Building a next generation Internet with source address validation architecture

被引:0
|
作者
WU JianPing1
2 Department of Electronic Engineering
3 Tsinghua National Laboratory for Information Science and Technology(TNList)
机构
基金
中国国家自然科学基金;
关键词
IP source address validation; network architecture; network security;
D O I
暂无
中图分类号
TP393.02 [];
学科分类号
摘要
The IP packet forwarding of current Internet is mainly destination based. In the forwarding process,the source IP address is not checked in most cases.This causes serious security,management and accounting problems. Based on the drastically increased IPv6 address space,a "source address validation architecture"(SAVA) is proposed in this paper,which can guarantee that every packet received and forwarded holds an authenticated source IP address. The design goals of the architecture are lightweight,loose coupling,"multi-fence support" and incremental deployment. This paper discusses the design and implementation for the architecture,including inter-AS,intra-AS and local subnet. The performance and scalability of SAVA are described. This architecture is deployed into the CNGI-CERNET2 infrastructure―a large-scale native IPv6 backbone network of the China Next Generation Internet project. We believe that the SAVA will help the transition to a new,more secure and dependable Internet.
引用
收藏
页码:1681 / 1691
页数:11
相关论文
共 50 条
  • [31] Towards Fog-based Next Generation Internet of Vehicles Architecture
    Siddiqui, Sarah Ali
    Mahmood, Adnan
    PROCEEDINGS OF THE 1ST INTERNATIONAL WORKSHOP ON COMMUNICATION AND COMPUTING IN CONNECTED VEHICLES AND PLATOONING (C3VP'18), 2018, : 15 - 21
  • [32] A Framework for Network State Management in the Next-Generation Internet Architecture
    Huang, Xin
    Ganapathy, Sivakumar
    Wolf, Tilman
    GLOBECOM 2008 - 2008 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2008,
  • [33] A novel DHT-based network architecture for the Next Generation Internet
    Hanka, Oliver
    Spleiss, Christoph
    Kunzmann, Gerald
    Eberspaecher, Joerg
    2009 EIGHTH INTERNATIONAL CONFERENCE ON NETWORKS, 2009, : 332 - 341
  • [34] On the deployability evaluation model of internet inter-domain source address validation
    Liu, Bing-Yang
    Bi, Jun
    Jisuanji Xuebao/Chinese Journal of Computers, 2015, 38 (03): : 500 - 514
  • [35] Next Generation Internet
    不详
    ELECTRONICS INFORMATION & PLANNING, 2000, 27 (10-11): : 295 - 295
  • [36] Next Generation Internet
    McLoughlin, GJ
    JOURNAL OF ACADEMIC LIBRARIANSHIP, 1998, 24 (03): : 237 - 239
  • [37] Next Generation Internet
    Eberspaecher, Joerg
    Phuoc Tran-Gia
    IT-INFORMATION TECHNOLOGY, 2008, 50 (06): : 341 - 344
  • [38] Next generation Internet
    Wang, JL
    Ni, CS
    Wu, JP
    Guo, YF
    I-SPAN 2004: 7TH INTERNATIONAL SYMPOSIUM ON PARALLEL ARCHITECTURES, ALGORITHMS AND NETWORKS, PROCEEDINGS, 2004, : 351 - 356
  • [39] Internet Protocol Suite for Safety Services: Validation with Next Generation Avionics
    Skorepa, Michal
    Olive, Michael L.
    Emberger, Luc
    Lopez, Enrique Mene
    2021 IEEE/AIAA 40TH DIGITAL AVIONICS SYSTEMS CONFERENCE (DASC), 2021,
  • [40] Internet 2 and the next generation Internet
    Preston, Cecilia
    Searcher:Magazine for Database Professionals, 1999, 7 (01):