Network Routing Using Device Security Capabilities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current networking technologies face inefficiencies in establishing secure network routes due to the lack of sharing and utilization of security capabilities among network devices, leading to increased time and effort in configuring paths that meet security criteria.

Innovation Solution

Network devices share their security characteristics and performance metrics with each other or a central controller, allowing for the determination of routes that satisfy both performance and security criteria, using modified routing algorithms that consider encryption capabilities and health metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is added to routes after establishing paths through the network, then network security is improved, but the time and effort required to configure paths increases

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having network devices advertise their security capabilities (such as encryption support) in advance through routing protocol extensions. This allows the routing algorithm to pre-filter and identify only those devices that meet the required security criteria before path computation, rather than adding encryption after route establishment. The security capability advertisement happens proactively during normal routing operations, so when a secure path is needed, the computation can immediately leverage this pre-shared information.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If security capabilities are not shared among network devices, then device complexity is reduced, but the ability to establish secure routes efficiently deteriorates

Engineering Contradiction:
Improvedevice complexityVSAvoidsecure route establishment efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent uses routing protocol messages as an intermediary mechanism to share security capabilities between network devices. Rather than requiring direct complex interactions between devices or a centralized authority, the security capability information is propagated through the existing routing protocol infrastructure. This allows devices to learn about each other's security capabilities through standard routing advertisements, maintaining low device complexity while enabling efficient secure route establishment.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If routing algorithms only consider performance characteristics, then routing simplicity is maintained, but the ability to satisfy security criteria deteriorates

Engineering Contradiction:
Improverouting simplicityVSAvoidsecurity criteria satisfaction
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges security criteria into the existing performance-based routing algorithm by extending the path computation to simultaneously optimize for both security and performance metrics. The routing algorithm is modified to treat security capabilities as an additional constraint and optimization parameter, combining them with traditional metrics like bandwidth, latency, and hop count. This unified approach maintains routing simplicity from the operator's perspective while automatically satisfying both security and performance requirements.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250385940A1Controller-based network routing based on network device security capabilities
Publication Date: 2025.12.18 NVIDIA CORP
  • US20250385940A1 patent drawing
  • US20250385940A1 patent drawing
  • US20250385940A1 patent drawing

AI summary

Systems and methods for sharing security capabilities of network devices are disclosed. A system for a first network device includes a memory. The system also includes one or more processors, coupled to the memory, to determine, at the first network device, security capabilities of the first network device, transmit the security capabilities of the first network device to a network controller, and receive, from the network controller, a first routing table reflecting the security capabilities of the first network device.