Skip to content

Does QUIC Connection ID provide sufficient session verification at AS border? #1

Description

@scottiep1pen

QUIC uses a Connection ID to identify sessions, but the Connection ID
is chosen by the endpoint and is not cryptographically bound to the
IP/AS of origin at the network layer.

Question for operators and implementers:
Is QUIC Connection ID sufficient as session verification criteria
for a border router to allow UDP inter-AS traffic, or do we need
something stronger at L3/L4?

Related: Section 5.1 and 5.3 of the paper.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions