Security-Classified Routing Paths for MACsec Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network devices face challenges in securely routing network traffic among multiple devices using MACsec links, requiring significant computing resources and inducing latency due to the need for specialized hardware and traffic engineering processes.

Innovation Solution

Network devices determine and maintain routing paths based on security classifications, using advertisement messages to update routing tables, allowing network traffic to be forwarded via appropriate security paths without specialized hardware or traffic engineering, thus reducing resource usage and latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic engineering processes and specialized hardware are used to securely route network traffic among multiple devices using MACsec links, then security is improved, but device complexity and computing resource usage increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security classification information from the network traffic and uses it to select pre-determined routing paths. By separating the security determination function from the routing function, the patent eliminates the need for complex traffic engineering processes and specialized hardware, achieving secure routing through standard network devices using classification-based path selection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary routing path determination by establishing multiple pre-configured routing paths associated with different security classifications before traffic needs to be routed. This advance preparation allows network devices to simply select from pre-determined paths based on traffic classification, avoiding real-time complex computations and eliminating the need for specialized traffic engineering hardware

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traffic engineering processes are used to securely route network traffic, then security is improved, but latency increases due to processing requirements

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary routing path determination by establishing multiple pre-configured routing paths associated with different security classifications before traffic needs to be routed. This advance preparation allows network devices to simply select from pre-determined paths based on traffic classification, avoiding real-time complex computations and eliminating the need for specialized traffic engineering hardware

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables network devices to autonomously select appropriate routing paths based on security classification information embedded in the traffic itself. This self-service mechanism eliminates the need for external traffic engineering control and real-time processing, allowing devices to independently make routing decisions without adding latency

Inventive Principle:
Principle #25Self-service

3Reliability

If specialized hardware is used for secure routing with MACsec links, then security is improved, but computing resources and power consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the security classification information from the network traffic and uses it to select pre-determined routing paths. By separating the security determination function from the routing function, the patent eliminates the need for complex traffic engineering processes and specialized hardware, achieving secure routing through standard network devices using classification-based path selection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces expensive specialized hardware with standard, readily available network devices. By using conventional equipment with software-based security classification and routing path selection, the patent achieves the same security functionality at lower cost and reduced power consumption

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP4195592B1Forwarding network traffic associated with a security classification via a routing path associated with the security classification
Publication Date: 2026.05.06 JUNIPER NETWORKS INC
  • EP4195592B1 patent drawingFigure 1A
  • EP4195592B1 patent drawingFigure 1B
  • EP4195592B1 patent drawingFigure 1C

AI summary

BACKGROUND Media access control security (MACsec) provides secure communication for traffic on physical links, such as Ethernet links. MACsec provides point-to-point security on links between directly connected devices. SUMMARY Some implementations described herein relate to a network device. The network device may include one or more memories and one or more processors. The network device may be configured to receive, from another network device, a first message, a second message, and a third message. The network device may be configured to update, based on the first message, the second message, and the third message, a routing table. The network device may be configured to determine, based on the routing table, a first routing path associated with the first security classification from the network device to the other network device, a second routing path associated with the second security classification from the network device to the other network device, and a third routing path associated with the third security classification from the network device to the other network device. The network device may be configured to receive network traffic that is destined for the other network device and that is associated with a particular security classification, of the first security classification, the second security classification, or the third security classification. The network device may be configured to forward the network traffic based on a particular routing path, of the first routing path, the second routing path, or the third routing path, that is associated with the other network device and the particular security classification. Some implementations described herein relate to a computer-readable medium that comprises a set of instructions for a network device. The set of instructions, when executed by one or more processors of the network device, may cause the network device to determine, based on a routing table, a first routing path associated with a first security classification from the network device to another network device. The set of instructions, when executed by one or more processors of the network device, may cause the network device to determine, based on the routing table, a second routing path associated with a second security classification from the network device to the other network device. The set of instructions, when executed by one or more processors of the network device, may cause the network device to determine, based on the routing table, a third routing path associated with a third security classification from the network device to the other network device. The set of instructions, when executed by one or more processors of the network device, may cause the network device to receive