Blockchain IP Traceback for Autonomous Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional IP traceback solutions lack record integrity, authenticity, and non-repudiation, making it difficult to identify malicious tampering and trace the source of DDoS attacks, especially with the increasing use of spoofed IP addresses in IoT-based attacks.

Innovation Solution

A blockchain-inspired traceback solution that uses decentralized and distributed storage to create, verify, and audit AS links in the network, ensuring validation and non-repudiation properties among autonomous systems, with cryptographic primitives for transaction verification and digital signatures to secure the traceback path.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional traceback solutions are used, then the system is simple to operate, but the record integrity and authenticity cannot be guaranteed

Engineering Contradiction:
Improverecord integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the traceback process into discrete cryptographic transactions that are independently verified and stored in a distributed ledger. Each AS link is represented as a separate transaction record containing cryptographic signatures, allowing individual verification while maintaining overall system integrity. This segmentation enables reliable tracing without requiring complex centralized verification mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic primitives and digital signatures as intermediaries between autonomous systems. These cryptographic mechanisms act as trusted mediators that provide verification and non-repudiation without requiring direct trust relationships between ASes. The distributed ledger serves as an intermediary storage layer that ensures record integrity while maintaining system decentralization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ASes faithfully mark or log the flow transition, then the traceback information is complete, but malicious tampering cannot be detected

Engineering Contradiction:
Improvetraceback authenticityVSAvoidverification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary cryptographic actions by having ASes sign their traffic markings with digital signatures before the traffic reaches the victim. This preliminary signing ensures that the traceback information is authenticated in advance, allowing detection of any subsequent tampering. The cryptographic verification is performed beforehand rather than requiring complex real-time verification during the tracing process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical logging and verification mechanisms with cryptographic primitives. Instead of relying on ASes to faithfully maintain logs, the system uses digital signatures and hash functions to cryptographically bind traffic markings to their sources. This substitution eliminates the need for complex trust-based verification mechanisms while ensuring authenticity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If spoofed IP addresses are used in attacks, then the attack source is hidden, but traditional traceback methods fail to identify the source

Engineering Contradiction:
Improvesource identification accuracyVSAvoidattack effectiveness
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements a marking mechanism that essentially 'colors' or tags packets with cryptographic identifiers as they pass through each AS. This marking is analogous to changing the color or appearance of the traffic to reveal its provenance. Even when IP addresses are spoofed, the cryptographic markings embedded in the traffic flow maintain the true path information, enabling precise source identification despite the harmful spoofing attack.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS11588833B2Tracing traffic in the internet
Publication Date: 2023.02.21 AGENCY FOR SCI TECH & RES
  • US11588833B2 patent drawing
  • US11588833B2 patent drawing
  • US11588833B2 patent drawing

AI summary

A traceback solution is provided. For a network of autonomous systems, the traceback solution traces the autonomous system path taken by traffic flows. Every link in the traceback path is created, verified, and audited by autonomous systems. Multiple autonomous systems may take part in the process, making the system robust against fake information. The database used to store the validated traceback paths is a decentralized and distributed storage. Multiple copies of the database may be maintained by the network of autonomous systems. The database may be accessible by any participating autonomous system; and is not accessible from outside the network of autonomous systems. The traceback solution achieves both validation and non-repudiation property among the ASes. The traceback solution mitigates some important attack scenarios that might be targeted specifically at the traceback solution.