ANYsec

Nokia ANYsec uses the IEEE 802.1AE (MACsec) standard in its encryption engine to encrypt MPLS payloads, while leaving the MPLS labels in clear text and unauthenticated. After the MPLS payload is encrypted, the MPLS packet is switched through an MPLS network and eventually is decrypted using the decryption engine at the terminating PE. Having the MPLS labels in clear text and unauthenticated allows any LSR router to switch the ANYsec packets from the iLER ANYsec PE to the eLER ANYsec PE. Any LSR router, including third-party routers, can manipulate the MPLS header. This includes performing label actions such as label swap, pop, and push. The following figure shows the ANYsec MPLS encryption and decryption process.

Figure 1. ANYsec MPLS encryption and decryption