Security-Metric Routing for Reliable Multi-Domain Network Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing routing protocols in complex computer networks face limitations in scalability, adaptability, and security, necessitating improved techniques for efficient and secure data transfer.

Innovation Solution

Incorporating security metrics into routing protocols by augmenting them with attestation indicators, reliability metrics, and encryption indicators to enhance path evaluation, using a federated routing engine for multi-domain networks, and assigning weights based on security and reliability data to select optimal paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing routing protocols are used in complex networks, then routing functionality is provided, but security and reliability are insufficient

Engineering Contradiction:
Improvenetwork securityVSAvoidprotocol adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The routing protocol dynamically adapts its behavior based on the security domain. It can switch between traditional routing modes and security-enhanced modes, adjusting its operation to match the requirements of different network environments. This allows the protocol to maintain reliability through security enhancements while preserving adaptability by not imposing a fixed rigid structure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The protocol changes key parameters such as authentication requirements, encryption levels, and trust verification thresholds based on the security domain context. By adjusting these parameters dynamically rather than using fixed values, the protocol enhances security where needed while maintaining flexibility and adaptability across different network conditions.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If security metrics are incorporated into routing protocols, then path evaluation is enhanced, but computational complexity increases

Engineering Contradiction:
Improvepath evaluation accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security metric calculation is divided into discrete, modular components that can be computed independently. Each security attribute (authentication, encryption, trust level) is evaluated separately and then aggregated, allowing for efficient computation and reducing overall complexity while maintaining comprehensive path evaluation accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary security metrics and intermediate calculation steps that simplify the overall computation. Rather than directly computing complex security evaluations, the system uses intermediate security scores and staged assessments that break down the computational burden while preserving measurement precision through systematic aggregation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple routing protocols are used for path recommendation, then path selection reliability is improved, but protocol coordination complexity increases

Engineering Contradiction:
Improvepath selection reliabilityVSAvoidprotocol coordination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple routing protocol recommendations into a unified security domain-aware selection process. Rather than coordinating complex interactions between multiple protocols, the system integrates their outputs through a common security evaluation framework that consolidates path recommendations while maintaining reliability through comprehensive security assessment.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The routing selection mechanism is designed with universal functionality that can handle recommendations from multiple different routing protocols through a single unified evaluation process. This multi-functional approach allows the system to process diverse protocol inputs without requiring complex protocol-specific coordination logic for each protocol pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12407731B2Routing techniques for enhanced network security
Publication Date: 2025.09.02 CISCO TECHNOLOGY INC
  • US12407731B2 patent drawing
  • US12407731B2 patent drawing
  • US12407731B2 patent drawing

AI summary

Techniques for optimizing routing decisions based on security metrics within a network environment are described herein. In some cases, by using various security metrics, such as encryption indicators, attestation indicators, secureness metrics, and reliability metrics, an exemplary system can assess the security level and reliability of network paths. These metrics may provide valuable insights into the trustworthiness and integrity of participating nodes and links and enable informed decision-making regarding path selection.