Internet-Draft Green Security July 2026
Soares & Nobre Expires 21 January 2027 [Page]
Workgroup:
Network Working Group
Internet-Draft:
draft-soares-sustain-green-security-00
Published:
Intended Status:
Informational
Expires:
Authors:
L. R. Soares
Federal University of Rio Grande do Sul
J. C. Nobre
Federal University of Rio Grande do Sul

Research Directions on Energy-Aware Security Mechanisms

Abstract

With the advancement of the climate emergency, all areas of human activity are expected to continuously assess their Greenhouse Gas emissions and encourage the use of clean energy as much as possible. The current discussion on green networking in the Network Management research field still needs to be expanded to the adjoined areas, such as Network Security. This document outlines possible research directions for energy-aware security mechanisms.

Status of This Memo

This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.

Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.

Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."

This Internet-Draft will expire on 21 January 2027.

Table of Contents

1. Introduction

Computer networking and the Internet are no exception to the global necessity of reducing CO2 emissions. Strategies to use energy efficiently can target the Internet backbone infrastructure, hardware components, protocols, and so on. Regardless of the approach, the green networking effort must follow from robust measurement frameworks capable of providing comprehensive visibility into the energy consumption of the network [RFC9845].

Despite the advancements on green networking, much of the discussion still needs to be expanded to adjoined research fields, such as network security. Security protocols and applications are some of the more expensive, and are likely to show up in measurement tools as top consumers of energy resources. However, neglecting them in modern applications is simply not possible. Policies and guidelines must take functionality into account when regarding energy consumption, or risk compromising security algorithms.

This document discusses the case for security protocols and applications to be regarded with special attention inside the green networking effort, and outlines future research directions for this goal.

2. Security Considerations in Green Networking

In most of the works in green networking so far, the security considerations are mostly regarding extra attack surface brought by the energy measurement tools and controls. An attacker might use these mechanisms to put resources to sleep in critical moments, drain energy to cause damage such as overheating and battery loss, and to tamper with the energy measurement, which would cause misguided energy saving policies to be put in place. Though these are all important considerations, they are security risks for energy-saving mechanisms and not energy-saving considerations for security mechanisms.

3. Research Directions on Energy-Aware Security Mechanisms

This document presents a non-exhaustive list of possible research challenges regarding the scope of security mechanisms in green networking. To illustrate possible outcomes of these research directions, we use the case of energy consumption of VPN protocols in Consumer-Premises Equipment (CPE) devices. In 2023, Netflix estimated that CPE devices accounted for roughly 38% of total carbon emissions of streaming service usage [Netflix-environmental]. VPN protocols can significantly increase both the processing load and the communication overhead of network devices, and consequently, their energy consumption.

The purpose of this example is to discuss the research topics of the green networking area when it comes to security--this is an informational document and should not be regarded as a standard proposal of any kind.

3.1. Measurement and Benchmarking

This research challenge borrows from the general state of affairs in the green networking research field, that is--datasets are needed if we want to make assumptions about energy consumption of protocols and applications. When it comes to security, what experimental setups we can use to assess the energy consumption of networking devices and security protocols, and what data they should collect?

In our VPN-CPE use-case, we used a testbed with an ESP32 and an INA228 current/power monitor to monitor two MikroTik devices operating under varying traffic profiles. We collected the total energy consumed by the device operating under a set VPN protocol, and the total number of bytes successfully delivered during the same interval. We also measured the baseline of no VPN protocol.

Other works benchmarking energy in network equipment are [I.D.draft-ietf-bmwg-powerbench-02] and [I.D.draft-elzahr-flow-carbon-trace-00].

3.2. Metrics in the Security Context

Are the energy metrics used in the context of security applications and protocols any different from the regular traffic metrics from the general green networking field? Do they need to be? Security protocols and applications often have greater costs if compared with other networking protocols. Energy consumption metrics should take functionality into account to avoid compromising security properties.

For example, we measured the energy cost of the CPE devices running each VPN protocol in millijoules per megabyte (mJ/MB). We then used the energy cost against the equipment's baseline of no VPN to compute a metric we called the Net Energy Cost of each protocol--that is, the energy cost beyond the idle operation. However, this method still raises some questions. How these metrics vary with protocol functionality? In other words, the Net Energy Cost of other network protocols will be lower than the VPN's, but this doesn't mean the VPN should be turned off to save energy.

Even more importantly, are any of these metrics up for industry-wide standardization? The standardization effort of energy metrics in networking is a key step for energy awareness throughout the entire Internet. Solid standards can avoid proprietary, redundant, and even contradictory metrics from taking hold across different vendors [RFC9547].

3.3. Cost-benefit analysis

When considering a security protocol or application, how can we assess if energy can be saved with little harm to safety and functionality? A fundamental aspect of risk-based security is that protocol selection should be guided by the needs of each deployment scenario, even before sustainability concerns come into consideration. However, there's a lack of visibility into the energy requirements of security protocols, which excludes the energy aspect from this cost-benefit analysis. Standard networking metrics such as throughput, jitter, and latency are well established--this should be the case for energy-efficiency metrics as well.

In the VPN-CPE use-case scenario, each VPN protocol we tried had different cryptographic and security guarantees. Measuring the mentioned energy metrics revealed a trade-off between energy consumption, throughput, latency, and security properties--which would be helpful to a network operator designing the security architecture of a network or application.

4. Security Considerations

To be added.

5. Sustainability Considerations

To be added.

6. IANA Considerations

To be added.

7. Acknowledgements

We thank the sustain RG chairs for their comments on the original version of this draft.

8. Informative References

[RFC9845]
Clemm, A., Ed., Pignataro, C., Ed., Westphal, C., Ciavaglia, L., Tantsura, J., and M. Odini, "Challenges and Opportunities in Management for Green Networking", RFC 9845, DOI 10.17487/RFC9845, , <https://www.rfc-editor.org/rfc/rfc9845>.
[RFC9547]
Arkko, J., Perkins, C. S., and S. Krishnan, "Report from the IAB Workshop on Environmental Impact of Internet Applications and Systems, 2022", RFC 9547, DOI 10.17487/RFC9547, , <https://www.rfc-editor.org/rfc/rfc9547>.
[I.D.draft-ietf-bmwg-powerbench-02]
Pignataro, C., Jacob, R., Fioccola, G., Wu, Q., Chen, G., and S. Prabhu, "Characterization and Benchmarking Methodology for Power in Networking Devices".
[I.D.draft-ietf-green-terminology-02]
Chen, G., Boucadair, M., Wu, Q., Contreras, L. M., and M. Palmero, "Terminology for Energy Efficiency Network Management", n.d..
[I.D.draft-elzahr-flow-carbon-trace-00]
Zahr, S. E., Schooler, E., Soulé, R., and N. Zilberman, "Flow-Level Carbon Emissions Tracing for Packet Networks", n.d..
[Netflix-environmental]
"2023 Netflix Environmental, Social & Governance Report", , <https://s22.q4cdn.com/959853165/files/doc_downloads/2024/6/2023-Netflix-Environmental-Social-Governance-Report.pdf>.

Appendix A. Changelog

Authors' Addresses

Laura Rodrigues Soares
Federal University of Rio Grande do Sul
Porto Alegre-
Brazil
Jeferson Campos Nobre
Federal University of Rio Grande do Sul
Porto Alegre-
Brazil