Inter-domain DDoS Mitigation via Authorization Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current DDoS mitigation systems face challenges in effectively managing the sharing of sensitive information with untrusted secondary service providers, potentially leading to security breaches during DDoS attacks, as they lack mechanisms to control the leakage of proprietary data and ensure secure authorization.
Innovation Solution
A mitigation management system that allows a client device to securely select and authorize secondary servers for mitigation services by generating a list of approved servers, using authorization tokens like OAuth 2.0, to ensure only trusted servers access mitigation resources, thereby controlling data flow and preventing unauthorized information leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the primary server shares sensitive attack information with secondary service providers to enable effective DDoS mitigation, then the mitigation capability is improved, but the security risk increases due to potential data leakage to untrusted providers
Solution Approach 1:
The patent introduces an authorization token mechanism as an intermediary between the primary server and secondary service providers. The token acts as a mediator that enables controlled information sharing - the primary server can provide necessary attack mitigation information to secondary providers without directly exposing sensitive data, thus maintaining security while enabling effective mitigation collaboration
2Quantity of substance
If the system allows multiple secondary servers to provide mitigation services, then the mitigation resources increase, but the system complexity increases due to managing trust and authorization across multiple providers
Solution Approach 1:
The patent segments the authorization management process into distinct components: the primary server generates and distributes authorization tokens to multiple secondary providers, and each secondary provider independently validates these tokens. This segmentation allows the system to manage multiple mitigation resources without proportionally increasing central coordination complexity, as each provider autonomously handles token validation
Data Source
AI summary
In one embodiment, a primary server receives, from a client device, a first request to mitigate an external attack on the client device. The primary server sends, to a plurality of secondary servers, a second request to mitigate the external attack, wherein each one of the plurality of secondary servers has associated mitigation resources, and receives from at least one of the plurality of secondary servers an indication that it has mitigation resources capable of mitigating the external attack. The primary server sends, to the client device, a list including the secondary servers having mitigation resources capable of mitigating the attack, and receives, from the client device, an indication that a subset of the list is selected to mitigate the external attack. In response, the primary server sends a request for mitigation services to one of the secondary servers in the subset selected to mitigate the external attack.


