Source address verification method and device, electronic equipment and storage medium
Through bidirectional authentication and SDN technology, multiple independent paths are calculated and traffic allocation is optimized. Combined with the use of sharding and verification identifiers, the verification problem in the existing technology in high-traffic attacks and asymmetric routing scenarios is solved, and more efficient and reliable source address verification is achieved.
Patent Information
- Application Number
- CN202510694529.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-05-28
AI Technical Summary
In the face of high-traffic attacks, the equipment load is too heavy and cannot effectively resist large-scale network attacks. In asymmetric routing or multi-path transmission scenarios, verification methods are prone to false filtering and cannot accurately identify malicious traffic.
Identity authentication is performed on the access network and source PoP nodes through the two-way authentication mechanism, source prefix information is obtained and entry interface is bound; PoP node and link status information are obtained using the SDN southbound interface, multiple independent paths are calculated, and the optimal path collection is determined based on the path dispersion score and traffic allocation is optimized; during the data transmission process, data packets are sharded and marked according to the preset sharding strategy, and verification identifiers are generated through the HMAC-SHA256 algorithm to ensure the integrity and authenticity of shards.
It effectively improves the security and reliability of network communications, and solves the problems in the existing technology that rely on a single path, cannot accurately identify malicious traffic, poor defense effects, cannot respond quickly to attacks and deployment difficulties.
Smart Images

Figure CN120223442A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a source address verification method, device, electronic device, and storage medium. Background Art
[0002] With the booming development of the Internet, network attack means have become increasingly complex and changeable. Among them, source address forgery attacks are particularly prominent, such as distributed denial of service attacks (DDoS), etc., posing a severe challenge to network security. However, traditional source address verification technologies, such as unicast reverse path forwarding (uRPF) and source address verification protocol (SAV), face many challenges when dealing with the complexity of modern network environments.
[0003] Traditional source address verification technologies rely on a single-path verification method. In the face of high-traffic attacks, it is easy to cause the network device to be overloaded, thereby affecting the device performance and being unable to effectively resist large-scale network attacks. Moreover, in the scenarios of asymmetric routing or multi-path transmission, traditional verification methods are prone to false filtering and cannot accurately identify malicious traffic, thus giving attackers an opportunity.
[0004] In addition, traditional methods cannot be flexibly adjusted dynamically according to network topologies and traffic characteristics, resulting in poor defense effects, being unable to quickly respond to rapidly changing network attacks, and concentrating verification tasks on a single device, which not only easily causes device resource overload, affects the overall network performance, but also easily becomes the target of network attacks.
[0005] Therefore, there is an urgent need for a source address verification method that can effectively improve the network's defense ability against source address forgery attacks, ensure the security and reliability of network communications, and is efficient, flexible, and scalable. Summary of the Invention
[0006] Embodiments of the present invention provide a source address verification method to solve the problems of the prior art relying on a single path, being unable to accurately identify malicious traffic, having a poor defense effect, being unable to quickly respond to attacks, and being difficult to deploy. The technical solutions are as follows: According to one aspect of the present invention, a source address verification method includes: authenticating the access network and the source PoP node through a two-way authentication mechanism, obtaining the source prefix information of the access network and binding the ingress interface; obtaining the status information of all PoP nodes and links, calculating multiple independent paths according to the status information, determining an optimal path set according to the path dispersion score, and optimizing traffic allocation; receiving a data packet through the source PoP node, fragmenting the data packet according to a preset fragmentation policy to obtain multiple fragments and marking them, and transmitting each fragment to the target PoP node based on the optimal path set; verifying the integrity and authenticity of each fragment through the target PoP node, recombining the verified fragments to obtain the original data packet, performing source address verification and legality verification on the original data packet, and forwarding it to the access network after passing the verification.
[0007] In one embodiment, obtaining the status information of all PoP nodes and links, calculating multiple independent paths according to the status information, determining an optimal path set according to the path dispersion score, and optimizing traffic allocation are implemented through the following steps: obtaining the status information of all PoP nodes and links at a set frequency through the SDN southbound interface; the status information includes CPU load, memory usage bandwidth, latency, and historical security records; assigning an initial security weight to each link, using the Dijkstra algorithm to calculate the shortest path with the security weight, and obtaining a path set by iteratively calculating the remaining paths; defining the overall dispersion score of the path set, selecting the path set whose dispersion score meets the set conditions and meets the bandwidth requirements as the optimal path set, and optimizing traffic allocation by solving the optimal traffic allocation problem through a linear programming model.
[0008] In one embodiment, after determining the optimal path set, the following steps are further included: setting a basic update interval for the paths that need to be updated periodically and initializing a timer, collecting the current network topology information when the timer decrements to zero; recalculating the optimal path set and traffic allocation according to the current network topology information, path dispersion score, and bandwidth requirements, and resetting the timer; dynamically adjusting the update interval according to the security threat level, and immediately updating the path in special cases; the special cases include network topology changes, detected suspicious attack attempts, or manually triggered update commands.
[0009] In one embodiment, fragmenting the data packet according to a preset fragmentation strategy to obtain multiple fragments and marking them, and transmitting each of the fragments to the target PoP node based on the optimal path set is achieved through the following steps: determining the number of fragments according to the header information of the data packet, the network bandwidth condition, and the security threat level, fragmenting the data packet according to the number of fragments to obtain multiple fragments and generating routing information; generating a verification identifier for each of the fragments by using the HMAC-SHA256 algorithm and a session key, and creating an IP header and a fragment header for each of the fragments; the fragment header contains fragment marking information; allocating each of the fragments to each independent path in the optimal path set and transmitting them to the target PoP node simultaneously, and optimizing the fragment allocation according to the path characteristics.
[0010] In one embodiment, the target PoP node performs integrity and authenticity verification on each of the fragments, and reconstructing the original data packet from the fragments that pass the verification is achieved through the following steps: the target PoP node verifies the legality of each of the fragments according to the fragment header information of each of the fragments and the local verification table, and checks whether the source address of each of the fragments matches the entry interface; storing the fragments that pass the verification into a reconstruction buffer, setting a reconstruction timeout timer according to the number of fragments, and if all the fragments are not received within a predetermined time, discarding all the received fragments; extracting the payload parts of all the fragments in the order of the fragment sequence numbers in the fragment header information for reconstruction to obtain the original data packet.
