IGP Source Address Validation Using SPF-Based SAV Tables

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing source address validation (SAV) technologies, such as DSAV, rely on new protocols and reactive convergence, leading to complex deployments and improper packet handling due to asymmetric routing and manual configuration needs.

Innovation Solution

Utilizing existing Interior Gateway Protocols (IGPs) like OSPF and IS-IS, with additional SPF calculations, to generate SAV tables based on link state announcements, ensuring symmetrical or asymmetrical path validation without additional protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing SAV technologies like DSAV are used, then source address validation can be performed, but deployment complexity increases and asymmetric routing causes improper packet handling

Engineering Contradiction:
Improvesource address validation accuracyVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines source address validation functionality with the existing IGP routing protocol infrastructure. By integrating SAV table generation into the standard SPF calculation process already performed by routing protocols like OSPF and IS-IS, the system achieves validation without adding separate complex validation protocols or infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the existing routing protocol infrastructure serve dual purposes: traditional packet forwarding and source address validation. The same link state announcements and SPF calculations used for routing are leveraged to generate SAV tables, eliminating the need for dedicated validation protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If new protocols are introduced for SAV, then validation functionality is achieved, but deployment complexity and manual configuration requirements increase

Engineering Contradiction:
Improvesource address validation capabilityVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically generating SAV tables through the existing SPF calculation process. Network devices autonomously compute validation tables using their standard routing protocol operations without requiring manual configuration or separate validation protocol deployments.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary action by pre-computing SAV tables using the same link state information and SPF calculations already performed for routing. This preliminary computation of validation data during the normal routing setup phase eliminates the need for separate configuration steps.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If reactive convergence is used in SAV, then validation updates can be performed, but packet handling becomes improper due to asymmetric routing

Engineering Contradiction:
Improvevalidation update capabilityVSAvoidpacket handling efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the validation information into specific table entries within the SAV table, separating validation data from routing data. This segmentation allows independent optimization of validation lookups without affecting routing operations, improving packet handling efficiency.

Inventive Principle:
Principle #1Segmentation

4Reliability

If manual configuration is required for SAV, then validation can be implemented, but deployment complexity and time increase

Engineering Contradiction:
Improvevalidation implementationVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system eliminates manual configuration by performing self-service through automatic SAV table generation. Network devices autonomously compute validation tables using their standard routing protocol operations without requiring manual configuration or separate validation protocol deployments.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250219928A1Intra-Domain Source Address Validation Using IGPs
Publication Date: 2025.07.03 HUAWEI TECH CO LTD
  • US20250219928A1 patent drawing
  • US20250219928A1 patent drawing
  • US20250219928A1 patent drawing

AI summary

A method implemented by a network node in an interior gateway protocol (IGP) domain. The method includes receiving a link state announcement from one or more other network nodes in the IGP domain, performing shortest path first (SPF) based on the link state announcement received from the one or more other network nodes to determine a path through the domain, building a forwarding information base (FIB) table based on the SPF, determining that the path through the domain is symmetrical, and duplicating the FIB to generate a source address validation (SAV) table.