Authentication Server Anti-Attack Method via CDN and Security Gateway

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies, such as traditional firewalls, have limited anti-attack capabilities due to inflexible defense rules, and some Internet services cannot be protected using Content Delivery Networks (CDN), leaving them vulnerable to attacks.

Innovation Solution

An Internet anti-attack method involving an authentication server that receives service access requests from a content delivery network node group, verifies user information, and sends access authentication requests to a security gateway to determine if the user's IP address has access rights, thereby improving the accuracy of service-serving request evaluation and enhancing anti-attack capabilities by using CDN to hide the authentication server's IP address.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall technology is used for protection, then the resource station IP can be protected with defined security rules, but the anti-attack capability is limited due to inflexible defense rules and cannot adapt to various types of attacks

Engineering Contradiction:
Improveanti-attack capabilityVSAvoiddefense rule flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic defense rules that automatically adjust based on attack detection. The system transitions from static firewall rules to dynamic rules that are generated and updated in real-time based on detected attack patterns, allowing the defense mechanism to adapt to various attack types while maintaining protection effectiveness

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an authentication server as an intermediary between users and the resource station. This server handles authentication and attack detection, allowing the resource station to focus on service delivery while the intermediary manages security complexities, thus improving both anti-attack capability and system adaptability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If CDN is used to hide the resource station IP, then attack traffic can be distributed and handled by multiple nodes, but some Internet services cannot use CDN because the resource station IP needs to be directly exposed to users

Engineering Contradiction:
Improveattack traffic distributionVSAvoidservice deployment flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication and service delivery functions. The authentication server handles security-related authentication requests through CDN nodes, while the resource station IP remains exposed for direct service delivery. This segmentation allows CDN protection for authentication traffic while maintaining service accessibility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication server acts as an intermediary that receives authentication requests from CDN nodes and forwards them to the resource station. This allows CDN to protect the authentication process without preventing direct user access to services, thus maintaining both security benefits and service flexibility

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the resource station directly evaluates and responds to attacks, then all attack traffic enters the resource station, but this pre-empts the resources of the resource station and affects normal operation

Engineering Contradiction:
Improveattack response capabilityVSAvoidnormal operation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the attack evaluation and response function from the resource station and places it in the authentication server. The authentication server专门 handles attack detection and response, while the resource station focuses on normal service delivery, thus preventing attack traffic from preempting resource station resources

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication server serves as an intermediary that filters and evaluates attack traffic before it reaches the resource station. By handling attack responses at the authentication layer, the system protects resource station resources while maintaining attack response capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11019383B2Internet anti-attack method and authentication server
Publication Date: 2021.05.25 CHINANETCENT TECH
  • US11019383B2 patent drawing
  • US11019383B2 patent drawing
  • US11019383B2 patent drawing

AI summary

An Internet anti-attack method includes: an authentication server receives a service access request, sent by a user, from a content delivery network node group through a WEB interface, where the service access request includes an IP address of the user. The authentication server sends an access authentication request to a security gateway, where the access authentication request includes the IP address of the user, and the access authentication request is used to instruct the security gateway to allow a service-serving request that includes the IP address of the user to be sent to the service server.