[0011] In one embodiment, before the target PoP node performs integrity and authenticity verification on each of the fragments, the following steps are further included: after receiving the fragment, the intermediate PoP node queries the local SAV table of the fragment and verifies whether the source address of the fragment matches the entry interface; verifying whether the verification identifier in the fragment header of the fragment is tampered with, and if the verification fails, the intermediate PoP node discards the fragment and reports an abnormal situation.
[0012] In one embodiment, after the target PoP node verifies the integrity and authenticity of each shard, the following steps are further included: verifying the consistency of the quantity, source target, and target address of all the shards, the continuity of the sequence number, and the validity of the timestamp. If the target PoP node detects the situation of shard loss, timeout, or verification failure, it immediately discards all relevant shards, releases resources, and simultaneously reports the abnormal type and relevant path; sends an ICMP error message to the source PoP node and controls the frequency to avoid DoS attacks, and classifies the abnormal situation into minor, general, and severe according to the severity of the abnormality; for minor abnormalities, it records the log and degrades the quality of the corresponding path, for general abnormalities, it discards the corresponding shard and reports it, and for severe abnormalities, it discards all shards, sends a high-priority alarm, triggers an emergency path update, and blocks the suspicious source traffic.
[0013] According to one aspect of the present invention, a source address verification device includes: a connection and authentication module for authenticating the access network and the source PoP node through a two-way authentication mechanism, obtaining the source prefix information of the access network and binding the entry interface; a path planning module for obtaining the status information of all PoP nodes and links, calculating multiple independent paths according to the status information, determining the optimal path set according to the path dispersion score, and optimizing the traffic allocation; a data transmission module for receiving a data packet through the source PoP node, fragmenting the data packet into multiple shards according to a preset fragmentation strategy and marking them, and transmitting each shard to the target PoP node based on the optimal path set; a verification and recombination module for verifying the integrity and authenticity of each shard through the target PoP node, recombining the verified shards into the original data packet, performing source address verification and legality verification on the original data packet, and forwarding it to the access network after passing the verification.
[0014] According to one aspect of the present invention, an electronic device includes at least one processor and at least one memory, wherein computer-readable instructions are stored on the memory; the computer-readable instructions are executed by one or more of the processors, enabling the electronic device to implement the source address verification method as described above.
[0015] According to one aspect of the present invention, a storage medium stores computer-readable instructions thereon, and the computer-readable instructions are executed by one or more processors to implement the source address verification method as described above.
[0016] The beneficial effects brought by the technical solution provided by the present invention are: In the above technical solution, the present invention first performs identity authentication on the access network and the source PoP node through a two-way authentication mechanism, obtains the source prefix information and binds the ingress interface, laying a foundation for subsequent verification. Then, it regularly obtains the PoP node and link status information through the SDN southbound interface, calculates multiple independent paths, determines the optimal path set according to the path dispersion score and bandwidth requirements, and optimizes the traffic allocation. At the same time, a periodic update mechanism is set to dynamically adjust the paths to adapt to network changes. In the data transmission stage, the data packets are fragmented and marked according to the preset fragmentation strategy, and the verification identifier is generated through the HMAC-SHA256 algorithm to ensure the integrity and authenticity of the fragments. Subsequently, the fragments are transmitted to the target PoP node based on the optimal path set. The target PoP node verifies the integrity and authenticity of the fragments, recombines them to obtain the original data packet, and performs source address and legality verification. In addition, the intermediate PoP nodes also participate in the verification process to ensure the security of the fragments during transmission. During the verification process, corresponding measures are taken for different abnormal situations, such as logging, discarding fragments, sending alerts, etc., to ensure the stability and security of network communication. Through the multi-level verification mechanism and dynamic path adjustment strategy, the security and reliability of network communication are effectively improved, thus effectively solving the problems of the existing technology relying on a single path, being unable to accurately identify malicious traffic, having poor defense effects, being unable to quickly respond to attacks, and being difficult to deploy. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the following drawings are only some embodiments of the present invention. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0018] Figure 1 is a flowchart of a source address verification method shown according to an exemplary embodiment; Figure 2 is a schematic structural diagram of deploying a source address verification system in an application scenario; Figure 3 is Figure 2 a schematic diagram of system adaptive optimization corresponding to the application scenario; Figure 4 is a block diagram of a source address verification device shown according to an exemplary embodiment; Figure 5 is a hardware structure diagram of an electronic device shown according to an exemplary embodiment; Figure 6 is a block diagram of an electronic device shown according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] Embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0020] Those skilled in the art of the present technology can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the", and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the specification of the present disclosure means the presence of the described features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say an element is "connected" or "coupled" to another element, it can be directly connected or coupled to other elements, or there may also be intermediate elements. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The term "and / or" used herein includes all or any unit and all combinations of one or more associated listed items.
[0021] The present invention provides a source address verification method. Through a multi-level verification mechanism and a dynamic path adjustment strategy, the security and reliability of network communication are effectively improved, and the problems in the prior art, such as relying on a single path, being unable to accurately identify malicious traffic, having poor defense effects, being unable to quickly respond to attacks, and being difficult to deploy, are solved. The source address verification method is applicable to a source address verification device, and the source address verification device may be an electronic device. The source address verification method in the embodiments of the present invention can be applied to various scenarios, such as the protection of application programs and online network platforms, etc.
[0022] Please refer to Figure 1 , an embodiment of the present invention provides a source address verification method, and this method is applicable to an electronic device.
[0023] In the following method embodiments, for the convenience of description, the execution subject of each step of the method is taken as an electronic device as an example for illustration, but this does not constitute a specific limitation thereto.
[0024] As Figure 1 shown, this method may include the following steps: Step 110, perform identity authentication on the access network and the source PoP node through a two-way authentication mechanism to obtain the source prefix information of the access network and bind the ingress interface.
[0025] In a possible implementation, the customer network establishes a connection with the nearest PoP node through an access module, then authenticates the customer network to ensure its legitimacy, publishes the source prefix of the customer network, and binds the ingress interface for future communication.
