Network Device TCA Validation via Cryptographic Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network technologies fail to differentiate between legitimate and malicious threshold crossing alerts (TCAs), leading to potential reflection-based attacks that cause network instability and traffic oscillations, as existing methods cannot validate the authenticity of TCAs.

Innovation Solution

Implementing a signature mechanism using encrypted TCAs, machine learning processes to predict and validate TCA authenticity, and peer device validation to confirm the legitimacy of TCAs, thereby mitigating potential network attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If TCA mechanism is used for dynamic path selection, then network performance optimization is improved, but network security deteriorates due to reflection-based attacks

Engineering Contradiction:
Improvenetwork performance optimizationVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by signing TCAs with cryptographic keys before transmission and validating signatures upon receipt. This preemptive security measure ensures that only authentic TCAs from authorized peer devices can trigger path selection changes, preventing reflection-based attacks while maintaining the dynamic path optimization capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Cryptographic signature verification acts as an intermediary validation layer between TCA generation and path selection execution. The signature mechanism mediates the trust relationship, allowing the system to accept TCAs from peer devices without directly trusting their assertions, thus resolving the security-risk contradiction

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If TCA validation mechanisms are implemented, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidvalidation mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses cryptographic signature pairs (public/private keys) as disposable validation objects. Each peer device generates its own signature pair, and the signatures are single-use validation tokens that verify TCA authenticity without requiring complex ongoing validation infrastructure, keeping the complexity manageable

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS9813314B2Mitigating reflection-based network attacks
Publication Date: 2017.11.07 CISCO TECHNOLOGY INC
  • US9813314B2 patent drawing
  • US9813314B2 patent drawing
  • US9813314B2 patent drawing

AI summary

In one embodiment, a network device routes traffic along a network path and receives a performance threshold crossing alert regarding performance of the network path. The network device detects that the performance threshold crossing alert is part of a potential network attack by analyzing, by the device, the performance threshold crossing alert. The network device also provides a notification of the detected network attack.