• DocumentCode
    3170589
  • Title

    Relieve Internet Routing Security of Public Key Infrastructure

  • Author

    Mancini, Luigi V. ; Spognardi, Angelo ; Soriente, Claudio ; Villani, Antonio ; Vitali, Domenico

  • fYear
    2012
  • fDate
    July 30 2012-Aug. 2 2012
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    Lack of security mechanisms expose the Border Gateway Protocol (BGP) to a wide range of threats that are constantly undermining security of the Internet. Most prominent attacks include prefix hijacking and announcement of false routes to maliciously attract or divert traffic. A number of cryptographic solutions to prevent both attacks have been proposed but have not been adopted due to involved operations and considerable overhead. Most of them rely on digital signatures to authorize Autonomous Systems to propagate route announcements. Surprisingly, the scientific community has devoted only little interest to the problem of revocation in BGP. In particular, BGP systems based on Public Key Infrastructure allow to revoke an Autonomous System by revoking its public key certificate. However, there seem to be no solution for selective revocation of AS-path announcements. This paper introduces reBGP, an enhanced version of BGP that leverages Identity Based Cryptography to secure BGP with minimal overhead. reBGP prevents prefix hijacking and false route announcement through Aggregate Identity Based Signatures and provides an effective revocation means to invalidate AS-path announcements. reBGP enjoys a constant overhead to verify authenticity of routes and does not require a Public Key Infrastructure. Extensive testing of our implementation, show that our proposal represents a practical solution to secure BGP.
  • Keywords
    Internet; computer network security; digital signatures; public key cryptography; routing protocols; AS-path announcements; Internet routing security; autonomous system authorization; border gateway protocol; cryptographic solutions; digital signatures; false route announcement; false routes announcement; identity based cryptography; prefix hijacking; public key certificate; public key infrastructure; reBGP; Aggregates; IP networks; Internet; Public key; Routing protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks (ICCCN), 2012 21st International Conference on
  • Conference_Location
    Munich
  • Print_ISBN
    978-1-4673-1543-2
  • Type

    conf

  • DOI
    10.1109/ICCCN.2012.6289235
  • Filename
    6289235