[0026] Specifically, the customer network establishes an encrypted connection with the nearest PoP node through a secure access protocol to ensure the confidentiality and integrity of communication. A two-way authentication mechanism is adopted, that is, the PoP node verifies the identity certificate of the customer network, and at the same time, the customer network also verifies the legitimacy of the PoP node to ensure the authenticity and reliability of both parties' identities. After the customer network passes the authentication, it publishes its source prefix information to the PoP node and binds a specific ingress interface. The PoP node records this information for subsequent data transmission and verification.
[0027] In the above process, the embodiment of the present invention realizes the secure connection and authentication between the customer network and the PoP node, binds the source prefix and the ingress interface, ensures the traceability and security of communication, provides a necessary information basis for subsequent steps, and facilitates data transmission and verification.
[0028] Step 120: Obtain the status information of all PoP nodes and links, calculate multiple independent paths according to the status information, and determine the optimal path set and optimize the traffic allocation according to the path dispersion score.
[0029] In a possible implementation, the status information of all PoP nodes and links is obtained through the SDN southbound interface at a set frequency, an initial security weight is assigned to each link, the Dijkstra algorithm is used to calculate the shortest path with security weights, the path set is obtained by iteratively calculating the remaining paths, the overall dispersion score of the path set is defined, and the path set that meets the set conditions and bandwidth requirements is selected as the optimal path set. The optimal traffic allocation problem is solved through a linear programming model to optimize the traffic allocation.
[0030] Among them, the status information includes CPU load, memory usage bandwidth, latency, historical security records, etc., which are not limited here.
[0031] In a possible implementation, after determining the optimal path set, a basic update interval is set for the paths that need to be updated periodically and the timer is initialized. When the timer decrements to zero, the current network topology information is collected. The optimal path set and traffic allocation are recalculated according to the current network topology information, path dispersion score, and bandwidth requirements, and the timer is reset. The update interval is dynamically adjusted according to the security threat level, and path updates are performed immediately in special cases. For example, the higher the security threat level, the higher the update frequency.
[0032] Among them, special cases include network topology changes, detection of suspicious attack attempts, or manual triggering of update commands, etc., which are not limited here.
[0033] Furthermore, after the path is updated, distributed verification continues through the intermediate PoP node and the target PoP node to ensure the security and integrity of data transmission. If any abnormality is found during the verification process, the system will handle it according to the verification failure handling mechanism. Through this intelligent path update mechanism, it can dynamically adapt to changes in network conditions and security threat levels, ensuring the security and efficiency of data transmission.
[0034] In the above process, the embodiments of the present invention achieve the diversification and independence of paths, improve the reliability and security of communication, balance security and performance by dynamically adjusting the path update frequency, and the optimized traffic distribution ensures the effective utilization of network resources and improves the data transmission efficiency.
[0035] Step 130, receive the data packet through the source PoP node, fragment the data packet according to the preset fragmentation strategy to obtain multiple fragments and mark them, and transmit each fragment to the target PoP node based on the optimal path set.
[0036] In a possible implementation, determine the number of fragments according to the header information of the data packet, network bandwidth conditions, and security threat levels, fragment the data packet according to the number of fragments to obtain multiple fragments and generate routing information, generate verification identifiers for each fragment through the HMAC-SHA256 algorithm and the session key, create an IP header and a fragment header for each fragment, allocate each fragment to each independent path in the optimal path set to ensure that only one fragment is transmitted on each path, and then transmit them to the target PoP node simultaneously through each independent path. Optimize the fragment allocation according to the path characteristics, for example, allocate smaller fragments to slower paths and larger fragments to faster paths to balance the arrival time.
[0037] Among them, the fragment header contains fragment marking information; In the above process, the embodiments of the present invention achieve the fragmented transmission of data, improve the flexibility and reliability of data transmission, reduce the risk of data being stolen or tampered with through multi-path transmission, and the use of verification identifiers and routing information ensures the integrity and authenticity of data, facilitating subsequent verification and recombination.
[0038] Step 140, perform integrity and authenticity verification on each fragment through the target PoP node, recombine the fragments that pass the verification to obtain the original data packet, perform source address verification and legality verification on the original data packet and forward it to the access network after passing.
[0039] In a possible implementation, the target PoP node verifies the legality of each shard according to the shard header information of each shard and the local verification table, checks whether the source address of each shard matches the entry interface, stores the shards that pass the verification in the reassembly buffer, sets a reassembly timeout timer according to the number of shards, and if all shards are not received within the predetermined time, discards all received shards, and extracts the payload parts of all shards in the order of the shard sequence numbers in the shard header information for reconstruction to obtain the original data packet.
[0040] Specifically, after receiving a shard, the target PoP node first checks the shard header information (such as shard ID, timestamp, etc.), and then queries the local verification table to verify the legality of the shard. If the corresponding session key exists locally, it recalculates the verification identifier and compares it with the VI in the shard. At the same time, it checks whether the shard arrives from the expected entry interface and whether the source address matches the expectation.
[0041] Furthermore, store the shards that pass the verification in the reassembly buffer, wait for all shards to arrive, determine the number of shards to wait for according to the total shard number field in the shard header, and set a reassembly timeout timer. If all shards are not received within the predetermined time, discard all received shards. Finally, extract the payload parts of all shards in the order of the shard sequence numbers to reconstruct the complete payload of the original data packet.
[0042] Furthermore, perform a final source address verification on the reassembled complete data packet, check the legality of the data packet (including protocol compliance and application layer data consistency). If the verification passes, forward it to the connected customer network. Otherwise, discard the data packet and report an abnormal situation.
[0043] Through the above process, the embodiment of the present invention realizes the integrity and authenticity verification of data, ensures the security of data transmission, waits for all shards to arrive through the reassembly buffer, improves the reliability of data transmission, and the final source address verification ensures the legality of the data packet, enhancing the security of the network.
[0044] In a possible implementation, before the target PoP node performs integrity and authenticity verification on each shard, after receiving a shard, the intermediate PoP node queries the local SAV table of the shard, verifies whether the source address of the shard matches the entry interface, and verifies whether the verification identifier in the shard header of the shard is tampered with. If the verification fails, the intermediate PoP node discards the shard and reports an abnormal situation.
