首页> 外文期刊>Information Forensics and Security, IEEE Transactions on >Enhancing the Trust of Internet Routing With Lightweight Route Attestation
【24h】

Enhancing the Trust of Internet Routing With Lightweight Route Attestation

机译:轻量级路由证明增强了Internet路由的信任

获取原文
获取原文并翻译 | 示例
           

摘要

The weak trust model in Border Gateway Protocol (BGP) introduces severe vulnerabilities for Internet routing including active malicious attacks and unintended misconfigurations. Although various secure BGP solutions have been proposed, the complexity of security enforcement and data-plane attacks still remain open problems. We propose TBGP, a trusted BGP scheme aiming to achieve high authenticity of Internet routing with a simple and lightweight attestation mechanism. TBGP introduces a set of route update and withdrawal rules that, if correctly enforced by each router, can guarantee the authenticity and integrity of route information that is announced to other routers in the Internet. To verify this enforcement, an attestation service running on each router provides interfaces for a neighboring router to challenge the integrity of its routing stack, enforced rules, and the attestation service itself. If this attestation succeeds, the neighboring router updates its routing table or announces the route to its neighbors, following the same rules. Thus, a router on a routing path only needs to verify one neighbor's routing status to ensure that the route information is valid. Through this, TBGP builds a transitive trust relationship among all routers on a routing path. We implement a prototype of TBGP to investigate its practicality. In our implementation, we use identity-based signature and trusted computing techniques to further reduce the complexity of security operations. Our security analysis and performance study shows that TBGP can achieve the security goals of BGP with significantly better convergence performance and lower computation overhead than existing secure BGP solutions.
机译:边界网关协议(BGP)中的弱信任模型引入了严重的Internet路由漏洞,包括活动的恶意攻击和意外的错误配置。尽管已经提出了各种安全的BGP解决方案,但是安全实施和数据平面攻击的复杂性仍然是未解决的问题。我们提出了TBGP,这是一种受信任的BGP方案,旨在通过简单且轻巧的证明机制来实现Internet路由的高度真实性。 TBGP引入了一组路由更新和撤消规则,如果每个路由器正确执行了这些规则,它们可以保证向Internet中其他路由器通告的路由信息​​的真实性和完整性。为了验证这种强制执行,在每个路由器上运行的证明服务为相邻路由器提供接口,以挑战其路由堆栈,强制执行的规则以及证明服务本身的完整性。如果此证明成功,则邻居路由器按照相同的规则更新其路由表或宣布到其邻居的路由。因此,路由路径上的路由器只需要验证一个邻居的路由状态即可确保路由信息有效。这样,TBGP在路由路径上的所有路由器之间建立了传递信任关系。我们实现了TBGP的原型以研究其实用性。在我们的实现中,我们使用基于身份的签名和可信计算技术来进一步降低安全操作的复杂性。我们的安全性分析和性能研究表明,与现有的安全BGP解决方案相比,TBGP可以以更高的收敛性能和更低的计算开销实现BGP的安全性目标。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号