BGP Route Verification Using Multi-Relationship Path Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for security verification on Border Gateway Protocol (BGP) routing information fail to provide accurate results, particularly in identifying path hijacking and path leakage attacks.
Innovation Solution
Enhance security verification by incorporating additional business relationships, such as customer to provider (C2P), peer to peer (P2P), sibling, partial transit, and hybrid relationships, along with topological and routing transmission path information, to improve the accuracy of verification results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional security verification methods are used on BGP routing information, then the verification process is simple, but the accuracy of the verification result is low
Solution Approach 1:
The patent applies preliminary action by pre-establishing business relationship information and topological relationship information before verification. The server stores C2P relationships, P2P relationships, sibling relationships, and topological data in advance, so that when BGP routing information needs verification, the network device can directly query these pre-prepared data structures to accurately determine whether the routing information is legitimate, thereby improving verification accuracy without increasing real-time complexity
Solution Approach 2:
The patent introduces a server as an intermediary between network devices and BGP routing information verification. The server acts as a mediator that stores and manages business relationship information and topological relationship information, providing these data to network devices for verification. This intermediary approach allows complex verification logic to be centralized in the server while keeping network devices relatively simple
2Reliability
If multiple business relationships are considered in security verification, then the accuracy of identifying BGP route attacks is improved, but the complexity of the verification process increases
Solution Approach 1:
The patent applies segmentation by dividing the verification process into distinct relationship types: C2P (customer-to-provider) relationships, P2P (peer-to-peer) relationships, sibling relationships, and topological relationships. Each relationship type is stored and verified separately, allowing the system to comprehensively check multiple business relationships without creating a monolithic complex verification process. This segmented approach improves attack identification accuracy while managing complexity through modular organization
Solution Approach 2:
The patent creates a universal verification framework that handles multiple types of business relationships (C2P, P2P, sibling, topological) through a single integrated system. The server and network device work together to verify routing information against all these relationship types uniformly, making the verification process multi-functional without proportionally increasing complexity. This universal approach improves reliability by covering diverse attack scenarios
Data Source
AI summary
Embodiments of this application disclose an information processing method. A network device may receive security verification information sent by a server, where the security verification information is used to perform security verification on BGP routing information, the security verification information includes a first business relationship and a second business relationship that correspond to a first network domain, and the first business relationship is C2P. After receiving the security verification information, the network device may store the security verification information, to subsequently perform security verification on the BGP routing information based on the security verification information. When performing security verification on the BGP routing information, in addition to performing security verification based on the first business relationship corresponding to the first network domain in the conventional technology, the network device may further perform security verification based on the second business relationship corresponding to the first network domain.