[0045] In a possible implementation, after the target PoP node verifies the integrity and authenticity of each shard, it verifies the consistency of the number of all shards, source and destination addresses, the continuity of the sequence number, and the validity of the timestamp. If the target PoP node detects missing shards, timeouts, or verification failures, it immediately discards all related shards, releases resources, and reports the abnormal type and related path at the same time.
[0046] Furthermore, an ICMP error message is sent to the source PoP node, and the frequency is controlled to avoid DoS attacks. According to the severity of the anomaly, the abnormal situations are divided into minor, general, and severe. For minor anomalies, the log is recorded and the quality of the corresponding path is degraded. For general anomalies, the corresponding shards are discarded and reported. For severe anomalies, all shards are discarded, a high-priority alarm is sent, an emergency path update is triggered, and the suspicious source traffic is blocked.
[0047] Through the above process, the present invention realizes the verification of the authenticity of the source address and the integrity of the data in network communication through initial connection and authentication, path planning, data transmission, and verification and recombination. By adopting a multi-path transmission and distributed verification mechanism, it ensures the security, flexibility, and reliability of data transmission. In the verification link, not only the target PoP node performs verification, but also the intermediate PoP nodes assume the verification responsibility, forming a multi-level verification system. At the same time, by dynamically adjusting the path update frequency and optimizing the traffic distribution, the balance between security and performance is achieved, which can effectively improve the security and reliability of network communication, and thus can effectively solve the problems of the prior art that rely on a single path, cannot accurately identify malicious traffic, have poor defense effects, cannot quickly respond to attacks, and are difficult to deploy.
[0048] In an exemplary embodiment, a source address verification system is shown to provide a highly secure source address verification service for communication between autonomous systems (AS). The system includes PoP nodes, a central controller, a verification table, and a customer network.
[0049] Among them, the PoP nodes are deployed at the network edge and core positions, responsible for packet processing, fragmentation, path forwarding, and source address verification; the central controller is the core of the system, responsible for global path planning, security policy formulation, dynamic path update scheduling, and anomaly monitoring and response; the verification table is a data structure maintained by each PoP node, recording information such as source destination prefix, incoming interface, message sequence number identifier, etc.; the customer network joins the autonomous system (AS) of the trusted network architecture and accesses the system through the nearest PoP node.
[0050] Specifically, it may include the following steps: The first step is the initial connection and authentication phase.
[0051] Specifically, the customer network AS1 establishes a connection with the nearest PoP node (PoP1) through the access module, conducts two-way identity authentication to ensure the identity legality of PoP1 and AS1. AS1 publishes its source prefix and binds the ingress interface for future communication to PoP1.
[0052] Furthermore, the central controller generates a session key K_session for AS1, which is generated using the HMAC-SHA256 algorithm based on the system master key K_master, the ID of AS1, the ID of the target AS (such as AS7), the timestamp, and the nonce. The dynamic generation and periodic update (once an hour) of the session key ensure the security of communication and prevent security risks caused by key leakage.
[0053] The second step is the path planning phase.
[0054] Specifically, the central controller collects the status information of all PoP nodes and links in the network, as well as historical security records, every 10 seconds through the SDN southbound interface.
[0055] Among them, the node status includes CPU load, memory usage, processing capacity, and queue length; the link status includes bandwidth, latency, packet loss rate, jitter, and utilization; the historical security record refers to the number of abnormal events detected on the link in the past 24 hours. The high-frequency collection of topology information ensures the real-time update of the network status and provides an accurate data basis for path planning.
[0056] Furthermore, using the improved Yen's K shortest path algorithm, multiple independent paths are calculated for AS1 to AS7. The initial path configuration is three paths: Path 1 (PoP1 → PoP2 → PoP5), Path 2 (PoP1 → PoP3 → PoP5), Path 3 (PoP1 → PoP4 → PoP5), where PoP1 is the source PoP node, PoP5 is the target PoP node, and PoP2, PoP3, and PoP4 are intermediate PoP nodes. Multipath transmission increases the difficulty for attackers to forge the source address and improves the security of the network.
[0057] Furthermore, since the higher the dispersion score indicates the stronger the independence of the paths in the path set, the optimal path set is selected according to the path dispersion score and the bandwidth requirement to ensure the independence between paths. The traffic allocation is optimized through a linear programming model to ensure load balancing on each path, and the optimized path set and its traffic allocation scheme are sent to the relevant PoP nodes. Path optimization improves the network transmission efficiency and resource utilization rate, and at the same time reduces the risk of single point of failure.
[0058] The third step is the data transmission phase.
[0059] Specifically, the source PoP node (PoP1) receives the data packets sent by AS1, determines the number of shards (e.g., 3 shards) according to the data packet size, network bandwidth condition, and security threat level. Each shard contains an authentication token and a verification identifier generated by the HMAC-SHA256 algorithm and the session key. Data sharding reduces the risk of a single data packet being tampered with and improves the flexibility of transmission at the same time.
[0060] Among them, after sending the shards, the source PoP node adds corresponding records to the verification table. The expiration time of the records is set to the current time plus twice the estimated round-trip time of the path. Records exceeding the expiration time will be automatically cleared to release the table space.
[0061] Among them, the unique verification identifier of each shard contains the following fields: original data packet ID (16 bits): used to identify different shards of the same data packet; shard sequence number (8 bits): identifies the position of the current shard among all shards (from 1 to N); total number of shards (8 bits): identifies how many shards the original data packet is divided into; timestamp (32 bits): identifies the generation time of the shard, used to prevent replay attacks; path identifier (16 bits): identifies the predetermined path that the shard will use; shard verification code (32 bits): a verification code generated using the HMAC algorithm and the session key.
[0062] Specifically, the payload of the original data packet is evenly divided into N parts according to the size. A new IP header is created for each shard, containing the original source IP and destination IP. A special shard header is inserted between the IP header and the data, containing the above shard marking information. The checksum field of each shard is updated to ensure data integrity.
[0063] Furthermore, the three shards are respectively assigned to three independent paths for transmission. Each path transmits one shard. Intermediate PoP nodes (such as PoP2, PoP3, PoP4) verify whether the source address of the shard matches the expected ingress interface according to the local verification table. If not, the shard is discarded. The distributed verification mechanism ensures the security of the data packet during transmission. Any forged or tampered data packet will be discarded in a timely manner.
