首页> 外文会议>IFIP/IEEE International Symposium on Integrated Network Management >The Horizontal INR Conflict-Detection Algorithm: Revealing INR Reallocation and Reauthorization in RPKI*
【24h】

The Horizontal INR Conflict-Detection Algorithm: Revealing INR Reallocation and Reauthorization in RPKI*

机译:水平INR冲突检测算法:在RPKI中揭示INR重新分配和重新授权*

获取原文

摘要

Resource Public Key Infrastructure (RPKI) is a promising security enhancement to the Border Gateway Protocol, but it only requires the relying party (RP) to validate Internet Number Resource (INR) allocation or authorization relationships expressed in parent-child certificate pairs vertically. Therefore, conflicts in INR allocation and authorization may exist because of the limitations of the validation procedure of the RP software, in other words, certification authority malfunctions in issuing RPKI objects within a publication point cannot be detected by the RP. We develop a model of such conflicts and propose a horizontal INR conflict-detection algorithm with acceptable build time and query time. The proposed algorithm was tested on real-world RPKI data to identify actual and potential INR conflicts and its accurateness has been tried to be evaluated. This paper also discusses the deployment issues and the accuracy dependence about our algorithm design.
机译:资源公钥基础架构(RPKI)是对边界网关协议的有希望的安全增强,但它只需要依赖方(RP)来验证垂直于父儿童证书对中表达的Internet号码资源(INR)分配或授权关系。 因此,由于RP软件的验证过程的限制,可能存在INR分配和授权中的冲突,换句话说,RP无法检测到在发布点内发出RPKI对象的认证机构故障。 我们开发了这种冲突的模型,并提出了一种具有可接受的构建时间和查询时间的水平INR冲突检测算法。 该算法在真实世界的RPKI数据上进行了测试,以识别实际和潜在的INR冲突,并且已经尝试评估其准确性。 本文还讨论了部署问题和关于我们算法设计的准确性依赖性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号