PCC-PCE Security Capability Negotiation via Extended PCEP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication systems between Path Computation Clients (PCC) and Path Computation Elements (PCE) lack a mechanism for dynamically negotiating security capabilities, relying on static configuration which is complex and vulnerable to unauthorized access and denial-of-service attacks.
Innovation Solution
Implementing a method where PCC and PCE negotiate security capabilities by exchanging packets carrying security policy information, using extended Path Computation Element Discovery (PCED) and Path Computation Element Communication Protocol (PCEP) protocols, to dynamically configure and simplify security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static configuration is used for security policies between PCC and PCE, then implementation is simple, but device complexity increases and vulnerability to attacks increases
Solution Approach 1:
The patent applies dynamics by transitioning from static security policy configuration to dynamic negotiation. The PCC and PCE exchange capability information packets to dynamically determine security policies, allowing the system to adapt security measures based on real-time capability assessments rather than relying on pre-configured static rules, thereby reducing configuration complexity while maintaining security reliability
Solution Approach 2:
The patent implements self-service by enabling the PCC and PCE to autonomously negotiate and determine their own security policies through capability exchange. Each endpoint independently assesses the other's capabilities and mutually agrees on appropriate security measures without requiring centralized manual configuration, thus simplifying deployment while ensuring reliable security posture
2Reliability
If dynamic negotiation of security capabilities is implemented, then security reliability improves, but protocol complexity increases
Solution Approach 1:
The patent applies universality by designing a multi-functional capability exchange mechanism that handles multiple security negotiation aspects within a unified framework. The same packet exchange process accommodates various security capabilities (authentication, encryption, integrity protection), allowing a single protocol extension to serve multiple security functions rather than requiring separate specialized protocols for each security feature
Solution Approach 2:
The patent utilizes parameter changes by enabling dynamic adjustment of security policy parameters based on negotiated capabilities. The system can modify security parameters such as authentication methods, encryption algorithms, and key management approaches according to the actual capabilities discovered during negotiation, allowing flexible adaptation to different security requirements without implementing every possible configuration option
3Ease of operation
If manual security policy configuration is used, then control is simple, but deployment complexity increases
Solution Approach 1:
The patent implements self-service by enabling the PCC and PCE to autonomously negotiate and determine their own security policies through capability exchange. Each endpoint independently assesses the other's capabilities and mutually agrees on appropriate security measures without requiring centralized manual configuration, thus simplifying deployment while ensuring reliable security posture
Solution Approach 2:
The patent applies preliminary action by having the PCE publish its security capabilities in advance through capability information packets before actual communication begins. This预先 disclosure allows PCCs to make informed decisions about security policy negotiation and compatibility assessment prior to establishing connections, simplifying deployment by enabling proactive rather than reactive security configuration
Data Source
AI summary
A method and a network system for negotiating a security capability between a path computation client (PCC) and a path computation element (PCE) are described. The method includes the steps as follows. The PCE sends a packet carrying security policy capability information to the PCC. After receiving the packet, the PCC acquires a security policy capability supported or required by the PCE or a security policy capability supported by both of the PCE and the PCC. In various embodiments of the present invention, negotiation of PCC-PCE and PCC-PCC may be performed by sending the packet carrying the security policy capability information, thereby greatly simplifying the security policy configuration between PCC-PCE and PCE-PCE, and simplifying the complexity in PCE deployment.


