SECURING MULTIPROTOCOL LABEL SWITCHING (MPLS) PAYLOADS

    公开(公告)号:US20240106744A1

    公开(公告)日:2024-03-28

    申请号:US18531947

    申请日:2023-12-07

    CPC classification number: H04L45/50 H04L45/66 H04L63/0464 H04L63/061 H04L69/22

    Abstract: In some implementations, an egress network device of a multiprotocol label switching (MPLS) network may exchange Internet key exchange (IKE) messages with an ingress network device of the MPLS network to establish a security association between the egress network device and the ingress network device. The egress network device may receive an MPLS packet that includes an MPLS header, a secure MPLS data header, and an MPLS payload. The egress network device may process the MPLS header to determine a label associated with a label-switched path (LSP) and a secure function indicator. The egress network device may decrypt, using a secure function identified based on the secure MPLS data header, the MPLS payload to generate a decrypted packet. The egress network device may transmit the decrypted packet towards a destination device.

    SECURING MULTIPROTOCOL LABEL SWITCHING (MPLS) PAYLOADS

    公开(公告)号:US20230370369A1

    公开(公告)日:2023-11-16

    申请号:US17663319

    申请日:2022-05-13

    CPC classification number: H04L45/50 H04L45/66 H04L63/0464 H04L63/061 H04L69/22

    Abstract: In some implementations, an ingress network device of a multiprotocol label switching (MPLS) network may receive a packet destined for a destination network device. The ingress network device may determine, based on the packet, a secure function to secure the packet and a label associated with a label-switched path (LSP) from the ingress network device to an egress network device of the MPLS network that is associated with the destination network device. The ingress network device may encrypt, using the secure function, the packet to generate an encrypted packet. The ingress network device may generate an MPLS packet comprising: an MPLS header that includes the label and a secure function indicator, a secure MPLS data header that includes information identifying the secure function, and an MPLS payload that includes the encrypted packet. The ingress network device may forward, based on the label, the MPLS packet.

Patent Agency Ranking