Trusted Routing via RPKI Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Border Gateway Protocol (BGP) systems lack comprehensive security measures to ensure trusted routing, particularly across different BGP deployments and geographical regions, making them vulnerable to attacks and requiring improved trust management in large communication networks.

Innovation Solution

The implementation of a trusted routing architecture that utilizes a Resource Public Key Infrastructure (RPKI) and a distributed repository system to create a chain of trusted BGP hops, incorporating geographical and trust attributes into routing decisions, and enhancing the Public Key Infrastructure (PKI) to establish a web of trust between security-conscious operators, ensuring the integrity and trustworthiness of routing information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security measures and trust validation for each BGP hop are implemented, then routing security and trustworthiness are improved, but system complexity and computational overhead increase significantly

Engineering Contradiction:
Improverouting securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-establishing a Resource Public Key Infrastructure (RPKI) that stores security information and trust attributes for autonomous systems before routing decisions are made. The distributed repository system pre-loads and caches validation data, so that when routing decisions need to be made, the trust validation can occur quickly using pre-computed security credentials rather than performing complex real-time verification of each hop.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary approach by using a distributed repository system that acts as a mediator between BGP routing decisions and trust validation. This repository stores pre-validated security information and serves as an intermediate authority that confirms trust relationships, reducing the complexity burden on individual routing devices while maintaining comprehensive security verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all root certificates of potential in-route gateways are stored in decision-making BGP systems, then routing trust validation is improved, but storage requirements and scalability deteriorate

Engineering Contradiction:
Improvetrust validationVSAvoidcertificate storage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies segmentation by dividing the centralized certificate authority function into a distributed repository system. Instead of one BGP system storing all root certificates, the trust validation data is segmented and distributed across multiple repository nodes. Each repository stores a portion of the security information and trust attributes, allowing validation to occur through distributed query and verification rather than centralized storage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The distributed repository system serves multiple functions: it stores security information, validates trust relationships, provides caching for frequent routing decisions, and supports multiple autonomous systems simultaneously. This multi-functional approach reduces the need for each BGP system to maintain separate complete certificate stores, as the universal repository serves all validation needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security validation is performed for the entire path of communication, then routing security is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvesecurity validationVSAvoidrouting decision time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing trust relationships and storing security information in the distributed repository before routing decisions are required. Trust attributes and security credentials are pre-validated and cached, enabling rapid lookup and verification during actual routing operations rather than performing complete path validation in real-time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by implementing selective trust validation based on the specific routing scenario. Not every routing decision requires complete end-to-end path validation - the system can use cached trust information from the distributed repository for routine decisions while performing more comprehensive validation only when needed, such as for high-security traffic or unusual routing patterns.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3235209B1Trusted routing between communication network systems
Publication Date: 2020.12.02 NOKIA SOLUTIONS & NETWORKS OY
  • EP3235209B1 patent drawingFigure 1
  • EP3235209B1 patent drawingFigure 2
  • EP3235209B1 patent drawingFigure 3~4

AI summary

An apparatus of a communication network system, which routes data packets and stores trusted routes between different communication network systems in a database, detects (S12) that a data packet requires a route with a specific level of trust, determines (S13), from the trusted routes stored in the database, a specific trusted route towards a destination as indicated in the data packet, and sets (S15) the data packet on the specific trusted route towards the destination.