Inter-Domain Source Address Validation With Targeted AS Signaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing inter-domain source address validation methods incur significant communication and calculation overheads due to the need to send validation information to all autonomous systems (ASs) along the forwarding path, leading to inefficient and resource-intensive network operations.

Innovation Solution

A method where a first network device in an autonomous system (AS) sends validation information and neighbor AS details only to a specified validation AS, reducing the need to communicate with all ASs along the path, by determining and sending validation information to a previous-hop AS, thereby optimizing communication overheads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If source address validation is performed in different autonomous systems using DSAV scheme, then source address spoofing attacks can be prevented, but communication overheads and calculation overheads increase significantly

Engineering Contradiction:
Improvesource address validationVSAvoidcommunication overheads
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by making the validation AS a special node with different functionality from other ASs in the path. The validation AS receives validation information and performs source address validation, while other ASs simply forward packets. This localized validation approach prevents spoofing attacks without requiring all ASs to participate in validation, thereby reducing communication overheads.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces a validation AS as an intermediary between the source AS and the destination AS. This validation AS receives validation information from the source AS and uses it to validate source addresses of packets. The intermediary validates packets without requiring direct communication between all ASs in the path, reducing overall communication overheads.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If source address validation is performed in different autonomous systems using DSAV scheme, then source address spoofing attacks can be prevented, but calculation overheads increase due to large quantity of ASs involved

Engineering Contradiction:
Improvesource address validationVSAvoidcalculation overheads
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by making the validation AS a special node with different functionality from other ASs in the path. The validation AS receives validation information and performs source address validation, while other ASs simply forward packets. This localized validation approach prevents spoofing attacks without requiring all ASs to participate in validation, thereby reducing communication overheads.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent extracts the validation function from all ASs and concentrates it in a specific validation AS. Instead of requiring every AS to perform validation calculations, the validation information is sent only to the validation AS, which then handles all validation operations. This extraction reduces calculation overheads by eliminating redundant validation operations in non-validation ASs.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If validation information is sent to all ASs along the forwarding path, then comprehensive source address validation can be achieved, but communication overheads increase

Engineering Contradiction:
Improvesource address validation coverageVSAvoidcommunication overheads
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent introduces a validation AS as an intermediary between the source AS and the destination AS. This validation AS receives validation information from the source AS and uses it to validate source addresses of packets. The intermediary validates packets without requiring direct communication between all ASs in the path, reducing overall communication overheads.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the validation function from all ASs and concentrates it in a specific validation AS. Instead of requiring every AS to perform validation calculations, the validation information is sent only to the validation AS, which then handles all validation operations. This extraction reduces calculation overheads by eliminating redundant validation operations in non-validation ASs.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4675979A1Validation information sending method and apparatus, validation table entry acquisition method and apparatus, and device
Publication Date: 2026.01.07 HUAWEI TECH CO LTD
  • EP4675979A1 patent drawingFigure 1a~1b
  • EP4675979A1 patent drawingFigure 2
  • EP4675979A1 patent drawingFigure 3~4

AI summary

This application discloses a validation information sending method, a validation entry obtaining method, an apparatus, and a device. A first network device in a first AS serving as an origin autonomous system AS obtains validation information corresponding to the first AS and a neighbor AS corresponding to a second AS used for validation, where the neighbor AS is a previous-hop AS of the second AS in a direction from the first AS to the second AS. The first network device sends the validation information and the neighbor AS to the second AS, and the validation AS obtains a validation entry based on the validation information and the neighbor AS, and performs validation on a source address of a received service packet based on the validation entry. In other words, in this application, the first AS may send, to the validation AS, the validation information and the neighbor AS corresponding to the validation AS, and does not need to send the validation information to all ASs on a path with the first AS as an origin AS. In this way, communication overheads are reduced.