SR-TE Policy Steering via Security Level Constraints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network security measures, such as link encryption, are ineffective in protecting sensitive information when network nodes are compromised, as they do not account for varying security levels of nodes and links within the network.
Innovation Solution
The system steers network traffic into Segment Routing - Traffic Engineering (SR-TE) policies based on security level constraints, using Segment Identifiers (SIDs) with associated security levels to ensure that traffic is routed through trusted nodes and links, leveraging the Security Level constraint to validate candidate paths and invalidate paths with lower security levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional link encryption is used to protect network traffic, then basic security is provided, but the protection is ineffective when network nodes are compromised
Solution Approach 1:
The patent assigns different security levels to different network nodes and links, creating local quality variations throughout the network. This allows the system to identify and avoid compromised nodes by routing traffic through paths with higher security levels, rather than treating all nodes uniformly as in traditional encryption approaches
Solution Approach 2:
The system pre-calculates and stores multiple candidate paths with their associated security levels before traffic needs to be routed. When traffic requires secure transmission, the system can quickly select from pre-evaluated paths that meet security requirements, avoiding the need to reactively search for secure routes after a compromise is detected
2Reliability
If security level constraints are enforced for all network traffic, then secure paths are ensured, but network complexity increases due to path validation requirements
Solution Approach 1:
The system pre-calculates security levels for all network nodes and links, and pre-identifies candidate paths that meet minimum security constraints. This preliminary evaluation stores security metadata in routing tables, allowing routers to make secure routing decisions based on simple lookups rather than complex real-time validation
Solution Approach 2:
The patent introduces a dedicated security level calculation mechanism that acts as an intermediary between network topology and routing decisions. This separate calculation layer evaluates security attributes and translates them into routing-friendly formats, isolating the complexity of security validation from the core routing logic
3Adaptability or versatility
If multiple candidate paths are maintained for SR-TE policies, then routing flexibility is improved, but path selection complexity increases due to security level validation
Solution Approach 1:
Each candidate path is assigned a security level attribute that reflects the minimum security level of its constituent nodes and links. This local quality marking allows routers to quickly compare paths and select appropriate routes based on traffic security requirements without performing complex real-time security analyses
Solution Approach 2:
The system maintains multiple candidate paths with varying security levels, providing more routing options than strictly necessary. This excessive path maintenance allows the system to quickly adapt to changing security requirements by selecting from pre-prepared paths rather than generating new paths when security conditions change
Data Source
AI summary
In one embodiment, a method includes a method includes receiving, by a headend node, network traffic. The method also includes determining, by the headend node, that the network traffic matches a service route. The method further includes steering, by the headend node, the network traffic into an SR-TE policy. The SR-TE policy is associated with the service route and includes a security level constraint.


