Router Routing Protocol Security with IPSec and Descriptor Sets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional routing protocols in computer networks are vulnerable to malicious attacks due to weak authentication techniques, such as MD5, which can lead to misrouting of traffic and exploitation of network topology, highlighting the need for robust security measures to secure routing communications.

Innovation Solution

Implementing Internet Protocol Security (IPSec) for authentication and encryption of Open Shortest Path First (OSPF) protocol Version 2 communications, allowing network devices to dynamically apply different security associations based on characteristics like interface index, destinations, and routing instances to secure outbound flows of routing protocol messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If weak authentication techniques (e.g., MD5, text-based passwords) are used between routers, then the device complexity is reduced and ease of operation is improved, but the reliability and security of routing communications deteriorate

Engineering Contradiction:
Improvesecurity of routing communicationsVSAvoidcomplexity of security implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies a universal security suite (IPSec) that can be used across multiple routing protocols (OSPF, BGP, ISIS, RIP) and different interface types. This multi-functional approach provides strong authentication and encryption while using a standardized framework that reduces overall system complexity compared to implementing separate security mechanisms for each protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the security parameters from weak authentication (MD5, text passwords) to strong authentication using IPSec with configurable security associations. The system allows dynamic adjustment of security parameters including authentication methods, encryption algorithms, and key management, enabling strong security without fixed complexity.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If a single security association is applied to all routing protocol communications, then the device complexity is reduced, but the adaptability to different traffic flows and interfaces deteriorates

Engineering Contradiction:
Improveability to apply different security to different flowsVSAvoidcomplexity of security management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments routing protocol communications into different flows based on interface type, destination, and routing instance. Each segment can have its own security association configured through descriptor sets that match specific traffic patterns. This segmentation allows tailored security for different flows while managing complexity through structured classification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic security association selection where the appropriate security policy is automatically applied based on real-time traffic flow characteristics. The system dynamically matches incoming routing protocol messages against descriptor sets and applies the corresponding security association, enabling adaptability without manual configuration for each flow.

Inventive Principle:
Principle #15Dynamics

3Reliability

If strong authentication and encryption are applied to all routing protocol traffic, then the reliability and security are improved, but the processing time and productivity deteriorate

Engineering Contradiction:
Improveauthentication and encryption strengthVSAvoidrouting message processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies strong authentication and encryption selectively rather than universally. By using descriptor sets to identify and match specific traffic flows, the system applies security only where needed based on interface type, destination, and routing instance. This partial action approach maintains strong security for critical flows while avoiding unnecessary processing overhead for other traffic.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary configuration of security associations and descriptor sets before routing protocol communications occur. The matching logic and security policies are pre-established, allowing the system to quickly apply appropriate security measures without real-time decision-making delays. This preliminary setup optimizes processing speed while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8954601B1Authentication and encryption of routing protocol traffic
Publication Date: 2015.02.10 JUNIPER NETWORKS INC
  • US8954601B1 patent drawing
  • US8954601B1 patent drawing
  • US8954601B1 patent drawing

AI summary

Techniques are described for providing encryption and authentication for different types of routing protocol communications based on a variety of factors. A method comprises configuring, on a network router, a set of logical interfaces for communicating routing protocol messages with one or more peer routing devices, maintaining a set of security associations that define corresponding authentication information and encryption information for the routing protocol messages, and maintaining one or more descriptor sets that each specify a set of criteria, wherein, for at least one of the descriptor sets, the set of criteria specifies one of the logical interfaces of the network router. The method further comprises selecting one of the descriptor sets having criteria that match an individual flow, selecting one of the security associations based on the selected descriptor set, and applying the selected security association to secure the outbound flow of the routing protocol messages.