Rethinking Routing Security in Named Data Networking
JACOB ZHI’S CAPSTONE PROJECT
presented by Lixia Zhang
The existing implementation
NDN routing: another application built on NDN
Separation of Routing and Forwarding
The basic difference existing and new designs
NFDc package unchanged?
NDN autoconfigu issue?
The new design
This work focuses on step-1; step-2 is determined by the routing protocol in use
Making prefix insertion request as versioned data simplifies (compared to tracking signed Interests)
To address the initialization-order problems (if certificates are unavailable until their prefix, and all other required prefixes in the verification chain, are added to routing, data producers can attach certificates to the prefix insertion
prefix registration protocol’s control command (signed interest)
prefix insertion protocol uses Interest to carry the insertion request as named, secured data
Prefix insertion
New routing security design gives ISPs flexibility
Examples: