CONTEXT SPECIFIC KEYS
A method for operating a network is provided. The method comprises segmenting the network into a plurality of virtual private networks, wherein each virtual private network runs on an underlying physical network; and wherein each virtual private network represents a particular context; and configuring at least some nodes within the network to send and receive traffic based on context.
1 . A method for operating a network, comprising:
segmenting the network into a plurality of virtual private networks, wherein each virtual private network runs on an underlying physical network; and wherein each virtual private network represents a particular context; and
configuring at least some nodes within the network to send and receive traffic based on context.
2 . The method of claim 1 , wherein each context is selected from the group consisting of an application, a department, and a specific topology.
3 . The method of claim 1 , wherein said network is operated based on a control plane, and a forwarding plane.
4 . The method of claim 3 , wherein configuration of a context is based on policy distributed by controller for the control plane to individual endpoints in the network.
5 . The method of claim 4 , wherein each endpoint comprises multiple contexts.
6 . The method of claim 5 , wherein each note is configured to generate encryption keys for each context.
7 . The method of claim 6 , when said encryption keys are distributed to other nodes in the network using the control plane.
8 . The method of claim 1 , wherein configuring said nodes, comprises configuring said nodes to perform an egress forwarding operation wherein only a packet for which there is a destination IP address associated with a source context identified in said packet is forwarded
9 . The method of claim 8 , wherein configuring said nodes, comprises configuring said nodes to perform an ingress forwarding operation wherein only a packet for which there is a destination IP address associated with a destination context identified in said packet is forwarded.
10 . The method of claim 9 , wherein said source context, and destination context stored locally within each edge node in the network.