Applying Attestation Tokens to Multicast Routing Protocols
Abstract
In one embodiment, method includes receiving, by a first network apparatus, a first multicast message from a second network apparatus. The first multicast message includes attestation-capability information associated with the second network apparatus and an attestation token. The attestation token is for proving that the second network apparatus is in a known safe state. The method also includes determining, by the first network apparatus, that the attestation-capability information satisfies a pre-determined attestation capability requirement and determining, by the first network apparatus, that the attestation token is valid for the second network apparatus at a current time. The method further includes establishing, by the first network apparatus, an adjacency to the second network apparatus.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A first network apparatus, comprising:
one or more processors; and one or more computer-readable non-transitory storage media coupled to the one or more processors and comprising instructions that, when executed by the one or more processors, cause the first network apparatus to perform operations comprising:
receiving, from a second network apparatus, a multicast message comprising attestation information associated with the second network apparatus;
determining that the attestation information fails to satisfy one or more pre-determined attestation requirements; and
processing the multicast message based on a local policy.
22 . The first network apparatus of claim 21 , wherein the first multicast message is one of the following:
a Protocol-Independent Multicast (PIM) hello message; or a Label Distribution Protocol (LDP) message.
23 . The first network apparatus of claim 21 , the attestation information comprising attestation-capability information associated with the second network apparatus, the operations further comprising determining that the attestation-capability information fails to satisfy a pre-determined attestation-capability requirement.
24 . The first network apparatus of claim 21 , the attestation information comprising security level information associated with the second network apparatus, the operations further comprising determining that a security level associated with the second network apparatus fails to satisfy a pre-determined security level threshold.
25 . The first network apparatus of claim 21 , the attestation information comprising an attestation token, wherein the attestation token is for proving that the second network apparatus is in a known safe state, the operations further comprising determining that the attestation token is invalid for the second network apparatus at a current time.
26 . The first network apparatus of claim 21 , wherein the local policy instructs the first network apparatus to drop the multicast message.
27 . The first network apparatus of claim 21 , wherein the local policy instructs the first network apparatus to set a metric of one or more links associated with the second network element to a maximum value.
28 . A method, comprising:
receiving, by a first network apparatus and from a second network apparatus, a multicast message comprising attestation information associated with the second network apparatus; determining, by the first network apparatus, that the attestation information fails to satisfy one or more pre-determined attestation requirements; and processing, by the first network apparatus, the multicast message based on a local policy.
29 . The method of claim 28 , wherein the first multicast message is one of the following:
a Protocol-Independent Multicast (PIM) hello message; or a Label Distribution Protocol (LDP) message.
30 . The method of claim 28 , the attestation information comprising attestation-capability information associated with the second network apparatus, further comprising:
determining that the attestation-capability information fails to satisfy a pre-determined attestation-capability requirement.
31 . The method of claim 28 , the attestation information comprising security level information associated with the second network apparatus, further comprising:
determining that a security level associated with the second network apparatus fails to satisfy a pre-determined security level threshold.
32 . The method of claim 28 , the attestation information comprising an attestation token, wherein the attestation token is for proving that the second network apparatus is in a known safe state, further comprising:
determining that the attestation token is invalid for the second network apparatus at a current time.
33 . The method of claim 28 , wherein the local policy instructs the first network apparatus to drop the multicast message.
34 . The method of claim 28 , wherein the local policy instructs the first network apparatus to set a metric of one or more links associated with the second network element to a maximum value.
35 . One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:
receiving, by a first network apparatus and from a second network apparatus, a multicast message comprising attestation information associated with the second network apparatus; determining that the attestation information fails to satisfy one or more pre-determined attestation requirements; and processing the multicast message based on a local policy.
36 . The one or more computer-readable non-transitory storage media of claim 35 , wherein the first multicast message is one of the following:
a Protocol-Independent Multicast (PIM) hello message; or a Label Distribution Protocol (LDP) message.
37 . The one or more computer-readable non-transitory storage media of claim 35 , the attestation information comprising attestation-capability information associated with the second network apparatus, the operations further comprising determining that the attestation-capability information fails to satisfy a pre-determined attestation-capability requirement.
38 . The one or more computer-readable non-transitory storage media of claim 35 , the attestation information comprising security level information associated with the second network apparatus, the operations further comprising determining that a security level associated with the second network apparatus fails to satisfy a pre-determined security level threshold.
39 . The one or more computer-readable non-transitory storage media of claim 35 , the attestation information comprising an attestation token, wherein the attestation token is for proving that the second network apparatus is in a known safe state, the operations further comprising determining that the attestation token is invalid for the second network apparatus at a current time.
40 . The one or more computer-readable non-transitory storage media of claim 35 , wherein the local policy instructs the first network apparatus to drop the multicast message.Join the waitlist — get patent alerts
Track US2023163968A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.