In-band Metadata Packet Path Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for verifying that packets traverse a specific path in a network, particularly in service function chains, are inadequate due to the blurring of trust domains in modern networking technologies like NFV and virtual overlays, which complicates the validation process and requires direct physical interface trust, making existing solutions inefficient.
Innovation Solution
A method that utilizes in-band metadata to verify packet transit through network nodes by generating and updating verification information based on configuration data, employing cryptographic keys and secret sharing schemes to ensure packets pass through the intended path, allowing for validation without relying on physical hand-off points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical hand-off points and direct physical interface trust are used for packet path verification, then verification reliability is improved, but device complexity and operational difficulty increase
Solution Approach 1:
The patent replaces physical hand-off point verification with cryptographic verification. Instead of relying on physical interface trust domains, the system uses cryptographic keys and in-band metadata to verify packet paths, substituting mechanical/physical verification mechanisms with cryptographic ones.
Solution Approach 2:
The patent introduces in-band metadata as an intermediary carrier that transports verification information through the network. This metadata acts as a mediator between the packet and the verification process, eliminating the need for direct physical interface verification while maintaining reliability.
2Ease of operation
If cryptographic verification methods are implemented without physical hand-off points, then ease of operation is improved, but verification reliability deteriorates
Solution Approach 1:
The patent performs preliminary cryptographic setup by distributing verification information and configuring in-band metadata structures before packet transmission. This preliminary configuration ensures that cryptographic verification can proceed reliably without requiring complex real-time physical verification.
Solution Approach 2:
The patent replaces physical trust domain verification with cryptographic verification mechanisms, achieving both ease of operation (no physical hand-off points needed) and reliability (cryptographic guarantees) simultaneously.
3Measurement precision
If detailed verification information is collected in in-band metadata, then measurement precision is improved, but loss of information and computational overhead increase
Solution Approach 1:
The patent extracts only the essential verification information needed for path validation into the in-band metadata, rather than collecting all possible packet attributes. This selective extraction maintains verification precision while minimizing metadata overhead and information loss.
4Reliability
If comprehensive path verification is performed at each network node, then verification reliability is improved, but productivity and processing speed deteriorate
Solution Approach 1:
The patent implements partial verification at each network node, where nodes perform only the necessary cryptographic checks on in-band metadata rather than comprehensive packet analysis. This partial action approach maintains verification reliability while preserving packet processing speed.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and methods are provided for verifying proof of transit of network traffic through a plurality of network nodes in a network. Information is obtained about a packet at a network node in a network. The information may include in-band metadata of the packet. Verification information is read from in-band metadata of the packet. Updated verification information is generated from the verification information read from the packet and based on configuration information associated with the network node. The updated verification information is written back to the in-band metadata in the packet. The packet is forwarded from the network node in the network.