Routing Protocol Packet Source Address Modification for ISP Filter Bypass

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet Service Providers (ISPs) often block routing protocol packets from unauthorized subnets, causing delays and obstacles for customers trying to make devices available on specific subnets, as existing solutions rely on manual subnet additions which are time-consuming and inconvenient.

Innovation Solution

A system that modifies routing protocol packets to appear as if they originated from an integrated router, bypassing filtering by replacing source addresses and generating additional packets to indicate subnet reachability, allowing these packets to be transmitted without being filtered by the ISP's routing protocol filter.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ISPs use filters to block routing protocol packets from unauthorized subnets, then network security and control are improved, but customer ability to make devices available on specific subnets deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary device (customer premises equipment or network device) that modifies routing protocol packets by replacing source subnet addresses with authorized gateway router addresses. This intermediary action allows packets from unauthorized subnets to bypass ISP filters while maintaining the appearance of authorized traffic, thus resolving the contradiction between security filtering and device availability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the routing protocol packet with a modified source address. Instead of transmitting the original packet with the unauthorized subnet address, a copied version with an authorized gateway address is transmitted, allowing the packet to pass through the filter while conveying the same routing information.

Inventive Principle:
Principle #26Copying

2Productivity

If customers request manual subnet additions to the authorized set, then routing protocol packet transmission is improved, but time consumption and operational complexity worsen

Engineering Contradiction:
Improverouting protocol transmissionVSAvoidsubnet configuration time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent enables customers to self-configure routing protocol transmission by implementing automatic address modification in their customer premises equipment. Instead of requiring manual ISP intervention to add subnets to the authorized set, the customer's own device automatically modifies packet addresses to bypass filters, eliminating the time-consuming manual subnet addition process.

Inventive Principle:
Principle #25Self-service

3Reliability

If routing protocol packets are blocked by filters, then unauthorized subnet access is prevented, but network communication efficiency deteriorates

Engineering Contradiction:
Improvefilter effectivenessVSAvoidnetwork communication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent inverts the traditional approach by not trying to gain access through the filter (which would require manual subnet addition), but rather by transforming the packet's source address to appear as if it originated from an authorized subnet. This inversion allows routing protocol packets to efficiently bypass filters without requiring filter configuration changes or manual authorization processes.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS7764692B1Bypass of routing protocol filtering in a multi-subnet network
Publication Date: 2010.07.27 CISCO TECHNOLOGY INC
  • US7764692B1 patent drawing
  • US7764692B1 patent drawing
  • US7764692B1 patent drawing

AI summary

In one embodiment, an apparatus may replace a first address included in a source address of a first routing protocol packet with a second address. The first address may identify a source router and the second address may identify an integrated router. The source address may indicate where the first routing protocol packet originated. The apparatus may also generate a second routing protocol packet that indicates a subnet of the source router is reachable by the integrated router. The apparatus may further transmit the first routing protocol packet and the second routing protocol packet to the integrated router.