MACsec IGP Convergence via MKA Failure Signaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network protocols fail to detect security failures in secure sessions promptly, leading to continued traffic forwarding on compromised links, resulting in undesirable delays and potential 'black-holing' of traffic.

Innovation Solution

Establishing a signaling channel between the MACsec Key Agreement (MKA) protocol and the Interior Gateway Protocol (IGP) to immediately notify IGP of security failures detected by MKA, allowing for instant declaration of failed routes and rerouting, thereby prioritizing security failures over IGP keepalives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MKA and IGP peer maintenance operate independently, then each protocol can detect its own failures, but security failures are not promptly detected by the routing protocol, leading to continued traffic forwarding on compromised links

Engineering Contradiction:
Improvesecurity failure detection accuracyVSAvoidtime delay in detecting security failures
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the failure detection capabilities of MKA and IGP by establishing a signaling channel between them. When MKA detects a security failure, it sends a notification through this channel to IGP, which then removes the affected route. This integration ensures that security failures are promptly detected and reflected in routing decisions, eliminating the time delay caused by independent operation while maintaining the reliability of both protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a feedback mechanism where MKA provides security status information to IGP through a dedicated signaling channel. This feedback loop allows IGP to receive real-time notifications about security failures and respond by removing compromised routes, ensuring that routing decisions are based on current security conditions and preventing continued traffic forwarding on compromised links.

Inventive Principle:
Principle #23Feedback

2Stability of the object's composition

If IGP continues to forward traffic after secure session tear-down, then routing paths remain stable, but network security is compromised due to traffic on decrypted links

Engineering Contradiction:
Improverouting path stabilityVSAvoidnetwork security vulnerability
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The signaling channel from MKA to IGP provides real-time feedback about security session status. When MKA tears down a secure session due to a security failure, it immediately notifies IGP through this feedback channel, which then removes the corresponding route. This ensures that routing paths are dynamically adjusted in response to security conditions, preventing traffic from being forwarded on compromised links while maintaining routing stability through controlled, protocol-coordinated changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements preliminary anti-action by having MKA proactively notify IGP of security failures before IGP can detect them through its own peer maintenance mechanisms. This preemptive notification allows IGP to remove compromised routes before any unauthorized traffic forwarding can occur, counteracting the potential security vulnerability before it manifests.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11411915B2Leveraging MACsec key agreement (MKA) state events to trigger fast IGP/EGP convergence on MACsec encrypted links
Publication Date: 2022.08.09 CISCO TECHNOLOGY INC
  • US11411915B2 patent drawing
  • US11411915B2 patent drawing
  • US11411915B2 patent drawing

AI summary

A network device configured to communicate with a network executes a security protocol. The security protocol establishes a secure session with a security peer network device, exchanges security protected traffic with the security peer network device over a secure link, detects whether there is a security failure in the secure session, and upon detecting a security failure, signals there is a security failure. The network device also executes a routing protocol. The routing protocol maintains a routing table that includes a route to the security peer over the secure link, routes the security protected traffic along the route, and, upon receiving from the security protocol the signal that there is a security failure, removes the route from the routing table to stop the routing.