Interface Selection via Application-Layer Data for Secure Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing routing mechanisms in computer networks lack the ability to control and manage how data is routed based on application-layer data, such as process and user identifiers, leading to potential security risks and inconsistent data integrity across different networks.
Innovation Solution
A system that selects an interface for routing outbound packets based on application-layer data, including process and user identifiers, using a super-routing mechanism that introduces a new table to configure routing decisions and allows multiple agents to specify rules, enabling context-based evaluations and nuanced routing policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional routing mechanisms are used, then network connectivity is maintained, but control over data routing based on application-layer data is lost
Solution Approach 1:
The patent introduces a new dimension to routing by incorporating application-layer data (process ID, application ID, user ID) into routing decisions. This extends traditional routing beyond network-layer information to include application context, enabling fine-grained control without fundamentally redesigning the entire routing architecture.
Solution Approach 2:
The routing control is segmented into multiple components: a super-routing table for high-level policy decisions, application-layer data extraction, and interface selection. This segmentation allows complex routing control to be implemented through modular, manageable parts rather than a monolithic system.
2Reliability
If application-layer data is used for routing decisions, then data integrity and security are improved, but routing mechanism complexity increases
Solution Approach 1:
The patent performs preliminary extraction and evaluation of application-layer data before routing decisions are made. By obtaining process ID, application ID, and user ID in advance and evaluating them against routing policies beforehand, the system ensures data integrity without adding complexity during the actual packet forwarding process.
Solution Approach 2:
The super-routing table acts as an intermediary between application-layer data and interface selection. It translates complex application context into simple routing decisions, shielding the rest of the routing mechanism from complexity while maintaining reliability through policy-based control.
3Adaptability or versatility
If multiple routing policies are enforced for different organizations, then security and data control are enhanced, but system complexity increases
Solution Approach 1:
The super-routing table is designed to be universal, handling routing decisions for multiple organizations and applications through a single mechanism. It evaluates multiple policies in a unified framework, allowing the system to adapt to different organizational requirements without requiring separate routing systems for each.
Solution Approach 2:
Different organizations and applications can have customized routing policies stored in the super-routing table, with each entry tailored to specific organizational needs. This allows localized policy customization while maintaining a unified routing infrastructure, balancing flexibility with manageable complexity.
Data Source
AI summary
The disclosed embodiments relate to a system for selecting an interface for routing an outbound packet. During operation, the system receives an outbound packet to be routed to a destination address. Next, the system obtains application-layer data associated with the outbound packet, including one or more of a process identifier, an application identifier and a user identifier. The system then selects an interface through which to route the outbound packet based on the application-layer data, and uses the selected interface to route the outbound packet.


