MACsec Label Policy Mapping for L3VPN Path Setup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing MACsec solutions in Level 3 Virtual Private Networks (L3VPNs) lack the capability to provide fine-grained path setup and apply different security strategies based on user-side information due to the absence of L2 MAC addresses and inaccessible L3/4 packet headers, leading to uniform security treatment of all traffic and increased latency.
Innovation Solution
Introduce a MACsec label concept that represents user information and associates it with specific policies, allowing flexible end-to-end MACsec path setup and unified policy application in L3VPNs using existing MPLS protocols like LDP, RSVP, and Segment Routing, ensuring consistent policy application across nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACsec is applied uniformly to all traffic in L3VPNs, then security coverage is improved, but latency increases and bandwidth consumption increases
Solution Approach 1:
The patent applies different security policies to different traffic flows by introducing flow identification mechanisms and policy association rules. Instead of uniform security treatment, the system enables selective MACsec application based on traffic characteristics, allowing critical traffic to receive enhanced security while non-critical traffic uses standard protection, thereby reducing overall latency and bandwidth consumption.
Solution Approach 2:
The patent changes the security parameter application from uniform to variable by introducing flow-specific policy parameters. Different MACsec policies can be assigned to different traffic flows based on their security requirements, enabling dynamic adjustment of security strength and corresponding performance characteristics for each flow.
2Adaptability or versatility
If fine-grained MACsec path setup is implemented in L3VPNs, then security policy flexibility is improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary mechanism in the form of policy association rules and flow identification structures that bridge the gap between traffic characteristics and security policies. This intermediary layer simplifies the mapping process by providing a standardized interface between traffic flow identification and MACsec policy selection, reducing the complexity of direct fine-grained path setup.
Solution Approach 2:
The patent creates universal structures for flow identification and policy association that can be applied across different traffic types and scenarios. The same mechanism framework handles various security policy requirements, reducing the need for separate complex configurations for each security scenario.
3Manufacturing precision
If user-side information is made accessible on the backbone side for MACsec policy selection, then path-setup granularity is improved, but information security requirements increase
Solution Approach 1:
The patent extracts only the necessary user-side information elements required for MACsec policy selection and transports them through the backbone network. By selectively extracting and transmitting only the minimal required information (such as flow identification markers) rather than complete user data, the system achieves fine-grained path setup while minimizing information security risks.
Data Source
AI summary
A method performed in a label-switched network is provided, and includes: to agree on a set of Media Access Control security, MACsec, policies for each of a plurality of interconnected node pairs of the network; to agree on an association between MACsec policies and MACsec labels for each interconnected node pair, and to establish a set of user information rules and associating each user information rule with a MACsec policy in at least one of the PE nodes. Corresponding methods for configuring PE and P nodes, PE and P node entities, a label-switched network, an improved MACsec packet and computer programs and computer program products are also provided.


