Building a next generation Internet with source address validation architecture

被引:0
|
作者
WU JianPing1
2 Department of Electronic Engineering
3 Tsinghua National Laboratory for Information Science and Technology(TNList)
机构
基金
中国国家自然科学基金;
关键词
IP source address validation; network architecture; network security;
D O I
暂无
中图分类号
TP393.02 [];
学科分类号
摘要
The IP packet forwarding of current Internet is mainly destination based. In the forwarding process,the source IP address is not checked in most cases.This causes serious security,management and accounting problems. Based on the drastically increased IPv6 address space,a "source address validation architecture"(SAVA) is proposed in this paper,which can guarantee that every packet received and forwarded holds an authenticated source IP address. The design goals of the architecture are lightweight,loose coupling,"multi-fence support" and incremental deployment. This paper discusses the design and implementation for the architecture,including inter-AS,intra-AS and local subnet. The performance and scalability of SAVA are described. This architecture is deployed into the CNGI-CERNET2 infrastructure―a large-scale native IPv6 backbone network of the China Next Generation Internet project. We believe that the SAVA will help the transition to a new,more secure and dependable Internet.
引用
收藏
页码:1681 / 1691
页数:11
相关论文
共 50 条
  • [41] Building the Next Generation
    Shuster, Laurie A.
    CIVIL ENGINEERING, 2018, 88 (04): : 12 - 12
  • [42] Building the Next Generation
    Wagman, David
    POWER ENGINEERING, 2010, 114 (05) : 6 - 6
  • [43] IER: ID-ELOC-RLOC BASED ARCHITECTURE FOR NEXT GENERATION INTERNET
    Yang Jiahai
    Xu Mingwei
    Wang Hui
    Chen Wenlong
    Yang Yuan
    Dong Qingzhou
    Wang Yang
    Journal of Electronics(China), 2014, 31 (06) : 519 - 536
  • [44] Study on Multi-dimentional Extendibility of Next-generation Internet Architecture
    He, Zhonglin
    MINES 2009: FIRST INTERNATIONAL CONFERENCE ON MULTIMEDIA INFORMATION NETWORKING AND SECURITY, VOL 2, PROCEEDINGS, 2009, : 37 - 40
  • [45] An architecture for a next-generation internet based on web services and utility computing
    Darlington, John
    Cohen, Jeremy
    Lee, William
    15TH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2006, : 169 - +
  • [46] Simulation of the Internet Computer Protocol: the Next Generation Multi-Blockchain Architecture
    Serena, Luca
    Li, AoXuan
    Zichichi, Mirko
    D'Angelo, Gabriele
    Ferretti, Stefano
    Tang, Su-Kit
    2022 IEEE/ACM 26TH INTERNATIONAL SYMPOSIUM ON DISTRIBUTED SIMULATION AND REAL TIME APPLICATIONS (DS-RT), 2022,
  • [47] Data-Plane Energy Efficiency of a Next-Generation Internet Architecture
    Tabaeiaghdaei, Seyedali
    Perrig, Adrian
    2022 27TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2022), 2022,
  • [48] Cloud, wireless technology, internet of things: the next generation of building automation systems?
    Bode, Gerrit
    Baranski, Marc
    Schraven, Markus
    Kuempel, Alexander
    Storek, Thomas
    Nuerenberg, Markus
    Mueller, Dirk
    Rothe, Andreas
    Ziegeldorf, Jan Henrik
    Fuetterer, Johannes
    Scheuffele, Bernd
    CLIMATE RESILIENT CITIES - ENERGY EFFICIENCY & RENEWABLES IN THE DIGITAL ERA (CISBAT 2019), 2019, 1343
  • [49] Classification of source address spoofing in the Internet
    Li, Peiguo
    Bi, Jun
    Yao, Guang
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2009, 49 (08): : 1237 - 1240
  • [50] Message from the organizers of the workshop on internet measurement technology and its applications to building next generation Internet
    Fukuda, Kensuke
    Tsuru, Masato
    SAINT - 2007 International Symposium on Applications and the Internet - Workshops, SAINT-W, 2007,