EP1631037B1

Apparatus and method for mitigating DoS attacks in a service discovery system

Abstract

This record has no abstract on file.

EP1631037B1, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 26 August 2025, 1.1 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

9 claims: 5 independent, 4 dependent

  1. 1
    A service discovery system including a client terminal (100) and a service providing device (200) which provides data or a function to the client terminal, a service request unit (103) adapted to generate a message requesting a service of the service providing device;a problem management unit (205) adapted to generate a problem imposing a load on the client terminal and which, when a solution to the problem is received from the client terminal, is adapted to verify the solution;a communication unit (102) adapted to send the message generated by the service request unit to the service providing device and which is adapted to receive from the service providing device a problem imposing a load on the client terminal;a solution unit (104) adapted to solve the problem;a service reply unit (203) which, when the solution to the problem is received, is adapted to generate a message replying to the service requesting message sent from the client terminal;characterized by a signature unit (204) adapted to add a digital signature to the message generated by the service reply unit;a time management unit (207) adapted to measure a length of solution time taken by the client terminal to solve the problem;and a risk avoidance unit (210) adapted to calculate a risk of the service requesting message, based on a statistic result given by a statistic processing unit (208).
  2. 2
    A client terminal (100) which is provided with data or a function from a service providing device:a service request unit (103) adapted to generate a message requesting a service of the service providing device;a communication unit (102) adapted to send the message generated by the service request unit to the service providing device and adapted to receive from the service providing device a problem imposing a load on the client terminal;a solution unit (104) adapted to solve the problem;characterized by a time management unit (105) adapted to record a time of reception of the problem from the service providing device and which, when a solution to the problem is sent out, adapted to attach thereto the time of reception of the problem;and a request retardation unit (106) which, when a length of time from a time of reception of the problem until a solution to the problem is obtained does not reach a given value, is adapted to wait to send the solution to the service providing device.
  3. 3
    A service providing device which provides data or a function to a client terminal;a problem management unit (205) adapted to generate a problem imposing a load on the client terminal and which, when a solution to the problem is received from the client terminal, adapted to verify the solution;a communication unit (202) which, when a message requesting a service is received from the client terminal, is adapted to send the problem to the client terminal and which receives the solution to the problem from the client terminal;a service reply unit (203) which, when the solution to the problem is received, is adapted to generate a message replying to the service requesting message sent from the client terminal;characterized by a signature unit (204) adapted to add a digital signature to the message generated by the service reply unit;a time management unit (207) adapted to measure a length of solution time taken by the client terminal to solve the problem;and a risk avoidance unit (210) adapted to calculate a risk of the service requesting message, based on a statistic result given by the statistic processing unit.
  4. 7
    A service discovery method for discovering a service providing device in a system including a client terminal (100) and a service providing device (200) which provides data or a function to the client terminal, comprising:by the client terminal, generating (S101) a message requesting a service of the service providing device;by the service providing device, generating (S106) a problem imposing a load on the client terminal;by the service providing device, sending (S108) the problem to the client terminal when the service requesting message is received from the client terminal;by the client terminal, solving (S113) the problem;by the service providing device, verifying (S123) a solution to the problem when the solution is received from the client terminal;by the service providing device, upon the verification of the solution to the problem, generating (S136) a message replying to the service requesting message sent from the client terminal;characterized in that by the service providing device, adding (S138, S139) a digital signature to the replying message;and by the client terminal, waiting (S118) to send the solution to the service providing device when a length of time from a time of reception of the problem until the solution to the problem is obtained does not reach a given value.
  5. 8
    A service discovery method for discovering a service providing device In a system including a client terminal (100) and a service providing device (200) which provides data or a function to the client terminal, comprising:by the client terminal, generating (S101) a message requesting a service of the service providing device;by the service providing device, generating (S106) a problem imposing a load on the client terminal;by the service providing device, sending (S108) the problem to the client terminal when the service requesting message is received from the client terminal;by the client terminal, solving (S113) the problem;by the service providing device, verifying (S123) a solution to the problem when the solution is received from the client terminal;by the service providing device, upon the verification of the solution to the problem, generating (S136) a message replying to the service requesting message sent from the client terminal;characterized in that by the service providing device, adding (S138, S139) a digital signature to the replying message;and by the service providing device;measuring (S126) a length of solution time taken by the client terminal to solve the problem;performing (S128) statistic processing on each message requesting the service, based on the solution time measured;determining (S130) a liability, based on a length of time for which the client terminal used the service providing device;calculating (S131) a risk of the service requesting message, based on a result of the statistic processing and the liability;and calculating (S134) a priority, based on a difficulty of the problem and the risk ;wherein in the step of adding (S138, S139) the digital signature, digital signatures are added in order according to the priority.