BGP Route Authorization with RPKI for Secure Destination Paths
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current BGP routing protocols lack mechanisms to ensure secure network paths for sensitive internet traffic, as they cannot verify the legitimacy and authenticity of BGP route advertisements, making them susceptible to tampering or hijacking.
Innovation Solution
Implementing a security extension to BGP, BGPSEC, and extending the Resource Public Key Infrastructure (RPKI) to provide Route Origin Authorizations (ROAs) with digital signatures, ensuring that network traffic is routed through trusted nodes by adhering to security requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If BGP routing protocol is used for network traffic routing, then routing information exchange is enabled, but security verification of route advertisements is lacking
Solution Approach 1:
The patent introduces RPKI (Resource Public Key Infrastructure) as an intermediary system that provides route origin authorizations and digital signatures. This mediator verifies the authenticity of BGP route advertisements by checking digital signatures against authorized route origin data, thereby resolving the contradiction by adding a verification layer without fundamentally changing the BGP routing mechanism.
Solution Approach 2:
The patent implements preliminary verification of route advertisements by checking digital signatures and route origin authorizations before accepting routing information. This preliminary action ensures that only authorized and authentic routes are processed, enhancing reliability while maintaining manageable complexity through pre-established verification protocols.
2Reliability
If security extension BGPSEC is implemented, then secure network path verification is achieved, but protocol complexity increases
Solution Approach 1:
The patent makes the security verification mechanism universal by implementing it at the route origin authorization level, which applies to all BGP route advertisements. This multi-functional approach allows the same verification infrastructure to secure various types of routing information without requiring separate security mechanisms for each routing scenario, thereby managing complexity while achieving comprehensive security.
Solution Approach 2:
The patent changes the parameter space of BGP by introducing digital signature verification and route origin authorization parameters. These new parameters enable security verification without fundamentally altering the core BGP routing logic, allowing security to be added through parameter extension rather than structural complexity.
3Object-affected harmful factors
If route origin authorization with digital signature is implemented, then unauthorized route manipulation is prevented, but system complexity increases
Solution Approach 1:
The patent extracts the security verification function from the core BGP routing process by separating route origin authorization into a distinct RPKI infrastructure. This extraction allows digital signature verification to be performed independently, preventing route hijacking and manipulation while containing system complexity to a dedicated verification subsystem rather than permeating the entire routing infrastructure.
Data Source
AI summary
Disclosed are systems, apparatuses, methods, and computer-readable media for secure network routing. A method includes: receiving, at a network node, an advertisement message for a network route including an IP address prefix; receiving, at the network node, a route origin authorization associated with the IP address prefix, the route origin authorization including a digital signature and a security requirement of a route to a destination that corresponds to the IP address prefix; determining, by the network node, one or more network nodes satisfies the security requirement to yield a determination; and determining, by the network node, to route network traffic to the IP address prefix based on the determination. In one example, the method can include, when the one or more network nodes satisfies the security requirement, advertising the route to the one or more network nodes that satisfies the security requirement.


