Lets just throw away the concept of 'addresses' for authentication and actually use a cryptographic authentication identifier of somekind, combined with some mux iteration ID.
Lets just throw away the concept of 'addresses' for authentication and actually use a cryptographic authentication identifier of somekind, combined with some mux iteration ID.
It implements a virtual ethernet layer using cryptographic identities underneath.
Here's the relevant section on the address computation from the manual: https://www.zerotier.com/manual.shtml#2_1_2
ZT is designed to just be an end to end encrypted virtual LAN for anything you want to dump across it.
There's also a library implementation which effectively gives every app its own cryptographically-derived address (if that's what you're into).
What specifically do you mean by that, and are you sure that it still applies to the IETF version?
I've not read about the IETF version; I'll look into it.
Mentioning ideas like that at work get queer looks about how it'd be impossible to configure a firewall at that point
But keep going further. End up with 128 bit CPU where every byte is IP addressable. Necessary security to block random outsiders from reading your memory, but capable of potentially running various parts remotely transparently
That does imply that there should be a way (possibly host to host, possibly build in to some kind of service resolution system) of looking up a 'name entry' and 'service type'.
This is already a thing: https://en.wikipedia.org/wiki/Remote_direct_memory_access
The folks at IETF meetings are doing a wonderful job trying to keep existing tech working. That's why you always extend old standards and rarely deprecate anything. Just look at BGP, for example.
We, the application software programmers on layers 5 through 7 with the "move fast and break things" attitude, could not ever have designed anything like the internet and keep it running as long as our current one has been.
Might be an interesting weekend project sometime.
That could be extended to the server side if we used something like SRV records instead of defaulting to port 80/443.
JdeBP's post provides a good answer about the SRV records. The short version is a single DNS packet can contain both A/AAAA and SRV responses.
Not for any technical reasons, though--I'm just lazy, and specifying port numbers is annoying.
Why is that? Wouldn't those addresses be hierarchical?
Mobile addresses for applications would make the usual case of "hey, you migrate service X to that other switch, and nothing works anymore" basically disappear.
https://en.wikipedia.org/wiki/Host_Identity_Protocol
Anyone know what's going on with those protocols?
Didn't Apple use something called Multipath TCP for mobile connections? Is that vaguely related to mobile IP?
https://www.usenix.org/system/files/conference/nsdi12/nsdi12...