[0064] Among them, the shard allocation is optimized according to the path characteristics. For example, smaller shards are assigned to slower paths, and larger shards are assigned to faster paths to balance the arrival time. Routing information of the corresponding path is added to each shard, the TTL value is set, and the information of the sent shards, including shard ID, sending time, expected arrival time, etc., is recorded in the verification table. The shards are handed over to the network forwarding module and start to be transmitted on their respective paths.
[0065] The fourth step is the verification and recombination phase.
[0066] Specifically, after the target PoP node (PoP5) receives all the shards, it first verifies the integrity and authenticity of the shards, including checking the validity of the shard ID and timestamp, and verifying the shard verification code using the session key. The strict verification process ensures that only legitimate and unmodified data packets can enter the target network.
[0067] It is worth mentioning that when each intermediate PoP node and the target PoP node receive a shard, they first extract the shard header information, including the source IP prefix, shard ID, path ID, and verification identifier, and then query the local verification table to check if there is a matching entry. Specifically, the verification content includes: confirming whether the source IP prefix of the shard is in the list of registered legitimate prefixes, checking whether the shard arrives from the expected ingress interface, verifying whether the timestamp is within the allowed time window (usually ±30 seconds), and if there is a corresponding session key locally, recalculating the verification identifier and comparing it with the VI in the shard. If the verification passes, the shard is forwarded to the next hop; if the verification fails, the reason for the failure is recorded, the shard is discarded, and an exception is reported to the central controller.
[0068] It should be noted that in addition to performing the verification steps of the intermediate nodes, the target PoP node also conducts additional integrity checks: collecting all the shards of the same data packet, checking whether the number of shards is complete; verifying whether the source and destination addresses of each shard are consistent; checking whether the shard sequence numbers are consecutive without missing or duplicate; verifying whether the timestamps of all shards are within a reasonable time window. Only when all verification steps pass can the target PoP node perform data packet recombination and forwarding processing.
[0069] Furthermore, the verified shards are stored in the recombination buffer. After all shards arrive, the payload part is extracted according to the shard sequence number order for reconstruction to obtain the original data packet. Data recombination restores the content of the original data packet, ensuring data integrity and availability.
[0070] Specifically, according to the "total number of shards" field in the shard header, determine the number of shards to wait for, set a recombination timeout timer. If all shards are not received within the predetermined time (usually 100 - 500 ms, configurable), discard all the received shards, check the "shard sequence number" fields of all received shards to confirm that there are no missing or duplicate shards, extract the payload parts of all shards in the shard sequence number order, and splice these payloads in the correct order to reconstruct the complete payload of the original data packet.
[0071] Furthermore, perform a final source address verification and legality verification on the recombined data packet. If the verification passes, forward it to the target customer network (AS7). The final verification ensures the security of the data packet during transmission and recombination, preventing any potential security threats.
[0072] Specifically, create a new IP header containing the original source IP and destination IP addresses, calculate and set the new checksum field to ensure the integrity of the reassembled packet, perform a final source address verification on the complete reassembled packet, and check the legality of the reassembled packet, including protocol compliance and application layer data consistency. If the verification passes, forward the reassembled packet to the target customer network and update the record of this data communication in the verification table, including metrics such as successful reception time and reassembly delay.
[0073] Among them, if any fragment is missing, the timeout is not reached, or the verification fails, the system will immediately discard all related fragments, release the buffer resources, and report the abnormal situation to the central controller, including information such as the type of abnormality and the occurrence path, and send an ICMP error message to the source PoP node, indicating the reason for the reassembly failure and controlling the frequency to prevent DoS attacks.
[0074] During the verification process of all intermediate PoP nodes and the target PoP node, for minor abnormalities (such as excessive delay of a single fragment), log the information, which may trigger a degradation of the path quality; for general abnormalities (such as mismatched verification identifiers), discard the fragment and report it to the central controller; for serious abnormalities (such as detecting a forged attack pattern), immediately discard all related fragments, send a high-priority alert to the central controller, trigger an emergency path update, and temporarily block the traffic of the suspicious source prefix.
[0075] Furthermore, the central controller aggregates the verification failure events reported by each PoP node, conducts pattern analysis, and implements different levels of responses for different types of abnormalities: for random failures (caused by network jitter), adjust the path quality score; for concentrated failures (specific path problems), temporarily disable the problematic path; for persistent failures or attacks, increase the security weight of the target path and increase the path update frequency; for maintaining the global security threat index, adjust the path selection and update strategy.
[0076] Through the above process, in the embodiments of the present invention, from the initial connection and authentication, path planning, data transmission to verification and reassembly, advanced technical means are incorporated in each stage, ensuring the security and reliability of network communication. At the same time, mechanisms such as high-frequency topology information collection, multi-path transmission, and distributed verification jointly constitute the security defense line of the system, effectively resisting various network attacks.
[0077] In an application scenario, a large e-commerce platform often faces the threat of distributed denial of service (DDoS) attacks during promotional activities. Attackers use forged source IP addresses to initiate a large number of connection requests, especially SYN flood attacks, exhausting the platform's network resources and preventing legitimate users from accessing normally. To effectively defend against such attacks, the platform has deployed a multi-path distributed source address verification system based on NFV technology. Figure 2 shows the protection deployment architecture diagram of the e-commerce platform. Figure 3 shows the dynamic changes of system parameters over time.
[0078] As Figure 2 shown, the e-commerce platform's data center is located in the central position, responsible for processing all transaction requests and data storage; PoP nodes (PoP1 - PoP5) are distributed in the edge network of the e-commerce platform, forming a virtual secure perimeter network. Each PoP node has the function of source address verification and is coordinated by the central security controller (SC); customer traffic (Customers A, B, C) connects to the nearest PoP node from various regions through the Internet and enters the system. It is transmitted and verified through multiple paths and finally reaches the platform's data center; the control information flow represented by the dotted line is used to show the transmission path of control signals between the central controller and each PoP node, including path planning, security policy updates, etc.; the data traffic path represented by the solid line is used to show the transmission path of user requests from the PoP node to the e-commerce platform's data center and the return path of response data.
