A trusted network path is a desired property of the Internet. Previous works introduced new protocol headers based on source routing for source authentication and path verification. It is obvious that any extra protocol headers will increase the network burden, and network path privacy deserves attention, especially when we use source routing. The emergence of IPv6 Segment Routing (SRv6) may bring the opportunity to assemble trusted network paths with a lightweight header. In this paper, we propose SR-TPP, a novel mechanism based on SRv6 to support network path verification meanwhile hides both-end and path information. Different from existing works, SR-TPP extends SRv6 function instead of introducing a new protocol header to meet the requirement of path compliance. Path information is sequentially encoded into the segment list in SR-TPP so that path information is partially visible to each intermediate router. The distributed verification of SR-TPP also makes it easier to locate faults. Finally, the security analysis and evaluation show that SR-TPP can assemble private and trusted network paths with acceptable performance.
SR-TPP: Extending IPv6 Segment Routing to enable Trusted and Private Network Paths