@techreport{vyncke-6man-segment-routing-security-02, number = {draft-vyncke-6man-segment-routing-security-02}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-vyncke-6man-segment-routing-security/02/}, author = {Éric Vyncke and Stefano Previdi and David Lebrun}, title = {{IPv6 Segment Routing Security Considerations}}, pagetotal = 13, year = 2015, month = feb, day = 27, abstract = {Segment Routing (SR) allows a node to steer a packet through a controlled set of instructions, called segments, by prepending a SR header to the packet. A segment can represent any instruction, topological or service-based. SR allows to enforce a flow through any path (topological, or application/service based) while maintaining per-flow state only at the ingress node to the SR domain. Segment Routing can be applied to the IPv6 data plane with the addition of a new type of Routing Extension Header. This document analyzes the security aspects of the Segment Routing Extension Header (SRH) and how it is used by SR capable nodes to deliver a secure service.}, }