[0079] Specifically, the multi-path distributed source address verification in this scenario can include the following steps: Step S1, system initialization and prefix registration.
[0080] Specifically, the e-commerce platform registers its legitimate IP prefixes into the system. The central controller initializes the verification table, binds the legitimate prefixes to the corresponding entry interfaces, and generates and distributes the initial session keys to each PoP node to ensure communication security.
[0081] Among them, after the user accesses the e-commerce platform server, the user's request data packet arrives at the entry PoP1. PoP1 verifies the legitimacy of the source address. PoP1 divides the request into 3 fragments. Each fragment contains an authentication token and a verification identifier, corresponding to different transmission paths respectively. Fragment 1 is transmitted through Path 1 (PoP1 → PoP2 → PoP5 → e-commerce platform data center), Fragment 2 is transmitted through Path 2 (PoP1 → PoP3 → PoP5 → e-commerce platform data center), and Fragment 3 is transmitted through Path 3 (PoP1 → PoP4 → PoP5 → e-commerce platform data center).
[0082] Further, the intermediate PoP nodes PoP2, PoP3, and PoP4 perform source address verification on the received fragments respectively to ensure the legal source of the fragments. After receiving all the fragments, the e-commerce platform data center reorganizes them, verifies the integrity and authenticity of the data, and then returns the response to the user through a similar multi-path process.
[0083] When the attack traffic reaches the system, the attacker initiates a large number of connection requests using a forged source IP address. The traffic reaches PoP1, and PoP1 conducts a preliminary verification and finds that the source address is suspicious, but it is temporarily unable to confirm whether it is attack traffic. The attack packets are fragmented and forwarded along multiple paths in an attempt to bypass single-point defense. The intermediate PoP nodes (PoP2, PoP3, and PoP4) conduct in-depth verification on the fragments and find that the verification identifiers do not match or the source address does not match the expected ingress interface. The relevant fragments are discarded, and the verification failure information is reported to the central controller. The controller records the abnormal traffic pattern, and the central controller analyzes the abnormal pattern and updates the defense strategy, such as temporarily blocking the traffic of the suspicious source prefix or increasing the verification intensity.
[0084] After detecting the attack, the system automatically increases the path update frequency (e.g., from once every 5 minutes to once every 30 seconds) to increase the difficulty for the attacker to predict the communication path, then increases the number of transmission paths (e.g., from 3 to 5), and selects a more dispersed set of paths to prevent the attacker from concentrating on attacking a single path. At the same time, the verification intensity is increased, and integrity verification is performed on more nodes to ensure that the data has not been tampered with during transmission.
[0085] As Figure 3 shown, the top is the curve of the path update frequency change, the middle is the path selection change, and the bottom is the verification intensity adjustment. An attack is detected at time t1, and the system automatically makes the following adjustments: the path update frequency is increased from once every 5 minutes to once every 30 seconds, the number of transmission paths is increased from 3 to 5, and a more dispersed set of paths is selected, and the verification intensity is increased, and integrity verification is performed on more nodes. As the attack intensity weakens at time t2, the system gradually resumes the normal configuration and optimizes resource usage. Figure 3 The curves in
[0086] show the dynamic changes of the system parameters over time, demonstrating the adaptive ability of the system. Through the above process, this large e-commerce platform effectively defends against DDoS attacks by deploying a multi-path distributed source address verification system based on NFV technology, ensuring the normal access of legitimate users. The characteristics of the system, such as high-accuracy attack detection, low false alarm rate, scalability, dynamic defense ability, and friendliness to incremental deployment, provide strong security guarantees for the e-commerce platform. At the same time, the adaptive optimization ability of the system enables it to dynamically adjust the defense strategy according to the network conditions, improving the overall performance and reliability of the system and ensuring the stable operation of the e-commerce platform during promotional activities.
[0087] The following is an embodiment of the device of the present invention, which can be used to execute the source address verification method involved in the present invention. For the details not disclosed in the embodiment of the device of the present invention, please refer to the method embodiment of the source address verification method involved in the present invention.
[0088] Please refer to Figure 4 , in the embodiment of the present invention, a source address verification device 800 is provided.
[0089] The source address verification device 800 includes but is not limited to: a connection and authentication module 810, a path planning module 830, a data transmission module 850, and a verification and recombination module 870.
[0090] Among them, the connection and authentication module 810 is used to perform identity authentication on the access network and the source PoP node through a two-way authentication mechanism, obtain the source prefix information of the access network and bind the ingress interface.
[0091] The path planning module 830 is used to obtain the status information of all PoP nodes and links, calculate multiple independent paths according to the status information, determine the optimal path set according to the path dispersion score, and optimize the traffic distribution.
[0092] The data transmission module 850 is used to receive data packets through the source PoP node, fragment the data packets according to a preset fragmentation strategy to obtain multiple fragments and mark them, and transmit each fragment to the target PoP node based on the optimal path set.
[0093] The verification and recombination module 870 is used to perform integrity and authenticity verification on each fragment through the target PoP node, recombine the verified fragments to obtain the original data packet, perform source address verification and legality verification on the original data packet, and forward it to the access network after passing the verification.
[0094] It should be noted that when the source address verification is provided in the above embodiment, only the above division of each functional module is used for illustration. In actual application, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the source address verification device will be divided into different functional modules to complete all or part of the functions described above.
[0095] In addition, the source address verification device provided in the above embodiment and the embodiment of the source address verification method belong to the same concept. The specific ways in which each module performs operations have been described in detail in the method embodiment, and will not be repeated here.
[0096] Figure 5 The structural schematic diagram of an electronic device shown according to an exemplary embodiment.
[0097] It should be noted that the electronic device is only an example adapted to the present invention and should not be considered as providing any limitation to the scope of use of the present invention. Nor can the electronic device be construed as requiring dependence on or necessarily having Figure 5 one or more components in the illustrated exemplary electronic device 2000.
[0098] The hardware structure of the electronic device 2000 may vary significantly due to different configurations or performances. For example, Figure 5 as shown, the electronic device 2000 includes: a power supply 210, an interface 230, at least one memory 250, and at least one central processing unit (CPU) 270.
