Inter-Domain Source Address Validation With Targeted AS Signaling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing inter-domain source address validation methods incur significant communication and calculation overheads due to the need to send validation information to all autonomous systems (ASs) along the forwarding path, leading to inefficient and resource-intensive network operations.
Innovation Solution
A method where a first network device in an autonomous system (AS) sends validation information and neighbor AS details only to a specified validation AS, reducing the need to communicate with all ASs along the path, by determining and sending validation information to a previous-hop AS, thereby optimizing communication overheads.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If source address validation is performed in different autonomous systems using DSAV scheme, then source address spoofing attacks can be prevented, but communication overheads and calculation overheads increase significantly
Solution Approach 1:
The patent applies local quality by making the validation AS a special node with different functionality from other ASs in the path. The validation AS receives validation information and performs source address validation, while other ASs simply forward packets. This localized validation approach prevents spoofing attacks without requiring all ASs to participate in validation, thereby reducing communication overheads.
Solution Approach 2:
The patent introduces a validation AS as an intermediary between the source AS and the destination AS. This validation AS receives validation information from the source AS and uses it to validate source addresses of packets. The intermediary validates packets without requiring direct communication between all ASs in the path, reducing overall communication overheads.
2Reliability
If source address validation is performed in different autonomous systems using DSAV scheme, then source address spoofing attacks can be prevented, but calculation overheads increase due to large quantity of ASs involved
Solution Approach 1:
The patent applies local quality by making the validation AS a special node with different functionality from other ASs in the path. The validation AS receives validation information and performs source address validation, while other ASs simply forward packets. This localized validation approach prevents spoofing attacks without requiring all ASs to participate in validation, thereby reducing communication overheads.
Solution Approach 2:
The patent extracts the validation function from all ASs and concentrates it in a specific validation AS. Instead of requiring every AS to perform validation calculations, the validation information is sent only to the validation AS, which then handles all validation operations. This extraction reduces calculation overheads by eliminating redundant validation operations in non-validation ASs.
3Reliability
If validation information is sent to all ASs along the forwarding path, then comprehensive source address validation can be achieved, but communication overheads increase
Solution Approach 1:
The patent introduces a validation AS as an intermediary between the source AS and the destination AS. This validation AS receives validation information from the source AS and uses it to validate source addresses of packets. The intermediary validates packets without requiring direct communication between all ASs in the path, reducing overall communication overheads.
Solution Approach 2:
The patent extracts the validation function from all ASs and concentrates it in a specific validation AS. Instead of requiring every AS to perform validation calculations, the validation information is sent only to the validation AS, which then handles all validation operations. This extraction reduces calculation overheads by eliminating redundant validation operations in non-validation ASs.
Data Source
Figure 1a~1b
Figure 2
Figure 3~4
AI summary
This application discloses a validation information sending method, a validation entry obtaining method, an apparatus, and a device. A first network device in a first AS serving as an origin autonomous system AS obtains validation information corresponding to the first AS and a neighbor AS corresponding to a second AS used for validation, where the neighbor AS is a previous-hop AS of the second AS in a direction from the first AS to the second AS. The first network device sends the validation information and the neighbor AS to the second AS, and the validation AS obtains a validation entry based on the validation information and the neighbor AS, and performs validation on a source address of a received service packet based on the validation entry. In other words, in this application, the first AS may send, to the validation AS, the validation information and the neighbor AS corresponding to the validation AS, and does not need to send the validation information to all ASs on a path with the first AS as an origin AS. In this way, communication overheads are reduced.