Security-Classified Routing Paths for MACsec Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network devices face challenges in securely routing network traffic among multiple devices using MACsec links, requiring significant computing resources and inducing latency due to the need for specialized hardware and traffic engineering processes.
Innovation Solution
Network devices determine and maintain routing paths based on security classifications, using advertisement messages to update routing tables, allowing network traffic to be forwarded via appropriate security paths without specialized hardware or traffic engineering, thus reducing resource usage and latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic engineering processes and specialized hardware are used to securely route network traffic among multiple devices using MACsec links, then security is improved, but device complexity and computing resource usage increase significantly
Solution Approach 1:
The patent extracts the security classification information from the network traffic and uses it to select pre-determined routing paths. By separating the security determination function from the routing function, the patent eliminates the need for complex traffic engineering processes and specialized hardware, achieving secure routing through standard network devices using classification-based path selection
Solution Approach 2:
The patent performs preliminary routing path determination by establishing multiple pre-configured routing paths associated with different security classifications before traffic needs to be routed. This advance preparation allows network devices to simply select from pre-determined paths based on traffic classification, avoiding real-time complex computations and eliminating the need for specialized traffic engineering hardware
2Reliability
If traffic engineering processes are used to securely route network traffic, then security is improved, but latency increases due to processing requirements
Solution Approach 1:
The patent performs preliminary routing path determination by establishing multiple pre-configured routing paths associated with different security classifications before traffic needs to be routed. This advance preparation allows network devices to simply select from pre-determined paths based on traffic classification, avoiding real-time complex computations and eliminating the need for specialized traffic engineering hardware
Solution Approach 2:
The patent enables network devices to autonomously select appropriate routing paths based on security classification information embedded in the traffic itself. This self-service mechanism eliminates the need for external traffic engineering control and real-time processing, allowing devices to independently make routing decisions without adding latency
3Reliability
If specialized hardware is used for secure routing with MACsec links, then security is improved, but computing resources and power consumption increase
Solution Approach 1:
The patent extracts the security classification information from the network traffic and uses it to select pre-determined routing paths. By separating the security determination function from the routing function, the patent eliminates the need for complex traffic engineering processes and specialized hardware, achieving secure routing through standard network devices using classification-based path selection
Solution Approach 2:
The patent replaces expensive specialized hardware with standard, readily available network devices. By using conventional equipment with software-based security classification and routing path selection, the patent achieves the same security functionality at lower cost and reduced power consumption
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
BACKGROUND Media access control security (MACsec) provides secure communication for traffic on physical links, such as Ethernet links. MACsec provides point-to-point security on links between directly connected devices. SUMMARY Some implementations described herein relate to a network device. The network device may include one or more memories and one or more processors. The network device may be configured to receive, from another network device, a first message, a second message, and a third message. The network device may be configured to update, based on the first message, the second message, and the third message, a routing table. The network device may be configured to determine, based on the routing table, a first routing path associated with the first security classification from the network device to the other network device, a second routing path associated with the second security classification from the network device to the other network device, and a third routing path associated with the third security classification from the network device to the other network device. The network device may be configured to receive network traffic that is destined for the other network device and that is associated with a particular security classification, of the first security classification, the second security classification, or the third security classification. The network device may be configured to forward the network traffic based on a particular routing path, of the first routing path, the second routing path, or the third routing path, that is associated with the other network device and the particular security classification. Some implementations described herein relate to a computer-readable medium that comprises a set of instructions for a network device. The set of instructions, when executed by one or more processors of the network device, may cause the network device to determine, based on a routing table, a first routing path associated with a first security classification from the network device to another network device. The set of instructions, when executed by one or more processors of the network device, may cause the network device to determine, based on the routing table, a second routing path associated with a second security classification from the network device to the other network device. The set of instructions, when executed by one or more processors of the network device, may cause the network device to determine, based on the routing table, a third routing path associated with a third security classification from the network device to the other network device. The set of instructions, when executed by one or more processors of the network device, may cause the network device to receive