[0099] Specifically, the power supply 210 is used to provide operating voltage for each hardware device on the electronic device 2000.
[0100] The interface 230 includes at least one wired or wireless network interface 231 for interacting with external devices. Of course, in other examples adapted to the present invention, the interface 230 may further include at least one serial-to-parallel conversion interface 233, at least one input / output interface 235, and at least one USB interface 237, etc. Figure 5 as shown, and no specific limitation is constituted hereby.
[0101] The memory 250, as a carrier for resource storage, can be a read-only memory, a random access memory, a magnetic disk, an optical disk, etc. The resources stored thereon include an operating system 251, application programs 253, and data 255, etc. The storage method can be transient storage or permanent storage.
[0102] Among them, the operating system 251 is used to manage and control each hardware device and application program 253 on the electronic device 2000 to enable the central processing unit 270 to perform operations and processing on the massive data 255 in the memory 250. It can be Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSD TM, etc.
[0103] The application program 253 is a computer-readable instruction that completes at least one specific task based on the operating system 251. It may include at least one module ( Figure 5 not shown), and each module can separately contain computer-readable instructions for the electronic device 2000. For example, the source address verification device can be regarded as an application program 253 deployed on the electronic device 2000.
[0104] The data 255 can be signal information, etc., and is stored in the memory 250.
[0105] The central processing unit 270 may include one or more processors, and is configured to communicate with the memory 250 through at least one communication bus, so as to read computer-readable instructions stored in the memory 250, and further implement the operation and processing of the massive data 255 in the memory 250. For example, the source address verification method is completed by reading a series of computer-readable instructions stored in the memory 250 through the central processing unit 270.
[0106] In addition, the present invention can also be implemented by a hardware circuit or a combination of a hardware circuit and software. Therefore, the implementation of the present invention is not limited to any specific hardware circuit, software, and the combination of the two.
[0107] Please refer to Figure 6 , in the embodiment of the present invention, an electronic device 4000 is provided. The electronic device 4000 may include: a desktop computer, a laptop computer, a server, etc. with sensor recognition capabilities.
[0108] In Figure 6 , the electronic device 4000 includes at least one processor 4001 and at least one memory 4003.
[0109] Among them, the data interaction between the processor 4001 and the memory 4003 can be realized through at least one communication bus 4002. The communication bus 4002 may include a path for transmitting data between the processor 4001 and the memory 4003. The communication bus 4002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The communication bus 4002 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 6 only a thick line is shown in
[0110] but it does not mean that there is only one bus or one type of bus. Optionally, the electronic device 4000 may further include a transceiver 4004. The transceiver 4004 can be used for data interaction between the electronic device and other electronic devices, such as data sending and / or data receiving, etc. It should be noted that in practical applications, the transceiver 4004 is not limited to one, and the structure of the electronic device 4000 does not constitute a limitation to the embodiment of the present invention.
[0111] The processor 4001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logical blocks, modules, and circuits described in connection with the disclosure of the present invention. The processor 4001 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0112] The memory 4003 may be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory), or other type of dynamic storage device that can store information and instructions. It may also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or any other medium that can be used to carry or store desired program instructions or code in the form of instruction or data structures and can be accessed by the electronic device 4000, but is not limited thereto.
[0113] Computer-readable instructions are stored on the memory 4003, and the processor 4001 can read the computer-readable instructions stored in the memory 4003 through the communication bus 4002.
[0114] The computer-readable instructions are executed by one or more processors 4001 to implement the source address verification method in the above embodiments.
[0115] In addition, an embodiment of the present invention provides a storage medium on which computer-readable instructions are stored, and the computer-readable instructions are executed by one or more processors to implement the source address verification method as described above.
[0116] In an embodiment of the present invention, a computer program product is provided. The computer program product includes computer-readable instructions stored in a storage medium. One or more processors of an electronic device read the computer-readable instructions from the storage medium, load and execute the computer-readable instructions, so that the electronic device implements the source address verification method described above.
[0117] Compared with the related art, the beneficial effects of the present invention are as follows: 1. The present invention can perform attack detection with high accuracy; through a multi-path distributed verification mechanism, it is required that the attacker must forge verification information on multiple independent paths simultaneously, thereby significantly reducing the verification success rate and achieving high-accuracy attack detection.
[0118] 2. The present invention features a low false alarm rate; by setting the rule that only when all path verifications fail is it determined as attack traffic, combined with the multi-path independent verification mechanism, it ensures that a single path verification error will not trigger interception, and legitimate traffic is not affected by single-point failures, thus achieving a low false alarm rate.
[0119] 3. The present invention has system scalability; by adopting the NFV architecture and the distributed verification mechanism, the computing load is dispersed to multiple nodes, achieving traffic sharding and distributed processing, reducing the single-node load, enabling the system to handle larger traffic, and having good scalability.
[0120] 4. The present invention has dynamic defense capabilities; through an adaptive path update algorithm, it can dynamically adjust path selection and update frequency, and perform dynamic path updates according to threat monitoring results, making it difficult for attackers to predict communication paths, thereby enhancing the defense intensity.
[0121] 4. The present invention has the characteristic of being friendly to incremental deployment; through virtualization based on NFV, without changing existing network devices, it can be seamlessly integrated with the existing infrastructure through virtualized PoP nodes and edge deployment, reducing the deployment threshold.
[0122] 5. The present invention can ensure business continuity; by effectively defending against DDoS attacks, it ensures the stable operation of application scenarios and network platforms under special circumstances, thereby ensuring business continuity.
[0123] 6. The present invention helps to improve the user experience; by defending against DDoS attacks, it ensures the normal access of legitimate users, reduces the situation where users cannot access the platform due to attacks, and thus improves the user experience.
[0124] 7. The present invention helps to reduce operation and maintenance costs; through the system's adaptive optimization ability, it can dynamically adjust defense strategies according to network conditions, reducing the need for manual intervention, and thus reducing operation and maintenance costs.
