首页> 外文期刊>Symmetry >BGPcoin: Blockchain-Based Internet Number Resource Authority and BGP Security Solution
【24h】

BGPcoin: Blockchain-Based Internet Number Resource Authority and BGP Security Solution

机译:BGPcoin:基于区块链的互联网号码资源授权机构和BGP安全解决方案

获取原文
           

摘要

Without the design for inherent security, the Border Gateway Protocol (BGP) is vulnerable to prefix/subprefix hijacks and other attacks. Though many BGP security approaches have been proposed to prevent or detect such attacks, the unsatisfactory cost-effectiveness frustrates their deployment. In fact, the currently deployed BGP security infrastructure leaves the chance for potential centralized authority misconfiguration and abuse. It actually becomes the critical yield point that demands the logging and auditing of misbehaviors and attacks in BGP security deployments. We propose a blockchain-based Internet number resource authority and trustworthy management solution, named BGPcoin, to facilitate the transparency of BGP security. BGPcoin provides a reliable origin advertisement source for origin authentication by dispensing resource allocations and revocations compliantly against IP prefix hijacking. We perform and audit resource assignments on the tamper-resistant Ethereum blockchain by means of a set of smart contracts, which also interact as one to provide the trustworthy origin route examination for BGP. Compared with RPKI, BGPcoin yields significant benefits in securing origin advertisement and building a dependable infrastructure for the object repository. We demonstrate it through an Ethereum prototype implementation, and we deploy it and do experiment on a locally-simulated network and an official Ethereum test network respectively. The extensive experiment and evaluation demonstrate the incentives to deploy BGPcoin, and the enhanced security provided by BGPcoin is technically and economically feasible.
机译:没有固有安全性的设计,边界网关协议(BGP)容易受到前缀/子前缀劫持和其他攻击的攻击。尽管已经提出了许多BGP安全方法来防止或检测此类攻击,但是令人满意的成本效益却阻碍了它们的部署。实际上,当前部署的BGP安全基础结构为潜在的集中式授权配置错误和滥用留下了机会。实际上,它变成了关键的屈服点,要求对BGP安全部署中的不良行为和攻击进行记录和审核。我们提出了一种基于区块链的互联网号码资源授权和可信赖的管理解决方案,称为BGPcoin,以提高BGP安全性的透明度。 BGPcoin通过遵照IP前缀劫持分配资源分配和撤销来提供可靠的来源通告源,用于来源认证。我们通过一组智能合约在防篡改的以太坊区块链上执行和审核资源分配,这些合约也可以作为一个智能合约进行交互以提供可信赖的BGP原始路由检查。与RPKI相比,BGPcoin在保护原始广告和为对象存储库构建可靠的基础结构方面具有显着的优势。我们通过以太坊原型实现对其进行演示,然后将其部署并分别在本地模拟的网络和官方的以太坊测试网络上进行实验。广泛的实验和评估证明了部署BGPcoin的动机,并且BGPcoin提供的增强的安全性在技术和经济上都是可行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号