IP Library › Granted Patent US 12,381,718
Granted Patent B2
US 12,381,718 · App. 18/348,965 · Granted Aug 5, 2025

Secure EVPN with MKA over BGP

Inventors: Ashish Ranjan Panda (Bengaluru, IN); Pix Xu (Beijing, CN); Xiangbo Wang (Beijing, CN); Parul Seth (Delhi, IN)
Assignee: Cisco Technology, Inc.
H04L9/0825H04L9/3242H04L12/4641H04L45/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,381,718
App. No.
18/348,965
Granted
Aug 5, 2025
Kind
B2
Abstract

Techniques described herein provide procedures for reducing MACsec Key Agreement (MKA)-related traffic and improving resource allocation for MKA protocol through an EVPN environment. Techniques include leveraging Border Gateway Protocol (BGP) signaling for MKA between Provider Edge (PE) routers instead of between Customer Edge (CE) routers, which mitigates both hardware restrictions and scalability challenges with a new Xaas enablement. A new BGP-EVPN route type is defined that can communicate a set of MKA information along with an address destination associated with a provider edge device to establish a BGP MKA session and enable MACsec encryption/decryption at the provider edge device.

Claims (53)

1. A method, comprising:

sending, by a first provider edge device of a plurality of provider edge devices of an Ethernet Virtual Private Network (EVPN) instance, a Border Gateway Protocol (BGP) MACsec Key Agreement (MKA) discovery message to one or more remaining provider edge devices of the plurality of provider edge devices;

the BGP MKA discovery message including MKA information;

advertising, by the first provider edge device and using the MKA information, a Security Association Key to the one or more remaining provider edge devices of the plurality of provider edge devices; and

encrypting or decrypting, at the first provider edge device and using the Security Association Key, a content message received at the first provider edge device.

2. The method of claim 1 , further comprising:

establishing a BGP EVPN session between the first provider edge device and the one or more remaining provider edge devices; and

sending, by the first provider edge device and through the BGP EVPN session, the MKA information to the one or more remaining provider edge devices.

3. The method of claim 1 , the BGP MKA discovery message being a BGP prefix advertisement descriptive of a BGP-EVPN route including the MKA information and an address destination associated with the first provider edge device.

4. The method of claim 1 , where receipt of the BGP MKA discovery message including the MKA information configures the one or more remaining provider edge devices to perform one or more functionalities associated with a MACsec encryption protocol.

5. The method of claim 1 , further comprising:

receiving, at the first provider edge device and from a customer edge device in communication with the first provider edge device, the content message for communication to the one or more remaining provider edge devices of the plurality of provider edge devices;

encrypting, at the first provider edge device, the content message using the Security Association Key; and

communicating, at the first provider edge device, the content message to the one or more remaining provider edge devices, the content message having been encrypted using the Security Association Key.

6. The method of claim 1 , further comprising:

receiving, at the first provider edge device and from a remaining provider edge device of the plurality of provider edge devices, the content message for communication to a customer edge device in communication with the first provider edge device;

decrypting, at the first provider edge device, the content message using the Security Association Key; and

communicating, at the first provider edge device, the content message to the customer edge device, the content message having been decrypted using the Security Association Key.

7. The method of claim 1 , further comprising:

sending, at the first provider edge device, one or more BGP maintenance messages through a BGP EVPN session, where the one or more BGP maintenance messages maintain an “active” MKA session status associated with the first provider edge device.

8. The method of claim 7 , further comprising:

assigning an “inactive” MKA session status to the first provider edge device of the plurality of provider edge devices following the withdrawal of the first provider edge device from the BGP EVPN session.

9. A system, comprising:

a first provider edge device of a plurality of provider edge devices of an Ethernet Virtual Private Network (EVPN) instance, comprising:

a processor in communication with a memory and including instructions executable by the processor to:

send a Border Gateway Protocol (BGP) MACsec Key Agreement (MKA) discovery message to one or more remaining provider edge devices of the plurality of provider edge devices, the BGP MKA discovery message including MKA information;

advertise, using the MKA information, a Security Association Key to the one or more remaining provider edge devices of the plurality of provider edge devices; and

encrypt or decrypt, using the Security Association Key, a content message received at the first provider edge device.

10. The system of claim 9 , the memory further comprising instructions executable by the processor to:

establish a BGP MKA session between the first provider edge device and the one or more remaining provider edge devices; and

send, by the first provider edge device and through the BGP EVPN session, the MKA information to the one or more remaining provider edge devices.

11. The system of claim 9 , the BGP MKA discovery message being a BGP prefix advertisement descriptive of a BGP-EVPN route including the MKA information and an address destination associated with the first provider edge device.

12. The system of claim 9 , where receipt of the BGP MKA discovery message including the MKA information configures the one or more remaining provider edge devices to perform one or more functionalities associated with a MACsec encryption protocol.

13. The system of claim 9 , the memory further comprising instructions executable by the processor to:

receive, from a customer edge device in communication with the first provider edge device, the content message for communication to the one or more remaining provider edge devices of the plurality of provider edge devices;

encrypt the content message using the Security Association Key; and

communicate the content message to the one or more remaining provider edge devices, the content message having been encrypted using the Security Association Key.

14. The system of claim 9 , the memory further comprising instructions executable by the processor to:

receive, from a remaining provider edge device of the plurality of provider edge devices, the content message for communication to a customer edge device in communication with the first provider edge device;

decrypt the content message using the Security Association Key; and

communicate the content message to the customer edge device, the content message having been decrypted using the Security Association Key.

15. The system of claim 9 , the memory further comprising instructions executable by the processor to:

send one or more BGP maintenance messages through a BGP EVPN session, where the one or more BGP maintenance messages maintain an “active” MKA session status associated with the first provider edge device.

