Securing multiprotocol label switching (MPLS) payloads

    公开(公告)号:US11882029B2

    公开(公告)日:2024-01-23

    申请号:US17663319

    申请日:2022-05-13

    摘要: In some implementations, an ingress network device of a multiprotocol label switching (MPLS) network may receive a packet destined for a destination network device. The ingress network device may determine, based on the packet, a secure function to secure the packet and a label associated with a label-switched path (LSP) from the ingress network device to an egress network device of the MPLS network that is associated with the destination network device. The ingress network device may encrypt, using the secure function, the packet to generate an encrypted packet. The ingress network device may generate an MPLS packet comprising: an MPLS header that includes the label and a secure function indicator, a secure MPLS data header that includes information identifying the secure function, and an MPLS payload that includes the encrypted packet. The ingress network device may forward, based on the label, the MPLS packet.

    Guaranteed bandwidth for segment routed (SR) paths

    公开(公告)号:US11070463B2

    公开(公告)日:2021-07-20

    申请号:US16589115

    申请日:2019-09-30

    摘要: At least one bandwidth-guaranteed segment routing (SR) path through a network is determined by: (a) receiving, as input, a bandwidth demand value; (b) obtaining network information; (c) determining a constrained shortest multipath (CSGi); (d) determining a set of SR segment-list(s) (Si=[sl1i, sl2i . . . slni]) a that are needed to steer traffic over CSGi; and (e) tuning the loadshares in Li, using Si and the per segment-list loadshare (Li=[l1i, l2i . . . lni]), the per segment equal cost multipath (“ECMP”), and the per link residual capacity, such that the bandwidth capacity that can be carried over CSGi is maximized.

    RSVP make-before-break label reuse

    公开(公告)号:US10313234B2

    公开(公告)日:2019-06-04

    申请号:US15834722

    申请日:2017-12-07

    IPC分类号: H04L12/723 H04L12/735

    摘要: Techniques are described for reusing downstream-assigned labels when establishing a new instance of a label switched path (LSP) prior to tearing down an existing instance of the LSP using make-before-break (MBB) procedures for RSVP. The techniques enable a routing engine of any non-ingress router along a path of the new LSP instance to reuse a previously allocated label for the existing LSP instance as the downstream assigned label for the new LSP instance when the paths of the existing LSP instance and the new LSP instance overlap. In this way, the non-ingress router does not need to update a label route in its forwarding plane for the reused label. When the new LSP instance completely overlaps the existing LSP instance, an ingress router of the LSP may avoid updating an ingress route in its forwarding plane for applications that use the LSP.

    Applications-aware targeted LDP sessions

    公开(公告)号:US10291522B1

    公开(公告)日:2019-05-14

    申请号:US15463106

    申请日:2017-03-20

    IPC分类号: H04L12/741 H04L29/08

    摘要: In general, the disclosure relates to techniques for initiating a targeted LDP session in a manner that includes information specifying one or more application for which a targeted LDP session is being initiated. In one example, a method includes receiving, by a network device, a LDP initialization message to initiate an Label Distribution Protocol (LDP) session with a peer network device, the LDP initialization message including a Targeted Applications Capability (TAC) field specifying one or more applications for which the LDP session is to be used for advertising forwarding equivalence class (FEC)-label bindings between the network device and the peer network device, and determining, by the network device, whether to allow the LDP session to be established based on the one or more applications specified in the TAC field.

    RSVP MAKE-BEFORE-BREAK LABEL REUSE
    7.
    发明申请

    公开(公告)号:US20180097726A1

    公开(公告)日:2018-04-05

    申请号:US15834722

    申请日:2017-12-07

    IPC分类号: H04L12/723 H04L12/735

    摘要: Techniques are described for reusing downstream-assigned labels when establishing a new instance of a label switched path (LSP) prior to tearing down an existing instance of the LSP using make-before-break (MBB) procedures for RSVP. The techniques enable a routing engine of any non-ingress router along a path of the new LSP instance to reuse a previously allocated label for the existing LSP instance as the downstream assigned label for the new LSP instance when the paths of the existing LSP instance and the new LSP instance overlap. In this way, the non-ingress router does not need to update a label route in its forwarding plane for the reused label. When the new LSP instance completely overlaps the existing LSP instance, an ingress router of the LSP may avoid updating an ingress route in its forwarding plane for applications that use the LSP.

    Applications-aware targeted LDP sessions

    公开(公告)号:US09602354B1

    公开(公告)日:2017-03-21

    申请号:US14320242

    申请日:2014-06-30

    CPC分类号: H04L41/0893 H04L45/507

    摘要: In general, the disclosure relates to techniques for initiating a targeted LDP session in a manner that includes information specifying one or more application for which a targeted LDP session is being initiated. In one example, a method includes receiving, by a network device, a LDP initialization message to initiate an Label Distribution Protocol (LDP) session with a peer network device, the LDP initialization message including a Targeted Applications Capability (TAC) field specifying one or more applications for which the LDP session is to be used for advertising forwarding equivalence class (FEC)-label bindings between the network device and the peer network device, and determining, by the network device, whether to allow the LDP session to be established based on the one or more applications specified in the TAC field.

    LABEL SWITCHED PATH PREEMPTION AVOIDANCE
    10.
    发明申请
    LABEL SWITCHED PATH PREEMPTION AVOIDANCE 审中-公开
    标签开关路径避免

    公开(公告)号:US20160277959A1

    公开(公告)日:2016-09-22

    申请号:US14713068

    申请日:2015-05-15

    摘要: Techniques are described for establishing lower priority LSPs on paths determined to be less likely to include bandwidth constrained links. In one example, a router includes a plurality of physical interfaces each having at least one link interconnecting the router as one of a plurality of routers in a network and a processor. The processor is configured to determine whether a link of one of the plurality of physical interfaces is congested based at least in part on an amount of available bandwidth on the link, and, responsive to determining that the link is congested, set a bandwidth subscription for the link, wherein the bandwidth subscription specifies that the amount of available bandwidth on the link for label switched paths having a lower priority is less than the amount of available bandwidth on the link for label switched paths having a higher priority.

    摘要翻译: 描述了用于在确定为不太可能包括带宽受限链路的路径上建立较低优先级的LSP的技术。 在一个示例中,路由器包括多个物理接口,每个物理接口具有将路由器互连到网络中的多个路由器之一和处理器中的至少一个链路。 处理器被配置为至少部分地基于链路上的可用带宽的量来确定多个物理接口中的一个的链路是否拥塞,并且响应于确定链路拥塞,为 所述链路,其中所述带宽预约指定具有较低优先级的标签交换路径的所述链路上的可用带宽量小于具有较高优先级的标签交换路径的所述链路上的可用带宽量。