首页> 外文会议>European Symposium on Research in Computer Security >Symmetric Key Approaches to Securing BGP— A Little Bit Trust Is Enough
【24h】

Symmetric Key Approaches to Securing BGP— A Little Bit Trust Is Enough

机译:保护BGP的对称密钥方法 - 一点点信任就足够了

获取原文
获取外文期刊封面目录资料

摘要

The Border Gateway Protocol (BGP) is the de facto inter-domain routing protocol that connects autonomous systems (ASes). De-spite its importance for the Internet infrastructure, BGP is vulnerableto a variety of attacks due to lack of security mechanisms in place. ManyBGP security mechanisms have been proposed, however, none of themhas been deployed because of either high cost or high complexity. Theright trade-off between efficiency and security has been ever challenging.In this paper, we attempt to trade-off between efficiency and secu-rity by giving a little dose of trust to BGP routers. We present a newflexible threat model that assumes for any path of length h, at leastone BGP router is trustworthy, where h is a parameter that can betuned according to security requirements. Based on this threat model,we present two new symmetric key approaches to securing BGP: the cen-tralized key distribution approach and the distributed key distributionapproach. Comparing our approaches to the previous SBGP scheme, ourcentralized approach has a 98% improvement in signature verification.Our distributed approach has equivalent signature generation cost as inSBGP and an improvement of 98% in signature verification. Comparingour approaches to the previous SPV scheme, our centralized approachhas a 42% improvement in signature generation and a 96% improvementin signature verification. Our distributed approach has a 90% improve-ment on signature generation cost and a 95% improvement in signatureverification cost. By combining our approaches with previous public keyapproaches, it is possible to simultaneously provide an increased level ofsecurity and reduced computation cost.
机译:边界网关协议(BGP)是连接自治系统(ASES)的事实上的域间路由协议。除了缺乏安全机制,BGP是对互联网基础设施的重要性,BGP是庞大的攻击。然而,已经提出了ManyBGP安全机制,因此由于高成本或高复杂性而部署了HINAHA。效率和安全之间的Theright折衷已挑战。在本文中,我们试图通过给予BGP路由器的一点点信任,试图在效率和SECU-RIET之间进行权衡。我们介绍了一个新的威胁模型,假设对于任何长度H路径,至少是BGP路由器是值得信赖的,其中H是可以根据安全要求筹集的参数。基于这种威胁模型,我们提出了两个新的对称密钥方法来保护BGP:CEN三元化关键分布方法和分布式密钥分发人数。比较我们对先前的SBGP方案的方法,签名验证的签名方法有98%提高。分布式方法具有同等签名生成成本作为INSBGP,签名验证的提高98%。比较论然,先前的SPV方案,我们的集中式方法在签名生成中提高了42%,提高了96%的签名验证。我们的分布式方法对签名生成成本有90%的提高,签名成本提高了95%。通过将我们的方法与以前的公共关键关键的方法相结合,可以同时提供增加的安全水平和减少的计算成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号