FABRID: Flexible Attestation-Based Routing for Inter-Domain Networks
Cyrill Kr\"ahenb\"uhl (ETH Z\"urich), Marc Wyss (ETH Z\"urich), David, Basin (ETH Z\"urich), Vincent Lenders (armasuisse), Adrian Perrig (ETH, Z\"urich), Martin Strohmeier (armasuisse)

TL;DR
FABRID is a system that enhances inter-domain routing by providing transparent, attested device information and flexible path selection, empowering applications with greater control and trust in the forwarding process.
Contribution
It introduces a novel routing framework that combines attested device information with user-defined preferences, implemented and tested on a global SCION network test bed.
Findings
High throughput achieved on commodity hardware
Effective protection of network and user privacy
Feasibility demonstrated on a global test bed
Abstract
In its current state, the Internet does not provide end users with transparency and control regarding on-path forwarding devices. In particular, the lack of network device information reduces the trustworthiness of the forwarding path and prevents end-user applications requiring specific router capabilities from reaching their full potential. Moreover, the inability to influence the traffic's forwarding path results in applications communicating over undesired routes, while alternative paths with more desirable properties remain unusable. In this work, we present FABRID, a system that enables applications to forward traffic flexibly, potentially on multiple paths selected to comply with user-defined preferences, where information about forwarding devices is exposed and transparently attested by autonomous systems (ASes). The granularity of this information is chosen by each AS…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInternet Traffic Analysis and Secure E-voting · Software-Defined Networks and 5G · Network Security and Intrusion Detection
