CCN Name Chaining for Privacy and Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Content Centric Networking (CCN) networks face issues with privacy and information leaks due to non-secure CCN Names, and lack client-driven naming capabilities similar to IP networks, which affect confidentiality and routing flexibility.
Innovation Solution
Implementing route transforming modules in CCN routers that modify CCN Names by removing route transformer identifiers, generating new CCN Names, and processing requests and replies to provide privacy and enable service chaining and policy-based routing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If CCN Names are made readable for routing purposes, then routing functionality is enabled, but privacy and confidentiality are compromised
Solution Approach 1:
The CCN Name is segmented into two parts: a readable prefix component used for routing decisions by network nodes, and an encrypted content identifier component that preserves privacy. This segmentation allows routing functionality to operate on the visible prefix while the sensitive content identifier remains protected through encryption.
Solution Approach 2:
An intermediary encryption mechanism is introduced between the CCN Name and the routing process. The encryption layer acts as a mediator that allows the routing system to function with readable prefixes while preventing direct exposure of the full unencrypted CCN Name, thus protecting privacy while maintaining routing capability.
2Object-affected harmful factors
If CCN Names are encrypted for privacy protection, then confidentiality is improved, but routing and forwarding capabilities are degraded
Solution Approach 1:
The encryption scheme segments the CCN_name structure into encrypted and unencrypted portions. The prefix portion remains readable for routing table lookups and forwarding decisions, while only the content-specific identifier portion is encrypted. This selective encryption maintains routing capability while achieving confidentiality for the sensitive content identifier.
Solution Approach 2:
Different parts of the CCN Name are treated with different encryption qualities. The prefix portion maintains plain text readability for network routing operations, while the content identifier portion applies strong encryption for privacy protection. This local differentiation of encryption quality allows simultaneous achievement of routing functionality and confidentiality.
3Adaptability or versatility
If route transformer identifiers are included in CCN Names, then service chaining and policy-based routing are enabled, but name length and processing complexity increase
Solution Approach 1:
The service chaining capability is implemented by segmenting the CCN Name into modular components including route transformer identifiers, prefixes, and content identifiers. Each segment serves a specific function and can be independently processed, which reduces overall processing complexity compared to handling a single monolithic name structure.
Solution Approach 2:
The segmented CCN_name structure with route transformer identifiers provides multi-functionality: it enables service chaining, supports policy-based routing, and maintains compatibility with existing CCN routing mechanisms. This universal structure handles multiple routing scenarios without requiring separate processing logic for each case.
Data Source
AI summary
A method provides route transforming by a network device implementing a content centric networking (CCN) gateway or CCN router, where the CCN gateway or CCN router is part of a CCN network. The method transforms a CCN Name in a CCN request before forwarding in the CCN network. The method includes receiving a first CCN request including a first CCN Name, the first CCN Name including a route transformer identifier, generating a modified first CCN Name by removing the route transformer identifier from the first CCN Name, generating a second CCN Name from the modified first CCN Name; and generating a second CCN request including the second CCN Name.


