SIXPACK: Securing internet eXchange points against curious onlookers

Marco Chiesa, Daniel Demmler, Marco Canini, Michael Schapira, Thomas Schneider

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

23 Scopus citations

Abstract

Internet eXchange Points (IXPs) play an ever-growing role in Internet inter-connection. To facilitate the exchange of routes amongst their members, IXPs provide Route Server (RS) services to dispatch the routes according to each member's peering policies. Nowadays, to make use of RSes, these policies must be disclosed to the IXP. This poses fundamental questions regarding the privacy guarantees of route-computation on confidential business information. Indeed, as evidenced by interaction with IXP administrators and a survey of network operators, this state of affairs raises privacy concerns among network administrators and even deters some networks from subscribing to RS services. We design sixpack1, an RS service that leverages Secure Multi-Party Computation (SMPC) to keep peering policies confidential, while extending, the functionalities of today's RSes. As SMPC is notoriously heavy in terms of communication and computation, our design and implementation of sixpack aims at moving computation outside of the SMPC without compromising the privacy guarantees. We assess the effectiveness and scalability of our system by evaluating a prototype implementation using traces of data from one of the largest IXPs in the world. Our evaluation results indicate that sixpack can scale to support privacy-preserving route-computation, even at IXPs with many hundreds of member networks.

Original languageEnglish
Title of host publicationCoNEXT 2017 - Proceedings of the 2017 13th International Conference on emerging Networking EXperiments and Technologies
PublisherAssociation for Computing Machinery, Inc
Pages120-133
Number of pages14
ISBN (Electronic)9781450354226
DOIs
StatePublished - 28 Nov 2017
Externally publishedYes
Event13th International Conference on Emerging Networking EXperiments and Technologies, CoNEXT 2017 - Incheon, Korea, Republic of
Duration: 12 Dec 201715 Dec 2017

Publication series

NameCoNEXT 2017 - Proceedings of the 2017 13th International Conference on emerging Networking EXperiments and Technologies

Conference

Conference13th International Conference on Emerging Networking EXperiments and Technologies, CoNEXT 2017
Country/TerritoryKorea, Republic of
CityIncheon
Period12/12/1715/12/17

Bibliographical note

Publisher Copyright:
© 2017 Copyright held by the owner/author(s). Publication rights licensed to Association for Computing Machinery.

Keywords

  • Interdomain routing
  • Internet eXchange Points
  • Privacy-preserving routing
  • Secure multi party computation

Fingerprint

Dive into the research topics of 'SIXPACK: Securing internet eXchange points against curious onlookers'. Together they form a unique fingerprint.

Cite this