Extended Community Attribute Preserving Originator Identity in VPN Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Virtual Private Networks (VPNs) face challenges in identifying the originating Customer Edge (CE) router during route propagation, leading to loss of originator information and hindered CE-CE verification checks, which affects route reachability and rerouting decisions.
Innovation Solution
Incorporating an extended community attribute in path verification messages to store and preserve the identity of the originating CE router, allowing it to be transported across the network undisturbed by successive routing operations, enabling CE-CE verification checks and route reachability aggregation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional routing operations are used to propagate routes across the network, then routing decisions can be made, but the identity of the originating CE router is lost during transmission
Solution Approach 1:
An extended community attribute acts as an intermediary carrier that transports the originating CE router identity through the routing process. This attribute is embedded in route updates and preserved through successive routing operations, allowing the originator information to survive transmission without interfering with normal routing functionality.
Solution Approach 2:
The routing information is segmented into multiple components: the standard routing data for path determination and the extended community attribute for originator identification. This segmentation allows the routing system to process path information while separately preserving and transmitting the originator identity through the extended attribute field.
2Reliability
If the originator information is preserved through extended community attributes, then CE-CE verification checks can be performed, but the routing message structure becomes more complex
Solution Approach 1:
The extended community attribute structure is designed to serve multiple functions: it preserves originator identity for verification purposes, maintains compatibility with existing routing protocols, and provides a standardized format that can be processed by various routing devices without requiring fundamental changes to the routing message structure.
3Adaptability or versatility
If conventional routing tables are used without originator identification, then routing decisions can be made quickly, but selective rerouting based on originator cannot be implemented
Solution Approach 1:
The originating CE router identity is embedded in the extended community attribute during the initial route advertisement, before any routing decisions or verification checks are needed. This preliminary inclusion of originator information eliminates the need for time-consuming verification processes later, as the identity is already available for immediate use in selective rerouting decisions.
Data Source
AI summary
Customer edge (CE) to CE device verification checks initiate routes from available CEs as a set of path verification messages, destined for remote CE routes serving a remote VPN. An extended community attribute, included among the attributes of the path verification message, stores the identity of the originating CE router. The path verification message propagates across the network, and transports the identity of the originating CE router because the originator identity is not overwritten by successive routing. Upon receipt by the remote CE, the originator is determinable from the extended community attribute. A further reachability field is also included in the extended community attribute and indicates whether per CE or per prefix is appropriate for the particular route in question. In this manner, CE-CE connectivity checks identify CEs which are reachable from other CEs. Accordingly, such a mechanism allows for route reachability aggregation on a per-CE or per-prefix reachability basis.