[0125] It should be understood that although the steps in the flowchart of the accompanying drawings are shown sequentially according to the indication of the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless there is a clear indication in this document, there is no strict order restriction for the execution of these steps, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0126] The above are only some embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A source address verification method, characterized in that, The method includes: Authenticate the access network and the source PoP node through a two-way authentication mechanism, obtain the source prefix information of the access network and bind the ingress interface; Obtain the status information of all PoP nodes and links, calculate multiple independent paths according to the status information, determine the optimal path set according to the path diversity score, and optimize the traffic allocation; Receive data packets through the source PoP node, fragment the data packets according to a preset fragmentation policy to obtain multiple fragments and mark them, and transmit each fragment to the target PoP node based on the optimal path set; Verify the integrity and authenticity of each fragment through the target PoP node, recombine the verified fragments to obtain the original data packet, perform source address verification and legality verification on the original data packet, and forward it to the access network after passing the verification.
2. The source address verification method according to claim 1, wherein The obtaining the status information of all PoP nodes and links, calculating multiple independent paths according to the status information, determining the optimal path set according to the path diversity score, and optimizing the traffic allocation includes: Obtain the status information of all PoP nodes and links at a set frequency through the SDN southbound interface; the status information includes CPU load, memory usage bandwidth, latency, and historical security records; Allocate an initial security weight to each link, use the Dijkstra algorithm to calculate the shortest path with the security weight, and obtain a path set by iteratively calculating the remaining paths; Define the overall diversity score of the path set, select the path set whose diversity score meets the set conditions and meets the bandwidth requirements as the optimal path set, and solve the optimal traffic allocation problem through a linear programming model to optimize the traffic allocation.
3. The source address verification method according to claim 1, characterized in that After determining the optimal path set, it further includes: Set a basic update interval for the paths that need to be updated periodically and initialize a timer. When the timer decrements to zero, collect the current network topology information; Recalculate the optimal path set and traffic allocation according to the current network topology information, path diversity score, and bandwidth requirements, and reset the timer; Dynamically adjust the update interval according to the security threat level, and perform path update immediately in special cases; the special cases include network topology changes, detected suspicious attack attempts, or manual trigger of update commands.
4. The source address verification method according to claim 1, characterized in that The fragmenting the data packet according to a preset fragmentation policy to obtain multiple fragments and mark them, and transmitting each fragment to the target PoP node based on the optimal path set includes: Determine the number of fragments according to the header information of the data packet, network bandwidth condition, and security threat level, fragment the data packet according to the number of fragments to obtain multiple fragments and generate routing information; Generate a verification identifier for each fragment through the HMAC-SHA256 algorithm and a session key, and create an IP header and a fragment header for each fragment; the fragment header contains fragment marking information; Allocate each fragment to each independent path in the optimal path set and transmit them to the target PoP node simultaneously, and optimize the fragment allocation according to the path characteristics.
5. The source address verification method according to claim 4, wherein, Performing integrity and authenticity verification on each of the shards by the target PoP node, and recombining the shards that pass the verification to obtain the original data packet, includes: Verifying the legality of each of the shards by the target PoP node according to the shard header information of each of the shards and the local verification table, and checking whether the source address of each of the shards matches the ingress interface; Storing the shards that pass the verification into the recombination buffer, setting a recombination timeout timer according to the number of the shards, and discarding all the received shards if all the shards are not received within a predetermined time; Extracting the payload parts of all the shards in the order of the shard sequence numbers in the shard header information for reconstruction to obtain the original data packet.
6. The source address verification method according to claim 1, characterized in that Before performing integrity and authenticity verification on each of the shards by the target PoP node, it further includes: After receiving the shard, the intermediate PoP node queries the local SAV table of the shard and verifies whether the source address of the shard matches the ingress interface; Verifying whether the verification identifier in the shard header of the shard is tampered with. If the verification fails, the intermediate PoP node will discard the shard and report an abnormal situation.
7. The source address verification method according to claim 1, characterized in that, After performing integrity and authenticity verification on each of the shards by the target PoP node, it further includes: Verifying the consistency of the number, source target, and target address of all the shards, the continuity of the sequence numbers, and the validity of the timestamps. If the target PoP node detects a situation of shard loss, timeout, or verification failure, immediately discard all relevant shards and release resources, and at the same time report the abnormal type and the relevant path; Sending an ICMP error message to the source PoP node and controlling the frequency to avoid a DoS attack, and classifying the abnormal situation into minor, general, and severe according to the severity of the abnormality; For minor abnormalities, record the log and degrade the quality of the corresponding path. For general abnormalities, discard the corresponding shard and report it. For severe abnormalities, discard all shards, send a high-priority alarm, trigger an emergency path update, and block the suspicious source traffic.
8. A source address verification device, characterized in that, The device includes: A connection and authentication module, configured to perform identity authentication on the access network and the source PoP node through a two-way authentication mechanism, obtain the source prefix information of the access network, and bind the ingress interface; A path planning module, configured to obtain the status information of all PoP nodes and links, calculate multiple independent paths according to the status information, determine an optimal path set according to the path dispersion score, and optimize the traffic allocation; A data transmission module, configured to receive a data packet through the source PoP node, shard the data packet according to a preset sharding strategy to obtain multiple shards and mark them, and transmit each of the shards to the target PoP node based on the optimal path set; A verification and recombination module, configured to perform integrity and authenticity verification on each of the shards by the target PoP node, recombine the shards that pass the verification to obtain the original data packet, perform source address verification and legality verification on the original data packet, and forward it to the access network after passing the verification.
9. An electronic device, characterized in that, Includes: At least one processor and at least one memory, wherein, Computer-readable instructions are stored on the memory; The computer-readable instructions are executed by one or more of the processors, so that the electronic device implements the source address verification method according to any one of claims 1 to 7.
10. A storage medium having computer-readable instructions stored thereon, characterized in that, The computer-readable instructions are executed by one or more processors to implement the source address verification method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Large-scale Internet of Things service domain isolation communication method and device, electronic equipment and storage medium
CN114172930A
Near-source DDoS defense method based on bidirectional source address verification
CN118432903A
Source address verification method and device based on virtual network, controller and medium
CN119561782A
Intra-domain source address validation using igps
WO2024010950A1
Cited By
Path verification method and system based on bloom filter storage link proof
CN120811665A
Network data security encryption transmission method and system
CN122001680A