Sovereignty for Routing, DNS, and Time Synchronization

Status:

This project started in March 2026 and is ongoing.

Researchers:

Marco Pioppini
Eduarda Assunção
Marc Frei
Dr. Tilmann Zäschke
Dr. Marc Wyss
Prof. Dr. Adrian Perrig

Industry Partner:

armasuisse

Description:

The Network Security (NetSec) group collaborates with armasuisse to advance sovereignty for critical distributed infrastructures. They propose to pursue the overarching theme of system dependency scoping for availability, where the dependencies of networked systems are transparent and under explicit control. In today’s distributed systems, identifying and controlling dependencies is challenging, as reflected in Leslie Lamport’s well-known observation: “A distributed system is one in which the failure of a computer that you didn’t even know existed can render your own computer unusable.” To enable sovereign operation of critical infrastructures, we aim to establish a foundation that provides sovereignty in routing, DNS, and time synchronization.

The SCION Internet architecture provides a strong foundation for sovereign routing and packet forwarding over shared, multi-provider infrastructure. Fine-grained control over packet forwarding is enabled through the FABRID extension, developed in collaboration with armasuisse. Routing sovereignty is achieved through fault isolation domains (ISDs), which allow routing policies to be defined and enforced independently of external entities. However, the creation of ISDs introduces management complexity and additional routing overhead, potentially limiting scalability. We therefore aim to develop light-weight ISDs that substantially reduce the operational cost of ISD creation while preserving SCION’s scalability and security guarantees. By enabling dependency scoping for routing, light-weight ISDs provide a foundation for higher-layer services, including DNS and time synchronization.

DNS is a critical dependency for most networked applications, and DNS failures can directly affect their availability and correct operation. As a globally distributed system spanning multiple administrative domains, DNS often relies on entities outside an operator’s control. It is therefore essential to restrict dependencies to trusted parties and to protect critical DNS infrastructure from external denial-of-service attacks. We aim to design and implement a DNS architecture that guarantees request processing while eliminating unnecessary external dependencies. The resulting system will ensure continued name resolution for critical infrastructure systems.

Time synchronization is another essential service for distributed systems, where disruptions to availability or correctness can lead to system failures. NetSec aims to design and implement a time synchronization architecture that maintains close system-wide synchronization even when external reference time sources are unavailable or cannot be trusted. Building on their previous work on robust and highly available time synchronization, they will extend these mechanisms to provide sovereign operation and reduce reliance on external entities.