Securing Load Balancing over QUIC

📅 2026-08-04
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses a core challenge in QUIC load balancing: ensuring that packets within the same stream are consistently mapped to the same backend server under dynamically changing server pools and constrained data-plane resources, all while preserving the unlinkability requirement of QUIC connection IDs. The paper presents the first stateless load balancing scheme fully compliant with the QUIC specification, requiring no modifications to connection IDs or backend servers. By leveraging programmable switch ASICs, it implements protocol-aware, stateless hash-based forwarding and allows non-initial packets to bypass the load balancer for improved performance. The design also identifies and mitigates emerging security threats, such as load balancer bypass and 0-RTT IP spoofing, achieving high throughput and strong security without compromising standards compliance.
📝 Abstract
In-network load balancing outperforms traditional software load balancing while costing less. For instance, programmable switch ASICs can use hashing to select the backend server for the initial packet of each flow at the line rate. However, when the pool of available servers changes, ensuring that the subsequent flow packets are mapped to the same server is challenging due to the data plane's limited memory resources and performance requirements. With the emergence of the QUIC transport protocol, several works show how Connection ID fields (CIDs) can embed the server identifier for all non-initial packets. This approach requires modifications on the server side and violates the QUIC specification, which mandates that CIDs remain unlinkable. In this work, we show that stateless QUIC load balancing can be implemented inside the data plane with no changes to CIDs. Moreover, QUIC packets, except the initial client packet, can bypass the load balancer. We also investigate and mitigate attacks on QUIC in this scenario, including full load balancer bypass and 0-RTT IP spoofing.
Problem

Research questions and friction points this paper is trying to address.

QUIC
load balancing
Connection ID
security
stateless
Innovation

Methods, ideas, or system contributions that make the work stand out.

stateless load balancing
QUIC
in-network load balancing
Connection ID
security mitigation
🔎 Similar Papers
G
Garegin Grigoryan
Alfred University
D
Dagim Mindaye
Alfred University
S
Shireen Maini
Rochester Institute of Technology
Minseok Kwon
Minseok Kwon
Professor of Computer Science, Rochester Institute of Technology
Computer networks