BGP AS Path Verification for Inter-Domain Traffic Redirection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Inter-domain traffic redirection in BGP is often transparent, leading to issues such as traffic black holes and loops due to unknown AS paths, which are not detected by routing protocols.
Innovation Solution
A method and apparatus for verifying the validity of inter-domain redirection paths by checking the AS sequence against a verification strategy, ensuring the path is valid before forwarding traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If inter-domain traffic redirection is configured on ASBR, then traffic can be forwarded according to customized rules, but the AS path becomes unknown and causes traffic black holes or loops
Solution Approach 1:
The patent implements a feedback mechanism where the AS path information is propagated back from the redirection point to the source AS through BGP update messages. This allows the source AS to learn the actual AS path that will be taken by redirected traffic, enabling validation and preventing black holes or loops while maintaining redirection flexibility
Solution Approach 2:
The patent introduces an intermediary mechanism using BGP update messages as carriers to transmit AS path information between ASBRs and source ASes. This intermediary allows the routing protocol to become aware of redirection paths without directly controlling the data plane forwarding, resolving the transparency issue
2Ease of operation
If traffic redirection is transparent to routing protocol, then routing protocol does not interfere with customized forwarding rules, but the routing protocol cannot detect invalid paths
Solution Approach 1:
The patent performs preliminary action by propagating AS path information through BGP updates before traffic is actually redirected. This allows the source AS to pre-validate the AS path sequence and detect potential black holes or loops before they occur, while keeping the redirection configuration simple at the data plane
3Reliability
If AS path validation is performed, then traffic black holes and loops are prevented, but additional verification operations are required
Solution Approach 1:
The patent implements self-service by having each ASBR automatically generate and propagate its own AS path information through BGP update messages. The verification logic is distributed across multiple ASes rather than centralized, reducing the complexity burden on individual devices while ensuring path validity
Data Source
AI summary
This application discloses a path validity verification method, a redirection path obtaining method, and an apparatus. A first network device obtains a first AS path obtained through inter-domain traffic redirection, and verifies validity of the first AS path according to a verification strategy, to obtain a verification result. The verification strategy is used to verify validity of an AS sequence included in the first AS path. To be specific, for an AS path obtained through inter-domain traffic redirection, the first network device may verify validity of an AS sequence included in the AS path, to ensure that the AS path obtained through redirection is a valid path, and ensure normal transport of inter-domain traffic.


