Title :
TTM Based Security Enhancement for Inter-domain Routing Protocol
Author :
Zhu, Peidong ; Hu, Xiangjiang ; Cao, Huayang ; Wang, Xiaoqiang
Author_Institution :
Sch. of Comput. Sci., Nat. Univ. of Defense Technol., Changsha, China
Abstract :
Border gateway protocol (BGP) acts as a vital part of the global infrastructure. Attacks against BGP are increasing in number and severity. Unfortunately, most security mechanisms based on public key cryptography suffer from performance, trust model and other issues. This paper proposes a solution that takes advantages of the power-law and rich-club features of the AS-level topology, and proposes the notion of AS Alliance and a new trust model - translator trust model (TTM). TTM avoids the global distribution of certificates by trust translating between different trust domains. It achieves that with much less memory overhead than traditional solutions, and a shorter validation chain. We develop a novel SE-BGP (security enhanced BGP) mechanism based on TTM. It introduces new path attributes to carry origin certificates and path signatures, and the algorithms to process origin authentication and path authentication. Our analyses indicate that SE-BGP is a viable solution.
Keywords :
Internet; digital signatures; public key cryptography; routing protocols; telecommunication network topology; autonomous systems Alliance; autonomous systems-level topology; border gateway protocol; interdomain routing protocol; origin authentication; origin certificates; path authentication; path signatures; public key cryptography; translator trust model based security enhancement; Authentication; Information security; Internet; Large-scale systems; National security; Network topology; Protection; Public key cryptography; Routing protocols; Time to market; AS Alliance; BGP; Origin Authentication; Path Authentication; Translator Trust Model;
Conference_Titel :
Network Computing and Applications, 2009. NCA 2009. Eighth IEEE International Symposium on
Conference_Location :
Cambridge, MA
Print_ISBN :
978-0-7695-3698-9
Electronic_ISBN :
978-0-7695-3698-9
DOI :
10.1109/NCA.2009.39