Secure Tunnel Self-Configuration via VRF Loopback Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication systems for networks, especially those requiring 'plug and play' functionality and intelligent routing, often conflict with security measures against Denial of Service attacks, leading to inflexibility and high configuration burdens, particularly in sensitive applications like military networks that need frequent re-deployment.

Innovation Solution

A method for creating secure traffic and management tunnels within a network using virtual routing and forwarding (VRF) modules, where each router node automatically detects and configures tunnels with neighboring nodes using loopback addresses and VRF modules, enabling self-configuration and separation of traffic and management tunnels over unique addresses, thus reducing user configuration and enhancing flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration of connections between nodes is implemented for security protection, then network security against DoS attacks is improved, but device complexity and ease of operation deteriorate due to lengthy data preparation and configuration burden

Engineering Contradiction:
Improvenetwork securityVSAvoidconfiguration burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The router node automatically performs security configuration by detecting routing prefixes from neighboring nodes and self-configuring traffic and management tunnels without user intervention. The system uses automated loopback address detection and tunnel establishment, eliminating the need for manual in-barracks data preparation while maintaining security through programmatically configured VRF modules and tunnel barriers.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual configuration of connections between nodes is implemented for security protection, then network security against DoS attacks is improved, but ease of operation worsens due to reduced plug and play functionality

Engineering Contradiction:
Improvenetwork securityVSAvoidplug and play functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables plug and play functionality by allowing router nodes to automatically detect neighboring nodes through loopback address advertisement, self-configure VRF modules, and establish secured tunnels without user intervention. The automated detection of routing prefixes and programmatic tunnel configuration maintains security while eliminating manual configuration steps.

Inventive Principle:
Principle #25Self-service

3Reliability

If security protection measures are implemented, then network security is improved, but adaptability worsens due to inflexibility when network topology needs to change

Engineering Contradiction:
Improvenetwork securityVSAvoidtopology flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts to topology changes by continuously monitoring for routing prefix advertisements from neighboring nodes. When new nodes are added or existing nodes change configuration, the system automatically detects the changed topology through loopback address detection and reconfigures tunnels accordingly, maintaining security while providing flexibility for frequent re-deployment scenarios.

Inventive Principle:
Principle #15Dynamics

4Reliability

If security protection measures are implemented, then network security is improved, but ease of operation worsens due to obscured routing path and metrics

Engineering Contradiction:
Improvenetwork securityVSAvoidrouting visibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses loopback addresses as intermediary elements that allow secure tunnel establishment without exposing actual network topology. The VRF modules act as intermediaries that encapsulate traffic, providing security through obscured routing paths while maintaining operational simplicity through automated tunnel configuration based on detected loopback addresses.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4123972A1Secure communication system
Publication Date: 2023.01.25 BAE SYSTEMS PLC
  • EP4123972A1 patent drawingFigure 1
  • EP4123972A1 patent drawingFigure 2
  • EP4123972A1 patent drawingFigure 3

AI summary

A method of creating one or more secure tunnels within a network, a router node implementing the method and a network comprising a plurality of router nodes. The method comprises: connecting a first router node to the network, wherein the first router node comprises a plurality of bearer interfaces, each having a virtual routing and forwarding VRF module; receiving, from neighbouring nodes in the network, at least one loopback address for at least one bearer interface in the neighbouring nodes; and detecting, using the first router node, one or more routing prefixes associated with a traffic or management tunnel within the at least one received loopback address. In response to detecting the one or more routing prefixes, the method comprises using the first router node to: build a routing table comprising at least one loopback address for a bearer interface of the same type in one of the neighbouring nodes; extract, from the built routing table, an IP address for each of the traffic and management tunnels to be created; and set each extracted IP address as the destination address for each of the traffic and management tunnels. The method also comprises establishing a traffic and management tunnel to each neighbouring node, by selecting a bearer interface to connect to each neighbouring node; learning the set destination addresses for the traffic and management tunnels for the selected bearer interface and building the management tunnel and the traffic tunnel to each neighbouring node using the learnt destination addresses.