首页> 外国专利> Method and apparatus for using client puzzles to protect against denial-of-service attacks

Method and apparatus for using client puzzles to protect against denial-of-service attacks

机译:使用客户端难题来防御拒绝服务攻击的方法和设备

摘要

One embodiment of the present invention provides a system that protects a server against denial-of-service attacks. During operation, the server receives a request for service from a client. Note that the client can be distinguished from other clients, for example, by its source IP address. In response to this request, the server sends a random number, y, and an identifier, id1, to the client, and allows the client to compute a preimage, x, such that y=h(x). Upon receiving an answer from the client including the preimage x and an identifier, id2, the server verifies that the identifier, id1, sent to the client matches the identifier, id2, received from the client. If the identifiers match, the server computes h(x), and compares h(x) against y. If h(x)=y, the server performs the requested service for the client. In this way, the server avoids computing h(x) until the server receives the answer with a matching identifier.
机译:本发明的一个实施例提供了一种保护服务器免受拒绝服务攻击的系统。在操作期间,服务器从客户端接收服务请求。请注意,例如,可以通过客户端的源IP地址将其与其他客户端区分开。响应此请求,服务器将一个随机数y和一个标识符id 1 发送到客户端,并允许客户端计算原像x,使得y = h( X)。服务器从客户端收到包含原像x和标识符id 2 的答案后,服务器将验证发送给客户端的标识符id 1 与标识符匹配,从客户端收到的id 2 。如果标识符匹配,则服务器计算h(x),并将h(x)与y进行比较。如果h(x)= y,则服务器为客户端执行请求的服务。以这种方式,服务器避免计算h(x),直到服务器接收到具有匹配标识符的答案。

著录项

  • 公开/公告号US6944663B2

    专利类型

  • 公开/公告日2005-09-13

    原文格式PDF

  • 申请/专利权人 CHRISTOPH L. SCHUBA;ERIK GUTTMAN;

    申请/专利号US20020091826

  • 发明设计人 CHRISTOPH L. SCHUBA;ERIK GUTTMAN;

    申请日2002-03-06

  • 分类号G06F15/173;G06F13/30;

  • 国家 US

  • 入库时间 2022-08-21 22:20:30

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号