Flexible Algorithm Security Level Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network protection methods, such as link encryption, are ineffective in preventing the leakage of sensitive information when network nodes become compromised, as they do not adequately exclude potentially compromised elements from data transmission routes.

Innovation Solution

The implementation of flexible algorithm technology within Interior Gateway Protocol (IGP) that advertises a security level using sub-TLVs, allowing network elements to determine and exclude compromised nodes, links, or prefixes from data transmission routes, ensuring that only secure elements with a security level meeting or exceeding a threshold are used.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional link encryption is used to protect network data, then data transmission security is improved, but the system becomes vulnerable when network nodes are compromised since encryption keys may be exposed

Engineering Contradiction:
Improvedata transmission securityVSAvoidvulnerability to node compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the security assessment function from traditional link encryption and places it at the routing decision level. By using FADs with security-level sub-TLVs, the system separately evaluates and selects secure routing paths independent of encryption mechanisms, allowing exclusion of compromised nodes without affecting encryption operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces FADs (Flexible Algorithm Definitions) with security-level sub-TLVs as an intermediary layer between routing protocols and security mechanisms. This intermediary enables network elements to advertise their security levels and allows routing decisions to incorporate security assessments, creating a mediator that coordinates routing and security functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network elements advertise security levels using FAD sub-TLVs, then the ability to exclude compromised elements is improved, but routing protocol complexity increases

Engineering Contradiction:
Improveexclusion of compromised elementsVSAvoidrouting protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the FAD framework universal by allowing it to carry multiple types of information through the security-level sub-TLV mechanism. The same FAD structure used for routing also carries security level advertisements, enabling multi-functionality that reduces the need for separate protocol extensions and minimizes overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameter space of existing routing protocols by introducing security-level sub-TLVs into FADs. Instead of creating entirely new protocols, the system modifies existing routing message parameters to include security level information, allowing gradual adoption and reducing the complexity impact of the enhancement.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security-level sub-TLVs are added to FADs, then network security assessment capability is improved, but message size and processing overhead increase

Engineering Contradiction:
Improvesecurity assessment capabilityVSAvoidmessage size
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by making security level information optional and selectively advertised only by network elements that support the feature. Not all FADs need to carry security-level sub-TLVs, only those from secure network elements, allowing the enhancement to be applied locally where needed without forcing increased message sizes across the entire network.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12095651B2Systems and methods for determining secure network elements using flexible algorithm technology
Publication Date: 2024.09.17 CISCO TECHNOLOGY INC
  • US12095651B2 patent drawing
  • US12095651B2 patent drawing
  • US12095651B2 patent drawing

AI summary

In one embodiment, an apparatus includes one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors. The one or more computer-readable non-transitory storage media include instructions that, when executed by the one or more processors, cause the apparatus to perform operations including receiving a first type-length-value (TLV) associated with a winning flexible algorithm definition (FAD) from a first element of a network. The operations also include determining a security level for the winning FAD based on the TLV. The operations further include determining a data transmission route through a plurality of elements of the network based on the security level for the winning FAD.