MACsec Label Policy Mapping for L3VPN Path Setup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing MACsec solutions in Level 3 Virtual Private Networks (L3VPNs) lack the capability to provide fine-grained path setup and apply different security strategies based on user-side information due to the absence of L2 MAC addresses and inaccessible L3/4 packet headers, leading to uniform security treatment of all traffic and increased latency.

Innovation Solution

Introduce a MACsec label concept that represents user information and associates it with specific policies, allowing flexible end-to-end MACsec path setup and unified policy application in L3VPNs using existing MPLS protocols like LDP, RSVP, and Segment Routing, ensuring consistent policy application across nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MACsec is applied uniformly to all traffic in L3VPNs, then security coverage is improved, but latency increases and bandwidth consumption increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies different security policies to different traffic flows by introducing flow identification mechanisms and policy association rules. Instead of uniform security treatment, the system enables selective MACsec application based on traffic characteristics, allowing critical traffic to receive enhanced security while non-critical traffic uses standard protection, thereby reducing overall latency and bandwidth consumption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the security parameter application from uniform to variable by introducing flow-specific policy parameters. Different MACsec policies can be assigned to different traffic flows based on their security requirements, enabling dynamic adjustment of security strength and corresponding performance characteristics for each flow.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If fine-grained MACsec path setup is implemented in L3VPNs, then security policy flexibility is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity policy flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism in the form of policy association rules and flow identification structures that bridge the gap between traffic characteristics and security policies. This intermediary layer simplifies the mapping process by providing a standardized interface between traffic flow identification and MACsec policy selection, reducing the complexity of direct fine-grained path setup.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates universal structures for flow identification and policy association that can be applied across different traffic types and scenarios. The same mechanism framework handles various security policy requirements, reducing the need for separate complex configurations for each security scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Manufacturing precision

If user-side information is made accessible on the backbone side for MACsec policy selection, then path-setup granularity is improved, but information security requirements increase

Engineering Contradiction:
Improvepath-setup granularityVSAvoidinformation security requirements
Core Design Contradiction:
Manufacturing precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary user-side information elements required for MACsec policy selection and transports them through the backbone network. By selectively extracting and transmitting only the minimal required information (such as flow identification markers) rather than complete user data, the system achieves fine-grained path setup while minimizing information security risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250211576A1End-to-end mac-security path setup in level 3 virtual private networks
Publication Date: 2025.06.26 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250211576A1 patent drawing
  • US20250211576A1 patent drawing
  • US20250211576A1 patent drawing

AI summary

A method performed in a label-switched network is provided, and includes: to agree on a set of Media Access Control security, MACsec, policies for each of a plurality of interconnected node pairs of the network; to agree on an association between MACsec policies and MACsec labels for each interconnected node pair, and to establish a set of user information rules and associating each user information rule with a MACsec policy in at least one of the PE nodes. Corresponding methods for configuring PE and P nodes, PE and P node entities, a label-switched network, an improved MACsec packet and computer programs and computer program products are also provided.