CGA Authentication for Network Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for preventing Distributed Denial of Service (DDoS) attacks are inadequate in accurately distinguishing between legitimate and malicious connections, leading to potential misjudgment of semi-connections during normal network operations.
Innovation Solution
A method and device that utilize cryptographically generated addresses (CGA) and signature information to authenticate data packets, ensuring the authenticity of source addresses and preventing network attacks by filtering out illegal packets through a data packet receiving, checking, authentication, and sending process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional threshold-based methods are used to detect semi-connections, then the system can monitor connection frequency and delete abnormal connections, but the method cannot precisely distinguish between legitimate and malicious semi-connections, leading to misjudgment errors
Solution Approach 1:
The patent replaces the mechanical threshold-based detection system with a cryptographic authentication system. Instead of using numerical thresholds to detect semi-connections, the system uses CGA (Cryptographically Generated Addresses) and digital signatures to verify the authenticity of source addresses. This substitution of detection mechanisms fundamentally improves both reliability and measurement precision by eliminating the inability to distinguish between legitimate and malicious connections.
Solution Approach 2:
The patent changes the detection parameter from connection frequency/threshold values to cryptographic authentication results. By transitioning from monitoring quantitative metrics (number of semi-connections, frequency) to qualitative authentication (CGA verification, signature validation), the system achieves precise distinction between legitimate and malicious connections without misjudgment errors.
2Reliability
If content-based access control is used to filter packets, then the system can monitor and delete semi-connections based on threshold values, but the method introduces device complexity and cannot accurately identify malicious connections during normal operations
Solution Approach 1:
The patent replaces the complex threshold-based content control system with a simpler cryptographic authentication mechanism. Instead of monitoring connection frequencies and setting multiple threshold values, the system verifies CGA parameters and digital signatures on data packets. This substitution reduces device complexity while maintaining or improving DDoS prevention effectiveness through more accurate malicious connection identification.
Solution Approach 2:
The patent extracts the essential authentication function from the complex content-based access control system. By focusing solely on verifying the cryptographic authenticity of source addresses through CGA and signatures, the system eliminates the need for complex threshold monitoring and multi-parameter analysis, thereby reducing device complexity while maintaining security effectiveness.
3Productivity
If routers delete semi-connections based on threshold values, then the system can meet demands for establishing new connections, but the method causes loss of legitimate connections and cannot precisely judge malicious connections
Solution Approach 1:
The patent replaces the threshold-based semi-connection deletion mechanism with cryptographic authentication. Instead of deleting connections based on numerical thresholds that may remove legitimate connections, the system authenticates each connection using CGA and digital signatures. This ensures that only truly malicious connections are blocked, maintaining server resource availability for legitimate clients while improving identification accuracy.
Solution Approach 2:
The patent converts the potential harm of overly aggressive connection deletion into a benefit by using cryptographic authentication. The authentication mechanism naturally filters out malicious connections without requiring threshold-based deletion, thereby preventing resource waste on legitimate connections while maintaining security. The cryptographic verification process itself becomes the beneficial filtering mechanism.
Data Source
AI summary
A method for preventing network attacks is provided, which includes: obtaining a data packet, where a source address of the data packet is a cryptographically generated address (CGA); determining that the obtained data packet includes a CGA parameter and signature information; authenticating the CGA parameter; authenticating the signature information according to the authenticated CGA parameter; and sending the data packet to a destination address when the signature information is authenticated. Accordingly, a device for preventing network attacks is also provided. A CGA parameter used by a data packet is directly used to ensure authenticity of a source address of the data packet, thus preventing network attacks performed by counterfeiting the address. In addition, by authenticating signature information, authenticity of identification of a sender of the data packet and bound address of the sender of the data packet are further ensured. Therefore, illegal data packets are filtered to prevent network attacks on servers, thus improving network security.


