• DocumentCode
    1336156
  • Title

    Keychain-Based Signatures for Securing BGP

  • Author

    Yin, Heng ; Sheng, Bo ; Wang, Haining ; Pan, Jianping

  • Author_Institution
    Dept. of Electr. Eng. & Comput. Sci., Syracuse Univ., Syracuse, NY, USA
  • Volume
    28
  • Issue
    8
  • fYear
    2010
  • fDate
    10/1/2010 12:00:00 AM
  • Firstpage
    1308
  • Lastpage
    1318
  • Abstract
    As a major component of Internet routing infrastructure, the Border Gateway Protocol (BGP) is vulnerable to malicious attacks. While Secure BGP (S-BGP) provides a comprehensive framework to secure BGP, its high computational cost and low incremental deployment benefits seriously impede its wide usage in practice. Using a lightweight symmetric signature scheme, SPV is much faster than S-BGP. However, the speed boost comes at the price of prohibitively large signatures. Aggregated path authentication reduces the overhead of securing BGP in terms of both time and space, but the speed improvement is still limited by public key computation. In this paper, we propose a keychain-based signature scheme called KC-x. It has low CPU and memory overheads and provides strong incentive for incremental deployment on the Internet. As a generic framework, KC-x has the flexibility of using different signature algorithms, which can even co-exist in a hybrid deployment. We investigate two implementations of KC-x: KC-RSA based on RSA and KC-MT based on Merkle hash tree. Using real BGP workloads, our experimental results show that KC-RSA is as efficient as SAS-V (the most efficient software approach for aggregated path authentication), and KC-MT is even three times faster than SPV with 40% smaller signatures. Through the hybrid deployment of KC-MT and KC-RSA, KC-x can achieve both small signature and high processing rate for BGP speakers.
  • Keywords
    Internet; routing protocols; telecommunication security; BGP; BGP speakers; Internet; Internet routing; Merkle hash tree; border gateway protocol; key chain-based signatures; lightweight symmetric signature; secure routing protocol; Bandwidth; Logic gates; Nickel; Public key; Routing; Routing protocols; BGP; Keychain-based Signature; Performance Optimization; Secure Routing Protocol;
  • fLanguage
    English
  • Journal_Title
    Selected Areas in Communications, IEEE Journal on
  • Publisher
    ieee
  • ISSN
    0733-8716
  • Type

    jour

  • DOI
    10.1109/JSAC.2010.101008
  • Filename
    5586443