CGA Authentication for Network Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for preventing Distributed Denial of Service (DDoS) attacks are inadequate in accurately distinguishing between legitimate and malicious connections, leading to potential misjudgment of semi-connections during normal network operations.

Innovation Solution

A method and device that utilize cryptographically generated addresses (CGA) and signature information to authenticate data packets, ensuring the authenticity of source addresses and preventing network attacks by filtering out illegal packets through a data packet receiving, checking, authentication, and sending process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional threshold-based methods are used to detect semi-connections, then the system can monitor connection frequency and delete abnormal connections, but the method cannot precisely distinguish between legitimate and malicious semi-connections, leading to misjudgment errors

Engineering Contradiction:
Improveaccuracy of semi-connection judgmentVSAvoidprecision in distinguishing legitimate and malicious connections
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent replaces the mechanical threshold-based detection system with a cryptographic authentication system. Instead of using numerical thresholds to detect semi-connections, the system uses CGA (Cryptographically Generated Addresses) and digital signatures to verify the authenticity of source addresses. This substitution of detection mechanisms fundamentally improves both reliability and measurement precision by eliminating the inability to distinguish between legitimate and malicious connections.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the detection parameter from connection frequency/threshold values to cryptographic authentication results. By transitioning from monitoring quantitative metrics (number of semi-connections, frequency) to qualitative authentication (CGA verification, signature validation), the system achieves precise distinction between legitimate and malicious connections without misjudgment errors.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If content-based access control is used to filter packets, then the system can monitor and delete semi-connections based on threshold values, but the method introduces device complexity and cannot accurately identify malicious connections during normal operations

Engineering Contradiction:
Improveeffectiveness in preventing DDoS attacksVSAvoidcomplexity of threshold setting and monitoring
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the complex threshold-based content control system with a simpler cryptographic authentication mechanism. Instead of monitoring connection frequencies and setting multiple threshold values, the system verifies CGA parameters and digital signatures on data packets. This substitution reduces device complexity while maintaining or improving DDoS prevention effectiveness through more accurate malicious connection identification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent extracts the essential authentication function from the complex content-based access control system. By focusing solely on verifying the cryptographic authenticity of source addresses through CGA and signatures, the system eliminates the need for complex threshold monitoring and multi-parameter analysis, thereby reducing device complexity while maintaining security effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If routers delete semi-connections based on threshold values, then the system can meet demands for establishing new connections, but the method causes loss of legitimate connections and cannot precisely judge malicious connections

Engineering Contradiction:
Improveavailability of server resourcesVSAvoidaccuracy in identifying malicious connections
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces the threshold-based semi-connection deletion mechanism with cryptographic authentication. Instead of deleting connections based on numerical thresholds that may remove legitimate connections, the system authenticates each connection using CGA and digital signatures. This ensures that only truly malicious connections are blocked, maintaining server resource availability for legitimate clients while improving identification accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent converts the potential harm of overly aggressive connection deletion into a benefit by using cryptographic authentication. The authentication mechanism naturally filters out malicious connections without requiring threshold-based deletion, thereby preventing resource waste on legitimate connections while maintaining security. The cryptographic verification process itself becomes the beneficial filtering mechanism.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS8499146B2Method and device for preventing network attacks
Publication Date: 2013.07.30 CHENGDU HUAWEI TECH CO LTD
  • US8499146B2 patent drawing
  • US8499146B2 patent drawing
  • US8499146B2 patent drawing

AI summary

A method for preventing network attacks is provided, which includes: obtaining a data packet, where a source address of the data packet is a cryptographically generated address (CGA); determining that the obtained data packet includes a CGA parameter and signature information; authenticating the CGA parameter; authenticating the signature information according to the authenticated CGA parameter; and sending the data packet to a destination address when the signature information is authenticated. Accordingly, a device for preventing network attacks is also provided. A CGA parameter used by a data packet is directly used to ensure authenticity of a source address of the data packet, thus preventing network attacks performed by counterfeiting the address. In addition, by authenticating signature information, authenticity of identification of a sender of the data packet and bound address of the sender of the data packet are further ensured. Therefore, illegal data packets are filtered to prevent network attacks on servers, thus improving network security.