Cloud Exchange Fabric Route Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems, such as firewalls, fail to detect and mitigate security breaches through route advertisements and internal traffic origination, particularly for outgoing packets, which are vulnerable to misappropriation by fraudsters.
Innovation Solution
A distributed routing engine is implemented within the cloud exchange fabric to authenticate routes and packets, verifying the legitimacy of routes by analyzing origin information and comparing it with blacklists or whitelists, thereby preventing illegitimate routes from being exchanged and ensuring secure outgoing packet transmissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If firewalls are used to evaluate incoming data traffic at customer edges, then incoming traffic security is improved, but outgoing packet security and route evaluation capability are worsened
Solution Approach 1:
A cloud exchange fabric is introduced as an intermediary between customers and the network core. This fabric includes routing engines that perform route authentication and packet flow evaluation for both incoming and outgoing traffic. The fabric acts as a mediator that enables route evaluation capabilities without requiring firewalls at customer edges, thus resolving the contradiction between incoming traffic security and route evaluation capability.
Solution Approach 2:
The security evaluation function is moved from the traditional perimeter (customer edge) to a new dimension - the cloud exchange fabric layer. This dimensional shift allows the system to evaluate both incoming and outgoing packets centrally, providing comprehensive security without limiting customer edge firewall functionality.
2Reliability
If route authentication is performed on all exchanged routes, then security against illegitimate routes is improved, but processing time and system complexity are worsened
Solution Approach 1:
Route authentication is performed in advance before routes are installed in routing tables. The routing engine evaluates origin information, checks against blacklists and whitelists, and validates AS paths before committing routes. This preliminary action prevents illegitimate routes from entering the system, reducing the need for complex real-time verification during packet forwarding.
Solution Approach 2:
The patent replaces complex manual route verification processes with automated routing engines that use predefined authentication mechanisms. These engines automatically validate routes against stored criteria, blacklists, and whitelists, substituting mechanical verification with automated electronic validation that reduces processing complexity.
3Reliability
If distributed routing engines are deployed across the cloud exchange fabric, then route authentication capability is improved, but network infrastructure complexity is worsened
Solution Approach 1:
The routing engine functionality is segmented and distributed across multiple nodes in the cloud exchange fabric. Each routing engine operates independently to authenticate routes within its domain, but they work collectively to provide comprehensive route validation. This segmentation allows the system to scale route authentication capability without proportionally increasing central control complexity.
Data Source
AI summary
In general, techniques are described for distributed route and packet flow evaluation within a cloud exchange fabric. In some examples, a routing engine is operative to: establish sessions between a first network and a second network to exchange message data identifying destinations in the second network; and verify routing information comprising routes from endpoints in the first network to the destinations based upon the message data, including, for each route of the routes: evaluating a source or a destination for indicia of illegitimate origination, and in response to detecting an illegitimate endpoint at the at least one of a source or a destination based upon identifying one or more of the indicia of illegitimate origination, dropping a corresponding route from the routing information.


