Route Origin Server for BGP Policy Automation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of BGP policies in large-scale networks leads to operational challenges, including lengthy router boot times, human error, and difficulties in deploying defensive policies, which can result in disruptive consequences such as the propagation of invalid routes, and there is skepticism about the effectiveness of BGPSEC in addressing these issues.
Innovation Solution
A method and apparatus for processing route data in a network of autonomous systems by receiving route data from border network devices, generating modified route data with metadata that instructs border network devices to modify route behavior, such as installing, withdrawing, promoting, or demoting routes, without identifying the source, thereby simplifying policy implementation and reducing processing overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If BGP policy infrastructure is expanded to handle complex routing requirements, then routing capability and control are improved, but configuration size and complexity increase substantially
Solution Approach 1:
The patent introduces a route origin server as an intermediary component that generates and manages route data with metadata. This server acts as a mediator between the routing infrastructure and border network devices, centralizing policy management functions and reducing the complexity burden on individual routers while maintaining enhanced routing capabilities through the intermediary's coordination
2Adaptability or versatility
If BGP policy configuration size increases to handle more routes, then routing control is improved, but router boot time and processing time increase
Solution Approach 1:
The patent extracts complex policy processing functions from individual routers and consolidates them in a centralized route origin server. By taking out the burden of generating and managing route data with metadata from the border network devices, the system reduces the configuration size that routers must process, thereby decreasing boot time and processing delays while preserving comprehensive routing control through the centralized server
3Reliability
If BGP policy configuration is made more comprehensive to prevent errors, then network security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements a self-service mechanism where the route origin server automatically generates route data with embedded metadata that instructs border network devices on routing decisions. This automation eliminates the need for manual configuration of complex defensive policies, allowing comprehensive security measures to be deployed without increasing operational complexity, as the system serves itself through automated policy generation and distribution
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Measures, including methods, systems and computer program products, for use in processing route data in a network comprising a plurality of autonomous systems. At a network device, route data defining at least one route for network traffic which is configured on at least one border network device is received from the at least one border network device. The at least one border network device is located at a border of an autonomous system in the plurality of autonomous systems. The network device processes the received route data according to a set of policies to generate modified route data. The network device transmits at least a part of the modified route data to the at least one border network device. The at least part of the modified route data is operable to instruct the at least one border network device to modify the behavior of the at least one route.