首页> 外国专利> Method and system for anti denial of service and anti traffic analysis capabilities for ip based virtual private networks and data distribution through use of an ip multicast address hopping technique

Method and system for anti denial of service and anti traffic analysis capabilities for ip based virtual private networks and data distribution through use of an ip multicast address hopping technique

机译:通过使用ip多播地址跳变技术来针对基于ip的虚拟专用网和数据分发的抗拒绝服务和抗流量分析能力的方法和系统

摘要

A method and system for Internet Protocol network communications and uses thereof for protecting Internet sites against denial of service and traffic analysis attacks on insecure public networks such as the Internet are provided. The method provides for communicating multicast packets between end stations, in a multicast IP network, on a chosen multicast IP address from a plurality of multicast IP addresses for multicast communication using a multicast address hopping technique. The technique selectively varies the chosen multicast IP address from the plurality of multicast IP addresses according to a predetermined scheme known to the end stations but not to unauthorized endstations. The packets are then communicated on the chosen multicast IP address. Indicia normally capable of identifying the source of the packets may be selectively varied to conceal the source of the packets. Further, the packets may be communicated to an end station having subscribed to a set of multicast IP addresses comprising at least one multicast IP address from the plurality of multicast IP addresses for multicast communication and including the chosen multicast IP address for transmitting the packets. The set of multicast IP addresses may also be selectively varied according to a secret predetermined scheme known to the end stations, particularly by randomly adding to and dropping from the set of multicast IP addresses. Multiple sets of communicating groups all utilizing the same address space can coexist such that their respective traffic is intermingled on the various addresses, making traffic analysis very difficult. In another embodiment, a data coding scheme such as code division multiplexing may be employed on the individual multicast packets data fields to allow data for individual destinations to be mixed together in one packet that is multicast to a plurality of receivers. Each receiver then decodes its applicable data by passing the received multicast data field through the appropriate decoding scheme such as a code division de-multiplexing process. In further aspects of the invention, various uses of the invention for Virtual Private Networks and other secure communication systems are also provided.
机译:提供了一种用于因特网协议网络通信的方法和系统,以及其用于保护因特网站点免受拒绝服务和对诸如因特网之类的不安全公共网络的流量分析攻击的用途。该方法提供了用于在多播IP网络中的终端站之间在从多个多播IP地址中选择的多播IP地址上的多播分组之间通信的多播分组,以使用多播地址跳跃技术进行多播通信。该技术根据对于终端站而不是未经授权的终端站已知的预定方案,从多个组播IP地址中选择性地改变所选择的组播IP地址。然后,在选定的多播IP地址上传送数据包。通常能够识别分组源的标记可以被选择性地改变以隐藏分组的源。进一步地,可以将分组传送到已经订阅了一组组播IP地址的终端站,该组播IP地址包括:多个组播IP地址中的至少一个组播IP地址,用于组播通信,并且包括所选择的组播IP地址,用于发送分组。还可根据终端站已知的秘密预定方案来选择性地改变多播IP地址的集合,特别是通过随机地添加到多播IP地址的集合和从多播IP地址的集合中删除。可以全部利用相同地址空间的多组通信组可以共存,以使它们各自的流量混合在各个地址上,从而使流量分析非常困难。在另一个实施例中,可以在各个多播分组数据字段上采用诸如码分复用之类的数据编码方案,以允许用于各个目的地的数据在一个分组中被混合在一起,该分组被多播到多个接收器。然后,每个接收器通过使接收到的多播数据字段通过适当的解码方案(例如码分多路分解过程)来解码其适用数据。在本发明的另一方面,还提供了本发明用于虚拟专用网和其他安全通信系统的各种用途。

著录项

  • 公开/公告号AU6195701A

    专利类型

  • 公开/公告日2001-12-03

    原文格式PDF

  • 申请/专利权人 LADR IT CORPORATION;

    申请/专利号AU20010061957

  • 发明设计人 CHARLES BYRON ALEXANDER SHAWCROSS;

    申请日2001-05-22

  • 分类号H04L29/00;

  • 国家 AU

  • 入库时间 2022-08-22 00:39:42

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号