Towards Internet-Scale Inter-Domain Path Verification

Wenbo Zhao, Xiaoliang Wang, Yangfei Guo · 2025

The Internet lacks mechanisms to verify the authenticity of packet forwarding paths, leading to numerous attacks that manipulate the data plane forwarding process. In response to such security threats, path verification is clearly essential. This security solution ensures that data packets remain untampered and their forwarding paths are authentic. However, existing path verification schemes are constrained by two major challenges: First, in large-scale deployment scenarios, each node must maintain a point-to-point trust relationship across the entire deployment, significantly increasing router processing delays and storage overhead. Second, a complete packet forwarding path often traverses regions with varying management and verification policies, which current path verification schemes struggle to unify. To address these issues, this paper proposes a novel data plane path verification scheme called HVTT(Hierarchical Path Verification with Trust Transfer). HVTT adopts the concept of Address Domain to facilitate cross-domain trust transfer, dividing the end-to-end forwarding process into collaborative efforts across several address domains. Different path verification methods can be employed between various Autonomous Systems (ASs) within an address domain. The verification and exchange of labels across address domains facilitate trust transfer. Its hierarchical design substantially reduces the number of trust relationship objects that need to be maintained. The trust transfer method enables cooperation between address domains, allowing effective adaptation to different security policy regions along the path. We implemented the HVTT prototype on VMware, and experiments showed that HVTT reduced forwarding verification delay by 40.47 % and increased throughput by 37.28 % compared to OPT in a four-hop Round-Trip Time (RTT) scenario.

Read the paper · More papers on PaperTik