> Through authenticating sources and validating paths, the OPT can construct high-level security mechanisms such as DDoS mitigation, path compliance and packet attribution.This is because that the source authentication guarantees the identity of source and the path validation eliminates the illegal use of path by attackers.
I found mention of "Dynamically Recreatable Key (DRKey) protocol" interesting, which it I guess they designed for this (because it only gets mentioned in papers talking about SCION). I'm curious to know how well understood this protocol is within the wider crypto community. DRkey is also explained in this video (https://video.ethz.ch/events/2019/scion/2eff3fa5-6c42-4b28-8...) at the >2 min mark.
At page 14 of the pdf they go on to listing the benefits of each architecture (where SCION seems to be a clear winner):
> We have presented five famous future Internet architectures in details: NDN, COAST, MobilityFirst, XIA and SCION. In this section, we present the pros and cons of each and further compare them in terms of a number of security properties: anonymity, authenticity, integrity, privacy, DoS/DDoS resistance, error/fault resilience, and evolvability.
> Furthermore, the integration of the SCION with the XIA achieves a higher security than the above three architectures, including accountability, anonymity and availability. In order to maintain trust relationships, each entity should hold a secure identifier besides the changeable and various XIDs. Otherwise, an adversary can register into the network with a new identifier that may eliminate its ever-bad records, which results in inaccurate trust evaluation. With greater efforts on security research, the SCION presents more security properties than other four projects, e.g., resisting DDoS attacks, anonymity, authentication, etc. Trust management is mentioned in the NDN, the COAST, and the MobilityFirst as a key technical challenge. But none of them gives a concrete method to manage trust. The SCION presents a detailed discussion on trust management. It adopts the notions of ISDs and TRC to control trust efficiently, which can dominate its own trust and limit the influence of compromised trust root within its own ISD.
...