MACsec IGP Convergence via MKA Failure Signaling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network protocols fail to detect security failures in secure sessions promptly, leading to continued traffic forwarding on compromised links, resulting in undesirable delays and potential 'black-holing' of traffic.
Innovation Solution
Establishing a signaling channel between the MACsec Key Agreement (MKA) protocol and the Interior Gateway Protocol (IGP) to immediately notify IGP of security failures detected by MKA, allowing for instant declaration of failed routes and rerouting, thereby prioritizing security failures over IGP keepalives.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MKA and IGP peer maintenance operate independently, then each protocol can detect its own failures, but security failures are not promptly detected by the routing protocol, leading to continued traffic forwarding on compromised links
Solution Approach 1:
The patent merges the failure detection capabilities of MKA and IGP by establishing a signaling channel between them. When MKA detects a security failure, it sends a notification through this channel to IGP, which then removes the affected route. This integration ensures that security failures are promptly detected and reflected in routing decisions, eliminating the time delay caused by independent operation while maintaining the reliability of both protocols.
Solution Approach 2:
The patent implements a feedback mechanism where MKA provides security status information to IGP through a dedicated signaling channel. This feedback loop allows IGP to receive real-time notifications about security failures and respond by removing compromised routes, ensuring that routing decisions are based on current security conditions and preventing continued traffic forwarding on compromised links.
2Stability of the object's composition
If IGP continues to forward traffic after secure session tear-down, then routing paths remain stable, but network security is compromised due to traffic on decrypted links
Solution Approach 1:
The signaling channel from MKA to IGP provides real-time feedback about security session status. When MKA tears down a secure session due to a security failure, it immediately notifies IGP through this feedback channel, which then removes the corresponding route. This ensures that routing paths are dynamically adjusted in response to security conditions, preventing traffic from being forwarded on compromised links while maintaining routing stability through controlled, protocol-coordinated changes.
Solution Approach 2:
The patent implements preliminary anti-action by having MKA proactively notify IGP of security failures before IGP can detect them through its own peer maintenance mechanisms. This preemptive notification allows IGP to remove compromised routes before any unauthorized traffic forwarding can occur, counteracting the potential security vulnerability before it manifests.
Data Source
AI summary
A network device configured to communicate with a network executes a security protocol. The security protocol establishes a secure session with a security peer network device, exchanges security protected traffic with the security peer network device over a secure link, detects whether there is a security failure in the secure session, and upon detecting a security failure, signals there is a security failure. The network device also executes a routing protocol. The routing protocol maintains a routing table that includes a route to the security peer over the secure link, routes the security protected traffic along the route, and, upon receiving from the security protocol the signal that there is a security failure, removes the route from the routing table to stop the routing.


