Site-controlled secure multi-homing and traffic engineering for IP

R. Atkinson, S. Bhatti, S. Hailes
{"title":"Site-controlled secure multi-homing and traffic engineering for IP","authors":"R. Atkinson, S. Bhatti, S. Hailes","doi":"10.1109/MILCOM.2009.5380044","DOIUrl":null,"url":null,"abstract":"Site multi-homing is an important capability in modern military networks. Resilience of a site is greatly enhanced when it has multiple upstream connections to the Global Information Grid, including the global Internet. Similarly, the ability to provide traffic engineering for a site can be important in reducing delays and packet loss over low-bandwidth and/or high-delay uplinks. Current approaches to site multi-homing and site traffic engineering (a) require assistance from a trusted network service provider; (b) inject significant additional routing information into the global Internet routing system. This approach reduces flexibility, does not scale and is a widespread concern today. The proposed Identifier-Locator Network Protocol (ILNP) offers backward compatible extensions for IPv6 to enable a site to (a) use multiple routing prefixes concurrently, without needing to advertise these more-specific site prefixes upstream to the site's service providers; (b) enables edge-site controlled traffic engineering and localised addressing, without breaking end-to-end connectivity. This feature combination provides both multi-homing and traffic engineering capabilities without any adverse impact on the routing system and does not require anything more than unicast routing capability in the provider network. ILNP enables concurrent multi-path transmission for a flow, without requiring multicast routing, to increase flow resilience to path interruptions. This technique has a secondary security benefit of reducing the risk of an adversary successfully blocking an ILNP flow via a Denial-of-Service attack on any single path or single link.","PeriodicalId":338641,"journal":{"name":"MILCOM 2009 - 2009 IEEE Military Communications Conference","volume":"102 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-10-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"13","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"MILCOM 2009 - 2009 IEEE Military Communications Conference","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MILCOM.2009.5380044","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 13

Abstract

Site multi-homing is an important capability in modern military networks. Resilience of a site is greatly enhanced when it has multiple upstream connections to the Global Information Grid, including the global Internet. Similarly, the ability to provide traffic engineering for a site can be important in reducing delays and packet loss over low-bandwidth and/or high-delay uplinks. Current approaches to site multi-homing and site traffic engineering (a) require assistance from a trusted network service provider; (b) inject significant additional routing information into the global Internet routing system. This approach reduces flexibility, does not scale and is a widespread concern today. The proposed Identifier-Locator Network Protocol (ILNP) offers backward compatible extensions for IPv6 to enable a site to (a) use multiple routing prefixes concurrently, without needing to advertise these more-specific site prefixes upstream to the site's service providers; (b) enables edge-site controlled traffic engineering and localised addressing, without breaking end-to-end connectivity. This feature combination provides both multi-homing and traffic engineering capabilities without any adverse impact on the routing system and does not require anything more than unicast routing capability in the provider network. ILNP enables concurrent multi-path transmission for a flow, without requiring multicast routing, to increase flow resilience to path interruptions. This technique has a secondary security benefit of reducing the risk of an adversary successfully blocking an ILNP flow via a Denial-of-Service attack on any single path or single link.
IP的站点控制安全多归巢和流量工程
站点多归巢是现代军事网络中的一项重要能力。当站点与全球信息网格(包括全球Internet)有多个上游连接时,站点的弹性将大大增强。同样,为站点提供流量工程的能力对于减少低带宽和/或高延迟上行链路上的延迟和数据包丢失也很重要。目前的站点多归属和站点流量工程方法(a)需要可靠的网络服务提供商的协助;(b)向全球互联网路由系统注入重要的额外路由信息。这种方法降低了灵活性,不能扩展,是当今广泛关注的问题。提出的标识-定位网络协议(ILNP)为IPv6提供了向后兼容的扩展,使站点能够(a)同时使用多个路由前缀,而不需要将这些更具体的站点前缀向上游站点的服务提供商发布;(b)在不破坏端到端连接的情况下,实现边缘站点控制的流量工程和本地寻址。此功能组合提供了多归巢和流量工程功能,而不会对路由系统产生任何不利影响,并且只需要提供商网络中的单播路由功能。ILNP支持流的并发多路径传输,而不需要组播路由,以增加流对路径中断的弹性。这种技术的第二个安全好处是降低了攻击者通过对任何单一路径或单一链路的拒绝服务攻击成功阻止ILNP流的风险。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信