Inter-domain DDoS Mitigation via Authorization Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current DDoS mitigation systems face challenges in effectively managing the sharing of sensitive information with untrusted secondary service providers, potentially leading to security breaches during DDoS attacks, as they lack mechanisms to control the leakage of proprietary data and ensure secure authorization.

Innovation Solution

A mitigation management system that allows a client device to securely select and authorize secondary servers for mitigation services by generating a list of approved servers, using authorization tokens like OAuth 2.0, to ensure only trusted servers access mitigation resources, thereby controlling data flow and preventing unauthorized information leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the primary server shares sensitive attack information with secondary service providers to enable effective DDoS mitigation, then the mitigation capability is improved, but the security risk increases due to potential data leakage to untrusted providers

Engineering Contradiction:
ImproveDDoS mitigation capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an authorization token mechanism as an intermediary between the primary server and secondary service providers. The token acts as a mediator that enables controlled information sharing - the primary server can provide necessary attack mitigation information to secondary providers without directly exposing sensitive data, thus maintaining security while enabling effective mitigation collaboration

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If the system allows multiple secondary servers to provide mitigation services, then the mitigation resources increase, but the system complexity increases due to managing trust and authorization across multiple providers

Engineering Contradiction:
Improvemitigation resourcesVSAvoidauthorization management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the authorization management process into distinct components: the primary server generates and distributes authorization tokens to multiple secondary providers, and each secondary provider independently validates these tokens. This segmentation allows the system to manage multiple mitigation resources without proportionally increasing central coordination complexity, as each provider autonomously handles token validation

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10305931B2Inter-domain distributed denial of service threat signaling
Publication Date: 2019.05.28 CISCO TECHNOLOGY INC
  • US10305931B2 patent drawing
  • US10305931B2 patent drawing
  • US10305931B2 patent drawing

AI summary

In one embodiment, a primary server receives, from a client device, a first request to mitigate an external attack on the client device. The primary server sends, to a plurality of secondary servers, a second request to mitigate the external attack, wherein each one of the plurality of secondary servers has associated mitigation resources, and receives from at least one of the plurality of secondary servers an indication that it has mitigation resources capable of mitigating the external attack. The primary server sends, to the client device, a list including the secondary servers having mitigation resources capable of mitigating the attack, and receives, from the client device, an indication that a subset of the list is selected to mitigate the external attack. In response, the primary server sends a request for mitigation services to one of the secondary servers in the subset selected to mitigate the external attack.