MPLS Security via Unified IKE and Secure Header Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
MPLS networks face challenges in securing data traffic as they lack a unified security scheme that can handle both layer 2 and layer 3 traffic, leading to potential security gaps and increased complexity due to the need for additional computing resources and network devices.
Innovation Solution
The implementation of a method where an ingress network device in an MPLS network encrypts packets using a secure function and generates an MPLS packet with a label and a secure function indicator, allowing for secure transmission through the network without the need for multiple security schemes or additional network devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MPLS networks use separate security schemes for layer 2 and layer 3 traffic, then security coverage is improved, but device complexity and configuration complexity increase
Solution Approach 1:
The patent implements a universal security scheme that can handle both layer 2 and layer 3 traffic through a single configuration framework. The security policy engine evaluates packets regardless of their layer type and applies appropriate security measures uniformly, eliminating the need for separate security schemes for different traffic layers.
Solution Approach 2:
The patent merges previously separate layer 2 and layer 3 security schemes into a unified security processing architecture. By combining security policy evaluation, encryption/decryption functions, and security header processing into a single integrated system, the patent reduces configuration complexity while maintaining comprehensive security coverage.
2Reliability
If additional computing resources and network devices are deployed to secure MPLS traffic, then security reliability is improved, but cost and device complexity increase
Solution Approach 1:
The patent enables network devices to perform security functions autonomously using integrated cryptographic modules and security policy engines. Each network device can independently encrypt outgoing packets and decrypt incoming packets without requiring additional dedicated security appliances, reducing the need for extra network devices while maintaining security reliability.
Solution Approach 2:
The patent designs network devices with multi-functional capabilities that combine routing, switching, and security processing in a single device. This universal design allows existing network infrastructure to provide security services without requiring additional specialized security devices, thereby reducing overall device complexity and cost.
3Reliability
If encryption is applied to all MPLS packets, then security coverage is improved, but processing time and productivity decrease
Solution Approach 1:
The patent applies security measures selectively rather than universally to all packets. The security policy engine evaluates each packet and applies encryption or security processing only when necessary based on policy rules, traffic type, or security requirements. This partial action approach maintains security coverage for required traffic while avoiding unnecessary processing overhead on packets that don't require security measures.
Solution Approach 2:
The patent performs security-related operations in advance where possible, such as pre-computing security parameters, pre-establishing security contexts, and pre-processing packets that require security measures. This preliminary action reduces the processing time required during actual packet forwarding, thereby maintaining higher packet processing speeds while still providing comprehensive security coverage.
Data Source
AI summary
In some implementations, an egress network device of a multiprotocol label switching (MPLS) network may exchange Internet key exchange (IKE) messages with an ingress network device of the MPLS network to establish a security association between the egress network device and the ingress network device. The egress network device may receive an MPLS packet that includes an MPLS header, a secure MPLS data header, and an MPLS payload. The egress network device may process the MPLS header to determine a label associated with a label-switched path (LSP) and a secure function indicator. The egress network device may decrypt, using a secure function identified based on the secure MPLS data header, the MPLS payload to generate a decrypted packet. The egress network device may transmit the decrypted packet towards a destination device.


