Building a next generation Internet with source address validation architecture

被引:0
|
作者
WU JianPing1
2 Department of Electronic Engineering
3 Tsinghua National Laboratory for Information Science and Technology(TNList)
机构
基金
中国国家自然科学基金;
关键词
IP source address validation; network architecture; network security;
D O I
暂无
中图分类号
TP393.02 [];
学科分类号
摘要
The IP packet forwarding of current Internet is mainly destination based. In the forwarding process,the source IP address is not checked in most cases.This causes serious security,management and accounting problems. Based on the drastically increased IPv6 address space,a "source address validation architecture"(SAVA) is proposed in this paper,which can guarantee that every packet received and forwarded holds an authenticated source IP address. The design goals of the architecture are lightweight,loose coupling,"multi-fence support" and incremental deployment. This paper discusses the design and implementation for the architecture,including inter-AS,intra-AS and local subnet. The performance and scalability of SAVA are described. This architecture is deployed into the CNGI-CERNET2 infrastructure―a large-scale native IPv6 backbone network of the China Next Generation Internet project. We believe that the SAVA will help the transition to a new,more secure and dependable Internet.
引用
收藏
页码:1681 / 1691
页数:11
相关论文
共 50 条
  • [1] Building a next generation Internet with source address validation architecture
    JianPing Wu
    Gang Ren
    Xing Li
    Science in China Series F: Information Sciences, 2008, 51 : 1681 - 1691
  • [2] Building a next generation Internet with source address validation architecture
    Wu JianPing
    Ren Gang
    Li Xing
    SCIENCE IN CHINA SERIES F-INFORMATION SCIENCES, 2008, 51 (11): : 1681 - 1691
  • [3] Building the next generation Internet
    Yanoff, L
    ALCATEL TELECOMMUNICATIONS REVIEW, 1997, (04): : 246 - 255
  • [4] A streaming architecture for next generation Internet
    Dutta, A
    2001 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-10, CONFERENCE RECORD, 2001, : 1303 - 1309
  • [5] Source address validation: Architecture and protocol design
    Wu, Jianping
    Ren, Gang
    Li, Xing
    2007 IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS, 2007, : 276 - +
  • [6] Research on next-generation Internet architecture
    Wu, Jian-Ping
    Xu, Ke
    JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2006, 21 (05) : 723 - 731
  • [7] Service model and architecture for next generation Internet
    Information Network Center, Beijing University of Posts and Telecommunications, Beijing 1000876, China
    Gaojishu Tongxin, 2007, 11 (1101-1106):
  • [8] Research on Next-Generation Internet Architecture
    Jian-Ping Wu
    Ke Xu
    Journal of Computer Science and Technology, 2006, 21 : 723 - 731
  • [9] Source Address Validation Solution with OpenFlow/NOX Architecture
    Yao, Guang
    Bi, Jun
    Xiao, Peiyao
    2011 19TH IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2011,
  • [10] FlexNGIA: A Flexible Internet Architecture for the Next-Generation Tactile Internet
    Zhani, Mohamed Faten
    ElBakoury, Hesham
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2020, 28 (04) : 751 - 795