首页> 外文会议>IEEE International Conference on Network Protocols >Communication based on per-packet One-Time Addresses
【24h】

Communication based on per-packet One-Time Addresses

机译:基于每个数据包一次性地址的通信

获取原文

摘要

The act of communication on the Internet inevitably leaks information. In particular, network headers reveal information (e.g., source address, flow information); yet, protecting the header has proven challenging. Past research successfully protected certain fields of the headers (e.g., source address), but no proposal has attempted to eliminate flow information from the header so that packets cannot be linked to flows; flow information is systematically used to subvert privacy. Hence, we investigate the following questions: Can we design an architecture that eliminates flow-packet linkability? Can we do so without imposing impractical requirements on the network infrastructure? Our proposed architecture is based on per-packet One Time Address (OTA)-an address that a host uses to send or receive exactly one packet. Furthermore, the architecture eliminates any implicit (e.g., the standard five-tuple in TCP/UDP packets) or explicit (e.g., flow identifier) flow information from packet headers. Yet, the architecture allows the communicating hosts to demultiplex seemingly unrelated packets to flows. We have implemented the proposed architecture, and our evaluation shows that it can satisfy today's packet forwarding requirements.
机译:Internet上的通信行为不可避免地会泄漏信息。特别地,网络报头揭示信息(例如,源地址,流信息);然而,事实证明,保护插头非常具有挑战性。过去的研究成功地保护了报头的某些字段(例如,源地址),但是没有提案试图从报头中消除流信息,从而使数据包不能链接到流。流信息被系统地用来颠覆隐私。因此,我们研究以下问题:是否可以设计一种消除流包可链接性的体系结构?我们可以在不对网络基础架构施加不切实际的要求的情况下这样做吗?我们提出的体系结构基于每个数据包的一次性地址(OTA),即主机用来发送或接收一个数据包的地址。此外,该架构从分组报头中消除了任何隐式(例如,TCP / UDP分组中的标准五元组)或显式(例如,流标识符)流信息。但是,该体系结构允许通信主机将看似无关的数据包解复用为流。我们已经实现了建议的体系结构,我们的评估表明它可以满足当今的数据包转发要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号