Service Network Device Packet Interception for Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices within autonomous systems (AS) lack the capability to perform services on packets with labels, such as firewall or deep packet inspection, when these packets are not destined for them, leading to potential security vulnerabilities and inefficient resource usage due to unserviced malicious content.

Innovation Solution

A service network device generates and provides route information that identifies itself as the next hop for packets, allowing it to perform services like firewall or deep packet inspection before forwarding, even if the packet is not destined for it, by manipulating route information and using protocols like EBGP or IBGP to ensure efficient packet handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a network device forwards packets with labels based on label information without performing services, then packet forwarding efficiency is improved, but security is worsened due to inability to inspect malicious content

Engineering Contradiction:
Improvepacket forwarding efficiencyVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a service network device as an intermediary between the label-switched path and the destination. This service device intercepts packets by being installed as the next-hop address in the label information, allowing service processing (firewall, deep packet inspection) to occur without breaking the label-switched forwarding efficiency. The service device acts as a mediator that enables security services while maintaining the high-speed label-based forwarding architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a service network device processes all packets destined for other devices, then security is improved by servicing packets before forwarding, but device complexity increases due to route information manipulation

Engineering Contradiction:
Improvesecurity vulnerabilityVSAvoidroute information manipulation
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent changes the next-hop address parameter in the label information from the original destination device to the service network device. This parameter change enables the service device to intercept packets through standard label-switched forwarding without requiring complex packet manipulation or protocol modifications. The simplicity of changing a single routing parameter resolves the contradiction by achieving security services through existing forwarding mechanisms rather than complex intervention.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If route information is modified to install service network device as next hop, then service capability is improved, but routing protocol complexity worsens

Engineering Contradiction:
Improveservice capabilityVSAvoidrouting protocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the service network device universally installable as next-hop for multiple different destination devices through standard routing protocols. By advertising the service device's address as the next-hop in label information for various destinations, the solution enables a single service device to provide security services for multiple service flows without requiring separate routing protocol modifications for each case. This multi-functionality approach improves service capability while keeping routing protocol complexity manageable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3343847B1Performing a service on a packet
Publication Date: 2020.05.06 JUNIPER NETWORKS INC
  • EP3343847B1 patent drawingFigure 1A
  • EP3343847B1 patent drawingFigure 1B
  • EP3343847B1 patent drawingFigure 2

AI summary

A first device may receive first route information, from a second device, identifying a first route to the second device for a packet to be provided toward a destination via the second device. The first device may generate second route information identifying a second route to the first device for the packet. The first device may provide the second route information to a third device. The packet is to be received by the first device. The first device may receive the packet from the third device via the second route after providing the second route information to the third device. The packet is to be provided to the second device by the first device. The first device may perform a service on the packet based on being identified by the second route information as a next hop for the packet and prior to providing the packet to the second device.