MPLS Security via Unified IKE and Secure Header Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

MPLS networks face challenges in securing data traffic as they lack a unified security scheme that can handle both layer 2 and layer 3 traffic, leading to potential security gaps and increased complexity due to the need for additional computing resources and network devices.

Innovation Solution

The implementation of a method where an ingress network device in an MPLS network encrypts packets using a secure function and generates an MPLS packet with a label and a secure function indicator, allowing for secure transmission through the network without the need for multiple security schemes or additional network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MPLS networks use separate security schemes for layer 2 and layer 3 traffic, then security coverage is improved, but device complexity and configuration complexity increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security scheme that can handle both layer 2 and layer 3 traffic through a single configuration framework. The security policy engine evaluates packets regardless of their layer type and applies appropriate security measures uniformly, eliminating the need for separate security schemes for different traffic layers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges previously separate layer 2 and layer 3 security schemes into a unified security processing architecture. By combining security policy evaluation, encryption/decryption functions, and security header processing into a single integrated system, the patent reduces configuration complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If additional computing resources and network devices are deployed to secure MPLS traffic, then security reliability is improved, but cost and device complexity increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidnetwork device quantity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables network devices to perform security functions autonomously using integrated cryptographic modules and security policy engines. Each network device can independently encrypt outgoing packets and decrypt incoming packets without requiring additional dedicated security appliances, reducing the need for extra network devices while maintaining security reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent designs network devices with multi-functional capabilities that combine routing, switching, and security processing in a single device. This universal design allows existing network infrastructure to provide security services without requiring additional specialized security devices, thereby reducing overall device complexity and cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If encryption is applied to all MPLS packets, then security coverage is improved, but processing time and productivity decrease

Engineering Contradiction:
Improvesecurity coverageVSAvoidpacket processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies security measures selectively rather than universally to all packets. The security policy engine evaluates each packet and applies encryption or security processing only when necessary based on policy rules, traffic type, or security requirements. This partial action approach maintains security coverage for required traffic while avoiding unnecessary processing overhead on packets that don't require security measures.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs security-related operations in advance where possible, such as pre-computing security parameters, pre-establishing security contexts, and pre-processing packets that require security measures. This preliminary action reduces the processing time required during actual packet forwarding, thereby maintaining higher packet processing speeds while still providing comprehensive security coverage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12244493B2Securing multiprotocol label switching (MPLS) payloads
Publication Date: 2025.03.04 JUNIPER NETWORKS INC
  • US12244493B2 patent drawing
  • US12244493B2 patent drawing
  • US12244493B2 patent drawing

AI summary

In some implementations, an egress network device of a multiprotocol label switching (MPLS) network may exchange Internet key exchange (IKE) messages with an ingress network device of the MPLS network to establish a security association between the egress network device and the ingress network device. The egress network device may receive an MPLS packet that includes an MPLS header, a secure MPLS data header, and an MPLS payload. The egress network device may process the MPLS header to determine a label associated with a label-switched path (LSP) and a secure function indicator. The egress network device may decrypt, using a secure function identified based on the secure MPLS data header, the MPLS payload to generate a decrypted packet. The egress network device may transmit the decrypted packet towards a destination device.