Method and apparatus for resilient decoy routing without conspiring autonomous systems (as) via distributed hash table (dht) routing
Abstract
A Method and apparatus for resilient Decoy Routing without conspiring Autonomous Systems by instead using a DHT routing table is described. In one embodiment of the present invention, there would exist a set of Decoy Routing Nodes which would be connected via a DHT's routing table. This would enable decoy routing nodes to not depend on a predefined list. Traditionally, Decoy Routing depends upon either a pre-configured list of computer systems to connect to or is wholly dependent upon BGP to happen to route to friendly Autonomous Systems that understand the true intent of the packet being routed. This method and apparatus solves these problems by providing a means to use a dynamic routing table, provided by a DHT to ensure that a packet can be delivered to computer systems that understand how to do decoy routing. This approach further ensures that the routing table being used is one that is kept up to date automatically as a function of the DHT providing the routing table. Further, the methodology described ensures that evading censorship, defending against TCP replay attacks, latency analysis, website fingerprinting, and denial of service (DoS) attacks are successfully executed.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method and apparatus for a computer system to connect to another computer system using a procedure which obscures the actual intended routing path from a third-party observer and is able to ensure routing by always having an accurate routing table which is provided for by way of a DHT.
2 . The method of claim 1 , wherein a computer system to connect to another computer system also ensures that the IP Packet being emitted by a computer system is successful in evading censorship.
3 . The method of claim 1 , wherein a computer system to connect to another computer system also ensures that a computer system intending to send an IP Packet is unable to be replayed in a Transmission Control Protocol (TCP) replay attack.
4 . The method of claim 1 , wherein a computer system to connect to another computer system also ensures a computer system emitting an IP Packet cannot be used in a latency analysis.
5 . The method of claim 1 , wherein a computer system to connect to another computer system also ensures a computer system emitting an IP Packet does not convey website fingerprinting.
6 . The method of claim 1 , wherein a computer system to connect to another computer system also ensures a computer system emitting an IP Packet can successfully thwart a denial of service (DoS) attack.Join the waitlist — get patent alerts
Track US2022303311A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.