Improved Validation Mechanism of Route Origination in BGP
CSTR:
Author:
  • Article
  • | |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • | |
  • Comments
    Abstract:

    Resource public key infrastructure (RPKI) is a kind of technology which is used to protect the authenticity of Internet code number resources allocation and a kind of system of supporting inter-domain routing security which solves the problem of the lack of validation of route origination in BGP.However, it may result in the lack of authenticity and validity of ROA information due to the current data synchronism mechanism between the relying party of RPKI system and BGP routers.Meanwhile, it will bring a lot of performance load of BGP routes that query the cache lists continuingly.In this paper, we propose an improved method for route origination authentication.The sender routers real-timely apply for ROA certificates from RP and transmit them to the peer routers with the update message.Then the peer routers can apply for the public key to verify the certificates and verify the authenticity of the route originate.The verification mechanism is changed from updating the cache list periodically to real-time application for certification.It can effectively solve the problem that the ROA of the RP and the router data synchronization may be wrong, and reduce the running load of routes caused by querying the cache lists effectively.It is proved that the feasibility of the scheme using the simulation tool of Quagga and we make the detailed analysis for the applicable situation of two mechanisms.

    Reference
    Related
    Cited by
Get Citation

贾佳,延志伟,耿光刚,金键.一种改进的BGP路由源认证机制.计算机系统应用,2017,26(1):240-245

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:April 19,2016
  • Revised:May 26,2016
  • Online: January 14,2017
Article QR Code
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063