VXLAN Access Authentication with Overlay-Only Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VXLAN access authentication methods require cumbersome configuration changes on both the underlay and overlay networks when modifying or creating new authentication modes, leading to complex operations and management.

Innovation Solution

Perform VXLAN access authentication on the overlay network using VXLAN authentication packets, allowing configuration changes to be made only on the overlay network, decoupling it from the underlay network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VXLAN access authentication is performed on the underlay network, then authentication can be established, but configuration complexity increases when modifying or creating authentication modes

Engineering Contradiction:
Improveauthentication establishmentVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process from the underlay network to the overlay network. The underlay network handles only packet forwarding, while the overlay network handles authentication operations. This segmentation allows independent configuration management, reducing overall system complexity when authentication modes need to be modified.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces VXLAN authentication packets as an intermediary mechanism. These packets carry authentication information through the overlay network without requiring underlay network configuration changes. The intermediary packet structure enables authentication mode modifications solely in the overlay network, decoupling configuration complexity from the underlay infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If VXLAN access authentication is performed on the overlay network, then configuration complexity is reduced, but authentication packet transmission is required through VXLAN tunnels

Engineering Contradiction:
Improveconfiguration complexityVSAvoidauthentication efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent establishes VXLAN tunnels and authentication pathways in advance before actual authentication operations. By pre-configuring the tunnel infrastructure and authentication packet routes, the system eliminates runtime configuration overhead, maintaining high authentication efficiency while enabling simplified overlay network configuration management.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication configuration is performed on both underlay and overlay networks, then comprehensive authentication is achieved, but operation and management become cumbersome

Engineering Contradiction:
Improveauthentication coverageVSAvoidoperation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication configuration requirements from the underlay network and concentrates them entirely in the overlay network. This extraction eliminates the need for coordinated configuration changes across multiple network layers, making operations and management significantly more convenient while maintaining comprehensive authentication coverage through the overlay network's authentication mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12388678B2VXLAN access authentication method and VTEP device
Publication Date: 2025.08.12 HUAWEI TECH CO LTD
  • US12388678B2 patent drawing
  • US12388678B2 patent drawing
  • US12388678B2 patent drawing

AI summary

A VXLAN access authentication method includes: An authentication point device receives a VXLAN authentication packet, where the VXLAN authentication packet is a VXLAN packet. The VXLAN authentication packet includes a VXLAN header and an authentication request sent by a terminal, the VXLAN header includes a first VNI, and the authentication request includes an authentication credential. The authentication point device obtains permission of the terminal or a second VNI based on the authentication credential. The permission of the terminal corresponds to the second VNI. The authentication point device sends the permission of the terminal or the second VNI to a control point device, where the control point device is a device that encapsulates the authentication request into the VXLAN authentication packet. In this application, VXLAN access authentication is performed on an overlay network, so that configuration complexity can be reduced when a VXLAN access authentication mode is modified or created.