Source Address Spoofing Detection via Self-Assurance Type ID

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting source address spoofing packets are inadequate as they rely on third-party verification and do not effectively prevent distributed denial of service (DDoS) attacks, as the IP layer lacks the capability to verify packet sources.

Innovation Solution

An authentication method and apparatus that utilize a self-assurance type ID, generated through digital signatures and hashing, to verify the source address of packets within the network layer, allowing only packets with normal source addresses to be forwarded, thereby preventing malicious attacks without third-party intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If statistical techniques or filtering methods are used to detect source address spoofing packets, then detection capability is improved, but the IP layer still cannot verify packet sources and DDoS attacks continue to succeed

Engineering Contradiction:
Improvedetection capabilityVSAvoidsource verification reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements self-service by enabling the IP layer to autonomously verify source addresses through digitally signed certificates embedded in packets. Each packet carries a certificate signed by the source node's private key, allowing receiving nodes to verify authenticity using public keys without requiring third-party intervention or higher-layer protocols, thus making the verification system self-sufficient at the network layer

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces cryptographic certificates as an intermediary mechanism between source and destination nodes. These certificates, containing public keys and signed by authoritative certificate authorities, serve as trusted mediators that enable verification of source identity without requiring direct trust relationships between communicating parties, thus solving the source verification problem at the IP layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If third-party verification methods are used to authenticate packet sources, then authentication capability is improved, but system complexity and intervention requirements increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the IP layer to autonomously verify source addresses through digitally signed certificates embedded in packets. Each packet carries a certificate signed by the source node's private key, allowing receiving nodes to verify authenticity using public keys without requiring third-party intervention or higher-layer protocols, thus making the verification system self-sufficient at the network layer

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-distributing public keys and certificates to all network nodes before communication occurs. Certificate authorities sign source node certificates in advance, and these verified certificates are distributed throughout the network, enabling immediate verification without requiring real-time third-party intervention during packet transmission

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8966609B2Authentication method and apparatus for detecting and preventing source address spoofing packets
Publication Date: 2015.02.24 ELECTRONICS & TELECOMM RES INST
  • US8966609B2 patent drawing
  • US8966609B2 patent drawing
  • US8966609B2 patent drawing

AI summary

An authentication apparatus for detecting and preventing a source address spoofing packet, includes a packet reception unit configured to receive a packet from a previous node or a user host; a self-assurance type ID generation unit configured to generate a self-assurance type ID of a source node of the received packet; and a self-assurance type ID verification unit configured to determine whether the source address of the received packet has been spoofed. Further, the authentication apparatus includes a white list storage unit configured to store a reliable source node; a black list storage unit configured to store an unreliable source node; and a packet transmission unit configured to transmit the packet whose source has been verified through the self-assurance type ID verification unit to a next network node.