• DocumentCode
    3072497
  • Title

    SafeZone: A Hierarchical Inter-Domain Authenticated Source Address Validation Solution

  • Author

    Li, Jie ; Wu, Jianping ; Xu, Ke

  • Author_Institution
    Dept. Comput. Sci. & Technol., Tsinghua Univ., Beijing, China
  • fYear
    2011
  • fDate
    5-9 Dec. 2011
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Next generation Internet is highly concerned with the issue of trustworthy. An important foundation of trustworthy is authentication of the source IP address. With existing signature-and-verification based defense mechanisms, there is a lack of hierarchical architecture, which makes the structure of the trust alliance excessively flat and single. Moreover, with the increasing scale of trust alliances, costs of validation grow so quickly that they do not adapt to incremental deployment. Via comparison with traditional solutions, this article proposes a hierarchical, inter-domain authenticated source address validation solution named SafeZone. SafeZone employs two intelligent designs: lightweight tag replacement and a hierarchical partitioning scheme, each of which helps to ensure that SafeZone can construct trustworthy and hierarchical trust alliances without the negative influences and complex operations on de facto networks. Extensive experiments also indicate that SafeZone can effectively obtain the design goals of a hierarchical architecture, along with lightweight, loose coupling and "multi-fence support" as well as supporting incremental deployment.
  • Keywords
    IP networks; Internet; computer network security; digital signatures; trusted computing; SafeZone; de facto network; hierarchical architecture; hierarchical inter-domain authenticated source address validation solution; hierarchical partitioning scheme; incremental deployment; lightweight tag replacement; multifence support; next generation Internet; signature-and-verification based defense mechanism; trustworthy; Computer architecture; IEEE Communications Society; IP networks; Internet; Optimization; Relays; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Global Telecommunications Conference (GLOBECOM 2011), 2011 IEEE
  • Conference_Location
    Houston, TX, USA
  • ISSN
    1930-529X
  • Print_ISBN
    978-1-4244-9266-4
  • Electronic_ISBN
    1930-529X
  • Type

    conf

  • DOI
    10.1109/GLOCOM.2011.6133740
  • Filename
    6133740