Guaranteed communication despite DDoS attacks – Scion
scion-architecture.net
scion-architecture.net
I note that a bunch of their running instances appear to just be AWS instances presumably set up for testing/marketing purposes - has anyone here actually tried to use this? Thoughts?
The next section "2.4.1 High-Availability Communication": In addition, the SIBRA extension, as described in Chapter 11, offers an extended level of availability through a concept we call DILL, which stands for dynamic inter-domain leased line. DILLs provide a lower bound on the guaranteed bandwidth at inter-domain scale, regardless of the bandwidth requirements of other ASes.
Also on the account of who is running it, the book and FAQ mentions 2 large Switzerland ISPs. Also appears some universities there are using it as well: https://dig.watch/resources/launch-scion-pilot-server.
I probably missed something crucial here, but ... My worry about path selection despite all its theoretical potential is that it's still left to the ISP how they sell this feature to the user (and whether that promised potential materializes for the user as envisioned in the docs today). If an ISP decides which paths are allowed they might give only a subset of what they could offer to the customer, and that would not be in the spirit of "empowering the user". A "malicious" ISP could just box their users into a specific subset of the available routing paths. Or once SCION is adopted widely a country could outlaw certain paths being selected - e.g. routing could be enforced not just to protect but also to allow stricter enforcement of rules in all type of scenarios (e.g. ban communication both with or via specific paths in a trade/cyber/kinetic war, etc).
I mean... maybe? But this is quite a big claim and just saying "yep, it does" with no further info is not a communications strategy that inspires confidence. I had to look about the site for a fair bit before I found the correct whitepaper, and I never managed to find the book until another poster linked it.
> Through authenticating sources and validating paths, the OPT can construct high-level security mechanisms such as DDoS mitigation, path compliance and packet attribution.This is because that the source authentication guarantees the identity of source and the path validation eliminates the illegal use of path by attackers.
I found mention of "Dynamically Recreatable Key (DRKey) protocol" interesting, which it I guess they designed for this (because it only gets mentioned in papers talking about SCION). I'm curious to know how well understood this protocol is within the wider crypto community. DRkey is also explained in this video (https://video.ethz.ch/events/2019/scion/2eff3fa5-6c42-4b28-8...) at the >2 min mark.
At page 14 of the pdf they go on to listing the benefits of each architecture (where SCION seems to be a clear winner):
> We have presented five famous future Internet architectures in details: NDN, COAST, MobilityFirst, XIA and SCION. In this section, we present the pros and cons of each and further compare them in terms of a number of security properties: anonymity, authenticity, integrity, privacy, DoS/DDoS resistance, error/fault resilience, and evolvability.
> Furthermore, the integration of the SCION with the XIA achieves a higher security than the above three architectures, including accountability, anonymity and availability. In order to maintain trust relationships, each entity should hold a secure identifier besides the changeable and various XIDs. Otherwise, an adversary can register into the network with a new identifier that may eliminate its ever-bad records, which results in inaccurate trust evaluation. With greater efforts on security research, the SCION presents more security properties than other four projects, e.g., resisting DDoS attacks, anonymity, authentication, etc. Trust management is mentioned in the NDN, the COAST, and the MobilityFirst as a key technical challenge. But none of them gives a concrete method to manage trust. The SCION presents a detailed discussion on trust management. It adopts the notions of ISDs and TRC to control trust efficiently, which can dominate its own trust and limit the influence of compromised trust root within its own ISD.
...
[1]https://docs.google.com/document/d/1nSiDpCB4fE_GTm3azZtygoWv...