16. The system of claim 9 , the memory further comprising instructions executable by the processor to:

assign an “inactive” MKA session status to the first provider edge device of the plurality of provider edge devices upon withdrawal of the first provider edge device from a BGP EVPN session.

17. One or more non-transitory computer-readable media comprising computer-readable instructions, executable by one or more processors of a first provider edge device to:

send a Border Gateway Protocol (BGP) MACsec Key Agreement (MKA) discovery message to one or more remaining provider edge devices of a plurality of provider edge devices, the BGP MKA discovery message including MKA information;

advertise, using the MKA information, a Security Association Key to the one or more remaining provider edge devices of the plurality of provider edge devices; and

encrypt or decrypt, using the Security Association Key, a content message received at the first provider edge device.

18. The one or more non-transitory computer-readable media of claim 17 , the BGP MKA discovery message being a BGP prefix advertisement descriptive of a BGP-EVPN route including the MKA information and an address destination associated with the first provider edge device.

19. The one or more non-transitory computer-readable media of claim 17 , where receipt of the BGP MKA discovery message including the MKA information configures the one or more remaining provider edge devices to perform one or more functionalities associated with a MACsec encryption protocol.

20. The one or more non-transitory computer-readable media of claim 17 , further including computer-readable instructions executable by the one or more processors of the first provider edge device to:

send one or more BGP maintenance messages through a BGP EVPN session, where the one or more BGP maintenance messages maintain an “active” MKA session status associated with the first provider edge device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2023
From: PANDA, ASHISH RANJAN; XU, PIX; WANG, XIANGBO; SETH, PARUL
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064189/0105 →
Continuity (1)
Related Publication 20250015976A1 · Jan 9, 2025
References Cited (47)
US 9900250B2 · Dong · 2018 [cited by examiner]
US 9985867B2 · Dong · 2018 [cited by examiner]
US 10212075B1 · Lakshmikanthan · 2019 [cited by examiner]
US 10250552B1 · Sajassi · 2019 [cited by examiner]
US 10757017B2 · Kanjariya · 2020 [cited by examiner]
US 11570179B2 · Gordon · 2023 [cited by examiner]
US 11601278B2 · Gordon · 2023 [cited by examiner]
US 20100208741A1 · Vasseur · 2010 [cited by examiner]
US 20150019524A1 · Fuhring · 2015 [cited by examiner]
US 20160134526A1 · Maino · 2016 [cited by examiner]
US 20180109450A1 · Filsfils · 2018 [cited by examiner]
US 20180248803A1 · Nagarajan · 2018 [cited by examiner]
US 20180375763A1 · Brissette · 2018 [cited by examiner]
US 20190190812A1 · Verma · 2019 [cited by examiner]
US 20190288984A1 · Hajduczenia · 2019 [cited by examiner]
US 20200067812A1 · Malhotra · 2020 [cited by examiner]
US 20200177503A1 · Hooda · 2020 [cited by examiner]
US 20200220843A1 · Hill · 2020 [cited by examiner]
US 20200280514A1 · Zhang · 2020 [cited by examiner]
US 20200358750A1 · Sharma · 2020 [cited by examiner]
US 20200389469A1 · Litichever · 2020 [cited by examiner]
US 20210075829A1 · Wei · 2021 [cited by examiner]
US 20210168125A1 · Vemulpali · 2021 [cited by examiner]
US 20210218598A1 · Ganapathy · 2021 [cited by examiner]
US 20210226816A1 · Holness · 2021 [cited by examiner]
US 20210297416A1 · Gavraskar · 2021 [cited by examiner]
US 20220052964A1 · Bhardwaj · 2022 [cited by examiner]
US 20220131721A1 · Boutros · 2022 [cited by examiner]
US 20220217075A1 · Xie · 2022 [cited by examiner]
US 20220232009A1 · Gordon · 2022 [cited by examiner]
US 20220353143A1 · Hill · 2022 [cited by examiner]
US 20220360605A1 · Baheri · 2022 [cited by examiner]
US 20220407798A1 · Holness · 2022 [cited by examiner]
US 20230008699A1 · Hill · 2023 [cited by examiner]
US 20230246950A1 · Kaimal · 2023 [cited by examiner]
US 20230261963A1 · Gupta · 2023 [cited by examiner]
US 20230412526A1 · Nallamothu · 2023 [cited by examiner]
US 20240031908A1 · Grewal · 2024 [cited by examiner]
US 20240039895A1 · Chen · 2024 [cited by examiner]
US 20240195648A1 · Mishra · 2024 [cited by examiner]
US 20240314066A1 · Mishra · 2024 [cited by examiner]
US 20240322999A1 · Bidgoli · 2024 [cited by examiner]
US 20240348553A1 · Mishra · 2024 [cited by examiner]
Stoianov, Nikolai, et al. “Integrated security infrastructures for law enforcement agencies.” Multimedia Tools and Applications 74 (2015): 4453-4468. [cited by examiner]
Mutlag, Ammar Awad, et al. “Multi-agent systems in fog-cloud computing for critical healthcare task management model (CHTM) used for ECG monitoring.” Sensors 21.20 (2021): 6923. [cited by examiner]
Birge-Lee, Henry, Maria Apostolaki, and Jennifer Rexford. “It takes two to tango: cooperative edge-to-edge routing.” Proceedings of the 21st ACM Workshop on Hot Topics in Networks. 2022. [cited by examiner]
Cisco: “Configuring Secure VXLAN EVPN Multi-Site Using Cloudsec”, Apr. 19, 2023, pp. 1-18. [cited by applicant]