A Security Scheme of BGP Base on Aggregate Signatures Algorithm
Jianhui Zhang, Sun’an Wang, Bin Wang, Binqiang Wang · 2009
The Border Gateway Protocol (BGP), which is used to distribute routing information between autonomous systems, is an important component of the Internet's routing infrastructure. However, due to the lack of the mechanism the BGP is highly vulnerable to a variety of attacks. Many solutions have been proposed by some corporations or individual. But the current propositions either were difficult in operation, or lacked the sufficient security guarantee. In the paper, a security scheme of BGP is proposed, which adopts identity-based cryptography and aggregate signatures algorithm for verifying the propriety of IP prefix origination and verify the validity of an AS to announce Network Information (NLRI). Compared with S-BGP, the scheme can efficient reduce BGP router's process load and more easily deployed across Internet.