Trusted Routing via RPKI Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Border Gateway Protocol (BGP) systems lack comprehensive security measures to ensure trusted routing, particularly across different BGP deployments and geographical regions, making them vulnerable to attacks and requiring improved trust management in large communication networks.
Innovation Solution
The implementation of a trusted routing architecture that utilizes a Resource Public Key Infrastructure (RPKI) and a distributed repository system to create a chain of trusted BGP hops, incorporating geographical and trust attributes into routing decisions, and enhancing the Public Key Infrastructure (PKI) to establish a web of trust between security-conscious operators, ensuring the integrity and trustworthiness of routing information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive security measures and trust validation for each BGP hop are implemented, then routing security and trustworthiness are improved, but system complexity and computational overhead increase significantly
Solution Approach 1:
The patent implements preliminary action by pre-establishing a Resource Public Key Infrastructure (RPKI) that stores security information and trust attributes for autonomous systems before routing decisions are made. The distributed repository system pre-loads and caches validation data, so that when routing decisions need to be made, the trust validation can occur quickly using pre-computed security credentials rather than performing complex real-time verification of each hop.
Solution Approach 2:
The patent introduces an intermediary approach by using a distributed repository system that acts as a mediator between BGP routing decisions and trust validation. This repository stores pre-validated security information and serves as an intermediate authority that confirms trust relationships, reducing the complexity burden on individual routing devices while maintaining comprehensive security verification.
2Reliability
If all root certificates of potential in-route gateways are stored in decision-making BGP systems, then routing trust validation is improved, but storage requirements and scalability deteriorate
Solution Approach 1:
The patent applies segmentation by dividing the centralized certificate authority function into a distributed repository system. Instead of one BGP system storing all root certificates, the trust validation data is segmented and distributed across multiple repository nodes. Each repository stores a portion of the security information and trust attributes, allowing validation to occur through distributed query and verification rather than centralized storage.
Solution Approach 2:
The distributed repository system serves multiple functions: it stores security information, validates trust relationships, provides caching for frequent routing decisions, and supports multiple autonomous systems simultaneously. This multi-functional approach reduces the need for each BGP system to maintain separate complete certificate stores, as the universal repository serves all validation needs.
3Reliability
If security validation is performed for the entire path of communication, then routing security is improved, but processing time and computational resources increase
Solution Approach 1:
The patent implements preliminary action by pre-establishing trust relationships and storing security information in the distributed repository before routing decisions are required. Trust attributes and security credentials are pre-validated and cached, enabling rapid lookup and verification during actual routing operations rather than performing complete path validation in real-time.
Solution Approach 2:
The patent applies partial action by implementing selective trust validation based on the specific routing scenario. Not every routing decision requires complete end-to-end path validation - the system can use cached trust information from the distributed repository for routine decisions while performing more comprehensive validation only when needed, such as for high-security traffic or unusual routing patterns.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
An apparatus of a communication network system, which routes data packets and stores trusted routes between different communication network systems in a database, detects (S12) that a data packet requires a route with a specific level of trust, determines (S13), from the trusted routes stored in the database, a specific trusted route towards a destination as indicated in the data packet, and sets (S15) the data packet on the specific trusted route towards the destination.