skip to main content
10.1145/1477942.1477965acmconferencesArticle/Chapter ViewAbstractPublication PagesancsConference Proceedingsconference-collections
poster

Data path credentials for high-performance capabilities-based networks

Published:06 November 2008Publication History

ABSTRACT

Capabilities-based networks present a fundamental shift in the security design of network architectures. Instead of permitting the transmission of packets from any source to any destination, routers deny forwarding by default. For a successful transmission, packets need to positively identify themselves and their permissions to the router. The analysis of the data path credentials data structure that we propose shows that as few as 128 bits are sufficient to reduce the probability of unauthorized traffic reaching its destination to a fraction of a percent.

References

  1. Anderson, T., Roscoe, T., and Wetherall, D. Preventing Internet denial-of-service with capabilities. SIGCOMM Computer Communication Review 34, 1 (Jan. 2004), 39--44. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Ballani, H., Chawathe, Y., Ratnasamy, S., Roscoe, T., and Shenker, S. Off by default! In Proc. of Fourth Workshop on Hot Topics in Networks (HotNets-IV) (College Park, MD, Nov. 2005).Google ScholarGoogle Scholar
  3. Wolf, T. A credential-based data path architecture for assurable global networking. In Proc. of the 2007 IEEE Conference on Military Communications (MILCOM) (Orlando, FL, Oct. 2007).Google ScholarGoogle ScholarCross RefCross Ref
  4. Wolf, T. Design of a network architecture with inherent data path security. In Proc. of ACM/IEEE Symposium on Architectures for Networking and Communication Systems (ANCS) (Orlando, FL, Dec. 2007), pp. 39--40. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. Data path credentials for high-performance capabilities-based networks

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Conferences
      ANCS '08: Proceedings of the 4th ACM/IEEE Symposium on Architectures for Networking and Communications Systems
      November 2008
      191 pages
      ISBN:9781605583464
      DOI:10.1145/1477942

      Copyright © 2008 ACM

      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 6 November 2008

      Permissions

      Request permissions about this article.

      Request Permissions

      Check for updates

      Qualifiers

      • poster

      Acceptance Rates

      ANCS '08 Paper Acceptance Rate17of67submissions,25%Overall Acceptance Rate88of314submissions,28%

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader