SCION
SCION - The new Internet connectivity
Transition from Border Gateway Protocol to SCION's new network architecture.
The problem with traditional internet
While the public internet offers universal access, it lacks security, reliability, and control, posing significant risks for businesses. Current protocols and infrastructures are unable to cope with the evolving landscape of cyber threats or the growing demand for stable and fast connectivity, leading to potential disruptions and vulnerabilities.
The internet with SCION
In response to the demands and challenges of the modern network, SCION was developed at ETH Zurich. A groundbreaking internet architecture that takes communication on public networks to a new level of security. SCION-based solutions combine the reach of the public internet with the robust security associated with private network infrastructure, ensuring flexibility, efficiency, and the highest standards of compliance and resilience.
SCION, which stands for Scalability, Control, and Isolation on Next-generation Networks, redefines the way data is transmitted over the internet. Unlike traditional internet protocols, which forward data via arbitrary paths, SCION enables precise control over data flow and ensures that packets are transmitted via predefined, secure paths.
SCION not only makes data traffic more secure, but also more resilient. The protocol’s multi-path routing function ensures that data can be immediately switched to another route even if one path fails, maintaining uninterrupted service and providing businesses with a more reliable, secure, and compliant means of data transmission.
Path Control & Multipath
SCION enables the sender to control routing and decide exactly how and where data packets are transmitted. With the multipath function, senders can select multiple paths simultaneously.
Isolation domain
The SCION isolation domain creates a secure entity that connects service providers and users in a trusted environment. This setup increases security and simplifies network management, see SSUN for example.
Explicit trust
With SCION, you can visualize and authenticate the path of your data using cryptographic methods. This explicit trust mechanism ensures secure and transparent data transmission.
The network structure of the SCION network
SCION combines the positive characteristics of the Internet—flexible, cost-effective, and an MPLS line—secure and reliable.
The performance of isolation domains in SCION
The architecture of SCION is structured around isolation domains (ISDs), which can be combined to form large networks. These domains group autonomous systems (ASs) together, enabling secure and reliable network communication. Each AS requires a special certificate to join an ISD. This ensures that network access and routing are strictly regulated, with enforced policies to ensure secure and efficient data flow and compliance with regulations.
Isolation domains available today are:
SSFN (Swiss Secure Finance Network) for the financial sector
SSHN (Swiss Secure Health Network) for the healthcare industry
SSUN (Swiss Secure Utility Network) for the utility industry
SEPN (Secure EFTPOS Network) for payment systems
