Source Address Spoofing Detection via Self-Assurance Type ID
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting source address spoofing packets are inadequate as they rely on third-party verification and do not effectively prevent distributed denial of service (DDoS) attacks, as the IP layer lacks the capability to verify packet sources.
Innovation Solution
An authentication method and apparatus that utilize a self-assurance type ID, generated through digital signatures and hashing, to verify the source address of packets within the network layer, allowing only packets with normal source addresses to be forwarded, thereby preventing malicious attacks without third-party intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If statistical techniques or filtering methods are used to detect source address spoofing packets, then detection capability is improved, but the IP layer still cannot verify packet sources and DDoS attacks continue to succeed
Solution Approach 1:
The patent implements self-service by enabling the IP layer to autonomously verify source addresses through digitally signed certificates embedded in packets. Each packet carries a certificate signed by the source node's private key, allowing receiving nodes to verify authenticity using public keys without requiring third-party intervention or higher-layer protocols, thus making the verification system self-sufficient at the network layer
Solution Approach 2:
The patent introduces cryptographic certificates as an intermediary mechanism between source and destination nodes. These certificates, containing public keys and signed by authoritative certificate authorities, serve as trusted mediators that enable verification of source identity without requiring direct trust relationships between communicating parties, thus solving the source verification problem at the IP layer
2Reliability
If third-party verification methods are used to authenticate packet sources, then authentication capability is improved, but system complexity and intervention requirements increase
Solution Approach 1:
The patent implements self-service by enabling the IP layer to autonomously verify source addresses through digitally signed certificates embedded in packets. Each packet carries a certificate signed by the source node's private key, allowing receiving nodes to verify authenticity using public keys without requiring third-party intervention or higher-layer protocols, thus making the verification system self-sufficient at the network layer
Solution Approach 2:
The patent applies preliminary action by pre-distributing public keys and certificates to all network nodes before communication occurs. Certificate authorities sign source node certificates in advance, and these verified certificates are distributed throughout the network, enabling immediate verification without requiring real-time third-party intervention during packet transmission
Data Source
AI summary
An authentication apparatus for detecting and preventing a source address spoofing packet, includes a packet reception unit configured to receive a packet from a previous node or a user host; a self-assurance type ID generation unit configured to generate a self-assurance type ID of a source node of the received packet; and a self-assurance type ID verification unit configured to determine whether the source address of the received packet has been spoofed. Further, the authentication apparatus includes a white list storage unit configured to store a reliable source node; a black list storage unit configured to store an unreliable source node; and a packet transmission unit configured to transmit the packet whose source has been verified through the self-assurance type ID verification unit to a next network node.


