4 ms·
He everyone! I'm Markus, the author of this blog post and the related USENIX paper. It's great to see the interest in this line of research. I would like to add
by mlegner 6y ago
He everyone! I'm Markus, the author of this blog post and the related USENIX paper. It's great to see the interest in this line of research. I would like to address some of the points brought up in the comments and provide additional information:
- Path-aware Internet architectures and SCION in particular are not source-routing architectures. End hosts neither have/need a full view of the network topology, nor can they unilaterally choose paths. Instead, network operators explore and distribute candidate paths. End hosts get a set of such pre-selected paths from which they can then choose the one they want to use. This is one of the main points of the paper: How can autonomous systems in the Internet efficiently restrict the choices of end hosts.
- SCION does not help with censorship. On the contrary: compared to the BGP/IP Internet, some power is shifted from network operators to end hosts. It is these end hosts, who can implement "geo-fencing" not the network operators. While these still retain a significant amount of control over paths (see above) it is easier for end hosts to circumvent networks that employ censorship.
- One important point about SCION and other path-aware architectures is that the path control of end hosts is at an autonomous-system level. Thus, most problems with LSRR/SSRR are not present in SCION. For example:
- End hosts cannot choose paths at a router level and thus not evade firewalls (unless they are very poorly deployed).
- End hosts do not learn any information about the intra-domain topology, only about the inter-domain topology. This information can already be inferred today and is available in public datasets such as the CAIDA AS-relationship dataset [1]
- There is a Tor-like anonymous-communication network designed to use with SCION: HORNET [2].
Of course, path control by itself cannot solve all problems. This is why SCION includes several additional innovations such as a public-key infrastructure (PKI) that does not depend on global trust anchors and single points of failure, a secure routing mechanism, highly efficient mechanisms for packet authentication, etc.
[1] https://www.caida.org/data/as-relationships/index.xml https://www.caida.org/data/as-relationships/index.xml
[2] https://netsec.ethz.ch/research/anonymity.php https://netsec.ethz.ch/research/anonymity.php