[2622] in Commercialization & Privatization of the Internet
AUPs
daemon@ATHENA.MIT.EDU (yakov@watson.ibm.com)
Mon Mar 23 12:44:49 1992
Date: Mon, 23 Mar 92 12:39:08 EST
From: yakov@watson.ibm.com
To: peter@goshawk.lanl.gov
Cc: com-priv@psi.com
>I believe most people will agree that the microphysics of hop by hop
>destination based packet forwarding makes enforcing AUPs which talk about
>end to end flows hard to enforce thru routing.
The problem with supporting/enforcing AUPs is that some of them are
expressed in terms that are not easily translatable into parameters present
in the IP header. An example of such situation is the NSFNET AUP
where NSFNET is required to restrict its traffic to R&E.
Unfortunately there is nothing in IP header that would allow to
indicate that a particular packet belongs to R&E traffic.
So, that supporting such AUP at the network layer becomes problematic.
Please note that source/destination addresses have little or
nothing to do with whether a packet belongs to R&E traffic.
Therefore, blaming the problem on destination based packet forwarding
and promoting other schemes (like source/destination based packet
forwarding as a solution to the problem of enforcing AUPs) is a step
in a wrong direction. Indeed, using addresses as a mechanism to
support AUPs is nothing more than overloading these fields with the
semantics they were not intended to carry.
In such a situation there are only three choices to support such AUPs:
a) change AUPs, so that the restrictions may be expressed in terms
of parameters present in the IP header
b) change/modify network layer protocol (IP) to something else, so that
the restrictions stated in AUPs will be translatable into parameters
present in the network layer header (e.g. define a new TOS that
would indicate R&E traffic)
c) support AUPs at upper layers via application layer gateways
Observe that support for AUPs, by itself, does not guarantee the
verification/enforcement. Indeed, even if a particular
mechanism may be suitable to support an AUP (e.g. TOS),
enforcement of such AUP may be impractical,
since it would require "that one look into
the contents of every datagram that passes through a gateway
between networks with different standards. Even then it is not
clear how one would determine if the contents are ok." (see
e-mail from Dan Schlitt to com-priv 3/23/92). Given this
situation one may ask about the relevence of AUP that can not be
verified/enforced.
>It is important to note that this does not mean that this is an
>unsolvable problem, and in fact, one can look at work like InterDomain
>Policy Routing to provide a clue as to what we might expect in the
>future.
If, indeed, you think that InterDomain Policy Routing provides
a clue "as to what we might expect in the future", then
let's shed more light on several aspects of this "future":
1. Size of the forwarding tables is likely to be large enough
in quite a few places within the Internet to make the whole
scheme impractical
2. Size of routing information is likely to be large enough
all over the Internet to make storage of this information
impossible, and timely computation over this information problematic.
3. A domain that has a complex AUP will require ALL the domains
within the Internet to share the burden of supporting a particular
routing scheme and bare the overhead burden, regardless of whether
other domains care or not about this AUP. In practical terms it
means that supporting NSFNET AUP would require to put unjustifiable
burden on all the commercial service providers, like CIX members,
who have nothing to do with the NSFNET AUP.
These are just few aspects, not an exhaustive list...
And, by the way, it still does not solve the NSFNET AUP problem.
>Can we agree that it is unlikely every network in the Internet
>will want to be a transit for every other network ?
There are two distinct types of networks: commercial and
federally funded. With respect to commercial networks
they'll be willing to act as a transit as long as there is
a settlement scheme in place.
Your assertion may be true with respect to the federally funded
networks, but the restriction on transit may be easily enforced
via controlled distribution of routing information (which is
not a new technology at all).
>I suggest the solution is to apply better technology, in other words,
>get a new physics.
I suggest that before applying "new physics" we need to perform
very careful cost/benefit analysis, so that the "new physics"
would not cost more than it would allow to save. After all,
federally funded networks should be concern not just with
the "special networks to special problems", but with the cost of
such special networks.
>I would also argue that in the future many commercial ventures will want
>to have policies which look a lot like AUPs.
Given the nature of current AUPs the above means to imply that
in the future many commercial ventures will want to have
support for absolutely arbitrary things that need not be:
a) implementable
b) verifiable
c) enforceable
Perhaps "this will be a natural state when the cost" of developing
new software and putting more memory, CPU and bandwidth, "reaches
its limit of zero, but we are not there today." (Quotations
are from the original mail).
Also, while we may argue about some future needs, one just need
to look at the current commercial ventures to count how many
AUPs they would like to impose.
>Time for new tech, new forwarding micro physics, more bits...
Time to sit and have a rationale discussion on the problems we
need to solve, rather than trying to push a particular solution that
may not necessarily solve the problem we need to solve, but instead
introduces few new problems.
Time to look at the overall managebility of an environment with
unconstrained proliferation of arbitrary AUPs.
Time to take a rationale evaluation of the overall picture
(and not just a microscopic view) and make very careful cost/benefit
assessment of any proposed solution (given that we first define
what is the problem we need to solve).
Time to realise that the Internet is not just a collection of federally funded
networks, but more and more pure commercial service providers,
to whom AUPs may not be relevant.
Yakov Rekhter