Abstract:
In one embodiment, a method includes receiving an OSPF hello message including an attestation token from a second network apparatus, determining that the attestation token is valid for the second network apparatus at a current time, establishing an adjacency to the second network apparatus in response to the determination, computing, based at least on the attestation token, a trust level for a first link from the first network apparatus to the second network apparatus and a trust level for first prefixes associated with the first link, and sending an LSA comprising the trust level for the first link and the trust level for the first prefixes to neighboring network apparatuses, where the trust level for the first link and the trust level for the prefixes are used by the network apparatuses in the network to compute a routing table of the network.
Abstract:
In one embodiment, a method includes receiving an ISIS hello message including an attestation token from a second network apparatus, determining that the attestation token is valid for the second network apparatus at a current time, establishing an adjacency to the second network apparatus in response to the determination, computing, based at least on the attestation token, a trust level for a first link from the first network apparatus to the second network apparatus and a trust level for first prefixes associated with the first link, and sending an LSP comprising the trust level for the first link and the trust level for the first prefixes to neighboring network apparatuses, where the trust level for the first link and the trust level for the prefixes are used by the network apparatuses in the network to compute a routing table of the network.
Abstract:
In one embodiment, a method includes receiving an OSPF hello message including an attestation token from a second network apparatus, determining that the attestation token is valid for the second network apparatus at a current time, establishing an adjacency to the second network apparatus in response to the determination, computing, based at least on the attestation token, a trust level for a first link from the first network apparatus to the second network apparatus and a trust level for first prefixes associated with the first link, and sending an LSA comprising the trust level for the first link and the trust level for the first prefixes to neighboring network apparatuses, where the trust level for the first link and the trust level for the prefixes are used by the network apparatuses in the network to compute a routing table of the network.
Abstract:
In one embodiment, a method includes receiving an ISIS hello message including an attestation token from a second network apparatus, determining that the attestation token is valid for the second network apparatus at a current time, establishing an adjacency to the second network apparatus in response to the determination, computing, based at least on the attestation token, a trust level for a first link from the first network apparatus to the second network apparatus and a trust level for first prefixes associated with the first link, and sending an LSP comprising the trust level for the first link and the trust level for the first prefixes to neighboring network apparatuses, where the trust level for the first link and the trust level for the prefixes are used by the network apparatuses in the network to compute a routing table of the network.
Abstract:
A link state information correction scheme is implemented by the present disclosure. In one embodiment, the correction scheme is implemented by a reload logic module that cooperates with link state protocol logic configured on a reload routing element (or routing element that has reloaded or hard restarted). The reload logic module is configured to receive a database descriptor message at a reload routing element, where the database descriptor message is received from a neighbor routing element during an adjacency formation. The reload logic module is also configured to determine whether the database descriptor message identifies a stale version of a link state advertisement (LSA), where the LSA is self-originated by the reload routing element. The reload logic module is also configured to generate a new version of the LSA during the adjacency formation.
Abstract:
A link state information correction scheme is implemented by the present disclosure. In one embodiment, the correction scheme is implemented by a reload logic module that cooperates with link state protocol logic configured on a reload routing element (or routing element that has reloaded or hard restarted). The reload logic module is configured to receive a database descriptor message at a reload routing element, where the database descriptor message is received from a neighbor routing element during an adjacency formation. The reload logic module is also configured to determine whether the database descriptor message identifies a stale version of a link state advertisement (LSA), where the LSA is self-originated by the reload routing element. The reload logic module is also configured to generate a new version of the LSA during the adjacency formation.