Organization Transit Gateway Protocol Secure Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional routing protocols like BGP face issues with security, congestion, and delays in data packet transmission due to insecure peering connections, network congestion, and the lack of consideration for organizational policies and network element malfunctions, leading to vulnerabilities and increased costs for organizations.
Innovation Solution
The Organization Transit Gateway Protocol (OTGP) establishes a secure linked network path between autonomous systems using cryptographic keys and service information, ensuring encrypted data packet transmission compliant with organizational policies, reducing congestion, and providing fault-tolerant communication without the need for additional security appliances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If BGP is used for exchanging routing information among network elements, then routing information can be distributed across autonomous systems, but security vulnerabilities arise due to insecure peering connections
Solution Approach 1:
The patent introduces an intermediary security layer between BGP peering connections that validates and secures routing information exchange. This intermediary mechanism verifies the authenticity of routing advertisements and establishes secure communication channels, preventing route hijacking and manipulation while maintaining BGP's core routing distribution functionality.
Solution Approach 2:
The patent applies preliminary anti-action by implementing pre-authorization and validation mechanisms before routing information is exchanged. Network elements perform security checks, authenticate peers, and establish trusted relationships in advance, preventing malicious routing advertisements and security threats before they can impact the network.
2Loss of information
If full mesh network is used for broadcasting routing information, then all network elements receive routing updates, but network congestion and delays increase
Solution Approach 1:
The patent segments the full mesh broadcasting approach into targeted, selective information distribution. Instead of flooding all network elements with complete routing tables, the system divides routing information into relevant subsets and delivers only necessary updates to specific network elements based on their roles and requirements, reducing overall network traffic.
Solution Approach 2:
The patent implements partial action by sending routing information selectively rather than universally. Network elements receive only the portion of routing information relevant to their function, avoiding the excessive broadcasting of complete routing tables to all peers, thereby reducing network congestion while ensuring necessary information reaches the right destinations.
3Reliability
If route reflector is used to determine active path for routing advertisement, then routing information is forwarded through determined path, but convergence time increases and fast rerouting is prevented
Solution Approach 1:
The patent introduces dynamic path selection capabilities that allow routing paths to adapt in real-time based on network conditions. Unlike static route reflector configurations, the system can dynamically switch between multiple active paths, enabling fast rerouting when link failures or congestion occur, thereby reducing convergence time while maintaining reliable path determination.
Solution Approach 2:
The patent employs parameter changes by allowing routing metrics and path selection criteria to be adjusted dynamically. Network elements can change routing parameters based on real-time conditions such as link status, traffic load, and failure detection, enabling rapid convergence and fast rerouting without being constrained by fixed route reflector paths.
4Object-affected harmful factors
If additional security appliances are deployed to secure organization network communications, then security requirements are met, but networking costs increase
Solution Approach 1:
The patent merges security functions directly into the routing protocol and network element operations. Instead of deploying separate security appliances, the security mechanisms are integrated into the BGP implementation itself, combining routing and security functions into a unified system that reduces infrastructure complexity and cost while maintaining robust security protection.
Solution Approach 2:
The patent enables network elements to perform security functions autonomously without requiring external security appliances. Each network element independently validates routing information, authenticates peers, and enforces security policies, allowing the network to self-secure through its own operational mechanisms rather than relying on additional dedicated security hardware.
Data Source
AI summary
Embodiments of the present disclosure provide systems and methods for sharing encrypted organization data packets among network devices using service-oriented protocol. Method implemented at first network device associated with first autonomous system (AS) includes accessing organization packet (OP) routing information, data structure and service information relating to organization associated with first AS. OP routing information and the service information are being accessed based on organization identifier of the organization and the service information indicating service type associated with the organization. Method includes sending connection request including the data structure and the service information to second network device to establish linked network path. The method includes receiving acknowledgment from the second network device. Responsive to receiving the acknowledgment, the method includes encrypting organization data packet using the data structure and the organization identifier, and sending the encrypted organization data packet to the second network device, via the linked network path.


