Authentication Server Anti-Attack Method via CDN and Security Gateway
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security technologies, such as traditional firewalls, have limited anti-attack capabilities due to inflexible defense rules, and some Internet services cannot be protected using Content Delivery Networks (CDN), leaving them vulnerable to attacks.
Innovation Solution
An Internet anti-attack method involving an authentication server that receives service access requests from a content delivery network node group, verifies user information, and sends access authentication requests to a security gateway to determine if the user's IP address has access rights, thereby improving the accuracy of service-serving request evaluation and enhancing anti-attack capabilities by using CDN to hide the authentication server's IP address.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall technology is used for protection, then the resource station IP can be protected with defined security rules, but the anti-attack capability is limited due to inflexible defense rules and cannot adapt to various types of attacks
Solution Approach 1:
The patent implements dynamic defense rules that automatically adjust based on attack detection. The system transitions from static firewall rules to dynamic rules that are generated and updated in real-time based on detected attack patterns, allowing the defense mechanism to adapt to various attack types while maintaining protection effectiveness
Solution Approach 2:
The patent introduces an authentication server as an intermediary between users and the resource station. This server handles authentication and attack detection, allowing the resource station to focus on service delivery while the intermediary manages security complexities, thus improving both anti-attack capability and system adaptability
2Reliability
If CDN is used to hide the resource station IP, then attack traffic can be distributed and handled by multiple nodes, but some Internet services cannot use CDN because the resource station IP needs to be directly exposed to users
Solution Approach 1:
The patent segments the authentication and service delivery functions. The authentication server handles security-related authentication requests through CDN nodes, while the resource station IP remains exposed for direct service delivery. This segmentation allows CDN protection for authentication traffic while maintaining service accessibility
Solution Approach 2:
The authentication server acts as an intermediary that receives authentication requests from CDN nodes and forwards them to the resource station. This allows CDN to protect the authentication process without preventing direct user access to services, thus maintaining both security benefits and service flexibility
3Reliability
If the resource station directly evaluates and responds to attacks, then all attack traffic enters the resource station, but this pre-empts the resources of the resource station and affects normal operation
Solution Approach 1:
The patent extracts the attack evaluation and response function from the resource station and places it in the authentication server. The authentication server专门 handles attack detection and response, while the resource station focuses on normal service delivery, thus preventing attack traffic from preempting resource station resources
Solution Approach 2:
The authentication server serves as an intermediary that filters and evaluates attack traffic before it reaches the resource station. By handling attack responses at the authentication layer, the system protects resource station resources while maintaining attack response capability
Data Source
AI summary
An Internet anti-attack method includes: an authentication server receives a service access request, sent by a user, from a content delivery network node group through a WEB interface, where the service access request includes an IP address of the user. The authentication server sends an access authentication request to a security gateway, where the access authentication request includes the IP address of the user, and the access authentication request is used to instruct the security gateway to allow a service-serving request that includes the IP address of the user to be sent to the service server.


