• DocumentCode
    1048323
  • Title

    Secure and Policy-Compliant Source Routing

  • Author

    Raghavan, Barath ; Verkaik, Patrick ; Snoeren, Alex C.

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Univ. of California at San Diego, La Jolla, CA
  • Volume
    17
  • Issue
    3
  • fYear
    2009
  • fDate
    6/1/2009 12:00:00 AM
  • Firstpage
    764
  • Lastpage
    777
  • Abstract
    In today´s Internet, inter-domain route control remains elusive; nevertheless, such control could improve the performance, reliability, and utility of the network for end users and ISPs alike. While researchers have proposed a number of source routing techniques to combat this limitation, there has thus far been no way for independent ASes to ensure that such traffic does not circumvent local traffic policies, nor to accurately determine the correct party to charge for forwarding the traffic. We present Platypus, an authenticated source routing system built around the concept of network capabilities, which allow for accountable, fine-grained path selection by cryptographically attesting to policy compliance at each hop along a source route. Capabilities can be composed to construct routes through multiple ASes and can be delegated to third parties. Platypus caters to the needs of both end users and ISPs: users gain the ability to pool their resources and select routes other than the default, while ISPs maintain control over where, when, and whose packets traverse their networks. We describe the design and implementation of an extensive Platypus policy framework that can be used to address several issues in wide-area routing at both the edge and the core, and evaluate its performance and security. Our results show that incremental deployment of Platypus can achieve immediate gains.
  • Keywords
    Internet; telecommunication network routing; telecommunication security; Internet; Platypus; policy compliant; source routing; telecommunication security; Authentication; capabilities; overlay networks; source routing;
  • fLanguage
    English
  • Journal_Title
    Networking, IEEE/ACM Transactions on
  • Publisher
    ieee
  • ISSN
    1063-6692
  • Type

    jour

  • DOI
    10.1109/TNET.2008.2007949
  • Filename
    4729675