USENIX Security2020Top-tier venue
EPIC: Every Packet Is Checked in the Data Plane of a Path-Aware Internet
Markus Legner, Tobias Klenze, Marc Wyss, Christoph Sprenger, Adrian Perrig
Abstract
An exciting insight of recent networking research has been that path-aware networking architectures are able to fundamentally solve many of the security issues of today's Internet, while increasing overall efficiency and giving control over path selection to end hosts. In this paper, we consider three important issues related to this new networking paradigm: First, network operators still need to be able to impose their own policies to rule out uneconomical paths and to enforce these decisions on the data plane. Second, end hosts should be able to verify that their forwarding decisions are actually followed by the network. Finally, both intermediate routers and recipients should be able to authenticate the source of packets. These properties have been considered by previous work, but there is no existing system that achieves both strong security guarantees and high efficiency. We propose EPIC, a family of data-plane protocols that provide increasingly strong security properties, addressing all three described requirements. The EPIC protocols have significantly lower communication overhead than comparable systems: for realistic path lengths, the overhead is 3-5 times smaller compared to the state-of-the-art systems OPT and ICING. Our prototype implementation is able to saturate a 40 Gbps link even on commodity hardware due to the use of only few highly efficient symmetric cryptographic operations in the forwarding process. Thus, by ensuring that every packet is checked at every hop, we make an important step towards an efficient and secure future Internet.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- Don't Yank My Chain: Auditable NF Service ChainingGuyue Liu, Hugo Sadok, Anne Kohlbrenner, Bryan Parno et al.NSDI 2021 · 17 citations
- Protecting Critical Inter-Domain Communication through Flyover ReservationsMarc Wyss, Giacomo Giuliari, Jonas Mohler, Adrian PerrigCCS 2022 · 4 citations
- Zero-setup Intermediate-rate Communication Guarantees in a Global InternetMarc Wyss, Adrian PerrigUSENIX Security 2024 · 3 citations
- Off-Path Network Traffic Manipulation via Revitalized ICMP Redirect AttacksXuewei Feng, Qi Li, Kun Sun, Zhiyun Qian et al.USENIX Security 2022
- ChainPatrol: Balancing Attack Detection and Classification with Performance Overhead for Service Function Chains Using Virtual TrailersMomen Oqaily, Hinddeep Purohit, Yosr Jarraya, Lingyu Wang et al.USENIX Security 2024
Builds on3
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
- SIBRA: Scalable Internet Bandwidth Reservation ArchitectureCristina Basescu, Raphael M. Reischuk, Pawel Szalachowski, Adrian Perrig et al.NDSS 2016 · 61 citations
- High-Speed Inter-Domain Fault LocalizationCristina Basescu, Yue-Hsun Lin, Haoming Zhang, Adrian PerrigS&P 2016 · 16 citations
Related papers
- Symphony: Path Validation at ScaleAnxiao He, Jiandong Fu, Kai Bu, Ruiqi Zhou et al.NDSS 2024
- 1BIT: Persistent Path Validation with Customized Noise Signal CharacteristicsKeji Miao, Jie Yuan, Xinghai Wei, Xingwu Wang et al.CCS 2025
- FABRID: Flexible Attestation-Based Routing for Inter-Domain NetworksCyrill Krähenbühl, Marc Wyss, David A. Basin, Vincent Lenders et al.USENIX Security 2023
- EPIC: Abstraction and Polymorphism of In-Network Collectives on EthernetYitao Yuan, Jianglong Nie, Tianyu Bai, Ruizhe Zhou et al.SIGCOMM 2026 · 1 citation
- OwlC: Compiling Security Protocols to Verified, Secure, High-Performance LibrariesPratap Singh, Joshua Gancher, Bryan ParnoUSENIX Security 2025
