling to all traffic for transparent LAN service, the system dynamically assesses traffic requirements and applies encapsulation only when necessary, improving network efficiency while maintaining interconnectivity capabilities.
Data Source
AI summary
Systems, methods, and other embodiments associated with layer two (L2) encryption for data center interconnectivity are described. One example system includes a receive logic to receive an unencrypted L2 switched frame (UL2SF). The UL2SF may include a payload and an L2 header. The example system may also include an encryption logic to selectively encrypt the UL2SF into an encrypted frame if the UL2SF is to be sent through an L2 virtual private network (L2VPN) requiring encryption. The example system may also include a delivery logic that adds a header to the encrypted frame. The header may include data to identify a decryption function to decrypt the encrypted frame and routing information for the encrypted frame. The delivery logic may also provide the encrypted frame to the L2VPN, where the providing includes selectively sending the encrypted frame as one of, a point to point packet, and a multipoint packet.


