Busca avançada
Ano de início
Entree


PathSec: Path-Aware Secure Routing with Native Path Verification and Auditability

Texto completo
Autor(es):
Martinello, Magnos ; Gomes, Roberta Lima ; Borges, Everson S. ; Layber, Henrique Coutinho ; Bonella, Vitor B. ; Dominicini, Cristina K. ; Guimaraes, Rafael ; Ribeiro, Moises ; Barcellos, Marinho
Número total de Autores: 9
Tipo de documento: Artigo Científico
Fonte: 2024 IEEE CONFERENCE ON NETWORK FUNCTION VIRTUALIZATION AND SOFTWARE DEFINED NETWORKS, NFV-SDN 2024; v. N/A, p. 7-pg., 2024-01-01.
Resumo

Selecting and verifying network paths for packet flows are fundamental for creating secure and efficient network architectures. These processes are essential for detecting and addressing anomalies, misconfigurations, or malicious activities, yet they remain challenging to implement effectively, even within a single administrative domain. To support a secure routing framework, it is necessary to: (i) select specific paths for packet flows, enabling "path awareness"; (ii) verify that packets follow the specified routes, ensuring adherence to the routing promise; and (iii) maintain tamper-proof audit records of path verification data. This paper introduces a novel path-aware secure routing approach based on Residue Number System (RNS) primitives, which enables both native path verification and auditability. Our method employs a lightweight multi-signature scheme built on simplified hash chain signatures, leveraging RNS-based native routing mechanisms. These signatures, which provide proofs of packet forwarding, are verified and recorded on a blockchain to ensure data integrity and prevent unauthorised tampering. A P4-based prototype demonstrates that our solution represents a viable hardware implementation for modern programmable switches. (AU)

Processo FAPESP: 20/05182-3 - PORVIR-5G: programabilidade, orquestração e virtualização em redes 5G
Beneficiário:José Marcos Silva Nogueira
Modalidade de apoio: Auxílio à Pesquisa - Temático