QUIC uses a Connection ID to identify sessions, but the Connection ID
is chosen by the endpoint and is not cryptographically bound to the
IP/AS of origin at the network layer.
Question for operators and implementers:
Is QUIC Connection ID sufficient as session verification criteria
for a border router to allow UDP inter-AS traffic, or do we need
something stronger at L3/L4?
Related: Section 5.1 and 5.3 of the paper.
QUIC uses a Connection ID to identify sessions, but the Connection ID
is chosen by the endpoint and is not cryptographically bound to the
IP/AS of origin at the network layer.
Question for operators and implementers:
Is QUIC Connection ID sufficient as session verification criteria
for a border router to allow UDP inter-AS traffic, or do we need
something stronger at L3/L4?
Related: Section 5.1 and 5.3 of the paper.