Router Routing Table Update Verification via Test Packets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current routing protocols in data networks are vulnerable to security threats, particularly 'hacked' routers that can send spurious routing updates, leading to packet loss or delay, and existing security measures are ineffective against such attacks and incur significant overhead.
Innovation Solution
A method that involves sending two test packets to verify the correctness of routing information updates, one following the existing routing table and the other based on the proposed update, and only updating the table if the comparison indicates the information is correct, thereby filtering out malicious updates without requiring encryption or additional hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security measures (encryption, authentication) are implemented to protect routing information, then security against hacked routers is improved, but device complexity and processing overhead increase significantly
Solution Approach 1:
The patent extracts the essential verification function from complex security protocols. Instead of implementing full encryption and authentication suites, the invention isolates the critical task of verifying routing information authenticity by sending simple test packets through proposed new routes and comparing results with existing routes. This extraction approach achieves security against hacked router attacks without the overhead of comprehensive cryptographic implementations.
Solution Approach 2:
The patent uses inexpensive, disposable test packets rather than complex security credentials. These test packets are simple data structures sent temporarily to verify routing information. If a route is compromised, the system discards the problematic routing information and generates new test packets, rather than maintaining complex long-term security keys or certificates. This approach provides security with minimal processing overhead.
2Productivity
If routing information is updated immediately upon receipt to improve responsiveness, then routing efficiency is improved, but vulnerability to spurious updates from hacked routers increases
Solution Approach 1:
The patent applies preliminary verification action before committing to routing table updates. When new routing information is received, the system first sends test packets through the proposed new route and compares the results with the existing route. Only after this preliminary verification confirms the new route is valid does the system update the routing table. This preliminary action prevents spurious updates from hacked routers while maintaining rapid response to legitimate routing changes.
Solution Approach 2:
The patent implements a feedback mechanism where test packets are sent through proposed routing paths and the results are fed back to verify correctness before updating. The system receives routing information, sends test packets, receives feedback about packet delivery success and timing, and uses this feedback to determine whether to accept or reject the routing update. This feedback loop ensures routing efficiency is maintained while protecting against malicious updates.
3Reliability
If comprehensive verification of all routing information is performed to ensure accuracy, then reliability of routing is improved, but processing time and network overhead increase
Solution Approach 1:
The patent applies partial verification action rather than comprehensive checking. Instead of verifying all aspects of routing information or sending multiple complex verification packets, the system sends a simple pair of test packets comparing the proposed route against the existing route. This partial action is sufficient to detect hacked routers while minimizing verification time and network overhead, achieving reliable routing updates without excessive processing delays.
Data Source
AI summary
A data network, of the type in which a number of inter-connected router devices forward received packets of data towards a destination node in accordance with a routing table associated with each router is operated. The network is operated by: receiving routing information at one of the routers, determining if the information is such that, if it were correct, it would cause the router to update its routing table in respect of one or more entries, and, if so, sending out two test packets, one of which is sent out according to the existing information contained in the routing table and the other of which is sent out according to the information which would be included in the routing table if it were updated in accordance with the received information; comparing the results of the two test sendings; and updating the routing table to reflect the received information if the comparison indicates that the received information is correct, but otherwise ignoring the information and maintaining the routing table unchanged.


