IGP Source Address Validation Using SPF-Based SAV Tables
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing source address validation (SAV) technologies, such as DSAV, rely on new protocols and reactive convergence, leading to complex deployments and improper packet handling due to asymmetric routing and manual configuration needs.
Innovation Solution
Utilizing existing Interior Gateway Protocols (IGPs) like OSPF and IS-IS, with additional SPF calculations, to generate SAV tables based on link state announcements, ensuring symmetrical or asymmetrical path validation without additional protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing SAV technologies like DSAV are used, then source address validation can be performed, but deployment complexity increases and asymmetric routing causes improper packet handling
Solution Approach 1:
The patent combines source address validation functionality with the existing IGP routing protocol infrastructure. By integrating SAV table generation into the standard SPF calculation process already performed by routing protocols like OSPF and IS-IS, the system achieves validation without adding separate complex validation protocols or infrastructure.
Solution Approach 2:
The patent makes the existing routing protocol infrastructure serve dual purposes: traditional packet forwarding and source address validation. The same link state announcements and SPF calculations used for routing are leveraged to generate SAV tables, eliminating the need for dedicated validation protocols.
2Reliability
If new protocols are introduced for SAV, then validation functionality is achieved, but deployment complexity and manual configuration requirements increase
Solution Approach 1:
The system performs self-service by automatically generating SAV tables through the existing SPF calculation process. Network devices autonomously compute validation tables using their standard routing protocol operations without requiring manual configuration or separate validation protocol deployments.
Solution Approach 2:
The patent performs preliminary action by pre-computing SAV tables using the same link state information and SPF calculations already performed for routing. This preliminary computation of validation data during the normal routing setup phase eliminates the need for separate configuration steps.
3Reliability
If reactive convergence is used in SAV, then validation updates can be performed, but packet handling becomes improper due to asymmetric routing
Solution Approach 1:
The patent segments the validation information into specific table entries within the SAV table, separating validation data from routing data. This segmentation allows independent optimization of validation lookups without affecting routing operations, improving packet handling efficiency.
4Reliability
If manual configuration is required for SAV, then validation can be implemented, but deployment complexity and time increase
Solution Approach 1:
The system eliminates manual configuration by performing self-service through automatic SAV table generation. Network devices autonomously compute validation tables using their standard routing protocol operations without requiring manual configuration or separate validation protocol deployments.
Data Source
AI summary
A method implemented by a network node in an interior gateway protocol (IGP) domain. The method includes receiving a link state announcement from one or more other network nodes in the IGP domain, performing shortest path first (SPF) based on the link state announcement received from the one or more other network nodes to determine a path through the domain, building a forwarding information base (FIB) table based on the SPF, determining that the path through the domain is symmetrical, and duplicating the FIB to generate a source address validation (SAV) table.


