Efficient Security Mechanisms for Routing Protocols

Efficient Security Mechanisms for Routing Protocols
复制标题

DOI:
--
复制
发表时间:
2003
期刊:
--
影响因子:
--
通讯作者:
Yih-Chun Hu
Yih-Chun Hu
中科院分区:
其他
文献类型:
--
作者:
Yih-Chun Hu

文献摘要

被引文献

相似文献

随着我们的经济和关键基础设施越来越依赖于互联网,确保路由协议的安全变得至关重要。在本文中,我们提出了四种新的机制作为保护距离矢量和路径矢量路由协议的工具。为了保护距离矢量协议,我们的哈希树链机制在转发路由表条目时强制路由器增加距离(度量)。为了在有限的时间内对接收到的路由更新进行身份验证,我们提出了一种类似于散列链的新机制,我们称之为树认证单向链。对于最大度量较大的情况,我们提出了skiipchains,它提供了更有效的初始计算成本和更有效的元素验证;这种机制基于一种新的加密机制,称为mw链,我们也提出了这种机制。为了确保路径矢量协议的安全,我们的累积认证机制在路由更新中对路径上的路由器列表进行认证,防止列表中的路由器地址被删除或重新排序;该机制在路由更新中只使用单个身份验证器,而不是每个路由器地址使用一个身份验证器。我们还提出了一种简单的机制来安全地切换单向链,通过使用前一个单向链对下一个单向链进行身份验证。这些机制都基于有效的对称加密技术,可以用作保护路由协议的构建块。
As our economy and critical infrastructure increasingly rely on the Internet, securing routing protocols becomes of critical importance. In this paper, we present four new mechanisms as tools for securing distance vector and path vector routing protocols. For securing distance vector protocols, our hash tree chain mechanism forces a router to increase the distance (metric) when forwarding a routing table entry. To provide authentication of a received routing update in bounded time, we present a new mechanism, similar to hash chains, that we call tree-authenticated oneway chains. For cases in which the maximum metric is large, we present skipchains, which provides more efficient initial computation cost and more efficient element verification; this mechanism is based on a new cryptographic mechanism, called MW-chains, which we also present. For securing path vector protocols, our cumulative authentication mechanism authenticates the list of routers on the path in a routing update, preventing removal or reordering of the router addresses in the list; the mechanism uses only a single authenticator in the routing update rather than one per router address. We also present a simple mechanism to securely switch one-way chains, by authenticating the next one-way chain using the previous one. These mechanisms are all based on efficient symmetric cryptographic techniques and can be used as building blocks for securing routing protocols.