OTGP Routing Protocol for Secure Inter-AS Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional BGP routing protocols lead to long data packet paths causing delays, security threats, and instability due to lack of security services for data packet routing, and vulnerabilities that can impact the integrity and confidentiality of organization data.
Innovation Solution
The Organization Transit Gateway Protocol (OTGP) is introduced, which uses a service-oriented approach to establish secure and reliable data packet routing by forming stateful communication links based on organization-specific policies and identifiers, eliminating the need for additional security appliances and reducing security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If BGP routing protocol is used to route data packets across autonomous systems, then routing information can be dynamically updated and networks can reach each other, but long transmission paths cause constant delays and affect quality of service
Solution Approach 1:
The patent pre-establishes service level agreement (SLA) routes between autonomous systems before actual data transmission. These pre-configured routes optimize the path selection to minimize transmission delays while maintaining dynamic adaptability through the SLA framework that can be updated without requiring full routing protocol re-negotiation.
2Adaptability or versatility
If BGP routing protocol is used to enable networks to reach each other, then global internet connectivity is achieved, but security threats such as route manipulation, route hijacking, and denial of service occur due to lack of security services
Solution Approach 1:
The patent introduces Service Level Agreement (SLA) as an intermediary layer between autonomous systems. The SLA framework acts as a mediator that authenticates and authorizes routing information exchange, preventing route manipulation and hijacking by verifying the legitimacy of routing advertisements through pre-established service agreements between networks.
3Adaptability or versatility
If BGP routing protocol is used for data packet routing, then autonomous systems can exchange routing information, but packet loss occurs due to routing equipment malfunction or inconsistencies
Solution Approach 1:
The patent implements feedback mechanisms through SLA monitoring and verification processes. Routing information exchanged between autonomous systems is validated against pre-established service level agreements, and any deviations or inconsistencies are detected and corrected through the SLA framework, preventing packet loss due to equipment malfunction or routing errors.
4Object-affected harmful factors
If additional security devices are deployed for encryption and traffic monitoring, then organization data security is improved, but device complexity and cost increase
Solution Approach 1:
The patent makes the SLA framework itself multi-functional, serving simultaneously as a routing protocol, authentication mechanism, encryption key management system, and traffic monitoring framework. This universal approach eliminates the need for separate security appliances by integrating multiple security functions into the routing infrastructure itself.
Data Source
AI summary
Embodiments of the present disclosure provide systems and methods for routing network traffic among organizations using service-oriented protocol. Method implemented at first network device associated with first autonomous system (AS) includes accessing routing table and service information of first AS, service information accessed based on organization identifier of organization of first AS. Method includes sending service messages to establish organization transit gateway protocol (OTGP) session with second network device of second AS. Upon receiving positive acknowledgement for each service message, method includes transferring data packets to second network device based on OTGP routing information relating to organization. Service messages include first service message for initiating discovery operation of second network device, second service message for performing negotiation operation with second network device, third service message for establishing linked network path with second network device, and fourth service message to transmit OTGP routing information for routing data packets.


