PCC-PCE Security Capability Negotiation via Extended PCEP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems between Path Computation Clients (PCC) and Path Computation Elements (PCE) lack a mechanism for dynamically negotiating security capabilities, relying on static configuration which is complex and vulnerable to unauthorized access and denial-of-service attacks.

Innovation Solution

Implementing a method where PCC and PCE negotiate security capabilities by exchanging packets carrying security policy information, using extended Path Computation Element Discovery (PCED) and Path Computation Element Communication Protocol (PCEP) protocols, to dynamically configure and simplify security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static configuration is used for security policies between PCC and PCE, then implementation is simple, but device complexity increases and vulnerability to attacks increases

Engineering Contradiction:
Improvesecurity against unauthorized access and DoS attacksVSAvoidsecurity policy configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by transitioning from static security policy configuration to dynamic negotiation. The PCC and PCE exchange capability information packets to dynamically determine security policies, allowing the system to adapt security measures based on real-time capability assessments rather than relying on pre-configured static rules, thereby reducing configuration complexity while maintaining security reliability

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements self-service by enabling the PCC and PCE to autonomously negotiate and determine their own security policies through capability exchange. Each endpoint independently assesses the other's capabilities and mutually agrees on appropriate security measures without requiring centralized manual configuration, thus simplifying deployment while ensuring reliable security posture

Inventive Principle:
Principle #25Self-service

2Reliability

If dynamic negotiation of security capabilities is implemented, then security reliability improves, but protocol complexity increases

Engineering Contradiction:
Improvecommunication security between PCC and PCEVSAvoidprotocol implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a multi-functional capability exchange mechanism that handles multiple security negotiation aspects within a unified framework. The same packet exchange process accommodates various security capabilities (authentication, encryption, integrity protection), allowing a single protocol extension to serve multiple security functions rather than requiring separate specialized protocols for each security feature

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent utilizes parameter changes by enabling dynamic adjustment of security policy parameters based on negotiated capabilities. The system can modify security parameters such as authentication methods, encryption algorithms, and key management approaches according to the actual capabilities discovered during negotiation, allowing flexible adaptation to different security requirements without implementing every possible configuration option

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If manual security policy configuration is used, then control is simple, but deployment complexity increases

Engineering Contradiction:
Improvesecurity policy setup simplicityVSAvoidPCE deployment complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the PCC and PCE to autonomously negotiate and determine their own security policies through capability exchange. Each endpoint independently assesses the other's capabilities and mutually agrees on appropriate security measures without requiring centralized manual configuration, thus simplifying deployment while ensuring reliable security posture

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by having the PCE publish its security capabilities in advance through capability information packets before actual communication begins. This预先 disclosure allows PCCs to make informed decisions about security policy negotiation and compatibility assessment prior to establishing connections, simplifying deployment by enabling proactive rather than reactive security configuration

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8127129B2Method and network system for negotiating a security capability between a PCC and a PCE
Publication Date: 2012.02.28 HUAWEI TECH CO LTD
  • US8127129B2 patent drawing
  • US8127129B2 patent drawing
  • US8127129B2 patent drawing

AI summary

A method and a network system for negotiating a security capability between a path computation client (PCC) and a path computation element (PCE) are described. The method includes the steps as follows. The PCE sends a packet carrying security policy capability information to the PCC. After receiving the packet, the PCC acquires a security policy capability supported or required by the PCE or a security policy capability supported by both of the PCE and the PCC. In various embodiments of the present invention, negotiation of PCC-PCE and PCC-PCC may be performed by sending the packet carrying the security policy capability information, thereby greatly simplifying the security policy configuration between PCC-PCE and PCE-PCE, and simplifying the complexity in PCE deployment.