SR-TE Policy Steering via Security Level Constraints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network security measures, such as link encryption, are ineffective in protecting sensitive information when network nodes are compromised, as they do not account for varying security levels of nodes and links within the network.

Innovation Solution

The system steers network traffic into Segment Routing - Traffic Engineering (SR-TE) policies based on security level constraints, using Segment Identifiers (SIDs) with associated security levels to ensure that traffic is routed through trusted nodes and links, leveraging the Security Level constraint to validate candidate paths and invalidate paths with lower security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional link encryption is used to protect network traffic, then basic security is provided, but the protection is ineffective when network nodes are compromised

Engineering Contradiction:
Improvesecurity protectionVSAvoidnode compromise vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent assigns different security levels to different network nodes and links, creating local quality variations throughout the network. This allows the system to identify and avoid compromised nodes by routing traffic through paths with higher security levels, rather than treating all nodes uniformly as in traditional encryption approaches

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system pre-calculates and stores multiple candidate paths with their associated security levels before traffic needs to be routed. When traffic requires secure transmission, the system can quickly select from pre-evaluated paths that meet security requirements, avoiding the need to reactively search for secure routes after a compromise is detected

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security level constraints are enforced for all network traffic, then secure paths are ensured, but network complexity increases due to path validation requirements

Engineering Contradiction:
Improvesecure path routingVSAvoidpath validation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-calculates security levels for all network nodes and links, and pre-identifies candidate paths that meet minimum security constraints. This preliminary evaluation stores security metadata in routing tables, allowing routers to make secure routing decisions based on simple lookups rather than complex real-time validation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a dedicated security level calculation mechanism that acts as an intermediary between network topology and routing decisions. This separate calculation layer evaluates security attributes and translates them into routing-friendly formats, isolating the complexity of security validation from the core routing logic

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple candidate paths are maintained for SR-TE policies, then routing flexibility is improved, but path selection complexity increases due to security level validation

Engineering Contradiction:
Improverouting flexibilityVSAvoidpath selection complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Each candidate path is assigned a security level attribute that reflects the minimum security level of its constituent nodes and links. This local quality marking allows routers to quickly compare paths and select appropriate routes based on traffic security requirements without performing complex real-time security analyses

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system maintains multiple candidate paths with varying security levels, providing more routing options than strictly necessary. This excessive path maintenance allows the system to quickly adapt to changing security requirements by selecting from pre-prepared paths rather than generating new paths when security conditions change

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12058038B2Systems and methods for steering traffic into SR-TE policies
Publication Date: 2024.08.06 CISCO TECHNOLOGY INC
  • US12058038B2 patent drawing
  • US12058038B2 patent drawing
  • US12058038B2 patent drawing

AI summary

In one embodiment, a method includes a method includes receiving, by a headend node, network traffic. The method also includes determining, by the headend node, that the network traffic matches a service route. The method further includes steering, by the headend node, the network traffic into an SR-TE policy. The SR-TE policy is associated with the service route and includes a security level constraint.