SCION wants to make the foundations of the internet safer

SCION wants to make the foundations of the internet safer

Today’s internet is structurally susceptible to route hijacks and unwanted, sneaky redirects. That is why the internet must and can be safer, according to the SCION Association. It all starts with the basics, namely the way in which data traffic finds its way over the network. We spoke with co-CEO Nicola Rustignoli about how SCION is building an architecture that cryptographically records network routes. The goal is to broaden network sovereignty and break dependency on individual vendors.

SCION stands for Scalability, Control and Isolation On Next-Generation Networks. Its origins lie more than eleven years ago in a wide-ranging research project. It started at Carnegie Mellon University in the United States and was then thoroughly developed for years at the prestigious ETH Zurich in Switzerland.

In 2017, the commercial spin-off Anapaya was created to bring the academic knowledge gained to the market, after which the non-profit SCION Association was founded in 2022. The association now has various members, ranging from ISPs to end users and academic institutions. The association finances itself through membership fees and grants and focuses mainly on the development of technical specifications, open source management, coordination and the organisation of knowledge events.

How exactly does SCION’s new architecture differ from the regular internet? Rustignoli points to the two essential technical pillars: trust domains and path security, which we will highlight further below.

How SCION works

The first concept, the trust domain, is a network with a uniform, predetermined level of trust that is anchored in cryptography. This creates a federation of telecom providers in which trust at the protocol level is ingrained. In Switzerland, there are already specific trust domains for the Secure Swiss Finance Network (SSFN) and the Secure EFTPOS Network (SEPN), but the architecture also supports broader geographical variants. The public SCION network is based on multiple isolation domains, but they are interconnected. These are designed in such a way that they reduce exposure to unauthorised or untrusted parties and help shrink the attack surface.

An isolation domain in SCION is a clearly defined network domain in which communication is explicitly governed by pre-established cryptographic policies and shared trust rules. Only authorized participants are permitted to communicate with one another, reducing the attack surface and preventing services from being automatically exposed to the public Internet.

The second pillar is path security. On today’s public internet, routers dynamically determine the most efficient route. However, this means that traffic sometimes takes an unnoticed detour via servers in other countries, whether maliciously or not. This poses a significant risk to data security and espionage. SCION, on the other hand, introduces a path-aware architecture that works with path segments instead of traditional forwarding tables. The route is cryptographically recorded in the packet header of the data, after which the routers follow the fixed instructions in the data packet. The sender thus explicitly determines and secures the path through the various autonomous systems. For example, an organization can enforce that highly sensitive traffic physically only travels over Dutch or Swiss ISPs.

In this context, the association chooses the words carefully. In similar situations, it is often about sovereignty, but SCION prefers the term optionality. Freedom of choice is therefore paramount. Some workloads require a strict, local, and secure path, while other, more general data packets are less relevant.

Breaking dependence

While a traditional MPLS connection or leased lines from a large telco can provide a similarly secure path, SCION’s underlying philosophy is fundamentally different. The network is being built as a cooperative federation. As a result, users are no longer dependent on the infrastructure of just one supplier, as is the case with closed global backbones of large cloud players. Instead, they rely on the collective redundancy of a group of connected parties.

It is precisely this focus on federations that makes the global rollout difficult at the same time. To successfully gain traction in a country, you need both the end users and the local telecom providers. Supply and demand must be closely matched in an ecosystem. Whereas adoption in the first few years logically relied mainly on Swiss telcos, the landscape is now starting to break open internationally. Large parties such as BT, Colt and system integrator IBM are now SCION-enabled. This growth is crucial for critical infrastructure. After all, international players already have physical Points of Presence (PoPs) and backbone infrastructure, which means that a new node abroad can be set up much faster.

The Netherlands as a European springboard, with open standards

Besides Switzerland, the Benelux currently has the highest concentration and availability of technical partners. The Dutch ecosystem is showing itself to be particularly willing. Parties such as internet exchanges NL-ix and AMS-IX, provider Odido and connectivity provider Megaport are actively involved. Previously, Odido Business brought the SCION protocol to the Dutch business market, while NL-ix joined forces with Anapaya to further roll out the network across Europe. In addition, the Dutch education and research network SURF has been supporting the SCION architecture for years and the maintenance of the open-source reference implementation is co-financed by European funds through the Netherlands-based NLnet foundation.

To drive widespread adoption, the technology continues to rely heavily on open standards and specifications. The reference implementation is completely open source. In addition, the association is working on the technical specifications within the IETF (Internet Engineering Task Force), a long-term process of which the publication of the necessary RFCs (Request for Comments) is now approaching the final phase. An important operational step is that the association will take over the management of the SCION registry. This body distributes the numbers that identify SCION networks and autonomous systems. This management is free of charge for members, non-members pay a fee.

Innovation through Clockwire and Hummingbird

Although the basic architecture now proves its stability in production environments, academic development at ETH Zurich does not stand still. For example, researchers focus on projects that are currently making the transition from the laboratory to commercial practice.

The first project, Clockwire, focuses on high-accuracy time synchronization over the network. Today, IT systems and critical infrastructures rely on time signals from GNSS (such as GPS and Galileo). However, these wireless signals are relatively easy to jam or manipulate (spoofing). Because SCION paths are perfectly reversible and the architecture allows for proactively selecting the route with the lowest delay and jitter via multipathing, Clockwire offers a robust alternative over the landline. In early tests, the precision of time synchronization across the network was dramatically improved, from about 50 microseconds to just 5 to 10 microseconds.

The second initiative, Hummingbird, offers the possibility of automated bandwidth reservations. With this technology, a regular SCION connection is temporarily scaled up to a reserved leaseline with guaranteed capacity. ISPs can offer their available, unused bandwidth through an automated marketplace. A customer or application can then dynamically purchase this capacity, for example exactly 10 megabits per second, strictly reserved for the duration of one minute, over one specific geographical path. This opens doors for extremely time-critical applications. Think of a surgeon operating remotely safely and without lag, industrial robotics or ultra-competitive gaming applications where every millisecond of delay makes a difference.

A gradual evolution

SCION will not replace the Border Gateway Protocol, on which the current internet relies for routing, overnight. However, SCION explicitly positions itself as an overlay network that can run powerfully alongside and on top of the existing internet.

According to Rustignoli, building these trust networks and scaling up the international footprint simply takes time and patience. With the transfer of the registry, the progress within the IETF specification and the proven traction within the Benelux, the foundation seems to be in place. The next phase is to broaden the ecosystem so that the internet gradually becomes a safer place.