A Lightweight Scheme for Protecting AS-PATH Attributes of Update Messages

Bo Yang · Journal of Networks · 2014

In existing schemes for protecting AS-PATH attributes of update messages, the security of S-BGP and BGPSEC has received wide acceptance. Yet, in S-BGP or BGPSEC, the number of signatures in a route attestation is linear in the length of AS-PATH , which is one of major hurdles of deploying in the real world and thus is an important and urgent problem. Existing schemes for solving this problem reduce the number of signatures by using aggregate signatures. Yet, its computation overhead of verifying ASPATH is too heavy. In this paper, we present a scheme for reducing the number of signatures by using aggregate signatures, whose computation overhead of verifying ASPATH can be significantly lowered. The presented scheme combines aggregate signature and Rabin signature. By it, the number of signatures in a route attestation is only one because aggregate signature is used. Moreover, differing from the existing aggregate-signature based schemes, the computation overhead of verifying AS-PATH is roughly only one multiplication each hop because Rabin signature is used. Computation overhead of verifying in presented scheme is roughly 1/2400 of that of existing scheme.

Read the paper · More papers on PaperTik