In-band Metadata Packet Path Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for verifying that packets traverse a specific path in a network, particularly in service function chains, are inadequate due to the blurring of trust domains in modern networking technologies like NFV and virtual overlays, which complicates the validation process and requires direct physical interface trust, making existing solutions inefficient.

Innovation Solution

A method that utilizes in-band metadata to verify packet transit through network nodes by generating and updating verification information based on configuration data, employing cryptographic keys and secret sharing schemes to ensure packets pass through the intended path, allowing for validation without relying on physical hand-off points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical hand-off points and direct physical interface trust are used for packet path verification, then verification reliability is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improveverification reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical hand-off point verification with cryptographic verification. Instead of relying on physical interface trust domains, the system uses cryptographic keys and in-band metadata to verify packet paths, substituting mechanical/physical verification mechanisms with cryptographic ones.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces in-band metadata as an intermediary carrier that transports verification information through the network. This metadata acts as a mediator between the packet and the verification process, eliminating the need for direct physical interface verification while maintaining reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cryptographic verification methods are implemented without physical hand-off points, then ease of operation is improved, but verification reliability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidverification reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary cryptographic setup by distributing verification information and configuring in-band metadata structures before packet transmission. This preliminary configuration ensures that cryptographic verification can proceed reliably without requiring complex real-time physical verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces physical trust domain verification with cryptographic verification mechanisms, achieving both ease of operation (no physical hand-off points needed) and reliability (cryptographic guarantees) simultaneously.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If detailed verification information is collected in in-band metadata, then measurement precision is improved, but loss of information and computational overhead increase

Engineering Contradiction:
Improvepath verification precisionVSAvoidmetadata overhead
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts only the essential verification information needed for path validation into the in-band metadata, rather than collecting all possible packet attributes. This selective extraction maintains verification precision while minimizing metadata overhead and information loss.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If comprehensive path verification is performed at each network node, then verification reliability is improved, but productivity and processing speed deteriorate

Engineering Contradiction:
Improveverification reliabilityVSAvoidpacket processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial verification at each network node, where nodes perform only the necessary cryptographic checks on in-band metadata rather than comprehensive packet analysis. This partial action approach maintains verification reliability while preserving packet processing speed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3289727B1Network path proof of transit using in-band metadata
Publication Date: 2020.03.18 CISCO TECHNOLOGY INC
  • EP3289727B1 patent drawingFigure 1
  • EP3289727B1 patent drawingFigure 2
  • EP3289727B1 patent drawingFigure 3

AI summary

A system and methods are provided for verifying proof of transit of network traffic through a plurality of network nodes in a network. Information is obtained about a packet at a network node in a network. The information may include in-band metadata of the packet. Verification information is read from in-band metadata of the packet. Updated verification information is generated from the verification information read from the packet and based on configuration information associated with the network node. The updated verification information is written back to the in-band metadata in the packet. The packet is forwarded from the network node in the network.