MaxLength Considered Harmful to the RPKI
MaxLength Considered Harmful to the RPKI
复制标题
MaxLength 被认为对 RPKI 有害
DOI:
10.1145/3143361.3143363
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
S. Goldberg
中科院分区:
文献类型:
--
作者:
Y. Gilad;Omar Sagga;S. Goldberg
User convenience and strong security are often at odds, and most security applications need to find some sort of balance between these two (often opposing) goals. The Resource Public Key Infrastructure (RPKI), a security infrastructure built on top of interdomain routing, is not immune to this issue. The RPKI uses the maxLength attribute to reduce the amount of information that must be explicitly recorded in its cryptographic objects. MaxLength also allows operators to easily reconfigure their networks without modifying their RPKI objects. Our network measurements, however, suggest that the maxLength attribute strikes the wrong balance between security and user convenience. We therefore believe that operators should avoid using maxLength. We give operational recommendations and develop software that allow operators to reap many of the benefits of maxLength without its security costs.