Affiliation:
1. Cornell University, Ithaca, NY
Abstract
The current model for flow establishment in the Internet: DNS Names, IP addresses, and transport ports, is inadequate. Not all of the problem is due to the small IPv4 address space and resulting NAT boxes. Even where global addresses exist, firewalls cannot glean enough information about a flow from packet headers, and so often err, typically by being over-conservative: disallowing flows that might otherwise be allowed. This paper presents a novel architecture, protocol design, and implementation, for flow establishment in the Internet. The architecture, called NUTSS, takes into account the combined policies of endpoints and network providers. While NUTSS borrows liberally from other proposals (URI-like naming, signaling to manage ephemeral IPv4 or IPv6 data flows), NUTSS is unique in that it couples overlay signaling with data-path signaling. NUTSS requires no changes to existing protocol stacks, and combined with recent NAT traversal techniques, works with IPv4 and existing NAT/firewalls. This paper describes NUTSS and shows how it satisfies a wide range of "end-middle-end"network requirements, including access control, middlebox steering, multi-homing, mobility, and protocol negotiation.
Publisher
Association for Computing Machinery (ACM)
Subject
Computer Networks and Communications,Software
Reference62 articles.
1. Akamai Technologies Inc. Akamai: How it works. Akamai Technologies Inc. Akamai: How it works.
2. Antisip SARL. The eXtended osip library. Antisip SARL. The eXtended osip library.
Cited by
14 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Programmable Session Layer MULTI-Connectivity;IEEE Access;2022
2. Unveiling the Mystery of Internet Packet Forwarding;ACM Computing Surveys;2021-09-30
3. A Verified Session Protocol for Dynamic Service Chaining;IEEE/ACM Transactions on Networking;2020
4. Dynamic Service Chaining with Dysco;Proceedings of the Conference of the ACM Special Interest Group on Data Communication;2017-08-07
5. Internet With Transient Destination-Controlled Addressing;IEEE/ACM Transactions on Networking;2016-04