Keychain-Based Signatures for Securing BGP

Keychain-Based Signatures for Securing BGP
复制标题

DOI:
10.1109/jsac.2010.101008
复制
发表时间:
2010-10
影响因子:
16.4
通讯作者:
Heng Yin;Bo Sheng;Haining Wang;Jianping Pan
Heng Yin;Bo Sheng;Haining Wang;Jianping Pan
中科院分区:
计算机科学1区
文献类型:
--
作者:
Heng Yin;Bo Sheng;Haining Wang;Jianping Pan

文献摘要

被引文献

相似文献

作为Internet路由基础设施的重要组成部分,边界网关协议BGP (Border Gateway Protocol)容易受到恶意攻击。安全BGP (Secure BGP, S-BGP)为安全BGP提供了一个全面的框架,但其高昂的计算成本和较低的增量部署效益严重阻碍了其在实际中的广泛应用。SPV采用轻量级对称签名方案,速度比S-BGP快得多。然而,速度的提升是以惊人的大签名为代价的。聚合路径认证从时间和空间上降低了保护BGP的开销,但速度的提高仍然受到公钥计算的限制。在本文中,我们提出了一个基于密钥链的签名方案KC-x。它具有较低的CPU和内存开销,并为Internet上的增量部署提供了强烈的激励。作为通用框架,KC-x具有使用不同签名算法的灵活性,甚至可以在混合部署中共存。我们研究了KC-x的两种实现:基于RSA的KC-RSA和基于Merkle哈希树的KC-MT。使用真实的BGP工作负载,我们的实验结果表明,KC-RSA与SAS-V(最有效的聚合路径认证软件方法)一样高效,KC-MT甚至比SPV快三倍,签名小40%。通过KC-MT和KC-RSA的混合部署,KC-x既可以实现小签名,又可以实现高处理速率。
As a major component of Internet routing infrastructure, the Border Gateway Protocol (BGP) is vulnerable to malicious attacks. While Secure BGP (S-BGP) provides a comprehensive framework to secure BGP, its high computational cost and low incremental deployment benefits seriously impede its wide usage in practice. Using a lightweight symmetric signature scheme, SPV is much faster than S-BGP. However, the speed boost comes at the price of prohibitively large signatures. Aggregated path authentication reduces the overhead of securing BGP in terms of both time and space, but the speed improvement is still limited by public key computation. In this paper, we propose a keychain-based signature scheme called KC-x. It has low CPU and memory overheads and provides strong incentive for incremental deployment on the Internet. As a generic framework, KC-x has the flexibility of using different signature algorithms, which can even co-exist in a hybrid deployment. We investigate two implementations of KC-x: KC-RSA based on RSA and KC-MT based on Merkle hash tree. Using real BGP workloads, our experimental results show that KC-RSA is as efficient as SAS-V (the most efficient software approach for aggregated path authentication), and KC-MT is even three times faster than SPV with 40% smaller signatures. Through the hybrid deployment of KC-MT and KC-RSA, KC-x can achieve both small signature and high processing rate for BGP speakers.