Busca avançada
Ano de início
Entree


PoT-PolKA: Let the Edge Control the Proof-of-Transit in Path-Aware Networks

Texto completo
Autor(es):
Borges, Everson Scherrer ; Martinello, Magnos ; Bonella, Vitor B. ; dos Santos, Abraao J. ; Gomes, Roberta L. ; Dominicini, Cristina K. ; Guimaraes, Rafael Silva ; Menegueti, Gabriel T. ; Barcellos, Marinho ; Ruffini, Marco
Número total de Autores: 10
Tipo de documento: Artigo Científico
Fonte: IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT; v. 21, n. 4, p. 11-pg., 2024-08-01.
Resumo

This paper presents a scalable and efficient solution for secure network design that involves the selection and verification of network paths. The proposal addresses the challenges related to compliance policies by introducing a Proof-of-Transit (PoT) feasible implementation for path-aware programmable networks. Our approach relies on i) a source routing mechanism based on a fixed routeID representing a unique identifier per path, which serves as a key for PoT lookup tables; ii) the "in situ" that allows to collect telemetry information in the packet while the packet traverses a path. The former enables path selection with policy at the edge, while the later allows to perform path verification without extra probe-traffic. A P4 programmable language prototype demonstrates the effectiveness of this approach to protect against deviation attacks with low overhead. The results show its scalability considering the protocol overhead as the path length increases; a significant reduction in network's forwarding state for fat-tree topologies depending on the workload per path (flows/path). Finally, experimental results show a RTT comparison evaluation, the impact of PoT computation, protection to path deviation and seamless path migration keeping flow protection. (AU)

Processo FAPESP: 20/05174-0 - SAWI - Savvy Access through Worldwide Internet
Beneficiário:Epaminondas Aguiar de Sousa Junior
Modalidade de apoio: Auxílio à Pesquisa - Pesquisa Inovativa em Pequenas Empresas - PIPE
Processo FAPESP: 20/05182-3 - PORVIR-5G: programabilidade, orquestração e virtualização em redes 5G
Beneficiário:José Marcos Silva Nogueira
Modalidade de apoio: Auxílio à Pesquisa - Temático