Exhaustible Network Resource Management via Environment Trust Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malicious consumption of exhaustible network resources, such as password attempts, leads to unauthorized account locking, affecting normal service operations, as existing systems fail to differentiate between trustable and untrustable environments, resulting in unnecessary resource exhaustion and user inconvenience.
Innovation Solution
A method and apparatus that classify service operation environments as trustable or untrustable, adjusting the resource value of exhaustible network resources accordingly, limiting usage within first-grade or second-grade values based on environment type to prevent malicious consumption and ensure legitimate users retain sufficient resource usage rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the resource value of exhaustible network resources is limited to prevent malicious consumption, then security against malicious use is improved, but normal service availability deteriorates due to false positives
Solution Approach 1:
The patent applies different resource value limits (first-grade for untrustable environments, second-grade for trustable environments) to different service operation environments. This local differentiation allows the system to be more restrictive where needed (preventing malicious consumption) while more permissive where safe (maintaining service availability), thus resolving the contradiction between security and availability
Solution Approach 2:
The patent changes the parameter of resource value limit based on the determined type of service operation environment. By dynamically adjusting the resource value parameter (first-grade vs second-grade limits) according to environment trustworthiness, the system achieves both malicious consumption prevention and normal service maintenance
2Productivity
If the resource value of exhaustible network resources is increased to allow more attempts, then service availability is improved, but vulnerability to malicious consumption increases
Solution Approach 1:
The patent implements location-based quality differentiation by assigning different resource value limits based on the determined type of service operation environment. Trustable environments receive higher limits (second-grade) while untrustable environments receive lower limits (first-grade), thus achieving both availability improvement and malicious consumption protection simultaneously
3Device complexity
If a uniform resource value limit is applied to all service operation environments, then system complexity is reduced, but inability to differentiate between malicious and legitimate use increases
Solution Approach 1:
The patent segments the service operation environment into different types (trustable and untrustable) based on determined characteristics. This segmentation allows the system to apply different resource value limits appropriately, achieving precise differentiation between malicious and legitimate use while maintaining manageable system complexity through clear classification criteria
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An embodiment of the present application discloses a method for using an exhaustible network resource. An exemplary method may include determining a type of the current service operation environment. The type may include a trustable environment and an untrustable environment. The current service operation may be able to influence the resource value of the exhaustible network resource. When the type of the current service operation environment is an untrustable environment, the method may also include limiting the resource value of the exhaustible network resource of the current service operation within a first-grade resource value. When the type of the current service operation environment is a trustable environment, the method may further include limiting the resource value of the exhaustible network resource of the current service operation within a second-grade resource value. The second-grade resource value may be larger than the first-grade resource value. Another embodiment of the present application also discloses an apparatus for using an exhaustible network resource. The implementation of the present application may reduce or avoid the impact on normal service operations caused by malicious consumption of exhaustible network resources.