BGP Data-Plane Extensions for Inter-Router Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security management is inadequate in addressing the growing complexity of network attacks, such as viruses, worms, and denial of service attacks, particularly in a decentralized Internet where administrative domains lack coordinated mechanisms for inter-domain communication of threat signatures and Quality of Service (QoS) routing.

Innovation Solution

The implementation of a system that uses BGP Data-Plane extensions for inter-router communication, enabling fast-path filtering and QoS marking, allowing for the recognition and filtering of malicious patterns and QoS signatures across administrative domains through data-plane filtering modules and TCAMs, and facilitating the propagation of anomaly signatures and QoS levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If BGP Data-Plane extensions are implemented for inter-router communication, then coordinated defense mechanisms across domains are enabled, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidrouting protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extends BGP to serve multiple functions: traditional routing plus data-plane filtering for security (worm detection), QoS marking, and anomaly signature propagation. By making BGP multi-functional, the patent avoids creating separate protocols for each function, thereby reducing overall system complexity while improving security coordination across domains.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent nests security filtering functionality within the existing BGP protocol structure. Data-plane filtering rules, QoS markings, and anomaly signatures are all carried within BGP update messages, creating a nested architecture where security functions are embedded within the routing protocol rather than operating as separate systems.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Speed

If data-plane filtering modules and TCAMs are used for fast-path filtering, then attack filtering speed improves, but hardware requirements increase

Engineering Contradiction:
Improvepacket filtering speedVSAvoidhardware requirements
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent uses TCAMs to store filtering rules in advance before packet processing occurs. By pre-loading anomaly signatures and filtering criteria into hardware memory, the system achieves fast-path filtering without requiring complex real-time analysis during packet transmission, thereby improving speed while keeping hardware requirements manageable.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces software-based packet filtering with hardware-accelerated filtering using TCAMs and data-plane filtering modules. This substitution of mechanical/hardware systems for software processing enables significantly faster packet decision-making while distributing the hardware complexity across standard router components rather than requiring specialized expensive equipment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If inter-domain communication of threat signatures is enabled, then coordinated security response improves, but network traffic overhead increases

Engineering Contradiction:
Improvesecurity coordinationVSAvoidnetwork bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the essential security information (anomaly signatures, QoS markings, filtering rules) from detailed packet data and transmits these condensed representations via BGP updates. By taking out only the critical metadata rather than entire packet contents, the system achieves effective security coordination while minimizing network bandwidth consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses BGP update messages to carry multiple types of information simultaneously: routing data, security signatures, QoS markings, and filtering rules. By making the communication protocol multi-functional, the system reduces the number of separate communication channels needed, thereby decreasing overall network traffic overhead while maintaining comprehensive security coordination.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8964763B2Inter-router communication method and module
Publication Date: 2015.02.24 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8964763B2 patent drawing
  • US8964763B2 patent drawing
  • US8964763B2 patent drawing

AI summary

A system and method of inter-router communication is described. The system and method include a routing protocol communication, configured to be sent between a plurality of routers on a network, and having a data plane update packet sent with a route update packet. The data plane update packet includes routing attributes corresponding to information export protocol signatures. A signature recognition module may be located on at least one of the routers in the network, and can store and recognize data packet signature patterns located in at least a portion of a payload of the data plane update packet. A data plane filter module can also be located on at least one of the routers, and can handle data packets according to filtering rules for specific data packet signature patterns.