APVAS+: A Practical Extension of BGPsec with Low Memory Requirement
APVAS+: A Practical Extension of BGPsec with Low Memory Requirement
复制标题
DOI:
10.1109/icc42927.2021.9500278
复制
发表时间:
2021-06
期刊:
影响因子:
--
通讯作者:
Tatsuya Takemura;Naoto Yanai;Naoki Umeda;Masayuki Okada;Shingo Okamura;Jason Paul Cruz
中科院分区:
文献类型:
--
作者:
Tatsuya Takemura;Naoto Yanai;Naoki Umeda;Masayuki Okada;Shingo Okamura;Jason Paul Cruz
BGPsec is a protocol that utilizes digital signatures to guarantee the validity of routing information on the Internet. However, it is impractical because its use of digital signatures requires significant memory that is beyond the memory capacity of current routers. The latest extension of BGPsec based on an aggregate signature scheme, which aggregates individual signatures into a single short signature, has been proposed in the recent years, but its memory requirement is still impractical. In this paper, we present APVAS+, a protocol that reduces the memory consumption of routers compared to state-of-the-art protocols. The memory requirement of APVAS+ is almost within the memory capacity of real-world routers. While the latest BGPsec protocol can only aggregate signatures generated on a single linear network topology, APVAS+ can aggregate signatures generated on any network topology by using a novel aggregate signature scheme. We also show a prototype implementation of APVAS+ by extending a router software called BIRD. Using this prototype, we conducted experiments on a full route information, i.e., about 800,000 routes. We consider that APVAS+ can be optimized to further reduce its memory requirement, and our promising results show that the memory consumption of routers running APVAS+ is lower than that of routers running other protocols by more than half when guaranteeing the validity of routing information.