VXLAN Packet Authentication via Dynamic Token Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
VXLAN encapsulation lacks security protection, making networks vulnerable to attacks where attackers can send fake packets, leading to network congestion and other negative impacts due to the lack of packet authentication.
Innovation Solution
Implementing a dynamic VXLAN packet authentication mechanism on both control and data panels using tokens to authenticate packets, where tokens are generated and verified across VXLAN Tunnel Endpoints (VTEPs) supporting both Ethernet and VXLAN formats, ensuring only valid packets are forwarded.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If VXLAN encapsulation is used to transmit packets in a network system, then network scalability and flexibility are improved, but network security deteriorates due to lack of packet authentication
Solution Approach 1:
The patent introduces an authentication code as an intermediary element between the VXLAN encapsulation mechanism and the packet transmission process. This authentication code, generated based on packet characteristics and cryptographic keys, acts as a mediator that verifies packet legitimacy without altering the core VXLAN encapsulation functionality, thus maintaining scalability while enhancing security
Solution Approach 2:
The patent modifies the VXLAN packet structure by adding an authentication code field and changes the packet processing parameters to include authentication verification. This parameter change allows the system to maintain compatibility with existing VXLAN infrastructure while implementing security checks that prevent fake packet injection
2Reliability
If packet authentication is implemented in a VXLAN system, then network security is improved, but device complexity increases due to additional authentication processing
Solution Approach 1:
The authentication code is generated in advance during the packet encapsulation process, before transmission. This preliminary action ensures that authentication verification at the receiving end is a simple comparison operation rather than a complex computation, reducing the processing complexity burden on network devices
Solution Approach 2:
The authentication mechanism uses cryptographic copying where the same authentication code generation algorithm and key pair are distributed to all VTEPs in the network. This allows each device to independently verify packets without requiring complex centralized authentication logic, simplifying device complexity while maintaining security
3Measurement precision
If dynamic token-based authentication is implemented across VTEPs, then packet verification accuracy is improved, but processing time increases due to token generation and verification operations
Solution Approach 1:
The authentication keys are updated periodically rather than being static, and the authentication code generation uses periodic cryptographic operations. This periodic action maintains high verification accuracy through frequent key rotation while keeping processing time manageable through efficient cryptographic algorithms and pre-computed key materials
Solution Approach 2:
Cryptographic key pairs are established and cached in advance before packet transmission occurs. This preliminary preparation of authentication materials allows the actual packet verification to use simple comparison operations rather than complex real-time cryptographic computations, reducing processing time while maintaining verification accuracy
Data Source
AI summary
Embodiments of the present disclosure relate to methods, systems, and computer program products for event management. In a method, a token is obtained at a first agent device that is included in a network system, the token is for authenticating a first packet that is transmitted in the network system, and the first packet is generated according to a first network format. A second packet is generated based on the first packet and the token according to a second network format. The second packet is transmitted to a second agent device that is included in the network system, here both of the first and second agent devices support the first and second network formats. With these embodiments, the packet may be authenticated in a more effective way.


