Cloud Exchange Fabric Route Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems, such as firewalls, fail to detect and mitigate security breaches through route advertisements and internal traffic origination, particularly for outgoing packets, which are vulnerable to misappropriation by fraudsters.

Innovation Solution

A distributed routing engine is implemented within the cloud exchange fabric to authenticate routes and packets, verifying the legitimacy of routes by analyzing origin information and comparing it with blacklists or whitelists, thereby preventing illegitimate routes from being exchanged and ensuring secure outgoing packet transmissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewalls are used to evaluate incoming data traffic at customer edges, then incoming traffic security is improved, but outgoing packet security and route evaluation capability are worsened

Engineering Contradiction:
Improveincoming traffic securityVSAvoidroute evaluation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

A cloud exchange fabric is introduced as an intermediary between customers and the network core. This fabric includes routing engines that perform route authentication and packet flow evaluation for both incoming and outgoing traffic. The fabric acts as a mediator that enables route evaluation capabilities without requiring firewalls at customer edges, thus resolving the contradiction between incoming traffic security and route evaluation capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security evaluation function is moved from the traditional perimeter (customer edge) to a new dimension - the cloud exchange fabric layer. This dimensional shift allows the system to evaluate both incoming and outgoing packets centrally, providing comprehensive security without limiting customer edge firewall functionality.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If route authentication is performed on all exchanged routes, then security against illegitimate routes is improved, but processing time and system complexity are worsened

Engineering Contradiction:
Improveroute legitimacy verificationVSAvoidrouting engine processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Route authentication is performed in advance before routes are installed in routing tables. The routing engine evaluates origin information, checks against blacklists and whitelists, and validates AS paths before committing routes. This preliminary action prevents illegitimate routes from entering the system, reducing the need for complex real-time verification during packet forwarding.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex manual route verification processes with automated routing engines that use predefined authentication mechanisms. These engines automatically validate routes against stored criteria, blacklists, and whitelists, substituting mechanical verification with automated electronic validation that reduces processing complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If distributed routing engines are deployed across the cloud exchange fabric, then route authentication capability is improved, but network infrastructure complexity is worsened

Engineering Contradiction:
Improveroute authentication capabilityVSAvoiddistributed system infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The routing engine functionality is segmented and distributed across multiple nodes in the cloud exchange fabric. Each routing engine operates independently to authenticate routes within its domain, but they work collectively to provide comprehensive route validation. This segmentation allows the system to scale route authentication capability without proportionally increasing central control complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12120128B1Route and packet flow evaluation on a cloud exchange
Publication Date: 2024.10.15 EQUINIX INC
  • US12120128B1 patent drawing
  • US12120128B1 patent drawing
  • US12120128B1 patent drawing

AI summary

In general, techniques are described for distributed route and packet flow evaluation within a cloud exchange fabric. In some examples, a routing engine is operative to: establish sessions between a first network and a second network to exchange message data identifying destinations in the second network; and verify routing information comprising routes from endpoints in the first network to the destinations based upon the message data, including, for each route of the routes: evaluating a source or a destination for indicia of illegitimate origination, and in response to detecting an illegitimate endpoint at the at least one of a source or a destination based upon identifying one or more of the indicia of illegitimate origination, dropping a corresponding route from the routing information.